bien allons y
le combo
ComboFix 08-05-26.2 - hp 2008-05-27 14:55:20.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1229 [GMT 2:00]
Endroit: C:\Users\hp\Desktop\ComboFix.exe
Command switches used :: C:\Users\hp\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\temp\b_internet.exe
C:\temp\b_internet460a.exe
C:\Windows\system32\AudFile.dll
C:\WINDOWS\System32\authuitu.dll
C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
C:\Windows\system32\WMAFile.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\b_internet.exe
C:\temp\b_internet460a.exe
C:\Windows\system32\AudFile.dll
C:\WINDOWS\System32\authuitu.dll
C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
C:\Windows\system32\WMAFile.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-27 to 2008-05-27 ))))))))))))))))))))))))))))))))))))
.
2008-05-27 09:44 . 2008-05-27 09:44 <REP> d-------- C:\Deckard
2008-05-27 09:31 . 2008-05-27 09:40 <REP> d-------- C:\Program Files\Hijackthis Version Française
2008-05-27 08:52 . 2008-05-27 08:52 <REP> d-------- C:\Program Files\Avira GmbH
2008-05-26 21:24 . 2008-05-26 21:24 <REP> d-------- C:\Program Files\Free Audio Pack
2008-05-26 17:11 . 2008-05-26 17:11 <REP> d-------- C:\Users\All Users\CheckPoint
2008-05-26 17:11 . 2008-05-26 17:11 <REP> d-------- C:\PROGRA~2\CheckPoint
2008-05-26 17:11 . 2008-03-03 15:06 279,440 --a------ C:\WINDOWS\System32\drivers\~GLH0014.TMP
2008-05-26 17:10 . 2008-05-26 17:22 <REP> d-------- C:\WINDOWS\Internet Logs
2008-05-26 16:58 . 2008-05-26 16:58 <REP> d-------- C:\Program Files\Soft4Ever
2008-05-26 15:29 . 2008-05-26 16:08 <REP> d-a------ C:\Users\All Users\TEMP
2008-05-26 15:29 . 2008-05-26 16:08 <REP> d-a------ C:\PROGRA~2\TEMP
2008-05-24 13:44 . 2005-09-19 00:00 25,264 --a------ C:\WINDOWS\System32\CH341DLL.DLL
2008-05-24 13:44 . 2006-01-12 00:00 19,392 --a------ C:\WINDOWS\System32\drivers\CH341WDM.SYS
2008-05-23 23:02 . 2008-05-23 23:02 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-05-22 11:04 . 2008-05-22 11:04 <REP> d-------- C:\Program Files\Lavasoft
2008-05-22 10:35 . 2008-05-27 14:26 <REP> d-------- C:\Users\hp\AppData\Roaming\uTorrent
2008-05-22 10:35 . 2008-05-22 10:55 <REP> d-------- C:\Program Files\uTorrent
2008-05-21 10:33 . 2008-05-27 14:32 <REP> d--h----- C:\$AVG8.VAULT$
2008-05-21 08:50 . 2008-05-26 21:36 <REP> d-------- C:\WINDOWS\System32\drivers\Avg
2008-05-21 08:50 . 2008-05-21 08:50 <REP> d-------- C:\Program Files\AVG
2008-05-21 08:50 . 2008-05-21 08:50 96,520 --a------ C:\WINDOWS\System32\drivers\avgldx86.sys
2008-05-21 08:50 . 2008-05-21 08:50 67,080 --a------ C:\WINDOWS\System32\drivers\avgwfpx.sys
2008-05-21 08:50 . 2008-05-21 08:50 12,424 --a------ C:\WINDOWS\System32\drivers\avgrkx86.sys
2008-05-21 08:50 . 2008-05-21 08:50 10,520 --a------ C:\WINDOWS\System32\avgrsstx.dll
2008-05-21 08:43 . 2008-05-26 16:05 <REP> d-------- C:\Users\All Users\Avg8
2008-05-21 08:43 . 2008-05-26 16:05 <REP> d-------- C:\PROGRA~2\Avg8
2008-05-20 22:14 . 2008-05-20 22:14 0 --a------ C:\WINDOWS\oodcnt.INI
2008-05-20 21:36 . 2008-05-20 21:39 <REP> d-------- C:\Users\hp\AppData\Roaming\GlarySoft
2008-05-20 21:27 . 2008-05-20 21:27 <REP> d-------- C:\Program Files\Glary Utilities
2008-05-19 08:46 . 2008-05-19 09:45 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-05-19 08:46 . 2008-05-19 09:45 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-05-16 15:28 . 2006-12-22 09:30 17,016,669 --a------ C:\temp\patch_complet_vega460c.exe
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\System32\lsdelete.exe
2008-05-15 21:30 . 2008-05-15 21:30 <REP> d-------- C:\HSF
2008-05-15 21:30 . 1997-10-10 13:00 640,512 --a------ C:\WINDOWS\system\Oc30.dll
2008-05-15 21:30 . 2001-01-31 11:31 377,344 --a------ C:\WINDOWS\Ssvw32.dll
2008-05-15 21:30 . 1997-10-10 13:00 253,952 --a------ C:\WINDOWS\system\Msvcrt20.dll
2008-05-15 21:30 . 2000-01-24 10:21 199,168 --a------ C:\WINDOWS\ACBSante.dll
2008-05-15 21:30 . 2000-01-14 19:30 167,936 --a------ C:\WINDOWS\rssmail.dll
2008-05-15 21:30 . 1997-10-10 13:00 133,904 --a------ C:\WINDOWS\system\Mfcans32.dll
2008-05-15 21:30 . 1997-10-10 13:00 20,480 --a------ C:\WINDOWS\system\Regsvr32.exe
2008-05-15 21:30 . 2008-05-15 21:33 26 --a------ C:\WINDOWS\WD.INI
2008-05-15 21:24 . 2008-05-16 15:28 <REP> d-------- C:\SSV
2008-05-14 21:29 . 2004-08-04 07:00 506,368 --a------ C:\WINDOWS\System32\msxml.dll
2008-05-12 12:29 . 2008-05-12 12:29 <REP> d-------- C:\Program Files\eMule
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\Users\hp\AppData\Roaming\Malwarebytes
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-05-12 10:22 . 2008-05-27 14:34 69,690 --a------ C:\WINDOWS\System32\oodbs.lor
2008-05-12 10:18 . 2008-05-12 10:18 <REP> d-------- C:\Program Files\OO Software
