D'accord destrio5, voila le rapport que tu veux -enfin je crois;
ComboFix 08-07-22.4 - SA POSTE 2 2008-07-23 12:08:21.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.189 [GMT -10:00]
Endroit: L:\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))))))))))))
.
2008-07-22 10:38 . 2008-07-22 14:14 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-07-21 14:13 . 2008-07-14 09:29 121,319 -r-hs---- C:\1yl2d.bat
2008-07-21 11:40 . 2008-07-21 11:40 <REP> d-------- C:\Documents and Settings\SA POSTE 2\Application Data\AdobeUM
2008-07-18 09:31 . 2008-07-18 09:31 <REP> d-------- C:\Program Files\SuperCopier2
2008-07-16 15:52 . 2008-07-16 15:52 <REP> d-------- C:\Program Files\MSECache
2008-07-15 12:41 . 2008-07-15 12:41 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-07-15 12:37 . 2008-07-18 09:31 <REP> d-------- C:\Documents and Settings\SA POSTE 2\Application Data\U3
2008-07-15 12:33 . 2008-07-15 12:59 <REP> d-------- C:\SCAN
2008-07-15 11:57 . 2008-07-15 11:57 <REP> d-------- C:\Program Files\Hewlett-Packard
2008-07-15 11:57 . 2004-09-15 05:20 61,440 -ra------ C:\WINDOWS\scrub2k.exe
2008-07-15 11:57 . 2004-09-15 06:18 83 -ra------ C:\WINDOWS\hpw1280k.ini
2008-07-15 11:55 . 2008-07-15 11:58 206,361 --a------ C:\WINDOWS\hpdj1280.his
2008-07-15 11:55 . 2008-07-15 11:58 13,261 --a------ C:\WINDOWS\hpdj1280.ini
2008-07-15 11:53 . 2004-09-15 05:28 196,608 -ra------ C:\WINDOWS\system32\hpbvnstp.dll
2008-07-15 11:53 . 2008-07-15 11:53 3,423 --a------ C:\WINDOWS\hpbvnstp.his
2008-07-15 11:53 . 2008-07-15 11:53 1,061 --a------ C:\WINDOWS\hpbvnstp.ini
2008-07-15 11:53 . 2008-07-15 11:55 685 --a------ C:\WINDOWS\hpbvspst.his
2008-07-15 11:53 . 2008-07-15 11:55 344 --a------ C:\WINDOWS\hpbvspst.ini
2008-07-15 11:53 . 2004-09-15 06:18 234 -ra------ C:\WINDOWS\system32\hpbvnstp.dat
2008-07-15 11:52 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-15 11:52 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-07-15 09:43 . 2008-07-23 12:05 <REP> d-------- C:\omap
2008-07-15 09:27 . 2008-07-15 09:27 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2008-07-15 09:27 . 2008-07-15 09:27 <REP> d-------- C:\Program Files\CyberLink
2008-07-15 09:27 . 2008-07-15 09:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-15 09:26 . 2008-07-15 09:26 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2008-07-15 09:25 . 2004-09-12 20:17 2,146,304 --------- C:\WINDOWS\UNNMP.exe
2008-07-15 09:25 . 2004-10-15 00:02 52,536 --------- C:\WINDOWS\UNNMP.cfg
2008-07-15 09:21 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-07-15 09:19 . 2004-10-13 22:19 2,285,568 --------- C:\WINDOWS\UNNeroVision.exe
2008-07-15 09:19 . 2004-10-15 00:02 97,294 --------- C:\WINDOWS\UNNeroVision.cfg
2008-07-15 09:19 . 2001-03-08 19:30 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2008-07-15 09:18 . 2008-07-15 09:20 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-07-15 09:18 . 2008-07-15 09:24 <REP> d-------- C:\Program Files\Ahead
2008-07-15 09:18 . 2008-07-15 09:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-15 09:18 . 2004-07-20 17:24 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-07-15 09:18 . 2004-07-20 17:24 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-07-15 09:18 . 2004-07-20 17:24 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-07-15 09:18 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-07-15 09:18 . 2004-07-20 17:24 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-07-15 09:18 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-07-15 09:18 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll
2008-07-15 09:10 . 2008-07-15 09:10 385 --a------ C:\WINDOWS\ODBC.INI
2008-07-15 09:08 . 2008-07-15 09:09 <REP> d-------- C:\WINDOWS\ShellNew
2008-07-14 22:09 . 2004-08-03 14:39 58,496 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-07-14 22:09 . 2001-08-17 11:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-07-14 22:08 . 2004-08-03 14:54 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-07-14 22:08 . 2004-08-03 13:07 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS
2008-07-14 22:08 . 2001-08-17 10:13 27,165 --a------ C:\WINDOWS\system32\drivers\fetnd5.sys
2008-07-14 22:06 . 2008-07-23 08:40 <REP> d-------- C:\WINDOWS\system32\CatRoot2
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage réseau
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage d'impression
2008-07-14 22:06 . 2008-07-15 08:16 <REP> d--h----- C:\Documents and Settings\Default User\Modèles
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d-------- C:\Documents and Settings\Default User\Mes documents
