Bonjour désolé du retard, week-end oblige....
Je reprend par etapes :
Désinstallation d'AVAST! : ok
Désinstallation de NORTON : Non ok.
En lancant le programme téléchargé, il m'indique que la version que j'utilise est expiré...
voici le rapport d'USBfix :
############################## | UsbFix V6.037 |
User : Utilisateur (Administrateurs) # CRC_87225036K
Update on 27/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 05:41:07 | 05/02/2004
Website : http://pagesperso-orange.fr/NosTools/index.html
Genuine Intel(R) CPU T2080 @ 1.73GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ (!) Disabled | Updated ]
AV : Norton Internet Security 2007 [ Enabled | Updated ]
FW : Norton Internet Security[ (!) Disabled ]2007
C:\ -> Disque fixe local # 32,01 Go (5,62 Go free) [WinXP] # NTFS
D:\ -> Disque fixe local # 101,73 Mo (98,75 Mo free) [BOOT] # FAT
E:\ -> Disque fixe local # 31,98 Go (3,66 Go free) [DONNEES] # FAT32
F:\ -> Disque CD-ROM
J:\ -> Disque fixe local # 931,28 Go (571,46 Go free) [My Book] # FAT32
P:\ -> Disque fixe local # 232,88 Go (151,1 Go free) [LWCP] # NTFS
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
c:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
c:\WINDOWS\system32\SgLogPlayer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
c:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\WINDOWS\startup.vbs
Supprimé ! P:\b.bat
Supprimé ! P:\h.cmd
Non supprimé ! P:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Non supprimé ! P:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
################## | Registre # Clés Run infectieuses |
Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "startup"
Supprimé ! [HKLM\software\microsoft\shared tools\msconfig\startupreg\amva]
Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{03869e0a-c92c-11d6-8d56-001b383e850b}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e20-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e21-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e22-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e23-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e24-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{4e962e25-ea4f-11d7-8eab-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{8df78dac-236d-11d7-8d93-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{90bea838-0b05-11d7-8d8b-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{e2fbd2b7-8ed3-11d6-8d1d-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{edad7c66-3f83-11d6-8ca9-001b383e850b}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{fce8be5e-2645-11d6-8c79-001b383e850b}\Shell\Auto\Command
################## | Listing des fichiers présent |
[04/08/2002 04:45|--a------|0] C:\AUTOEXEC.BAT
[31/07/2003 23:00|-rahs----|212] C:\boot.ini
[05/08/2004 11:00|-rahs----|4952] C:\Bootfont.bin
[04/08/2002 04:45|--a------|0] C:\CONFIG.SYS
[02/08/2002 10:42|--a------|148] C:\dxlog.txt
[?|?|?] C:\hiberfil.sys
[04/08/2002 04:45|-rahs----|0] C:\IO.SYS
[04/08/2002 04:45|-rahs----|0] C:\MSDOS.SYS
[05/08/2004 11:00|-rahs----|47564] C:\NTDETECT.COM
[05/08/2004 11:00|-rahs----|251712] C:\ntldr
[?|?|?] C:\pagefile.sys
[29/08/2002 12:27|--a------|1950036] C:\Pour entr‚e7.pdf
[30/11/2002 07:47|--a------|90] C:\Setup.log
[27/07/2007 16:17|--ah-----|176] C:\SWSTAMP.TXT
[05/02/2004 05:47|--a------|4983] C:\UsbFix.txt
[15/05/1998 20:01|--a------|222390] D:\IO.SYS
[04/09/2005 19:44|--a------|64] D:\MSDOS.SYS
[15/05/1998 20:01|--a------|95864] D:\COMMAND.COM
[15/05/1998 20:01|--a------|69127] D:\DRVSPACE.BIN
[04/08/2007 17:19|--ah-----|301] D:\BOOTLOG.PRV
[05/08/2004 12:00|-rahs----|4952] D:\Bootfont.bin
[05/08/2004 12:00|-rahs----|251712] D:\ntldr
[05/08/2004 12:00|-rahs----|47564] D:\NTDETECT.COM
[03/08/2007 14:11|---hs----|512] D:\bootsect.dos
[03/08/2007 14:26|---hs----|239] D:\boot.ini
[17/01/2008 15:52|--a------|558] D:\CONFIG.SYS
[20/08/2007 15:02|--a------|573] D:\AUTOEXEC.BAT
[30/07/2003 23:11|--a------|349] D:\GHOSTERR.TXT
[30/07/2003 23:11|--ah-----|301] D:\BOOTLOG.TXT
[01/08/2006 14:18|--a------|1394964] D:\ghost.exe
[05/06/2002 13:12|--a------|17788920] E:\antivir_workstation_win7u_en_h.exe
[28/01/2008 13:40|--a------|1692824] E:\setup.exe
[28/07/2002 05:08|--a------|4683] E:\codes.txt
[11/04/2002 20:37|--a------|902] E:\Journal de trac‚ et de publication.CSV
[17/05/2007 20:07|--a------|362802] P:\1600x1200_adidas_originals_9.jpg
[05/11/2007 02:18|--a------|64603] P:\Fond d'‚cran LWCP.jpg
[16/05/2007 14:23|---hs----|348160] P:\msvcr71.dll
[16/10/2002 21:50|--ahs----|6656] P:\Thumbs.db
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# E:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
