Donc voilà, j'ai effectué ce que tu m'as dit et voici le résultat :
ComboFix 09-07-05.01 - Pauline 05/07/2009 23:05.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.352.1036.18.2008.1297 [GMT 2:00]
Lancé depuis: c:\users\Pauline\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1243321965-3589882168-3296649825-1001
c:\$recycle.bin\S-1-5-21-75162790-1064007011-202293021-500
c:\windows\Installer\216b4.msi
c:\windows\Installer\51473e7.msi
c:\windows\system32\drivers\msqpdxmbcbcrrx.sys
c:\windows\system32\drivers\SKYNETysnjrfmw.sys
c:\windows\system32\msqpdxrfppntlv.dll
c:\windows\system32\msqpdxwqsctmei.dll
c:\windows\TEMP\jqoypqbkks.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSQPDXSERV.SYS
-------\Service_Boonty Games
-------\Legacy_msqpdxserv.sys
-------\Service_AeLookupSvcAGWinService
-------\Service_msqpdxserv.sys
-------\Service_SKYNETdpqnugyp
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-05 au 2009-07-05 ))))))))))))))))))))))))))))))))))))
.
2009-07-05 07:04 . 2009-07-05 07:04 -------- d-----w- c:\users\Invité
2009-07-04 22:39 . 2009-07-05 20:54 18944 ----a-w- c:\windows\system32\SKYNETqptuupdn.dll
2009-07-04 22:18 . 2009-07-04 22:18 -------- d-----w- c:\users\Pauline\AppData\Roaming\Samsung
2009-07-04 21:59 . 2007-05-02 09:12 15112 ----a-w- c:\windows\system32\drivers\ssm_mdfl.sys
2009-07-04 21:59 . 2007-05-02 09:12 12424 ----a-w- c:\windows\system32\drivers\ssm_whnt.sys
2009-07-04 21:59 . 2007-05-02 09:12 12424 ----a-w- c:\windows\system32\drivers\ssm_wh.sys
2009-07-04 21:59 . 2007-05-02 09:12 109704 ----a-w- c:\windows\system32\drivers\ssm_mdm.sys
2009-07-04 21:59 . 2007-05-02 09:12 83592 ----a-w- c:\windows\system32\drivers\ssm_bus.sys
2009-07-04 21:59 . 2007-05-02 09:12 12424 ----a-w- c:\windows\system32\drivers\ssm_cmnt.sys
2009-07-04 21:59 . 2007-05-02 09:12 12424 ----a-w- c:\windows\system32\drivers\ssm_cm.sys
2009-07-04 21:58 . 2009-07-04 22:39 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-07-04 21:57 . 2006-07-24 14:05 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-07-04 21:57 . 2009-07-04 21:57 -------- d-----w- c:\program files\Samsung
2009-06-29 04:45 . 2009-07-05 20:54 93 ----a-w- c:\windows\system32\SKYNETerrmifpw.dat
2009-06-29 04:40 . 2009-06-29 04:40 -------- d-----w- c:\program files\LeeGTs Games
2009-06-29 04:38 . 2009-07-05 21:11 102613 ----a-w- c:\windows\system32\SKYNEToxxqxtbs.dat
2009-06-29 04:38 . 2009-06-29 04:38 45056 ----a-w- c:\windows\system32\SKYNETpvpptmky.dll
2009-06-16 19:26 . 2009-06-16 19:26 -------- d-----w- c:\program files\Kiwee Toolbar
2009-06-16 19:26 . 2009-06-16 19:26 -------- d-----w- c:\programdata\Kiwee Toolbar
2009-06-16 19:25 . 2009-06-16 19:26 -------- d-----w- c:\users\Pauline\AppData\Roaming\agi
2009-06-16 19:25 . 2009-06-16 19:25 339968 ----a-w- c:\windows\system32\pythoncom25.dll
2009-06-16 19:25 . 2009-06-16 19:25 2117632 ----a-w- c:\windows\system32\python25.dll
2009-06-16 19:25 . 2009-06-16 19:25 114688 ----a-w- c:\windows\system32\pywintypes25.dll
2009-06-16 19:24 . 2008-09-16 16:26 1332197 ----a-w- c:\windows\system32\pythondll.zip
2009-06-16 19:24 . 2009-06-16 19:25 -------- d-----w- c:\programdata\AGI
2009-06-16 19:24 . 2009-06-16 19:24 -------- d-----w- c:\program files\AGI
2009-06-14 20:42 . 2009-07-04 18:57 -------- d-----w- c:\users\Pauline\AppData\Roaming\Sony
2009-06-14 20:42 . 2009-06-14 20:42 -------- d-----w- c:\programdata\Sony
2009-06-14 20:41 . 2009-07-04 18:57 -------- d-----w- c:\users\Pauline\AppData\Local\Sony
2009-06-14 20:39 . 2009-06-14 20:39 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-06-14 20:35 . 2009-06-14 20:37 -------- d-----w- c:\program files\QuickTime
2009-06-14 08:32 . 2009-06-14 08:32 -------- d-----w- c:\program files\Rockstar Games
2009-06-13 14:49 . 2009-06-13 14:49 -------- d-----w- c:\programdata\BVRP Software
2009-06-13 14:25 . 2008-05-16 10:33 25512 ----a-w- c:\windows\system32\drivers\s0016nd5.sys
