Je sais pas trop si c'est normal, mais mon image du bureau est parti, puis tout est devenu noir,...
j'ai du redemarrer, puis j'ai relancé combofix.
voila le rapport qu'il me donne.
ps: shards => eridan (je me suis inscrit)
ComboFix 08-10-19.01 - BN 2008-10-19 21:57:40.2 - NTFSx86
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.1282 [GMT 2:00]
Lancé depuis: C:\Users\BN\Downloads\ComboFix.exe
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Users\BN\AppData\Roaming\Adobe\Player.exe.bak
Q:\Autorun.inf
S:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-19 au 2008-10-19 ))))))))))))))))))))))))))))))))))))
.
2008-10-19 21:13 . 2008-10-19 21:13 5,674 --a------ C:\Windows\System32\tmp.reg
2008-10-19 17:36 . 2008-10-19 17:36 <REP> d-------- C:\Users\BN\AppData\Roaming\Malwarebytes
2008-10-19 17:36 . 2008-10-19 17:36 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-10-19 17:36 . 2008-10-19 17:36 <REP> d-------- C:\ProgramData\Malwarebytes
2008-10-19 17:36 . 2008-10-19 18:55 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-19 17:36 . 2008-10-16 20:25 38,496 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-19 17:36 . 2008-10-16 20:25 15,504 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-19 14:22 . 2008-10-19 15:40 <REP> d-------- C:\Program Files\Navilog1
2008-10-17 21:34 . 2008-10-17 21:34 0 --a------ C:\Windows\nsreg.dat
2008-10-15 23:15 . 2008-06-19 17:24 28,544 --a------ C:\Windows\System32\drivers\pavboot.sys
2008-10-15 23:14 . 2008-10-15 23:14 <REP> d-------- C:\Program Files\Panda Security
2008-10-15 18:37 . 2008-10-15 18:37 <REP> d-------- C:\Program Files\Trend Micro
2008-10-15 18:28 . 2008-10-15 18:28 <REP> d-------- C:\Program Files\Alwil Software
2008-10-15 18:28 . 2008-07-19 16:36 51,280 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2008-10-15 17:51 . 2008-10-15 17:51 1,152 --a------ C:\Windows\System32\windrv.sys
2008-10-15 17:44 . 2008-10-15 17:44 <REP> d-------- C:\Users\BN\AppData\Roaming\Download Manager
2008-10-15 17:29 . 2008-10-15 20:58 <REP> d-------- C:\Users\All Users\moncmd
2008-10-15 17:29 . 2008-10-15 20:57 <REP> d-------- C:\Users\All Users\gtutadgb
2008-10-15 17:29 . 2008-10-15 20:58 <REP> d-------- C:\ProgramData\moncmd
2008-10-15 17:29 . 2008-10-15 20:57 <REP> d-------- C:\ProgramData\gtutadgb
2008-10-14 10:59 . 2008-10-14 10:59 <REP> d-------- C:\Users\All Users\POP3Profiles
2008-10-14 10:59 . 2008-10-14 10:59 <REP> d-------- C:\ProgramData\POP3Profiles
2008-10-14 10:23 . 2008-10-14 10:23 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-10-14 00:41 . 2008-10-14 00:41 <REP> d-------- C:\Users\All Users\Electronic Arts
2008-10-14 00:41 . 2008-10-14 00:41 <REP> d-------- C:\ProgramData\Electronic Arts
2008-10-14 00:36 . 2008-10-14 00:36 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-10-14 00:32 . 2008-10-14 00:32 <REP> d-------- C:\Users\BN\AppData\Roaming\DAEMON Tools
2008-10-14 00:30 . 2008-10-15 22:53 <REP> d-------- C:\Program Files\free-downloads.net
2008-10-02 15:35 . 2008-10-02 15:35 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-10-01 18:58 . 2008-10-01 18:58 <REP> d-------- C:\Program Files\Rockstar Games
2008-09-25 22:36 . 2008-09-25 22:36 <REP> d-------- C:\Windows\Philips
2008-09-25 22:36 . 2008-09-25 22:36 <REP> d-------- C:\Users\BN\AppData\Roaming\ArcSoft
2008-09-25 22:34 . 2008-09-25 22:34 <REP> d-------- C:\Program Files\Common Files\ArcSoft
2008-09-25 22:34 . 2004-12-07 10:11 258,352 --a------ C:\Windows\System32\unicows.dll
2008-09-25 22:34 . 1995-08-01 04:44 212,480 --a------ C:\Windows\PCDLIB32.DLL
2008-09-25 22:32 . 2008-09-25 22:32 <REP> d-------- C:\Program Files\Philips
2008-09-25 22:32 . 2008-09-25 22:33 <REP> d-------- C:\Program Files\Common Files\SPC610NC
2008-09-25 22:32 . 2007-01-10 21:53 465,408 --a------ C:\Windows\VPro610.exe
2008-09-25 22:32 . 2007-01-19 17:14 409,728 --a------ C:\Windows\System32\drivers\SPC610NC.SYS
2008-09-25 22:32 . 2007-01-19 21:48 120,832 --a------ C:\Windows\System32\SPC610NC.AX
2008-09-25 22:32 . 2006-11-20 09:04 6,656 --a------ C:\Windows\System32\CoInst_070119.dll
2008-09-25 22:32 . 2007-01-19 17:50 518 --a------ C:\Windows\System32\SPC610NC.ini
2008-09-19 17:38 . 2008-09-19 17:39 <REP> d-------- C:\Users\BN\AppData\Roaming\SPORE
2008-09-19 17:36 . 2008-09-19 17:36 <REP> dr-h----- C:\Users\BN\AppData\Roaming\SecuROM
2008-09-19 17:28 . 2008-10-15 21:57 <REP> d-------- C:\Program Files\Electronic Arts
2008-09-19 17:24 . 2008-10-18 13:17 <REP> d-------- C:\Users\BN\AppData\Roaming\Roxio
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 11:49 --------- d-----w C:\ProgramData\Roxio
2008-10-18 07:35 --------- d-----w C:\Program Files\Windows Mail
2008-10-18 07:31 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-16 09:42 --------- d-----w C:\Program Files\adslTV