# P:\autorun.inf -> Folder created by UsbFix.
################## | Upload |
Veuillez envoyer le fichier : C:\DOCUME~1\UTILIS~1\Bureau\UsbFix_Upload_Me_CRC_87225036K.zip : http://forum-aide-contre-virus.be/usbfix/choix_fichier.php
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.037 ! |
Ainsi que celui de COMBOfix :
ComboFix 09-10-04.01 - Utilisateur 05/02/2004 6:01.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1526.1095 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Bureau\Unlucky.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\adaqijaqyj.inf
c:\documents and settings\All Users\Application Data\atizoteqi.sys
c:\documents and settings\All Users\Application Data\elelyne._dl
c:\documents and settings\All Users\Application Data\jipeganoz._dl
c:\documents and settings\All Users\Application Data\vifocupoji.lib
c:\documents and settings\All Users\Application Data\ytificam.com
c:\documents and settings\Utilisateur\Application Data\akikakifud.com
c:\documents and settings\Utilisateur\Application Data\ebokabejy.reg
c:\documents and settings\Utilisateur\Application Data\lizkavd.exe
c:\documents and settings\Utilisateur\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Utilisateur\Application Data\seres.exe
c:\documents and settings\Utilisateur\Application Data\svcst.exe
c:\documents and settings\Utilisateur\Application Data\uveba._sy
c:\documents and settings\Utilisateur\Application Data\wiaserva.log
c:\documents and settings\Utilisateur\Bureau\AntivirusPro_2010.lnk
c:\documents and settings\Utilisateur\Cookies\evogikuw._dl
c:\documents and settings\Utilisateur\Cookies\idymupaqo.exe
c:\documents and settings\Utilisateur\Local Settings\Application Data\fymyvow._sy
c:\documents and settings\Utilisateur\Local Settings\Application Data\gurasas.inf
c:\documents and settings\Utilisateur\Local Settings\Application Data\ntias64\ntias64.dll
c:\documents and settings\Utilisateur\Local Settings\Temporary Internet Files\bugodumohe.ban
c:\documents and settings\Utilisateur\Local Settings\Temporary Internet Files\vovyjimiw.bat
c:\documents and settings\Utilisateur\Local Settings\Temporary Internet Files\xugiwaq.vbs
c:\documents and settings\Utilisateur\Local Settings\Temporary Internet Files\ycep.com
c:\documents and settings\Utilisateur\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Fichiers communs\cetuk.bat
c:\program files\Fichiers communs\iripo.pif
c:\program files\Fichiers communs\ypademot.dl
c:\windows\daryfe.scr
c:\windows\efone.bat
c:\windows\Installer\1005137.msi
c:\windows\iqometivop.scr
c:\windows\rolofi.scr
c:\windows\system32\_scui.cpl
c:\windows\system32\kaqymelah.bin
c:\windows\system32\lawilucyxe.vbs
c:\windows\system32\omydyqiqam.pif
c:\windows\system32\prnqctl.vbs
c:\windows\system32\restorer32_a.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2004-01-05 au 2004-02-05 ))))))))))))))))))))))))))))))))))))
.