2008-05-07 19:37 . 2008-05-07 19:37 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-05-07 15:51 . 2008-05-07 15:51 <REP> d-------- C:\Users\hp\AppData\Roaming\InstallShield
2008-05-07 10:14 . 2008-05-07 10:14 <REP> d-------- C:\Program Files\SpeedFan
2008-05-07 10:12 . 2008-05-07 10:14 <REP> d-------- C:\Program Files\Motherboard Monitor 5
2008-05-04 17:43 . 2008-05-04 17:43 <REP> d-------- C:\Program Files\Windows Live
2008-05-04 17:43 . 2008-05-04 17:46 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-04 17:36 . 2008-05-04 17:43 <REP> d-------- C:\Users\All Users\WLInstaller
2008-05-04 17:36 . 2008-05-04 17:43 <REP> d-------- C:\PROGRA~2\WLInstaller
2008-04-29 17:14 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\System32\uxtuneup.dll
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\Users\All Users\TuneUp Software
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\PROGRA~2\TuneUp Software
2008-04-29 17:13 . 2008-04-29 17:14 354,560 --a------ C:\WINDOWS\System32\TuneUpDefragService.exe
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\System32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\System32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\System32\drivers\Awrtpd.sys
2008-04-27 09:34 . 2008-04-27 09:34 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Music
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 07:40 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-05-27 06:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-24 17:10 --------- d-----w C:\Program Files\adslTV
2008-05-24 17:07 --------- d-----w C:\Users\hp\AppData\Roaming\vlc
2008-05-23 22:33 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-23 21:35 --------- d-----w C:\Users\hp\AppData\Roaming\FileZilla
2008-05-22 09:04 --------- d-----w C:\PROGRA~2\Lavasoft
2008-05-22 09:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-22 07:06 27,050 ----a-w C:\Users\hp\AppData\Roaming\nvModes.dat
2008-05-21 22:40 --------- d-----w C:\Program Files\Yahoo!
2008-05-20 20:15 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-05-20 20:01 --------- d-----w C:\Program Files\Microsoft Works
2008-05-20 16:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 06:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-19 06:40 --------- d-----w C:\PROGRA~2\Symantec
2008-05-18 12:25 --------- d-----w C:\Program Files\Ubisoft
2008-05-14 16:43 --------- d-----w C:\Program Files\Windows Mail
2008-05-14 16:43 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-05-12 10:30 --------- d-----w C:\PROGRA~2\eMule
2008-04-30 10:29 --------- d-----w C:\PROGRA~2\DVD Shrink
2008-04-27 17:42 --------- d-----w C:\PROGRA~2\CyberLink
2008-04-24 07:58 --------- d-----w C:\Program Files\VirtualDub
2008-04-21 16:34 --------- d-----w C:\Users\hp\AppData\Roaming\PeerNetworking
2008-04-21 07:28 --------- d-----w C:\Program Files\Google
2008-04-20 13:06 --------- d-----w C:\Program Files\PC Wizard 2008
2008-04-13 08:08 --------- d-----w C:\Users\hp\AppData\Roaming\Ubisoft
2008-04-13 08:08 --------- d-----w C:\PROGRA~2\Ubisoft
2008-04-06 16:45 --------- d-----w C:\Users\hp\AppData\Roaming\BitTorrent
2008-04-06 12:59 98,304 ----a-w C:\Windows\system32CmdLineExt.dll
2008-04-04 20:51 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-04 20:51 --------- d-----w C:\Program Files\Bonjour
2008-04-04 20:41 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-04-03 16:56 --------- d-----w C:\Users\hp\AppData\Roaming\Media Player Classic
2008-04-03 16:53 --------- d-----w C:\PROGRA~2\HPSSUPPLY
2008-03-29 20:51 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Journal
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Defender
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Collaboration
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Calendar
2008-03-28 17:14 174 --sha-w C:\Program Files\desktop.ini
2008-03-28 16:32 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-28 16:32 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-27 17:04 --------- d-----w C:\Program Files\Yamicsoft
2008-03-13 11:52 51,528 ----a-w C:\Windows\System32\ftserui2.dll
2008-03-13 11:50 202,048 ----a-w C:\Windows\System32\ftd2xx.dll
2008-03-13 11:49 185,664 ----a-w C:\Windows\System32\FTLang.dll
