J'ai réussi a reinstaller mon anti virus
j'ai fait un scan et j'ai mis en quarantaine 122 virus TR/Bagle.Gen.B
j'ai fait un scan comboix et vola le rapport
ComboFix 08-11-12.02 - Jean Luc 2008-11-14 15:51:49.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.564 [GMT 1:00]
Lancé depuis: c:\documents and settings\Jean Luc\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Starware316
c:\documents and settings\All Users\Application Data\Starware316\buttons\775_button_1b_def.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\FindIt.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\FindItHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\findithotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\finditxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\Free_Credit_Score0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Free_Music0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\logo.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\logoxp.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Reference.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\ReferenceHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\referencehotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\referencexp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\Ringtones0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Screensavers0.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\Weather.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\WeatherHot.bmp
c:\documents and settings\All Users\Application Data\Starware316\buttons\weatherhotxp.png
c:\documents and settings\All Users\Application Data\Starware316\buttons\weatherxp.png
c:\documents and settings\All Users\Application Data\Starware316\contexts\error.xml
c:\documents and settings\All Users\Application Data\Starware316\contexts\Related.xml
c:\documents and settings\All Users\Application Data\Starware316\contexts\Travel.xml
c:\documents and settings\All Users\Application Data\Starware316\images\walertXP.bmp
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\ProductMessagingConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\ProductMessagingConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\SimpleUpdateConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\SimpleUpdateConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\TimerManagerConfig.xml
c:\documents and settings\All Users\Application Data\Starware316\SimpleUpdate\TimerManagerConfig.xml.backup
c:\documents and settings\Jean Luc\Application Data\inst.exe
c:\documents and settings\Jean Luc\Application Data\ShoppingReport
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Jean Luc\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\Jean Luc\Application Data\Starware316(2)
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\BrowserSearch\BrowserSearch.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Configurator\Configurator.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Configurator\Configurator.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ErrorSearch\ErrorSearchOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ErrorSearch\ErrorSearchOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Free_Credit_Score\Free_Credit_ScoreOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Free_Credit_Score\Free_Credit_ScoreOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Free_Music\Free_MusicOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Free_Music\Free_MusicOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Layouts\ToolbarLayout.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Layouts\ToolbarLayout.