Voici le rapport, la dernière fois qu'il a redémarré antivir s'est ouvert. Bonne nouvelle ! Vraiment Merci de ton aide !
ComboFix 10-01-03.05 - Tom 04/01/2010 17:04:27.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.3326.2938 [GMT 1:00]
Lancé depuis: c:\documents and settings\Tom\Bureau\MDG.exe.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Tom\LOCALS~1\Temp\install_flash_player.exe
C:\LOG.TXT
c:\windows\system32\drivers\H8SRTdkturuqlvh.sys
c:\windows\system32\H8SRTbmwfxuxoyq.dat
c:\windows\system32\H8SRTcjkvscgrql.dll
c:\windows\system32\H8SRTklvmyxirpi.dll
c:\windows\system32\H8SRTtledqmptam.dll
c:\windows\system32\llbiirc.dll
c:\windows\system32\srcr.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-04 au 2010-01-04 ))))))))))))))))))))))))))))))))))))
.
2010-01-04 14:46 . 2010-01-04 14:46 -------- d-----w- C:\rsit
2010-01-04 14:46 . 2010-01-04 14:46 -------- d-----w- c:\program files\trend micro
2010-01-03 17:40 . 2010-01-03 18:25 -------- d-----w- C:\FindyKill
2010-01-03 17:22 . 2010-01-03 17:23 -------- d-----w- c:\documents and settings\Tom\Application Data\QuickScan
2010-01-03 17:22 . 2010-01-02 23:26 789320 ----a-w- c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\uc5283d8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-01-03 17:22 . 2010-01-02 23:26 697672 ----a-w- c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\uc5283d8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2010-01-03 16:09 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-03 16:09 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-03 16:09 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-03 16:09 . 2010-01-03 16:09 -------- d-----w- c:\program files\Avira
2010-01-03 16:09 . 2010-01-03 16:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-01-01 14:51 . 2010-01-04 14:37 860 ----a-w- c:\windows\system32\krl32mainweq.dll
2009-12-22 20:22 . 2009-12-22 20:22 11520 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-21 17:41 . 2009-12-21 17:57 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-12-21 17:40 . 2009-12-21 18:05 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-12-21 17:18 . 2009-12-21 17:18 -------- d-----w- c:\documents and settings\Tom\Local Settings\Application Data\PunkBuster
2009-12-07 18:47 . 2009-12-21 13:17 -------- d-----w- c:\documents and settings\Tom\Application Data\TwonkyMedia
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 16:08 . 2009-09-12 10:49 16608 ----a-w- c:\windows\gdrv.sys
2010-01-04 14:32 . 2009-09-13 17:37 -------- d-----w- c:\documents and settings\Tom\Application Data\vlc
2009-12-31 13:33 . 2009-09-13 17:25 -------- d-----w- c:\documents and settings\Tom\Application Data\uTorrent
2009-12-31 00:32 . 2009-09-21 18:19 -------- d-----w- c:\documents and settings\Tom\Application Data\dvdcss
2009-12-22 14:48 . 2009-09-26 11:01 -------- d-----w- c:\documents and settings\Tom\Application Data\LimeWire
2009-12-21 17:50 . 2009-11-08 19:01 139152 ----a-w- c:\documents and settings\Tom\Application Data\PnkBstrK.sys
2009-12-21 17:50 . 2009-11-08 19:01 139152 ----a-w- c:\documents and settings\Tom\Application Data\PnkBstrK.sys
2009-12-21 17:40 . 2009-11-08 19:01 794408 ----a-w- c:\windows\system32\pbsvc.exe
2009-12-21 17:40 . 2009-11-08 19:01 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-12-02 18:40 . 2009-09-12 16:59 18440 ----a-w- c:\documents and settings\Tom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 18:14 . 2009-09-30 15:23 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-11-30 16:49 . 2009-11-30 16:49 8704 ----a-w- c:\windows\system32\SpOrder.dll
2009-11-24 14:32 . 2009-09-14 22:09 -------- d-----w- c:\documents and settings\Tom\Application Data\DiskAid
2009-11-24 14:31 . 2009-09-14 21:10 -------- d-----w- c:\documents and settings\Tom\Application Data\TuneAid
2009-11-23 22:07 . 2004-08-05 12:00 80748 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-23 22:07 . 2004-08-05 12:00 500900 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-23 22:07 . 2009-11-23 22:07 68008 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-23 22:07 . 2009-11-23 22:07 -------- d-----w- c:\program files\MSBuild
2009-11-23 22:07 . 2009-11-23 22:07 -------- d-----w- c:\program files\Reference Assemblies
2009-11-23 22:04 . 2009-11-23 22:04 -------- d-----w- c:\program files\MSXML 6.0
2009-11-22 17:50 . 2009-11-22 17:50 -------- d-----w- c:\program files\Microsoft
2009-11-22 17:50 . 2009-11-22 17:50 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-22 17:49 . 2009-09-25 14:21 -------- d-----w- c:\program files\Windows Live
2009-11-22 17:48 . 2009-11-22 17:48 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-11-20 10:01 . 2009-10-30 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\TmForever
2009-11-20 09:20 . 2009-11-20 09:20 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-11-20 09:20 . 2009-11-20 09:20 -------- d--h--r- c:\documents and settings\Tom\Application Data\SecuROM
2009-11-15 19:50 . 2009-11-15 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2009-11-15 19:42 . 2009-11-15 19:42 -------- d-----w- c:\program files\MSXML 4.0
