Voila je t'ai tout copié... je n'ai plus d'alerte ni d'icone dans ma barre de démarrage... donc a mon avis c'est bon je n'ai pus le virus. je te remercie pour ton aide et pour ton temps.
ComboFix 08-11-04.02 - Laetitia 2008-11-05 11:37:48.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2009 [GMT 1:00]
Lancé depuis: c:\users\Laetitia\Desktop\TRISTAN.EXE
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
c:\programdata\vlc-0.9.4-win32.exe
c:\users\Laetitia\AppData\Roaming\.#
c:\users\Laetitia\AppData\Roaming\.#\MBX@161C@1CF2990.###
c:\users\Laetitia\AppData\Roaming\.#\MBX@161C@1CF29C0.###
c:\users\Laetitia\AppData\Roaming\.#\MBX@161C@1CF29F0.###
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-05 au 2008-11-05 ))))))))))))))))))))))))))))))))))))
.
2008-11-05 10:36 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Searches
2008-11-05 10:36 . 2008-11-05 10:36 <REP> d-------- c:\users\Secours\AppData\Roaming\Yahoo!
2008-11-05 10:36 . 2008-11-05 10:36 <REP> d-------- c:\users\Secours\AppData\Roaming\Validity
2008-11-05 10:36 . 2008-11-05 10:36 <REP> d-------- c:\users\Secours\AppData\Roaming\ATI
2008-11-05 10:36 . 2008-11-05 10:36 <REP> d-------- c:\users\All Users\Yahoo! Companion
2008-11-05 10:36 . 2008-11-05 10:36 <REP> d-------- c:\programdata\Yahoo! Companion
2008-11-05 10:36 . 2008-11-05 10:36 71,280 --a------ c:\windows\System32\GDIPFONTCACHEV1.DAT
2008-11-05 10:35 . 2008-11-05 10:35 <REP> dr------- c:\users\Secours\Contacts
2008-11-05 10:32 . 2008-11-05 10:01 1,528,982 --a------ c:\users\Public\SDFix.exe
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Videos
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Saved Games
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Pictures
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Music
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Links
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Downloads
2008-11-05 10:26 . 2008-11-05 10:36 <REP> dr------- c:\users\Secours\Documents
2008-11-05 10:26 . 2006-11-02 13:37 <REP> d-------- c:\users\Secours\AppData\Roaming\Media Center Programs
2008-11-05 10:26 . 2008-03-21 11:55 <REP> d-------- c:\users\Secours\AppData\Roaming\Acer GameZone Console
2008-11-05 10:26 . 2008-11-05 10:36 <REP> d--h----- c:\users\Secours\AppData
2008-11-05 10:26 . 2008-11-05 10:36 <REP> d-------- c:\users\Secours
2008-11-05 10:23 . 2008-11-05 11:09 <REP> d-------- C:\SDFix
2008-11-05 09:58 . 2008-11-05 09:58 59,904 --a------ c:\windows\System32\Obwx0HVn.exe
2008-11-05 09:57 . 2008-11-05 09:57 <REP> d-------- c:\users\Invité\AppData\Roaming\Validity
2008-11-05 09:57 . 2008-11-05 09:57 <REP> d-------- c:\users\Invité\AppData\Roaming\Macromedia
2008-11-05 09:57 . 2008-11-05 09:57 <REP> d-------- c:\users\Invité\AppData\Roaming\ATI
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Videos
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Videos
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Searches
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Searches
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Saved Games
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Saved Games
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Pictures
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Pictures
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Music
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Music
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Links
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Links
2008-11-05 09:56 . 2008-11-05 09:57 <REP> dr------- c:\users\Invité\Favorites
2008-11-05 09:56 . 2008-11-05 09:57 <REP> dr------- c:\users\Invité\Favorites
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Downloads
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Downloads
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Documents
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Documents
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Desktop
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Desktop
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Contacts
2008-11-05 09:56 . 2008-11-05 09:56 <REP> dr------- c:\users\Invité\Contacts
2008-11-05 09:56 . 2008-11-05 09:57 <REP> d---s---- c:\users\Invité\AppData\Roaming\Microsoft
2008-11-05 09:56 . 2006-11-02 13:37 <REP> d-------- c:\users\Invité\AppData\Roaming\Media Center Programs
2008-11-05 09:56 . 2008-11-05 09:56 <REP> d-------- c:\users\Invité\AppData\Roaming\Identities
2008-11-05 09:56 . 2008-03-21 11:55 <REP> d-------- c:\users\Invité\AppData\Roaming\Acer GameZone Console
