Bonjour,
j ai telecharger combofix et l ai lance a la fin j ai recu un message ou raport pouve vous me dire que dois je faire
voici le mesage
ComboFix 09-09-11.01 - nadji 11/09/2009 21:41.1.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.52.3082.18.1790.982 [GMT -5:00]
Running from: c:\users\nadji\Downloads\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3508031722-711558119-1327504054-500
c:\users\nadji\AppData\Roaming\.#
c:\users\nadji\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Registration .LNK
.
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-12 02:47 . 2009-09-12 02:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-12 02:20 . 2009-09-12 02:20 72824 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-09-12 01:56 . 2009-09-12 01:56 680 ----a-w- c:\users\nadji\AppData\Local\d3d9caps.dat
2009-09-12 00:07 . 2009-09-12 02:24 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-09-11 19:02 . 2009-09-11 19:02 -------- d-----w- c:\program files\Real
2009-09-11 19:02 . 2009-09-12 01:53 -------- d-----w- c:\program files\Common Files\Real
2009-09-11 17:45 . 2009-09-12 00:20 -------- d-----w- c:\users\nadji\AppData\Roaming\Skype
2009-09-11 02:13 . 2009-09-11 02:15 -------- d-----w- c:\program files\Skype
2009-09-11 02:12 . 2009-09-11 02:12 -------- d-----w- c:\programdata\Skype
2009-09-10 21:51 . 2009-09-10 21:53 -------- d-----w- c:\users\nadji\AppData\Roaming\IDM
2009-09-10 21:51 . 2009-09-10 21:53 -------- d-----w- c:\users\nadji\AppData\Roaming\DMCache
2009-09-10 21:51 . 2009-09-10 21:51 -------- d-----w- c:\program files\Internet Download Manager
2009-09-10 01:35 . 2009-09-10 01:38 16232888 ----a-w- c:\users\nadji\flight_simulator_x_DHL737.zip
2009-09-10 01:19 . 2009-09-10 01:20 4464 ----a-w- c:\users\nadji\flight_simulator_x_a380.exe.zip
2009-09-09 23:52 . 2009-09-12 01:56 -------- d-----w- c:\users\nadji\Tracing
2009-09-09 23:50 . 2009-09-09 23:50 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-09 23:49 . 2009-09-09 23:49 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-09-09 21:04 . 2009-09-11 20:34 -------- d-----w- c:\users\nadji\AppData\Roaming\LimeWire
2009-09-09 20:52 . 2009-09-09 20:52 2230069 ----a-w- c:\users\nadji\qf_380.zip
2009-09-09 20:51 . 2009-09-09 20:51 214198 ----a-w- c:\users\nadji\73raf_l3.zip
2009-09-09 20:49 . 2009-09-09 20:50 934966 ----a-w- c:\users\nadji\b7773ali.zip
2009-09-09 18:44 . 2009-09-10 22:34 -------- d-----w- c:\program files\AskBarDis
2009-09-09 18:43 . 2009-09-12 01:52 -------- d-----w- c:\users\nadji\AppData\Roaming\uTorrent
2009-09-09 03:09 . 2009-09-09 03:09 -------- d-----w- c:\users\nadji\AppData\Roaming\GRETECH
2009-09-09 03:03 . 2009-09-09 03:03 -------- d-----w- c:\program files\GRETECH
2009-09-07 22:05 . 2009-09-07 22:05 -------- d-----w- c:\users\nadji\AppData\Roaming\CyberLink
2009-09-06 18:50 . 2009-09-06 18:50 -------- d-----w- c:\programdata\Friends Games
2009-09-06 18:41 . 2009-09-12 02:16 -------- d-----w- c:\programdata\SpinTop Games
2009-09-06 16:33 . 2009-09-06 16:33 -------- d-----w- c:\users\nadji\AppData\Roaming\Transcend
2009-09-06 02:50 . 2009-09-06 02:50 -------- d-----w- c:\programdata\TERMINAL Studio
2009-09-06 01:24 . 2009-09-06 01:24 -------- d-----w- c:\programdata\Arcade Lab
2009-09-06 01:12 . 2009-09-06 01:13 -------- d-----w- c:\programdata\Go Go Gourmet
2009-09-06 00:41 . 2009-09-06 00:41 -------- d-----w- c:\programdata\Ubisoft
2009-09-06 00:40 . 2009-09-06 00:40 -------- d-----w- c:\users\nadji\AppData\Local\Oberon Games
2009-09-06 00:39 . 2009-09-06 00:39 10134 ----a-r- c:\users\nadji\AppData\Roaming\Microsoft\Installer\{89661B04-C646-4412-B6D3-5E19F02F1F37}\ARPPRODUCTICON.exe
2009-09-05 23:39 . 2009-09-06 01:18 -------- d-----w- c:\users\nadji\AppData\Roaming\Flood Light Games
2009-09-05 23:39 . 2009-09-06 01:18 -------- d-----w- c:\programdata\Flood Light Games
2009-09-05 23:30 . 2009-09-05 23:30 -------- d-----w- c:\program files\Ubisoft
2009-09-05 22:45 . 2005-12-29 17:21 7062292 ----a-w- c:\windows\system32\Data.bin
2009-09-05 22:45 . 2005-12-29 03:20 3991928 ----a-w- c:\windows\system32\StringLib.dll
2009-09-05 22:45 . 2002-08-12 16:00 1126400 ----a-w- c:\windows\system32\ANIKINFO.exe
2009-09-05 22:45 . 2009-09-12 02:16 -------- d-----w- c:\windows\system32\DATA
2009-09-05 22:37 . 2009-09-05 22:37 -------- d-----w- c:\program files\MSXML 4.0
2009-09-05 22:37 . 2005-05-26 20:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-09-05 22:24 . 2009-09-12 02:22 -------- d-----w- c:\programdata\Electronic Arts
2009-09-05 22:19 . 2008-09-05 00:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-09-05 22:19 . 2006-09-28 21:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-09-05 22:13 . 2009-09-06 02:14 -------- d-----w- c:\users\nadji\AppData\Local\Microsoft Games
2009-09-05 22:11 . 2009-09-05 22:20 -------- d-----w- c:\program files\Electronic Arts
2009-09-05 22:04 . 2009-09-05 22:04 -------- d-----w- c:\users\nadji\AppData\Roaming\eSobi
2009-09-05 21:28 . 2009-09-05 21:28 -------- d-----w- c:\users\nadji\AppData\Local\Adobe
2009-09-05 21:26 . 2009-09-11 20:37 -------- d-----w- c:\users\nadji\AppData\Local\Google
2009-09-05 21:26 . 2009-09-05 21:26 -------- d-----w- c:\users\nadji\AppData\Roaming\Leadertech
