Bonsoir jlpjlp et déjà merci...
J'ai désinstallé Evidence Eliminator (logiciel espion ??...)
J'ai installé Combofix dont voici le rapport. Je t'envoie celui de smitfraudix dès que je l'ai.
ComboFix 08-04-29.3 - Gwenaël 2008-04-30 18:33:57.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1944 [GMT 2:00]
Endroit: C:\Users\Gwenaël\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\jusched.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))))))))
.
2008-04-30 00:41 . 2008-04-30 00:41 <REP> d-------- C:\Program Files\Trend Micro
2008-04-21 16:26 . 2008-04-21 16:26 <REP> d-------- C:\Program Files\Windows Installer Clean Up
2008-04-21 05:58 . 2008-04-21 16:25 <REP> d-------- C:\Program Files\MSECACHE
2008-04-18 23:45 . 2008-04-18 23:45 <REP> d-------- C:\Users\All Users\Apple
2008-04-18 23:45 . 2008-04-18 23:45 <REP> d-------- C:\ProgramData\Apple
2008-04-18 23:45 . 2008-04-18 23:45 <REP> d-------- C:\Program Files\Apple Software Update
2008-04-18 17:35 . 2008-04-18 17:35 <REP> d-------- C:\Users\Gwenaël\AppData\Roaming\NeroDCTemplates
2008-04-17 05:46 . 2008-04-17 05:46 <REP> d-------- C:\PerfLogs
2008-04-17 05:12 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-04-17 05:11 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-04-17 05:10 . 2008-01-19 09:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-04-17 05:10 . 2008-01-19 09:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-04-17 05:10 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-04-17 05:10 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-04-17 05:10 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-04-17 05:10 . 2008-01-19 09:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-04-17 05:10 . 2008-01-19 09:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-04-17 05:10 . 2008-01-19 09:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-04-17 05:10 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-04-17 05:10 . 2006-11-02 11:39 6,656 --a------ C:\Windows\System32\kbd106.dll
2008-04-15 14:45 . 2008-04-15 14:45 <REP> d-------- C:\Program Files\Shareaza
2008-04-14 20:38 . 2001-06-12 01:20 28,944 --a------ C:\Windows\System32\temp.04C
2008-04-14 20:38 . 2001-08-17 00:00 22,528 --a------ C:\Windows\System32\temp.04B
2008-04-14 20:37 . 2006-11-27 15:54 433,152 --a------ C:\Windows\System32\temp.049
2008-04-14 20:37 . 2004-08-04 13:00 276,992 --a------ C:\Windows\System32\temp.04A
2008-04-14 20:37 . 2004-08-04 13:00 3,584 --a------ C:\Windows\System32\temp.048
2008-04-14 20:34 . 2001-03-13 15:53 326,656 --a------ C:\Windows\System32\temp.047
2008-04-14 20:33 . 2000-08-20 22:00 1,388,544 --a------ C:\Windows\System32\temp.046
2008-04-14 20:33 . 2001-03-13 15:47 598,288 --a------ C:\Windows\System32\temp.042
2008-04-14 20:33 . 2001-03-13 15:47 164,112 --a------ C:\Windows\System32\temp.043
2008-04-14 20:33 . 2001-03-13 15:45 147,728 --a------ C:\Windows\System32\temp.044
2008-04-14 20:33 . 2001-03-13 15:47 17,920 --a------ C:\Windows\System32\temp.045
2008-04-11 22:28 . 2008-04-20 18:59 <REP> d-------- C:\Users\Gwenaël\AppData\Roaming\Roxio
2008-04-09 02:29 . 2008-02-29 09:11 988,216 --a------ C:\Windows\System32\winload.exe
2008-04-09 02:29 . 2008-02-29 09:11 927,288 --a------ C:\Windows\System32\winresume.exe
2008-04-09 02:29 . 2008-02-22 07:05 615,992 --a------ C:\Windows\System32\ci.dll