2008-12-12 09:18 . 2008-12-12 09:18 87336 ----a-w- c:\windows\system32\dns-sd.exe
2008-12-12 09:11 . 2008-12-12 09:11 61440 ----a-w- c:\windows\system32\dnssd.dll
2008-11-06 16:37 . 2008-11-06 16:37 1585664 ----a-w- c:\windows\system32\VC80CRTRedist.msi
2008-07-07 07:40 . 2008-07-07 07:40 56108 ----a-w- c:\windows\system32\drivers\scdemu.sys
2008-06-26 09:58 . 2008-06-26 10:37 318 ----a-w- c:\windows\system32\stan_deezer_ripper_xp.bat
2008-06-26 09:57 . 2008-06-26 09:58 94208 ----a-w- c:\windows\system32\HoboCopy.exe
2008-06-26 09:57 . 2008-06-26 09:57 126895 ----a-w- c:\windows\system32\Flv2Mp3.exe
2008-05-13 11:35 . 2008-05-13 11:35 189712 ----a-w- c:\windows\system32\RALMain.dll
2008-05-13 11:34 . 2008-05-13 11:34 38160 ----a-w- c:\windows\system32\MLPagAx.dll
2008-05-13 11:32 . 2008-05-13 11:32 54544 ----a-w- c:\windows\system32\PCLEGetGuid.dll
2008-01-29 11:02 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2008-01-29 11:01 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2007-11-29 22:30 . 2008-11-06 16:35 200704 ----a-w- c:\windows\system32\ssldivx.dll
2007-11-29 22:30 . 2008-11-06 16:35 1044480 ----a-w- c:\windows\system32\libdivx.dll
2007-08-08 10:27 . 2002-02-24 21:52 -------- d--h--w- c:\windows\system32\GroupPolicy
2007-08-06 11:18 . 2002-06-26 11:34 -------- d-----w- c:\documents and settings\Utilisateur\.gimp-2.2
2007-08-06 11:17 . 2007-08-06 11:17 -------- d-----w- c:\program files\GIMP-2.0
2007-08-06 11:13 . 2007-08-06 11:13 -------- d-----w- c:\program files\Fichiers communs\GTK
2007-08-06 09:29 . 2007-08-06 09:29 -------- d-----w- c:\documents and settings\Utilisateur\Local Settings\Application Data\Help
2007-08-05 19:46 . 2007-08-05 19:46 -------- d-s---w- c:\documents and settings\Utilisateur\UserData
2007-08-05 19:37 . 2002-05-07 14:04 1408 -c--a-w- c:\windows\mozver.dat
2007-08-05 19:36 . 2002-03-30 19:57 -------- d-----w- c:\program files\Fichiers communs\Adobe
2007-08-05 19:36 . 2007-08-06 09:24 -------- d-----w- c:\windows\SxsCaPendDel
2007-08-05 19:30 . 2004-02-02 04:04 -------- d-----w- c:\documents and settings\Utilisateur\Application Data\OpenOffice.org2
2007-08-05 19:14 . 2007-04-28 12:54 593920 ----a-w- c:\windows\system32\xvidcore.dll
2007-08-05 19:14 . 2007-04-23 00:15 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2007-08-05 19:14 . 2007-04-23 00:02 73728 ----a-w- c:\windows\system32\dpl100.dll
2007-08-05 19:14 . 2006-11-01 12:54 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2007-08-05 19:14 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2007-08-05 19:14 . 2007-06-03 12:31 10752 ----a-w- c:\windows\system32\ff_vfw.dll
2007-08-05 19:14 . 2007-05-31 06:44 740442 ----a-w- c:\windows\system32\divx.dll
2007-08-05 19:14 . 2007-08-05 19:14 -------- d-----w- c:\program files\K-Lite Codec Pack
2007-08-05 18:47 . 2007-08-05 18:47 -------- d-----w- c:\program files\Fichiers communs\xing shared
2007-08-05 18:46 . 2003-10-08 05:24 -------- d-----w- c:\documents and settings\Utilisateur\Local Settings\Application Data\Google
2007-08-05 18:46 . 2007-08-05 18:47 -------- d-----w- c:\program files\Fichiers communs\Real
2007-08-05 18:46 . 2007-08-05 18:46 -------- d-----w- c:\program files\Real
2007-08-05 18:41 . 2002-05-01 01:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2007-08-05 18:40 . 2001-10-28 15:42 116224 ----a-w- c:\windows\system32\pdfcmnnt.dll
2007-08-05 18:40 . 2000-10-01 17:00 119568 ----a-w- c:\windows\system32\VB6FR.DLL
2007-08-05 18:40 . 1998-07-13 00:08 59904 ----a-w- c:\windows\system32\MSCC2FR.DLL
2007-08-05 18:40 . 1998-07-13 00:08 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
2007-08-05 18:40 . 1998-07-05 23:00 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL
2007-08-05 18:40 . 2007-08-05 18:40 -------- d-----w- c:\program files\PDFCreator
2007-08-05 18:37 . 2007-08-05 18:37 -------- d-----w- c:\program files\OpenOffice.org 2.2
2007-08-05 18:34 . 2007-08-05 18:34 -------- d-----w- c:\documents and settings\Utilisateur\Local Settings\Application Data\Thunderbird
2007-08-05 18:34 . 2007-08-05 18:34 -------- d-----w- c:\documents and settings\Utilisateur\Application Data\Thunderbird
2007-08-05 18:33 . 2003-04-29 00:13 -------- d-----w- c:\program files\Mozilla Thunderbird
