- j'ai fait une petite erreur de manip , j'ai relancé involontairement un scan combofix normal avant de faire ce que tu m'a dit ci-dessus , je te joint ce rapport à tout hasard.
- concernant la ligne : F3 - REG:win.ini: load=C:\WINDOWS\System32\drivers\esentutl.exe
que tu me dit de "Fix checked" , elle existe quand je relance hijackthis mais sous cette forme :
F3 - REG:win.ini: load=C:\DOCUME~1\jean\LOCALS~1\APPLIC~1\MICROS~1\mstsc.exe
doit-je faire quand même "Fix checked" ?
- enfin pour la dernière manip que tu me demande (Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) , que veut dire glisser / déposer ?
doit-je cliquer gauche et faire glisser le bloc notes (sous le nom CFScript.txt) sur l'icône C-fix sur mon bureau ?
Désolé pour tout ces détails mais je ne voudrais pas faire de bétises.
Merci pour ta patience.
nouveau rapport combofix
ComboFix 09-03-03.01 - jean 2009-03-05 14:05:14.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1023.684 [GMT 1:00]
Lancé depuis: c:\documents and settings\jean\Bureau\C-fix.exe
AV: avast! antivirus 4.8.1335 [VPS 090305-0] *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-05 au 2009-03-05 ))))))))))))))))))))))))))))))))))))
.
2009-03-03 22:14 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\mqtgsvc.exe
2009-03-03 22:08 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\mstsc.exe
2009-03-03 22:05 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\comrepl.exe
2009-03-03 22:05 . 2009-01-18 16:48 77,824 --a------ c:\windows\rsvp.exe
2009-03-03 22:02 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\comrepl.exe
2009-03-03 21:59 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\cmstp.exe
2009-03-03 21:57 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\ieudinit.exe
2009-03-03 21:54 . 2009-01-18 16:48 77,824 --a------ c:\windows\sessmgr.exe
2009-03-03 21:52 . 2009-01-18 16:48 77,824 --a------ c:\windows\logman.exe
2009-03-03 21:51 . 2009-01-18 16:48 77,824 --a------ c:\documents and settings\Sandrine 2\Application Data\cmstp.exe
2009-03-03 21:50 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\cisvc.exe
2009-03-03 21:50 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\cmstp.exe
2009-03-03 21:48 . 2009-01-18 16:48 77,824 --a------ c:\windows\mqtgsvc.exe
2009-03-03 21:48 . 2009-01-18 16:48 77,824 --a------ c:\documents and settings\Sandrine 2\Application Data\mstsc.exe
2009-03-03 21:47 . 2009-01-18 16:48 77,824 --a------ c:\documents and settings\Sandrine 2\Application Data\sessmgr.exe
2009-03-03 21:46 . 2009-01-18 16:48 77,824 --a------ c:\documents and settings\Sandrine 2\Application Data\mqtgsvc.exe
2009-03-03 21:45 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\sessmgr.exe
2009-03-03 21:45 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\mstinit.exe
2009-03-03 21:44 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\dllhst3g.exe
2009-03-03 21:43 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\esentutl.exe
2009-03-03 21:43 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\clipsrv.exe
2009-03-03 21:42 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\ieudinit.exe
2009-03-03 21:42 . 2009-01-18 16:48 77,824 --a------ c:\windows\mstinit.exe
2009-03-03 21:41 . 2009-01-18 16:48 77,824 --a------ c:\documents and settings\Sandrine 2\Application Data\mstinit.exe
2009-03-03 21:40 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\mstinit.exe
2009-03-03 21:40 . 2009-01-18 16:48 77,824 --a------ c:\windows\comrepl.exe
2009-03-03 21:40 . 2009-01-18 16:48 77,824 --a------ c:\windows\cmstp.exe
2009-03-03 21:39 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\logman.exe
2009-03-03 21:38 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\rsvp.exe
2009-03-03 21:38 . 2009-01-18 16:48 77,824 --a------ c:\windows\ieudinit.exe
2009-03-03 21:03 . 2009-03-03 21:03 <REP> d-------- c:\documents and settings\jean\Application Data\Malwarebytes
2009-03-03 21:03 . 2009-03-03 21:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-03 21:03 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-03 21:03 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-03 20:09 . 2009-03-03 20:59 <REP> d-------- C:\Lop SD
2009-03-03 15:16 . 2009-03-03 20:07 <REP> d-------- c:\program files\Navilog1
