RE RE Salut Jacques,
Tu as raisons, j'ai toujours parlé de Blaster car ce sont les mêmes caractéristiques, mais je commence sérieusement à penser que c'est soit une version plus évolué de Blaster, soit un tout autre virus ou simplement une erreur systeme... n'empêche que c'est très corriace!!
A noté qu'au tout début de l'apparition du virus mon PC redémarré environ 3 fois de suite puis ensuite le virus n'apparaissait plus... jusqu'a ce que je l'étteigne puis le redemarre et ainsi de suite... mais maintenant il est tout le temps présent.
donc j'ai fait ce dont tu m'as demander avec "Combofix", voici le rapport, a noter que le problème est toujours présent:
ComboFix 09-05-14.03 - Administrateur 04/04/2008 6:12.1 - NTFSx86
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\install.exe
c:\install\install.exe
c:\windows\system32\tmp69.tmp
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-03-04 au 2008-04-04 ))))))))))))))))))))))))))))))))))))
.
2009-05-12 16:17 . 2009-05-06 08:13 -------- d-----w c:\windows\BDOSCAN8
2009-05-12 12:45 . 2009-05-12 12:45 664 ----a-w c:\windows\system32\d3d9caps.dat
2009-05-12 07:14 . 2009-05-12 07:14 138184 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-05-12 07:14 . 2009-05-12 07:14 183112 ----a-w c:\windows\system32\PnkBstrB.exe
2009-05-12 07:14 . 2009-05-12 07:14 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-05-11 11:38 . 2009-05-11 11:38 -------- d-----w c:\program files\directx
2009-05-11 11:35 . 2009-05-11 11:35 -------- d-----w c:\program files\Digitalo Studios
2009-05-11 11:10 . 1996-11-06 10:04 302592 ----a-w c:\windows\unin040c.exe
2009-05-11 11:07 . 1996-11-05 14:13 299008 ----a-w c:\windows\uninst.exe
2009-05-11 06:45 . 2009-05-11 06:46 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-11 06:45 . 2009-05-11 11:00 -------- d-----w c:\program files\Trojan Remover
2009-05-11 06:24 . 2008-04-08 09:34 -------- d-----w C:\HiJackThis
2009-05-10 22:57 . 2009-05-10 22:57 -------- d-----w c:\program files\NovaLogic
2009-05-06 16:11 . 2009-05-06 16:11 -------- d-----w c:\program files\EA Sports
2009-05-05 19:24 . 2009-05-05 19:24 -------- d-----w c:\program files\DelphineSoft
2009-05-04 17:12 . 2009-05-04 17:12 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Gearbox Software
2009-05-01 16:12 . 2009-05-01 16:12 -------- d-----w c:\program files\Micro Application
2009-04-23 17:24 . 2009-04-23 17:28 -------- d-----w c:\program files\Flatout 2
2009-04-18 20:33 . 2009-04-18 20:33 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\FlatOut Ultimate Carnage
2009-04-18 20:31 . 2009-04-18 20:31 -------- d-----w c:\windows\system32\xlive
2009-04-18 20:28 . 2009-04-18 20:28 -------- d-----w c:\program files\Empire Interactive
2009-04-18 20:20 . 2009-04-18 20:20 -------- d-----w c:\documents and settings\Administrateur\Application Data\Red Alert 3
2009-04-18 20:17 . 2009-04-18 20:17 -------- d--h--r c:\documents and settings\Administrateur\Application Data\SecuROM
2009-04-18 20:13 . 2009-04-18 20:13 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Criterion Games
2009-04-18 19:59 . 2009-04-18 19:59 -------- d-----w C:\ProgramData
