voila le rapport ComboFix!:
ComboFix 09-11-04.05 - PISTILLI 05/11/2009 18:49.1.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3069.1806 [GMT 1:00]
Lancé depuis: c:\users\PISTILLI\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2368636544-1982421479-1015652006-500
c:\$recycle.bin\S-1-5-21-2616400443-3417004063-1195618842-500
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-05 au 2009-11-05 ))))))))))))))))))))))))))))))))))))
.
2009-11-05 18:13 . 2009-11-05 18:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-05 17:27 . 2009-11-05 17:27 -------- d-----w- c:\users\PISTILLI\.netbeans
2009-11-05 17:27 . 2009-11-05 17:27 -------- d-----w- c:\users\PISTILLI\.netbeans-registration
2009-11-05 17:27 . 2009-11-05 17:27 4096 d-----w- c:\program files\sges-v3-prelude
2009-11-05 17:25 . 2009-11-05 17:25 -------- d-----w- C:\Sun
2009-11-05 17:15 . 2009-11-05 17:25 12288 d-----w- c:\program files\NetBeans 6.7.1
2009-11-05 17:12 . 2009-11-05 17:36 4096 d-----w- c:\users\PISTILLI\.nbi
2009-11-03 06:51 . 2009-08-13 14:40 43008 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-03 06:51 . 2009-08-13 14:39 340480 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-03 06:51 . 2009-08-13 14:39 346112 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-02 20:34 . 2009-11-05 17:05 8192 d-----w- C:\ToolBar SD
2009-11-01 21:28 . 2009-11-01 21:29 -------- d-----w- C:\rsit
2009-10-30 19:37 . 2009-10-30 19:37 -------- d-----w- c:\program files\Trend Micro
2009-10-30 19:21 . 2009-10-30 19:21 -------- d-----w- c:\program files\iPod
2009-10-30 19:21 . 2009-10-30 19:22 4096 d-----w- c:\program files\iTunes
2009-10-30 19:10 . 2009-10-30 19:10 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-30 11:22 . 2009-10-30 11:22 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-30 10:42 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-30 10:40 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-30 10:40 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-30 10:40 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-29 16:07 . 2009-10-29 16:07 -------- d-----w- c:\users\PISTILLI\AppData\Roaming\Malwarebytes
2009-10-29 16:07 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-29 16:07 . 2009-10-29 16:07 -------- d-----w- c:\programdata\Malwarebytes
2009-10-29 16:07 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-29 16:07 . 2009-10-29 16:07 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 17:04 . 2009-10-24 17:04 0 ----a-r- c:\users\PISTILLI\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
2009-10-22 15:39 . 2009-10-22 15:39 10134 ----a-r- c:\users\PISTILLI\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-10-22 15:39 . 2009-10-22 15:39 -------- d-----w- c:\program files\Microsoft WSE
2009-10-22 15:16 . 2009-10-20 11:33 545280 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-10-22 15:16 . 2009-10-20 11:33 4716544 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\components\cooliris.dll
2009-10-22 15:16 . 2009-10-20 11:33 344064 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-10-22 15:16 . 2009-10-20 11:33 153600 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2009-10-22 15:16 . 2009-10-20 11:33 103424 ----a-w- c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-10-18 20:35 . 2009-10-18 20:35 653560 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-10-14 12:23 . 2009-11-04 15:31 4096 d-----w- c:\users\PISTILLI\AppData\Roaming\FileZilla
2009-10-14 12:18 . 2009-10-14 12:18 4096 d-----w- c:\program files\FileZilla FTP Client
2009-10-11 20:44 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-11 20:44 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-11 20:43 . 2009-10-11 20:44 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-11 20:41 . 2009-10-11 20:42 4096 d-----w- c:\program files\QuickTime
2009-10-07 17:10 . 2009-10-07 17:11 -------- d-----w- c:\windows\system32\ca-ES
2009-10-07 17:10 . 2009-10-07 17:11 -------- d-----w- c:\windows\system32\eu-ES
2009-10-07 17:10 . 2009-10-07 17:10 -------- d-----w- c:\windows\system32\vi-VN
2009-10-07 16:37 . 2009-10-07 16:37 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-07 16:37 . 2009-10-07 16:37 -------- d-----w- c:\users\PISTILLI\Office Genuine Advantage
2009-10-07 16:31 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-07 16:31 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-07 16:31 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-07 16:31 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-07 16:30 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-07 16:30 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-07 16:30 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-07 16:30 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-07 16:30 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-07 10:31 . 2009-10-07 10:31 4096 d-----w- c:\windows\system32\EventProviders
2009-10-07 10:28 . 2009-04-11 06:28 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-10-07 10:27 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-10-06 19:39 . 2009-10-06 19:39 -------- d-----w- c:\programdata\HipSoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-05 17:44 . 2008-10-26 20:43 4096 d-----w- c:\users\PISTILLI\AppData\Roaming\Skype
2009-11-05 16:17 . 2008-10-31 16:39 4096 d-----w- c:\programdata\Google Updater
