Salut,
J'ai fait l'analyse des fichiers et parmi eux certains étaient détectés comme infectés. Je les ais donc rajoutés comme tu m'a dit.
Ah oui aussi j'ai fait glisser CFScript sur combofix et le scna s'est lancé mais le message Type 1 to continue, or 2 to abort n'est pas apparu donc j'espere que je ne me suis pas trompé
Sinon voici le rapport du scan :
ComboFix 08-06-20.4 - Tibo! 2008-06-27 15:34:56.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.568 [GMT 2:00]
Endroit: C:\Documents and Settings\Tibo!\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tibo!\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE ::
C:\WINDOWS\system32\aujipyyb.dll
C:\WINDOWS\system32\cflbkgwl.dll
C:\WINDOWS\system32\egctbilw.dll
C:\WINDOWS\system32\geuiuknx.dll
C:\WINDOWS\system32\gtfdtkig.dll
C:\WINDOWS\system32\lnlmfymd.dll
C:\WINDOWS\system32\rkktyhuq.dll
C:\WINDOWS\system32\vrerotlp.dll
C:\WINDOWS\system32\yhmvgpvq.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\aujipyyb.dll
C:\WINDOWS\system32\cflbkgwl.dll
C:\WINDOWS\system32\egctbilw.dll
C:\WINDOWS\system32\geuiuknx.dll
C:\WINDOWS\system32\gtfdtkig.dll
C:\WINDOWS\system32\lnlmfymd.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\rkktyhuq.dll
C:\WINDOWS\system32\vrerotlp.dll
C:\WINDOWS\system32\yhmvgpvq.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-27 to 2008-06-27 ))))))))))))))))))))))))))))))))))))
.
2008-06-27 02:31 . 2008-06-27 02:33 <REP> d-------- C:\hijackthis
2008-06-27 02:17 . 2008-06-27 02:21 354 ---hs---- C:\WINDOWS\system32\qvpgvmhy.ini
2008-06-26 21:10 . 2008-06-26 21:10 <REP> d-------- C:\Program Files\Trend Micro
2008-06-26 21:05 . 2008-06-26 21:20 <REP> d-------- C:\VundoFix Backups
2008-06-26 16:11 . 2008-06-26 16:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-26 15:37 . 2008-06-26 15:31 23,552 --a------ C:\WINDOWS\system32\normaliz.dll
2008-06-24 21:57 . 2008-06-24 21:58 <REP> d-------- C:\WINDOWS\system32\NtmsData
2008-06-22 12:47 . 2008-06-22 12:47 268 --ah----- C:\sqmdata16.sqm
2008-06-22 12:47 . 2008-06-22 12:47 244 --ah----- C:\sqmnoopt16.sqm
2008-06-21 17:10 . 2008-06-21 17:10 <REP> d-------- C:\Documents and Settings\Marion\Application Data\DivX
2008-06-20 09:27 . 2008-06-20 09:27 268 --ah----- C:\sqmdata15.sqm
2008-06-20 09:27 . 2008-06-20 09:27 244 --ah----- C:\sqmnoopt15.sqm
2008-06-20 08:26 . 2008-06-20 08:26 268 --ah----- C:\sqmdata14.sqm
2008-06-20 08:26 . 2008-06-20 08:26 244 --ah----- C:\sqmnoopt14.sqm
2008-06-20 08:24 . 2008-06-20 08:24 268 --ah----- C:\sqmdata13.sqm
2008-06-20 08:24 . 2008-06-20 08:24 244 --ah----- C:\sqmnoopt13.sqm
2008-06-17 18:33 . 2008-06-19 18:01 <REP> d-------- C:\Program Files\PKR
2008-06-08 14:46 . 2008-06-08 14:46 268 --ah----- C:\sqmdata12.sqm
2008-06-08 14:46 . 2008-06-08 14:46 244 --ah----- C:\sqmnoopt12.sqm
2008-06-08 14:24 . 2008-06-08 14:24 268 --ah----- C:\sqmdata11.sqm
2008-06-08 14:24 . 2008-06-08 14:24 244 --ah----- C:\sqmnoopt11.sqm
2008-06-08 14:23 . 2008-06-08 14:23 268 --ah----- C:\sqmdata10.sqm
2008-06-08 14:23 . 2008-06-08 14:23 244 --ah----- C:\sqmnoopt10.sqm
2008-06-05 19:29 . 2008-06-05 19:29 <REP> d-------- C:\Program Files\Games-Masters.com
2008-05-27 21:58 . 2007-09-18 23:41 258,352 --a------ C:\WINDOWS\system32\unicows.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 13:19 --------- d-s---w C:\Program Files\HLSW
2008-06-26 14:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-26 14:36 --------- d-----w C:\Documents and Settings\Tibo!\Application Data\mIRC
2008-06-26 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-25 21:23 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-06-25 13:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-06-24 14:00 --------- d-----w C:\Program Files\mIRC
2008-06-22 14:59 --------- d-----w C:\Documents and Settings\Marion\Application Data\OpenOffice.org2
2008-06-07 07:54 --------- d-----w C:\Documents and Settings\Tibo!\Application Data\Azureus
2008-06-04 18:11 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-04 18:11 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-06-04 17:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-04 11:41 --------- d-----w C:\Program Files\Azureus
2008-05-27 17:18 --------- d-----w C:\Documents and Settings\Tibo!\Application Data\OpenOffice.org2
2008-05-27 08:46 --------- d-----w C:\Documents and Settings\Brigitte\Application Data\OpenOffice.org2
2008-05-15 08:54 --------- d-----w C:\Program Files\Google
2008-05-13 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\ATI
2008-05-13 19:15 --------- d-----w C:\Program Files\ATI Technologies
