Merci!
Voici le rapport de Combofix. J'ai suivi tes intructions, mais j'ai oublié de désactiver l'UAC... :-(
ComboFix 08-10-18.03 - JS 2008-10-19 5:41:38.2 - NTFSx86
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.858 [GMT 2:00]
Lancé depuis: C:\Users\JS\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\afffdfdce2_z.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-19 au 2008-10-19 ))))))))))))))))))))))))))))))))))))
.
2008-10-19 05:36 . 2008-10-19 05:36 318,976 --a------ C:\Windows\System32\CF15442.exe
2008-10-19 03:42 . 2008-10-19 03:42 <REP> d-------- C:\Program Files\jv16 PowerTools 2008
2008-10-19 03:42 . 2008-10-19 03:42 23 --a------ C:\Windows\System32\cbcaadb6_z.ocx
2008-10-18 09:40 . 2008-10-18 09:40 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-10-18 09:36 . 2008-08-17 12:33 678,408 --a------ C:\Windows\System32\gpprefcl.dll
2008-10-16 11:35 . 2008-09-18 04:16 2,032,640 --a------ C:\Windows\System32\win32k.sys
2008-10-16 11:35 . 2008-09-03 05:59 468,992 --a------ C:\Windows\System32\newdev.dll
2008-10-16 11:35 . 2008-08-27 03:06 288,768 --a------ C:\Windows\System32\drivers\srv.sys
2008-10-16 11:35 . 2008-09-03 05:58 74,752 --a------ C:\Windows\System32\newdev.exe
2008-10-16 11:34 . 2008-09-18 07:09 3,601,464 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-10-16 11:34 . 2008-09-18 07:09 3,549,240 --a------ C:\Windows\System32\ntoskrnl.exe
2008-10-16 11:34 . 2008-10-02 03:32 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-10-16 11:34 . 2008-10-02 05:49 827,392 --a------ C:\Windows\System32\wininet.dll
2008-10-15 22:12 . 2008-10-15 22:12 99,904 --a------ C:\Windows\System32\drivers\AnyDVD.sys
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Users\JS\AppData\Roaming\r2 Studios
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Users\All Users\r2 Studios
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\ProgramData\r2 Studios
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Program Files\r2 Studios
2008-10-08 16:12 . 2008-10-08 16:12 <REP> d-------- C:\Program Files\Common Files\Skype
2008-09-29 11:30 . 2008-09-29 11:32 <REP> d-------- C:\Program Files\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 03:43 --------- d-----w C:\Users\JS\AppData\Roaming\Skype
2008-10-19 03:33 --------- d---a-w C:\ProgramData\TEMP
2008-10-19 03:28 --------- d-----w C:\Program Files\ZoneTick
2008-10-19 02:36 351,783 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-10-19 02:19 4,102,144 ----a-w C:\Windows\Internet Logs\xDB96E1.tmp
2008-10-18 22:04 --------- d-----w C:\Users\JS\AppData\Roaming\skypePM
2008-10-18 22:04 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-10-18 19:48 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-10-17 08:16 --------- d-----w C:\ProgramData\Microsoft Help
2008-10-17 08:08 --------- d-----w C:\Program Files\Spyware Doctor
2008-10-16 23:02 --------- d-----w C:\Program Files\a-squared Free
2008-10-16 22:19 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-16 18:25 38,496 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-10-16 18:25 15,504 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-10-16 14:10 --------- d-----w C:\Program Files\Windows Mail
2008-10-10 07:04 18,482,854 ----a-w C:\Windows\Internet Logs\tvDebug.zip
2008-10-08 14:12 --------- d-----w C:\ProgramData\Skype
2008-10-08 14:12 --------- d-----r C:\Program Files\Skype
2008-09-29 19:33 1,610,240 ----a-w C:\Windows\Internet Logs\xDB9BF0.tmp
2008-09-29 11:07 351,783 ---ha-w C:\Windows\system32\drivers\vsconfig(136).xml
2008-09-29 11:05 4,373,504 ----a-w C:\Windows\Internet Logs\xDBA1AB.tmp
2008-09-16 23:30 2,793,472 ----a-w C:\Windows\Internet Logs\xDB9E41.tmp
2008-09-15 19:44 3,435,520 ----a-w C:\Windows\Internet Logs\xDBA5B0.tmp
2008-09-12 15:00 --------- d-----w C:\ProgramData\RoboForm
2008-09-08 17:28 3,887,616 ----a-w C:\Windows\Internet Logs\xDB9F98.tmp
2008-09-07 21:53 3,120,640 ----a-w C:\Windows\Internet Logs\xDBAAA0.tmp
2008-09-07 14:45 --------- d-----w C:\Program Files\QuickTime Alternative
2008-09-02 22:32 --------- d-----w C:\Program Files\Bonjour
2008-09-02 19:20 351,783 ---ha-w C:\Windows\system32\drivers\vsconfig(140).xml
