Bonjour,
Après quelques heures de décalage horaire! voici le rapport édité par Combofix, merci de l'analyse.
Meilleures salutations.
Cacarate.
ComboFix 09-04-22.02 - gilles 22/04/2009 22:54.1 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.447.146 [GMT -4:00]
Lancé depuis: d:\programmes téléchargés sur internet\A NETTOYEURS ANTIVIRUS DESINSTALLEURS\jacombo\jaCombo.exe
AV: Norton AntiVirus 2006 *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Exécution préalable -------
.
c:\documents and settings\gilles\Application Data\Microsoft\SystemCertificates\Request
c:\windows\pack.epk
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\autorun.ini
c:\windows\system32\stera.log
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WASFSD
-------\Legacy_WASFSD
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-23 au 2009-04-23 ))))))))))))))))))))))))))))))))))))
.
2009-04-21 19:19 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-21 19:19 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 21:06 . 2009-04-18 21:06 -------- d-----w c:\documents and settings\gilles\Application Data\Symantec
2009-04-18 20:49 . 2009-04-18 22:07 60808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-04-18 20:49 . 2009-04-18 22:07 124464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-18 20:49 . 2009-04-18 20:49 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-04-12 14:19 . 2009-04-12 14:19 603904 ----a-w c:\windows\system32\TUProgSt.exe
2009-04-12 14:19 . 2008-12-11 17:31 27904 ----a-w c:\windows\system32\uxtuneup.dll
2009-04-12 14:19 . 2009-04-12 14:19 360192 ----a-w c:\windows\system32\TuneUpDefragService.exe
2009-04-12 14:18 . 2009-04-12 14:18 -------- d-----w c:\documents and settings\gilles\Application Data\TuneUp Software
2009-04-12 14:16 . 2009-04-12 14:16 -------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-04-12 14:15 . 2009-04-12 14:15 -------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-04-12 14:08 . 2008-04-13 18:45 49408 ----a-w c:\windows\system32\drivers\stream.sys
2009-04-12 14:08 . 2008-04-13 18:45 49408 ----a-w c:\windows\system32\dllcache\stream.sys
2009-04-12 14:07 . 2008-04-13 19:19 146048 ----a-w c:\windows\system32\drivers\portcls.sys
2009-04-12 14:07 . 2008-04-13 19:19 146048 ----a-w c:\windows\system32\dllcache\portcls.sys
2009-04-12 14:07 . 2008-04-13 18:45 60160 ----a-w c:\windows\system32\drivers\drmk.sys
2009-04-12 14:07 . 2008-04-13 18:45 60160 ----a-w c:\windows\system32\dllcache\drmk.sys
2009-04-12 14:06 . 2008-04-14 02:34 129536 ----a-w c:\windows\system32\ksproxy.ax
2009-04-12 14:06 . 2008-04-14 02:34 129536 ----a-w c:\windows\system32\dllcache\ksproxy.ax
2009-04-11 15:25 . 2009-04-11 15:25 -------- d-sh--w C:\FOUND.004
2009-04-09 18:16 . 2009-04-09 18:16 -------- d-sh--w C:\FOUND.003
2009-03-25 03:56 . 2009-03-25 03:56 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 03:00 . 2006-09-07 15:16 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-04-22 12:11 . 2009-01-18 21:59 0 ----a-w C:\Log.txt
2009-04-21 19:19 . 2009-04-21 19:19 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-19 01:06 . 2009-04-19 01:06 -------- d-----w c:\program files\devolo
2009-04-18 22:07 . 2006-11-28 23:31 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-04-18 22:07 . 2006-11-28 23:31 10635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-18 20:50 . 2009-04-18 20:49 -------- d-----w c:\program files\Norton AntiVirus
2009-04-18 20:49 . 2006-05-21 06:28 10344 ----a-w c:\windows\system32\drivers\symlcbrd.sys
2009-04-18 20:49 . 2009-04-18 20:49 -------- d-----w c:\program files\Symantec
2009-04-18 20:38 . 2009-04-18 20:38 34465804 ----a-w c:\program files\NAV061220FR.exe
2009-04-18 02:54 . 2005-10-17 23:13 73460 ----a-w c:\windows\system32\perfc00C.dat
2009-04-18 02:54 . 2005-10-17 23:13 466476 ----a-w c:\windows\system32\perfh00C.dat
2009-04-18 02:54 . 2008-03-25 13:46 55464 ----a-w c:\windows\system32\perfc040.dat
2009-04-18 02:54 . 2008-03-25 13:46 427448 ----a-w c:\windows\system32\perfh040.dat
2009-04-13 13:50 . 2009-04-13 13:50 -------- d-----w c:\program files\Fichiers communs\xing shared
2009-04-12 14:16 . 2009-04-12 14:16 -------- d-----w c:\program files\TuneUp Utilities 2009
