Bonjour, je suis de retour (le cyber a réouvert !!), j'ai fait la manipulation demandée avec combofix (même s'il semblerait qu'il y ait eu un pbl avec la console de réinstallation qu'il m'a en premier lieu reconnue puis après non.. mais l'analyse a pu se faire apparemment). Je poste le rapport, en espérant que cette fois sera la bonne ;-)
ComboFix 09-01-11.02 - BIBLIO'BROUSSE 2009-01-12 12:14:16.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1023.640 [GMT 0:00]
Lancé depuis: c:\documents and settings\BIBLIO'BROUSSE\Bureau\ComboFix.exe
Commutateurs utilisés :: F:\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Outdated)
FW: Pare-feu BitDefender *disabled*
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-12 au 2009-01-12 ))))))))))))))))))))))))))))))))))))
.
2009-01-10 16:25 . 2009-01-10 16:25 <REP> d-------- C:\_OTMoveIt
2009-01-10 16:18 . 2009-01-10 16:00 348,160 --a------ c:\program files\OTMoveIt3.exe
2009-01-10 15:22 . 2009-01-10 15:22 <REP> d-------- c:\documents and settings\ELEVES\Application Data\BitDefender
2009-01-10 15:03 . 2009-01-10 15:12 <REP> d-------- c:\program files\UsbFix
2009-01-10 15:00 . 2009-01-10 15:41 565,786 --a------ c:\program files\UsbFix.exe
2009-01-10 12:25 . 2009-01-10 12:25 <REP> d-------- c:\program files\Trend Micro
2009-01-10 12:25 . 2008-10-06 12:47 812,344 --a------ c:\program files\HJTInstall.exe
2009-01-10 12:25 . 2008-10-06 12:47 401,720 --a------ c:\program files\HiJackThis.exe
2009-01-10 12:25 . 2008-10-06 12:58 231,299 --a------ c:\program files\install_mbamsetup.exe
2009-01-09 17:27 . 2009-01-09 18:51 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-09 17:26 . 2009-01-09 17:26 <REP> d-------- c:\program files\Trojan Remover
2009-01-09 17:26 . 2009-01-09 17:26 <REP> d-------- c:\documents and settings\BIBLIO'BROUSSE\Application Data\Simply Super Software
2009-01-09 17:26 . 2009-01-09 17:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-01-09 17:26 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-01-09 17:26 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-01-09 17:26 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-01-09 17:26 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-01-09 17:26 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-01-09 17:24 . 2009-01-09 17:24 <REP> d-------- c:\program files\PrevxCSI
2009-01-09 17:24 . 2009-01-09 20:23 <REP> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-01-09 17:24 . 2009-01-09 16:32 8,244,072 --a------ c:\program files\trjsetup675.exe
2009-01-09 17:24 . 2009-01-09 16:32 927,288 --a------ c:\program files\PREVXProduct.EXE
2009-01-09 17:24 . 2009-01-09 17:24 26,808 --a------ c:\windows\system32\drivers\pxark.sys
2009-01-09 13:36 . 2009-01-09 13:39 1,851,544 --a------ c:\program files\install_flash_player.exe
2009-01-09 11:33 . 2009-01-09 11:33 <REP> d-------- c:\documents and settings\BIBLIO'BROUSSE\Application Data\BitDefender
2009-01-09 11:32 . 2009-01-09 11:33 <REP> d-------- c:\program files\BitDefender
2009-01-09 11:32 . 2009-01-09 11:36 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2009-01-05 14:40 . 2009-01-05 14:40 850 --a------ c:\windows\system32\ProductTweaks.xml
2009-01-05 14:40 . 2009-01-05 14:40 385 --a------ c:\windows\system32\user_gensett.xml
2009-01-05 14:29 . 2009-01-05 13:52 86,548,824 --a------ c:\program files\bitdefender_totalsecurity_2009_32b.exe
2009-01-05 14:29 . 2009-01-05 13:02 35,372,888 --a------ c:\program files\weekly(2).exe
2009-01-05 10:50 . 2009-01-05 10:50 <REP> d---s---- c:\documents and settings\BIBLIO'BROUSSE\UserData
2008-12-23 19:10 . 2008-12-23 19:10 <REP> d-------- c:\documents and settings\ELEVES\Application Data\Ahead
2008-12-22 14:24 . 2008-12-22 14:24 0 --a------ c:\windows\nsreg.dat
2008-12-20 16:51 . 2008-12-20 16:53 151 --a------ c:\windows\PhotoSnapViewer.INI
2008-12-20 16:37 . 2009-01-05 17:44 69 --a------ c:\windows\NeroDigital.ini
2008-12-19 21:38 . 2008-12-20 16:37 <REP> d-------- c:\documents and settings\BIBLIO'BROUSSE\Application Data\Ahead
2008-12-19 21:30 . 2008-12-19 21:30 <REP> d-------- c:\program files\Nero
2008-12-19 21:30 . 2008-12-19 21:40 <REP> d-------- c:\program files\Fichiers communs\Ahead
2008-12-12 15:57 . 2008-12-12 15:57 <REP> d--h----- c:\windows\PIF
2008-12-12 15:38 . 2008-12-12 15:50 <REP> d-------- C:\www
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 11:32 --------- d-----w c:\program files\Fichiers communs\BitDefender
2009-01-05 10:55 81,984 ----a-w c:\windows\system32\bdod.bin
2008-12-19 21:26 --------- d-----w c:\program files\ahead
2008-12-14 09:45 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\U3
