ouf enfin le rapport après plusieurs messages pendant le scan comme PEV.cf.exe erreur application pev.exe etc le rapport ci-joint merci pour ta patience
ComboFix 11-01-07.01 - Patrice 08/01/2011 14:58:17.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.549 [GMT 1:00]
Lancé depuis: c:\documents and settings\Patrice\Bureau\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Clément\Application Data\xssend2
c:\documents and settings\Patrice\Mes documents\Readiris.DUS
c:\program files\INSTALL.LOG
c:\windows\pack.epk
c:\windows\system32\kqpvjjpp.ini
c:\windows\system32\leohdknk.ini
c:\windows\system32\ykvdoilu.ini
c:\windows\winhelp.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-12-08 au 2011-01-08 ))))))))))))))))))))))))))))))))))))
.
2011-01-08 11:16 . 2011-01-08 11:16 -------- d-----w- c:\program files\Common Files
2011-01-08 11:16 . 2005-06-02 00:09 86016 ------w- c:\windows\system32\BrWebIns.dll
2011-01-08 11:16 . 2005-06-02 00:08 69632 ------w- c:\windows\system32\BRWEBUP.EXE
2011-01-08 11:16 . 2004-12-03 00:26 188416 ------w- c:\windows\system32\PDRVINST.DLL
2011-01-08 11:16 . 2000-01-28 11:19 513536 ------w- c:\program files\Fichiers communs\InstallShield\WebUpdate\IFTW.EXE
2011-01-08 11:16 . 2000-01-28 11:19 331776 ------w- c:\program files\Fichiers communs\InstallShield\WebUpdate\WebUpdate.exe
2011-01-08 11:16 . 2000-01-28 11:19 24576 ------w- c:\program files\Fichiers communs\InstallShield\WebUpdate\RasThunk.dll
2011-01-08 11:16 . 2000-01-28 11:19 132096 ------w- c:\program files\Fichiers communs\InstallShield\WebUpdate\ISiteLite.dll
2011-01-08 11:16 . 2011-01-08 11:16 -------- d-----w- C:\Brother
2011-01-08 11:15 . 2002-12-05 13:12 692224 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-01-08 11:15 . 2002-12-05 13:10 155648 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-01-08 11:15 . 2002-12-02 14:22 5632 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-01-08 11:15 . 2002-12-02 12:33 57344 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-01-08 11:15 . 2002-12-02 12:33 237568 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-01-08 11:15 . 2011-01-08 11:15 282756 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-01-08 11:15 . 2011-01-08 11:15 163972 ----a-w- c:\program files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-01-08 11:05 . 2011-01-08 11:05 -------- d-----w- c:\program files\SYSTRAN
2011-01-08 11:05 . 2011-01-08 11:09 -------- d-----w- c:\windows\system32\E177E04D548C4006A465EEB92D3DE021
2011-01-08 00:13 . 2011-01-08 00:13 -------- d-----w- C:\TDSSKiller_Quarantine
2011-01-08 00:12 . 2011-01-08 10:32 -------- d-----w- C:\tdsskiller
2011-01-06 15:54 . 2011-01-08 09:50 -------- d-----w- c:\program files\ZHPDiag
2011-01-01 23:36 . 2005-06-06 16:51 11264 ----a-w- c:\windows\system32\drivers\vulfntr.sys
2011-01-01 23:36 . 2005-01-05 17:02 6912 ----a-w- c:\windows\system32\drivers\vulfnth.sys
2011-01-01 23:36 . 2003-10-03 15:28 45056 ----a-w- c:\windows\system32\vusetup.dll
2011-01-01 17:05 . 2011-01-06 09:03 -------- d-----w- c:\windows\system32\NtmsData
2010-12-31 19:42 . 2010-12-31 19:42 -------- d-----r- c:\documents and settings\NetworkService\Favoris
2010-12-31 19:42 . 2010-12-31 19:42 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-12-31 19:42 . 2010-12-31 19:42 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-12-30 17:13 . 2009-08-12 09:37 38672 ----a-w- c:\windows\system32\pcleUtil.dll
2010-12-30 17:13 . 2009-01-28 09:52 142337 ----a-w- c:\windows\system32\Wait.exe
2010-12-30 17:12 . 2010-09-27 13:38 323640 ----a-w- c:\windows\system32\hcwpnp32.dll
2010-12-30 17:12 . 2010-08-26 16:07 118840 ----a-w- c:\windows\system32\hcwi2c32.dll
2010-12-30 17:12 . 2009-02-16 21:09 831554 ----a-w- c:\windows\system32\hcwtvwnd.dll
2010-12-30 17:12 . 2006-10-10 17:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
2010-12-30 16:18 . 2010-12-30 17:13 -------- d-----w- c:\program files\WinTV
2010-12-30 16:07 . 2006-09-08 11:40 96256 ----a-w- c:\windows\system32\hcwcp.ax
2010-12-30 16:07 . 2006-09-08 11:40 139264 ----a-w- c:\windows\system32\hcwecppp.ax
2010-12-30 16:07 . 2002-09-23 14:11 40960 ----a-w- c:\windows\system32\hcwxds.dll
2010-12-30 16:07 . 2010-08-16 16:20 396928 ----a-w- c:\windows\system32\drivers\hcw88vid.sys
2010-12-30 16:07 . 2010-08-16 16:20 216576 ----a-w- c:\windows\system32\drivers\hcw88bda.sys
2010-12-30 16:07 . 2010-08-16 16:20 321408 ----a-w- c:\windows\system32\drivers\hcw88tse.sys
2010-12-30 16:07 . 2010-08-16 16:20 78080 ----a-w- c:\windows\system32\drivers\hcw88tun.sys