2007-08-05 18:32 . 2007-08-05 18:32 -------- d-----w- c:\documents and settings\Utilisateur\Local Settings\Application Data\Mozilla
2007-08-05 18:24 . 2001-08-23 15:04 12288 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2007-08-05 18:24 . 2001-08-23 15:04 12288 ----a-w- c:\windows\system32\drivers\mouhid.sys
2007-08-05 18:23 . 2001-08-17 20:02 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2007-08-05 18:23 . 2001-08-17 20:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2007-08-03 13:10 . 2004-08-03 21:08 26496 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2007-08-03 13:02 . 2007-08-03 13:02 -------- d-----w- c:\documents and settings\Default User\Voisinage réseau
2007-08-03 13:02 . 2007-08-03 13:02 -------- d-----w- c:\documents and settings\Administrateur\Voisinage réseau
2007-08-03 13:02 . 2003-02-23 18:29 -------- d-----w- c:\documents and settings\Utilisateur\Voisinage réseau
2007-08-03 13:02 . 2007-08-03 13:02 -------- d-----w- c:\program files\Atheros
2007-08-03 13:02 . 2007-08-03 13:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Atheros
2007-08-03 13:00 . 2007-08-03 21:20 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2007-08-03 13:00 . 2007-04-16 08:19 11776 ----a-w- c:\windows\system32\drivers\UVCFTR_S.SYS
2007-08-03 13:00 . 2007-08-03 13:00 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2007-08-03 13:00 . 2007-08-03 13:00 -------- d-----w- c:\program files\Apoint2K
2007-08-03 13:00 . 2004-11-16 06:22 101874 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2007-08-03 13:00 . 2003-08-30 08:37 87865 ----a-w- c:\windows\system32\Vxdif.dll
2007-08-03 13:00 . 2007-08-03 21:20 -------- d-----w- c:\documents and settings\Default User\WINDOWS
2007-08-02 12:20 . 2007-08-02 12:20 220184 ----a-w- c:\documents and settings\Utilisateur\Local Settings\Application Data\Interop.Microsoft.Office.Core.dll
2007-07-25 13:05 . 2005-05-11 14:00 245760 -c--a-w- c:\windows\TBTdetect.exe
2007-07-25 12:59 . 2004-08-05 10:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2007-07-24 11:27 . 2006-11-02 23:09 1419232 ----a-w- c:\windows\system32\WdfCoinstaller01005.dll
2007-07-24 11:26 . 2007-04-05 05:19 546112 ----a-w- c:\windows\system32\drivers\ar5211.sys
2007-07-24 11:10 . 2007-08-03 13:14 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2007-07-24 11:09 . 2007-08-03 21:20 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Seven Zip
2007-07-24 11:05 . 2007-08-03 21:39 -------- d-----w- c:\program files\Microsoft SQL Server
2007-07-24 10:57 . 2007-07-24 10:57 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Microsoft Help
2007-07-24 10:57 . 2007-08-03 23:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2007-07-24 10:15 . 2007-08-03 21:20 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Adobe
2007-07-24 10:13 . 2004-01-17 00:17 153096 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-07-24 10:09 . 2006-05-25 17:30 114688 ----a-w- c:\windows\system32\TODDSrv.exe
2007-07-24 10:08 . 2002-11-22 00:57 204800 ----a-w- c:\windows\system32\IVIresizeW7.dll
2007-07-24 10:08 . 2002-11-22 00:57 188416 ----a-w- c:\windows\system32\IVIresizePX.dll
2007-07-24 10:08 . 2002-11-22 00:57 200704 ----a-w- c:\windows\system32\IVIresizeA6.dll
2007-07-24 10:08 . 2002-11-22 00:57 192512 ----a-w- c:\windows\system32\IVIresizeP6.dll
2007-07-24 10:08 . 2002-11-22 00:57 192512 ----a-w- c:\windows\system32\IVIresizeM6.dll
2007-07-24 10:08 . 2002-11-22 00:57 20480 ----a-w- c:\windows\system32\IVIresize.dll
2007-07-24 10:08 . 2007-08-03 21:35 -------- d-----w- c:\program files\InterVideo
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-30 09:32 . 2004-01-31 07:21 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-02-13 11:28 . 2004-01-31 07:21 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-02-13 11:17 . 2004-01-31 07:21 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2008-11-19 08:41 . 2003-10-27 04:29 16640 ----a-w- c:\windows\system32\drivers\WsAudioDevice_383.sys
2008-10-16 13:13 . 2007-07-24 07:35 202776 ----a-w- c:\windows\system32\wuweb.dll
2008-10-16 13:13 . 2007-07-24 07:35 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2008-10-16 13:12 . 2007-07-24 07:35 323608 ----a-w- c:\windows\system32\wucltui.dll