2009-04-18 18:38 . 2009-04-18 18:38 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Downloaded Installations
2009-04-18 15:25 . 2009-04-18 15:25 32293 ----a-w c:\windows\scunin.dat
2009-04-18 15:25 . 2009-04-18 15:25 967 ----a-w c:\windows\ScUnin.pif
2009-04-18 15:25 . 2009-04-18 15:25 69632 ----a-w c:\windows\ScUnin.exe
2009-04-18 15:13 . 2009-04-18 17:05 -------- d-----w C:\UT2004
2009-04-18 14:58 . 2009-04-18 14:58 -------- d-----w c:\program files\SuperCopier2
2009-04-18 14:54 . 2009-04-18 15:00 -------- d-----w c:\program files\Left4Dead
2009-04-14 15:58 . 2009-04-29 18:30 -------- d-----w c:\program files\Valve
2009-04-08 17:30 . 2009-04-08 17:30 165376 ----a-w c:\windows\system32\drivers\atksgt.sys
2009-04-08 17:30 . 2009-04-08 17:30 18048 ----a-w c:\windows\system32\drivers\lirsgt.sys
2009-03-31 18:39 . 2009-05-04 12:30 -------- d-----w c:\program files\Préinstallé
2009-03-31 17:34 . 2009-03-31 17:34 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Activision
2009-03-31 17:33 . 2008-05-30 12:17 65032 ----a-w c:\windows\system32\XAPOFX1_0.dll
2009-03-31 17:33 . 2008-05-30 12:19 507400 ----a-w c:\windows\system32\XAudio2_1.dll
2009-03-31 17:33 . 2008-05-30 12:18 238088 ----a-w c:\windows\system32\xactengine3_1.dll
2009-03-31 17:33 . 2008-05-30 12:17 25608 ----a-w c:\windows\system32\X3DAudio1_4.dll
2009-03-31 17:23 . 2009-04-18 21:35 -------- d-----w c:\program files\Activision
2009-03-31 17:00 . 2009-03-31 17:00 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-31 16:44 . 2009-03-31 16:44 -------- d-----w c:\program files\CCleaner
2009-03-30 20:45 . 2009-03-30 20:45 -------- d-----w c:\documents and settings\All Users\Application Data\2DBoy
2009-03-30 20:45 . 2009-03-30 20:45 -------- d-----w c:\program files\WorldOfGoo
2009-03-30 20:28 . 2009-03-30 20:28 -------- d-----w c:\windows\system32\AGEIA
2009-03-26 18:58 . 2009-03-31 17:07 -------- d-----w c:\program files\Serious Sam 2
2009-03-26 18:42 . 2009-03-28 12:56 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\GameSpy
2009-03-26 18:42 . 2009-03-26 18:42 137 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
2009-03-26 18:42 . 2009-03-28 12:55 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\ApplicationHistory
2009-03-25 22:27 . 2009-03-25 22:49 -------- d-----w c:\program files\Far Cry
2009-03-25 22:12 . 2009-03-25 22:12 -------- d-----w c:\windows\system32\URTTEMP
2009-03-25 22:12 . 2009-04-19 01:06 22328 ----a-w c:\documents and settings\Administrateur\Application Data\PnkBstrK.sys
2009-03-25 22:07 . 2009-03-26 18:41 -------- d-----w c:\windows\SxsCaPendDel
2009-03-25 21:25 . 2009-04-18 15:26 -------- d-----w c:\program files\Starcraft
2009-03-25 21:14 . 2009-03-25 21:22 -------- d-----w c:\program files\Nina - Agent Chronicles
2009-03-25 20:30 . 2009-05-04 17:11 1584 ----a-w c:\windows\eReg.dat
2009-03-25 19:31 . 2009-03-25 19:31 -------- d-----w C:\rc
2009-03-25 19:16 . 2001-05-16 16:54 309616 ----a-w c:\windows\system32\wmv8dmod.dll
2009-03-25 19:16 . 2001-05-11 12:18 420240 ----a-w c:\windows\system32\mpg4c32.dll
2009-03-25 19:03 . 2009-04-19 01:02 -------- d-----w c:\program files\Ubisoft
2009-03-25 18:54 . 2009-03-25 18:54 -------- d-----w c:\program files\City Interactive
