Heu, j'ai bien lancé combo-fix.exe, mais il n'a pas redémarré mon PC. Est ce normal ?
Je te mets le rapport ci-dessous.
Par contre, je sais pas ce que c'est un "nouveau rapport hijackthis" ... Est ce que c'est le premier rapport que j'ai fait avec S!ri ?
Rapport ComboFix :
ComboFix 09-01-13.03 - Administrateur 2009-01-13 23:30:11.1 - NTFSx86
Microsoft® Windows Vista™ Édition Intégrale 6.0.6000.0.1252.1.1036.18.2046.1341 [GMT 1:00]
Lancé depuis: c:\users\Administrateur\Desktop\combo-fix.exe
AV: avast! antivirus 4.8.1229 [VPS 090113-1] *On-access scanning disabled* (Outdated)
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\hpowiav1.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\resycled
E:\resycled
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-13 au 2009-01-13 ))))))))))))))))))))))))))))))))))))
.
2009-01-13 23:11 . 2009-01-13 23:12 <REP> d-------- c:\program files\FindyKill
2009-01-13 00:16 . 2009-01-13 00:16 691 --a------ c:\users\Administrateur\AppData\Roaming\GetValue.vbs
2009-01-13 00:16 . 2009-01-13 00:16 35 --a------ c:\users\Administrateur\AppData\Roaming\SetValue.bat
2008-12-14 14:32 . 2008-12-14 14:32 <REP> d-------- c:\program files\Hewlett-Packard
2008-12-14 14:32 . 2008-12-14 14:32 <REP> d-------- c:\program files\Common Files\HP
2008-12-14 14:32 . 2008-12-14 14:32 <REP> d-------- c:\program files\Common Files\Hewlett-Packard
2008-12-14 14:30 . 2008-12-14 14:30 <REP> d-------- c:\program files\HP
2008-12-14 14:28 . 2008-12-14 14:32 164,303 --a------ c:\windows\hpoins19.dat
2008-12-14 14:26 . 2008-12-14 14:32 <REP> d-------- c:\users\All Users\HP
2008-12-14 14:26 . 2008-12-14 14:32 <REP> d-------- c:\programdata\HP
2008-12-14 14:26 . 2006-12-16 07:19 897,024 --a------ c:\windows\System32\hpotiop1.dll
2008-12-14 14:26 . 2006-12-16 07:19 303,104 --a------ c:\windows\System32\hpovst01.dll
2008-12-14 14:26 . 2006-11-20 22:36 258,048 --a------ c:\windows\System32\hpzids01.dll
2008-12-14 14:26 . 2007-03-13 20:27 26,952 --a------ c:\windows\hpomdl19.dat
2008-12-14 14:11 . 2008-12-14 14:11 <REP> d-------- c:\users\Administrateur\AppData\Roaming\HP
2008-12-13 13:46 . 2009-01-11 16:29 244 --ah----- C:\sqmnoopt19.sqm
2008-12-13 13:46 . 2009-01-11 16:29 232 --ah----- C:\sqmdata19.sqm
2008-12-13 13:40 . 2008-12-13 13:41 <REP> d-------- C:\UsinePreparations
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-23 18:12 --------- d-----w c:\programdata\2DBoy
2008-11-23 04:12 66,872 ----a-w c:\windows\System32\PnkBstrA.exe
2008-11-23 04:12 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-23 04:12 103,736 ----a-w c:\windows\System32\PnkBstrB.exe
2008-11-22 23:47 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-08-19 19:01 22,328 ----a-w c:\users\Administrateur\AppData\Roaming\PnkBstrK.sys
2008-07-28 20:14 174 --sha-w c:\program files\desktop.ini
2008-09-04 20:37 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-09-04 20:37 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-09-04 20:37 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2006-11-02 1196032]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 92704]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 c:\windows\RtHDVCpl.exe]
c:\users\Administrateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de notification Live Search.lnk - c:\users\Administrateur\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2008-11-03 143360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableInstallerDetection"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DisableNotifications"= 1 (0x1)
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"= c:\program files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1D2F6CA8-65F2-44AA-AE46-3A096F78B5C6}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{16222347-E4B4-4753-9531-3F8C368EABEC}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{040037F0-1137-4308-9E30-9F014DDBE48B}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0284E8D0-4EF0-480A-9BEE-2A0696232DD6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1C820141-A0D1-41E0-9A6F-434DC662C733}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DisableNotifications"= 1 (0x1)
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DisableNotifications"= 1 (0x1)
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"= c:\program files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-09-01 78416]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-09-01 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2008-09-01 51280]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25f53d8b-5ce1-11dd-adc2-806e6f6e6963}]
\shell\AutoRun\command - F:\AutoStarter.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{467d8a34-8f0f-11dd-9251-001fc6111bfa}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a7be4f7-5ce4-11dd-9da5-001fc6111bfa}]
\shell\AutoRun\command - G:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9a7be4f9-5ce4-11dd-9da5-001fc6111bfa}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc5330ec-8727-11dd-9399-001fc6111bfa}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
.
Contenu du dossier 'Tâches planifiées'
2009-01-13 c:\windows\Tasks\User_Feed_Synchronization-{9D2C9BB4-6A54-4BC9-95FA-E34EFE1291D7}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 10:45]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-13 23:31:06
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\ADMINI~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
Heure de fin: 2009-01-13 23:32:19
ComboFix-quarantined-files.txt 2009-01-13 22:32:17
Avant-CF: 81 393 360 896 octets libres
Après-CF: 82,087,473,152 octets libres
154