2008-12-12 12:16 --------- d-----w c:\documents and settings\All Users\Application Data\CanonIJPLM
2008-12-04 16:18 73,728 ----a-w c:\windows\ALCFDRTM.EXE
2008-12-03 11:43 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\AdobeUM
2008-11-29 09:33 --------- d-----w c:\documents and settings\ELEVES\Application Data\Malwarebytes
2008-11-26 16:56 --------- d-----w c:\documents and settings\ELEVES\Application Data\vlc
2008-11-18 16:55 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\ODF
2008-11-18 16:54 --------- d-----w c:\program files\OD Fellowship
2008-11-18 15:05 --------- d-----w c:\program files\MSXML 4.0
2008-11-18 10:44 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\Malwarebytes
2008-11-18 10:44 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-16 14:04 --------- d-----w c:\documents and settings\ELEVES\Application Data\Kunnafoni
2008-11-15 11:09 --------- d-----w c:\program files\OpenOffice.org1.1.4
2008-11-15 11:00 69,632 ----a-w c:\windows\uinst001.exe
2008-11-15 10:56 --------- d-----w c:\program files\open office
2008-11-13 17:55 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\vlc
2008-11-12 14:03 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\Leadertech
2008-11-12 13:39 51,919 ----a-w c:\windows\BricoPackUninst.cmd
2008-11-12 13:39 4,839 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2008-11-12 13:39 219,648 ----a-w c:\windows\system32\uxtheme.dll
2008-11-12 13:32 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-12 13:17 --------- d-----w c:\documents and settings\All Users\Application Data\Adobe Systems
2008-11-12 13:02 --------- d-----w c:\program files\Fichiers communs\Adobe Systems Shared
2008-11-12 12:55 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\GlarySoft
2008-11-12 12:54 --------- d-----w c:\program files\Yahoo!
2008-11-12 12:32 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-12 12:32 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-11-12 11:26 --------- d-----w c:\program files\ScanSoft
2008-11-12 11:26 --------- d-----w c:\program files\Fichiers communs\ScanSoft Shared
2008-11-12 11:26 --------- d-----w c:\documents and settings\BIBLIO'BROUSSE\Application Data\ScanSoft
2008-11-12 11:26 --------- d-----w c:\documents and settings\All Users\Application Data\ScanSoft
2008-11-12 11:26 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-12 11:24 --------- d-----w c:\program files\Canon
2008-11-12 11:22 --------- d-----w c:\program files\Fichiers communs\CANON
2008-11-12 11:20 --------- d--h--w c:\documents and settings\All Users\Application Data\CanonBJ
2008-11-12 11:19 --------- d--h--w c:\program files\CanonBJ
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 14:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 14:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 10:38 663,552 ----a-w c:\windows\system32\wininet.dll
2009-01-09 12:01 61,440 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"DiskeeperSystray"="d:\programmes\Diskeeper\DkIcon.exe" [2005-11-22 221184]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2008-10-30 741376]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-01-01 1231752]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-06-29 c:\windows\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\BIBLIO'BROUSSE\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\BIBLIO'BROUSSE\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\BIBLIO'BROUSSE\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Assistant d'Acrobat.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 pxark;pxark;c:\windows\system32\drivers\pxark.sys [2009-01-09 26808]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-10-17 104328]
R4 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-09-04 82440]
R4 CSIScanner;CSIScanner;c:\program files\PrevxCSI\prevxcsi.exe [2009-01-09 927288]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Tâches planifiées'
2009-01-12 c:\windows\Tasks\GlaryInitialize.job
- d:\programmes\Glary Utilities\initialize.exe [2008-09-17 16:35]
2009-01-12 c:\windows\Tasks\Sauv.job
- c:\program files\BitDefender\BitDefender Backup\backup.exe [2008-11-17 12:22]
.
.
------- Examen supplémentaire -------
.
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\BIBLIO'BROUSSE\Application Data\Mozilla\Firefox\Profiles\[u]0/u5d6kkr5.default\
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-12 12:16:05
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-01-12 12:17:30
ComboFix-quarantined-files.txt 2009-01-12 12:17:27
Avant-CF: 68 285 779 968 octets libres
Après-CF: 68,274,528,256 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
190 --- E O F --- 2009-01-09 12:57:43