2008-10-16 09:38 --------- d-----w C:\Users\BN\AppData\Roaming\vlc
2008-10-16 09:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-14 08:54 --------- d-----w C:\Program Files\Ubisoft
2008-10-13 22:33 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-10-04 06:58 --------- d-----w C:\ProgramData\SiteAdvisor
2008-10-04 06:58 --------- d-----w C:\Program Files\McAfee
2008-10-03 15:38 --------- d-----w C:\ProgramData\McAfee
2008-10-02 03:49 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-09-18 05:09 3,601,464 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w C:\Windows\System32\win32k.sys
2008-09-15 08:56 --------- d-----w C:\Program Files\BitComet
2008-09-14 13:43 --------- d-----w C:\Users\BN\AppData\Roaming\Ubisoft
2008-09-13 21:50 --------- d-----w C:\Users\BN\AppData\Roaming\InterVideo
2008-09-12 23:33 --------- d-----w C:\ProgramData\Ubisoft
2008-09-12 20:52 --------- d-----w C:\Users\BN\AppData\Roaming\InstallShield
2008-09-12 19:42 --------- d-----w C:\Program Files\Microsoft Games
2008-09-12 19:34 --------- d-----w C:\Program Files\Codemasters
2008-09-12 12:07 --------- d-----w C:\Program Files\Pacman 2005
2008-09-11 12:51 --------- d-----w C:\Program Files\Activision
2008-09-11 11:53 --------- d-----w C:\Program Files\Alcohol Soft
2008-09-10 16:53 --------- d-----w C:\Program Files\Gothic III
2008-09-10 14:08 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-09-10 13:19 271,360 ----a-w C:\Windows\system32\drivers\atksgt.sys
2008-09-10 13:19 18,048 ----a-w C:\Windows\system32\drivers\lirsgt.sys
2008-09-10 12:03 --------- d-----w C:\Program Files\Windows Live
2008-09-10 11:59 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-10 11:56 --------- d-----w C:\ProgramData\WLInstaller
2008-09-10 11:19 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-09-10 10:57 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-10 08:30 --------- d-----w C:\ProgramData\Lenovo
2008-09-10 08:25 --------- d-----w C:\Users\BN\AppData\Roaming\Lenovo
2008-09-10 08:25 --------- d-----w C:\Users\BN\AppData\Roaming\ATI
2008-09-10 08:24 100 ----a-w C:\Windows\system32\drivers\Lenovo_2056_A29.MRK
2008-09-10 08:24 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-09-10 08:24 --------- d-----w C:\Program Files\Common Files\Lenovo
2008-09-10 08:14 --------- d-----w C:\Program Files\McAfee.com
2008-09-10 08:14 --------- d-----w C:\Program Files\Common Files\McAfee
2008-09-10 08:02 --------- d-sh--w C:\ProgramData\Modèles
2008-09-10 08:02 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-09-10 08:02 --------- d-sh--w C:\ProgramData\Favoris
2008-09-10 08:02 --------- d-sh--w C:\ProgramData\Bureau
2008-09-10 08:02 --------- d-sh--w C:\Program Files\Fichiers communs
2008-09-03 16:16 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-09-03 16:16 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-09-03 16:16 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-09-03 16:15 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-09-03 16:15 891,448 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-09-03 16:15 885,248 ----a-w C:\Windows\System32\RacEngn.dll
2008-09-03 16:15 784,896 ----a-w C:\Windows\System32\rpcrt4.dll
2008-09-03 16:15 72,192 ----a-w C:\Windows\system32\drivers\pacer.sys
2008-09-03 16:15 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-09-03 16:15 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-09-03 16:15 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-09-03 16:15 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-09-03 16:15 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2008-09-03 16:15 135,168 ----a-w C:\Windows\System32\cscript.exe
2008-09-03 16:14 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-09-03 16:14 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-09-03 16:12 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-09-03 16:11 529,464 ----a-w C:\Windows\system32\drivers\ndis.sys
2008-09-03 16:11 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-09-03 16:11 1,695,744 ----a-w C:\Windows\System32\gameux.dll
2008-09-03 16:10 988,216 ----a-w C:\Windows\System32\winload.exe
2008-09-03 16:10 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-09-03 16:10 615,992 ----a-w C:\Windows\System32\ci.dll
2008-09-03 16:10 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-09-03 16:10 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-09-03 16:10 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-09-03 16:10 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-09-03 16:10 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-09-03 16:10 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-09-03 16:10 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-09-03 16:09 177,208 ----a-w C:\Windows\System32\halmacpi.dll
