Voilà, je pense avoir supprimé tous ces logiciels, a part search settings que je ne trouve pas, meme en cherchant sur tout le disque...
Voilà le rapport de combofix:
ComboFix 11-07-18.01 - Jerem 18/07/2011 15:26:59.2.2 - x86
Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3068.1943 [GMT 2:00]
Lancé depuis: c:\users\Jerem\Desktop\jerem.exe
Commutateurs utilisés :: c:\users\Jerem\Desktop\CFScript.txt
AV: COMODO Defense+ *Disabled/Updated* {A7500527-8708-6548-7035-7F679C5FCEA5}
AV: Panda Cloud Antivirus *Disabled/Updated* {86971480-9989-6750-B122-681A86518D59}
FW: COMODO Defense+ *Disabled* {9F6B8402-CD67-6410-5B6A-D652628C89DE}
SP: COMODO Defense+ *Disabled/Updated* {1C31E4C3-A132-6AC6-4A85-4415E7D88418}
SP: Panda Cloud Antivirus *Disabled/Updated* {3DF6F564-BFB3-68DE-8B92-5368FDD6C7E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\506DDFBE983F4BC384B865F423B2D798.TMP
c:\windows\506DDFBE983F4BC384B865F423B2D798.TMP\WiseCustomCalla.dll
c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP\WiseCustomCalla.dll
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Application Updater
-------\Service_Lavasoft Ad-Aware Service
-------\Service_Norton Internet Security
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-06-18 au 2011-07-18 ))))))))))))))))))))))))))))))))))))
.
.
2011-07-18 13:37 . 2011-07-18 13:40 -------- d-----w- c:\users\Jerem\AppData\Local\temp
2011-07-18 13:37 . 2011-07-18 13:37 -------- d-----w- c:\users\Invité\AppData\Local\temp
2011-07-18 13:37 . 2011-07-18 13:37 -------- d-----w- c:\users\Eric\AppData\Local\temp
2011-07-18 13:37 . 2011-07-18 13:37 -------- d-----w- c:\users\eric.PC-de-Jerem\AppData\Local\temp
2011-07-18 13:37 . 2011-07-18 13:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-18 10:17 . 2011-07-18 10:07 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-07-18 10:07 . 2011-07-18 13:17 -------- d-----w- C:\32788R22FWJFW
2011-07-18 06:33 . 2011-07-18 09:53 -------- d-----w- c:\users\Jerem\{26722992-de30-4c5a-8e6a-a2c43806ec0a}
2011-07-18 06:23 . 2011-07-18 13:37 54016 ----a-w- c:\windows\system32\drivers\wpvxaijq.sys
2011-07-17 23:55 . 2011-07-18 06:19 -------- d-----w- c:\program files\lala
2011-07-17 22:56 . 2011-07-17 22:56 -------- d-----w- c:\program files\Application Updater
2011-07-17 22:56 . 2011-07-17 22:56 -------- d-----w- c:\program files\pdfforge Toolbar
2011-07-17 22:23 . 2011-07-17 22:42 -------- d-----w- C:\jerem
2011-07-17 17:31 . 2011-07-18 13:03 -------- d-----w- c:\program files\ZHPDiag
2011-07-17 15:06 . 2011-07-17 15:06 -------- d-----w- c:\users\Jerem\AppData\Roaming\Malwarebytes
2011-07-17 15:06 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-17 15:06 . 2011-07-17 15:06 -------- d-----w- c:\programdata\Malwarebytes
2011-07-17 15:06 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-17 14:50 . 2011-07-17 14:50 -------- d-----w- c:\users\Jerem\AppData\Roaming\SUPERAntiSpyware.com
2011-07-17 14:50 . 2011-07-17 14:50 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-07-17 14:27 . 2011-07-18 13:01 -------- dc----w- c:\windows\system32\DRVSTORE
2011-07-17 14:27 . 2011-07-17 14:27 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-07-17 14:23 . 2011-07-17 14:23 -------- d-----w- c:\users\Jerem\AppData\Local\Sunbelt Software
2011-07-17 14:20 . 2011-07-18 13:01 -------- d-----w- c:\programdata\Lavasoft
2011-07-17 12:46 . 2011-07-17 12:46 -------- d-----w- c:\users\Jerem\AppData\Roaming\Panda Security
2011-07-17 12:40 . 2011-07-17 12:40 -------- d-----w- c:\program files\Toolbar Cleaner
2011-07-17 12:40 . 2011-07-17 12:41 -------- d-----w- c:\users\Jerem\AppData\Local\panda2_0dn
2011-07-17 12:39 . 2011-07-18 13:39 -------- d-----w- c:\programdata\Panda Security URL Filtering
2011-07-17 12:34 . 2011-07-17 12:37 -------- d-----w- c:\program files\Panda Security
2011-07-17 12:34 . 2011-07-17 12:34 -------- d-----w- c:\programdata\Panda Security
2011-07-17 12:33 . 2011-07-17 12:34 -------- d-----w- C:\temp
2011-07-17 10:32 . 2011-07-17 13:59 -------- d-----w- c:\program files\Common Files\PC Tools
2011-07-17 10:15 . 2011-07-17 13:59 -------- d-----w- c:\program files\AVAST Software
2011-07-17 10:15 . 2011-07-17 13:11 -------- d-----w- c:\programdata\AVAST Software
2011-07-17 10:14 . 2011-07-17 13:04 -------- d-----w- c:\programdata\PC Tools
2011-07-17 08:49 . 2011-07-17 09:14 -------- d--h--w- c:\windows\msdownld.tmp
2011-07-17 08:49 . 2011-07-17 08:55 -------- d-----w- c:\program files\PCSX2 0.9.8
2011-07-17 07:38 . 2011-07-17 07:38 -------- d-----w- c:\users\Jerem\AppData\Local\Ascaron Entertainment
2011-07-17 07:33 . 2008-07-12 06:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2011-07-17 07:33 . 2008-07-12 06:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2011-07-17 07:32 . 2011-07-17 07:32 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2011-07-17 07:32 . 2011-07-17 07:32 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2011-07-17 06:57 . 2011-07-17 06:57 -------- d-----w- c:\program files\Deep Silver
2011-07-16 13:15 . 2011-07-16 13:15 -------- d-----w- c:\users\Jerem\AppData\Roaming\StokedBigAir
2011-07-15 10:01 . 2011-07-15 10:01 -------- d-----w- c:\program files\NVIDIA Corporation