2008-04-09 02:29 . 2008-02-29 08:53 378,368 --a------ C:\Windows\System32\srcore.dll
2008-04-09 02:29 . 2008-02-29 06:12 318,464 --a------ C:\Windows\System32\rstrui.exe
2008-04-09 02:29 . 2008-02-29 08:53 46,592 --a------ C:\Windows\System32\setbcdlocale.dll
2008-04-09 02:29 . 2008-02-29 08:53 40,960 --a------ C:\Windows\System32\srclient.dll
2008-04-09 02:29 . 2008-02-29 09:14 19,000 --a------ C:\Windows\System32\kd1394.dll
2008-04-09 02:29 . 2008-02-29 06:12 14,848 --a------ C:\Windows\System32\srdelayed.exe
2008-04-09 02:29 . 2008-02-29 08:35 6,656 --a------ C:\Windows\System32\kbd106n.dll
2008-04-09 02:26 . 2008-02-29 06:21 2,032,128 --a------ C:\Windows\System32\win32k.sys
2008-04-09 02:25 . 2008-02-22 04:50 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-04-09 02:25 . 2008-02-22 07:01 826,880 --a------ C:\Windows\System32\wininet.dll
2008-04-09 02:25 . 2008-02-22 06:57 295,936 --a------ C:\Windows\System32\gdi32.dll
2008-04-04 21:37 . 2008-04-04 21:37 <REP> d-------- C:\Users\All Users\Apple Computer
2008-04-04 21:37 . 2008-04-04 21:37 <REP> d-------- C:\ProgramData\Apple Computer
2008-04-04 21:37 . 2008-04-04 21:38 <REP> d-------- C:\Program Files\QuickTime
2008-03-30 04:16 . 2005-07-05 04:09 77,472 --a------ C:\Windows\System32\drivers\U81xmgmt.sys
2008-03-30 04:15 . 2005-07-05 04:09 75,456 --a------ C:\Windows\System32\drivers\U81xobex.sys
2008-03-30 04:13 . 2005-07-05 04:09 84,480 --a------ C:\Windows\System32\drivers\U81xmdm.sys
2008-03-30 04:13 . 2005-07-05 04:09 6,144 --a------ C:\Windows\System32\drivers\U81xcmnt.sys
2008-03-30 04:13 . 2005-07-05 04:09 6,144 --a------ C:\Windows\System32\drivers\U81xcm.sys
2008-03-30 04:13 . 2005-07-05 04:09 6,064 --a------ C:\Windows\System32\drivers\U81xmdfl.sys
2008-03-30 04:12 . 2005-07-05 04:09 52,352 --a------ C:\Windows\System32\drivers\U81xbus.sys
2008-03-30 04:12 . 2005-07-05 04:09 5,744 --a------ C:\Windows\System32\drivers\U81xwhnt.sys
2008-03-30 04:12 . 2005-07-05 04:09 5,744 --a------ C:\Windows\System32\drivers\U81xwh.sys
2008-03-30 03:29 . 2008-03-30 03:29 <REP> d-------- C:\Program Files\Audacity
2008-03-29 02:24 . 2008-03-29 19:02 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-29 02:24 . 2008-03-29 19:02 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-03-29 02:24 . 2008-03-29 19:04 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\Windows\System32\QuickTimeVR.qtx
2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\Windows\System32\QuickTime.qts
2008-03-27 22:09 . 2008-01-08 14:10 98,304 --a------ C:\Windows\RTKAUDIOSERVICE.EXE
2008-03-27 22:09 . 2007-11-14 16:18 553 --a------ C:\Windows\USetup.iss
2008-03-27 22:08 . 2008-01-15 12:26 4,874,240 --a------ C:\Windows\RtHDVCpl.exe
2008-03-27 22:08 . 2008-01-15 20:19 2,047,576 --a------ C:\Windows\System32\drivers\RTKVHDA.sys
2008-03-27 22:08 . 2007-11-07 18:31 1,191,936 --a------ C:\Windows\RtlUpd.exe
2008-03-27 22:08 . 2008-01-09 19:52 636,416 --a------ C:\Windows\System32\RtkPgExt.dll
2008-03-27 22:08 . 2007-11-13 13:35 532,480 --a------ C:\Windows\System32\RTSndMgr.cpl
2008-03-27 22:08 . 2007-07-25 10:33 135,168 --a------ C:\Windows\System32\SRSWOW.dll
2008-03-27 22:08 . 2008-01-14 17:18 29,696 --a------ C:\Windows\System32\RtkCoInst.dll
2008-03-24 17:56 . 2008-03-24 17:56 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-03-24 06:44 . 2008-03-24 06:44 <REP> d-------- C:\Program Files\Common Files\xing shared