2009-03-02 17:45 . 2009-03-02 17:45 <REP> d-------- c:\documents and settings\jean\Application Data\Desktopicon
2009-02-27 14:05 . 2009-02-27 14:59 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-22 15:33 . 2009-02-22 15:33 <REP> d-------- c:\documents and settings\Sandrine 2\Application Data\Avant Profiles
2009-02-22 15:31 . 2009-02-22 15:32 <REP> d-------- c:\documents and settings\Sandrine 2\Contacts
2009-02-20 20:43 . 2009-02-22 15:48 <REP> dr------- c:\documents and settings\Sandrine 2\Mes documents
2009-02-20 20:41 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Sandrine 2\Voisinage réseau
2009-02-20 20:41 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Sandrine 2\Voisinage d'impression
2009-02-20 20:41 . 2007-05-18 16:40 <REP> d--h----- c:\documents and settings\Sandrine 2\Modèles
2009-02-20 20:41 . 2007-05-18 23:32 <REP> dr------- c:\documents and settings\Sandrine 2\Menu Démarrer
2009-02-20 20:41 . 2009-02-20 20:42 <REP> dr------- c:\documents and settings\Sandrine 2\Favoris
2009-02-20 20:41 . 2007-05-18 23:32 <REP> d-------- c:\documents and settings\Sandrine 2\Bureau
2009-02-20 20:41 . 2009-03-03 22:43 <REP> d-------- c:\documents and settings\Sandrine 2
2009-02-18 21:43 . 2009-02-18 21:44 <REP> d-------- c:\documents and settings\SanD\Contacts
2009-02-18 09:46 . 2009-01-18 16:48 77,824 --a------ c:\windows\system\logman.exe
2009-02-18 09:27 . 2009-01-18 16:48 77,824 --a------ c:\windows\system32\drivers\clipsrv.exe
2009-02-18 09:26 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\SanD\Voisinage réseau
2009-02-18 09:26 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\SanD\Voisinage d'impression
2009-02-18 09:26 . 2007-05-18 16:40 <REP> d--h----- c:\documents and settings\SanD\Modèles
2009-02-18 09:26 . 2009-02-19 21:01 <REP> dr------- c:\documents and settings\SanD\Mes documents
2009-02-18 09:26 . 2007-05-18 23:32 <REP> dr------- c:\documents and settings\SanD\Menu Démarrer
2009-02-18 09:26 . 2009-02-18 09:27 <REP> dr------- c:\documents and settings\SanD\Favoris
2009-02-18 09:26 . 2007-05-18 23:32 <REP> d-------- c:\documents and settings\SanD\Bureau
2009-02-18 09:26 . 2009-02-19 22:40 <REP> d-------- c:\documents and settings\SanD
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Invité\Voisinage réseau
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Invité\Voisinage réseau
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Invité\Voisinage d'impression
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d--h----- c:\documents and settings\Invité\Voisinage d'impression
2009-02-17 22:59 . 2007-05-18 16:40 <REP> d--h----- c:\documents and settings\Invité\Modèles
2009-02-17 22:59 . 2007-05-18 16:40 <REP> d--h----- c:\documents and settings\Invité\Modèles
2009-02-17 22:59 . 2009-02-17 22:59 <REP> dr------- c:\documents and settings\Invité\Mes documents
2009-02-17 22:59 . 2009-02-17 22:59 <REP> dr------- c:\documents and settings\Invité\Mes documents
2009-02-17 22:59 . 2007-05-18 23:32 <REP> dr------- c:\documents and settings\Invité\Menu Démarrer
2009-02-17 22:59 . 2007-05-18 23:32 <REP> dr------- c:\documents and settings\Invité\Menu Démarrer
2009-02-17 22:59 . 2009-02-17 22:59 <REP> dr------- c:\documents and settings\Invité\Favoris
2009-02-17 22:59 . 2009-02-17 22:59 <REP> dr------- c:\documents and settings\Invité\Favoris
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d-------- c:\documents and settings\Invité\Bureau
2009-02-17 22:59 . 2007-05-18 23:32 <REP> d-------- c:\documents and settings\Invité\Bureau
2009-02-17 22:59 . 2009-02-17 22:59 <REP> d-------- c:\documents and settings\Invité
2009-02-13 18:40 . 2009-02-13 18:40 <REP> d-------- c:\program files\Trend Micro
2009-02-12 12:19 . 2009-01-18 16:48 77,824 --a------ c:\windows\cisvc.exe
2009-02-11 18:29 . 2009-02-11 18:29 498 --a------ c:\windows\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-11 17:27 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-03 15:16 --------- d-----w c:\program files\IncrediMail
2009-01-21 17:30 --------- d-----w c:\documents and settings\jean\Application Data\Vidalia
2009-01-21 17:30 --------- d-----w c:\documents and settings\jean\Application Data\tor
2009-01-18 15:48 77,824 ----a-w c:\windows\system32\drivers\esentutl.exe
2009-01-16 12:50 --------- d-----w c:\documents and settings\jean\Application Data\LimeWire