2009-06-13 14:25 . 2008-05-16 10:33 15016 ----a-w- c:\windows\system32\drivers\s0016mdfl.sys
2009-06-13 14:25 . 2008-05-16 10:33 115752 ----a-w- c:\windows\system32\drivers\s0016unic.sys
2009-06-13 14:25 . 2008-05-16 10:33 89256 ----a-w- c:\windows\system32\drivers\s0016bus.sys
2009-06-13 14:25 . 2008-05-16 10:33 12200 ----a-w- c:\windows\system32\drivers\s0016whnt.sys
2009-06-13 14:25 . 2008-05-16 10:33 12200 ----a-w- c:\windows\system32\drivers\s0016wh.sys
2009-06-13 14:25 . 2008-05-16 10:33 12200 ----a-w- c:\windows\system32\drivers\s0016cmnt.sys
2009-06-13 14:25 . 2008-05-16 10:33 12200 ----a-w- c:\windows\system32\drivers\s0016cm.sys
2009-06-13 14:25 . 2008-05-16 10:33 120744 ----a-w- c:\windows\system32\drivers\s0016mdm.sys
2009-06-13 14:25 . 2008-05-16 10:33 114216 ----a-w- c:\windows\system32\drivers\s0016mgmt.sys
2009-06-13 14:25 . 2008-05-16 10:33 110632 ----a-w- c:\windows\system32\drivers\s0016obex.sys
2009-06-13 14:25 . 2008-05-16 10:33 10792 ----a-w- c:\windows\system32\drivers\s0016cr.sys
2009-06-12 19:21 . 2009-06-12 19:22 -------- d-----w- c:\users\Pauline\AppData\Local\Ludi
2009-06-12 19:21 . 2009-06-12 19:21 -------- d-----w- c:\program files\Ludi
2009-06-11 13:26 . 2009-04-24 16:05 827904 ----a-w- c:\windows\system32\wininet.dll
2009-06-11 13:26 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-11 13:26 . 2009-04-24 13:44 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-11 12:51 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-11 12:45 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-06-11 12:40 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-09 14:12 . 2009-06-09 14:12 -------- d-----w- c:\program files\uTorrent
2009-06-09 14:11 . 2009-07-04 22:08 -------- d-----w- c:\users\Pauline\AppData\Roaming\uTorrent
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-05 21:16 . 2009-07-05 21:16 421 ----a-w- c:\windows\system32\SKYNETiobjxenu.dat
2009-07-05 21:07 . 2008-05-26 15:53 669566 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-05 21:07 . 2008-05-26 15:53 123556 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-05 20:56 . 2008-10-10 18:02 1356 ----a-w- c:\users\Pauline\AppData\Local\d3d9caps.dat
2009-07-05 19:36 . 2009-02-08 11:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-05 19:36 . 2009-02-08 11:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-07-05 19:10 . 2008-05-26 06:48 -------- d-----w- c:\program files\Google
2009-07-05 19:10 . 2008-05-26 06:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-05 19:08 . 2008-10-12 19:27 -------- d-----w- c:\users\Pauline\AppData\Roaming\skypePM
2009-07-04 18:59 . 2008-10-21 19:08 -------- d-----w- c:\program files\Sony
2009-07-02 19:50 . 2008-10-13 21:24 1 ----a-w- c:\users\Pauline\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-30 23:21 . 2008-11-07 11:48 -------- d-----w- c:\users\Pauline\AppData\Roaming\dvdcss
2009-06-30 00:06 . 2008-10-09 20:53 -------- d-----w- c:\program files\Windows Live
2009-06-25 20:58 . 2008-10-12 19:26 -------- d-----w- c:\users\Pauline\AppData\Roaming\Skype
2009-06-14 20:35 . 2008-11-18 17:48 -------- d-----w- c:\programdata\Apple Computer
2009-06-13 14:18 . 2008-05-26 06:31 -------- d-----w- c:\program files\Common Files\InstallShield
2009-06-10 17:58 . 2009-05-28 12:07 -------- d-----w- c:\program files\Warcraft III
2009-05-28 12:25 . 2009-05-28 12:12 55358 ----a-w- c:\windows\War3Unin.dat
2009-05-28 12:25 . 2009-05-28 12:12 2829 ----a-w- c:\windows\War3Unin.pif
2009-05-28 12:25 . 2009-05-28 12:12 139264 ----a-w- c:\windows\War3Unin.exe
2009-05-24 21:28 . 2009-05-24 21:27 -------- d-----r- c:\program files\Skype
2009-05-24 21:28 . 2009-05-24 21:28 -------- d-----w- c:\program files\Common Files\Skype
2009-05-24 21:28 . 2008-05-26 07:17 -------- d-----w- c:\programdata\Skype
2009-05-21 17:01 . 2008-12-22 18:47 -------- d-----w- c:\program files\DivX