2011-07-15 09:57 . 2010-06-02 02:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-07-15 09:57 . 2010-06-02 02:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-07-15 09:57 . 2010-06-02 02:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-07-15 09:56 . 2010-05-26 09:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-07-15 09:56 . 2010-05-26 09:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-07-15 09:56 . 2010-05-26 09:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-07-15 09:56 . 2010-05-26 09:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-07-15 09:56 . 2010-05-26 09:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-07-15 09:56 . 2010-02-04 08:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2011-07-15 09:56 . 2010-02-04 08:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
2011-07-15 09:56 . 2010-02-04 08:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
2011-07-15 09:56 . 2010-02-04 08:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2011-07-15 09:56 . 2008-10-15 04:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2011-07-15 09:56 . 2008-10-15 04:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2011-07-15 09:56 . 2008-10-15 04:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2011-07-15 09:50 . 2011-07-15 09:51 -------- d-----w- c:\program files\Faery - Legends of Avalon
2011-07-15 07:23 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{72943CB4-0251-42ED-8EC1-7777826F73C8}\mpengine.dll
2011-07-15 07:19 . 2006-02-07 13:40 204800 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-07-15 07:19 . 2006-02-07 13:40 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-07-15 07:19 . 2006-02-07 13:40 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-07-15 07:19 . 2006-02-07 13:45 757760 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-07-15 07:19 . 2011-07-15 07:19 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-07-15 07:19 . 2011-07-15 07:19 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-07-14 09:09 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
2011-07-14 09:08 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-14 09:08 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-14 09:07 . 2011-07-14 09:07 -------- d-----w- c:\program files\Yontoo Layers
2011-07-13 21:10 . 2011-07-13 21:10 -------- d-----w- c:\users\Jerem\AppData\Roaming\FUEL
2011-07-13 20:03 . 2011-07-13 20:03 -------- d-----w- c:\windows\system32\xlive
2011-07-13 20:03 . 2011-07-14 09:04 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2011-07-13 20:00 . 2008-07-12 06:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2011-07-13 19:44 . 2011-07-13 19:44 -------- d-----w- c:\program files\Codemasters
2011-07-13 19:25 . 2011-07-13 19:26 -------- d-----w- c:\program files\WildGames
2011-07-13 11:52 . 2011-07-13 11:52 -------- d-----w- c:\program files\WildTangent Games
2011-07-10 11:01 . 2011-07-10 11:01 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-10 11:01 . 2011-07-10 11:01 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-07-04 19:17 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-18 00:37 . 2008-01-21 02:24 71680 ----a-w- c:\windows\system32\drivers\tdx.sys
2011-07-17 12:45 . 2008-09-13 07:13 196608 ----a-w- c:\windows\system32\nvvsvc.exe
2011-05-24 17:14 . 2009-10-09 10:53 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-02 15:58 . 2011-06-16 14:38 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 12:49 . 2011-06-16 14:38 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 12:49 . 2011-06-16 14:38 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-29 12:49 . 2011-06-16 14:38 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-29 12:49 . 2011-06-16 14:38 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-29 12:49 . 2011-06-16 14:38 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-28 21:47 . 2011-04-28 21:47 365888 ----a-w- c:\windows\system32\PSUNCpl.cpl
2011-04-28 11:57 . 2011-04-28 11:57 112712 ----a-w- c:\windows\system32\drivers\PSINProt.sys
2011-04-28 11:57 . 2011-04-28 11:57 99400 ----a-w- c:\windows\system32\drivers\PSINFile.sys
2011-04-28 11:57 . 2011-04-28 11:57 143432 ----a-w- c:\windows\system32\drivers\PSINAflt.sys
2011-04-28 11:57 . 2011-04-28 11:57 126024 ----a-w- c:\windows\system32\drivers\PSINKNC.sys
2011-04-28 11:57 . 2011-04-28 11:57 111176 ----a-w- c:\windows\system32\drivers\PSINProc.sys
2011-04-21 15:00 . 2011-06-16 14:38 833024 ----a-w- c:\windows\system32\wininet.dll
2011-04-21 14:57 . 2011-06-16 14:38 78336 ----a-w- c:\windows\system32\ieencode.dll
2011-04-21 13:28 . 2011-06-16 14:38 389632 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:16 . 2011-06-16 14:38 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-21 13:08 . 2011-06-16 14:38 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-10 11:01 . 2011-05-11 10:59 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}]
2011-05-13 13:25 86696 ----a-w- c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-02-28 22:11 191488 ------w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}"= "c:\program files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll" [2011-05-13 86696]
.