2008-09-03 16:09 141,880 ----a-w C:\Windows\System32\halacpi.dll
2008-09-03 07:13 --------- d-----w C:\ProgramData\ATI
2008-09-03 07:12 --------- d-----w C:\Program Files\Microsoft Office Suite Activation Assistant
2008-09-03 07:06 --------- d-----w C:\Program Files\Microsoft Small Business
2008-09-03 07:05 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-03 07:03 --------- d-----w C:\Program Files\Microsoft Works
2008-09-03 07:00 --------- d-----w C:\ProgramData\PC-Doctor
2008-09-03 07:00 --------- d-----w C:\Program Files\PCDR5
2008-09-03 07:00 --------- d-----w C:\Program Files\Lenovo
2008-09-03 06:58 --------- d-----w C:\Program Files\ThinkPad
2008-09-03 06:52 33,536 ----a-w C:\Windows\system32\drivers\tvtfilter.sys
2008-09-03 06:51 30,144 ----a-w C:\Windows\system32\drivers\psadd.sys
2008-09-03 06:51 129,784 ------w C:\Windows\System32\pxafs.dll
2008-09-03 06:51 118,520 ------w C:\Windows\System32\pxinsi64.exe
2008-09-03 06:51 116,472 ------w C:\Windows\System32\pxcpyi64.exe
2008-09-03 06:51 --------- d-----w C:\Program Files\Verizon Wireless
2008-09-03 06:50 --------- d-----w C:\Program Files\ThinkVantage
2008-09-03 06:48 --------- d-----w C:\Program Files\Java
2008-09-03 06:47 --------- d-----w C:\ProgramData\Uninstall
2008-09-03 06:47 --------- d-----w C:\ProgramData\Sonic
2008-09-03 06:47 --------- d-----w C:\ProgramData\InstallShield
2008-09-03 06:47 --------- d-----w C:\Program Files\Sonic Icons for Lenovo
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"picon"="C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-05-29 367128]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-21 820520]
"TPFNF7"="C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-07-30 60192]
"TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-03-24 68464]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2008-06-04 242976]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-06-12 150040]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-06-12 170520]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-06-12 145944]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"FingerPrintSoftware"="C:\Program Files\Lenovo Fingerprint Software\fpapp.exe" [2008-05-10 1396736]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-05-24 487424]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LPManager"="C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe" [2008-06-08 165208]
"LPMailChecker"="C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe" [2008-06-08 124248]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 419376]
"RoxioDragToDisc"="C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 1116920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PWMTRV"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2008-07-28 632096]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2008-07-28 214576]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-07-30 431392]
"ACWlIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWlIcon.exe" [2008-07-30 148768]
"cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2008-06-25 3077432]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SPC610NC_Monitor"="C:\Windows\Philips\SPC610NC\Monitor.exe" [2006-11-03 319488]
"TpShocks"="TpShocks.exe" [2008-06-06 C:\Windows\System32\TpShocks.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2008-03-17 752168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2008-09-03 50688]
VPro610.lnk - C:\Windows\VPro610.exe [2008-09-25 465408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{244F1FE6-8F19-4D6C-A931-DC920FFEBFC3}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{FCF2A02D-EFC0-46D7-8401-FC7187108239}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{7E5AF285-4353-46EA-842A-DB29ACB6A8CA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BD304424-E6E7-46FF-B8AA-1218BFC32420}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{858A3E93-7932-4EB0-AB16-0B7D4A63A1FB}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{187E76BD-78AA-43E0-A0E5-AD16D1A61E9C}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{D467E0AE-1BD3-48BC-83D5-1A807F7D1DBF}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{3DE804AB-B506-488E-AE0E-BA30946BBD22}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{5201CFE9-CC9A-44BB-B5A0-840B33317BFB}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{A27D792F-49C8-4A76-A577-FEF1906BC2A3}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{52C367A9-DD25-467A-9715-45887BE3D981}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{CCE60EED-FD88-4493-AA81-B7015BC243A2}"= UDP:56829:Pando P2P TCP Listening Port
"{93E77259-5866-4BC4-A4EC-4AF6037AB6C1}"= TCP:56829:Pando P2P UDP Listening Port