2008-07-14 22:06 . 2008-07-14 22:06 <REP> dr------- C:\Documents and Settings\Default User\Menu Démarrer
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d-------- C:\Documents and Settings\Default User\Favoris
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d-------- C:\Documents and Settings\Default User\Bureau
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d--h----- C:\Documents and Settings\All Users\Modèles
2008-07-14 22:06 . 2008-07-15 09:09 <REP> dr------- C:\Documents and Settings\All Users\Menu Démarrer
2008-07-14 22:06 . 2008-07-14 22:06 <REP> d-------- C:\Documents and Settings\All Users\Favoris
2008-07-14 22:06 . 2008-07-15 08:18 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-07-14 22:06 . 2008-07-15 12:42 <REP> d-------- C:\Documents and Settings\All Users\Bureau
2008-07-14 22:05 . 2008-07-15 09:21 <REP> d--h----- C:\Documents and Settings\Default User
2008-07-14 22:05 . 2008-07-15 08:20 <REP> d-------- C:\Documents and Settings\All Users
2008-07-14 22:05 . 2008-07-15 08:43 <REP> d-------- C:\Documents and Settings
2008-07-14 22:04 . 2008-07-15 08:24 261 --a------ C:\WINDOWS\system32\$winnt$.inf
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-15 23:52 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-07-15 23:51 50,536 ----a-w C:\WINDOWS\system32\drivers\WpsHelper.sys
2008-07-15 18:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-15 18:52 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-15 18:52 60,808 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-15 18:52 136,496 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-15 18:52 10,652 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-15 18:52 --------- d-----w C:\Program Files\Symantec
2008-07-15 18:21 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-15 18:19 --------- d-----w C:\Program Files\Services en ligne
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 02:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:07 1667584]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 06:45 1052672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-06-25 09:45 115560]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"HPWS myPrintMileage Agent"="C:\Program Files\Hewlett-Packard\HP Deskjet 1280\Toolbox\mpm.exe" [2004-10-31 05:47 102400]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 02:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antvirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"C:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"C:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe"=
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-06-25 09:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20ad7afa-582a-11dd-be1f-0013d398bb6b}]
\Shell\AutoRun\command - J:\1yl2d.bat
\Shell\explore\Command - J:\1yl2d.bat
\Shell\open\Command - J:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20ad7afe-582a-11dd-be1f-0013d398bb6b}]
\Shell\AutoRun\command - J:\1yl2d.bat
\Shell\explore\Command - J:\1yl2d.bat
\Shell\open\Command - J:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36d600e1-5364-11dd-be17-0013d398bb6b}]
\Shell\AutoRun\command - r6r.exe
\Shell\explore\Command - r6r.exe
\Shell\open\Command - r6r.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{764e8f9e-529c-11dd-be14-0013d398bb6b}]
\Shell\AutoRun\command - J:\1yl2d.bat
\Shell\explore\Command - J:\1yl2d.bat
\Shell\open\Command - J:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{764e8f9f-529c-11dd-be14-0013d398bb6b}]
\Shell\AutoRun\command - L:\1yl2d.bat
\Shell\explore\Command - L:\1yl2d.bat
\Shell\open\Command - L:\1yl2d.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adde00db-52c1-11dd-be16-0013d398bb6b}]
\Shell\AutoRun\command - K:\1yl2d.bat
\Shell\explore\Command - K:\1yl2d.bat
\Shell\open\Command - K:\1yl2d.bat
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://intranet.justice.gouv.fr/site/portail/index.php
R1 -: HKCU-Internet Settings,ProxyServer = proxy2.justice.gouv.fr:8080
R1 -: HKCU-Internet Settings,ProxyOverride = intranet.justice.gouv.fr;*.intranet.justice.gouv.fr;*.intranet.justice.fr;10.2.150.*;<local>
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O17 -: HKLM\CCS\Interface\{5F067FA3-E382-4B19-8A35-D2ED0EA710AC}: NameServer = 10.122.1.3
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-23 12:10:40
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\DOCUME~1\SAPOST~1\LOCALS~1\Temp\mc21.tmp"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
Temps d'accomplissement: 2008-07-23 12:12:05
ComboFix-quarantined-files.txt 2008-07-23 22:11:56
Pre-Run: 28,847,513,600 octets libres
Post-Run: 28,887,666,688 octets libres
190