Bonsoir,
Merci pour ta prompte réponse. J'ai fait ce que tu m'as suggéré et voici le log de combofix.
NB:
1. Il n'y a pas eu de prompt de "console de récupération" comme indiqué dans le tutoriel. Est-ce ok ou dois-je l'installer séparément, si oui pourquoi et comment?
2. En remettant en route Spybot teatimer, celui-ci a détecté une bonne dizaine de modifications à la base de registre (ajout, modif et suppressions) que j'ai TOUTES autorisées. Ais-je bien fait?
3. Que dois-je faire avec les "anomalies" mentionées dans mon post initial?
4. Je n'ai pas encore redémarré mon PC car tout semble fonctionner. Devrais-je le faire avant de poursuivre cette discussion?
Voici le log. J'attends tes conseils avec impatience...
ComboFix 09-01-19.05 - pdf 20/01/2009 18:51:28.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.511.238 [GMT 1:00]
Running from: c:\documents and settings\pdf.W2KGE014\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\winnt\Downloaded Program Files\setup.inf
c:\winnt\system\msvbvm60.dll
c:\winnt\system32\mdm.exe
c:\winnt\twain_16.dll
c:\winnt\Web\default.htt
.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2040-02-05 11:28 9,728 ----a-r c:\winnt\SYSTEM32\HPW9lmn.dll
2009-01-20 17:47 --------- d-----w c:\documents and settings\pdf.W2KGE014\Application Data\Skype
2009-01-20 17:41 --------- d---a-w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-13 15:34 --------- d-----w c:\program files\MyMobiler
2009-01-04 17:28 --------- d-----w c:\program files\Sunbelt Software
2009-01-04 17:17 --------- d-----w c:\program files\CCleaner
2009-01-04 16:47 30,958 ----a-w c:\winnt\system32\drivers\fwdrv.err
2008-12-25 10:38 --------- d-----w c:\program files\RamBoost XP
2008-12-20 22:02 --------- d-----w c:\documents and settings\pdf.W2KGE014\Application Data\Image Zone Express
2008-12-11 12:09 239,472 ----a-w c:\winnt\system32\drivers\SRV.SYS
2008-12-11 12:09 239,472 ------w c:\winnt\SYSTEM32\DLLCACHE\srv.sys
2008-12-10 22:03 2,706,432 ----a-w c:\winnt\SYSTEM32\DLLCACHE\MSHTML.DLL
2008-12-10 16:37 --------- d-----w c:\program files\TCPoptimizer
2008-12-08 09:08 --------- d-----w c:\documents and settings\pdf.W2KGE014\Application Data\skypePM
2008-11-26 08:47 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-22 18:43 --------- d-----w c:\program files\QuickTime
2008-11-07 17:32 2,109,440 ------w c:\winnt\SYSTEM32\DLLCACHE\WMVCore.dll
2008-10-23 05:27 237,840 ----a-w c:\winnt\SYSTEM32\GDI32.DLL
2008-10-23 05:27 237,840 ----a-w c:\winnt\SYSTEM32\DLLCACHE\GDI32.DLL
2008-03-04 13:30 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2004-08-20 18:09 62,865 -c--a-w c:\winnt\INF\IM\odysseyIM3.sys
2004-08-20 18:09 45,056 ----a-w c:\winnt\INF\IM\imdinst.exe
2004-08-20 18:09 12,739 -c--a-w c:\winnt\INF\IM\odNetInstall.dll
2001-05-30 09:50 271 -c-ha-w c:\program files\DESKTOP.INI
2001-05-30 09:50 21,952 -c-ha-w c:\program files\FOLDER.HTT
2001-05-08 04:00 32,528 -c--a-w c:\winnt\INF\WBFIRDMA.SYS
2005-05-13 15:12 217,073 --sha-r c:\winnt\meta4.exe
2005-10-24 09:13 66,560 --sha-r c:\winnt\MOTA113.exe
2005-10-13 19:27 422,400 --sha-r c:\winnt\x2.64.exe
2005-10-07 17:14 308,224 --sha-r c:\winnt\SYSTEM32\avisynth.dll
2005-07-14 10:31 27,648 --sha-r c:\winnt\SYSTEM32\AVSredirect.dll
2005-06-26 13:32 616,448 --sha-r c:\winnt\SYSTEM32\cygwin1.dll
2005-06-21 20:37 45,568 --sha-r c:\winnt\SYSTEM32\cygz.dll
2004-01-24 22:00 70,656 --sha-r c:\winnt\SYSTEM32\i420vfw.dll
2006-04-27 08:24 2,945,024 --sha-r c:\winnt\SYSTEM32\Smab.dll
2005-02-28 11:16 240,128 --sha-r c:\winnt\SYSTEM32\x.264.exe
2004-01-24 22:00 70,656 --sha-r c:\winnt\SYSTEM32\yv12vfw.dll
.
