Bonjour bibou0007
J'ai suivi à la lettre tes instructions, et apparemment, je n'ai plus d'ouverture intempestive de fenêtre pendant la navigation internet. Voici les rapports suite à l'analyse par Combofix:
2007-08-23 21:47 87608 --a------ C:\Qoobox\Quarantine\C\Users\jean-luc\AppData\Roaming\inst.exe.vir
2008-04-30 21:32 39936 --a------ C:\Qoobox\Quarantine\C\Windows\System32\byXNdawV.dll.vir
2008-04-30 21:33 39936 --a------ C:\Qoobox\Quarantine\C\Windows\System32\xxyaxVmm.dll.vir
2008-05-03 09:36 54 --a------ C:\Qoobox\Quarantine\catchme.log
ComboFix 08-05-01.3 - jean-luc 2008-05-03 9:34:55.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1676 [GMT 2:00]
Endroit: C:\Users\jean-luc\Downloads\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\jean-luc\AppData\Roaming\.#
C:\Users\jean-luc\AppData\Roaming\inst.exe
C:\Windows\system32\byXNdawV.dll
C:\Windows\system32\xxyaxVmm.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-03 to 2008-05-03 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-03 07:19 --------- d---a-w C:\PROGRA~2\TEMP
2008-05-03 07:00 58,000 ----a-w C:\Users\jean-luc\AppData\Roaming\GDIPFONTCACHEV1.DAT
2008-05-02 18:08 --------- d-----w C:\PROGRA~2\Google Updater
2008-05-02 17:52 --------- d-----w C:\Program Files\Trend Micro
2008-05-02 16:01 --------- d-----w C:\Program Files\Spyware Doctor
2008-05-01 10:30 --------- d-----w C:\Users\jean-luc\AppData\Roaming\Azureus
2008-04-30 15:47 --------- d-----w C:\Users\jean-luc\AppData\Roaming\PC Tools
2008-04-20 19:33 --------- d-----w C:\Users\jean-luc\AppData\Roaming\Microsoft Game Studios
2008-04-20 19:33 --------- d-----w C:\Program Files\Microsoft Games
2008-04-20 19:33 --------- d-----w C:\PROGRA~2\Microsoft Games
2008-04-20 19:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-20 19:19 --------- d-----w C:\Program Files\EA GAMES
2008-04-15 19:22 --------- d-----w C:\Program Files\Azureus
2008-04-14 18:45 --------- d-----w C:\Program Files\Paint.NET
2008-04-12 12:56 --------- d-----w C:\Users\jean-luc\AppData\Roaming\LimeWire
2008-04-09 16:20 --------- d-----w C:\Program Files\Free PDF to Word Doc Converter
2008-04-09 03:10 --------- d-----w C:\Program Files\Windows Mail
2008-04-04 01:59 --------- d-----w C:\Program Files\Picasa2
2008-03-15 20:46 --------- d-----w C:\Program Files\EA SPORTS
2008-03-15 20:34 --------- d-----w C:\Program Files\QuickTime
2008-03-14 17:46 --------- d-----w C:\Program Files\Java
2008-03-05 19:05 --------- d-----w C:\Users\jean-luc\AppData\Roaming\Vso
2008-03-05 18:41 --------- d-----w C:\Program Files\DVDFab Platinum 4
2008-03-05 17:35 --------- d-----w C:\Program Files\DVD Shrink
2008-03-05 17:35 --------- d-----w C:\PROGRA~2\DVD Shrink
2008-02-29 14:46 669,184 ----a-w C:\Windows\System32\pbsvc.exe
2008-02-29 14:46 22,328 ----a-w C:\Users\jean-luc\AppData\Roaming\PnkBstrK.sys
2008-02-29 14:46 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-27 16:46 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-14 04:07 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 04:04 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 04:04 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 04:04 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 04:04 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 04:04 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 04:03 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 04:03 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 04:03 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 04:03 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-14 04:03 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 04:03 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 04:03 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2007-08-29 18:42 174 --sha-w C:\Program Files\desktop.ini
2007-08-23 19:47 47,360 ----a-w C:\Users\jean-luc\AppData\Roaming\pcouffin.sys
2007-07-24 16:28 20 ---h--w C:\Users\All Users\PKP_DLec.DAT
2007-07-24 16:28 20 ---h--w C:\Users\All Users\PKP_DLds.DAT
2007-07-24 16:28 20 ---h--w C:\PROGRA~2\PKP_DLec.DAT
2007-07-24 16:28 20 ---h--w C:\PROGRA~2\PKP_DLds.DAT
2007-05-07 09:11 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2008-01-26 07:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-26 07:24 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-26 07:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-11 06:01 1232896]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-07 20:44 68856]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29 165784]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-05-07 20:55 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 15:46 4349952 C:\Windows\RtHDVCpl.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 13:39 151552]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-24 22:44 29744]
"toolbar_eula_launcher"="C:\Program Files\GoogleEULA\EULALauncher.exe" [2007-02-09 16:54 16896]
"SystrayORAHSS"="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 20:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-28 19:42 185632]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 05:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 05:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 05:28 81920]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 14:23 200704]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-05-07 19:09:45 118784]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-07 20:44:21 125624]
StupAssist.lnk - C:\Program Files\Common Files\Nikon\Utilities\StupAssist.exe [2007-05-07 19:10:02 31744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{B3E91D63-35E8-4995-9808-27478C9C48CE}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{7B32628A-1ED1-4BD9-BA6A-95A54B914B65}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{E5B21E85-800A-4B9F-9E8F-3B0CE1B7A957}C:\\users\\jean-luc\\appdata\\local\\temp\\nero web\\setupxu.exe"= UDP:C:\users\jean-luc\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
"UDP Query User{32131B5D-7106-47ED-BC29-B6FFABEEC6C6}C:\\users\\jean-luc\\appdata\\local\\temp\\nero web\\setupxu.exe"= TCP:C:\users\jean-luc\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
"TCP Query User{6B18781C-4E38-4545-BFCA-4FA8F5448212}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{269C098B-DDEF-41C4-B268-F8D3D974DFBA}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{8481F3F3-AEE2-4F07-A9E8-307AC94C4059}"= UDP:C:\Program Files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{4CEAC6DC-CB1B-4C47-AF26-C6659BD946AC}"= TCP:C:\Program Files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{66ABFF8C-9141-47B3-AAC8-A7AF86B93796}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{AC8AC571-6F35-4A83-A1C5-257A3497D3DB}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{63FCD8D7-B45A-4E02-81FB-18C05A4F6D82}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{09DE8F8F-4E20-4472-9D25-CDD374DD5E7C}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{00DC014D-96F8-4D64-8D85-144A4C3C0BF6}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{AA8F58D7-2A68-44FC-B7C5-5B8F1D8B5172}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{C85FE93E-924C-4CCF-85BC-C3A0600B2E3E}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{0731ADE0-0C76-44CD-8B43-42CBBF08460E}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{ECE6DE09-4ED4-4AA2-B4E0-56C5482B8402}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{DD02BF3B-F594-44EC-B980-3ECEFC320A5B}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
S3 cxbu0wdm;CardMan 1021;C:\Windows\system32\DRIVERS\cxbu0wdm.sys [2008-01-15 13:39]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-24 22:44]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys [2006-11-28 21:46]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2006-11-28 21:46]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\shell\AutoRun\command - E:\Startup.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - ECACHE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-03 09:45:57
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-03 9:46:30
ComboFix-quarantined-files.txt 2008-05-03 07:46:18
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
170 --- E O F --- 2008-05-02 10:21:50
Merci pour ton futur dignostic.