Voici le rapport combofix
ComboFix 08-02.05.3 - nadgy 2008-02-07 11:15:59.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.612 [GMT 1:00]
Endroit: C:\Documents and Settings\nadgy\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\nadgy\Mes documents\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE
File::C:\WINDOWS\mrofinu2000351.exeC:\WINDOWS\system32\DRIVERS\nvsmu.sysC:\WINDOWS\system32\spoolsvv.exe Folder::C:\Program Files\SymantecC:\Documents and Settings\All Users\Application Data\Symantec Registry::[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1][-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv] Driver::nvsmu
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-07 to 2008-02-07 ))))))))))))))))))))))))))))))))))))
.
2008-02-07 11:15 . 2008-02-07 11:17 53,248 --a------ C:\WINDOWS\PSEXESVC.EXE
2008-02-06 15:39 . 2008-02-06 15:39 <REP> d-------- C:\Program Files\Trend Micro
2008-02-06 14:57 . 2008-02-06 14:57 <REP> d-------- C:\Program Files\Panda Security
2008-02-05 11:58 . 2008-02-05 11:49 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-05 11:58 . 2008-02-05 11:58 3,447 --a------ C:\WINDOWS\unins000.dat
2008-02-04 15:24 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\Sony
2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony
2008-02-04 15:20 . 2008-02-04 15:20 <REP> d-------- C:\Program Files\MSBuild
2008-02-04 15:17 . 2008-02-04 15:17 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-02-04 15:16 . 2008-02-04 15:16 <REP> d-------- C:\Program Files\Reference Assemblies
2008-02-04 15:16 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Program Files\Sony Setup
2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony Setup
2008-02-03 00:55 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\VSTplugins
2008-02-03 00:55 . 2008-02-03 00:55 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Publish Providers
2008-02-03 00:54 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony
2008-02-02 20:16 . 2008-02-02 20:16 <REP> dr-h----- C:\Documents and Settings\nadgy\Application Data\SecuROM
2008-02-02 20:16 . 2008-02-02 20:16 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-02-02 20:06 . 2008-02-02 20:06 36,864 --a------ C:\WINDOWS\mrofinu2000351.exe.tmp
2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Program Files\SystemRequirementsLab
2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\SystemRequirementsLab
2008-02-02 01:14 . 2008-02-06 22:49 51,048 --a------ C:\WINDOWS\system32\nvapps.xml
2008-02-02 01:14 . 2006-08-18 09:00 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-02-02 01:11 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-02-02 01:10 . 2008-02-02 01:10 <REP> d-------- C:\NVIDIA
2008-01-27 18:50 . 2008-02-06 15:58 <REP> d-------- C:\VundoFix Backups
2008-01-26 17:36 . 2008-01-26 17:36 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\dvdcss
2008-01-26 14:00 . 2008-02-02 23:02 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-26 13:52 . 2008-01-26 14:12 <REP> d-------- C:\Program Files\VirtualDJ
2008-01-26 13:42 . 2008-01-26 13:45 <REP> d-------- C:\Program Files\Windows Live
2008-01-25 15:28 . 2008-01-25 15:29 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\MMTVConfig
2008-01-25 15:27 . 2008-01-25 15:27 <REP> d-------- C:\Program Files\MMTVConfig
2008-01-24 21:48 . 2008-01-25 12:38 <REP> d-------- C:\Program Files\MeuhMeuhTV
2008-01-24 20:53 . 2008-01-24 20:53 <REP> d-------- C:\Program Files\DivX
2008-01-23 10:52 . 2008-01-23 10:52 <REP> d-------- C:\Program Files\DIFX
2008-01-23 10:50 . 2007-01-12 14:57 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
2008-01-23 10:46 . 2008-01-23 10:46 <REP> d-------- C:\Program Files\Broadcom
2008-01-23 10:38 . 2008-01-23 10:38 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\InstallShield
2008-01-21 14:17 . 2008-01-21 14:17 58 --a------ C:\WINDOWS\yesmessenger.ini
2008-01-19 23:54 . 2008-01-19 23:54 583 --a------ C:\WINDOWS\eReg.dat
2008-01-16 19:58 . 2008-01-16 19:58 <REP> d-------- C:\Program Files\Flagship Studios
2008-01-16 19:58 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-01-16 19:58 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-01-16 19:58 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-01-16 15:40 . 2008-01-16 15:40 528 -r-hs---- C:\WINDOWS\egirllic151
2008-01-16 15:38 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-01-16 15:38 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-01-15 12:20 . 2008-02-06 14:21 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\OpenOffice.org2
2008-01-15 10:59 . 2008-01-15 10:59 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
2008-01-15 10:58 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-12 17:56 . 2008-01-12 17:55 57,856 --a------ C:\WINDOWS\taskmon.exe
2008-01-12 12:00 . 2008-01-12 12:00 <REP> d-------- C:\myinst
2008-01-12 11:59 . 2008-01-12 11:59 720,896 --a------ C:\WINDOWS\iun6002.exe
2008-01-12 09:59 . 2008-01-12 09:59 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
2008-01-12 09:59 . 2008-01-12 09:59 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
2008-01-12 09:56 . 2008-01-12 10:27 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Propellerhead Software
