J'ai le même problème voici le rapport Combofix
Merci d'avance si quelqu'un peut m'aider.
ComboFix 09-01-05.05 - HP_Propriétaire 2009-01-06 11:16:54.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.511.204 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\av.dat
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSdxcp.dll
c:\windows\system32\TDSSmtve.dat
c:\windows\system32\TDSSnvuo.dll
c:\windows\system32\TDSSoitu.dll
c:\windows\system32\TDSSvoqm.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-04 03:00 . 2009-01-04 03:00 <REP> d-------- c:\program files\Fichiers communs\xing shared
2009-01-04 00:06 . 2009-01-04 00:06 <REP> d-------- c:\program files\CCleaner
2009-01-02 23:24 . 2009-01-02 23:50 <REP> d-------- c:\documents and settings\HP_Propriétaire\Application Data\LimeWire
2008-12-27 09:19 . 2009-01-01 00:46 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-27 09:19 . 2008-12-27 09:19 1,409 --a------ c:\windows\QTFont.for
2008-12-19 05:37 . 2009-01-06 11:05 <REP> d-------- c:\windows\ie8updates
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 06:35 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\uTorrent
2009-01-05 20:38 --------- d-----w c:\program files\Partouche
2009-01-04 02:00 --------- d-----w c:\program files\Fichiers communs\Real
2009-01-03 11:31 --------- d-----w c:\program files\eMule
2008-12-23 06:27 35,646 ----a-w c:\documents and settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-11-08 01:39 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\Todae
2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\dllcache\gdi32.dll
2008-10-21 12:40 19,610 ----a-w c:\program files\Fichiers communs\eticikery.inf
2008-10-21 12:40 19,091 ----a-w c:\program files\Fichiers communs\meriviko.ban
2008-10-21 12:40 19,022 ----a-w c:\program files\Fichiers communs\gerapec.db
2008-10-21 12:40 18,771 ----a-w c:\windows\aliv.exe
2008-10-21 12:40 16,732 ----a-w c:\program files\Fichiers communs\akudycob.dat
2008-10-21 12:40 16,600 ----a-w c:\program files\Fichiers communs\utejexuti.ban
2008-10-21 12:40 13,847 ----a-w c:\windows\erop.reg
2008-10-21 12:40 12,630 ----a-w c:\windows\ifeves.pif
2008-10-21 12:40 11,071 ----a-w c:\windows\quxi.reg
2008-10-21 12:40 10,807 ----a-w c:\documents and settings\All Users\Application Data\xiwy.com
2008-10-21 12:40 10,465 ----a-w c:\windows\hapuhal.reg
2008-10-21 12:40 10,362 ----a-w c:\program files\Fichiers communs\kytaty.exe
2008-10-21 11:27 19,920 ----a-w c:\windows\cuhagona.bat
2008-10-21 11:27 18,049 ----a-w c:\documents and settings\All Users\Application Data\ikydosade.sys
2008-10-21 11:27 17,058 ----a-w c:\windows\system32\kosyvo.bat
2008-10-21 11:27 15,589 ----a-w c:\program files\Fichiers communs\riqovat.db
2008-10-21 11:27 13,624 ----a-w c:\program files\Fichiers communs\safajavu.dl
2008-10-21 11:27 10,787 ----a-w c:\program files\Fichiers communs\heduruzyza.ban
2008-10-21 11:27 10,417 ----a-w c:\windows\bizakuweg.exe
2008-10-21 11:27 10,349 ----a-w c:\program files\Fichiers communs\hahi.ban
2008-10-21 11:09 17,859 ----a-w c:\program files\Fichiers communs\sapywoget.pif
2008-10-21 11:09 15,645 ----a-w c:\documents and settings\All Users\Application Data\yfynilaxy.com
2008-10-21 11:09 14,286 ----a-w c:\program files\Fichiers communs\isaz.com
2008-10-21 11:09 14,151 ----a-w c:\documents and settings\All Users\Application Data\xixodoxyt.scr
2008-10-21 11:09 12,915 ----a-w c:\windows\lyhyfify.pif
2008-10-21 11:09 12,616 ----a-w c:\documents and settings\HP_Propriétaire\Application Data\otijotijo.exe
2008-10-21 11:09 11,723 ----a-w c:\documents and settings\All Users\Application Data\hupuvydy.bat
2008-10-21 11:09 10,969 ----a-w c:\program files\Fichiers communs\havatigun.sys
2008-10-21 11:09 10,811 ----a-w c:\windows\system32\qadyf.pif
2008-10-21 08:56 94,208 ----a-w c:\windows\DUMP82dc.tmp
2008-10-21 08:45 94,208 ----a-w c:\windows\DUMP75cc.tmp
