Voila, j'ai fait ce que vous m'avez dit voila le rapport, et j'ai refait un scan rapide avec malwarebites mais backdoor est toujours là
ComboFix 09-06-29.02 - vince 29/06/2009 23:14:14.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3070.1922 [GMT 2:00]
Lancé depuis: C:\Users\vince\Desktop\ComboFix.exe
AV: ThreatFire *On-access scanning disabled* (Updated) {67B2B9A1-25C8-4057-962D-807958FFC9E3}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: ThreatFire *disabled* (Updated) {79E34F8F-D0AD-48d6-9223-C657C6491F67}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-28 au 2009-06-29 ))))))))))))))))))))))))))))))))))))
.
2009-06-29 21:19:36 . 2009-06-29 21:19:45 0 d-----w- C:\Users\vince\AppData\Local\temp
2009-06-29 21:19:36 . 2009-06-29 21:19:36 0 d-----w- C:\Users\Administrateur\AppData\Local\temp
2009-06-29 21:19:36 . 2009-06-29 21:19:36 0 d-----w- C:\Users\Administrateur.PC-de-vince\AppData\Local\temp
2009-06-29 20:10:04 . 2009-06-29 20:10:20 0 d-----w- C:\rsit
2009-06-29 20:10:04 . 2009-06-29 20:10:18 0 d-----w- C:\Program Files\trend micro
2009-06-28 12:00:01 . 2009-06-17 09:27:56 38160 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2009-06-28 11:59:59 . 2009-06-28 19:20:42 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-28 11:59:59 . 2009-06-17 09:27:44 19096 ----a-w- C:\Windows\system32\drivers\mbam.sys
2009-06-27 18:47:00 . 2009-06-28 20:18:31 0 d-----w- C:\Program Files\PDFConverterDesktop
2009-06-25 21:01:15 . 2009-06-25 21:01:15 0 d-----w- C:\Program Files\MSSOAP
2009-06-25 21:00:59 . 2009-06-25 21:00:59 0 d-----w- C:\Program Files\Webroot
2009-06-25 20:54:17 . 2009-06-25 20:54:23 164 ----a-w- C:\Windows\install.dat
2009-06-23 20:33:18 . 2009-06-23 20:33:18 0 d-----w- C:\Program Files\Lavalys
2009-06-16 19:21:39 . 2009-06-16 19:21:39 456304 ----a-w- C:\ProgramData\Google\Google Toolbar\Update\gtb7081.tmp.exe
2009-06-14 17:57:42 . 2009-06-14 17:57:42 0 d-----w- C:\Users\vince\AppData\Roaming\Megaupload
2009-06-14 17:52:58 . 2009-06-14 17:52:58 0 d-----w- C:\Program Files\Megaupload
2009-06-14 17:51:39 . 2009-06-14 17:51:39 0 d-----w- C:\Users\vince\AppData\Roaming\InstallShield
2009-06-13 18:51:41 . 2009-06-13 18:51:46 0 d-----w- C:\Program Files\Common Files\DivX Shared
2009-06-12 20:00:22 . 2009-06-12 20:00:22 604416 ----a-w- C:\Windows\system32\TUProgSt.exe
2009-06-12 20:00:19 . 2009-04-27 12:21:36 28928 ----a-w- C:\Windows\system32\uxtuneup.dll
2009-06-12 20:00:18 . 2009-04-27 12:21:44 17152 ----a-w- C:\Windows\system32\authuitu.dll
2009-06-12 20:00:13 . 2009-06-12 20:00:13 361216 ----a-w- C:\Windows\system32\TuneUpDefragService.exe
2009-06-12 19:59:54 . 2009-06-12 19:59:54 0 d-----w- C:\Users\vince\AppData\Roaming\TuneUp Software
2009-06-12 19:59:07 . 2009-06-12 19:59:42 0 d-----w- C:\Program Files\TuneUp Utilities 2009
2009-06-12 19:59:04 . 2009-06-12 19:59:04 0 d-----w- C:\ProgramData\TuneUp Software
2009-06-12 19:58:21 . 2009-06-12 19:58:21 0 d-sh--w- C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-12 17:20:14 . 2009-06-12 17:20:14 0 d-----w- C:\Program Files\JRE
2009-06-09 21:56:48 . 2009-06-09 21:58:01 0 d-----w- C:\Users\vince\AppData\Roaming\vlc
2009-06-07 12:15:44 . 2009-06-07 12:15:44 0 d-----w- C:\ProgramData\TechSmith
2009-06-07 12:15:39 . 2009-06-07 12:15:39 0 d-----w- C:\Users\vince\AppData\Local\TechSmith
2009-06-07 12:15:39 . 2009-06-07 12:15:39 0 d-----w- C:\Program Files\TechSmith