------- Sigcheck -------
21/03/05 15:13 11264 ab176f2171db704d51b8809e8a5c38bd c:\winnt\SYSTEM32\CTFMON.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [07/11/08 14:31 21633320]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [13/11/06 13:07 1289000]
"rcwinHyper"="c:\program files\Le Robert\Le Robert & Collins\rcwinHyper.exe" [18/10/03 21:41 139264]
"Le Petit Robert Hyperappel"="c:\program files\Le Robert\Le Petit Robert\prhyper.exe" [11/10/01 12:11 22560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [26/11/08 18:18 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [15/10/08 01:04 39792]
"Synchronization Manager"="mobsync.exe" [19/06/03 12:05 111376 c:\winnt\SYSTEM32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [19/06/03 12:05 186640]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus G+ Wireless Adapter Utility.lnk - c:\program files\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE [2005-01-06 671744]
explorer.exe.lnk - c:\winnt\explorer.exe [2004-02-10 243472]
Process Explorer.lnk - c:\program files\Process explorer\procexp.exe [2007-10-26 3278400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ActiveSync]
13/11/06 13:05 16168 c:\winnt\SYSTEM32\WcesWlgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
"MSACM.CEGSM"= mobilev.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);c:\winnt\SYSTEM32\DRIVERS\SonyPVM1.sys [2005-12-25 28224]
R1 aswSP;avast! Self Protection;c:\winnt\SYSTEM32\DRIVERS\aswSP.sys [2008-04-06 111184]
R1 cdudf;cdudf;c:\winnt\SYSTEM32\DRIVERS\cdudf.sys [2002-07-31 362083]
R1 ClntMgmt;Compaq Client Management Driver;c:\winnt\SYSTEM32\DRIVERS\CLNTMGMT.SYS [2003-08-06 54254]
R1 SbFw;SbFw;c:\winnt\SYSTEM32\DRIVERS\SbFw.sys [2009-01-04 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\winnt\SYSTEM32\DRIVERS\sbhips.sys [2008-06-21 66600]
R3 dfmirage;dfmirage;c:\winnt\SYSTEM32\DRIVERS\dfmirage.sys [2008-04-15 31896]
R3 openhci;Microsoft USB Open Host Controller Driver;c:\winnt\SYSTEM32\DRIVERS\openhci.sys [2002-05-10 24784]
R3 ramirr;ramirr;c:\winnt\SYSTEM32\DRIVERS\ramirr.sys [2004-10-14 4864]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\winnt\SYSTEM32\DRIVERS\SBFWIM.sys [2009-01-04 65448]
R3 TNET1130;D-Link AirPlus G+ Wireless Adapter;c:\winnt\SYSTEM32\DRIVERS\GPLUS.sys [2005-01-06 286364]
R3 usbhub20;USB Hub Support;c:\winnt\SYSTEM32\DRIVERS\usbhub20.sys [2004-02-10 49776]
R4 aswFsBlk;aswFsBlk;c:\winnt\SYSTEM32\DRIVERS\aswFsBlk.sys [2008-04-06 20560]
R4 aswMon;avast! Standard Shield Support;c:\winnt\SYSTEM32\DRIVERS\aswmon.sys [2005-10-25 93296]
R4 BrSerial;Brother Serial Driver;c:\winnt\SYSTEM32\DRIVERS\BrSerial.sys [2005-07-08 44101]
R4 cpqWebDmi;Compaq DMI Web Agent;c:\progra~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [2003-08-06 24576]
R4 navi;VeriSign Updater;c:\program files\VeriSign\NAVI\naviagent.exe uimode=agentupdate --> c:\program files\VeriSign\NAVI\naviagent.exe uimode=agentupdate [?]