2009-03-24 20:41 . 2006-08-30 06:10 158456 ------w c:\windows\system32\pxwma.dll
2009-03-24 20:40 . 2009-03-24 20:48 -------- d-----w c:\program files\muvee Technologies
2009-03-24 20:40 . 2009-03-24 20:40 -------- d-----w c:\program files\Fichiers communs\muvee Technologies
2009-03-24 20:40 . 2009-03-24 20:40 -------- d-----w c:\documents and settings\All Users\Application Data\muvee Technologies
2009-03-24 20:38 . 2008-07-09 22:19 103424 ----a-w c:\windows\system32\bzDCT.dll
2009-03-24 20:38 . 2008-10-30 21:15 227840 ----a-w c:\windows\system32\bzFlRdr.dll
2009-03-24 20:38 . 2008-09-26 18:44 126976 ----a-w c:\windows\system32\bzpdfc.dll
2009-03-24 20:38 . 2008-09-05 04:29 193024 ----a-w c:\windows\system32\bzpdf.dll
2009-03-24 20:38 . 2005-09-07 23:03 86728 ----a-w c:\windows\system32\msxml6r.dll
2009-03-24 20:38 . 2005-09-07 23:03 1330888 ----a-w c:\windows\system32\msxml6.dll
2009-03-24 20:38 . 2009-03-24 20:38 -------- d-----w c:\program files\Bullzip
2009-03-24 20:33 . 2003-06-18 16:31 17920 ----a-w c:\windows\system32\mdimon.dll
2009-03-24 20:32 . 2009-03-24 20:32 -------- d-----w c:\program files\Microsoft ActiveSync
2009-03-24 20:32 . 2009-03-24 20:32 -------- d-----w c:\windows\SHELLNEW
2009-03-24 20:30 . 2009-03-24 20:30 -------- d-----w c:\program files\Microsoft.NET
2009-03-24 20:30 . 2009-03-24 20:30 -------- d--h--r C:\MSOCache
2009-03-04 21:02 . 2009-03-04 21:02 -------- d-----w c:\documents and settings\All Users\Application Data\ScanSoft
2009-02-22 20:49 . 2009-02-22 20:49 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Google
2009-02-22 20:49 . 2006-10-05 02:42 2432 ------w c:\windows\system32\drivers\cdr4_xp.sys
2009-02-22 20:49 . 2006-10-05 02:42 2560 ------w c:\windows\system32\drivers\cdralw2k.sys
2009-02-22 20:49 . 2009-02-22 20:49 -------- d-----w c:\windows\system32\IOSUBSYS
2009-02-22 20:49 . 2009-02-22 20:49 -------- d-----w c:\program files\Google
2009-02-22 20:49 . 2009-02-22 20:49 -------- d-----w c:\program files\Picasa2
2009-02-22 20:43 . 2001-08-23 16:47 5632 ----a-w c:\windows\system32\ptpusb.dll
2009-02-22 20:43 . 2004-08-03 23:54 159232 ----a-w c:\windows\system32\ptpusd.dll
2009-02-09 21:09 . 2009-05-11 11:18 -------- d-----w c:\program files\Electronic Arts
2009-02-09 17:52 . 2009-02-09 17:52 -------- d-----w c:\program files\sierra
2009-02-09 17:40 . 2009-02-09 17:40 -------- d-----w c:\documents and settings\All Users\Application Data\NFS Underground
2009-02-09 17:19 . 2009-02-09 17:21 -------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
2009-02-09 17:14 . 2009-02-09 17:17 -------- d-----w c:\program files\TmUnitedForever
2009-02-08 22:53 . 2009-05-11 16:48 -------- d-----w C:\Image CD DVD
2009-02-08 22:39 . 2009-02-26 17:50 -------- d-----w c:\program files\Microsoft Games
2009-02-08 22:13 . 2009-02-21 21:38 -------- d-----w c:\documents and settings\All Users\Application Data\Test Drive Unlimited
2009-02-08 22:02 . 2009-02-08 22:02 -------- d-----w c:\program files\Elaborate Bytes
2009-02-07 19:45 . 2009-02-07 19:45 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Codemasters
2009-02-07 18:08 . 2009-02-07 18:08 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Identities