2009-03-22 14:55 . 2009-03-22 14:55 -------- d-----w c:\program files\eMule
2009-03-21 14:07 . 2005-10-17 23:13 1054720 ----a-w c:\windows\system32\dllcache\kernel32.dll
2009-03-20 18:19 . 2009-03-20 18:19 -------- d-----w c:\program files\Mozilla Thunderbird
2009-03-06 16:14 . 2009-03-06 16:14 -------- d-----w c:\documents and settings\All Users\Application Data\FlashFXP
2009-03-06 14:20 . 2005-10-17 23:13 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-06 14:20 . 2005-10-17 23:13 286720 ----a-w c:\windows\system32\dllcache\pdh.dll
2009-03-03 00:13 . 2005-10-17 23:13 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-03 00:13 . 2005-10-17 23:13 826368 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-02-28 04:54 . 2005-10-17 23:24 636072 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-20 10:20 . 2007-05-09 14:53 13824 ----a-w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2005-10-17 23:13 70656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2005-10-17 23:13 161792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-20 00:40 . 2006-03-09 13:38 30487 ----a-w C:\stub.log
2009-02-16 01:43 . 2009-02-16 01:43 244 ---ha-w C:\sqmnoopt05.sqm
2009-02-16 01:43 . 2009-02-16 01:43 232 ---ha-w C:\sqmdata05.sqm
2009-02-15 23:12 . 2009-02-15 23:12 244 ---ha-w C:\sqmnoopt04.sqm
2009-02-15 23:12 . 2009-02-15 23:12 232 ---ha-w C:\sqmdata04.sqm
2009-02-15 03:26 . 2009-02-15 03:26 244 ---ha-w C:\sqmnoopt03.sqm
2009-02-15 03:26 . 2009-02-15 03:26 232 ---ha-w C:\sqmdata03.sqm
2009-02-12 15:54 . 2009-02-12 15:54 244 ---ha-w C:\sqmnoopt02.sqm
2009-02-12 15:54 . 2009-02-12 15:54 232 ---ha-w C:\sqmdata02.sqm
2009-02-10 23:06 . 2004-08-04 04:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-10 23:06 . 2004-08-04 04:48 2068096 ----a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-09 14:05 . 2005-10-17 23:13 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 14:05 . 2005-10-17 23:13 1846912 ----a-w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:24 . 2005-10-17 23:13 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:24 . 2005-10-17 23:13 2191104 ----a-w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-09 11:23 . 2008-10-25 22:25 2025984 ----a-w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-09 11:23 . 2008-10-25 22:25 2147328 ----a-w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-09 11:23 . 2005-10-17 23:13 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 11:23 . 2005-10-17 23:13 111104 ----a-w c:\windows\system32\dllcache\services.exe
2009-02-09 10:53 . 2005-10-17 23:23 473600 ----a-w c:\windows\system32\dllcache\fastprox.dll
2009-02-09 10:53 . 2005-10-17 23:23 453120 ----a-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 10:53 . 2005-10-17 23:13 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2005-10-17 23:13 401408 ----a-w c:\windows\system32\dllcache\rpcss.dll
2009-02-09 10:53 . 2005-10-17 23:13 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2005-10-17 23:13 739840 ----a-w c:\windows\system32\dllcache\ntdll.dll
2009-02-09 10:53 . 2005-10-17 23:13 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2005-10-17 23:13 735744 ----a-w c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 10:53 . 2005-10-17 23:13 685568 ----a-w c:\windows\system32\dllcache\advapi32.dll
2009-02-09 10:53 . 2005-10-17 23:13 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-06 10:39 . 2005-10-17 23:13 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2005-10-17 23:13 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-06 10:10 . 2005-10-17 23:23 227840 ----a-w c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 19:58 . 2005-10-17 23:13 56832 ----a-w c:\windows\system32\secur32.dll
2009-02-03 19:58 . 2005-10-17 23:13 56832 ----a-w c:\windows\system32\dllcache\secur32.dll
2009-01-13 20:22 . 2009-01-13 20:21 101576 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-12-21 16:05 . 2005-10-21 14:30 101576 ----a-w c:\documents and settings\gilles\Application Data\GDIPFONTCACHEV1.DAT
2008-12-20 02:54 . 2005-09-30 18:34 101576 ----a-w c:\documents and settings\gilles\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-06-12 16:45 . 2007-06-12 16:45 81920 ----a-w c:\documents and settings\gilles\Application Data\ezpinst.exe