2008-10-16 13:12 . 2007-07-24 07:35 561688 ----a-w- c:\windows\system32\wuapi.dll
2008-10-16 13:09 . 2007-07-24 07:35 51224 ----a-w- c:\windows\system32\wuauclt.exe
2008-10-16 13:09 . 2007-07-24 07:24 92696 ----a-w- c:\windows\system32\cdm.dll
2008-10-16 13:09 . 2007-04-16 20:45 43544 ----a-w- c:\windows\system32\wups2.dll
2008-10-16 13:08 . 2007-07-24 07:35 34328 ----a-w- c:\windows\system32\wups.dll
2008-09-13 03:30 . 2003-02-05 20:04 266240 ----a-w- c:\windows\system32\TubeFinder.exe
2008-06-04 17:42 . 2003-02-05 20:04 9728 ----a-w- c:\windows\system32\PCCLPFR.DLL
2008-05-30 12:19 . 2003-05-09 01:05 507400 ----a-w- c:\windows\system32\XAudio2_1.dll
2008-05-30 12:18 . 2003-05-09 01:05 238088 ----a-w- c:\windows\system32\xactengine3_1.dll
2008-05-30 12:17 . 2003-05-09 01:05 65032 ----a-w- c:\windows\system32\XAPOFX1_0.dll
2008-05-30 12:17 . 2003-05-09 01:05 25608 ----a-w- c:\windows\system32\X3DAudio1_4.dll
2008-05-30 12:11 . 2003-05-09 01:05 467984 ----a-w- c:\windows\system32\d3dx10_38.dll
2008-05-30 12:11 . 2003-05-09 01:05 1491992 ----a-w- c:\windows\system32\D3DCompiler_38.dll
2008-05-30 12:11 . 2003-05-09 01:05 3850760 ----a-w- c:\windows\system32\D3DX9_38.dll
2008-03-05 14:03 . 2003-05-09 01:05 479752 ----a-w- c:\windows\system32\XAudio2_0.dll
2008-03-05 14:03 . 2003-05-09 01:05 238088 ----a-w- c:\windows\system32\xactengine3_0.dll
2008-03-05 14:00 . 2003-05-09 01:05 25608 ----a-w- c:\windows\system32\X3DAudio1_3.dll
2008-03-05 13:56 . 2003-05-09 01:05 1420824 ----a-w- c:\windows\system32\D3DCompiler_37.dll
2008-03-05 13:56 . 2003-05-09 01:05 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2008-02-05 21:07 . 2003-05-09 01:05 462864 ----a-w- c:\windows\system32\d3dx10_37.dll
2007-10-22 01:39 . 2003-05-09 01:05 267272 ----a-w- c:\windows\system32\xactengine2_10.dll
2007-10-22 01:37 . 2003-05-09 01:05 17928 ----a-w- c:\windows\system32\X3DAudio1_2.dll
2007-10-12 13:14 . 2003-05-09 01:05 1374232 ----a-w- c:\windows\system32\D3DCompiler_36.dll
2007-10-12 13:14 . 2003-05-09 01:05 3734536 ----a-w- c:\windows\system32\d3dx9_36.dll
2007-10-02 07:56 . 2003-05-09 01:05 444776 ----a-w- c:\windows\system32\d3dx10_36.dll
2007-09-03 12:03 . 2002-07-15 23:01 368640 ----a-w- c:\windows\system32\ReWire.dll
2007-08-03 23:46 . 2007-07-24 08:32 -------- d-----w- c:\program files\Toshiba
2007-08-03 21:41 . 2007-07-24 08:27 -------- d-----w- c:\program files\Realtek
2007-08-03 21:41 . 2007-07-24 07:35 -------- d-----w- c:\program files\Services en ligne
2007-08-03 21:36 . 2007-07-24 08:31 -------- d-----w- c:\program files\ltmoh
2007-08-03 21:35 . 2007-07-24 08:20 -------- d-----w- c:\program files\Intel
2007-08-03 21:32 . 2007-07-24 08:09 -------- d-----w- c:\program files\Fichiers communs\Java
2007-08-03 21:20 . 2007-07-24 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Vista64
2007-08-03 21:20 . 2007-07-24 07:41 -------- d-----w- c:\documents and settings\All Users\Application Data\SBSI
2007-08-03 21:20 . 2007-07-24 09:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\toshiba
2007-08-03 21:19 . 2007-08-03 13:01 -------- d-----w- c:\documents and settings\Utilisateur\Application Data\InstallShield
2007-08-03 21:19 . 2007-07-24 08:30 -------- d-----w- c:\documents and settings\Administrateur\Application Data\InstallShield
2007-08-03 13:02 . 2007-08-03 13:02 0 --sha-r- c:\windows\system32\drivers\TOSHIBA_Satellite A200_05611-FR_PSAE0E-02M01.MRK
2007-07-24 11:28 . 2007-07-24 11:28 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_TpChoice_01005.Wdf
2007-07-24 11:28 . 2007-07-24 11:28 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-07-24 11:14 . 2007-07-24 11:11 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2007-07-24 11:14 . 2007-07-24 11:11 8014 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2007-07-24 11:05 . 2007-08-03 13:01 68464 ----a-w- c:\documents and settings\Utilisateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-07-24 09:36 . 2007-07-24 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\XP
2007-07-24 08:27 . 2007-07-24 08:27 315392 -c--a-w- c:\windows\HideWin.exe
2007-07-24 08:04 . 2007-07-24 08:04 -------- d-----w- c:\program files\MSXML 4.0
2007-07-24 07:43 . 2007-07-24 07:43 137 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