2009-11-05 15:01 . 2008-10-26 20:46 4096 d-----w- c:\users\PISTILLI\AppData\Roaming\skypePM
2009-11-05 14:42 . 2009-09-24 18:20 4096 d-----w- c:\programdata\Lx_cats
2009-11-05 05:54 . 2008-06-13 11:48 669890 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-05 05:54 . 2008-06-13 11:48 123896 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-04 21:27 . 2008-06-13 02:03 12 ----a-w- c:\windows\bthservsdp.dat
2009-11-02 22:06 . 2009-01-06 15:04 1356 ----a-w- c:\users\PISTILLI\AppData\Local\d3d9caps.dat
2009-11-02 12:36 . 2008-11-07 20:33 4096 d-----w- c:\program files\Messenger Plus! Live
2009-10-30 19:21 . 2009-03-09 15:41 -------- d-----w- c:\program files\Common Files\Apple
2009-10-30 12:45 . 2008-06-13 03:39 12288 d-----w- c:\programdata\Microsoft Help
2009-10-30 11:22 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-30 11:22 . 2009-10-30 11:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-10-30 11:21 . 2009-10-30 11:21 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-29 16:05 . 2008-11-11 08:05 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-26 20:25 . 2008-06-13 02:13 4096 d-----w- c:\program files\Hewlett-Packard
2009-10-24 17:07 . 2008-10-26 20:44 4096 d-----w- c:\program files\Windows Live
2009-10-22 19:19 . 2009-02-06 20:17 4096 d-----w- c:\program files\Electronic Arts
2009-10-22 19:19 . 2008-06-13 02:17 12288 d--h--w- c:\program files\InstallShield Installation Information
2009-10-22 15:16 . 2009-04-13 14:49 4096 d-----w- c:\program files\EA Games
2009-10-21 05:18 . 2008-06-13 04:10 4096 d-----w- c:\program files\Java
2009-10-19 16:15 . 2008-10-27 12:51 13982 ----a-w- c:\users\PISTILLI\AppData\Roaming\wklnhst.dat
2009-10-15 19:01 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-15 16:15 . 2009-03-09 15:47 -------- d-----w- c:\users\PISTILLI\AppData\Roaming\Apple Computer
2009-10-14 12:06 . 2008-11-01 09:49 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-07 17:11 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-07 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Sidebar
2009-10-07 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Journal
2009-10-07 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Collaboration
2009-10-07 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Photo Gallery
2009-10-07 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Defender
2009-10-07 17:05 . 2009-10-07 17:05 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2009-10-07 09:58 . 2009-09-16 08:07 4096 d-----w- c:\users\PISTILLI\AppData\Roaming\codeblocks
2009-10-06 19:38 . 2008-06-13 03:00 12288 d-----w- c:\program files\HP Games
2009-10-06 19:37 . 2008-10-30 21:01 1707016 ----a-w- c:\programdata\WildTangent\My HP Game Console\Downloads\fr\Installers\SetupGamesClient.exe
2009-10-01 10:22 . 2009-02-26 12:59 4096 d-----w- c:\program files\Common Files\Real
2009-10-01 10:21 . 2009-10-01 10:21 -------- d-----w- c:\program files\Common Files\xing shared
2009-10-01 08:29 . 2009-10-05 11:08 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-01 01:02 . 2009-10-30 10:42 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-10-30 10:42 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-10-30 10:42 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-10-30 10:42 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-10-30 10:42 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-10-30 10:42 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-10-30 10:42 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-10-30 10:42 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-10-30 10:42 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-10-30 10:42 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-10-30 10:42 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-10-30 10:42 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-10-30 10:42 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-10-30 10:42 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-10-30 10:42 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-30 13:19 . 2009-09-30 13:19 4096 d-----w- c:\program files\Xming
2009-09-30 08:59 . 2009-09-30 08:59 -------- d-----w- c:\program files\SecureW2
2009-09-27 13:19 . 2009-09-27 13:19 -------- d-----w- c:\programdata\Lexmark 3600-4600 Series
2009-09-26 13:44 . 2009-09-26 13:44 471664 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbC44A.tmp.exe
2009-09-25 10:50 . 2009-09-25 10:50 -------- d-----w- c:\users\PISTILLI\AppData\Roaming\FaxCtr
2009-09-25 02:10 . 2009-10-30 10:43 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-30 10:43 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-10-30 10:43 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-10-30 10:43 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-10-30 10:43 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-10-30 10:43 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-10-30 10:43 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-10-30 10:43 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-10-30 10:43 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-10-30 10:43 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-10-30 10:43 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-10-30 10:43 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-10-30 10:43 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-10-30 10:43 