2007-06-12 16:45 . 2007-06-12 16:45 47360 ----a-w c:\documents and settings\gilles\Application Data\pcouffin.sys
2007-05-18 00:32 . 2007-05-18 00:31 9466787 ----a-w c:\program files\open-workbench_open_workbench_1.1.4_francais_13874.zip
2005-10-04 18:08 . 2005-10-04 18:08 129 ----a-w c:\documents and settings\gilles\Local Settings\Application Data\fusioncache.dat
2006-05-03 09:06 . 2007-05-19 23:28 163328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2007-05-19 23:28 31232 --sh--r c:\windows\system32\msfDX.dll
2008-09-14 18:32 . 2008-09-14 18:32 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008091420080915\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-04-13 198160]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-03-08 53096]
"NAV CfgWiz"="c:\program files\Norton AntiVirus\CfgWiz.exe" [2006-02-02 120512]
"Symantec PIF AlertEng"="c:\program files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2004-06-29 88363]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideClock"= 0 (0x0)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll
"wave5"= serwvdrv.dll
"wave6"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave7"= serwvdrv.dll
"wave8"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0
/u?????\[u]0
/ulsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" /hide
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\WINDOWS\\System32\\FXSCLNT.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Download Express\\dep.exe"=
"c:\\Program Files\\ITUNES\\iTunes.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"c:\\Program Files\\devolo\\dlanaudioextender\\VAudioServer.exe"=
"c:\\Program Files\\devolo\\informer\\devinf.exe"=
"c:\\Program Files\\devolo\\easyshare\\easyshare.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21:UDP"= 21:UDP:filezilla
R2 gupdate1c9abb676fbff56;Service Google Update (gupdate1c9abb676fbff56);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 133104]
R3 gwiopm;gwiopm;c:\program files\My Drivers\gwiopm.sys [1998-06-03 3904]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]
S0 ppa;Pilote de filtre de port parallèle Iomega;c:\windows\system32\DRIVERS\ppa.sys [2001-08-18 17792]
S2 HPFECP13;HPFECP13; [x]
S2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\system32\drivers\npf_devolo.sys [2007-02-07 35840]
S2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe [2008-04-14 14336]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-04-12 603904]
S2 VAService;Virtual Audio Service;c:\program files\devolo\dlanaudioextender\VaudioServer.exe [2007-08-15 114688]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 A_USBETHMP;USB PowerPacket Network Adapter;c:\windows\system32\Drivers\usbethmp.sys [2004-11-22 14342]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-04-20 101936]
S3 VA;dLAN Audio extender;c:\windows\system32\drivers\vaudio.sys [2007-08-29 32256]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - aawservice
*Deregistered* - Acer Media Server
*Deregistered* - AgereModemAudio
*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - gupdate1c9abb676fbff56
*Deregistered* - helpsvc
*Deregistered* - ImapiService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LiveUpdate
*Deregistered* - LiveUpdate Notice Service
*Deregistered* - LmHosts
*Deregistered* - LVPr2Mon
*Deregistered* - LVPrcSrv
*Deregistered* - LVSrvLauncher
*Deregistered* - LVUSBSta
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - navapsvc
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NPF_devolo
*Deregistered* - NPFMntor
*Deregistered* - Npfs
*Deregistered* - NSCService
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - NwSapAgent
*Deregistered* - PartMgr
*Deregistered* - Pcouffin
*Deregistered* - Planificateur LiveUpdate automatique
*Deregistered* - PolicyAgent
*Deregistered* - ppa
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SAVRT
*Deregistered* - SAVRTPEL
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SNDSrvc
*Deregistered* - SNMP
*Deregistered* - SPBBCDrv
*Deregistered* - SPBBCSvc
