Rebonjour,
j'ai encore des problèmes avec mon PC :windows se ferme toute seul sans pouvoir redemarrer.
ComboFix 09-03-23.01 - Administrateur 2009-03-25 18:24:22.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.479.148 [GMT 0:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFscript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\olhrwef.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\msssc.dll
c:\windows\system32\nmdfgds0.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-25 au 2009-03-25 ))))))))))))))))))))))))))))))))))))
.
2009-03-25 15:50 . 2009-03-25 15:51 <REP> d-------- C:\rsit
2009-03-18 13:29 . 2009-03-18 13:29 <REP> d-------- c:\program files\Avira
2009-03-18 11:59 . 2009-03-18 11:59 268 --ah----- C:\sqmdata19.sqm
2009-03-18 11:59 . 2009-03-18 11:59 244 --ah----- C:\sqmnoopt19.sqm
2009-03-18 11:36 . 2009-03-18 11:36 268 --ah----- C:\sqmdata18.sqm
2009-03-18 11:36 . 2009-03-18 11:36 244 --ah----- C:\sqmnoopt18.sqm
2009-03-18 11:29 . 2009-03-18 11:29 268 --ah----- C:\sqmdata17.sqm
2009-03-18 11:29 . 2009-03-18 11:29 244 --ah----- C:\sqmnoopt17.sqm
2009-03-18 00:27 . 2009-03-18 00:27 268 --ah----- C:\sqmdata16.sqm
2009-03-18 00:27 . 2009-03-18 00:27 244 --ah----- C:\sqmnoopt16.sqm
2009-03-18 00:25 . 2009-03-18 00:25 268 --ah----- C:\sqmdata15.sqm
2009-03-18 00:25 . 2009-03-18 00:25 244 --ah----- C:\sqmnoopt15.sqm
2009-03-17 20:16 . 2009-03-17 20:16 268 --ah----- C:\sqmdata14.sqm
2009-03-17 20:16 . 2009-03-17 20:16 244 --ah----- C:\sqmnoopt14.sqm
2009-03-15 20:59 . 2009-03-15 20:59 268 --ah----- C:\sqmdata13.sqm
2009-03-15 20:59 . 2009-03-15 20:59 244 --ah----- C:\sqmnoopt13.sqm
2009-03-12 22:15 . 2009-03-12 22:15 <REP> d-------- C:\CODY5
2009-03-12 18:50 . 2009-03-12 18:50 <REP> d-------- c:\documents and settings\Administrateur\WINDOWS
2009-03-12 18:48 . 2009-03-12 18:48 268 --ah----- C:\sqmdata11.sqm
2009-03-12 18:48 . 2009-03-12 18:48 244 --ah----- C:\sqmnoopt11.sqm
2009-03-12 18:19 . 2009-03-12 18:19 268 --ah----- C:\sqmdata10.sqm
2009-03-12 18:19 . 2009-03-12 18:19 244 --ah----- C:\sqmnoopt10.sqm
2009-03-12 18:14 . 2009-03-12 18:14 268 --ah----- C:\sqmdata09.sqm
2009-03-12 18:14 . 2009-03-12 18:14 244 --ah----- C:\sqmnoopt09.sqm
2009-03-12 16:25 . 2009-03-12 16:25 268 --ah----- C:\sqmdata08.sqm
2009-03-12 16:25 . 2009-03-12 16:25 244 --ah----- C:\sqmnoopt08.sqm
2009-03-12 16:15 . 1997-01-14 23:00 149,504 --a------ c:\windows\system32\MFCANS32.DLL
2009-03-12 16:15 . 2009-03-12 16:15 0 --a------ c:\windows\PROTOCOL.INI
2009-03-12 16:02 . 2009-03-12 16:02 268 --ah----- C:\sqmdata07.sqm
2009-03-12 16:02 . 2009-03-12 16:02 244 --ah----- C:\sqmnoopt07.sqm
2009-03-12 14:22 . 1998-02-06 21:39 304,128 --a------ c:\windows\unin040c.exe
2009-03-12 00:08 . 2009-03-12 00:08 <REP> d-------- C:\DATACODY
2009-03-11 21:02 . 2009-03-11 21:02 268 --ah----- C:\sqmdata06.sqm
2009-03-11 21:02 . 2009-03-11 21:02 244 --ah----- C:\sqmnoopt06.sqm
2009-03-11 20:16 . 2009-03-11 20:16 268 --ah----- C:\sqmdata05.sqm
2009-03-11 20:16 . 2009-03-11 20:16 244 --ah----- C:\sqmnoopt05.sqm
2009-03-11 20:13 . 2009-03-11 20:13 268 --ah----- C:\sqmdata04.sqm
2009-03-11 20:13 . 2009-03-11 20:13 244 --ah----- C:\sqmnoopt04.sqm
2009-03-10 19:25 . 2009-03-10 19:25 268 --ah----- C:\sqmdata03.sqm
2009-03-10 19:25 . 2009-03-10 19:25 244 --ah----- C:\sqmnoopt03.sqm
2009-03-10 15:33 . 2009-03-10 15:33 268 --ah----- C:\sqmdata02.sqm
2009-03-10 15:33 . 2009-03-10 15:33 244 --ah----- C:\sqmnoopt02.sqm
2009-03-10 14:32 . 2009-03-10 14:32 268 --ah----- C:\sqmdata01.sqm
2009-03-10 14:32 . 2009-03-10 14:32 244 --ah----- C:\sqmnoopt01.sqm
2009-03-10 01:14 . 2009-03-10 01:14 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-03-09 19:58 . 2009-03-09 19:58 230 --a------ c:\windows\system32\spupdsvc.inf
2009-03-08 19:56 . 2009-03-08 19:57 <REP> d-------- c:\windows\system32\NtmsData