2009-06-07 12:05:13 . 2009-06-07 12:06:01 25354165 ----a-w- C:\Users\vince\AppData\Roaming\OpenCandy\SnagItWrapperfr.exe
2009-06-07 12:05:13 . 2009-06-07 12:05:13 0 d-----w- C:\Users\vince\AppData\Roaming\OpenCandy
2009-06-03 20:57:22 . 2009-06-03 20:57:22 0 d-----w- C:\ProgramData\WindowsSearch
2009-06-03 19:10:39 . 2009-06-07 11:47:21 0 d-----w- C:\Users\vince\AppData\Roaming\FrostWire
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 20:57:48 . 2008-10-22 09:05:26 12 ----a-w- C:\Windows\bthservsdp.dat
2009-06-29 19:49:54 . 2009-05-29 17:06:53 0 d-----w- C:\Program Files\ZebHelpProcess
2009-06-29 13:03:39 . 2009-04-01 17:09:13 1356 ----a-w- C:\Users\vince\AppData\Local\d3d9caps.dat
2009-06-29 10:45:06 . 2009-02-15 01:02:10 0 d-----w- C:\ProgramData\Spybot - Search & Destroy
2009-06-29 10:41:19 . 2009-04-29 18:07:38 0 d-----w- C:\Program Files\SpywareBlaster
2009-06-28 21:45:10 . 2009-05-17 20:26:28 0 d-----w- C:\Program Files\totalcmd
2009-06-28 21:43:19 . 2009-02-14 12:51:26 1 ----a-w- C:\Users\vince\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-28 20:14:54 . 2009-05-30 11:33:30 0 d-----w- C:\Users\vince\AppData\Roaming\Spyware Terminator
2009-06-28 20:14:54 . 2009-05-30 11:33:27 0 d-----w- C:\Program Files\Spyware Terminator
2009-06-28 19:40:22 . 2008-10-22 18:46:25 669566 ----a-w- C:\Windows\system32\perfh00C.dat
2009-06-28 19:40:22 . 2008-10-22 18:46:25 123556 ----a-w- C:\Windows\system32\perfc00C.dat
2009-06-28 15:37:25 . 2009-05-03 16:50:54 0 d-----w- C:\ProgramData\RFA_backups
2009-06-28 15:20:05 . 2009-03-26 11:47:31 0 d-----w- C:\ProgramData\Lavasoft
2009-06-28 15:20:05 . 2009-03-26 11:47:31 0 d-----w- C:\Program Files\Lavasoft
2009-06-28 15:19:06 . 2009-04-21 18:17:00 0 d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2009-06-28 13:19:20 . 2009-02-22 21:01:29 0 d-----w- C:\ProgramData\Avira
2009-06-28 11:57:30 . 2009-05-30 12:36:42 0 d-----w- C:\Program Files\WinClamAVShield
2009-06-26 19:02:53 . 2009-05-30 11:33:27 0 d-----w- C:\ProgramData\Spyware Terminator
2009-06-24 19:02:52 . 2009-05-26 20:20:06 0 d-----w- C:\Program Files\ThreatFire
2009-06-21 19:48:56 . 2009-02-12 23:51:58 0 d-----w- C:\Users\vince\AppData\Roaming\dvdcss
2009-06-21 19:29:06 . 2009-03-03 19:13:27 0 d-----w- C:\Program Files\DivX
2009-06-21 19:11:48 . 2009-05-22 21:31:17 0 d-----w- C:\Program Files\a-squared Free
2009-06-19 20:37:29 . 2009-05-26 20:20:06 46864 ----a-w- C:\Windows\system32\drivers\TfSysMon.sys
2009-06-19 20:37:28 . 2009-05-26 20:20:06 33552 ----a-w- C:\Windows\system32\drivers\TfNetMon.sys
2009-06-19 20:37:27 . 2009-05-26 20:20:06 51984 ----a-w- C:\Windows\system32\drivers\TfFsMon.sys
2009-06-16 15:37:44 . 2009-04-28 17:35:00 0 d-----w- C:\Program Files\Unlocker
2009-06-14 17:52:57 . 2008-10-22 09:17:33 0 d--h--w- C:\Program Files\InstallShield Installation Information
2009-06-12 17:26:35 . 2009-02-11 19:51:07 73568 ----a-w- C:\Users\vince\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-12 17:22:27 . 2009-02-11 20:52:35 0 d-----w- C:\Program Files\OpenOffice.org 3
2009-06-09 21:55:01 . 2009-02-11 21:00:36 0 d-----w- C:\Program Files\VideoLAN
2009-06-07 12:04:59 . 2009-02-11 20:58:36 0 d-----w- C:\Program Files\VDOWNLOADER
2009-06-07 12:04:51 . 2009-04-28 17:35:01 0 d-----w- C:\Users\vince\AppData\Roaming\Desktopicon
2009-05-30 11:33:31 . 2009-05-30 11:33:31 6144 ----a-w- C:\ProgramData\Spyware Terminator\sp_rsdel.exe