2010-12-30 16:07 . 2010-08-16 16:20 12288 ----a-w- c:\windows\system32\drivers\hcw88rc5.sys
2010-12-30 16:07 . 2010-08-16 16:20 17920 ----a-w- c:\windows\system32\drivers\hcw88bar.sys
2010-12-30 16:07 . 2007-11-08 09:59 9539 ----a-w- c:\windows\system32\drivers\hcw88r9x.sys
2010-12-30 10:25 . 2002-06-03 16:18 237624 ----a-r- c:\windows\Primary.exe
2010-12-29 12:33 . 2010-12-29 12:33 -------- d-----w- c:\documents and settings\Patrice\Local Settings\Application Data\PackageAware
2010-12-28 20:04 . 2010-12-28 20:14 -------- d-----r- c:\documents and settings\LocalService\Mes documents
2010-12-28 16:17 . 2010-12-28 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Mender
2010-12-28 14:13 . 2010-12-28 14:13 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple
2010-12-28 14:13 . 2010-12-28 14:13 -------- d-----w- c:\documents and settings\Clément\Application Data\gmvtbcmhvvxbc3zrjel2szwamu2dety2
2010-12-28 14:13 . 2010-12-28 14:13 -------- d-----w- c:\documents and settings\Clément\Application Data\wpfotteydz
2010-12-28 13:18 . 2010-12-28 13:18 -------- d-sh--w- c:\documents and settings\Matthieu\PrivacIE
2010-12-27 08:12 . 2010-12-27 08:12 -------- d-----w- c:\documents and settings\Clément\Application Data\Malwarebytes
2010-12-24 07:19 . 2010-11-10 04:33 6273872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{3DD608C4-7ED3-4B33-99CC-635045BDFC49}\mpengine.dll
2010-12-15 10:03 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2010-12-15 10:02 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2010-12-11 19:49 . 2010-12-11 19:49 -------- d-----w- c:\program files\Fichiers communs\NSV
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 17:09 . 2008-07-24 15:52 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 17:08 . 2008-07-24 15:52 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-18 18:12 . 2006-08-24 13:59 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-05-09 13:00 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2008-08-08 11:27 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-10 04:33 . 2006-10-27 13:07 6273872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2010-11-06 00:21 . 2004-08-05 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2004-08-05 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2004-08-05 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-08-05 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-05 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:14 . 2004-08-05 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 14:07 . 2004-08-05 12:00 1853440 ----a-w- c:\windows\system32\win32k.sys
2010-10-19 09:41 . 2009-10-03 21:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2007-12-26 20:57 . 2008-01-05 13:43 1702143 ----a-r- c:\program files\tk85.dll
2007-12-26 20:54 . 2008-01-05 13:43 1449112 ----a-r- c:\program files\tcl85.dll
2007-01-14 13:24 . 2009-04-26 14:22 585728 ----a-w- c:\program files\lame.exe
2004-09-23 21:09 . 2008-01-05 13:43 13822 ----a-w- c:\program files\dsdrv4.vxd
2004-09-23 21:09 . 2008-01-05 13:43 8833 ----a-w- c:\program files\dsdrv4.sys
2001-09-28 16:00 . 2008-12-11 08:14 164864 ----a-w- c:\program files\UNWISE.EXE
2007-05-22 17:14 . 2007-08-13 07:04 8784 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-05-22 17:17 . 2007-08-13 07:04 245408 ----a-w- c:\program files\mozilla firefox\plugins\unicows.dll
2008-08-29 18:21 . 2008-10-29 13:32 106496 ----a-w- c:\program files\mozilla firefox\components\FototaggerMGrab.dll
2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-25 335872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SetDefPrt"="c:\program files\Brother\Brmfl05a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-07-22 933888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Contr"leur d''tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2011-1-8 802816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0SsiEfr.ex\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe\0SsiEfr.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winfi58.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winhk48.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winps04.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AOL 9.0 Icône AOL.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\AOL 9.0 Icône AOL.lnk
backup=c:\windows\pss\AOL 9.0 Icône AOL.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoStart IR.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\AutoStart IR.lnk