2008-11-05 09:56 . 2008-11-05 09:56 <REP> d--h----- c:\users\Invité\AppData
2008-11-05 09:56 . 2008-11-05 09:56 <REP> d--h----- c:\users\Invité\AppData
2008-11-05 09:56 . 2008-11-05 09:56 <REP> d-------- c:\users\Invité
2008-11-05 09:56 . 2008-11-05 11:37 786,432 --ahs---- c:\users\Invité\NTUSER.DAT
2008-11-05 09:56 . 2008-11-05 11:37 786,432 --ahs---- c:\users\Invité\NTUSER.DAT
2008-11-05 09:42 . 2008-11-05 09:42 <REP> d-------- c:\program files\Trend Micro
2008-11-05 09:14 . 2008-11-05 09:14 <REP> d-------- c:\windows\System32\Kaspersky Lab
2008-11-05 08:59 . 2008-11-05 09:01 <REP> d-------- c:\users\All Users\Lavasoft
2008-11-05 08:59 . 2008-11-05 09:01 <REP> d-------- c:\programdata\Lavasoft
2008-11-05 08:59 . 2008-11-05 08:59 <REP> d-------- c:\program files\Lavasoft
2008-11-05 08:58 . 2008-11-05 08:58 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-01 10:07 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-11-01 10:07 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-11-01 10:07 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-11-01 10:06 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-11-01 10:06 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-11-01 10:06 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-01 10:06 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-11-01 10:06 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-25 10:49 . 2008-10-25 10:49 <REP> d-------- c:\users\Laetitia\AppData\Roaming\Samsung
2008-10-25 10:34 . 2007-07-03 15:58 106,792 --a------ c:\windows\System32\drivers\sscdmdm.sys
2008-10-25 10:34 . 2007-07-03 15:54 80,552 --a------ c:\windows\System32\drivers\sscdbus.sys
2008-10-25 10:34 . 2007-07-03 15:57 11,944 --a------ c:\windows\System32\drivers\sscdmdfl.sys
2008-10-25 10:34 . 2007-07-03 16:00 9,256 --a------ c:\windows\System32\drivers\sscdwhnt.sys
2008-10-25 10:34 . 2007-07-03 16:00 9,256 --a------ c:\windows\System32\drivers\sscdwh.sys
2008-10-25 10:34 . 2007-07-03 15:56 9,256 --a------ c:\windows\System32\drivers\sscdcmnt.sys
2008-10-25 10:34 . 2007-07-03 15:56 9,256 --a------ c:\windows\System32\drivers\sscdcm.sys
2008-10-25 10:33 . 2008-10-25 10:35 <REP> d-------- c:\windows\System32\Samsung_USB_Drivers
2008-10-25 10:33 . 2005-08-28 19:51 766 --a------ c:\windows\System32\Uninstall.ico
2008-10-25 10:32 . 2008-10-25 10:32 <REP> d-------- c:\program files\Samsung
2008-10-25 10:32 . 2008-10-25 10:45 5,632 --a------ c:\windows\System32\drivers\StarOpen.sys
2008-10-15 13:00 . 2008-09-18 03:16 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-10-15 12:55 . 2008-09-18 06:09 3,601,464 --a------ c:\windows\System32\ntkrnlpa.exe
2008-10-15 12:55 . 2008-09-18 06:09 3,549,240 --a------ c:\windows\System32\ntoskrnl.exe
2008-10-15 12:55 . 2008-08-27 02:06 288,768 --a------ c:\windows\System32\drivers\srv.sys
2008-10-15 12:53 . 2008-10-02 02:32 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2008-10-15 12:53 . 2008-10-02 04:49 827,392 --a------ c:\windows\System32\wininet.dll
2008-10-14 20:08 . 2008-10-14 20:09 <REP> d-------- c:\users\Laetitia\AppData\Roaming\BeachPartyCraze
2008-10-14 17:28 . 2008-10-14 17:28 <REP> d-------- c:\program files\Google
2008-10-12 16:39 . 2008-10-12 16:39 <REP> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-12 16:39 . 2008-10-12 16:39 <REP> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-12 16:39 . 2008-10-12 16:39 <REP> d-------- c:\program files\iTunes
2008-10-12 16:39 . 2008-10-12 16:39 <REP> d-------- c:\program files\iPod
2008-10-10 07:20 . 2008-10-10 07:24 <REP> d-------- c:\program files\PhotoFiltre
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 10:37 786,432 --sha-w c:\users\Invité\NTUSER.DAT
2008-11-05 10:37 786,432 --sha-w c:\users\Invité\NTUSER.DAT
2008-11-05 08:57 --------- d-s---w c:\users\Invité\AppData\Roaming\Microsoft
2008-11-05 08:57 --------- d-----w c:\users\Invité\AppData\Roaming\Validity
2008-11-05 08:57 --------- d-----w c:\users\Invité\AppData\Roaming\Macromedia
2008-11-05 08:57 --------- d-----w c:\users\Invité\AppData\Roaming\ATI
2008-11-05 08:56 --------- d-----w c:\users\Invité\AppData\Roaming\Identities
2008-10-25 09:50 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-16 04:56 --------- d-----w c:\program files\Windows Mail
2008-10-15 21:09 --------- d-----w c:\programdata\Microsoft Help
2008-10-14 20:08 --------- d---a-w c:\programdata\TEMP
2008-10-04 09:21 --------- d-----w c:\program files\DivX
2008-10-04 09:20 --------- d-----w c:\program files\Common Files\PX Storage Engine
2008-10-01 13:23 --------- d-----w c:\users\Laetitia\AppData\Roaming\PlayFirst