2008-09-01 05:57 4,409,856 ----a-w C:\Windows\Internet Logs\xDBA4A7.tmp
2008-08-30 07:58 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-29 09:15 --------- d-----w C:\Program Files\Weather Watcher Live
2008-08-29 09:07 --------- d-----w C:\ProgramData\Anuko
2008-08-25 10:36 81,288 ----a-w C:\Windows\system32\drivers\iksyssec.sys
2008-08-25 10:36 66,952 ----a-w C:\Windows\system32\drivers\iksysflt.sys
2008-08-25 10:36 40,840 ----a-w C:\Windows\system32\drivers\ikfilesec.sys
2008-08-19 13:29 --------- d-----w C:\ProgramData\CityPhotos
2008-08-17 21:31 4,720,128 ----a-w C:\Windows\Internet Logs\xDB9FB7.tmp
2008-08-10 22:14 4,943,360 ----a-w C:\Windows\Internet Logs\xDB9B25.tmp
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-31 01:13 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-07-25 13:00 2,932,224 ----a-w C:\Windows\Internet Logs\xDB9201.tmp
2008-07-25 08:36 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-07-24 13:05 2,679,296 ----a-w C:\Windows\Internet Logs\xDBA311.tmp
2008-07-23 16:50 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-07-23 16:50 129,784 ------w C:\Windows\System32\pxafs.dll
2008-07-23 16:50 120,056 ------w C:\Windows\System32\pxcpyi64.exe
2008-07-23 16:50 118,520 ------w C:\Windows\System32\pxinsi64.exe
2008-07-23 16:48 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-07-23 10:51 3,567,616 ----a-w C:\Windows\Internet Logs\xDB17A4.tmp
2008-07-23 10:30 443,904 ----a-w C:\Windows\Internet Logs\xDB8B4D.tmp
2008-07-23 08:18 392,704 ----a-w C:\Windows\Internet Logs\xDB8F91.tmp
2008-07-22 22:04 3,492,352 ----a-w C:\Windows\Internet Logs\xDB9665.tmp
2008-07-19 18:27 4,569,088 ----a-w C:\Windows\Internet Logs\xDB8F24.tmp
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-06-05 17:42 190 ----a-w C:\Program Files\Common Files\psasetup.log
2008-04-16 21:30 691 ----a-w C:\Users\JS\AppData\Roaming\GetValue.vbs
2008-04-16 21:30 35 ----a-w C:\Users\JS\AppData\Roaming\SetValue.bat
2008-04-11 17:50 174 --sha-w C:\Program Files\desktop.ini
2008-04-10 10:40 32 ----a-w C:\Users\All Users\ezsid.dat
2008-04-10 10:40 32 ----a-w C:\ProgramData\ezsid.dat
2008-05-22 17:57 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-22 17:57 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-22 17:57 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2008-01-24 2476408]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-26 1235736]
"StartupDelayer"="C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" [2007-12-14 26112]
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" [2008-10-16 398992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
C:\Users\JS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.MJPG"= Pvmjpg30.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"<NO NAME>"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED0E2B27-5D12-4E4E-87BF-31ADA9A69E10}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5BF98E0C-F62B-4B70-82D1-AEFF0A2D5238}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{1B44C2C4-C304-4E0F-B330-B5CBF767A057}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{95F4CE44-0469-49BA-B90F-64EEDB35D4B1}"= UDP:C:\Program Files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"{F56286C3-3DEC-4D4F-BD9E-3F30AC98B92F}"= TCP:C:\Program Files\SmartFTP Client\SmartFTP.exe:SmartFTP Client
"{59F8EA1D-916B-492A-8DE8-C4349E5BF7C5}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{96A0044C-661E-4DEF-B91D-864BD56257FD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{28A12F32-B809-4379-995B-B5B9D5FE5613}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{E722109A-8C72-453A-99D3-079470B48DF7}C:\\users\\js\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\mm94yw56\\housecall66[1].exe"= UDP:C:\users\js\appdata\local\microsoft\windows\temporary internet files\content.ie5\mm94yw56\housecall66[1].exe:housecall66[1].exe
"UDP Query User{B27D1734-A3AB-4A25-AD6C-AD0408EF750E}C:\\users\\js\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\mm94yw56\\housecall66[1].exe"= TCP:C:\users\js\appdata\local\microsoft\windows\temporary internet files\content.ie5\mm94yw56\housecall66[1].exe:housecall66[1].exe