backup=c:\windows\pss\AutoStart IR.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Contrôleur d'état.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Contrôleur d'état.lnk
backup=c:\windows\pss\Contrôleur d'état.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinTV Recording Status..lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\WinTV Recording Status..lnk
backup=c:\windows\pss\WinTV Recording Status..lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Clément^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Clément\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Patrice^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Patrice\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 11:49 932288 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-11-10 11:49 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-01-02 14:41 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 02:33 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverMax]
2008-11-10 08:32 5347672 ----a-w- c:\program files\Innovative Solutions\DriverMax\devices.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
2009-11-02 08:58 222736 ----a-w- c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadwin PrintScreen]
2008-12-09 11:08 495616 ----a-w- c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-03-18 15:32 136176 ----atw- c:\documents and settings\Clément\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2008-06-24 18:34 41824 ----a-w- c:\program files\Fichiers communs\AOL\1159112407\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2008-06-10 19:56 1406024 ----a-w- c:\program files\Microsoft IntelliPoint\ipoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-05-30 10:30 292136 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2007-10-25 14:33 563984 ----a-w- c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2007-10-25 14:37 2178832 ----a-w- c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Octoshape Streaming Services]
2009-01-08 13:44 70936 ----a-w- c:\documents and settings\Patrice\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2008-11-11 19:23 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMDeviceManager]
2006-08-25 15:24 1142922 ----a-w- c:\program files\Fichiers communs\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-01-26 14:31 2144088 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
2009-01-04 14:11 1783808 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44 248552 ----a-w- c:\program files\Fichiers communs\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-12-10 12:28 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-11-03 07:59 204288 ------w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\LeechFTP\\Leechftp.exe"=
"c:\\Program Files\\AOL 9.0a\\waol.exe"=
"c:\\Bases\\kavupd.exe"=
"d:\\Jeux\\World of Warcraft\\WoW-1.12.0-frFR-downloader.exe"=
"c:\\Program Files\\AOL 9.0a\\aol.exe"=
"d:\\Jeux\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-frFR-downloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\ICQ6\\ICQ.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Spamihilator\\cdcc.exe"=
"c:\\Program Files\\Spamihilator\\dccproc.exe"=
"c:\\Program Files\\Spamihilator\\spamihilator.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\play2p\\play2p.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Clément\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Clément\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\WinTV\\WinTV7\\WinTV7.exe"=
R1 SLEE_16_DRIVER;Steganos Live Encryption Engine 16 [Driver];c:\windows\system32\drivers\sleen16.sys [11/10/2007 11:24 79104]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [04/01/2009 15:11 141312]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [15/07/2009 22:50 108289]
R2 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\TVServer\HAUPPA~1.EXE [30/12/2010 18:13 558592]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [10/12/2010 13:29 92008]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [05/10/2006 21:11 13592]
R3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;c:\windows\system32\drivers\hcw88bda.sys [30/12/2010 17:07 216576]
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\drivers\hcw88rc5.sys [30/12/2010 17:07 12288]
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;c:\windows\system32\drivers\hcw88tse.sys [30/12/2010 17:07 321408]
R3 hcw88vid;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [30/12/2010 17:07 396928]
S0 Winfi58;Winfi58;c:\windows\system32\Drivers\Winfi58.sys --> c:\windows\system32\Drivers\Winfi58.sys [?]