2008-03-13 11:49 120,128 ----a-w C:\Windows\System32\ftbusui.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 22:43 729088]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 19:31 1033512]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 19:50 4390912 C:\WINDOWS\RtHDVCpl.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 16:37 174872]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 11:38 159744]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 13:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 16:12 317128]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 03:29 102400]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2008-01-19 09:33 227840]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-01 12:27 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-01 12:27 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-01 12:27 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-06-25 23:26 77824]
"OODefragTray"="C:\Windows\system32\oodtray.exe" [2007-06-28 23:01 2512128]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-21 08:50 1177368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2008-03-19 02:31:20 4742184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Users^hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d'écran et lancement.lnk]
backup=C:\Windows\pss\OneNote 2007 - Capture d'écran et lancement.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registration Assassin's Creed.LNK]
backup=C:\Windows\pss\Registration Assassin's Creed.LNK.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 16:35 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 18:51 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 10:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 16:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-01-20 09:05 217088 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--------- 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{63E473AA-F42E-438A-967D-10594C088465}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{385886E8-F959-405D-AEA8-53E522F0198F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7F62BBC5-75E4-4939-B914-21991D03E0E3}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6F6977C4-538B-4C11-8C36-585CE4D624CC}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{172BF219-4273-4226-BA6D-14064E00682F}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{A991D1BC-2681-4061-8A78-0A5269C4313B}C:\\program files\\adsltv\\adsltv.exe"= UDP:C:\program files\adsltv\adsltv.exe:adsltv
"UDP Query User{79251719-0EFF-4CB7-AD1B-8567EDD68E16}C:\\program files\\adsltv\\adsltv.exe"= TCP:C:\program files\adsltv\adsltv.exe:adsltv
"TCP Query User{DCBF923C-D433-4A36-BBE6-E5F2AE15C71F}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{AE6D9C20-2C5D-44F9-95BF-B013B6C29504}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{60C06E80-E72E-42D0-981A-761CF898C999}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{5E8EC173-E0C3-4562-855C-1C9827281EEC}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{5A19B57C-7EE5-44B5-BFBB-37579E3BBBF1}C:\\users\\hp\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\hp\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{7DB0D671-F784-4B5F-B6F9-70ECE94F9222}C:\\users\\hp\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\hp\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{6157FC84-C368-435F-A68B-BB60BBA91672}C:\\program files\\bitcomet\\bitcomet.exe"= Disabled:UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{C5AC5DA6-EB9D-4E9F-846B-C1B32324ACC4}C:\\program files\\bitcomet\\bitcomet.exe"= Disabled:TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{1B89E138-F70E-4C15-98B3-181D3986C999}"= Disabled:UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{43AAF8B6-B658-4927-9EB3-5E3AFDCECC58}"= Disabled:TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{7919DF0A-25E9-4697-8C8A-493A1EA39FFE}"= Disabled:UDP:C:\Program Files\DNA\btdna.exe:DNA
"{50EE0FD4-AC5A-4BF9-BA80-C652412619EF}"= Disabled:TCP:C:\Program Files\DNA\btdna.exe:DNA
"TCP Query User{C72A918A-B314-4E80-BF3D-29F157E39BF1}C:\\users\\hp\\documents\\fichiers-logiciels\\utorrent.exe"= UDP:C:\users\hp\documents\fichiers-logiciels\utorrent.exe:utorrent.exe
"UDP Query User{27991649-9C91-47D3-8E8B-B34C99C25BB4}C:\\users\\hp\\documents\\fichiers-logiciels\\utorrent.exe"= TCP:C:\users\hp\documents\fichiers-logiciels\utorrent.exe:utorrent.exe
"TCP Query User{168FC703-FA6C-4983-BD15-3DC1DF2BACF9}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E4607E79-11F9-4907-823E-562F4E11A4BA}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{2CB86718-484D-446C-86C3-37E2CA721009}C:\\users\\hp\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:C:\users\hp\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{82E9BAE4-9291-4857-8CE2-4FC9EECDF9FC}C:\\users\\hp\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:C:\users\hp\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{593D323B-94B1-4622-94E0-09D35F6011BD}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{5256342A-B297-445B-91AD-F92C7D099886}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{B4541CD8-545F-4304-8087-F4CB6D73C1FA}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{E9F12EA8-0718-45FA-A1F1-5FB927F1EDAA}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{8290FC5E-CD68-4C51-AA67-45897CD39F64}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{5BFA6DA6-20F1-40D6-BFAA-E80D600DE2DE}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{933A4C1A-100E-4549-B9A0-7A32E0A790B7}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{AD5145BE-3327-4857-B633-CF2773B19A09}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
