Salut jlpjlp,
Il est tard, et ce n'est pas faute d'avoir posé mes fesses devant mon ordi plus tôt: voilà 1h30 que je me démène pour que l'ordi s'allume presque normalement et pouvoir me connecter à internet et appliquer tes demandesMais bref, l'important c'est d'y être. :)
J'ai suivi tes conseils pour Hijackthis, et Combofix. Voici le rapport de ce dernier.
ComboFix 08-03-04.3 - Khalid 2008-03-04 22:54:16.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6000.0.1252.1.1036.18.295 [GMT 1:00]
Endroit: C:\Users\Khalid\Desktop\KillBagle.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-04 to 2008-03-04 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 21:45 --------- d-----w C:\ProgramData\Symantec
2008-03-04 18:56 --------- d-----w C:\Users\Khalid\AppData\Roaming\Skype
2008-03-04 04:55 --------- d-----w C:\Users\Khalid\AppData\Roaming\Azureus
2008-03-03 22:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-03 22:32 177,390,110 ----a-w C:\Windows\System32\ma base de registre de mars 2008.reg
2008-03-03 20:42 --------- d-----w C:\Users\Khalid\AppData\Roaming\Grisoft
2008-03-03 20:28 --------- d-----w C:\ProgramData\Grisoft
2008-03-03 20:06 --------- d-----w C:\Program Files\Trend Micro
2008-03-02 16:27 --------- d-----w C:\Program Files\MediaCoder
2008-03-02 11:49 --------- d-----w C:\Program Files\Panda Security
2008-03-01 21:07 --------- d-----w C:\Program Files\Mininova
2008-03-01 21:07 --------- d-----w C:\Program Files\Conduit
2008-03-01 16:40 --------- d-----w C:\Users\Khalid\AppData\Roaming\Symantec
2008-03-01 16:36 --------- d-----w C:\ProgramData\Symantec Temporary Files
2008-02-23 18:09 --------- d-----w C:\Program Files\Winamp
2008-02-23 18:07 --------- d-----w C:\Users\Khalid\AppData\Roaming\Winamp
2008-02-13 19:05 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 19:05 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-13 18:58 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-13 18:58 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-13 18:58 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 18:58 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 18:58 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 18:58 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 18:58 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-13 18:58 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-13 18:58 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 18:58 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-13 18:58 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-13 18:58 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-13 18:57 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 18:57 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 18:57 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 18:57 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 18:57 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 18:57 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-13 18:52 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-13 18:52 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 18:51 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-13 18:51 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-01-27 13:27 --------- d-----w C:\Users\Khalid\AppData\Roaming\CyberLink
2008-01-27 13:14 2,560 ------w C:\Windows\system32\drivers\cdralw2k.sys
2008-01-27 13:14 2,432 ------w C:\Windows\system32\drivers\cdr4_xp.sys
2008-01-27 13:14 158,456 ------w C:\Windows\System32\pxwma.dll
2008-01-26 22:02 --------- d-----w C:\Program Files\Common Files\xing shared
2008-01-26 22:02 --------- d-----w C:\Program Files\Common Files\Real
2008-01-21 12:16 --------- d-----w C:\Program Files\Norton 360
2008-01-19 02:02 --------- d-----w C:\Program Files\Windows Mail
2008-01-15 08:54 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-01-15 04:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-01-12 17:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-01-09 19:23 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-08 21:25 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-08 21:25 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-08 21:25 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2007-12-12 22:58 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 22:58 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 22:58 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-08-31 05:25 174 --sha-w C:\Program Files\desktop.ini
2007-08-16 14:26 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-08-16 14:26 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-08-16 14:26 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-08 22:25 1232896]
"????r"="" []
"?????????"="??????????????e" []
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-27 01:01 32768]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-06-09 20:43 171448]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-02-22 22:31 25388584]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:34 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-11 23:21 1006264]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 17:12 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Empowering Technology Monitor"="C:\Windows\system32\SysMonitor.exe" [2006-11-23 15:24 319488]
"Acer Tour"="" []
"eRecoveryService"="" []
"PCMService"="C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe" [2006-11-25 01:57 151552]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
"iHP-100"="C:\Program Files\iRiver\HSeries\iHPDetect.exe" [2004-07-05 14:50 24576]
"USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 20:44 65536]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22 517768]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-05-17 10:52 505368]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-05-17 10:53 780312]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-26 23:01 185896]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
C:\Users\Khalid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
HotSync Manager.lnk - C:\Program Files\palmOne\HOTSYNC.EXE [2004-04-12 21:38:32 299008]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-09-17 15:25:49 1183744]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-15 12:59:45 528384]
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 00:06:58 28672]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-02-27 01:01:58 450560]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-02-27 00:57:27 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3D7FB22F-99DB-4524-ACFF-19B11C5AF818}"= UDP:C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{3133F0F7-30A4-4875-9C3D-A89F266ACE64}"= TCP:C:\Acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{1B5F55AA-DC07-4594-A01A-1069A13944BE}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{21BAA4E3-7695-4099-9D21-8933E6983FE2}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{E427861B-161B-4A0F-948B-FC004DF3DD19}"= Disabled:UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{4B325AFD-C08C-47BE-A505-78D6FD8ECAD6}"= Disabled:TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{B1DCE408-C40D-4CFE-A400-7F734586B5D9}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{7DE36F32-4210-4712-AAFA-7086EF9AA32D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{1D719D62-5E42-46AC-A617-A12E21200D5D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{387202B2-5A6C-423F-BFD0-2E93C59490D7}"= UDP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{C3848389-326D-4CED-86EB-2C42D132CF78}"= TCP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{D1A29683-FDD2-431F-A718-49AA93C01C26}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{55EDE63D-F50E-4EA1-B45B-94E5B62C8647}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{3EA1634C-B4A3-40CE-9FC8-E3703C6DF328}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-08-24 12:32]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\Windows\system32\drivers\sfsync03.sys [2005-12-06 16:11]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080227.001\IDSvix86.sys [2008-02-13 17:18]
R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-24 14:46]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-01-09 23:32]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 02:52]
S0 AFS;AFS;C:\Windows\system32\drivers\AFS.sys [2007-08-03 21:29]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 16:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4154ac48-d5ae-11dc-8648-00030d000001}]
\shell\AutoRun\command - J:\InstallTomTomHOME.exe
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-04 22:59:24
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-04 23:01:25
.
2008-02-29 20:42:53 --- E O F ---
Merci bien mex!
ps: que puis je faire pour que mon ordi ne se bloque pas littéralement lorsque Windows démarre? Un écran bleu apparait soudainement, avec texte parlant de dumpping et des chiffres qui défilent en pourcentage pour finir par se bloquer et ne plus répondre ni au reset ni au power on/of. Je suis obligé de débrancher le courant. Et parfois, quand je remets la prise de courant, la tour fait des biiiiip biiiiip sans arrêt et rien à l'écran. Obligé de redébrancher... C'est glauque hein? :)