2009-02-07 18:03 . 2004-08-03 23:54 21504 -c--a-w c:\windows\system32\dllcache\hidserv.dll
2009-02-07 18:03 . 2004-08-03 23:54 21504 ----a-w c:\windows\system32\hidserv.dll
2009-02-07 18:03 . 2004-08-03 23:45 14848 -c--a-w c:\windows\system32\dllcache\kbdhid.sys
2009-02-07 18:03 . 2004-08-03 23:45 14848 ----a-w c:\windows\system32\drivers\kbdhid.sys
2009-02-03 20:35 . 2009-02-03 20:35 -------- d-----w c:\program files\Eidos
2009-02-03 17:59 . 2009-03-24 19:15 -------- d-----w c:\documents and settings\Administrateur\Application Data\AdobeUM
2009-02-03 17:59 . 2009-02-03 17:59 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Adobe
2009-02-03 17:59 . 2009-02-03 17:59 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-02-03 17:54 . 2009-02-03 17:54 -------- d-----w c:\program files\RivaTuner v2.22
2009-02-03 17:52 . 2009-02-03 17:52 -------- d-----w c:\documents and settings\All Users\Application Data\ATI
2009-02-03 17:50 . 2009-02-07 18:45 -------- d-----w c:\program files\ATI
2009-02-03 17:47 . 2009-02-03 17:47 -------- d-----w C:\ATI
2009-02-03 17:42 . 2009-02-03 17:42 -------- d--h--w c:\windows\PIF
2009-02-03 17:26 . 2001-08-17 20:56 7552 -c--a-w c:\windows\system32\dllcache\sonypvu1.sys
2009-02-03 17:26 . 2001-08-17 20:56 7552 ----a-w c:\windows\system32\drivers\SONYPVU1.SYS
2009-01-31 15:00 . 2009-01-31 15:00 -------- d-----w c:\documents and settings\Administrateur\Application Data\vlc
2009-01-31 14:53 . 2009-01-31 14:53 -------- d--h--w C:\BJPrinter
2009-01-31 14:53 . 2004-08-16 20:00 7680 ----a-w c:\windows\system32\CNMVS6f.DLL
2009-01-31 14:53 . 2004-08-16 20:00 116736 ----a-w c:\windows\system32\CNMLM6f.DLL
2009-01-31 14:52 . 2004-08-03 21:58 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-01-31 14:52 . 2004-08-03 21:58 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-01-31 14:50 . 2009-01-31 14:50 -------- d-----w c:\documents and settings\Administrateur\Application Data\ScanSoft
2009-01-31 14:50 . 2009-03-04 20:58 -------- d-----w c:\documents and settings\All Users\Application Data\SSScanWizard
2009-01-31 14:50 . 2009-03-04 20:58 -------- d-----w c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-01-31 14:50 . 2009-01-31 14:50 -------- d-----w c:\program files\Fichiers communs\ScanSoft Shared
2009-01-31 14:50 . 2009-01-31 14:50 -------- d-----w c:\program files\ScanSoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-11 16:47 . 2009-01-27 17:40 -------- d-----w c:\program files\EA Games
2009-05-11 11:35 . 2009-01-27 16:24 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-06 07:28 . 2009-01-27 16:19 -------- d-----w c:\program files\Kazaa Lite Resurrection
2009-05-01 19:39 . 2009-01-27 16:31 49728 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-31 17:05 . 2009-01-27 17:34 -------- d-----w c:\program files\Alcohol Soft
2009-03-30 20:28 . 2009-03-26 19:04 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-30 20:28 . 2009-03-30 20:28 -------- d-----w c:\program files\AGEIA Technologies
2009-03-30 20:28 . 2009-03-30 20:28 -------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-03-30 19:07 . 2009-03-30 19:07 -------- d-----w c:\program files\Activision Value
2009-03-28 11:04 . 2009-03-28 11:04 -------- d-----w c:\program files\system