2009-11-15 19:41 . 2009-09-12 10:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-08 19:41 . 2009-11-08 19:41 -------- d-----w- c:\documents and settings\Tom\Application Data\DAEMON Tools Pro
2009-10-30 14:54 . 2009-11-01 18:10 289072 ----a-w- c:\documents and settings\Tom\Application Data\Microsoft\Internet Explorer\Quick Launch\uTorrent.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-13 133104]
"DAEMON Tools Lite"="e:\logiciel\Demons Tools\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"PMCLoader"="e:\logiciel\Pinnacle\PMCLoader.exe" [2007-07-26 105544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="m’|\ü" [X]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-07 16862208]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"LogitechVideoRepair"="e:\logiciel\Labtec\ISStart.exe" [2004-12-14 458752]
"LogitechVideoTray"="e:\logiciel\Labtec\LogiTray.exe" [2004-12-14 217088]
"Adobe Reader Speed Launcher"="e:\logiciel\Adobe\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - e:\logiciel\SetPoint\SetPoint.exe [2009-9-13 692224]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- e:\logiciel\Adobe\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-05 12:00 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-04-23 13:51 691656 ----a-w- e:\logiciel\Demons Tools\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-09-13 12:39 133104 ----atw- c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- e:\logiciel\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-12-14 16:19 221184 ----a-w- c:\windows\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-25 03:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Logiciel\\uTorrent\\uTorrent.exe"=
"e:\\Logiciel\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\Jeux\\Officiels\\COD5\\CoDWaWmp.exe"=
"e:\\Jeux\\Officiels\\COD5\\CoDWaW.exe"=
"e:\\Logiciel\\steam\\SteamApps\\to_t0m\\counter-strike source\\hl2.exe"=
"e:\\Jeux\\Officiels\\COD4\\iw3mp.exe"=
"e:\\Jeux\\Officiels\\TMNF\\TmNationsForever\\TmForever.exe"=
"c:\\Documents and Settings\\Tom\\Application Data\\Microsoft\\Internet Explorer\\Quick Launch\\uTorrent.exe"=
"e:\\Jeux\\Officiels\\Crysis\\Bin32\\Crysis.exe"=
"e:\\Jeux\\Officiels\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Logiciel\\IP Privacy\\IP Privacy.exe"=
"e:\\Logiciel\\TwonkyMedia\\twonkymediaserver.exe"=
"e:\\Logiciel\\TwonkyMedia\\twonkymedia.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [03/01/2010 17:09 108289]
R2 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\EnergySaver\GSvr.exe [12/09/2009 11:50 80392]
R3 AmplusnetPrivacyTools;AmplusnetPrivacyTools;c:\windows\system32\AmplusnetPrivacyTools.exe [30/11/2009 17:48 2347008]
R3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\system32\drivers\Ltn_stk7070P.sys [15/11/2009 20:42 466048]
R3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\system32\drivers\Ltn_stkrc.sys [15/11/2009 20:42 13440]
S3 Media Center 14 Service;Media Center 14 Service;e:\logiciel\Media Center\JRService.exe [18/10/2009 18:09 346624]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/09/2009 19:31 721904]
.
Contenu du dossier 'Tâches planifiées'
2009-12-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1532298954-839522115-1003Core.job
- c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-13 12:39]
2010-01-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1532298954-839522115-1003UA.job
- c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-13 12:39]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.iphon.fr/
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:8080
LSP: c:\windows\system32\PCProxy.dll
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\uc5283d8.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.fr
FF - component: c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\uc5283d8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\uc5283d8.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\documents and settings\Tom\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\logiciel\Adobe\Reader\browser\nppdf32.dll
FF - plugin: e:\logiciel\iTunes\Mozilla Plugins\npitunes.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-PMCRemote - (no file)
HKLM-Run-IPPrivacy - (no file)
MSConfigStartUp-Steam - e:\logiciel\Steam.exe
AddRemove-abgx360 - e:\abgx360\uninstall.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-Steam App 240 - e:\logiciel\steam.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-04 17:08
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(940)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(996)
c:\windows\system32\PCProxy.dll
- - - - - - - > 'explorer.exe'(1732)
e:\logiciel\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
e:\logiciel\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
e:\logiciel\Labtec\FxSvr2.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2010-01-04 17:09:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-04 16:09
Avant-CF: 92 873 117 696 octets libres
Après-CF: 92 910 649 344 octets libres
- - End Of File - - 9D0001DC4CD59514630D341F3453CD70