2008-03-24 02:55 . 2000-08-20 22:00 1,388,544 --a------ C:\Windows\System32\temp.030
2008-03-24 02:55 . 2001-03-13 15:47 598,288 --a------ C:\Windows\System32\temp.02C
2008-03-24 02:55 . 2006-11-27 16:54 433,152 --a------ C:\Windows\System32\temp.033
2008-03-24 02:55 . 2001-03-13 15:53 326,656 --a------ C:\Windows\System32\temp.031
2008-03-24 02:55 . 2004-08-04 14:00 276,992 --a------ C:\Windows\System32\temp.034
2008-03-24 02:55 . 2001-03-13 15:47 164,112 --a------ C:\Windows\System32\temp.02D
2008-03-24 02:55 . 2001-03-13 15:45 147,728 --a------ C:\Windows\System32\temp.02E
2008-03-24 02:55 . 2001-06-12 02:20 28,944 --a------ C:\Windows\System32\temp.036
2008-03-24 02:55 . 2001-08-17 01:00 22,528 --a------ C:\Windows\System32\temp.035
2008-03-24 02:55 . 2001-03-13 15:47 17,920 --a------ C:\Windows\System32\temp.02F
2008-03-24 02:55 . 2004-08-04 14:00 3,584 --a------ C:\Windows\System32\temp.032
2008-03-24 02:49 . 2008-04-30 18:15 2,560 --a------ C:\Windows\_MSRSTRT.EXE
2008-03-22 02:38 . 2000-08-20 22:00 1,388,544 --a------ C:\Windows\System32\temp.01A
2008-03-22 02:38 . 2001-03-13 15:47 598,288 --a------ C:\Windows\System32\temp.016
2008-03-22 02:38 . 2006-11-27 16:54 433,152 --a------ C:\Windows\System32\temp.01D
2008-03-22 02:38 . 2001-03-13 15:53 326,656 --a------ C:\Windows\System32\temp.01B
2008-03-22 02:38 . 2004-08-04 14:00 276,992 --a------ C:\Windows\System32\temp.01E
2008-03-22 02:38 . 2001-03-13 15:47 164,112 --a------ C:\Windows\System32\temp.017
2008-03-22 02:38 . 2001-03-13 15:45 147,728 --a------ C:\Windows\System32\temp.018
2008-03-22 02:38 . 2001-06-12 02:20 28,944 --a------ C:\Windows\System32\temp.020
2008-03-22 02:38 . 2001-08-17 01:00 22,528 --a------ C:\Windows\System32\temp.01F
2008-03-22 02:38 . 2001-03-13 15:47 17,920 --a------ C:\Windows\System32\temp.019
2008-03-22 02:38 . 2004-08-04 14:00 3,584 --a------ C:\Windows\System32\temp.01C
2008-03-18 19:04 . 2008-03-18 19:04 <REP> d-------- C:\Users\Gwenaël\AppData\Roaming\Canon
2008-03-18 19:01 . 2008-03-18 19:01 <REP> d-------- C:\Users\Gwenaël\AppData\Roaming\ArcSoft
2008-03-18 18:41 . 1997-10-14 06:19 11,776 --a------ C:\Windows\System32\pmsbfn32.dll
2008-03-18 18:41 . 2005-06-01 01:28 9,606 --a------ C:\Windows\System32\NEWSOFT
2008-03-18 18:41 . 2008-03-18 18:41 264 --a------ C:\Windows\setup.iss
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Windows\System32\Color
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Users\Gwenaël\AppData\Roaming\ScanSoft
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Users\All Users\ScanSoft
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Users\All Users\InstallShield
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\ProgramData\ScanSoft
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\ProgramData\InstallShield
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Program Files\NewSoft
2008-03-18 18:39 . 2008-03-18 18:39 <REP> d-------- C:\Program Files\Common Files\ScanSoft Shared
2008-03-18 18:39 . 2008-03-18 18:41 <REP> d-------- C:\Program Files\Common Files\PDFView
2008-03-18 18:39 . 2008-03-18 18:39 416 --a------ C:\Windows\MAXLINK.INI
2008-03-18 18:38 . 2008-03-18 18:38 <REP> d-------- C:\Program Files\ScanSoft
2008-03-18 18:37 . 2008-03-18 18:37 <REP> d-------- C:\Program Files\Common Files\CANON
