Re-bonjour,
voici le rapport,
Encore merci pour ton aide !
ComboFix 09-07-14.08 - Besancenot 17/07/2009 18:09.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3536.3102 [GMT 2:00]
Running from: c:\documents and settings\Besancenot\Bureau\ComboFi.exe
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Besancenot\Application Data\inst.exe
c:\windows\system32\drivers\ESQULdotawuvpwmpfminhmtqmtaoyppxbpkmc.sys
c:\windows\system32\ESQULjajnjwkdxedddxwootkylgineykyeqpw.dll
c:\windows\system32\ESQULxvfpyyilmxcwjrxeiqldpjkjtluuaxni.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ESQULserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-17 to 2009-07-17 )))))))))))))))))))))))))))))))
.
2009-07-17 06:58 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-07-16 20:22 . 2009-07-16 20:22 -------- d-----w- c:\program files\ESET
2009-07-16 20:02 . 2009-07-17 09:42 -------- d-----w- c:\program files\Trend Micro
2009-07-16 18:07 . 2009-07-16 19:03 -------- d-----w- c:\program files\Panda Security
2009-07-16 18:05 . 2009-07-16 23:02 -------- d-----w- c:\windows\BDOSCAN8
2009-07-16 16:24 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 16:24 . 2009-07-16 16:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-16 16:24 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-14 10:04 . 2004-02-22 08:11 719872 ----a-w- c:\windows\system32\devil.dll
2009-07-14 10:04 . 2007-05-17 15:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2009-07-14 10:04 . 2006-10-07 15:43 502784 ----a-w- c:\windows\x2.64.exe
2009-07-14 10:04 . 2006-04-12 07:47 217073 ----a-w- c:\windows\meta4.exe
2009-07-14 10:04 . 2006-04-05 06:09 66560 ----a-w- c:\windows\MOTA113.exe
2009-07-14 10:04 . 2005-07-14 10:31 27648 ----a-w- c:\windows\system32\AVSredirect.dll
2009-07-14 10:04 . 2005-02-28 11:16 240128 ----a-w- c:\windows\system32\x.264.exe
2009-07-14 10:04 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\yv12vfw.dll
2009-07-14 10:04 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2009-07-14 10:04 . 2009-07-14 10:04 -------- d-----w- c:\program files\AviSynth 2.5
2009-07-14 09:55 . 2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
2009-07-14 09:55 . 2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2009-07-14 09:55 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2009-07-14 09:55 . 2009-07-14 09:55 -------- d-----w- c:\program files\eRightSoft
2009-07-08 09:59 . 2009-07-08 09:59 -------- d--h--w- C:\CanoScan
2009-07-08 08:09 . 2009-07-08 08:11 -------- d-----w- c:\program files\Readiris Pro 11 Demo
2009-07-07 15:27 . 2009-07-07 15:27 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\TomTom
2009-07-07 15:25 . 2009-07-07 15:25 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\TomTom
2009-07-07 15:25 . 2009-07-07 15:25 -------- d-----w- c:\documents and settings\Besancenot\Application Data\TomTom
2009-07-07 15:25 . 2009-07-07 15:25 -------- d-----w- c:\program files\TomTom International B.V
2009-07-07 15:24 . 2009-07-07 15:25 -------- d-----w- c:\program files\TomTom HOME 2
2009-07-05 20:30 . 2009-07-05 20:41 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Publish or Perish
2009-07-05 20:29 . 2009-07-05 20:29 -------- d-----w- c:\program files\Harzing's Publish or Perish
2009-07-05 20:29 . 2009-07-05 20:29 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Tarma Installer
2009-07-05 16:31 . 2009-07-16 15:16 -------- d-----w- c:\documents and settings\torrent\finis
2009-07-05 16:30 . 2009-07-08 16:44 -------- d-----w- c:\documents and settings\torrent
2009-07-04 12:12 . 2009-07-04 12:12 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Roxio
2009-07-04 10:11 . 2009-07-04 10:11 -------- d-----w- c:\program files\DVDFab 6
2009-07-04 09:08 . 2009-07-04 09:08 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\DAEMON Tools Lite
2009-07-04 09:08 . 2009-07-16 23:03 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\AskToolbar
2009-07-04 09:07 . 2009-07-04 09:08 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-07-04 09:02 . 2009-07-04 09:02 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-07-04 09:02 . 2009-07-04 09:10 -------- d-----w- c:\documents and settings\Besancenot\Application Data\DAEMON Tools Lite
2009-07-04 07:56 . 2009-07-04 07:56 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-07-03 19:12 . 2009-07-03 19:12 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\Temp
2009-07-03 18:56 . 2009-07-03 18:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-07-02 18:03 . 2009-07-02 18:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-02 13:04 . 2009-07-01 12:18 52224 ----a-w- c:\documents and settings\Besancenot\Application Data\Mozilla\Firefox\Profiles\4upcifqz.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