2009-05-30 11:33:30 . 2009-05-30 11:33:30 5632 ----a-w- C:\ProgramData\Spyware Terminator\fileobjinfo.sys
2009-05-30 11:33:30 . 2009-05-30 11:33:30 142592 ----a-w- C:\Windows\system32\drivers\sp_rsdrv2.sys
2009-05-29 18:02:04 . 2009-05-26 20:20:06 0 d-----w- C:\ProgramData\PC Tools
2009-05-29 17:07:29 . 2009-05-29 17:07:29 0 d-----w- C:\Program Files\Common Files\Borland Shared
2009-05-27 10:57:28 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Calendar
2009-05-27 10:57:28 . 2006-11-02 11:18:33 0 d-----w- C:\Program Files\Windows Mail
2009-05-27 10:57:27 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Sidebar
2009-05-27 10:57:26 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Journal
2009-05-27 10:57:26 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Collaboration
2009-05-27 10:57:25 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Photo Gallery
2009-05-27 10:57:22 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Defender
2009-05-27 10:56:36 . 2006-11-02 10:25:05 665600 ----a-w- C:\Windows\inf\drvindex.dat
2009-05-22 20:41:12 . 2009-05-17 20:26:28 0 d-----w- C:\Users\vince\AppData\Roaming\GHISLER
2009-05-16 18:28:09 . 2009-05-16 18:28:09 0 d-----w- C:\ProgramData\AVS4YOU
2009-05-16 18:27:41 . 2009-05-16 18:27:18 0 d-----w- C:\Program Files\AVS4YOU
2009-05-16 18:27:39 . 2009-03-03 12:10:38 0 d-----w- C:\Program Files\Common Files\AVSMedia
2009-05-16 11:01:35 . 2009-05-15 20:44:16 0 d-----w- C:\Users\vince\AppData\Roaming\NeoDivX2008
2009-05-15 20:57:07 . 2009-05-15 20:52:24 0 d-----w- C:\Program Files\NeoDivX2009
2009-05-15 20:52:31 . 2009-05-15 20:52:24 0 d-----w- C:\Users\vince\AppData\Roaming\NeoDivX2009
2009-05-15 10:37:11 . 2009-05-15 10:37:11 0 d-----w- C:\ProgramData\SlySoft
2009-05-09 05:50:28 . 2009-06-10 11:02:42 915456 ----a-w- C:\Windows\system32\wininet.dll
2009-05-09 05:34:34 . 2009-06-10 11:02:40 71680 ----a-w- C:\Windows\system32\iesetup.dll
2009-05-06 23:14:16 . 2009-05-06 23:14:16 27977008 ----a-w- C:\Windows\system32\snagitfr.exe
2009-05-05 20:56:51 . 2009-02-17 22:41:27 0 d-----w- C:\Program Files\RegSeeker
2009-05-05 20:38:41 . 2009-05-05 20:38:41 0 d-----w- C:\Program Files\VS Revo Group
2009-05-04 21:09:57 . 2009-05-04 21:09:57 0 d-----w- C:\Users\vince\AppData\Roaming\Avira
2009-05-04 21:04:13 . 2009-05-04 21:04:13 0 d-----w- C:\Program Files\Avira
2009-05-04 21:02:43 . 2009-05-04 21:04:14 96104 ----a-w- C:\Windows\system32\drivers\avipbb.sys
2009-05-04 21:02:42 . 2009-05-04 21:04:14 55640 ----a-w- C:\Windows\system32\drivers\avgntflt.sys
2009-05-01 21:02:28 . 2009-05-01 21:02:28 90112 ----a-w- C:\Windows\system32\dpl100.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 823296 ----a-w- C:\Windows\system32\divx_xx0c.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 823296 ----a-w- C:\Windows\system32\divx_xx07.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 815104 ----a-w- C:\Windows\system32\divx_xx0a.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 811008 ----a-w- C:\Windows\system32\divx_xx16.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 802816 ----a-w- C:\Windows\system32\divx_xx11.dll
2009-05-01 21:02:26 . 2009-05-01 21:02:26 685056 ----a-w- C:\Windows\system32\DivX.dll
2009-05-01 20:22:43 . 2009-05-01 20:22:43 0 d-----w- C:\Users\vince\AppData\Roaming\Malwarebytes
2009-05-01 20:22:37 . 2009-05-01 20:22:37 0 d-----w- C:\ProgramData\Malwarebytes