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:59 332,800 ----a-w c:\windows\system32\dllcache\netapi32.dll
2006-12-30 22:21 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((( snapshot@2009-01-03_23.42.09.85 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-09-06 16:43:28 216,800 ----a-w c:\windows\ie7\spuninst\spuninst.exe
- 2008-08-22 01:06:30 72,704 ----a-w c:\windows\system32\admparse.dll
+ 2007-08-13 17:39:20 71,680 ----a-w c:\windows\system32\admparse.dll
- 2008-08-22 01:06:16 128,512 ----a-w c:\windows\system32\advpack.dll
+ 2008-08-26 08:11:45 124,928 ----a-w c:\windows\system32\advpack.dll
- 2008-08-22 01:07:08 18,944 ----a-w c:\windows\system32\corpol.dll
+ 2004-08-05 18:00:00 35,328 ----a-w c:\windows\system32\corpol.dll
- 2008-08-22 01:06:30 72,704 ----a-w c:\windows\system32\dllcache\admparse.dll
+ 2007-08-13 17:39:20 71,680 ----a-w c:\windows\system32\dllcache\admparse.dll
- 2008-08-22 01:06:16 128,512 ----a-w c:\windows\system32\dllcache\advpack.dll
+ 2008-08-26 08:11:45 124,928 ----a-w c:\windows\system32\dllcache\advpack.dll
- 2008-08-22 01:07:08 18,944 ----a-w c:\windows\system32\dllcache\corpol.dll
+ 2004-08-05 18:00:00 35,328 ----a-w c:\windows\system32\dllcache\corpol.dll
- 2008-08-22 01:05:16 346,624 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-08-26 08:11:45 347,136 ----a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-22 01:05:10 217,088 ----a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-08-26 08:11:45 214,528 ----a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-22 01:00:28 68,608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2007-08-13 17:18:02 60,416 ----a-w c:\windows\system32\dllcache\hmmapi.dll
- 2008-08-22 01:05:20 61,952 ----a-w c:\windows\system32\dllcache\icardie.dll
+ 2008-08-26 08:11:45 63,488 ----a-w c:\windows\system32\dllcache\icardie.dll
- 2008-08-22 01:06:24 162,304 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-08-25 08:39:40 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-22 01:06:36 124,928 ----a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-08-26 08:11:45 153,088 ----a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-22 01:06:40 228,864 ----a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-08-26 08:11:45 230,400 ----a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-22 01:06:24 163,840 ----a-w c:\windows\system32\dllcache\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
- 2008-07-29 20:58:08 3,670,112 ----a-w c:\windows\system32\dllcache\ieapfltr.dat
+ 2007-07-01 03:31:33 2,455,488 ----a-w c:\windows\system32\dllcache\ieapfltr.dat
- 2008-08-22 00:42:22 443,392 ----a-w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-08-26 08:11:46 383,488 ----a-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-22 01:06:44 385,024 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-08-26 08:11:46 384,512 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 17:45:18 78,336 ----a-w c:\windows\system32\dllcache\ieencode.dll
- 2008-08-22 01:10:34 11,985,408 ----a-w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-03 17:12:27 6,066,176 ----a-w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-22 01:05:24 186,880 ----a-w c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 17:54:10 191,488 ----a-w c:\windows\system32\dllcache\iepeers.dll
- 2008-08-22 01:06:20 55,808 ----a-w c:\windows\system32\dllcache\iernonce.dll
+ 2008-08-26 08:11:48 44,544 ----a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-22 01:06:02 1,778,688 ----a-w c:\windows\system32\dllcache\iertutil.dll
+ 2008-08-26 08:11:48 267,776 ----a-w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-22 01:06:24 71,680 ----a-w c:\windows\system32\dllcache\iesetup.dll
+ 2007-08-13 17:39:12 55,296 ----a-w c:\windows\system32\dllcache\iesetup.dll
- 2008-09-08 22:23:38 637,984 ----a-w c:\windows\system32\dllcache\iexplore.exe