2008-03-18 18:37 . 2008-03-18 18:37 <REP> d-------- C:\Program Files\ArcSoft
2008-03-18 18:37 . 1995-07-31 14:44 212,480 --a------ C:\Windows\PCDLIB32.DLL
2008-03-18 18:36 . 2008-03-18 18:36 <REP> d--h----- C:\Windows\System32\CanonIJ Uninstaller Information
2008-03-18 18:35 . 2008-03-18 18:35 <REP> d--h----- C:\Program Files\CanonBJ
2008-03-18 18:35 . 2006-07-20 17:51 1,298,432 --a------ C:\Windows\System32\CNQC4803.DLL
2008-03-18 18:35 . 2007-08-09 13:17 229,376 --a------ C:\Windows\System32\CNQL4803.DLL
2008-03-18 18:35 . 2006-06-29 16:29 106,496 --a------ C:\Windows\System32\cnqo4803.dll
2008-03-18 18:35 . 2006-07-20 17:51 57,344 --a------ C:\Windows\System32\CNQI4803.DLL
2008-03-18 18:34 . 2008-03-18 18:36 <REP> d-------- C:\Program Files\Canon
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 16:39 4,456,448 --sha-w C:\Users\Gwenaël\NTUSER.DAT
2008-04-30 16:39 4,456,448 --sha-w C:\Users\Gwenaël\NTUSER.DAT
2008-04-30 16:16 0 ----a-w C:\Windows\system32\drivers\lvuvc.hs
2008-04-22 02:20 --------- d-----w C:\ProgramData\Symantec
2008-04-20 16:59 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\Roxio
2008-04-18 23:15 --------- d-----w C:\Program Files\Paint.NET
2008-04-18 21:47 --------- d-----w C:\Program Files\SpywareBlaster
2008-04-18 15:35 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\NeroDCTemplates
2008-04-18 04:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-18 04:03 --------- d-----w C:\Program Files\LG PC Suite
2008-04-18 03:41 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\POP Peeper
2008-04-17 03:56 174 --sha-w C:\Program Files\desktop.ini
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Mail
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Journal
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Defender
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Collaboration
2008-04-17 03:48 --------- d-----w C:\Program Files\Windows Calendar
2008-04-17 03:28 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-17 03:28 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-16 22:34 --------- d-----w C:\Program Files\POP Peeper
2008-04-16 12:25 29,952 ----a-w C:\Windows\Help\OEM\scripts\HPScript.exe
2008-04-11 20:26 --------- d-----w C:\ProgramData\Sonic
2008-04-10 16:21 --------- d-s---w C:\Users\Gwenaël\AppData\Roaming\Microsoft
2008-04-09 04:05 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-29 14:44 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-27 20:08 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-03-27 20:08 --------- d-----w C:\Program Files\Realtek
2008-03-18 17:04 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\Canon
2008-03-18 17:01 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\ArcSoft
2008-03-18 16:39 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\ScanSoft
2008-03-18 16:39 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-13 23:04 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\Adobe
2008-03-10 23:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-09 00:29 --------- d-----w C:\Program Files\Google
2008-03-08 15:07 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\Real
2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-03-04 00:09 --------- d-----w C:\Users\Gwenaël\AppData\Roaming\LG Electronics
2008-02-29 15:46 --------- d-----w C:\ProgramData\Messenger Plus!