[HKEY_CLASSES_ROOT\clsid\{b821bf60-5c2d-41eb-92dc-3e4ccd3a22e4}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-13 13584928]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-13 92704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-09-11 446556]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-26 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-05-27 1800464]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-07-27 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-18 767312]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2011-04-28 439616]
"Panda Security URL Filtering"="c:\programdata\Panda Security URL Filtering\Panda_URL_Filtering.exe" [2011-04-27 231592]
"SearchSettings"="c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe" [2011-06-24 534880]
.
c:\users\Jerem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrMfcWnd]
2006-11-24 19:20 622592 ----a-w- c:\program files\Brother\Brmfcmon\BrMfcWnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer for HP TouchSmart]
2008-09-25 17:42 189736 ------w- c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter3]
2006-07-19 13:51 65536 ----a-w- c:\program files\Brother\ControlCenter3\BrCtrCen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDAgent]
2008-09-26 01:36 1148200 ------w- c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-08-01 14:14 202032 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
2011-06-24 16:22 534880 ----a-w- c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartMenu]
2008-09-23 10:03 912688 ----a-w- c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSMAgent]
2008-09-25 17:41 1152296 ------w- c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2008-06-13 17:11 210216 ------w- c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 CFcatchme;CFcatchme;c:\users\Jerem\AppData\Local\Temp\CFcatchme.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 PCTSFileEnum;PCTSFileEnum;c:\program files\PC Tools Security\PCTSFiles.exe [x]
R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-06 691696]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2010-05-27 130960]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2010-05-27 29520]
S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [2011-04-28 126024]
S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 59376]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe [2011-07-17 77824]
S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456]
S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-07-18 136512]
S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [2011-04-28 143432]
S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [2011-04-28 99400]
S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [2011-04-28 111176]
S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [2011-04-28 112712]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2011-07-17 365904]
S2 SBSDWSCService;SBSD Security Center Service;c:\users\Jerem\Documents\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-04-29 54784]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-07-21 100184]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-08-28 3664384]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-08-06 44576]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 09:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
.
2000-12-31 c:\windows\Tasks\HPCeeScheduleForAdministrator.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-10-23 09:34]
.
2009-11-24 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-10-11 13:31]
.
2011-07-17 c:\windows\Tasks\User_Feed_Synchronization-{4555CD27-C70F-409D-9FC1-77C2CDB27A1A}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.mystart.com/?pr=vmn&id=pandasecuritytb&v=2_0
mStart Page = hxxp://www.google.com
IE: &Recherche AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\fr-FR\local\search.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{256AA203-8D41-47EB-B797-C4F3C0DA9432}: NameServer = 156.154.70.25,156.154.71.25
FF - ProfilePath - c:\users\Jerem\AppData\Roaming\Mozilla\Firefox\Profiles\grfv3fb9.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UT [...] &gfns=1&q=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
URLSearchHooks-{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - (no file)
WebBrowser-{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-18 15:39
Windows 6.0.6001 Service Pack 1 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
.
c:\windows\$NtUninstallKB7981$:SummaryInformation 0 bytes hidden from API
.
Scan terminé avec succès
Fichiers cachés: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1354417510-1443585376-2791320165-1000\Software\SecuROM\License information*]
"datasecu"=hex:25,29,70,f2,4e,b2,5d,24,b7,2a,90,74,94,2b,da,bf,f0,41,a1,ab,94,
9c,50,98,2b,fd,6d,5f,76,9e,5e,0f,e6,54,ae,0d,4f,b9,98,cc,ee,51,92,61,5a,c2,\
"rkeysecu"=hex:48,28,8d,83,a2,f0,f8,37,ea,30,2c,fb,b9,b0,24,f3
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'Explorer.exe'(6032)
c:\programdata\Panda Security URL Filtering\panda_url_filtering.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Heure de fin: 2011-07-18 15:48:49 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-07-18 13:48
ComboFix2.txt 2011-07-18 10:54
.
Avant-CF: 26 216 865 792 octets libres
Après-CF: 26 088 648 704 octets libres
.
- - End Of File - - 8B5EED3B9FF9F50BEF9A52328E97FAC5