+ 2008-08-23 05:56:15 635,848 ----a-w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-22 01:05:14 35,840 ----a-w c:\windows\system32\dllcache\imgutil.dll
+ 2007-08-13 17:36:06 36,352 ----a-w c:\windows\system32\dllcache\imgutil.dll
- 2008-08-22 01:06:16 94,720 ----a-w c:\windows\system32\dllcache\inseng.dll
+ 2007-08-13 17:39:02 92,672 ----a-w c:\windows\system32\dllcache\inseng.dll
- 2008-08-22 01:06:30 552,960 ----a-w c:\windows\system32\dllcache\jscript.dll
+ 2007-08-13 17:38:04 491,520 ----a-w c:\windows\system32\dllcache\jscript.dll
- 2008-08-22 01:06:58 28,672 ----a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-08-26 08:11:49 27,648 ----a-w c:\windows\system32\dllcache\jsproxy.dll
- 2008-08-22 01:08:00 43,008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
+ 2007-08-13 17:44:18 40,960 ----a-w c:\windows\system32\dllcache\licmgr10.dll
- 2008-08-22 01:05:48 580,608 ----a-w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-08-26 08:11:49 459,264 ----a-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-22 01:05:22 53,760 ----a-w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-08-26 08:11:49 52,224 ----a-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-22 01:04:54 45,568 ----a-w c:\windows\system32\dllcache\mshta.exe
+ 2007-08-13 17:32:30 45,568 ----a-w c:\windows\system32\dllcache\mshta.exe
- 2008-12-14 14:00:58 5,699,584 ----a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-08-27 09:11:52 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-22 01:05:08 70,656 ----a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-26 08:11:52 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-22 01:05:00 48,128 ----a-w c:\windows\system32\dllcache\mshtmler.dll
+ 2007-08-13 17:01:12 48,128 ----a-w c:\windows\system32\dllcache\mshtmler.dll
- 2008-08-22 00:57:56 156,160 ----a-w c:\windows\system32\dllcache\msls31.dll
+ 2007-08-13 17:54:10 156,160 ----a-w c:\windows\system32\dllcache\msls31.dll
- 2008-08-22 01:07:50 193,536 ----a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-08-26 08:11:52 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
- 2008-08-22 01:05:34 630,272 ----a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-08-26 08:11:52 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
- 2008-08-22 01:07:50 116,224 ----a-w c:\windows\system32\dllcache\occache.dll
+ 2008-08-26 08:11:52 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
- 2008-08-22 01:05:14 45,056 ----a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-26 08:11:52 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
- 2008-08-22 01:07:58 105,984 ----a-w c:\windows\system32\dllcache\url.dll
+ 2008-08-26 08:11:52 105,984 ----a-w c:\windows\system32\dllcache\url.dll
- 2008-08-22 01:08:22 1,206,784 ----a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-08-26 08:11:53 1,159,680 ----a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-22 01:06:36 434,176 ----a-w c:\windows\system32\dllcache\vbscript.dll
+ 2007-08-13 17:54:10 413,696 ----a-w c:\windows\system32\dllcache\vbscript.dll
- 2008-08-22 01:07:20 755,200 ----a-w c:\windows\system32\dllcache\VGX.dll
+ 2007-07-12 23:30:52 765,952 ----a-w c:\windows\system32\dllcache\vgx.dll
- 2008-08-22 01:08:08 236,544 ----a-w c:\windows\system32\dllcache\webcheck.dll
+ 2008-08-26 08:11:53 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-22 01:08:06 878,592 ----a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-08-26 08:11:54 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
- 2008-08-22 01:05:16 346,624 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-08-26 08:11:45 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-22 01:05:10 217,088 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-08-26 08:11:45 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-10-25 01:54:35 247,904 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-01-04 06:03:13 247,104 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2008-08-22 01:05:20 61,952 ----a-w c:\windows\system32\icardie.dll