2007-07-24 07:34 . 2007-07-24 07:34 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2007-07-19 22:57 . 2003-05-09 01:05 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
2007-07-19 16:14 . 2003-05-09 01:05 444776 ----a-w- c:\windows\system32\d3dx10_35.dll
2007-07-19 16:14 . 2003-05-09 01:05 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll
2007-07-19 16:14 . 2003-05-09 01:05 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2007-07-11 09:45 . 2002-12-13 21:36 21632 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2007-07-11 09:40 . 2002-12-13 21:36 12416 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2007-06-30 06:18 . 2007-06-30 06:18 28672 ----a-w- c:\windows\system32\TCtrlIOHook.exe
2007-06-21 21:55 . 2007-06-21 21:55 401408 ----a-w- c:\windows\system32\pvmjpg30.dll
2007-06-20 18:46 . 2003-05-09 01:05 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2007-06-14 23:41 . 2007-07-24 08:27 4429312 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2007-06-13 21:49 . 2007-07-24 08:27 16377344 ----a-w- c:\windows\RTHDCPL.exe
2007-06-12 13:45 . 2007-06-12 13:45 28672 ----a-w- c:\windows\system32\TPeculiarity.dll
2007-05-29 03:39 . 2007-07-24 08:27 1826816 -c--a-w- c:\windows\SkyTel.exe
2007-05-18 12:41 . 2007-05-18 12:41 24576 ----a-w- c:\windows\system32\CeTPPolicy.dll
2007-05-16 15:13 . 2007-07-24 07:35 683520 ----a-w- c:\windows\system32\inetcomm.dll
2007-05-16 14:45 . 2003-05-09 01:05 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2007-05-16 14:45 . 2003-05-09 01:05 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2007-05-16 14:45 . 2003-05-09 01:05 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2007-04-25 23:55 . 2007-07-24 08:27 2162688 -c--a-w- c:\windows\MicCal.exe
2007-04-25 14:22 . 2007-07-24 07:24 144896 ----a-w- c:\windows\system32\schannel.dll
2007-04-23 10:32 . 2007-07-24 07:24 364160 ----a-w- c:\windows\system32\drivers\update.sys
2007-04-18 16:14 . 2007-07-24 07:24 2854400 ----a-w- c:\windows\system32\msi.dll
2007-04-18 12:44 . 2007-07-24 07:24 669696 ----a-w- c:\windows\system32\wininet.dll
2007-04-13 09:05 . 2007-04-13 09:05 103928 ----a-w- c:\windows\system32\CddbLangNL.dll
2007-04-13 09:05 . 2007-04-13 09:05 83448 ----a-w- c:\windows\system32\CddbLangJA.dll
2007-04-13 09:05 . 2007-04-13 09:05 108024 ----a-w- c:\windows\system32\CddbLangIT.dll
2007-04-13 09:05 . 2007-04-13 09:05 103928 ----a-w- c:\windows\system32\CddbLangFR.dll
2007-04-13 09:05 . 2007-04-13 09:05 103928 ----a-w- c:\windows\system32\CddbLangES.dll
2007-04-13 09:05 . 2007-04-13 09:05 103928 ----a-w- c:\windows\system32\CddbLangDE.dll
2007-04-13 09:04 . 2007-04-13 09:04 808440 ----a-w- c:\windows\system32\CDDBUI.dll
2007-04-13 09:04 . 2007-04-13 09:04 796152 ----a-w- c:\windows\system32\CDDBControl.dll
2007-04-13 01:21 . 2007-04-13 01:21 271360 ----a-w- c:\windows\system32\mscoree.dll
2007-04-04 16:55 . 2003-05-09 01:04 261480 ----a-w- c:\windows\system32\xactengine2_7.dll
2007-04-04 16:53 . 2003-05-09 01:04 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2007-04-03 04:31 . 2007-04-03 04:31 77312 ----a-w- c:\windows\system32\TWAIN_32.DLL
2007-04-03 04:31 . 2007-04-03 04:31 69632 ----a-w- c:\windows\system32\TWUNK_32.EXE
2007-04-03 04:31 . 2007-04-03 04:31 48560 ----a-w- c:\windows\system32\TWUNK_16.EXE
2007-03-26 10:22 . 2007-03-26 10:22 105856 ----a-w- c:\windows\system32\drivers\tdudf.sys
2007-03-24 02:19 . 2007-07-24 08:27 9715200 -c--a-w- c:\windows\RTLCPL.exe
2007-03-17 13:44 . 2007-07-24 07:24 293376 ----a-w- c:\windows\system32\winsrv.dll
2007-03-15 14:57 . 2003-05-09 01:04 443752 ----a-w- c:\windows\system32\d3dx10_33.dll
2007-03-12 14:42 . 2003-05-09 01:04 1123696 ----a-w- c:\windows\system32\D3DCompiler_33.dll
2007-03-12 14:42 . 2003-05-09 01:04 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2007-03-12 13:02 . 2007-03-12 13:02 947472 ----a-w- c:\windows\system32\msjava.dll
2007-03-08 15:37 . 2007-07-24 07:24 578560 ----a-w- c:\windows\system32\user32.dll
2008-10-30 19:00 . 2003-03-16 22:23 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-10-30 19:00 . 2003-03-16 22:23 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-10-30 19:00 . 2003-03-16 22:23 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-10-30 19:00 . 2003-03-16 22:23 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-10-30 19:00 . 2003-03-16 22:23 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SgeIconOvl]