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - Symantec Core LC
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - symlcbrd
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - TuneUp.ProgramStatisticsSvc
*Deregistered* - tunmp
*Deregistered* - Update
*Deregistered* - UxTuneUp
*Deregistered* - VAService
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - WinDefend
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09197a08-06d2-11db-93b6-00148543a37c}]
\Shell\AutoRun\command - RavMon.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-20 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]
2009-04-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 12:53]
2009-04-23 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 19:04]
2009-04-18 c:\windows\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - gilles.job
- c:\progra~1\NORTON~1\Navw32.exe [2006-02-05 16:00]
2009-04-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://wmua.ool.fr/cgi-bin/wmua.pl
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Télécharger en utilisant Download &Express - c:\program files\Download Express\Add_Url.htm
TCP: {7D16BDE6-769F-41FF-8EE9-316D524CFD1E} = 217.175.160.11,217.175.160.12
TCP: {D43B8ABD-4765-47E6-B7C1-54B62EE0AB3F} = 217.175.160.11,217.175.160.12
TCP: {FE5B3242-4A5A-4F8B-B899-A2969EF41C39} = 217.175.160.11,217.175.160.12
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Name-Space Handler: ftp\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: http\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
Name-Space Handler: https\HIEClickCatcher - {E131C96E-4DDB-11D4-84B8-008048B33DEA} - c:\progra~1\DOWNLO~1\mdpph.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {C771B05E-E725-4516-97A5-4CE5EB163CFB}
FF - ProfilePath - c:\documents and settings\gilles\Application Data\Mozilla\Firefox\Profiles\qtdig2vh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - qtl
FF - prefs.js: browser.startup.homepage - hxxp://wmua.ool.fr/cgi-bin/wmua.pl
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&q=
FF - component: c:\documents and settings\gilles\Application Data\Mozilla\Firefox\Profiles\qtdig2vh.default\extensions\{D249FD00-4DF9-11D9-9FDC-0080481ADA61}\components\mpint.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\gilles\Application Data\Mozilla\Firefox\Profiles\qtdig2vh.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: capability.policy.policynames - allowclipboard
FF - user.js: capability.policy.allowclipboard.sites - hxxp://mornecapot.unblog.fr/wp-admin/post-new.php
FF - user.js: capability.policy.allowclipboard.Clipboard.cutcopy - allAccess
FF - user.js: capability.policy.allowclipboard.Clipboard.paste - allAccess.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-22 23:04
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3184080246-1834691591-4250616730-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3184080246-1834691591-4250616730-1006\Software\Policies\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (S-1-5-21-3184080246-1834691591-4250616730-1006)
@Allowed: (Read) (S-1-5-21-3184080246-1834691591-4250616730-1006)
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(6088)
c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\CCSETMGR.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
c:\program files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Fichiers communs\Symantec Shared\CCPD-LC\SYMLCSVC.EXE
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
c:\program files\acer\Acer eConsole\MediaServerService.exe
c:\program files\LSI SOFTMODEM\AGRSMSVC.EXE
c:\program files\NORTON ANTIVIRUS\NAVAPSVC.EXE
c:\program files\Norton AntiVirus\IWP\NPFMntor.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\SYSTEM32\SNMP.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\program files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
.
**************************************************************************
.
Heure de fin: 2009-04-23 23:24 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-23 03:23
Avant-CF: 28 734 619 648 octets libres
Après-CF: 28 706 340 864 octets libres
Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
436 --- E O F --- 2009-04-22 21:03