2009-03-25 20:42 . 2004-07-17 11:36 12400 ----a-w c:\windows\system32\drivers\secdrv.sys
2009-02-03 17:49 . 2009-01-27 16:24 -------- d-----w c:\program files\ATI Technologies
2009-01-31 14:27 . 2009-01-31 14:27 -------- d-----w c:\program files\Hercules
2009-01-30 22:08 . 2009-01-27 16:24 -------- d-----w c:\program files\Fichiers communs\InstallShield
2009-01-27 17:02 . 2009-01-27 17:02 -------- d-----w c:\program files\Marvell
2009-01-27 17:00 . 2009-01-27 16:59 -------- d-----w c:\program files\ASUS
2009-01-27 16:48 . 2009-01-27 16:48 -------- d-----w c:\program files\Analog Devices
2009-01-27 16:34 . 2009-01-27 16:34 -------- d-----w c:\program files\Intel
2009-01-27 16:30 . 2009-01-27 16:30 0 ----a-w c:\windows\ativpsrm.bin
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\WinISO
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\DVD Shrink
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\Satsuki Decodeur Pack
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\mozilla
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\Java
2009-01-27 16:19 . 2009-01-27 16:19 -------- d-----w c:\program files\Fichiers communs\Java
2009-01-27 16:18 . 2009-01-27 16:18 -------- d-----w c:\program files\Fichiers communs\Ahead
2009-01-27 16:18 . 2009-01-27 16:18 -------- d-----w c:\program files\MSN Messenger
2009-01-27 16:17 . 2009-01-27 16:17 -------- d-----w c:\program files\FlashGet
2009-01-27 16:17 . 2009-01-27 16:17 -------- d-----w c:\program files\eMule
2009-01-27 16:17 . 2009-01-27 16:17 -------- d-----w c:\program files\Azureus
2009-01-27 16:17 . 2009-01-27 16:17 -------- d-----w c:\program files\Lavasoft
2009-01-27 16:13 . 2009-01-27 16:13 -------- d-----w c:\program files\microsoft frontpage
2009-01-27 16:12 . 2009-01-27 16:12 -------- d-----w c:\program files\Services en ligne
2009-01-27 16:11 . 2009-01-27 16:11 21892 ----a-w c:\windows\system32\emptyregdb.dat
2009-01-14 07:14 . 2007-12-18 02:46 3455488 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 05:46 . 2009-01-14 05:46 11591680 ----a-w c:\windows\system32\atioglxx.dll
2009-01-14 04:53 . 2007-12-18 01:08 286720 ----a-w c:\windows\system32\atiok3x2.dll
2009-01-14 04:49 . 2009-01-27 16:24 425984 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-01-14 04:47 . 2007-12-18 01:53 323584 ----a-w c:\windows\system32\ati2dvag.dll
2009-01-14 04:36 . 2007-12-18 01:46 196608 ----a-w c:\windows\system32\atipdlxx.dll
2009-01-14 04:36 . 2007-10-12 05:01 151552 ----a-w c:\windows\system32\Oemdspif.dll
2009-01-14 04:36 . 2007-12-18 01:46 26112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-01-14 04:35 . 2007-12-18 01:46 43520 ----a-w c:\windows\system32\ati2edxx.dll
2009-01-14 04:35 . 2007-12-18 01:45 155648 ----a-w c:\windows\system32\ati2evxx.dll
2009-01-14 04:34 . 2007-12-18 01:44 598016 ----a-w c:\windows\system32\ati2evxx.exe
2009-01-14 04:32 . 2007-12-18 01:43 53248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-01-14 04:22 . 2007-12-18 01:36 4009152 ----a-w c:\windows\system32\ati3duag.dll
2009-01-14 04:05 . 2007-12-18 01:25 2500224 ----a-w c:\windows\system32\ativvaxx.dll
2009-01-14 03:50 . 2007-12-18 01:15 48640 ----a-w c:\windows\system32\amdpcom32.dll