"TCP Query User{CF96B4AF-E103-4CD2-9A04-6B55A3BA0F32}C:\\users\\js\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\kldulmas\\housecall66[1].exe"= UDP:C:\users\js\appdata\local\microsoft\windows\temporary internet files\content.ie5\kldulmas\housecall66[1].exe:housecall66[1].exe
"UDP Query User{7D8948FC-3C0A-4599-9E3B-C7543202FBC1}C:\\users\\js\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\kldulmas\\housecall66[1].exe"= TCP:C:\users\js\appdata\local\microsoft\windows\temporary internet files\content.ie5\kldulmas\housecall66[1].exe:housecall66[1].exe
"TCP Query User{D104485D-50AA-4830-800E-6E84EA35D5C0}C:\\program files\\skype\\phone\\skype.exe"= Disabled:UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{A1A24CBB-2434-47BA-BD42-A4EFEA842615}C:\\program files\\skype\\phone\\skype.exe"= Disabled:TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{B67455D3-C0CA-4600-9EF8-025CC1FB354A}"= UDP:C:\Program Files\Nonoh.net\Nonoh\Nonoh.exe:Nonoh
"{F2634459-9077-4595-BCE1-3E0593483E60}"= TCP:C:\Program Files\Nonoh.net\Nonoh\Nonoh.exe:Nonoh
"{CE5E1914-645D-4020-AAC8-0F568A36272D}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{7DD42F0C-DFDE-4E64-817A-3353EE7593FD}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{D267F130-6CFB-46EC-9E9C-A706D7DEC1FF}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{CA54965C-1527-43C6-9694-975AFA2F3444}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{CF15F5A6-B935-427A-B73C-F565FD1A2B10}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{EED0C968-15A9-4C23-8B27-C2B344405A0A}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{8444EEA4-CE19-4146-AB55-BA97BB4826DC}"= UDP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
"{98E99882-472C-4622-969A-4064B3A23C36}"= TCP:C:\Program Files\Pinnacle\Studio 11\programs\umi.exe:umi
"{18127985-1322-41B7-81B0-CA2F970E3C32}"= UDP:C:\Windows\System32\lxdjcoms.exe:Lexmark Communications System
"{2A32C1E5-2ABD-4781-8A77-EE6188A1AAC9}"= TCP:C:\Windows\System32\lxdjcoms.exe:Lexmark Communications System
"{B5E7EEA2-EBD0-4792-81F3-3DAE6353D018}"= UDP:C:\Program Files\Lexmark 1400 Series\lxdjamon.exe:Lexmark Device Monitor
"{A7197A04-EE38-4445-8834-3F5A72B6DB7A}"= TCP:C:\Program Files\Lexmark 1400 Series\lxdjamon.exe:Lexmark Device Monitor
"{F1AC7F79-727C-449B-B19B-216EAFFF1568}"= UDP:C:\Program Files\Lexmark 1400 Series\App4R.exe:Lexmark Imaging Studio
"{37F8108E-EC36-43BD-BF12-6B61E3D43909}"= TCP:C:\Program Files\Lexmark 1400 Series\App4R.exe:Lexmark Imaging Studio
"{132F5F94-4DEA-47CC-BDCF-04FBCD5B21AD}"= UDP:C:\Users\JS\AppData\Local\Temp\lxdj\wireless\FRENCH\lxdjwpss.exe:
"{39B24EDB-7739-4832-8D79-B04B2A407A02}"= TCP:C:\Users\JS\AppData\Local\Temp\lxdj\wireless\FRENCH\lxdjwpss.exe:
"{F946CB62-8081-498B-AE98-6B85293BA946}"= UDP:C:\Windows\System32\lxdjcfg.exe:
"{960DCF40-022E-4738-A993-E61352B73EC7}"= TCP:C:\Windows\System32\lxdjcfg.exe:
"{E848D408-BB08-43A7-8B64-151DEA7934D4}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{48D52041-8585-4E8B-9C1C-943F99DE6341}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{1FA2D391-7D29-4738-BC4C-652A17100232}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"{D79843B8-F1CC-44F9-94FC-C496C433A0F8}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"{E9E4A8CA-9D8C-424B-A6D2-363F561FE8B4}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{FCF01314-43F5-41AA-B60C-5CB64C40BBE0}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{BEE90761-9552-4498-B40A-99607E2C349A}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"{3FFD1605-872E-4275-8445-D7E791F611AA}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"{5A541E25-6FE9-4949-8F3D-E41F6A3DA644}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AvgRkx86;avgrkx86.sys;C:\Windows\system32\Drivers\avgrkx86.sys [2008-06-20 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-07-26 97928]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-26 231704]
R2 Maximizer-CMGR-Service;Maximizer Email Service;C:\Program Files\Maximizer\Campaign Manager\AutoProgService.exe [2006-07-24 49152]
R2 Maximizer-PrintFax-Service;Maximizer PrintFax Service;C:\Program Files\Maximizer\Campaign Manager\AutoPrintservice.exe [2006-07-24 184320]