+ 2008-08-26 08:11:45 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-08-22 01:06:24 162,304 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-08-25 08:39:40 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-08-22 01:06:36 124,928 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-08-26 08:11:45 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2008-08-22 01:06:40 228,864 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-08-26 08:11:45 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2008-08-22 01:06:24 163,840 ----a-w c:\windows\system32\ieakui.dll
+ 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
- 2008-07-29 20:58:08 3,670,112 ----a-w c:\windows\system32\ieapfltr.dat
+ 2007-07-01 03:31:33 2,455,488 ----a-w c:\windows\system32\ieapfltr.dat
- 2008-08-22 00:42:22 443,392 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-08-26 08:11:46 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-08-22 01:06:44 385,024 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-08-26 08:11:46 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2007-08-13 17:45:18 78,336 ----a-w c:\windows\system32\ieencode.dll
- 2008-08-22 01:10:34 11,985,408 ----a-w c:\windows\system32\ieframe.dll
+ 2008-10-03 17:12:27 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-08-22 01:05:24 186,880 ----a-w c:\windows\system32\iepeers.dll
+ 2007-08-13 17:54:10 191,488 ----a-w c:\windows\system32\iepeers.dll
- 2008-08-22 01:06:20 55,808 ----a-w c:\windows\system32\iernonce.dll
+ 2008-08-26 08:11:48 44,544 ----a-w c:\windows\system32\iernonce.dll
- 2008-08-22 01:06:02 1,778,688 ----a-w c:\windows\system32\iertutil.dll
+ 2008-08-26 08:11:48 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-08-22 01:06:24 71,680 ----a-w c:\windows\system32\iesetup.dll
+ 2007-08-13 17:39:12 55,296 ----a-w c:\windows\system32\iesetup.dll
- 2008-08-22 00:58:12 181,760 ----a-w c:\windows\system32\ieui.dll
+ 2007-08-13 17:54:10 180,736 ----a-w c:\windows\system32\ieui.dll
- 2008-08-22 01:05:14 35,840 ----a-w c:\windows\system32\imgutil.dll
+ 2007-08-13 17:36:06 36,352 ----a-w c:\windows\system32\imgutil.dll
- 2008-08-22 01:06:16 94,720 ----a-w c:\windows\system32\inseng.dll
+ 2007-08-13 17:39:02 92,672 ----a-w c:\windows\system32\inseng.dll
- 2008-08-22 01:06:30 552,960 ----a-w c:\windows\system32\jscript.dll
+ 2007-08-13 17:38:04 491,520 ----a-w c:\windows\system32\jscript.dll
- 2008-08-22 01:06:58 28,672 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-08-26 08:11:49 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2008-08-22 01:08:00 43,008 ----a-w c:\windows\system32\licmgr10.dll
+ 2007-08-13 17:44:18 40,960 ----a-w c:\windows\system32\licmgr10.dll
- 2008-08-22 01:05:48 580,608 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-08-26 08:11:49 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-08-22 01:05:22 53,760 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-08-26 08:11:49 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-22 01:05:22 13,312 ----a-w c:\windows\system32\msfeedssync.exe
+ 2007-08-13 17:36:40 12,288 ----a-w c:\windows\system32\msfeedssync.exe
- 2008-08-22 01:04:54 45,568 ----a-w c:\windows\system32\mshta.exe
+ 2007-08-13 17:32:30 45,568 ----a-w c:\windows\system32\mshta.exe
- 2008-12-14 14:00:58 5,699,584 ----a-w c:\windows\system32\mshtml.dll
+ 2008-08-27 09:11:52 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-22 01:05:08 70,656 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-08-26 08:11:52 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-08-22 01:05:00 48,128 ----a-w c:\windows\system32\mshtmler.dll
+ 2007-08-13 17:01:12 48,128 ----a-w c:\windows\system32\mshtmler.dll
- 2008-08-22 00:57:56 156,160 ----a-w c:\windows\system32\msls31.dll