2009-01-14 03:45 . 2007-12-18 01:11 401408 ----a-w c:\windows\system32\atikvmag.dll
2009-01-14 03:44 . 2009-01-14 03:44 110592 ----a-w c:\windows\system32\atiadlxx.dll
2009-01-14 03:44 . 2007-12-18 01:10 17408 ----a-w c:\windows\system32\atitvo32.dll
2009-01-14 03:43 . 2007-12-18 01:07 53248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-01-14 03:37 . 2009-01-27 16:24 307200 ----a-w c:\windows\system32\atiiiexx.dll
2009-01-14 03:37 . 2007-12-18 01:04 577536 ----a-w c:\windows\system32\ati2cqag.dll
2009-01-14 02:36 . 2009-01-14 02:36 45056 ----a-w c:\windows\system32\amdcalrt.dll
2009-01-14 02:36 . 2009-01-14 02:36 45056 ----a-w c:\windows\system32\amdcalcl.dll
2009-01-14 02:34 . 2009-01-14 02:34 3227648 ----a-w c:\windows\system32\Amdcaldd.dll
2009-01-13 20:05 . 2009-01-27 16:25 593920 ------w c:\windows\system32\ati2sgag.exe
2008-10-29 22:13 . 2009-01-27 16:24 180720 ----a-w c:\windows\system32\atiicdxx.dat
2008-10-27 08:04 . 2009-04-18 20:05 514384 ----a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 08:04 . 2009-04-18 20:05 235856 ----a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 08:04 . 2009-04-18 20:05 23376 ----a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-27 08:04 . 2009-04-18 20:05 70992 ----a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-21 18:51 . 2008-10-21 18:51 118784 ----a-w c:\windows\system32\atibrtmon.exe
2008-10-21 17:40 . 2007-08-21 09:51 81920 ----a-w c:\windows\system32\ATIODE.exe
2008-10-21 17:40 . 2007-08-21 07:36 45056 ----a-w c:\windows\system32\ATIODCLI.exe
2008-10-10 02:52 . 2009-04-18 20:05 452440 ----a-w c:\windows\system32\d3dx10_40.dll
2008-10-10 02:52 . 2009-04-18 20:05 4379984 ----a-w c:\windows\system32\D3DX9_40.dll
2008-10-10 02:52 . 2009-04-18 20:05 2036576 ----a-w c:\windows\system32\D3DCompiler_40.dll
2008-09-29 15:43 . 2008-09-29 15:43 84936 ----a-w c:\windows\system32\ElbyVCD.dll
2008-09-24 10:29 . 2008-09-24 10:29 29184 ----a-w c:\windows\system32\drivers\VClone.sys
2008-07-30 04:20 . 2009-04-18 20:05 68616 ----a-w c:\windows\system32\XAPOFX1_1.dll
2008-07-30 04:20 . 2009-04-18 20:05 509448 ----a-w c:\windows\system32\XAudio2_2.dll
2008-07-30 04:20 . 2009-04-18 20:05 238088 ----a-w c:\windows\system32\xactengine3_2.dll
2008-07-21 12:11 . 2008-07-21 12:11 24392 ----a-w c:\windows\system32\drivers\ElbyCDIO.sys
2008-07-10 09:01 . 2009-04-18 20:05 467984 ----a-w c:\windows\system32\d3dx10_39.dll
2008-07-10 09:00 . 2009-04-18 20:05 1493528 ----a-w c:\windows\system32\D3DCompiler_39.dll
2008-07-10 09:00 . 2009-04-18 20:05 3851784 ----a-w c:\windows\system32\D3DX9_39.dll
2008-06-26 11:06 . 2008-06-26 11:06 93128 ----a-w c:\windows\system32\ElbyCDIO.dll
2008-05-30 12:11 . 2009-03-30 18:38 467984 ----a-w c:\windows\system32\d3dx10_38.dll
2008-05-30 12:11 . 2009-03-30 18:38 3850760 ----a-w c:\windows\system32\D3DX9_38.dll
2008-05-30 12:11 . 2009-03-30 18:38 1491992 ----a-w c:\windows\system32\D3DCompiler_38.dll
2008-05-19 07:46 . 2009-01-27 16:56 150568 ----a-r c:\windows\system32\drivers\mv61xx.sys
2008-04-28 14:53 . 2009-01-30 21:58 805400 ----a-r c:\windows\system32\tmp6A.tmp
2008-04-04 04:08 . 2001-08-24 14:00 76780 ----a-w c:\windows\system32\perfc00C.dat