2009-07-02 13:04 . 2009-07-01 12:18 114688 ----a-w- c:\documents and settings\Besancenot\Application Data\Mozilla\Firefox\Profiles\4upcifqz.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\npmozax.dll
2009-07-01 14:00 . 2009-07-01 14:00 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Canon
2009-07-01 13:57 . 2008-04-13 09:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-07-01 13:57 . 2008-04-13 09:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-06-30 21:15 . 2009-07-04 10:22 -------- d-----w- c:\documents and settings\Besancenot\Application Data\dvdcss
2009-06-30 18:25 . 2009-06-30 18:25 -------- d-----w- c:\program files\PC Inspector File Recovery
2009-06-30 17:18 . 2009-06-30 18:24 -------- d-----w- c:\program files\diskrescue
2009-06-30 15:39 . 2009-07-03 06:25 -------- d-----w- C:\swp55
2009-06-30 15:21 . 2009-07-03 06:26 -------- d-----w- C:\SW5.5
2009-06-30 14:40 . 2009-06-30 14:56 -------- d-----w- c:\program files\Fichiers communs\Canon
2009-06-30 14:00 . 2009-06-30 14:03 -------- d-----w- c:\program files\Maple 8
2009-06-30 13:24 . 2009-07-03 17:18 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Apple Computer
2009-06-30 13:23 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-06-30 13:23 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-06-30 13:23 . 2009-06-30 13:23 -------- d-----w- c:\program files\iPod
2009-06-30 13:23 . 2009-06-30 13:23 -------- d-----w- c:\program files\iTunes
2009-06-30 13:23 . 2009-06-30 13:23 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-06-30 13:18 . 2009-06-30 14:57 -------- d-----w- c:\program files\Canon
2009-06-30 08:31 . 2009-06-30 08:31 -------- d-----w- c:\windows\Ask & Record Toolbar
2009-06-29 22:04 . 2009-06-29 22:04 -------- d-----w- c:\program files\Bonjour
2009-06-29 22:00 . 2009-06-29 22:01 -------- d-----w- c:\program files\QuickTime
2009-06-29 22:00 . 2009-06-30 13:23 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple Computer
2009-06-29 21:59 . 2009-06-29 21:59 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\Apple
2009-06-29 21:59 . 2009-06-29 21:59 -------- d-----w- c:\program files\Apple Software Update
2009-06-29 21:58 . 2009-06-30 13:23 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-06-29 21:58 . 2009-06-29 21:58 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Apple
2009-06-29 21:57 . 2009-06-29 21:57 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-06-29 21:57 . 2009-02-15 22:10 69000 ----a-w- c:\windows\system32\zlcomm.dll
2009-06-29 21:57 . 2009-02-15 22:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2009-06-29 21:57 . 2009-02-15 22:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-06-29 21:57 . 2009-06-29 21:57 -------- d-----w- c:\windows\system32\ZoneLabs
2009-06-29 21:57 . 2009-06-29 21:57 -------- d-----w- c:\program files\Zone Labs
2009-06-29 21:54 . 2009-06-29 21:55 -------- d-----w- c:\documents and settings\Besancenot\Application Data\vlc
2009-06-29 21:52 . 2009-07-17 16:10 -------- d-----w- c:\windows\Internet Logs
2009-06-29 21:50 . 2009-06-30 13:24 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\Apple Computer
2009-06-29 21:50 . 2009-06-29 21:50 -------- d-----w- c:\windows\Freecorder Toolbar
2009-06-29 21:49 . 2009-06-29 21:49 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\Thunderbird
2009-06-29 21:49 . 2009-06-29 21:49 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Thunderbird
2009-06-29 21:48 . 2009-07-17 15:48 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-06-29 21:27 . 2009-06-29 21:59 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-06-29 20:28 . 2008-04-13 09:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-06-29 20:28 . 2008-04-13 09:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-29 19:06 . 2009-06-29 19:06 -------- d-----w- c:\documents and settings\Besancenot\Local Settings\Application Data\RadonLabs
2009-06-29 19:05 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-06-29 19:02 . 2009-06-29 19:04 -------- d-----w- c:\program files\Riding Star
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-17 15:57 . 2009-05-05 07:53 0 ----a-w- c:\documents and settings\Besancenot\Local Settings\Application Data\WavXMapDrive.bat
2009-07-17 15:57 . 2009-03-28 11:19 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-17 15:52 . 2009-05-05 12:40 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Microsoft Help
2009-07-17 15:52 . 2009-03-28 10:42 -------- d-----w- c:\program files\Windows Desktop Search