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Manager\ManagerOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Manager\ManagerOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Reference\ReferenceOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Reference\ReferenceOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\RelatedSearch\RelatedSearchOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\RelatedSearch\RelatedSearchOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Ringtones\RingtonesOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Ringtones\RingtonesOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Screensavers\ScreensaversOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Screensavers\ScreensaversOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Toolbar\TBProductsOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Toolbar\TBProductsOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ToolbarLogo\ToolbarLogoOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ToolbarSearch\ToolbarSearchOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\TravelSearch\TravelSearchOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\TravelSearch\TravelSearchOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Weather\AlertArchive.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Weather\WeatherOptions.xml
c:\documents and settings\Jean Luc\Application Data\Starware316(2)\Weather\WeatherOptions.xml.backup
c:\documents and settings\Jean Luc\Application Data\Ultimate Cleaner
c:\documents and settings\Jean Luc\Application Data\Ultimate Cleaner\settings.dat
c:\documents and settings\Jean Luc\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\documents and settings\Jean Luc\Local Settings\Application Data\qsmqaiu.dat
c:\documents and settings\Jean Luc\Local Settings\Application Data\qsmqaiu_nav.dat
c:\documents and settings\Jean Luc\Local Settings\Application Data\qsmqaiu_navps.dat
c:\program files\akl
c:\program files\akl\akl.dll
c:\program files\akl\akl.exe
c:\program files\akl\uninstall.exe
c:\program files\akl\unsetup.exe
c:\program files\Orange\SessionManager\SessionManager.exe
c:\program files\Starware316
c:\program files\Starware316\Starware316Config.xml
c:\windows\a.bat
c:\windows\base64.tmp
c:\windows\bdn.com
c:\windows\cookies.ini
c:\windows\iTunesMusic.exe
c:\windows\mslagent
c:\windows\mslagent\2_mslagent.dll
c:\windows\mslagent\mslagent.exe
c:\windows\mslagent\uninstall.exe
c:\windows\mssecu.exe
c:\windows\system32\AdMVCcdd.ini
c:\windows\system32\AdMVCcdd.ini2
c:\windows\system32\akttzn.exe
c:\windows\system32\anticipator.dll
c:\windows\system32\awtoolb.dll
c:\windows\system32\bdn.com
c:\windows\system32\bsmvmdft.ini
c:\windows\system32\bsva-egihsg52.exe
c:\windows\system32\dao350.dll
c:\windows\system32\dpcproxy.exe
c:\windows\system32\drivers\downld
c:\windows\system32\h@tkeysh@@k.dll
c:\windows\system32\hoproxy.dll
c:\windows\system32\HQYGPXyb.ini
c:\windows\system32\HQYGPXyb.ini2
c:\windows\system32\hxiwlgpm.dat
c:\windows\system32\hxiwlgpm.exe
c:\windows\system32\ibvslncm.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\msgp.exe
c:\windows\system32\msnbho.dll
c:\windows\system32\mssecu.exe
c:\windows\system32\msvchost.exe
c:\windows\system32\mtr2.exe
c:\windows\system32\mwin32.exe
c:\windows\system32\netode.exe
c:\windows\system32\newsd32.exe
c:\windows\system32\nvs2.inf
c:\windows\system32\ps1.exe
c:\windows\system32\psof1.exe
c:\windows\system32\psoft1.exe
c:\windows\system32\regc64.dll
c:\windows\system32\regm64.dll
c:\windows\system32\Rundl1.exe
c:\windows\system32\smp
c:\windows\system32\smp\msrc.exe
c:\windows\system32\sncntr.exe
c:\windows\system32\ssurf022.dll
c:\windows\system32\ssvchost.com
c:\windows\system32\ssvchost.exe
c:\windows\system32\sysreq.exe
c:\windows\system32\taack.dat
c:\windows\system32\taack.exe
c:\windows\system32\temp#01.exe
c:\windows\system32\thun.dll
c:\windows\system32\thun32.dll
c:\windows\system32\urngwlmb.ini
c:\windows\system32\VBIEWER.OCX
c:\windows\system32\vbsys2.dll
c:\windows\system32\vcatchpi.dll
c:\windows\system32\winlogonpc.exe
c:\windows\system32\winsystem.exe
c:\windows\system32\WINWGPX.EXE
c:\windows\userconfig9x.dll
c:\windows\winsystem.exe
c:\windows\zip1.tmp
c:\windows\zip2.tmp
c:\windows\zip3.tmp
c:\windows\zipped.tmp
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Legacy_WINDOWS_TASK_MANAGER
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-14 au 2008-11-14 ))))))))))))))))))))))))))))))))))))
.