2009-09-05 21:26 . 2009-09-05 21:26 -------- d-----w- c:\users\nadji\AppData\Roaming\Acer
2009-09-05 21:26 . 2009-09-12 02:19 8224 ----a-w- c:\users\nadji\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-05 21:24 . 2009-09-05 21:24 -------- d-----w- c:\programdata\Partner
2009-09-05 21:24 . 2009-09-12 02:16 -------- d-----w- C:\ACERSW
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\users\Default\Reciente
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 02:40 . 2009-01-20 06:44 -------- d-----w- c:\program files\Google
2009-09-12 02:34 . 2008-01-21 08:32 667144 ----a-w- c:\windows\system32\perfh00A.dat
2009-09-12 02:34 . 2008-01-21 08:32 129706 ----a-w- c:\windows\system32\perfc00A.dat
2009-09-12 02:29 . 2009-01-20 06:49 -------- d-----w- c:\program files\McAfee
2009-09-12 02:29 . 2009-01-20 06:49 -------- d-----w- c:\programdata\McAfee
2009-09-12 02:16 . 2009-01-20 06:46 -------- d-----w- c:\program files\Windows Live
2009-09-12 02:16 . 2009-01-20 06:46 -------- d-----w- c:\program files\Microsoft
2009-09-12 02:16 . 2009-01-20 06:49 -------- d-----w- c:\program files\McAfee.com
2009-09-12 02:16 . 2009-01-20 06:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-12 02:16 . 2009-01-20 06:50 -------- d-----w- c:\program files\Common Files\McAfee
2009-09-09 18:23 . 2006-10-10 22:27 -------- d-----w- c:\programdata\NVIDIA
2009-09-05 22:05 . 2009-01-20 07:17 -------- d-----w- c:\programdata\eSobi
2009-09-05 21:40 . 2006-11-02 12:35 -------- d-----w- c:\program files\Microsoft Games
2009-09-05 21:39 . 2009-01-20 06:20 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-05 21:24 . 2009-01-20 06:32 -------- d-----w- c:\program files\Acer
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Plantillas
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Menú Inicio
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Favoritos
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Escritorio
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Documentos
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\programdata\Datos de programa
2009-09-05 21:20 . 2009-09-05 21:20 -------- d-sh--we c:\program files\Archivos comunes
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2009-09-05 21:24 157168 ----a-w- c:\programdata\Partner\partner.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-29 23:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-10-01 319488]
"EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-10-01 323584]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-20 30192]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-29 526896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-09 68640]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-08 13584928]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-09-23 641208]
"Acer Product Registration"="c:\program files\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392]
"Acer Assist Launcher"="c:\program files\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DB6B812C-C59F-4A18-92C6-2F611568B2BC}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DD2A7F0A-037C-4A96-9FEF-20A3A17C7AF8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{316D1953-FCAC-44C4-8293-E2FFFB344735}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{9288933D-521D-46B5-95E7-A741ABC98858}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{6CD31212-DF69-41ED-929D-FA728B82B2DF}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{5CEC8F64-20CB-464C-A665-825DBD50EAAC}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{EB4C2AB7-6ACF-4215-9F25-D26CB89CF76D}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{99487BD7-F71E-4B26-986F-E83DDF2F7D12}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{D30C9BA8-D9B8-489B-B79C-2AAB72E1BCC8}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{359C163D-445E-48AB-BB65-E88540E67E20}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [20/01/2009 01:32 24576]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [23/09/2008 15:11 144632]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [20/01/2009 01:46 43552]
S3 GoogleDesktopManager-092308-165331;Administrador de Google Desktop 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [20/01/2009 01:44 30192]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [23/09/2008 15:11 50424]
S3 Partner Service;Partner Service;c:\programdata\Partner\partner.exe [05/09/2009 16:24 110576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2009-01-20 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-20 06:32]
2009-01-20 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-20 06:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=080a&s=1&o=vb32&d=1006&m=aspire_x1300
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=080a&s=1&o=vb32&d=1006&m=aspire_x1300
LSP: %SYSTEMROOT%\system32\nvLsp.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Run-Setresolution - c:\acer\config\1600X900.cmd
HKLM-Run-MontiorGeo - c:\acer\MonitorGeo.cmd
HKLM-Run-eRecoveryService - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-11 21:47
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-09-12 21:49
ComboFix-quarantined-files.txt 2009-09-12 02:49
Pre-Run: 107 436 843 008 bytes libres
Post-Run: 106 428 903 424 bytes libres
197
merci de bien m aider.

