Voici les différents rapports....
Rien d'alarmant si j'ai bien suivi... cependant, rien de changé non plus dans le comportement du PC :'(
JavaRa 1.13 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sun Mar 22 15:38:12 2009
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
------------------------------------
Finished reporting.
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1883
Windows 5.1.2600 Service Pack 3
22/03/2009 15:50:57
mbam-log-2009-03-22 (15-50-57).txt
Type de recherche: Examen rapide
Eléments examinés: 58960
Temps écoulé: 4 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
=================================================
ComboFix 09-03-19.02 - Jean-Yves 2009-03-22 16:02:12.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.248 [GMT 1:00]
Lancé depuis: c:\documents and settings\Jean-Yves\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-22 au 2009-03-22 ))))))))))))))))))))))))))))))))))))
.
2009-03-22 15:43 . 2009-03-22 15:43 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-22 15:43 . 2009-03-22 15:43 <REP> d-------- c:\documents and settings\Jean-Yves\Application Data\Malwarebytes
2009-03-22 15:43 . 2009-03-22 15:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-22 15:43 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-22 15:43 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-22 15:40 . 2009-03-22 15:40 <REP> d--hs---- c:\documents and settings\Jean-Yves\PrivacIE
2009-03-22 15:40 . 2009-03-22 15:40 <REP> d--hs---- c:\documents and settings\Jean-Yves\IECompatCache
2009-03-22 12:30 . 2009-03-22 12:30 <REP> d--hs---- c:\documents and settings\LocalService\IETldCache
2009-03-22 12:30 . 2009-03-22 12:30 <REP> d--hs---- c:\documents and settings\Jean-Yves\IETldCache
2009-03-22 12:26 . 2009-03-22 12:26 <REP> d-------- c:\windows\ie8updates
2009-03-22 12:23 . 2009-03-22 12:26 <REP> d--h-c--- c:\windows\ie8
2009-03-22 12:21 . 2009-02-28 05:55 105,984 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-03-22 12:05 . 2009-03-22 12:05 <REP> d-------- C:\rsit
2009-03-22 12:02 . 2009-03-22 12:05 <REP> d-------- c:\program files\trend micro
2009-03-22 10:32 . 2009-03-22 10:32 <REP> d-------- c:\program files\Photo Story 3 for Windows
2009-03-22 10:25 . 2009-03-22 10:25 <REP> d-------- c:\documents and settings\Jean-Yves\Application Data\Windows Desktop Search
2009-03-22 10:24 . 2009-03-22 10:24 <REP> d-------- c:\windows\system32\GroupPolicy
2009-03-22 10:24 . 2009-03-22 10:24 <REP> d-------- c:\program files\Windows Desktop Search
2009-03-22 10:24 . 2008-03-07 18:02 192,000 -----c--- c:\windows\system32\dllcache\offfilt.dll
2009-03-22 10:24 . 2008-03-07 18:02 98,304 -----c--- c:\windows\system32\dllcache\nlhtml.dll
2009-03-22 10:24 . 2008-03-07 18:02 29,696 -----c--- c:\windows\system32\dllcache\mimefilt.dll
2009-03-22 10:20 . 2009-03-22 10:20 <REP> d-------- c:\program files\Windows Media Connect 2
2009-03-22 10:18 . 2009-03-22 10:18 <REP> d-------- c:\windows\system32\LogFiles
2009-03-22 10:18 . 2009-03-22 10:19 <REP> d-------- c:\windows\system32\drivers\UMDF
2009-03-22 10:18 . 2009-03-22 16:00 <REP> d-------- c:\documents and settings\Jean-Yves\Application Data\Skype
2009-03-22 10:17 . 2009-03-22 10:17 <REP> dr------- c:\program files\Skype
2009-03-22 10:17 . 2009-03-22 10:17 <REP> d-------- c:\program files\Fichiers communs\Skype
2009-03-22 10:17 . 2009-03-22 10:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Skype
2009-03-22 10:11 . 2008-07-31 23:17 9,200 --------- c:\windows\system32\drivers\cdralw2k.sys
2009-03-22 10:11 . 2008-07-31 23:17 9,072 --------- c:\windows\system32\drivers\cdr4_xp.sys
2009-03-22 10:10 . 2009-03-22 10:10 <REP> d-------- c:\windows\system32\IOSUBSYS
2009-03-22 09:49 . 2009-03-22 09:49 <REP> d-------- c:\program files\Java
2009-03-22 09:49 . 2009-03-22 09:49 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-22 09:49 . 2009-03-22 09:49 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-22 09:41 . 2009-03-22 09:41 0 --a------ c:\windows\nsreg.dat