@="{ba930330-a721-11d3-a7b9-00500464ee16}"
[HKEY_CLASSES_ROOT\CLSID\{ba930330-a721-11d3-a7b9-00500464ee16}]
2005-06-08 17:30 77824 ----a-w- c:\program files\Utimaco\SafeGuard Easy\SgeDrse.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SgeIconOvl2]
@="{2030D939-54A7-4fea-9B06-49EA77EFC87F}"
[HKEY_CLASSES_ROOT\CLSID\{2030D939-54A7-4fea-9B06-49EA77EFC87F}]
2005-06-08 17:30 77824 ----a-w- c:\program files\Utimaco\SafeGuard Easy\SgeDrse.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2003-04-21 342848]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2003-05-26 68856]
"restorer32_a"="c:\documents and settings\Utilisateur\restorer32_a.exe" [2004-01-31 43520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-26 495616]
"SgeEcView"="c:\program files\Utimaco\SafeGuard Easy\Ecview.exe" [2005-06-08 24576]
"EdWizard"="c:\program files\Utimaco\SafeGuard Easy\EdWizard.exe" [2005-06-08 245760]
"UERLKUP"="c:\program files\Utimaco\SafeGuard Easy\uerlkupn.exe" [2006-03-29 36864]
"D066UUtility"="c:\windows\TWAIN_32\D66U\D066UUTY.EXE" [2000-07-06 32768]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-03-20 213936]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-03-20 86960]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-08-05 185896]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-12-27 73728]
"TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-08-12 266240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 30720]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 30720]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 30720]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acc‚l‚rateur de d‚marrage AutoCAD.lnk - c:\program files\Fichiers communs\Autodesk Shared\acstart16.exe [2005-3-5 10872]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 30720]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 14:28 110592 ----a-w- c:\windows\system32\SGLogEx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 10:27 69632 ----a-w- c:\windows\system32\SGLogNotification.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uerclt]
2006-03-29 13:14 77824 ----a-w- c:\windows\system32\uercltn.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Accélérateur de démarrage AutoCAD.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Accélérateur de démarrage AutoCAD.lnk
backup=c:\windows\pss\Accélérateur de démarrage AutoCAD.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^Memeo AutoSync Launcher.lnk]
path=c:\documents and settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\Memeo AutoSync Launcher.lnk
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^WD Anywhere Backup Launcher.lnk]
path=c:\documents and settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\WD Anywhere Backup Launcher.lnk
backup=c:\windows\pss\WD Anywhere Backup Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Autodesk\\Maya8.5\\bin\\maya.exe"=
"c:\\Program Files\\Electric Rain\\Swift 3D\\Version 4.00\\Program\\Swift3D.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Program Files\\Next Limit\\Maxwell\\mxcl.exe"=
"c:\\Program Files\\Toshiba\\ConfigFree\\CFXFER.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
R0 AES-256;AES-256;c:\windows\system32\drivers\AES256.sys [08/06/2005 18:47 17952]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [06/12/2005 16:11 35328]
R0 SgeFlt;SgeFlt;c:\windows\system32\drivers\SGEFLT.sys [08/06/2005 18:48 54880]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [31/01/2004 08:21 108289]
R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [26/03/2007 11:22 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [19/02/2007 11:15 134016]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [22/05/2002 10:40 24652]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [16/05/2008 16:12 102400]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [31/01/2004 08:21 194817]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [31/01/2004 08:21 434945]
S3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys --> c:\windows\system32\DRIVERS\TpChoice.sys [?]