2009-05-21 17:01 . 2008-10-21 19:13 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-05-21 17:00 . 2009-05-21 16:59 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-05-21 12:53 . 2009-05-21 12:53 -------- d-----w- c:\program files\Chaos Shredder2.3FR
2009-05-20 21:03 . 2008-12-15 21:36 -------- d-----w- c:\users\Pauline\AppData\Roaming\ESTsoft
2009-05-20 21:03 . 2009-05-20 21:02 -------- d-----w- c:\program files\ESTsoft
2009-05-14 01:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-09 08:33 . 2009-05-09 08:33 -------- d-----w- c:\program files\Avira
2009-05-09 08:33 . 2009-04-07 06:57 -------- d-----w- c:\programdata\Avira
2009-04-23 20:28 . 2009-04-23 20:27 21878064 ----a-w- c:\users\Pauline\AppData\Roaming\Sony Setup\A189E68E-2253-4C3B-86B7-D77E36F13C55\QuickTimeInstaller.exe
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w- c:\windows\system32\DivX.dll
2008-06-30 11:44 . 2008-10-10 05:16 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-05-26 15:58 . 2008-05-26 15:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2009-06-16 19:26 277648 ----a-w- c:\program files\Kiwee Toolbar\2.9.201\KiweeIEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Does wait"="c:\programdata\mapi rule rule.rbrxv" [X]
"Hope Draw Obj Funk"="c:\programdata\HOPE LIES DART.l4op9a7" [X]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2008-02-04 1038136]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"Speech Recognition"="c:\windows\Speech\Common\sapisvr.exe" [2008-01-21 49664]
"Google Update"="c:\users\Pauline\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-12-05 133104]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-11 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-11 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-11 145944]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-08 894512]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-26 29744]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-28 198160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"KiweeHook"="c:\program files\Kiwee Toolbar\2.9.201\kwtbaim.exe" [2009-06-16 56456]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-06-27 6295552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{21AEC2E7-FEE5-47FD-BB06-BA93600638EA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{769EDCAB-AA23-4F50-AE37-D6B23D09AE7B}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1F20F986-497B-4045-ABBA-5A98D5B27A05}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{68DB0F74-AC44-4DB0-B62D-6D8FA4C93A83}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{7B6CE150-E3DA-42AE-9774-650A5DD88C01}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule Plus
"UDP Query User{330A880B-300E-4EE0-BDFE-9B3B1BE39849}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule Plus
"TCP Query User{C550615A-4F0E-4732-B148-0EE7A9B952AE}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Packard Bell - Skype
"UDP Query User{CA001725-C64F-4363-A426-98D44B951943}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Packard Bell - Skype
"{3B8FFFBB-C972-47F6-BD28-15D97DD551A9}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{8DC75970-59CB-4989-92E6-0C3DF54FCFEB}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{BED62AC2-D99B-4F2D-8062-30CD3150736E}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"TCP Query User{40B030FC-38DF-4493-84F5-51999FCCB504}c:\\ut2004\\system\\ut2004.exe"= UDP:c:\ut2004\system\ut2004.exe:UT2004
"UDP Query User{86AA4F51-44B0-45FB-9DBC-A09655FEA866}c:\\ut2004\\system\\ut2004.exe"= TCP:c:\ut2004\system\ut2004.exe:UT2004
"{C55D61F4-A160-4B2F-99ED-CAFBAF1ABEAE}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{D2FE08EB-D132-4862-A942-A853367BDD2C}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{43204573-6B06-4303-9AE3-3653AD56756A}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III