2008-01-12 09:56 . 2008-01-12 09:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
2008-01-12 09:55 . 2008-01-12 09:55 <REP> d-------- C:\Program Files\Propellerhead
2008-01-11 23:41 . 2008-01-11 23:41 <REP> d-------- C:\WINDOWS\Downloaded Installations
2008-01-11 12:40 . 2008-01-11 12:40 <REP> d-------- C:\Program Files\KONAMI
2008-01-09 22:38 . 2008-02-02 22:23 <REP> d-------- C:\Program Files\eMule
2008-01-09 21:54 . 2008-01-09 21:54 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\HP
2008-01-09 12:14 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-01-09 12:14 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-01-09 12:14 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-01-09 12:13 . 2008-02-06 16:05 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-01-09 12:13 . 2008-01-09 12:13 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-09 11:06 . 2008-01-30 16:42 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\AdobeUM
2008-01-09 11:00 . 2008-01-09 11:00 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Steinberg
2008-01-09 10:45 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
2008-01-09 10:38 . 2008-01-09 10:38 <REP> d-------- C:\Program Files\Steinberg
2008-01-09 10:35 . 2003-07-31 20:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
2008-01-09 10:35 . 2003-05-26 15:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
2008-01-09 10:35 . 2003-05-26 15:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
2008-01-09 10:33 . 2008-01-09 10:43 <REP> d-------- C:\Program Files\Syncrosoft
2008-01-09 10:33 . 2005-10-17 09:35 704,512 --a------ C:\WINDOWS\system32\SYNSOACC.dll
2008-01-09 10:33 . 2004-05-10 15:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
2008-01-09 10:33 . 2002-11-25 08:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
2008-01-09 10:33 . 2002-11-25 05:46 16,896 --a------ C:\WINDOWS\system32\drivers\SynasUSB.sys
2008-01-09 10:27 . 2008-01-09 10:27 <REP> d-------- C:\Program Files\Alcohol Soft
2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-08 17:03 . 2008-01-08 17:03 <REP> d-------- C:\Program Files\Codemasters
2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys
2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\dllcache\mpe.sys
2008-01-07 18:46 . 2008-01-07 18:46 <REP> d-------- C:\Program Files\MSXML 4.0
2008-01-07 18:46 . 2007-06-14 14:41 466,048 --a------ C:\WINDOWS\system32\drivers\Ltn_stk7070P.sys
2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\dllcache\bdaplgin.ax
2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\BdaPlgIn.ax
2008-01-07 18:46 . 2007-02-02 18:30 13,696 --a------ C:\WINDOWS\system32\drivers\PctvVirtualNdis.sys
2008-01-07 18:46 . 2007-06-13 19:30 13,440 --a------ C:\WINDOWS\system32\drivers\Ltn_stkrc.sys
2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\dllcache\bdasup.sys
2008-01-07 18:45 . 2006-12-01 23:54 626,688 --------- C:\WINDOWS\system32\msvcr80.dll
2008-01-07 18:45 . 2006-12-01 23:54 548,864 --------- C:\WINDOWS\system32\msvcp80.dll
2008-01-07 18:45 . 2004-07-23 09:00 446,464 --------- C:\WINDOWS\system32\HHActiveX.dll
2008-01-07 18:42 . 2008-01-24 20:51 <REP> d-------- C:\Program Files\Pinnacle
2008-01-07 18:40 . 2008-01-24 20:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-01-07 17:28 . 2008-01-07 17:28 <REP> d-------- C:\Program Files\Hercules
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-05 11:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-05 11:06 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-23 09:46 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
2008-01-19 22:54 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-01-19 22:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-15 13:27 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
2008-01-15 09:58 --------- d-----w C:\Program Files\Java
2008-01-09 11:14 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-07 11:29 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-01-07 11:08 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-07 10:49 --------- d-----w C:\Program Files\Wanadoo
2008-01-06 18:51 --------- d-----w C:\Program Files\Windows Plus
2008-01-06 18:50 --------- d-----w C:\Program Files\Synaptics
2008-01-06 18:49 --------- d-----w C:\Program Files\NetWaiting
2008-01-06 18:49 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-06 18:48 --------- d-----w C:\Program Files\HP
2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-06 18:47 --------- d-----w C:\Program Files\CONEXANT
2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-01-06 12:10 --------- d-----w C:\Documents and Settings\nadgy\Application Data\Talkback
2008-01-06 10:30 --------- d-----w C:\Program Files\Symantec
2008-01-06 10:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-06 10:27 --------- d-----w C:\Program Files\Alwil Software
2008-01-06 10:22 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-01-06 10:10 1,658 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP PAVILION DV6000 (RP980EA#ABF)_YN_0Pavi_QCNF6472Z0M_E432250052_46_I30B8_SQuanta_V65.29_BF.3B_T071002_WXP2_L40C_M1023_J80_7AMD_8Turion 64 Technology MK-36_92.01_#060920_N14E44311_(RP980EA#ABF)_XMOBILE.MRK