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-10-30 10:43 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-10-30 10:43 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-10-30 10:43 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-10-30 10:43 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-10-30 10:43 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-10-30 10:43 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-10-30 10:43 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-10-30 10:43 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-10-30 10:43 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-10-30 10:43 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-10-30 10:43 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-10-30 10:43 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-10-30 10:43 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-24 18:20 . 2009-09-24 18:03 81920 d-----w- c:\program files\Lexmark 3600-4600 Series
2009-09-24 18:17 . 2009-09-24 18:17 -------- d-----w- c:\programdata\App4rTemp
2009-09-24 18:16 . 2009-09-24 18:16 -------- d-----w- c:\users\PISTILLI\AppData\Roaming\Lexmark Productivity Studio
2009-09-24 18:14 . 2009-09-24 18:13 24576 d-----w- c:\program files\Lexmark Fax Solutions
2009-09-24 18:14 . 2009-09-24 18:14 -------- d-----w- c:\programdata\FaxCtr
2009-09-24 18:13 . 2009-09-24 18:13 81920 d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2009-09-24 18:13 . 2009-09-24 18:13 -------- d-----w- c:\program files\Lexmark Tools for Office
2009-09-24 18:12 . 2009-09-24 18:12 -------- d-----w- c:\program files\Lexmark Toolbar
2009-09-23 19:45 . 2009-02-09 21:25 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-23 19:44 . 2009-02-09 21:24 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-09-23 11:23 . 2009-09-23 11:23 4096 d-----w- c:\program files\7-Zip
2009-09-15 11:24 . 2008-11-11 08:05 8192 d-----w- c:\program files\Spybot - Search & Destroy
2009-09-14 09:29 . 2009-10-15 11:57 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 22:15 . 2008-12-20 20:12 4096 d-----w- c:\program files\Microsoft Silverlight
2009-09-10 16:48 . 2009-10-15 11:57 218624 ----a-w- c:\windows\system32\msv1_0.dll
2008-10-26 20:40 . 2008-10-26 20:40 22 --sha-w- c:\windows\SMINST\HPCD.sys
2008-06-13 11:53 . 2008-06-13 11:53 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-01-29 23975720]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-31 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-01 554288]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-04 468264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-10-03 39792]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-06-13 668328]
"lxdxamon"="c:\program files\Lexmark 3600-4600 Series\lxdxamon.exe" [2008-06-13 16040]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2008-06-13 320168]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-01 198160]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-21 458844]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]
c:\users\PISTILLI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'‚cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-8 809488]
Rappels du Calendrier Microsoft Works.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-10-5 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"WorksFUD"=c:\program files\Microsoft Works\wkfud.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):5d,01,f9,f3,71,47,ca,01
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [10/07/2009 10:22 108289]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 03:23 21504]
R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [20/12/2008 21:11 55264]
R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [18/03/2008 15:24 24880]
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service --> c:\windows\system32\lxdxcoms.exe -service [?]
R2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdxserv.exe [24/09/2009 19:16 98984]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [22/08/2008 15:32 361808]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [11/11/2008 09:05 1153368]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 15:28 1533808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [13/06/2008 03:47 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [24/01/2008 14:23 52736]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [17/04/2009 08:48 114528]
S2 gupdate1c9a2ec86e135c7;Google Update Service (gupdate1c9a2ec86e135c7);c:\program files\Google\Update\GoogleUpdate.exe [12/03/2009 09:28 133104]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [21/01/2008 03:23 21504]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe [03/01/2009 17:36 98488]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-11-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-22 08:49]
2009-11-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-31 11:19]
2009-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 08:28]
2009-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-12 08:28]
2009-10-27 c:\windows\Tasks\HPCeeScheduleForPISTILLI.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-06-13 13:14]
2009-11-05 c:\windows\Tasks\User_Feed_Synchronization-{0A56E598-963D-493C-8535-9120CC710C27}.job
- c:\windows\system32\msfeedssync.exe [2009-10-15 03:41]
.
.
------- Examen supplémentaire -------
.