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 pavboot;pavboot;C:\Windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R0 Shockprf;Shockprf;C:\Windows\system32\DRIVERS\Apsx86.sys [2008-05-14 114728]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM86.sys [2008-05-14 19496]
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 28120]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2008-05-12 13480]
R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2008-07-28 12080]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R2 ATService;AuthenTec Fingerprint Service;C:\Windows\system32\AtService.exe [2008-05-10 1160440]
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 LMS;Intel(R) Active Management Technology Local Management Service;C:\Program Files\Intel\AMT\LMS.exe [2008-05-29 174616]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R2 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2008-07-28 66848]
R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-08-21 3881472]
R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys [2008-08-21 54784]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;C:\Windows\system32\Drivers\ATSwpWDF.sys [2008-05-10 475136]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service;C:\Windows\system32\drivers\CHDRT32.sys [2008-05-28 220672]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y6032.sys [2008-03-27 224384]
R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-06-12 2381312]
R3 NETw5v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits ;C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-05-01 3660800]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys [2008-02-22 37312]
S1 tvtumon;tvtumon;C:\Windows\system32\DRIVERS\tvtumon.sys [2008-05-24 48192]
S2 SessionLauncher;SessionLauncher;C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [ ]
S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2008-03-17 81960]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2008-03-17 100392]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2008-03-17 17320]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 29183504]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
S3 SPC610NC;SPC 610NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 409728]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{092ab2d7-79ce-11dd-a371-001c259480db}]
\shell\AutoRun\command - S:\LenovoSDrive.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d4a48f4-9977-11dd-9b31-001c259480db}]
\shell\AutoRun\command - E:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d4a48f6-9977-11dd-9b31-001c259480db}]
\shell\AutoRun\command - F:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26d1fa25-7980-11dd-ae6d-806e6f6e6963}]
\shell\AutoRun\command - Q:\LenovoQDrive.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2947b0d7-87ab-11dd-b3d5-001c259480db}]
\shell\AutoRun\command - H:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81d2bf70-7ff7-11dd-99fd-001c259480db}]
\shell\AutoRun\command - F:\Install.exe
.
Contenu du dossier 'Tâches planifiées'
2008-09-10 C:\Windows\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-09-10 C:\Windows\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-10-19 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 15:54]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-SNM - C:\Program Files\SpyNoMore\SNM.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Users\BN\AppData\Roaming\Mozilla\Firefox\Profiles\gv2r23ml.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 22:05:33
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
-> C:\Windows\system32\DLAAPI_W.DLL
.
------------------------ Autres processus actifs ------------------------
.
C:\Windows\System32\ibmpmsvc.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\wlanext.exe
C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Windows\System32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\System32\TPHDEXLG.exe
C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Windows\System32\conime.exe
C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE
C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE
C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Lenovo\ZOOM\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Lenovo\Client Security Solution\password_manager.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACGadgetWrapper.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.EXE
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Heure de fin: 2008-10-19 22:09:15 - La machine a redémarré [BN]
ComboFix-quarantined-files.txt 2008-10-19 20:09:03
Avant-CF: 50,513,186,816 octets libres
Après-CF: 50,242,363,392 octets libres
374 --- E O F --- 2008-10-18 10:03:20