S3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [27/10/2003 05:29 16640]
S4 AutoSyncService;Memeo AutoSync service;c:\program files\Memeo\AutoSync\MemeoService.exe [06/07/2007 16:28 31768]
.
Contenu du dossier 'Tâches planifiées'
2004-01-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2007-08-03 c:\windows\Tasks\Rappel d'enregistrement 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-07-24 10:00]
2007-08-17 c:\windows\Tasks\Rappel d'enregistrement 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-07-24 10:00]
2007-08-03 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2007-07-24 10:00]
.
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.cherche.us/keyword/%s
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.regioncentre.fr/
uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: chat-land.org
FF - ProfilePath - c:\documents and settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\73eieb4s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
HKCU-Run-mserv - c:\documents and settings\Utilisateur\Application Data\seres.exe
HKCU-Run-ntias64 - c:\documents and settings\Utilisateur\Local Settings\Application Data\ntias64\ntias64.dll
HKLM-Run-restorer32_a - c:\windows\system32\restorer32_a.exe
HKLM-Run-11029214 - c:\documents and settings\All Users\Application Data\11029214\11029214.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2004-02-05 06:04
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,9f,a7,29,31,41,
02,26,b4,c8,28,51,af,b0,29,a3,98,d5,5d,ba,af,b5,3a,47,f0,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,2f,c7,5d,66,14,
0f,17,48,71,3b,04,66,8b,46,0d,96,1c,56,97,38,6f,10,70,30,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,7c,8e,74,05,94,
bb,9f,46,25,da,ec,7e,55,20,c9,26,d3,0b,31,93,cd,cb,44,58,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,db,97,35,13,98,
ef,98,38,3e,1e,9e,e0,57,5a,93,61,f7,0e,11,6a,c8,c6,cf,ee,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,f4,40,0b,01,61,
19,e5,3b,cd,44,cd,b9,a6,33,6c,cd,49,d1,bd,eb,29,be,ea,4a,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,e2,67,4c,9b,41,
91,27,a3,b0,18,ed,a7,3f,8d,37,a4,7a,20,20,a0,dc,d3,85,40,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,08,80,6a,8d,13,
e8,49,bd,31,77,e1,ba,b1,f8,68,02,35,e1,92,77,40,2e,07,e7,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,f5,65,ed,be,fd,
58,43,93,83,6c,56,8b,a0,85,96,ab,ce,f6,90,f6,08,30,04,30,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,48,32,44,02,9d,
08,04,13,51,fa,6e,91,28,9e,14,cc,ec,ff,a8,b9,7f,e1,7b,a3,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,d7,91,47,39,a1,
9e,67,17,b1,cd,45,5a,a8,c4,f8,b9,f8,38,ea,3d,d5,da,a9,64,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,3a,0e,b5,a6,89,
a7,fc,2a,e3,0e,66,d5,eb,bc,2f,6b,2f,94,c7,03,a1,0b,38,88,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,2b,8c,dc,71,bb,
ca,46,92,fa,ea,66,7f,d4,3b,6b,70,11,7c,60,5a,1b,08,03,6c,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\system32\SGLogEx.dll
c:\windows\system32\SGLogNotification.dll
c:\windows\system32\uercltn.dll
c:\windows\system32\USWERRLN.dll
c:\windows\system32\uerlibws.dll
c:\windows\system32\GetUserSid.dll
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Avira\AntiVir Desktop\avsda.dll
c:\program files\Utimaco\SafeGuard Easy\SGEDRV.dll
c:\program files\Utimaco\SafeGuard Easy\FLTAPI.dll
c:\program files\Utimaco\SafeGuard Easy\SgeUtil.dll
c:\windows\system32\LogMsgApp.Dll
c:\program files\Utimaco\SafeGuard Easy\SgMsgBhk.dll
- - - - - - - > 'lsass.exe'(1036)
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
Heure de fin: 2004-02-05 6:06
ComboFix-quarantined-files.txt 2004-02-05 05:06
Avant-CF: 5 945 401 344 octets libres
Après-CF: 5 903 532 032 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
516 --- E O F --- 2002-02-07 20:16
En vous remerciant une fois de plus pour votre aide précieuse...