2009-03-22 08:56 . 2009-03-22 08:56 0 --a------ c:\windows\VAIOUpdt.INI
2009-03-22 08:50 . 2009-03-22 08:50 0 --a------ C:\winamp.ini
2009-03-21 18:01 . 2009-03-21 18:01 <REP> d-------- c:\program files\Avira
2009-03-21 18:01 . 2009-03-21 18:01 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-21 17:28 . 2009-03-08 04:39 11,063,808 --a--c--- c:\windows\system32\dllcache\ieframe.dll
2009-03-21 17:28 . 2009-02-06 21:07 3,698,584 --a--c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-03-21 17:28 . 2009-03-08 04:32 1,985,024 --a--c--- c:\windows\system32\dllcache\iertutil.dll
2009-03-21 17:28 . 2009-03-08 14:18 1,310,720 --a--c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-21 17:28 . 2009-03-08 04:32 594,432 --a--c--- c:\windows\system32\dllcache\msfeeds.dll
2009-03-21 17:28 . 2009-03-08 04:11 445,952 --a--c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-03-21 17:28 . 2009-03-08 04:31 59,904 --a--c--- c:\windows\system32\dllcache\icardie.dll
2009-03-21 17:28 . 2009-03-08 04:31 55,296 --a--c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-21 17:28 . 2008-12-19 10:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-03-21 17:05 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-03-21 17:03 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-21 17:03 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-21 17:03 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-21 17:03 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-21 17:03 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-21 17:03 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2009-03-21 17:02 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-03-21 17:02 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-03-21 17:02 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-03-21 17:02 . 2008-12-11 11:57 333,952 -----c--- c:\windows\system32\dllcache\srv.sys
2009-03-21 17:02 . 2008-05-01 15:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-03-21 16:26 . 2009-03-22 12:30 <REP> d-------- c:\windows\system32\fr-fr
2009-03-21 16:26 . 2009-03-21 16:26 <REP> d-------- c:\windows\system32\fr
2009-03-21 16:26 . 2009-03-21 16:26 <REP> d-------- c:\windows\system32\bits
2009-03-21 16:26 . 2009-03-21 16:26 <REP> d-------- c:\windows\l2schemas
2009-03-21 16:21 . 2009-03-21 16:21 <REP> d-------- c:\windows\ServicePackFiles
2009-03-21 16:10 . 2009-03-21 16:10 <REP> d-------- c:\windows\EHome
2009-03-21 15:58 . 2004-08-04 00:38 327,168 --------- c:\windows\system32\drivers\ati2mtaa.sys
2009-03-21 15:41 . 2009-03-22 12:26 <REP> d--h----- c:\windows\$hf_mig$
2009-03-21 15:41 . 2009-01-07 18:21 26,144 --a------ c:\windows\system32\spupdsvc.exe
2009-03-21 15:39 . 2009-03-21 15:39 <REP> d--hs---- c:\documents and settings\Jean-Yves\UserData
2009-03-21 15:29 . 2003-07-17 16:40 265,728 --a------ c:\windows\system32\drivers\bcmwl5.sys
2009-03-21 13:58 . 2009-03-21 14:01 <REP> d-------- c:\program files\Microsoft Works
2009-03-21 13:48 . 2003-08-26 17:03 757,760 --a------ c:\windows\system32\CDDBUI.dll
2009-03-21 13:48 . 2003-08-26 17:01 630,784 --a------ c:\windows\system32\CDDBControl.dll
2009-03-21 13:48 . 2003-07-11 14:23 110,592 --a------ c:\windows\system32\CddbLangFR.dll
2009-03-21 13:47 . 2009-03-21 13:47 <REP> d-------- c:\program files\Sonic
2009-03-21 13:43 . 2009-03-21 13:43 <REP> d-------- c:\documents and settings\All Users\Application Data\VAIO Media Platform
2009-03-21 13:42 . 2004-08-20 19:17 <REP> d--h----- c:\documents and settings\Jean-Yves\Voisinage réseau
2009-03-21 13:42 . 2004-08-20 19:17 <REP> d--h----- c:\documents and settings\Jean-Yves\Voisinage d'impression
2009-03-21 13:42 . 2004-08-20 17:22 <REP> d--h----- c:\documents and settings\Jean-Yves\Modèles
2009-03-21 13:42 . 2009-03-22 12:30 <REP> dr------- c:\documents and settings\Jean-Yves\Mes documents