+ 2007-08-13 17:54:10 156,160 ----a-w c:\windows\system32\msls31.dll
- 2008-08-22 01:07:50 193,536 ----a-w c:\windows\system32\msrating.dll
+ 2008-08-26 08:11:52 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-08-22 01:05:34 630,272 ----a-w c:\windows\system32\mstime.dll
+ 2008-08-26 08:11:52 671,232 ----a-w c:\windows\system32\mstime.dll
- 2008-08-22 01:07:50 116,224 ----a-w c:\windows\system32\occache.dll
+ 2008-08-26 08:11:52 102,912 ----a-w c:\windows\system32\occache.dll
- 2007-02-13 15:09:17 278,528 ----a-w c:\windows\system32\pncrt.dll
+ 2009-01-04 02:00:16 278,528 ----a-w c:\windows\system32\pncrt.dll
- 2007-02-13 15:09:18 6,656 ----a-w c:\windows\system32\pndx5016.dll
+ 2009-01-04 02:00:21 6,656 ----a-w c:\windows\system32\pndx5016.dll
- 2007-02-13 15:09:18 5,632 ----a-w c:\windows\system32\pndx5032.dll
+ 2009-01-04 02:00:21 5,632 ----a-w c:\windows\system32\pndx5032.dll
- 2008-08-22 01:05:14 45,056 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-08-26 08:11:52 44,544 ----a-w c:\windows\system32\pngfilt.dll
- 2007-02-13 15:09:25 185,952 ----a-w c:\windows\system32\rmoc3260.dll
+ 2009-01-04 02:00:39 185,920 ----a-w c:\windows\system32\rmoc3260.dll
- 2008-08-22 01:07:58 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-08-26 08:11:52 105,984 ----a-w c:\windows\system32\url.dll
- 2008-08-22 01:08:22 1,206,784 ----a-w c:\windows\system32\urlmon.dll
+ 2008-08-26 08:11:53 1,159,680 ----a-w c:\windows\system32\urlmon.dll
- 2008-08-22 01:06:36 434,176 ----a-w c:\windows\system32\vbscript.dll
+ 2007-08-13 17:54:10 413,696 ----a-w c:\windows\system32\vbscript.dll
- 2008-08-22 01:08:08 236,544 ----a-w c:\windows\system32\webcheck.dll
+ 2008-08-26 08:11:53 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2008-08-22 01:08:22 208,384 ----a-w c:\windows\system32\WinFXDocObj.exe
+ 2007-08-13 17:45:16 206,336 ----a-w c:\windows\system32\winfxdocobj.exe
- 2008-08-22 01:08:06 878,592 ----a-w c:\windows\system32\wininet.dll
+ 2008-08-26 08:11:54 826,368 ----a-w c:\windows\system32\wininet.dll
+ 2009-01-06 10:07:11 16,384 ----atw c:\windows\temp\Perflib_Perfdata_1b4.dat
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 49263]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-13 339968]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-01 98304]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-11-28 222720]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2008-06-12 991584]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-07 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-07 c:\windows\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 258048]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-06-13 450560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= c:\windows\system32\l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-21 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-21 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0fcc4778-cbf1-11dc-bf0e-000b6b9d4bc1}]
\Shell\Auto\command - wscript "esta ig.vbs"
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "esta ig.vbs"
.
.
------- Examen supplémentaire -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
uStart Page = hxxp://www.orange.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
mStart Page = hxxp://www.google.com
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q305&bd=pavilion&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\7b7sbfwm.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll
FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 11:20:59
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*NULL*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-01-06 11:22:46
ComboFix-quarantined-files.txt 2009-01-06 10:22:17
ComboFix2.txt 2009-01-03 22:43:19
Avant-CF: 32 386 678 784 octets libres
Après-CF: 32,503,930,880 octets libres
383 --- E O F --- 2008-12-19 04:37:45