"{5F7B623A-4F43-4381-9236-B4F00BAD88DF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{C1B43801-204F-45FF-B358-784ABDF97736}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{C019811F-D531-431D-BBF8-07845CAF14C4}"= UDP:44535:Torrent
"{8F3BAC46-AD77-46C6-A406-BEED2F8B0877}"= TCP:44535:Torrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [16/06/2009 21:25 10240]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [09/05/2009 10:33 108289]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 04:33 21504]
R3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr73.sys [26/05/2008 17:46 489984]
R3 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [13/05/2008 06:48 51288]
R3 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [13/05/2008 03:48 43736]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\System32\drivers\IcdUsb2.sys [21/10/2008 21:09 39048]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\System32\drivers\s0016bus.sys [13/06/2009 16:25 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\System32\drivers\s0016mdfl.sys [13/06/2009 16:25 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\System32\drivers\s0016mdm.sys [13/06/2009 16:25 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s0016mgmt.sys [13/06/2009 16:25 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\System32\drivers\s0016nd5.sys [13/06/2009 16:25 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\System32\drivers\s0016obex.sys [13/06/2009 16:25 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\System32\drivers\s0016unic.sys [13/06/2009 16:25 115752]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - Ndisprot.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenu du dossier 'Tâches planifiées'
2009-07-05 c:\windows\Tasks\Extension de garantie-Pauline.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-05-26 10:13]
2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1243321965-3589882168-3296649825-1000Core.job
- c:\users\Pauline\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-05 06:21]
2009-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1243321965-3589882168-3296649825-1000UA.job
- c:\users\Pauline\AppData\Local\Google\Update\GoogleUpdate.exe [2008-12-05 06:21]
2009-07-05 c:\windows\Tasks\User_Feed_Synchronization-{7DD4461A-AF1A-409F-A9A7-CE23A63F1F23}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
2009-07-05 c:\windows\Tasks\User_Feed_Synchronization-{A7BEE8AB-23DD-48DE-8AF7-A0AA78AFE1E7}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
.
.
------- Examen supplémentaire -------
.
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\Pauline\AppData\Roaming\Mozilla\Firefox\Profiles\gt3se141.default\
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\users\Pauline\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-05 23:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\Pauline\AppData\Local\Temp\~DF730D.tmp 16384 bytes
c:\users\Pauline\AppData\Local\Temp\~DF7D54.tmp 512 bytes
c:\users\Pauline\AppData\Roaming\Microsoft\Windows\Cookies\pauline@kiwee[1].txt 1243 bytes
c:\users\Pauline\AppData\Roaming\Microsoft\Windows\Cookies\pauline@www1.kiwee[2].txt 542 bytes
Scan terminé avec succès
Fichiers cachés: 4
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SKYNETdpqnugyp]
"imagepath"="\systemroot\system32\drivers\SKYNETysnjrfmw.sys"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SKYNETdpqnugyp]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\SKYNETysnjrfmw.sys"
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\O2Micro Flash Memory Card Driver\o2flash.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\conime.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Heure de fin: 2009-07-05 23:27 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-05 21:27
Avant-CF: 97 595 076 608 octets libres
Après-CF: 97 615 900 672 octets libres
312 --- E O F --- 2009-07-02 16:41