"{03B823B0-D635-4DAC-83B6-C30CF62203AE}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{59415A11-63AF-40EE-8A56-D0B783EFA701}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5129FE32-8531-4AE8-B85F-157F92F6DAEA}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{1D7E2658-7E2F-4F89-835E-5C7228B772C2}C:\\program files\\adsltv\\vlc.exe"= UDP:C:\program files\adsltv\vlc.exe:VLC media player
"UDP Query User{BF1A55FA-CA26-4ADB-A37A-AA188372DCFE}C:\\program files\\adsltv\\vlc.exe"= TCP:C:\program files\adsltv\vlc.exe:VLC media player
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\avgrkx86.sys [2008-05-21 08:50]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-21 08:50]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-21 08:50]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-21 08:50]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 12:43]
R2 UxTuneUp;TuneUp Extension de thème;C:\Windows\System32\svchost.exe [2008-01-19 09:33]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-05-21 08:50]
S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 09:30]
S3 CH341;CH341WDM;C:\Windows\system32\Drivers\CH341WDM.SYS [2006-01-12 00:00]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-04-29 17:14]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-27 12:34:27 C:\Windows\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-21 06:26:50 C:\Windows\Tasks\GlaryOneClickOptimizer.job"
- C:\Program Files\Glary Utilities\oneclickoptimizer.exe
"2008-05-21 06:26:50 C:\Windows\Tasks\GlaryUpdate.job"
- C:\Program Files\Glary Utilities\webupdate.exe
"2008-04-29 15:14:23 C:\Windows\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-27 12:55:14 C:\Windows\Tasks\User_Feed_Synchronization-{2DFB62E9-DAEC-4F82-A938-0E3B06A813DE}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-27 14:57:21
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-27 14:58:44
ComboFix-quarantined-files.txt 2008-05-27 12:57:58
Pre-Run: 21,905,416,192 octets libres
Post-Run: 21,873,922,048 octets libres
307 --- E O F --- 2008-05-23 14:15:08
et le hijackthis
ComboFix 08-05-26.2 - hp 2008-05-27 14:55:20.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1229 [GMT 2:00]
Endroit: C:\Users\hp\Desktop\ComboFix.exe
Command switches used :: C:\Users\hp\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\temp\b_internet.exe
C:\temp\b_internet460a.exe
C:\Windows\system32\AudFile.dll
C:\WINDOWS\System32\authuitu.dll
C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
C:\Windows\system32\WMAFile.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\b_internet.exe
C:\temp\b_internet460a.exe
C:\Windows\system32\AudFile.dll
C:\WINDOWS\System32\authuitu.dll
C:\WINDOWS\System32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
C:\Windows\system32\WMAFile.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-27 to 2008-05-27 ))))))))))))))))))))))))))))))))))))
.
2008-05-27 09:44 . 2008-05-27 09:44 <REP> d-------- C:\Deckard
2008-05-27 09:31 . 2008-05-27 09:40 <REP> d-------- C:\Program Files\Hijackthis Version Française
2008-05-27 08:52 . 2008-05-27 08:52 <REP> d-------- C:\Program Files\Avira GmbH
2008-05-26 21:24 . 2008-05-26 21:24 <REP> d-------- C:\Program Files\Free Audio Pack
2008-05-26 17:11 . 2008-05-26 17:11 <REP> d-------- C:\Users\All Users\CheckPoint
2008-05-26 17:11 . 2008-05-26 17:11 <REP> d-------- C:\PROGRA~2\CheckPoint
2008-05-26 17:11 . 2008-03-03 15:06 279,440 --a------ C:\WINDOWS\System32\drivers\~GLH0014.TMP
2008-05-26 17:10 . 2008-05-26 17:22 <REP> d-------- C:\WINDOWS\Internet Logs
2008-05-26 16:58 . 2008-05-26 16:58 <REP> d-------- C:\Program Files\Soft4Ever
2008-05-26 15:29 . 2008-05-26 16:08 <REP> d-a------ C:\Users\All Users\TEMP
2008-05-26 15:29 . 2008-05-26 16:08 <REP> d-a------ C:\PROGRA~2\TEMP
2008-05-24 13:44 . 2005-09-19 00:00 25,264 --a------ C:\WINDOWS\System32\CH341DLL.DLL
2008-05-24 13:44 . 2006-01-12 00:00 19,392 --a------ C:\WINDOWS\System32\drivers\CH341WDM.SYS
2008-05-23 23:02 . 2008-05-23 23:02 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-05-22 11:04 . 2008-05-22 11:04 <REP> d-------- C:\Program Files\Lavasoft
2008-05-22 10:35 . 2008-05-27 14:26 <REP> d-------- C:\Users\hp\AppData\Roaming\uTorrent