2009-07-17 15:42 . 2008-04-25 12:46 94716 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-17 15:42 . 2008-04-25 12:46 535034 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-17 15:23 . 2009-05-17 17:55 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-17 07:42 . 2009-05-17 17:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-16 17:07 . 2009-05-17 17:55 -------- d-----w- c:\documents and settings\Besancenot\Application Data\uTorrent
2009-07-15 22:23 . 2009-05-17 17:43 -------- d-----w- c:\program files\VideoLAN
2009-07-13 22:52 . 2009-06-30 13:00 -------- d-----w- c:\program files\Free Video Converter
2009-07-07 11:19 . 2009-05-17 17:48 -------- d-----w- c:\program files\Google
2009-07-04 10:11 . 2009-06-30 13:05 -------- d-----w- c:\documents and settings\Besancenot\Application Data\Vso
2009-06-30 18:25 . 2009-03-28 10:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-30 16:13 . 2009-03-28 11:03 117408 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 16:13 . 2009-03-28 11:21 117408 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 13:10 . 2009-06-30 13:10 -------- d-----w- c:\program files\Ask.com
2009-06-30 13:10 . 2009-06-30 08:31 -------- d-----w- c:\program files\Ask & Record Toolbar
2009-06-30 13:05 . 2009-06-30 13:05 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-30 13:05 . 2009-06-30 13:05 47360 ----a-w- c:\documents and settings\Besancenot\Application Data\pcouffin.sys
2009-06-30 13:05 . 2009-06-30 13:05 47360 ----a-w- c:\documents and settings\Besancenot\Application Data\pcouffin.sys
2009-06-30 13:05 . 2009-06-30 13:05 -------- d-----w- c:\program files\DVDFab 5
2009-06-30 13:03 . 2009-06-30 12:58 -------- d-----w- c:\program files\HomePlayer
2009-06-30 12:53 . 2009-06-30 12:53 -------- d-----w- c:\program files\DVD Shrink
2009-06-30 12:53 . 2009-06-30 12:53 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\DVD Shrink
2009-06-29 11:16 . 2009-03-01 18:01 143360 ----a-w- c:\windows\system32\bcmwlapi.dll
2009-06-16 14:40 . 2008-04-25 12:46 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:40 . 2008-04-25 12:46 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:10 . 2008-04-25 12:46 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 18:58 . 2009-03-28 10:44 -------- d-----w- c:\program files\Java
2009-06-02 18:57 . 2009-06-02 18:57 152576 ----a-w- c:\documents and settings\Besancenot\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-02 18:56 . 2009-06-02 18:56 -------- d-----w- c:\program files\cdstomp
2009-05-24 22:24 . 2008-05-26 22:18 350208 ----a-w- c:\windows\system32\mssph.dll
2009-05-12 13:12 . 2008-04-25 18:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 15:33 . 2008-04-25 12:46 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 08:03 . 2009-05-05 08:03 0 ----a-w- c:\windows\nsreg.dat
2009-04-29 04:45 . 2008-04-25 12:46 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:45 . 2008-04-25 12:46 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 19:42 . 2008-04-25 12:46 1847936 ----a-w- c:\windows\system32\win32k.sys
2009-06-24 15:27 . 2009-05-05 08:03 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-05-03 09:06 . 2009-07-14 09:55 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-07-14 09:55 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-07-14 09:55 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-04 16:04 1144712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-04 1144712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-04 1144712]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2009-01-14 10:24 40960 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2009-01-14 10:24 40960 ----a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-06-03 251240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-10-28 200704]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-12-01 483420]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-12-01 471040]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-17 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-17 150040]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-12-04 186904]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-01-19 667648]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2008-12-19 184320]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2008-12-22 145408]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2009-01-16 656696]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2009-01-16 95544]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2009-01-16 15360]
"DellConnectionManager"="c:\program files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe" [2009-03-01 1810432]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"CLIVFR"="c:\program files\Dell\Latitude ON Reader Data\CLIVFR.exe" [2008-08-29 233472]