2008-05-13 18:21 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-08 11:57 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-05-08 11:56 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-05-08 11:50 --------- d-----w C:\Program Files\Java
2008-05-05 17:18 --------- d-----w C:\Program Files\Radeon Omega Drivers
2008-04-17 14:19 451,072 ----a-w C:\WINDOWS\Radeon Omega Drivers v3.8.231 Uninstall.exe
2008-04-17 13:45 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-04-08 17:19 451,072 ----a-w C:\WINDOWS\Radeon Omega Drivers v3.8.421 Uninstall.exe
2008-03-29 05:19 9,801,728 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-03-29 04:40 167,936 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-03-29 04:05 372,736 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-03-29 04:04 299,008 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-03-29 03:56 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-03-29 03:56 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-03-29 03:55 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-03-29 03:55 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-03-29 03:55 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-03-29 03:54 536,576 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-03-29 03:52 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-03-29 03:43 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-03-29 03:39 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-03-29 03:36 1,765,120 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-03-29 03:24 46,080 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-03-29 03:21 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-03-29 03:19 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-03-29 03:12 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-03-28 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-01-12 15:48 22,328 ----a-w C:\Documents and Settings\Tibo!\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-27_ 2.20.53.28 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-27 00:16:01 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-27 13:37:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-27 13:38:05 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5c4.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:09 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BDARemote.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BDARemote.lnk
backup=C:\WINDOWS\pss\BDARemote.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage Setup]
C:\Program Files\DAEMON Tools Lite\AdVantageSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RaidTool]
--a------ 2005-04-26 11:22 589824 C:\Program Files\VIA\RAID\raid_tool.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\tiboss42\\counter-strike\\hl.exe"=
"C:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe"=
"C:\\Program Files\\HLSW\\hlsw.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\rodyhmk@msn.com\\counter-strike\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\tiboss42\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Valve\\Steam\\Steam.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\tiboss42\\condition zero\\hl.exe"=
"C:\\Program Files\\TmNationsForever\\TmForever.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2007-03-26 15:26]
R0 vIdeBus;vIdeBus;C:\WINDOWS\system32\DRIVERS\vIdeBus.sys [2004-10-22 11:28]
R0 vIdePort;VIA IDE Controller PORT Driver;C:\WINDOWS\system32\DRIVERS\vIdePort.sys [2004-10-22 11:28]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-03-29 11:36]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2007-03-26 15:26]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 13:29]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-09 11:53:40 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job"
- c:\Program Files\Microsoft IntelliPoint\ipoint.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-27 15:38:19
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-27 15:42:54 - machine was rebooted [Tibo!]
ComboFix-quarantined-files.txt 2008-06-27 13:42:49
ComboFix2.txt 2008-06-27 00:21:12
Pre-Run: 31,208,624,128 octets libres
Post-Run: 31,208,681,472 octets libres
200
___________________________________________________________________________________________
ET le rapport de hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:48:46, on 27/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ngohq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
End of file - 4603 bytes
__________________________________________________________________________________________
Voila ^^ tiens moi au courant
Merci