2008-05-22 10:35 . 2008-05-22 10:55 <REP> d-------- C:\Program Files\uTorrent
2008-05-21 10:33 . 2008-05-27 14:32 <REP> d--h----- C:\$AVG8.VAULT$
2008-05-21 08:50 . 2008-05-26 21:36 <REP> d-------- C:\WINDOWS\System32\drivers\Avg
2008-05-21 08:50 . 2008-05-21 08:50 <REP> d-------- C:\Program Files\AVG
2008-05-21 08:50 . 2008-05-21 08:50 96,520 --a------ C:\WINDOWS\System32\drivers\avgldx86.sys
2008-05-21 08:50 . 2008-05-21 08:50 67,080 --a------ C:\WINDOWS\System32\drivers\avgwfpx.sys
2008-05-21 08:50 . 2008-05-21 08:50 12,424 --a------ C:\WINDOWS\System32\drivers\avgrkx86.sys
2008-05-21 08:50 . 2008-05-21 08:50 10,520 --a------ C:\WINDOWS\System32\avgrsstx.dll
2008-05-21 08:43 . 2008-05-26 16:05 <REP> d-------- C:\Users\All Users\Avg8
2008-05-21 08:43 . 2008-05-26 16:05 <REP> d-------- C:\PROGRA~2\Avg8
2008-05-20 22:14 . 2008-05-20 22:14 0 --a------ C:\WINDOWS\oodcnt.INI
2008-05-20 21:36 . 2008-05-20 21:39 <REP> d-------- C:\Users\hp\AppData\Roaming\GlarySoft
2008-05-20 21:27 . 2008-05-20 21:27 <REP> d-------- C:\Program Files\Glary Utilities
2008-05-19 08:46 . 2008-05-19 09:45 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-05-19 08:46 . 2008-05-19 09:45 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-05-16 15:28 . 2006-12-22 09:30 17,016,669 --a------ C:\temp\patch_complet_vega460c.exe
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\System32\lsdelete.exe
2008-05-15 21:30 . 2008-05-15 21:30 <REP> d-------- C:\HSF
2008-05-15 21:30 . 1997-10-10 13:00 640,512 --a------ C:\WINDOWS\system\Oc30.dll
2008-05-15 21:30 . 2001-01-31 11:31 377,344 --a------ C:\WINDOWS\Ssvw32.dll
2008-05-15 21:30 . 1997-10-10 13:00 253,952 --a------ C:\WINDOWS\system\Msvcrt20.dll
2008-05-15 21:30 . 2000-01-24 10:21 199,168 --a------ C:\WINDOWS\ACBSante.dll
2008-05-15 21:30 . 2000-01-14 19:30 167,936 --a------ C:\WINDOWS\rssmail.dll
2008-05-15 21:30 . 1997-10-10 13:00 133,904 --a------ C:\WINDOWS\system\Mfcans32.dll
2008-05-15 21:30 . 1997-10-10 13:00 20,480 --a------ C:\WINDOWS\system\Regsvr32.exe
2008-05-15 21:30 . 2008-05-15 21:33 26 --a------ C:\WINDOWS\WD.INI
2008-05-15 21:24 . 2008-05-16 15:28 <REP> d-------- C:\SSV
2008-05-14 21:29 . 2004-08-04 07:00 506,368 --a------ C:\WINDOWS\System32\msxml.dll
2008-05-12 12:29 . 2008-05-12 12:29 <REP> d-------- C:\Program Files\eMule
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\Users\hp\AppData\Roaming\Malwarebytes
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-05-12 11:24 . 2008-05-12 11:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-05-12 10:22 . 2008-05-27 14:34 69,690 --a------ C:\WINDOWS\System32\oodbs.lor
2008-05-12 10:18 . 2008-05-12 10:18 <REP> d-------- C:\Program Files\OO Software
2008-05-07 19:37 . 2008-05-07 19:37 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-05-07 15:51 . 2008-05-07 15:51 <REP> d-------- C:\Users\hp\AppData\Roaming\InstallShield
2008-05-07 10:14 . 2008-05-07 10:14 <REP> d-------- C:\Program Files\SpeedFan
2008-05-07 10:12 . 2008-05-07 10:14 <REP> d-------- C:\Program Files\Motherboard Monitor 5
2008-05-04 17:43 . 2008-05-04 17:43 <REP> d-------- C:\Program Files\Windows Live
2008-05-04 17:43 . 2008-05-04 17:46 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-04 17:36 . 2008-05-04 17:43 <REP> d-------- C:\Users\All Users\WLInstaller
2008-05-04 17:36 . 2008-05-04 17:43 <REP> d-------- C:\PROGRA~2\WLInstaller
2008-04-29 17:14 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\System32\uxtuneup.dll
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\Users\All Users\TuneUp Software
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-04-29 17:13 . 2008-04-29 17:13 <REP> d-------- C:\PROGRA~2\TuneUp Software
2008-04-29 17:13 . 2008-04-29 17:14 354,560 --a------ C:\WINDOWS\System32\TuneUpDefragService.exe
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\System32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\System32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\System32\drivers\Awrtpd.sys
2008-04-27 09:34 . 2008-04-27 09:34 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Music
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 07:40 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-05-27 06:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-24 17:10 --------- d-----w C:\Program Files\adslTV
2008-05-24 17:07 --------- d-----w C:\Users\hp\AppData\Roaming\vlc
2008-05-23 22:33 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-05-23 21:35 --------- d-----w C:\Users\hp\AppData\Roaming\FileZilla
2008-05-22 09:04 --------- d-----w C:\PROGRA~2\Lavasoft
2008-05-22 09:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-22 07:06 27,050 ----a-w C:\Users\hp\AppData\Roaming\nvModes.dat
2008-05-21 22:40 --------- d-----w C:\Program Files\Yahoo!