2008-02-20 17:56 118,784 ------r C:\Windows\bwUnin-7.2.0.157-8876480SL.exe
2008-01-19 07:43 376,376 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-01-19 07:43 3,600,440 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-01-19 07:43 3,548,728 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-01-19 07:42 94,776 ----a-w C:\Windows\System32\MigAutoPlay.exe
2008-01-19 07:42 51,768 ----a-w C:\Windows\System32\PSHED.DLL
2008-01-19 07:42 247,352 ----a-w C:\Windows\System32\clfs.sys
2008-01-19 07:42 177,208 ----a-w C:\Windows\System32\halmacpi.dll
2008-01-19 07:42 141,880 ----a-w C:\Windows\System32\halacpi.dll
2008-01-19 07:41 24,120 ----a-w C:\Windows\System32\BOOTVID.DLL
2008-01-19 07:41 21,560 ----a-w C:\Windows\System32\kdusb.dll
2008-01-19 07:41 19,512 ----a-w C:\Windows\System32\kdcom.dll
2008-01-19 07:38 46,080 ----a-w C:\Windows\System32\NAPCRYPT.DLL
2008-01-19 07:38 4,595,712 ----a-w C:\Windows\System32\AuthFWSnapin.dll
2008-01-19 07:38 242,744 ----a-w C:\Windows\System32\rsaenh.dll
2008-01-19 07:38 155,704 ----a-w C:\Windows\System32\dssenh.dll
2008-01-19 07:38 131,640 ----a-w C:\Windows\System32\basecsp.dll
2008-01-19 07:38 103,936 ----a-w C:\Windows\System32\NAPHLPR.DLL
2008-01-19 07:38 1,203,792 ----a-w C:\Windows\System32\ntdll.dll
2008-01-19 07:36 996,352 ----a-w C:\Windows\System32\WMNetMgr.dll
2008-01-19 07:35 98,304 ----a-w C:\Windows\System32\mssitlb.dll
2008-01-19 07:34 98,816 ----a-w C:\Windows\System32\mfps.dll
2008-01-19 07:33 98,304 ----a-w C:\Windows\System32\makecab.exe
2008-01-19 07:32 879,616 ----a-w C:\Windows\System32\Bubbles.scr
2008-01-19 07:32 704,512 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-01-19 07:32 5,714,432 ----a-w C:\Windows\System32\logon.scr
2008-01-19 07:32 258,048 ----a-w C:\Windows\System32\winspool.drv
2008-01-19 07:32 221,184 ----a-w C:\Windows\System32\Mystify.scr
2008-01-19 07:32 220,672 ----a-w C:\Windows\System32\Ribbons.scr
2008-01-19 07:32 21,504 ----a-w C:\Windows\System32\msacm32.drv
2008-01-19 07:32 166,912 ----a-w C:\Windows\System32\wdmaud.drv
2008-01-19 07:32 1,370,624 ----a-w C:\Windows\System32\Aurora.scr
2008-01-19 07:31 7,680 ----a-w C:\Windows\System32\spwizres.dll
2008-01-19 07:31 57,856 ----a-w C:\Windows\System32\nlsbres.dll
2008-01-19 07:31 118,272 ----a-w C:\Windows\System32\RDPENCDD.dll
2008-01-19 07:30 17,920 ----a-w C:\Windows\System32\netevent.dll
2008-01-19 07:29 705,536 ----a-w C:\Windows\System32\imagesp1.dll
2008-01-19 07:29 58,880 ----a-w C:\Windows\System32\msobjs.dll
2008-01-19 07:28 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-01-19 07:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-01-19 06:01 14,336 ----a-w C:\Windows\System32\tsddd.dll
2008-01-19 06:01 134,656 ----a-w C:\Windows\System32\rdpdd.dll
2008-01-19 05:52 56,320 ----a-w C:\Windows\System32\vga256.dll
2008-01-19 05:52 21,504 ----a-w C:\Windows\System32\vga64k.dll
2008-01-19 05:52 11,776 ----a-w C:\Windows\System32\framebuf.dll
2008-01-19 05:52 10,752 ----a-w C:\Windows\System32\vga.dll
2008-01-19 05:50 14,848 ----a-w C:\Windows\System32\iscsilog.dll
2008-01-19 05:49 2,048 ----a-w C:\Windows\System32\dmdskres2.dll
2008-01-19 05:48 20,992 ----a-w C:\Windows\System32\msdtcVSp1res.dll
2008-01-19 05:48 1,291,264 ----a-w C:\Windows\System32\comres.dll
2008-01-19 05:46 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-19 05:39 13,312 ----a-w C:\Windows\System32\WsmRes.dll
2008-01-19 05:39 1,536 ----a-w C:\Windows\System32\WsmCl.dll
2008-01-19 05:36 289,792 ----a-w C:\Windows\System32\atmfd.dll
2008-01-19 05:33 56,320 ----a-w C:\Windows\System32\graftabl.com
2008-01-19 05:31 8,322,048 ----a-w C:\Windows\System32\spwizimg.dll
2008-01-19 05:27 2,560 ----a-w C:\Windows\System32\bootstr.dll