"BIOSEvent"="c:\program files\Dell\Latitude ON Reader Data\BIOSEvent.exe" [2008-08-29 110592]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-06-29 2220032]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"Ask and Record FLV Service"="c:\program files\Ask & Record Toolbar\FLVSrvc.exe" [2009-03-10 156672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\docume~1\ALLUSE~1\MENUDM~1\PROGRA~1\DMARRA~1\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-8-15 604776]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2009-2-6 1095456]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\HomePlayer\\VLC\\vlc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [19/04/2007 07:56 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [29/12/2008 13:07 320800]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [22/01/2009 12:19 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [22/01/2009 12:19 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [06/02/2009 22:06 443168]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe [01/03/2009 20:09 77824]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [03/06/2009 14:46 92008]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [28/03/2009 20:26 112128]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [28/03/2009 20:26 32808]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [28/03/2009 20:26 244368]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [28/03/2009 20:26 110080]
R3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [28/03/2009 20:26 148056]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [28/03/2009 20:26 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [28/03/2009 20:26 277440]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys --> c:\windows\system32\Drivers\NvtSp50.sys [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://www.google.com/ie
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: secuser.com\www
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\docume~1\BESANC~1\APPLIC~1\Mozilla\Firefox\Profiles\4upcifqz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\documents and settings\Besancenot\Application Data\Mozilla\Firefox\Profiles\4upcifqz.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "
https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-17 18:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\System32\TdmNetworkProvider.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'lsass.exe'(1036)
c:\windows\system32\wvauth.dll
.
Completion time: 2009-07-17 18:13
ComboFix-quarantined-files.txt 2009-07-17 16:13
Pre-Run: 32 246 165 504 octets libres
Post-Run: 32 230 739 968 octets libres
356 --- E O F --- 2009-07-17 15:53
MERCI pour ta réponse rapide...
voici le résultat du scan (mais vu le contenu j'ai peut être le rapport destiné aux utilisateurs sans aide) :
Rapport GenProc 2.604 [1] - 16/07/2009 à 20:22:18
@ Windows XP Service Pack 3 - Mode normal
@ Mozilla Firefox (3.5) [Navigateur par défaut]
Il est impératif de désactiver le résident TeaTimer de Spybot pendant l'ensemble des manipulations qui vont suivre. Aide Tea-Timer : http://www.genproc.com/spybot/spybot.html
Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures" ; par la suite, laisse-le avec ses réglages par défaut. C'est tout.
# Etape 1/ Télécharge :
- WORT http://pc-system.fr/WORT/WORT.exe (dj QUIOU) sur le Bureau.
- Toolbar-S&D http://eric.71.mespages.googlepages.com/ToolBarSD.exe (Team IDN) sur ton Bureau.
Redémarre en mode sans échec comme indiqué ici http://www.pcloisirs.eu/mode_sans_echec.htm ; Choisis ta session courante *** Besancenot *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[1]" sur ton bureau).
# Etape 2/
Lance Toolbar-S&D situé sur le Bureau.
Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.
# Etape 3/
Double-clique sur le fichier WORT.exe et sélectionne le Bureau à l'aide du bouton "Parcourir". Suis les instructions et double-clique sur le fichier Wareout Removal Tool.bat qui vient d'être créé sur le Bureau. Sélectionne l'option 1 et valide par entrée.
# Etape 4/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 5/
Redémarre normalement et poste, dans la même réponse :
- Le contenu du rapport TB.txt situé dans C:\ ;
- Le contenu du rapport WORT_report.txt situé dans C:\Wort ;
- Un nouveau rapport HijackThis http://tinyurl.com/GenProc-HijackThis ;
- Un nouveau rapport GenProc ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
~~ Arguments de la procédure ~~
# Détections [1] GenProc 2.604 16/07/2009 à 20:23:22
WareOut:le 16/07/2009 à 20:23:35
[HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters\interfaces\{93F7363D-2B56-45A2-BC43-FC98E01E2A48}]
NameServer REG_SZ 85.255.112.73,85.255.112.7
Toolbar:le 16/07/2009 à 20:23:36 "C:\Program Files\DAEMON Tools Toolbar"
----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------
~~ Fin à 20:23:56 ~~