R2 Pervasive Workgroup Engine;Pervasive Workgroup Engine;C:\PVSW\bin\psql_svc.exe run [ ]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R2 ZTime;ZoneTick Time;C:\Program Files\ZoneTick\timesync.exe [2008-10-18 77824]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 2427392]
R3 AvgWfpX;AVG8 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfpx.sys [2008-06-20 69128]
R3 MBAMProtector;MBAMProtector;C:\Windows\system32\drivers\mbam.sys [2008-10-16 15504]
R3 RimSerPort;RIM Virtual Serial Port;C:\Windows\system32\DRIVERS\RimSerial.sys [2004-08-06 17920]
R3 TMPassthruMP;TMPassthruMP;C:\Windows\system32\DRIVERS\TMPassthru.sys [2007-11-27 35216]
S2 gupdate1c922161d603900;Google Update Service (gupdate1c922161d603900);C:\Program Files\Google\Update\GoogleUpdate.exe [2008-09-29 133104]
S2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-10-16 172688]
S2 RUBotted;Trend Micro RUBotted Service;C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe [ ]
S2 Workflow Automation Powered by KnowledgeSync;Workflow Automation Powered by KnowledgeSync;C:\Program Files\Maximizer\Workflow Automation\Bin\KS_Serv.exe [2004-12-29 507904]
S3 TMPassthru;Trend Micro Passthru Ndis Service;C:\Windows\system32\DRIVERS\TMPassthru.sys [2007-11-27 35216]
S3 WMSvc;Service de gestion Web;C:\Windows\system32\inetsrv\wmsvc.exe [2008-01-19 11264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1bf5f1e2-9528-11dd-b274-00197ee62c13}]
\shell\AutoRun\command - G:\PortableRoboForm.exe
\shell\RoboForm2Go\command - G:\PortableRoboForm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6d3b5a39-94ff-11dd-8a9c-00197ee62c13}]
\shell\AutoRun\command - E:\PortableRoboForm.exe
\shell\RoboForm2Go\command - E:\PortableRoboForm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97daa9b0-5e10-11dd-935b-00197ee62c13}]
\shell\AutoRun\command - E:\PortableRoboForm.exe
\shell\RoboForm2Go\command - E:\PortableRoboForm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b88d3cfb-8a16-11dd-8751-00197ee62c13}]
\shell\AutoRun\command - E:\PortableRoboForm.exe
\shell\RoboForm2Go\command - E:\PortableRoboForm.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f86ecca8-5304-11dd-84a0-00197ee62c13}]
\shell\AutoRun\command - E:\PortableRoboForm.exe
\shell\RoboForm2Go\command - E:\PortableRoboForm.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-10-19 C:\Windows\Tasks\GoogleUpdateTaskMachine.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2008-09-29 11:49]
2008-10-16 C:\Windows\Tasks\GoogleUpdateTaskUser.job
- C:\Users\JS\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-17 01:10]
2008-10-19 C:\Windows\Tasks\Malwarebytes' Scheduled Update for SYSTEM.job
- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-16 20:25]
2008-10-16 C:\Windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-07 09:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-TMRUBottedTray - C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Local Page = hxxp://www.google.com/
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O16 -: {03BCF80B-B975-498C-B9CC-1F517915995A} - hxxps://secure.interfax.net/Office2003.ocx
C:\Windows\Downloaded Program Files\Office2003.ocx
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.de/scan_de/scan8/oscan8.cab
C:\Windows\Downloaded Program Files\oscan8.inf
C:\Windows\bdoscandellang.ini
C:\Windows\bdoscandel.exe
C:\Windows\Downloaded Program Files\live.ini
C:\Windows\Downloaded Program Files\scanoptions.tsi
C:\Windows\Downloaded Program Files\lang.ini
C:\Windows\Downloaded Program Files\ipsupd.dll
C:\Windows\Downloaded Program Files\bdupd.dll
C:\Windows\Downloaded Program Files\libfn.dll
C:\Windows\Downloaded Program Files\bdcore.dll
C:\Windows\Downloaded Program Files\oscan8.ocx
O16 -: {A996E48C-D3DC-4244-89F7-AFA33EC60679} - hxxps://gestaoar.certisign.com.br/gestaoar/capicom.cab
C:\Windows\Downloaded Program Files\capicom.inf
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 05:48:00
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-19 5:50:13
ComboFix-quarantined-files.txt 2008-10-19 03:49:49
Avant-CF: 20,241,436,672 octets libres
Après-CF: 20,015,333,376 octets libres
292 --- E O F --- 2008-10-18 07:42:01