2008-01-19 05:26 605,696 ----a-w C:\Windows\System32\adtschema.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 09:36 2153472 C:\Windows\System32\oobefldr.dll]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-06-01 13:40 1783400]
"POP Peeper"="C:\Program Files\POP Peeper\POPPeeper.exe" [2008-03-12 01:09 1429504]
"Meteo Fusion"="C:\Program Files\Eggiz\Meteo Fusion\Meteo Fusion.exe" [2007-04-12 14:01 294912]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]
"Evidence Eliminator"="C:\Program Files\Evidence Eliminator\ee.exe" [ ]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\" [2008-02-20 19:56 8192]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-09 02:29 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 17:01 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 18:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 13:59 118784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-06-14 20:31 178968]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 12:26 4874240 C:\Windows\RtHDVCpl.exe]
"CCUTRAYICON"="FactoryMode" []
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 13:13 71176]
"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2007-04-07 02:56 54936]
"HP Software Update"="c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 16:59 115816]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 14:16 185896]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 13:45 75304]
"WrtMon.exe"="C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 09:35 20480]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-24 06:43 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-02-20 19:56:08 196608]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-09 02:29:27 125624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C811BB3A-C6BF-48F1-A9B2-9E3A25CD7478}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{EF6CA61F-9863-45F4-8549-FD48443B7E7E}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{AD63F5DE-D4D5-42A6-8136-9102C7EF05E3}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{0AB6ED54-0E52-40D4-9621-20AB7D749574}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{66FF50A4-40D9-4C3E-A4CD-BC4C3A933208}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{DBCB39EF-C1D7-4419-9ECE-DE15D7C52483}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{2B83BC5B-2FC0-449C-91AE-F09F87BA0CCF}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{069B212C-2947-402F-BD6A-6350E37F07BA}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{800E623B-F966-404B-BD1A-EFB2E7600C37}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{15BAABF4-066D-4AC3-9084-0EA894789355}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{88CF437A-59B2-47DF-826A-CFB3369FAFDE}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B14462A1-9BF8-4428-865B-2D8469B489FC}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{0244B739-83BE-4C7C-BB8F-2C5ED85337F0}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{31E4C11F-CF60-452F-88C0-0F674221F709}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{6D084173-29C1-4B27-8106-794BD37F6CA7}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080429.001\IDSvix86.sys [2008-02-14 03:51]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-10 02:35]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-04-28 18:46:06 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - Gwenaël.job"
- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 18:39:50
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-30 18:49:04
ComboFix-quarantined-files.txt 2008-04-30 16:48:01
Pre-Run: 86,614,179,840 octets libres
Post-Run: 85,845,536,768 octets libres
345 --- E O F --- 2008-04-26 22:40:13
Voilà... bon courage pour la recherche d'infos dans tout ça !
Merci!