2008-10-01 13:23 --------- d-----w c:\programdata\PlayFirst
2008-09-29 16:13 --------- d-----w c:\users\Laetitia\AppData\Roaming\.ABC
2008-09-28 11:59 --------- d-----w c:\program files\ABC
2008-09-26 13:09 --------- d-----w c:\users\Laetitia\AppData\Roaming\vlc
2008-09-26 12:47 --------- d-----w c:\program files\Veoh Networks
2008-09-23 17:32 --------- d-----w c:\programdata\AirportMania
2008-09-23 16:01 --------- d-----w c:\users\Laetitia\AppData\Roaming\Valusoft
2008-09-23 16:01 --------- d-----w c:\programdata\Valusoft
2008-09-18 15:35 --------- d-----w c:\programdata\McAfee
2008-09-18 15:32 --------- d-----w c:\programdata\SiteAdvisor
2008-09-17 18:17 --------- d-----w c:\programdata\Fugazo
2008-09-16 18:05 --------- d-----w c:\users\Laetitia\AppData\Roaming\Jane s Hotel
2008-09-16 17:03 --------- d-----w c:\users\Laetitia\AppData\Roaming\blg
2008-09-16 17:03 --------- d-----w c:\programdata\blg
2008-09-16 15:16 --------- d-----w c:\program files\Acer GameZone
2008-09-16 00:11 161,096 ----a-w c:\windows\System32\DivXCodecVersionChecker.exe
2008-09-15 17:27 --------- d-----w c:\program files\VideoLAN
2008-09-15 16:37 --------- d-----w c:\program files\Apple Software Update
2008-09-15 16:34 --------- d-----w c:\program files\Bonjour
2008-09-15 16:33 --------- d-----w c:\program files\QuickTime
2008-09-15 16:32 --------- d-----w c:\program files\Common Files\Apple
2008-09-14 20:22 --------- d-----w c:\users\Laetitia\AppData\Roaming\ViquaSoft
2008-09-14 14:09 --------- d-----w c:\program files\bfgclient
2008-09-14 13:38 --------- d-----w c:\program files\Common Files\Oberon Media
2008-09-12 07:28 --------- d-----w c:\program files\Safari
2008-09-11 13:33 --------- d-----w c:\programdata\NannyMania
2008-09-11 13:19 --------- d-----w c:\programdata\SpinTop Games
2008-09-10 20:04 --------- d-----w c:\program files\Microsoft Works
2008-09-10 16:26 --------- d-----w c:\users\Laetitia\AppData\Roaming\Home Sweet Home
2008-09-10 16:00 --------- d-----w c:\programdata\CyberLink
2008-09-09 19:58 --------- d-----w c:\users\Laetitia\AppData\Roaming\FloodLightGames
2008-09-08 18:57 --------- d-----w c:\users\Laetitia\AppData\Roaming\Big Fish Games
2008-09-07 15:37 --------- d-----w c:\users\Laetitia\AppData\Roaming\Gamelab
2008-09-07 13:23 --------- d-----w c:\programdata\Go Go Gourmet
2008-09-07 08:27 --------- d-----w c:\programdata\Arcade Lab
2008-09-07 08:20 --------- d-----w c:\users\Laetitia\AppData\Roaming\CyberLink
2008-09-07 08:20 --------- d-----w c:\programdata\PlayMovie
2008-09-06 08:46 --------- d-----w c:\programdata\Oberon Games
2008-09-05 17:31 --------- d-----w c:\programdata\Sandlot Games
2008-09-05 17:31 --------- d-----w c:\program files\Common Files\Sandlot Shared
2008-09-05 15:38 --------- d-----w c:\users\Laetitia\AppData\Roaming\Apple Computer
2008-09-05 15:37 --------- d-----w c:\programdata\Apple Computer
2008-09-05 15:34 --------- d-----w c:\programdata\Apple
2008-09-05 15:31 --------- d-----w c:\users\Laetitia\AppData\Roaming\Acer
2008-09-05 15:21 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-08-29 08:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 23:38 121392 --a------ c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-28 3660848]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-04 1037608]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-03-07 544768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-03 178712]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-06-28 3673600]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-04-28 809480]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-04-25 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-04-25 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-05-12 167936]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-05-09 397312]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-11 c:\windows\RtHDVCpl.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2008-06-28 1216512]
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-04-24 723760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-06-28 23:29 3130368 c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FE015045-F8E4-492E-A03D-0771E64FCC90}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{94B6DB73-5141-4A2B-85EF-CD29836B2E4E}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{63EA630E-9436-4BC8-B82B-22F39F00B076}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{A48BE2C1-D6C0-4DF8-A064-454204B2DADF}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe:Acer Play Movie
"{CFD1BCDE-3CEC-42B1-8944-013124C66939}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe:Acer Play Movie Resident Program