2008-04-04 04:08 . 2001-08-24 14:00 470942 ----a-w c:\windows\system32\perfh00C.dat
2008-03-26 03:15 . 2009-01-27 16:34 53248 ----a-r c:\windows\system32\CSVer.dll
2008-03-24 01:08 . 2009-01-27 16:48 331264 ----a-r c:\windows\system32\drivers\ADIHdAud.sys
2008-03-05 15:03 . 2009-01-27 17:40 479752 ----a-w c:\windows\system32\XAudio2_0.dll
2008-03-05 15:03 . 2009-01-27 17:40 238088 ----a-w c:\windows\system32\xactengine3_0.dll
2008-03-05 15:00 . 2009-01-27 17:40 25608 ----a-w c:\windows\system32\X3DAudio1_3.dll
2008-03-05 14:56 . 2009-01-27 17:40 3786760 ----a-w c:\windows\system32\D3DX9_37.dll
2008-03-05 14:56 . 2009-01-27 17:40 1420824 ----a-w c:\windows\system32\D3DCompiler_37.dll
2008-02-23 02:38 . 2008-02-23 02:38 43872 ------w c:\windows\system32\drivers\pxhelp20.sys
2008-02-05 22:07 . 2009-01-27 17:40 462864 ----a-w c:\windows\system32\d3dx10_37.dll
2008-01-09 13:01 . 2008-01-09 13:01 53248 ----a-w c:\windows\bdoscandel.exe
.
------- Sigcheck -------
[-] 2004-08-18 09:22 359040 27A5959C94EE173A063CA06BD14F021A c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-22 22:35 1036288 998F3F568F6074A35AB08CD3395A9DC2 c:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2008-11-23 203208]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 32881]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-03-16 1040384]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"RivaTuner"="c:\program files\RivaTuner v2.22\RivaTuner.exe" [2008-12-29 2732032]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
ASUS WiFi-AP @n Utility.lnk - c:\program files\ASUS\WiFi-AP @n\WiFi-AP@n.exe [2009-1-27 1224704]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Codemasters\\Turning Point - Fall of Liberty\\Binaries\\LTCG-TPGame.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Atari\\Act of War - High Treason\\ActOfWar_HighTreason.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutLauncher.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutConfigTool.exe"=
"c:\\Program Files\\Electronic Arts\\Burnout(TM) Paradise The Ultimate Box\\BurnoutParadise.exe"=
"c:\\Program Files\\Empire Interactive\\FlatOut Ultimate Carnage\\Fouc.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\DelphineSoft\\Moto Racer 3\\Mr3.exe"=
"c:\\Program Files\\Codemasters\\Race Driver 3\\RD3.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25:TCP"= 25:TCP:File and Printer Sharing
"1590:TCP"= 1590:TCP:egop
"7243:TCP"= 7243:TCP:egop
"5744:TCP"= 5744:TCP:egop
"6528:TCP"= 6528:TCP:egop
"7375:TCP"= 7375:TCP:egop
"5481:TCP"= 5481:TCP:egop
"5671:TCP"= 5671:TCP:egop
"5568:TCP"= 5568:TCP:egop
R0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [2008-05-19 150568]
R2 pr2ah4nc;DiRT Drivers Auto Removal (pr2ah4nc);c:\windows\system32\pr2ah4nc.exe svc [x]
R2 vmmreg;Windows VMM Registry Library;c:\windows\system32\rundll32.exe vmmreg.dll,egop [x]
R3 axskbus;axskbus;c:\windows\system32\DRIVERS\axskbus.sys [x]
R3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [x]
S0 pe3ah4nc;DiRT Environment Driver (pe3ah4nc);c:\windows\system32\drivers\pe3ah4nc.sys [2007-05-18 64880]
S0 ps6ah4nc;DiRT Synchronization Driver (ps6ah4nc);c:\windows\system32\drivers\ps6ah4nc.sys [2007-05-18 55160]