S0 Winhk48;Winhk48;c:\windows\system32\Drivers\Winhk48.sys --> c:\windows\system32\Drivers\Winhk48.sys [?]
S0 Winps04;Winps04;c:\windows\system32\Drivers\Winps04.sys --> c:\windows\system32\Drivers\Winps04.sys [?]
S2 gupdate1c97e4a65553072;Google Update Service (gupdate1c97e4a65553072);c:\program files\Google\Update\GoogleUpdate.exe [24/01/2009 18:37 133104]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [20/12/2010 15:55 251760]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\359.tmp --> c:\windows\system32\359.tmp [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-12-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2011-01-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-25 12:31]
2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-24 17:37]
2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-24 17:37]
2011-01-07 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-08-02 17:18]
2011-01-08 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-10-05 20:11]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:64020
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {50DC58D0-C870-4BE6-BC41-971ED2D5F022} - hxxp://www.super-messenger.fr/tab/HookWlmEx.exe
FF - ProfilePath - c:\documents and settings\Patrice\Application Data\Mozilla\Firefox\Profiles\k5mxdx1m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/ig?hl=fr&source=iglk
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 64020
FF - prefs.js: network.proxy.type - 0
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-Wincf58.sys
SafeBoot-Winru37.sys
MSConfigStartUp-EPGServiceTool - c:\progra~1\WinTV\EPG Services\System\EPGClient.exe
MSConfigStartUp-mssend - c:\documents and settings\Clément\Application Data\xssend2\svcnost.exe
MSConfigStartUp-SpybotSnD - c:\program files\Spybot - Search & Destroy\SpybotSD.exe
MSConfigStartUp-Sys151 - c:\windows\Sys151.exe
MSConfigStartUp-Sys152 - c:\windows\Sys152.exe
MSConfigStartUp-Sys153 - c:\windows\Sys153.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-08 15:22
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\359.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{234399AF-0FDB-9235-B859A4E3AC2ADE1B}\{19B8A235-5775-8B53-4D38DBAF8988D503}\{76727453-9A12-1EF5-D0F3E23CAC7A8CDF}*]
"WVZENWCHWFKXMRXM1FQWBAYGMD1"=hex:01,00,01,00,00,00,00,00,fa,de,c6,7c,16,d0,d3,
6d,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A356E26F-F64B-8F5D-7C18E49D604F2F76}\{6A54AA76-7D92-69B0-4B2831BB70973615}\{981C58D8-528B-1766-742A6B252CC7665F}*]
"WVZENWCHWFKXMRXM1FQWBAYGMD1"=hex:01,00,01,00,00,00,00,00,fa,de,c6,7c,16,d0,d3,
6d,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3428)
c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\MatroskaProp\MatroskaProp.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\WinTV\TVServer\CAPTUR~4.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\wanmpsvc.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-01-08 15:31:13 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-01-08 14:31
Avant-CF: 3 179 933 696 octets libres
Après-CF: 3 296 403 456 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - A79F795C029AD5AD6F859E74452342FB