2009-05-01 15:47:24 . 2009-05-01 15:47:24 0 d-----w- C:\Users\vince\AppData\Roaming\FreeLanguageTranslator
2009-05-01 15:47:12 . 2009-05-01 15:47:11 98534 ----a-r- C:\Users\vince\AppData\Roaming\Microsoft\Installer\{420058C0-ACDE-4FC1-980C-F3823E9F1BA7}\_7D51EA2244C5115E67DCCF.exe
2009-05-01 15:47:11 . 2009-05-01 15:47:12 0 d-----w- C:\Program Files\FreeLanguageTranslator
2009-05-01 15:47:11 . 2009-05-01 15:47:11 98534 ----a-r- C:\Users\vince\AppData\Roaming\Microsoft\Installer\{420058C0-ACDE-4FC1-980C-F3823E9F1BA7}\_C9D4E05D763437E2020F76.exe
2009-05-01 15:47:11 . 2009-05-01 15:47:11 98534 ----a-r- C:\Users\vince\AppData\Roaming\Microsoft\Installer\{420058C0-ACDE-4FC1-980C-F3823E9F1BA7}\_6FEFF9B68218417F98F549.exe
2009-05-01 15:47:11 . 2009-05-01 15:47:11 1078 ----a-r- C:\Users\vince\AppData\Roaming\Microsoft\Installer\{420058C0-ACDE-4FC1-980C-F3823E9F1BA7}\_8FB0A1AF382AEC832DA851.exe
2009-04-29 10:38:43 . 2009-04-29 10:38:43 86576 ----a-w- C:\Users\vince\AppData\Roaming\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2009-04-29 10:38:43 . 2009-04-29 10:38:43 392728 ----a-w- C:\Users\vince\AppData\Roaming\Microsoft\Services Windows Live\Services Windows Live.dll
2009-04-29 10:38:43 . 2009-04-29 10:38:43 132672 ----a-w- C:\Users\vince\AppData\Roaming\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2009-04-23 21:00:45 . 2009-02-26 18:34:13 472 ----a-w- C:\Users\vince\AppData\Roaming\wklnhst.dat
2009-04-23 12:15:07 . 2009-06-10 11:02:36 784896 ----a-w- C:\Windows\system32\rpcrt4.dll
2009-04-23 12:14:10 . 2009-06-10 11:02:38 623616 ----a-w- C:\Windows\system32\localspl.dll
2009-04-21 11:39:47 . 2009-06-10 11:02:45 2034688 ----a-w- C:\Windows\system32\win32k.sys
2009-04-17 14:58:28 . 2009-04-21 18:30:52 954368 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-04-17 14:58:28 . 2009-04-21 18:30:52 103424 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-04-17 14:58:28 . 2009-04-21 18:30:48 344064 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-04-17 14:58:26 . 2009-04-21 18:30:52 1161626 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\avcodec-51.dll
2009-04-17 14:58:26 . 2009-04-21 18:30:51 65536 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-04-17 14:58:26 . 2009-04-21 18:30:49 71652 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\avutil-49.dll
2009-04-17 14:58:26 . 2009-04-21 18:30:49 4579328 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\cooliris18.dll
2009-04-17 14:58:26 . 2009-04-21 18:30:49 4534272 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-04-17 14:58:26 . 2009-04-21 18:30:48 131868 ----a-w- C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\libs\avformat-52.dll
2009-04-12 14:25:57 . 2009-04-12 14:25:57 0 ----a-w- C:\Windows\nsreg.dat
2009-04-11 06:33:19 . 2009-05-27 10:41:11 986600 ----a-w- C:\Windows\system32\winload.exe
2009-04-11 06:33:19 . 2009-05-27 10:40:51 926184 ----a-w- C:\Windows\system32\winresume.exe
2009-04-11 06:33:03 . 2009-05-27 10:40:30 292840 ----a-w- C:\Windows\system32\drivers\volmgrx.sys
2009-04-11 06:33:02 . 2009-05-27 10:41:09 897000 ----a-w- C:\Windows\system32\drivers\tcpip.sys
2009-04-11 06:33:02 . 2009-05-27 10:40:56 614376 ----a-w- C:\Windows\system32\ci.dll
2009-04-11 06:28:28 . 2009-05-27 10:40:54 56320 ----a-w- C:\Windows\system32\xmlfilter.dll