2009-03-08 11:22 . 2009-03-08 11:22 1,066,718 --a------ C:\upload_moi_USER-252EDE6F12.tar.gz
2009-03-04 21:59 . 2009-03-06 22:58 250 --a------ c:\windows\gmer.ini
2009-03-02 19:25 . 2007-08-28 15:17 21,632 --a------ c:\windows\system32\drivers\lgevdomodem.sys
2009-03-02 19:25 . 2007-08-28 15:17 19,840 --a------ c:\windows\system32\drivers\lgevdodiag.sys
2009-03-02 19:25 . 2007-08-28 15:17 19,840 --a------ c:\windows\system32\drivers\lgevdoatc.sys
2009-03-02 19:25 . 2007-08-28 15:17 12,800 --a------ c:\windows\system32\drivers\lgevdobus.sys
2009-03-01 15:31 . 2003-05-27 17:05 578,304 --a------ c:\windows\system32\drivers\smwdm.sys
2009-03-01 15:31 . 2003-01-08 12:23 49,152 --a------ c:\windows\system32\DSndUp.exe
2009-03-01 15:31 . 2002-04-17 16:05 45,056 --a------ c:\windows\system32\CleanUp.exe
2009-03-01 15:31 . 2003-12-18 14:23 4,816 --a------ c:\windows\system32\drivers\aeaudio.sys
2009-03-01 15:31 . 2003-12-18 14:23 3,744 --a------ c:\windows\system32\drivers\smsens.sys
2009-02-28 21:20 . 2009-02-28 21:20 8,704 --ahs---- c:\windows\Thumbs.db
2009-02-28 16:07 . 2009-02-28 16:07 <REP> d-------- c:\documents and settings\Administrateur\Application Data\SiteRanker
2009-02-28 16:02 . 2009-02-28 21:02 <REP> d-------- c:\program files\SiteRanker
2009-02-27 23:03 . 2009-02-28 16:50 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Free Download Manager(2)
2009-02-27 18:45 . 2009-02-27 18:45 <REP> d---s---- c:\documents and settings\Administrateur\UserData
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-25 15:51 --------- d-----w c:\program files\Trend Micro
2009-03-20 17:32 --------- d-----w c:\program files\Google
2009-03-18 13:29 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-03-12 18:21 --------- d-----w c:\program files\Free Download Manager
2009-03-02 19:25 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-02 19:25 --------- d-----w c:\program files\LG Electronics
2009-03-01 15:57 --------- d-----w c:\program files\Java
2009-02-28 21:07 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-02-24 21:52 --------- d-----w c:\program files\Screamer Radio
2009-02-23 23:01 --------- d-----w c:\program files\CCleaner
2009-02-12 21:07 --------- d-----w c:\program files\MathType
2009-02-12 21:05 --------- d-----w c:\program files\Intel
2009-02-12 21:04 --------- d-----w c:\program files\ma-config.com
2009-02-12 21:00 --------- d-----w c:\documents and settings\Administrateur\Application Data\CVitae
2009-02-07 14:13 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-02-05 22:16 --------- d-----w c:\program files\Max2k
2009-01-31 21:02 --------- d-----w c:\program files\Free Audio Pack
2009-01-29 21:41 --------- d-----w c:\program files\VS Revo Group
2009-01-29 00:23 --------- d-----w c:\documents and settings\Administrateur\Application Data\Leadertech
2009-01-28 23:38 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-01-27 20:05 159,743 ----a-w c:\windows\Marsu-Fix Uninstaller.exe
2009-01-27 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2009-01-20 01:45 32,768 ----a-w c:\windows\system32\winsystems.dll.tmp
2009-01-04 01:35 8 --sh--w c:\program files\.ex010705.dat
2009-01-04 01:35 8 --sh--w c:\program files\.ex010507.dat
2009-01-04 01:35 8 --sh--w c:\program files\.data211204.dat
2009-01-04 01:35 8 --sh--w c:\program files\.data211004.dat
2009-01-04 01:35 8 --sh--w c:\program files\.data110704.dat
2009-01-04 01:35 8 --sh--w c:\program files\.bx050107.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.xp070105.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.px050107.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.data001.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.data000.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.ax010705.dat
2009-01-04 01:35 8 --sh--w c:\documents and settings\Administrateur\Application Data\.addit001.dat