2009-01-14 21:37 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Corporation
2009-01-08 12:32 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-08 12:32 --------- d-----w c:\program files\Java
2009-01-06 19:15 --------- d-----w c:\program files\K-Lite Codec Pack
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-12 21:47 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-12 10:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 10:11 61,440 ----a-w c:\windows\system32\dnssd.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_17.05.59.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 11:05:34 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_378.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2007-04-11 462892]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-10 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-20 15360]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-01-27 251264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-08 136600]
"RoxioEngineUtility"="c:\program files\Fichiers communs\Roxio Shared\System\EngUtil.exe" [2003-02-27 69632]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-02-27 757760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2008-11-20 290088]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SoundMan"="SOUNDMAN.EXE" [2006-03-02 c:\windows\soundman.exe]
"nwiz"="nwiz.exe" [2007-04-19 c:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-20 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"MqtgSVC"="c:\docume~1\jean\LOCALS~1\APPLIC~1\MICROS~1\mqtgsvc.exe" [2009-01-18 77824]
"rsvp"="c:\windows\System32\drivers\rsvp.exe" [2009-01-18 77824]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"rsvp"="c:\docume~1\jean\APPLIC~1\MICROS~1\rsvp.exe" [2009-01-18 77824]
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Cisvc"="c:\docume~1\jean\APPLIC~1\MICROS~1\cisvc.exe" [2009-01-18 77824]
"Spool"="c:\docume~1\SANDRI~1\LOCALS~1\APPLIC~1\MICROS~1\spoolsv.exe" [2009-01-18 77824]
"Logman"="c:\windows\System\logman.exe" [2009-01-18 77824]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\MSI\BToes Logiciel Bluetooth\BTTray.exe [2005-03-29 569405]
Privoxy.lnk - c:\program files\Vidalia Bundle\Privoxy\privoxy.exe [2006-11-20 250368]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=c:\docume~1\jean\LOCALS~1\Temp\cmstp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll
"vidc.ffds"= d:\combin~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Avant Browser\\avant.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"d:\\adslTV+vlc\\adsltv.exe"=
"d:\\adslTV+vlc\\vlc.exe"=
"d:\\TVUPlayer\\TVUPlayer.exe"=
"d:\\SopCast\\adv\\SopAdver.exe"=
"d:\\SopCast\\SopCast.exe"=
"d:\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"d:\\itunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"d:\\eMule\\emule.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-27 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-27 20560]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [2007-05-18 6369]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f325363-b0b8-11dd-b092-001966128575}]
\Shell\AutoRun\command - I:\OIF_rapport_2008.exe
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
IE: Bloquer cette publicité... - d:\avant browser\AddToADBlackList.htm
IE: Bloquer toutes les publicités de ce site... - d:\avant browser\AddAllToADBlackList.htm
IE: Ouvrir dans une nouvelle fenêtre... - d:\avant browser\OpenInNewBrowser.htm
IE: Ouvrir des liens de la page... - d:\avant browser\OpenAllLinks.htm
IE: Rechercher sur le Web - d:\avant browser\Search.htm
IE: Surligner toutes les occurrences sur la page - d:\avant browser\Highlight.htm
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
FF - ProfilePath - c:\documents and settings\jean\Application Data\Mozilla\Firefox\Profiles\bhyf7ftj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - MyStart Rechercher
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 14:07:23
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-03-05 14:08:58
ComboFix-quarantined-files.txt 2009-03-05 13:08:56
ComboFix2.txt 2009-03-04 16:07:07
Avant-CF: 34 180 120 576 octets libres
Après-CF: 34,404,913,152 octets libres
215 --- E O F --- 2009-02-25 21:59:56