2009-05-01 21:02:48 . 2009-05-01 21:02:48 1044480 ----a-w- C:\Program Files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02:48 . 2009-05-01 21:02:48 200704 ----a-w- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
2008-10-22 18:49:46 . 2008-10-22 18:49:44 8192 --sha-w- C:\Windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-29_20.59.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-29 20:58:37 . 2009-06-29 20:58:37 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-23 23:30:17 . 2009-06-29 20:59:38 262144 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-02-23 23:30:17 . 2009-06-29 20:58:51 262144 C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnhancedStorageShell]
@="{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}"
[HKEY_CLASSES_ROOT\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}]
2009-04-11 06:28:19 114176 ----a-w- C:\Windows\System32\EhStorShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 02:25:11 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 15:41:12 178712]
"HControlUser"="C:\Program Files\ATK Hotkey\HcontrolUser.exe" [2008-01-11 20:40:10 98304]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 10:17:18 61440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-06 11:04:20 1041704]
"RtHDVCpl"="RtHDVCpl.exe" - C:\Windows\RtHDVCpl.exe [2008-06-13 05:52:52 6183456]
"Skytel"="Skytel.exe" - C:\Windows\SkyTel.exe [2007-11-20 10:15:58 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"BindDirectlyToPropertySetStorage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0SsiEfr.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^vince^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe"
"toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):a4,0c,ce,8b,ba,de,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A72F6AF9-0AC5-4273-A9B3-1DB241E1FC84}"= UDP:C:\Program Files\eMule\emule.exe:eMule
"{BB2069BC-52EB-47D4-B0EB-2726049EBF3E}"= TCP:C:\Program Files\eMule\emule.exe:eMule
"TCP Query User{F0960BB4-C161-40E8-BC61-F781A4FD809B}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{8CD664D3-EDCE-48E4-AFE9-5992E17A0060}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"{C56D9643-C10F-4F40-ADA9-EE6037D6F69E}"= UDP:C:\Program Files\a-squared Free\a2free.exe:a-squared Free
"{88E0FFA0-5015-4E48-834E-4FE2001F3C3E}"= TCP:C:\Program Files\a-squared Free\a2free.exe:a-squared Free
"TCP Query User{1754B518-2C19-4715-AFA2-84329AAEBD6D}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{7C17D77E-7CDC-454E-BD7A-84BE2F3FC54F}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"TCP Query User{D095A04C-F068-40A6-B58C-AE5D44D77042}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{E74733D2-7AEF-414C-BAFB-0255DDF48B43}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R0 TfFsMon;TfFsMon;C:\Windows\System32\drivers\TfFsMon.sys [26/05/2009 22:20:06 51984]
R0 TfSysMon;TfSysMon;C:\Windows\System32\drivers\TfSysMon.sys [26/05/2009 22:20:06 46864]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\System32\drivers\sp_rsdrv2.sys [30/05/2009 13:33:30 142592]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 00:45:04 124832]
R2 AntiVirMailService;Avira AntiVir MailGuard;C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [04/05/2009 23:04:13 194817]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;C:\Program Files\Avira\AntiVir Desktop\sched.exe [04/05/2009 23:04:14 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe [04/05/2009 23:04:13 432897]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [21/01/2008 04:23:43 21504]