2008-05-20 20:15 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-05-20 20:01 --------- d-----w C:\Program Files\Microsoft Works
2008-05-20 16:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 06:42 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-19 06:40 --------- d-----w C:\PROGRA~2\Symantec
2008-05-18 12:25 --------- d-----w C:\Program Files\Ubisoft
2008-05-14 16:43 --------- d-----w C:\Program Files\Windows Mail
2008-05-14 16:43 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-05-12 10:30 --------- d-----w C:\PROGRA~2\eMule
2008-04-30 10:29 --------- d-----w C:\PROGRA~2\DVD Shrink
2008-04-27 17:42 --------- d-----w C:\PROGRA~2\CyberLink
2008-04-24 07:58 --------- d-----w C:\Program Files\VirtualDub
2008-04-21 16:34 --------- d-----w C:\Users\hp\AppData\Roaming\PeerNetworking
2008-04-21 07:28 --------- d-----w C:\Program Files\Google
2008-04-20 13:06 --------- d-----w C:\Program Files\PC Wizard 2008
2008-04-13 08:08 --------- d-----w C:\Users\hp\AppData\Roaming\Ubisoft
2008-04-13 08:08 --------- d-----w C:\PROGRA~2\Ubisoft
2008-04-06 16:45 --------- d-----w C:\Users\hp\AppData\Roaming\BitTorrent
2008-04-06 12:59 98,304 ----a-w C:\Windows\system32CmdLineExt.dll
2008-04-04 20:51 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-04 20:51 --------- d-----w C:\Program Files\Bonjour
2008-04-04 20:41 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-04-03 16:56 --------- d-----w C:\Users\hp\AppData\Roaming\Media Player Classic
2008-04-03 16:53 --------- d-----w C:\PROGRA~2\HPSSUPPLY
2008-03-29 20:51 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Journal
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Defender
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Collaboration
2008-03-28 18:59 --------- d-----w C:\Program Files\Windows Calendar
2008-03-28 17:14 174 --sha-w C:\Program Files\desktop.ini
2008-03-28 16:32 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-28 16:32 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-27 17:04 --------- d-----w C:\Program Files\Yamicsoft
2008-03-13 11:52 51,528 ----a-w C:\Windows\System32\ftserui2.dll
2008-03-13 11:50 202,048 ----a-w C:\Windows\System32\ftd2xx.dll
2008-03-13 11:49 185,664 ----a-w C:\Windows\System32\FTLang.dll
2008-03-13 11:49 120,128 ----a-w C:\Windows\System32\ftbusui.dll
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 22:43 729088]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 19:31 1033512]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 19:50 4390912 C:\WINDOWS\RtHDVCpl.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 16:37 174872]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 11:38 159744]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 13:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 16:12 317128]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 03:29 102400]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2008-01-19 09:33 227840]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-01 12:27 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-01 12:27 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-01 12:27 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-06-25 23:26 77824]
"OODefragTray"="C:\Windows\system32\oodtray.exe" [2007-06-28 23:01 2512128]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-21 08:50 1177368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2008-03-19 02:31:20 4742184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Users^hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 - Capture d'écran et lancement.lnk]
backup=C:\Windows\pss\OneNote 2007 - Capture d'écran et lancement.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^hp^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registration Assassin's Creed.LNK]
backup=C:\Windows\pss\Registration Assassin's Creed.LNK.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 16:35 202024 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 18:51 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 10:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 16:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-01-20 09:05 217088 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--------- 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{63E473AA-F42E-438A-967D-10594C088465}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{385886E8-F959-405D-AEA8-53E522F0198F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7F62BBC5-75E4-4939-B914-21991D03E0E3}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6F6977C4-538B-4C11-8C36-585CE4D624CC}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{172BF219-4273-4226-BA6D-14064E00682F}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{A991D1BC-2681-4061-8A78-0A5269C4313B}C:\\program files\\adsltv\\adsltv.exe"= UDP:C:\program files\adsltv\adsltv.exe:adsltv