2009-03-21 13:42 . 2004-08-20 19:17 <REP> dr------- c:\documents and settings\Jean-Yves\Menu Démarrer
2009-03-21 13:42 . 2009-03-21 17:41 <REP> dr------- c:\documents and settings\Jean-Yves\Favoris
2009-03-21 13:42 . 2009-03-22 15:52 <REP> d-------- c:\documents and settings\Jean-Yves\Bureau
2009-03-21 13:42 . 2004-08-23 13:10 <REP> d-------- c:\documents and settings\Jean-Yves\Application Data\Symantec
2009-03-21 13:42 . 2009-03-21 16:02 <REP> d-------- c:\documents and settings\Jean-Yves\Application Data\Sony Corporation
2009-03-21 13:42 . 2009-03-22 15:40 <REP> d-------- c:\documents and settings\Jean-Yves
2009-03-21 13:41 . 2009-03-21 13:41 0 -rah----- c:\windows\system32\drivers\Sony_PCG-K315S(FR).mrk
2009-03-21 13:40 . 2009-03-21 13:40 <REP> d-------- c:\program files\Raccourcis de programmes
2009-03-08 14:17 . 2009-03-08 14:17 57,344 --------- c:\windows\system32\msrating.dll.mui
2009-03-08 14:17 . 2009-03-08 14:17 2,560 --------- c:\windows\system32\mshta.exe.mui
2009-03-08 14:16 . 2009-03-08 14:16 4,096 --------- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:15 . 2009-03-08 14:15 81,920 --------- c:\windows\system32\iedkcs32.dll.mui
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 11:44 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-03-22 09:10 --------- d-----w c:\program files\Google
2009-03-22 07:47 --------- d-----w c:\program files\Sony
2009-03-22 07:46 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-03-22 07:45 --------- d-----w c:\program files\Fichiers communs\Sony Shared
2009-03-22 07:30 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-03-22 07:25 --------- d-----w c:\program files\Symantec
2009-03-22 07:25 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-03-21 13:04 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-21 13:04 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Corporation
2009-03-08 03:34 914,944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 03:34 43,008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 03:33 420,352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 03:33 18,944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 03:32 72,704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 03:32 71,680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 03:31 48,128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 03:31 45,568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 03:31 34,816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 03:22 156,160 ----a-w c:\windows\system32\msls31.dll
2009-02-09 14:05 1,846,912 ----a-w c:\windows\system32\win32k.sys
2009-01-07 17:20 265,720 ----a-w c:\windows\system32\msdbg2.dll
2009-01-07 17:20 26,112 ----a-w c:\windows\system32\idndl.dll
2009-01-07 17:20 24,576 ----a-w c:\windows\system32\nlsdl.dll
2009-01-07 17:20 23,552 ----a-w c:\windows\system32\normaliz.dll
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-16 24095528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2004-06-29 180224]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2004-06-29 122880]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 c:\windows\system32\ico.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
S3 WPC54GSv1;Linksys Wireless Notebook Adapter WPC54GSv1 Driver;c:\windows\system32\drivers\WPC54GSv1.SYS [2006-11-30 610816]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.club-vaio.com/fr
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward &Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Si&milar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
FF - ProfilePath - c:\documents and settings\Jean-Yves\Application Data\Mozilla\Firefox\Profiles\o0o1g3mf.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-22 16:03:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(468)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-03-22 16:05:43
ComboFix-quarantined-files.txt 2009-03-22 15:05:38
Avant-CF: 23 167 766 528 octets libres
Après-CF: 23,200,399,360 octets libres
202