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: &Recherche AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\fr-FR\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {163D76F5-3C40-467B-8AC5-B803DBD45E1F} = 193.50.27.66,193.50.27.67
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game14.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\K-Lite Codec Pack\Real\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\Netscape6\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\Netscape6\nprjplug.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\Netscape6\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\PISTILLI\AppData\Roaming\Mozilla\Firefox\Profiles\dd0z6ycb.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\users\PISTILLI\AppData\Roaming\Mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-05 19:14
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll >>UNKNOWN [0x85C80500]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c80500
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\.Default\Software\KasperskyLab\protected]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.blog]
@DACL=(02 0000)
"order"=dword:0000000a
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.books]
@DACL=(02 0000)
"order"=dword:0000000b
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.calendar]
@DACL=(02 0000)
"order"=dword:0000000c
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country]
@DACL=(02 0000)
"order"=dword:00000002
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.documents]
@DACL=(02 0000)
"order"=dword:0000000d
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.finance]
@DACL=(02 0000)
"order"=dword:0000000e
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.froogle]
@DACL=(02 0000)
"order"=dword:00000008
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.groups]
@DACL=(02 0000)
"order"=dword:00000007
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images]
@DACL=(02 0000)
"order"=dword:00000003
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky]
@DACL=(02 0000)
"order"=dword:00000000
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.maps]
@DACL=(02 0000)
"order"=dword:00000006
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news]
@DACL=(02 0000)
"ontoolbar_start_time"=hex:4c,03,b8,49
"order"=dword:00000005
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000001
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.orkut]
@DACL=(02 0000)
"order"=dword:0000000f
"in_search_list"=dword:00000001
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.patents]
@DACL=(02 0000)
"order"=dword:00000010
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.photos]
@DACL=(02 0000)
"order"=dword:00000011
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.scholar]
@DACL=(02 0000)
"order"=dword:00000012
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site]
@DACL=(02 0000)
"order"=dword:00000001
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video]
@DACL=(02 0000)
"order"=dword:00000004
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.web_history]
@DACL=(02 0000)
"order"=dword:00000009
"in_search_list"=dword:00000001
"ontoolbar"=dword:00000000
"title"=""
"option1"=""
"gadget_options"=""
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\KasperskyLab\protected]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**“% ]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**“% \OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ˆ%*ì*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*ˆ%*ì*\OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Safer Networking Limited\SpybotSnD\Immunization]
@DACL=(02 0000)
"ShowBrowserWarning"=dword:00000001
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Safer Networking Limited\SpybotSnD\Timestamp]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Safer Networking Limited\SpybotSnD\UI]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Safer Networking Limited\SpybotSnD\Verification]
@DACL=(02 0000)
"25e2c910f8494dfc0fb07aff41942bdd"="D41D8CD98F00B204E9800998ECF8427E"
"d45adb259ab080d8bd1321c78d56c85f"="64C839759D795294E3C617592E377F92"
"d2bb5484fc19e99af47a687a7cb84c03"="D41D8CD98F00B204E9800998ECF8427E"
"6effe5eba97c26e90865c721e6273ff9"="801C76A193ED99DF5D356F511957936F"
"2de9a0566d5aec5de6056537121371f9"="D41D8CD98F00B204E9800998ECF8427E"
"ed619a4b1c35f97fce360822cc5c0837"="D41D8CD98F00B204E9800998ECF8427E"
"0eb68dfa9b508045fe37d0e8faf77a82"="D41D8CD98F00B204E9800998ECF8427E"
"a3d6899701aad2ef7b150289957a30c2"="D41D8CD98F00B204E9800998ECF8427E"
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\Safer Networking Limited\SpybotSnD\ViewReportConfig]
@DACL=(02 0000)
"IncludeResults"=dword:00000001
"IncludeSysInfo"=dword:00000001
"IncludeStartup"=dword:00000001
"IncludeWinsockLSPs"=dword:00000001
"IncludeBHO"=dword:00000001
"IncludeActiveX"=dword:00000001
"IncludeBrowserPages"=dword:00000001
"IncludeProcessList"=dword:00000001
"IncludeUninstall"=dword:00000000
"IncludeServices"=dword:00000000
[HKEY_USERS\S-1-5-21-2616400443-3417004063-1195618842-1000\Software\SecuROM\License information*]
"datasecu"=hex:c4,f2,89,e6,70,c2,db,0a,b2,ab,fa,5c,3d,c0,86,8d,57,25,03,23,c7,
cd,8a,7d,c3,1f,0b,a8,16,c1,7f,b5,72,09,6b,c0,83,29,55,f9,79,f8,4f,f7,88,de,\
"rkeysecu"=hex:a7,cd,ef,bf,dc,4c,51,32,f5,e9,02,c9,70,fa,8c,38
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(3616)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Heure de fin: 2009-11-05 19:18
ComboFix-quarantined-files.txt 2009-11-05 18:18
Avant-CF: 69 806 895 104 octets libres
Après-CF: 69 796 888 576 octets libres