S3 ovt530;Webcam Classic;c:\windows\system32\Drivers\ov530vid.sys [2005-03-15 161792]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys [2007-07-28 517632]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AsIO
*Deregistered* - Aspi32
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - atksgt
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ElbyCDIO
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - HTTP
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - isapnp
*Deregistered* - Kbdclass
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - lirsgt
*Deregistered* - LmHosts
*Deregistered* - mchInjDrv
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - pe3ah4nc
*Deregistered* - PnkBstrA
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - pr2ah4nc
*Deregistered* - prodrv06
*Deregistered* - prohlp02
*Deregistered* - prosync1
*Deregistered* - ProtectedStorage
*Deregistered* - ps6ah4nc
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RivaTuner32
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - Secdrv
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - sfdrv01
*Deregistered* - sfhlp01
*Deregistered* - sfhlp02
*Deregistered* - sfsync02
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - StarWindServiceAE
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - UMWdf
*Deregistered* - Update
*Deregistered* - VClone
*Deregistered* - VgaSave
*Deregistered* - vmmreg
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ecf4bd4-21d8-11de-8ebc-0022157c70fc}]
\Shell\AutoRun\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59865bf6-f230-11dd-8e74-0015af722dfc}]
\Shell\AutoRun\command - I:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be96fd1e-f217-11dd-8e71-0015af722dfc}]
\Shell\AutoRun\command - e:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - e:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f99d49ba-ef9f-11dd-8e6d-0015af722dfc}]
\Shell\AutoRun\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-21CX5C574571}]
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
IE: E&xport to Microsoft Excel - c:\progra~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Tout télécharger avec FlashGet - c:\progra~1\FlashGet\jc_all.htm
IE: Télécharger avec FlashGet - c:\progra~1\FlashGet\jc_link.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-04 06:14
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc21.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1060284298-1844823847-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:55,32,e3,b6,c0,d6,ed,d8,55,f2,f0,c3,3d,34,0b,89,79,82,ca,10,c7,
1b,de,cc,8e,eb,84,bd,0f,80,87,c0,e8,e9,1e,27,b9,d5,fa,55,e8,a7,7d,8f,2a,94,\
"rkeysecu"=hex:80,39,92,b0,cb,48,d6,cf,e8,bd,51,0f,56,2e,11,d5
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(596)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2008-04-04 6:15
ComboFix-quarantined-files.txt 2008-04-04 04:15
Avant-CF: 273 158 782 976 octets libres
Après-CF: 273 152 802 816 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
486
Voilà, bonne lecture, j'aimerais vraiment pouvoir t'aider d'avantage a comprendre mon problème, ce n'est jamais facile sans être devant.
a toute!