"UDP Query User{79251719-0EFF-4CB7-AD1B-8567EDD68E16}C:\\program files\\adsltv\\adsltv.exe"= TCP:C:\program files\adsltv\adsltv.exe:adsltv
"TCP Query User{DCBF923C-D433-4A36-BBE6-E5F2AE15C71F}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{AE6D9C20-2C5D-44F9-95BF-B013B6C29504}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{60C06E80-E72E-42D0-981A-761CF898C999}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= UDP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"UDP Query User{5E8EC173-E0C3-4562-855C-1C9827281EEC}C:\\program files\\common files\\nero\\nero web\\setupx.exe"= TCP:C:\program files\common files\nero\nero web\setupx.exe:Nero Installer
"TCP Query User{5A19B57C-7EE5-44B5-BFBB-37579E3BBBF1}C:\\users\\hp\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\hp\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{7DB0D671-F784-4B5F-B6F9-70ECE94F9222}C:\\users\\hp\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\hp\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{6157FC84-C368-435F-A68B-BB60BBA91672}C:\\program files\\bitcomet\\bitcomet.exe"= Disabled:UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{C5AC5DA6-EB9D-4E9F-846B-C1B32324ACC4}C:\\program files\\bitcomet\\bitcomet.exe"= Disabled:TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{1B89E138-F70E-4C15-98B3-181D3986C999}"= Disabled:UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{43AAF8B6-B658-4927-9EB3-5E3AFDCECC58}"= Disabled:TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{7919DF0A-25E9-4697-8C8A-493A1EA39FFE}"= Disabled:UDP:C:\Program Files\DNA\btdna.exe:DNA
"{50EE0FD4-AC5A-4BF9-BA80-C652412619EF}"= Disabled:TCP:C:\Program Files\DNA\btdna.exe:DNA
"TCP Query User{C72A918A-B314-4E80-BF3D-29F157E39BF1}C:\\users\\hp\\documents\\fichiers-logiciels\\utorrent.exe"= UDP:C:\users\hp\documents\fichiers-logiciels\utorrent.exe:utorrent.exe
"UDP Query User{27991649-9C91-47D3-8E8B-B34C99C25BB4}C:\\users\\hp\\documents\\fichiers-logiciels\\utorrent.exe"= TCP:C:\users\hp\documents\fichiers-logiciels\utorrent.exe:utorrent.exe
"TCP Query User{168FC703-FA6C-4983-BD15-3DC1DF2BACF9}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{E4607E79-11F9-4907-823E-562F4E11A4BA}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{2CB86718-484D-446C-86C3-37E2CA721009}C:\\users\\hp\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= UDP:C:\users\hp\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"UDP Query User{82E9BAE4-9291-4857-8CE2-4FC9EECDF9FC}C:\\users\\hp\\appdata\\local\\temp\\onlineupdate8\\setupxu.exe"= TCP:C:\users\hp\appdata\local\temp\onlineupdate8\setupxu.exe:setupxu.exe
"{593D323B-94B1-4622-94E0-09D35F6011BD}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{5256342A-B297-445B-91AD-F92C7D099886}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{B4541CD8-545F-4304-8087-F4CB6D73C1FA}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{E9F12EA8-0718-45FA-A1F1-5FB927F1EDAA}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{8290FC5E-CD68-4C51-AA67-45897CD39F64}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{5BFA6DA6-20F1-40D6-BFAA-E80D600DE2DE}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{933A4C1A-100E-4549-B9A0-7A32E0A790B7}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{AD5145BE-3327-4857-B633-CF2773B19A09}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
"{03B823B0-D635-4DAC-83B6-C30CF62203AE}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"TCP Query User{59415A11-63AF-40EE-8A56-D0B783EFA701}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{5129FE32-8531-4AE8-B85F-157F92F6DAEA}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{1D7E2658-7E2F-4F89-835E-5C7228B772C2}C:\\program files\\adsltv\\vlc.exe"= UDP:C:\program files\adsltv\vlc.exe:VLC media player
"UDP Query User{BF1A55FA-CA26-4ADB-A37A-AA188372DCFE}C:\\program files\\adsltv\\vlc.exe"= TCP:C:\program files\adsltv\vlc.exe:VLC media player
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\avgrkx86.sys [2008-05-21 08:50]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-05-21 08:50]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-21 08:50]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-21 08:50]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 12:43]
R2 UxTuneUp;TuneUp Extension de thème;C:\Windows\System32\svchost.exe [2008-01-19 09:33]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-05-21 08:50]
S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 09:30]