"{E940B55C-D962-4717-9DA5-C1B3020D4034}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:Acer HomeMedia
"{1F3D742A-D764-444B-9FC6-29D9567563BD}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM
"{47BF15BC-29DF-4BE5-A1D6-7D52783DBEE8}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{EE5CDDDD-2660-49AD-807E-17179F331E5A}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{A111E818-2932-45CF-9513-5F8E30BA71E0}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{562161D5-6ADE-44C2-BF3F-E68B1BB48BB5}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{F00E00D7-6611-4B86-BA3E-352C76FD90D8}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{62B21C4E-EF6B-4839-93CF-F820AF071C44}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{E22B0E9F-5BC2-4D9A-A3A0-C353F249399C}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{80CB7FB7-71A1-4CCE-8E1B-C72A8F11FEA4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A97831FE-45F4-4D0E-B8CA-CF62FC4BFE4E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B1E8229A-2B4F-4133-84C8-1A97382A346E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1AA0FEE2-6E27-4FA2-A5DE-98951122136C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1021532F-CAEA-4363-874C-5DD3D4BFBD1E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\Drivers\AlfaFF.sys [2008-06-28 43184]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\[u]0
/u00.fcl [2008-05-02 16:27 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-21 24576]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [2008-06-28 3488768]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-04-27 599344]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-05-08 3552256]
R3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1E60x86.sys [2008-03-11 48128]
R3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-04-27 40752]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-11 84240]
S4 ErrDev;Microsoft Hardware Error Device Driver;c:\windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR;c:\windows\system32\drivers\megasr.sys [2008-01-21 386616]
.
Contenu du dossier 'Tâches planifiées'
2008-11-05 c:\windows\Tasks\At1.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At10.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At11.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At12.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At13.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At14.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At15.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At16.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At17.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At18.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At19.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At2.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At20.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At21.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At22.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At23.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At24.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At3.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At4.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At5.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At6.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At7.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At8.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-05 c:\windows\Tasks\At9.job
- c:\windows\system32\Obwx0HVn.exe [2008-11-05 09:58]
2008-11-04 c:\windows\Tasks\User_Feed_Synchronization-{150FEB6A-36AC-4B35-9329-FA40521619D8}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 03:24]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-eRecoveryService - (no file)
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R0 -: HKLM-Main,Start Page = hxxp://fr.fr.acer.yahoo.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-05 12:10:22
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\System32\conime.exe
c:\program files\Launch Manager\LManager.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Acer\Acer Bio Protection\PwdBank.exe
c:\windows\ehome\ehmsas.exe
c:\users\Laetitia\AppData\Local\Temp\RtkBtMnt.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Acer\Acer VCM\acp2HID.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Heure de fin: 2008-11-05 12:14:04 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-05 11:13:54
Avant-CF: 81 690 816 512 octets libres
Après-CF: 81,630,244,864 octets libres
378 --- E O F --- 2008-11-05 07:41:45