2008-01-06 10:05 --------- d-----w C:\Program Files\HPQ
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-14 07:28 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28 728,576 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" [2006-05-21 08:43 180224]
"RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36 827392]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 09:23 1187840]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 09:00 7585792]
C:\Documents and Settings\nadgy\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk.disabled [2008-01-07 12:29:08 842]
UberIcon.lnk.disabled [2008-01-07 12:29:11 862]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk.disabled]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk.disabled
backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Gamesurround Muse Pocket.lnk.disabled]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Gamesurround Muse Pocket.lnk.disabled
backup=C:\WINDOWS\pss\Gamesurround Muse Pocket.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Pavilion Webcam Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Pavilion Webcam Tray Icon.lnk
backup=C:\WINDOWS\pss\HP Pavilion Webcam Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LoopBe1 Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LoopBe1 Monitor.lnk
backup=C:\WINDOWS\pss\LoopBe1 Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2007-07-02 11:29 220544 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2006-03-25 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-08-05 20:34 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2006-06-02 01:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 22:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2006-05-03 21:58 458752 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-08-04 08:07 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-08-18 09:00 7585792 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-08-18 09:00 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-08-18 09:00 1617920 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
C:\WINDOWS\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCS]
C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2006-06-19 10:33 163840 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu2000351.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]
C:\WINDOWS\system32\spoolsvv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 20:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LightScribeService"=2 (0x2)
"IDriverT"=3 (0x3)
"Nero BackItUp Scheduler 3"=2 (0x2)
"McrdSvc"=2 (0x2)
"hpqwmiex"=2 (0x2)
"WMPNetworkSvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
"PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
"PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Cpqset"=C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"nwiz"=nwiz.exe /installquiet /nodetect
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
"H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe"
"Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 00:49]
R3 PctvVirtualNdis;Pinnacle Virtual Miniport;C:\WINDOWS\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 18:30]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 Ltn_stk7070P;PCTV based TV tuner device;C:\WINDOWS\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 14:41]
S3 Ltn_stkrc;PCTV Infrared Receiver;C:\WINDOWS\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 19:30]
S3 MPUSens;MPUSens;C:\WINDOWS\system32\drivers\MPUSens.sys [2004-04-26 09:49]
S3 USB28xxBGA;PCTV 100e/150e Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 19:04]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 19:04]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-02 19:27:06 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 11:17:49
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
.
Temps d'accomplissement: 2008-02-07 11:18:18
ComboFix-quarantined-files.txt 2008-02-07 10:18:09
ComboFix2.txt 2008-02-06 17:09:20
.
2008-01-10 09:59:12 --- E O F ---
voici le raport sdfix
SDFix: Version 1.137
Run by Administrateur on 07/02/2008 at 11:27
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\mrofinu2000351.exe.tmp - Deleted
C:\WINDOWS\taskmon.exe - Deleted
Removing Temp Files...
ADS Check:
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 11:30:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:f5,2b,2c,63,d4,ca,e9,17,68,4a,28,23,23,7c,3d,9b,60,02,d8,a9,8f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000000
"ujdew"=hex:f5,2b,2c,63,d4,ca,e9,17,68,4a,28,23,23,7c,3d,9b,60,02,d8,a9,8f,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 10
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 9 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Finished!
en fait je debute dasn le sound design je fai pas vraiment de musique a proprement parler en fait pour tout dire pour l'instant j'essai juste de maitriser un pu plus tous ces prog
re ps: est ce que tu pourrais m'expliquer les manip que je viens de faire et qu'est ce qui c passer je suis assez curieux de savoir comment ca marche c trojan a la con et comment on a fait pour le virer