2008-11-26 22:23 8 --sh--w c:\program files\.drv120405.dat
2008-11-26 22:23 8 --sh--w c:\program files\.dat000002.dat
2008-11-26 22:23 8 --sh--w c:\program files\.dat000001.dat
2008-11-26 22:23 8 --sh--w c:\documents and settings\Administrateur\Application Data\.drv190904.dat
2008-11-26 22:23 8 --sh--w c:\documents and settings\Administrateur\Application Data\.drv120205.dat
2008-11-26 22:23 8 --sh--w c:\documents and settings\Administrateur\Application Data\.app190905.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UMService"="c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe" [2008-05-09 28672]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-01-20 1451248]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-11-15 185896]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2008-03-04 999424]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2002-11-25 172032]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SMCWCBT-G 108Mbps WLAN Cardbus.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SMCWCBT-G 108Mbps WLAN Cardbus.lnk
backup=c:\windows\pss\SMCWCBT-G 108Mbps WLAN Cardbus.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
--------- 2005-09-06 10:10 450560 c:\program files\VIAudioi\SBADeck\ADeck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
--a------ 2004-06-09 14:37 40960 c:\windows\VM_STI.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:54 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2006-02-07 08:36 77824 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2006-02-07 08:39 94208 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 10:55 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2003-10-31 18:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--------- 2005-11-10 12:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-11-15 22:58 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UMService]
--a------ 2008-05-09 18:07 28672 c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 UsbEvdoAtc;LGE EVDO USB Serial Port;c:\windows\system32\drivers\lgevdoatc.sys [2009-03-02 19840]
R3 usbevdobus;LGE EVDO Composite USB Device;c:\windows\system32\drivers\lgevdobus.sys [2009-03-02 12800]
R3 UsbEvdoDiag;LGE EVDO USB Serial DM Port;c:\windows\system32\drivers\lgevdodiag.sys [2009-03-02 19840]
R3 USBEVDOModem;LGE EVDO USB Modem;c:\windows\system32\drivers\lgevdomodem.sys [2009-03-02 21632]
S3 SMCWCBTG;SMCWCBT-G 108Mbps WLAN Cardbus Service;c:\windows\system32\DRIVERS\SMCWCBTG.sys --> c:\windows\system32\DRIVERS\SMCWCBTG.sys [?]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.sys [2004-04-21 16384]
S3 ZSMC302;VIMICRO USB PC Camera;c:\windows\system32\drivers\usbVM31b.sys [2008-11-16 90568]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://fr.yhs.search.yahoo.com/avg/search?fr=yhs-avg
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-25 18:25:58
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-839522115-842925246-1060284298-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,05,55,90,b9,79,1d,8a,4e,b0,a0,b4,\
"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,05,55,90,b9,79,1d,8a,4e,b0,a0,b4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{14549f3e-aa8d-438c-a0b2-747e1c237095}]
@Denied: (Full) (Everyone)
"Model"=dword:0000015a
"Therad"=dword:00000031
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):a4,45,cb,cc,06,ed,48,4d,15,d2,87,21,a3,3b,3b,3f,0d,66,31,5f,2c,
b2,cf,b1,94,58,de,7b,00,35,90,84,ee,6b,94,fa,26,33,4b,04,00,00,00,00,00,00,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\netprovcredman.dll
.
Heure de fin: 2009-03-25 18:27:45
ComboFix-quarantined-files.txt 2009-03-25 18:27:29
Avant-CF: 23 000 961 024 octets libres
Après-CF: 22,991,147,008 octets libres
230 --- E O F --- 2008-12-01 00:08:13
Encore merci de votre aide.