R2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [28/06/2009 14:00:04 195856]
R2 ThreatFire;ThreatFire;C:\Program Files\ThreatFire\TFService.exe service --> C:\Program Files\ThreatFire\TFService.exe service [?]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\System32\drivers\itecir.sys [22/10/2008 11:25:47 54784]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [28/06/2009 13:59:59 19096]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;C:\Windows\System32\drivers\NETw5v32.sys [18/07/2008 12:47:23 3662848]
R3 TfNetMon;TfNetMon;C:\Windows\System32\drivers\TfNetMon.sys [26/05/2009 22:20:06 33552]
R3 X10Hid;X10 Hid Device;C:\Windows\System32\drivers\x10hid.sys [22/10/2008 11:28:57 13976]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [22/10/2008 11:59:21 24064]
S4 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [10/03/2009 20:21:52 1153368]
S4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;C:\Windows\System32\TUProgSt.exe [12/06/2009 22:00:22 604416]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-06-28 C:\Windows\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42:06 . 2009-04-27 13:42:06]
2009-06-29 C:\Windows\Tasks\Malwarebytes' Scheduled Scan for vince.job
- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-06-28 12:00:01 . 2009-06-17 09:27:48]
2009-06-28 C:\Windows\Tasks\Malwarebytes' Scheduled Update for vince.job
- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-06-28 12:00:01 . 2009-06-17 09:27:48]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
LSP: C:\Program Files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://france.meteofrance.com/france/meteo?PREVISIONS_PORTLET.path=previsionsville%2F470010%2F|http://mail2.voila.fr/webmail/fr_FR/inbox.html?PAGE=1&FromSubmit=true
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - component: C:\Users\vince\AppData\Roaming\Mozilla\Firefox\Profiles\p3akc9he.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Java Console: No Registry Reference - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-29 23:19:45
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
C:\Users\vince\AppData\Local\Temp\catchme.dll 53248 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,49,e1,ac,6f,1f,4b,09,49,83,29,a2,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,49,e1,ac,6f,1f,4b,09,49,83,29,a2,\
[HKEY_LOCAL_MACHINE\software\Classes\Applications\WINWORD.EXE\TaskbarExceptionsIcons]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{46B89F5A-769D-4792-AD9A-E3755915CBC3}\ProxyStubClsid]
@DACL=(02 0000)
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{46B89F5A-769D-4792-AD9A-E3755915CBC3}\ProxyStubClsid32]
@DACL=(02 0000)
@="{00020420-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{46B89F5A-769D-4792-AD9A-E3755915CBC3}\TypeLib]
@DACL=(02 0000)
"Version"="1.0"
@="{47A7A4B0-2723-41BA-865E-EBBB7081A602}"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(712)
C:\Program Files\ThreatFire\TFWAH.dll
- - - - - - - > 'lsass.exe'(660)
C:\Program Files\ThreatFire\TFWAH.dll
- - - - - - - > 'Explorer.exe'(4004)
C:\Program Files\ThreatFire\TFWAH.dll
C:\Windows\system32\PortableDeviceTypes.dll
.
Heure de fin: 2009-06-29 23:23:34
ComboFix-quarantined-files.txt 2009-06-29 21:23:30
Avant-CF: 195 539 226 624 octets libres
Après-CF: 195 428 786 176 octets libres
318 --- E O F --- 2009-06-24 10:57:47