R4 NetWizard Workstation Service;Workstation Agent Service;c:\winnt\SYSTEM\NWIZARD\WINSVC32.EXe [2003-08-12 548864]
R4 PRPC;PRPC;c:\winnt\SYSTEM32\DRIVERS\prpc.sys [2003-08-06 10495]
R4 RAInfo;RAInfo;c:\winnt\SYSTEM\NWIZARD\RCONTR32\TUPES\rainfo.sys [2004-10-14 8192]
R4 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-10-31 95528]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-23 24652]
S3 BDA_Capture_225;USB Digital-TV receiver Driver 2.0.1.8;c:\winnt\SYSTEM32\DRIVERS\BDA_Capture_225.sys [2006-09-22 14592]
S3 BDA_Loader_225;USB Digital-TV Receiver Firmware Loader 6.5.8.0;c:\winnt\SYSTEM32\DRIVERS\BDA_Loader_225.sys [2006-09-22 18944]
S3 BrUsbMdm;Brother MFC USB FaxModem driver;c:\winnt\SYSTEM32\DRIVERS\BrUsbMdm.sys [2005-07-08 10908]
S3 BrUsbScn;Brother MFC USB Scanner driver;c:\winnt\SYSTEM32\DRIVERS\BrUsbScn.sys [2005-07-08 10908]
S3 cirrus;cirrus;c:\winnt\SYSTEM32\DRIVERS\CIRRUS.SYS [1999-10-08 45744]
S3 CpqDtct;CpqDtct;\??\c:\winnt\System32\Drivers\Cpqdtct.sys --> c:\winnt\System32\Drivers\Cpqdtct.sys [?]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\winnt\SYSTEM32\DRIVERS\e4usbaw.sys [2007-07-19 114616]
S3 FBIKB_NT;FBIKB_NT;\??\c:\winnt\System32\Drivers\FBIKB_NT.Sys --> c:\winnt\System32\Drivers\FBIKB_NT.Sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\winnt\SYSTEM32\DRIVERS\gflmouhid.sys [2004-07-26 6528]
S3 InputPen;USB Input Pen;c:\winnt\SYSTEM32\DRIVERS\InputPen2K.sys [2003-08-30 14365]
S3 MR97310_VGA_DUAL_CAMERA;Dual-Mode Digital Camera;c:\winnt\SYSTEM32\DRIVERS\MR97310v.sys [2008-05-03 116126]
S3 N100;Compaq Ethernet or Fast Ethernet NIC NT Driver;c:\winnt\SYSTEM32\DRIVERS\N100NT5.SYS [1999-10-27 87824]
S3 ncp2;ncp2;c:\winnt\SYSTEM32\DRIVERS\ncp2.sys [2004-02-10 40741]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" --> c:\program files\Symantec AntiVirus\SavRoam.exe [?]
S3 usb_rndisy;USB RNDIS Adapter;c:\winnt\SYSTEM32\DRIVERS\usb8023y.sys [2006-03-08 14336]
S3 wldel48;TrueMobile 1150 Series Driver;c:\winnt\SYSTEM32\DRIVERS\wldel48.sys [2004-11-24 78913]
S4 CpqDfwWebAgent;Compaq Remote Diagnostics Enabling Agent;c:\winnt\Cpqdiag\Cpqdfwag.exe --> c:\winnt\Cpqdiag\Cpqdfwag.exe [?]
S4 cpqdiag;Compaq Diagnostics Driver;\??\c:\winnt\System32\drivers\cpqdiag.sys --> c:\winnt\System32\drivers\cpqdiag.sys [?]
S4 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\winnt\SYSTEM32\DRIVERS\e4ldr.sys [2007-07-19 63555]
S4 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-10-31 1365288]
S4 SSPORT;SSPORT;\??\c:\winnt\system32\Drivers\SSPORT.sys --> c:\winnt\system32\Drivers\SSPORT.sys [?]
S4 TimeServ;Time Service;c:\winnt\system32\timeserv.exe --> c:\winnt\system32\timeserv.exe [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - PROCEXP100
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [29/08/07 13:57 ]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ch/
uInternet Settings,ProxyOverride = 127.0.0.1;*.bec.ch;*.extrabec.*;*.rservices.com;*.sandoz*.ch;*.bec*.ch;10.100.20.1;10.100.60.*;10.60.50.*;<local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: %SystemRoot%\system32\msafd.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} - hxxp://www.meetstream.com/activex/28081/activeid.cab
FF - ProfilePath - c:\documents and settings\pdf.W2KGE014\Application Data\Mozilla\Firefox\Profiles\388vkzg1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - PONS Französisch ⇆ Deutsch
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ch/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPunyte.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
.
------- File Associations -------
.
VBSFile=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 18:57:29
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Le Petit Robert Hyperappel = c:\program files\Le Robert\Le Petit Robert\prhyper.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
c:\winnt\system32\Perflib_Perfdata_6f8.dat 16384 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(216)
c:\winnt\system32\wzcdlg.dll
c:\winnt\system32\WZCSAPI.DLL
c:\winnt\system32\WcesWlgn.dll
.
Completion time: 20/01/2009 19:02:34
ComboFix-quarantined-files.txt 2009-01-20 18:01:00
Pre-Run: 16,040,980,992 bytes free
Post-Run: 16,042,334,208 bytes free
187 --- E O F --- 2009-01-14 11:31:12