S3 CH341;CH341WDM;C:\Windows\system32\Drivers\CH341WDM.SYS [2006-01-12 00:00]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\Windows\System32\TuneUpDefragService.exe [2008-04-29 17:14]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-27 12:34:27 C:\Windows\Tasks\GlaryInitialize.job"
- C:\Program Files\Glary Utilities\initialize.exe
"2008-05-21 06:26:50 C:\Windows\Tasks\GlaryOneClickOptimizer.job"
- C:\Program Files\Glary Utilities\oneclickoptimizer.exe
"2008-05-21 06:26:50 C:\Windows\Tasks\GlaryUpdate.job"
- C:\Program Files\Glary Utilities\webupdate.exe
"2008-04-29 15:14:23 C:\Windows\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
"2008-05-27 12:55:14 C:\Windows\Tasks\User_Feed_Synchronization-{2DFB62E9-DAEC-4F82-A938-0E3B06A813DE}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-27 14:57:21
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-27 14:58:44
ComboFix-quarantined-files.txt 2008-05-27 12:57:58
Pre-Run: 21,905,416,192 octets libres
Post-Run: 21,873,922,048 octets libres
307 --- E O F --- 2008-05-23 14:15:08
je fait ca et je post le rapport
Avira AntiRootkit Tool - Beta (1.0.1.17)
========================================================================================================
- Scan started mardi 27 mai 2008 - 08:53:42
========================================================================================================
--------------------------------------------------------------------------------------------------------
Configuration:
--------------------------------------------------------------------------------------------------------
- [X] Scan files
- [X] Scan registry
- [X] Scan processes
- [ ] Fast scan
- Working disk total size : 141.59 GB
- Working disk free size : 22.61 GB (15 %)
--------------------------------------------------------------------------------------------------------
Results:
Value data mismatch : HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM -> autorecover mofs
Hidden value : HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\System -> oodefrag10.00.00.01workstation
--------------------------------------------------------------------------------------------------------
Files: 0/157037
Registry items: 2/438795
Processes: 0/77
Scan time: 00:06:33
--------------------------------------------------------------------------------------------------------
Active processes:
- ghlqhzea.exe (PID 6084) (Avira AntiRootkit Tool - Beta)
- Mystify.scr (PID 6000)
- taskeng.exe (PID 244)
- System (PID 4)
- smss.exe (PID 504)
- csrss.exe (PID 588)
- wininit.exe (PID 640)
- csrss.exe (PID 652)
- services.exe (PID 696)
- lsass.exe (PID 708)
- lsm.exe (PID 716)
- winlogon.exe (PID 852)
- svchost.exe (PID 928)
- svchost.exe (PID 988)
- svchost.exe (PID 1032)
- svchost.exe (PID 1112)
- svchost.exe (PID 1148)
- svchost.exe (PID 1180)
- audiodg.exe (PID 1276)
- SLsvc.exe (PID 1308)
- svchost.exe (PID 1344)
- svchost.exe (PID 1456)
- dwm.exe (PID 1716)
- aawservice.exe (PID 1724)
- explorer.exe (PID 1752)
- spoolsv.exe (PID 1912)
- svchost.exe (PID 1936)
- taskeng.exe (PID 2012)
- avgwdsvc.exe (PID 924)
- mDNSResponder.exe (PID 972)
- IAANTmon.exe (PID 1744)
- taskeng.exe (PID 1428)
- LSSrvc.exe (PID 1804)
- NBService.exe (PID 232)
- oodag.exe (PID 2360)
- svchost.exe (PID 2488)
- svchost.exe (PID 2532)
- svchost.exe (PID 2604)
- SearchIndexer.exe (PID 2664)
- hpqwmiex.exe (PID 2848)
- SDWinSec.exe (PID 2960)
- avgam.exe (PID 3672)
- avgrsx.exe (PID 4064)
- avgnsx.exe (PID 1808)
- avgemc.exe (PID 2448)
- MSASCui.exe (PID 3612)
- sm56hlpr.exe (PID 3692)
- SynTPEnh.exe (PID 3644)
- RtHDVCpl.exe (PID 3700)
- IAAnotif.exe (PID 3716)
- QLBCTRL.exe (PID 3704)
- HPWAMain.exe (PID 3780)
- WiFiMsg.exe (PID 3804)
- rundll32.exe (PID 3864)
- jusched.exe (PID 3892)
- oodtray.exe (PID 3904)
- avgtray.exe (PID 3924)
- sidebar.exe (PID 3940)
- TeaTimer.exe (PID 3960)
- YahooWidgets.exe (PID 3968)
- rundll32.exe (PID 3992)
- WmiPrvSE.exe (PID 4048)
- sidebar.exe (PID 2380)
- YahooWidgets.exe (PID 3080)
- YahooWidgets.exe (PID 3088)
- YahooWidgets.exe (PID 3140)
- YahooWidgets.exe (PID 3388)
- HpqToaster.exe (PID 3500)
- SynTPHelper.exe (PID 2352)
- ieuser.exe (PID 4292)
- HPHC_Service.exe (PID 4932)
- AcroRd32.exe (PID 5000)
- VSSVC.exe (PID 5560)
- svchost.exe (PID 6060)
- iexplore.exe (PID 4780)
- FlashUtil9e.exe (PID 4904)
- avirarkd.exe (PID 1548)
========================================================================================================
- Scan finished mardi 27 mai 2008 - 09:00:16
========================================================================================================