2008-11-14 14:50 . 2008-11-14 14:50 <REP> d-------- c:\program files\Avira
2008-11-14 14:25 . 2008-11-14 14:25 <REP> d-------- c:\program files\Trend Micro
2008-11-14 13:58 . 2008-11-14 13:58 <REP> d-------- c:\program files\CCleaner
2008-11-14 00:45 . 2008-11-14 00:45 <REP> d-------- C:\_OTMoveIt
2008-11-13 13:59 . 2008-11-14 15:45 <REP> d-------- c:\program files\FindyKill
2008-11-13 12:43 . 2008-11-13 12:43 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-13 12:43 . 2008-11-13 12:43 1,409 --a------ c:\windows\QTFont.for
2008-11-11 12:06 . 2008-11-11 12:06 <REP> d-------- c:\documents and settings\Jean Luc\Application Data\Uniblue
2008-11-11 03:04 . 2008-11-14 00:41 <REP> d-------- c:\program files\Panda Security
2008-11-11 02:46 . 2008-11-11 02:53 <REP> d-------- c:\program files\Windows Live Safety Center
2008-11-11 02:37 . 2008-11-11 02:37 <REP> d-------- c:\program files\Alwil Software
2008-11-10 22:01 . 2008-11-13 01:10 <REP> d-------- c:\program files\QUAD Utilities
2008-10-28 18:40 . 2008-10-28 18:40 <REP> d-------- c:\documents and settings\All Users\Documents
2008-10-28 17:49 . 2008-10-28 17:49 <REP> d-------- c:\windows\system32\DRM
2008-10-26 14:01 . 2008-10-26 14:01 <REP> d-------- c:\documents and settings\Amy\Contacts
2008-10-26 13:48 . 2002-01-01 01:04 <REP> d--h----- c:\documents and settings\Amy\Voisinage réseau
2008-10-26 13:48 . 2002-01-01 01:04 <REP> d--h----- c:\documents and settings\Amy\Voisinage d'impression
2008-10-26 13:48 . 2007-10-04 13:31 <REP> d--h----- c:\documents and settings\Amy\Modèles
2008-10-26 13:48 . 2002-01-01 01:04 <REP> dr------- c:\documents and settings\Amy\Menu Démarrer
2008-10-26 13:48 . 2008-10-26 13:52 <REP> dr------- c:\documents and settings\Amy\Favoris
2008-10-26 13:48 . 2008-10-26 13:50 <REP> d-------- c:\documents and settings\Amy\Bureau
2008-10-26 13:48 . 2008-10-27 14:02 <REP> d-------- c:\documents and settings\Amy
2008-10-24 09:58 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 09:25 . 2008-10-23 09:25 <REP> d-------- c:\documents and settings\LocalService\Bureau
2008-10-15 23:53 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-15 23:52 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-15 23:51 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 23:51 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 23:51 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 23:51 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-14 14:04 --------- d-----w c:\program files\NetPumper
2008-11-14 13:50 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-11-14 01:12 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-10 19:39 --------- d-----w c:\program files\Windows Live
2008-10-27 11:11 --------- d-----w c:\program files\Lexmark X1100 Series
2008-10-15 17:20 --------- d-----w c:\program files\Dictionnaire
2008-10-10 17:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-10 17:03 --------- d-----w c:\program files\Ensemble clavier et souris sans fil Labtec
2008-10-10 16:24 --------- d-----w c:\documents and settings\Jean Luc\Application Data\Research In Motion
2008-10-10 15:56 --------- d-----w c:\program files\Fichiers communs\Sonic Shared
2008-10-10 15:55 --------- d-----w c:\program files\Roxio
2008-10-10 15:54 --------- d-----w c:\program files\Fichiers communs\Roxio Shared
2008-10-10 15:53 --------- d-----w c:\documents and settings\All Users\Application Data\Roxio
2008-10-10 15:45 --------- d-----w c:\program files\Fichiers communs\Research In Motion
2008-10-10 15:44 --------- d-----w c:\program files\Research In Motion
2008-10-10 14:26 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-07 18:33 --------- d-----w c:\program files\EoRezo
2008-10-07 18:30 --------- d-----w c:\documents and settings\Jean Luc\Application Data\EoRezo
2008-10-07 17:40 --------- d-----w c:\program files\Fichiers communs\Windows Live
2008-10-02 02:12 --------- d-----w c:\program files\RegCleaner
2008-04-16 18:34 47,360 -c--a-w c:\documents and settings\Jean Luc\Application Data\pcouffin.sys
2008-02-25 13:56 303,104 -c--a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2007-12-18 14:21 125,320 -c--a-w c:\documents and settings\Jean Luc\Application Data\GDIPFONTCACHEV1.DAT
2008-08-09 11:35 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008080920080810\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"F-Secure Manager"="c:\program files\Securitoo\av_fw\Common\FSM32.EXE" [2008-11-14 176177]
"F-Secure TNB"="c:\program files\Securitoo\av_fw\FSGUI\TNBUtil.exe" [2008-11-14 733184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-11-24 185896]
"RoxWatchTray"="c:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Activer l'ensemble clavier et souris sans fil Labtec.lnk - c:\program files\Ensemble clavier et souris sans fil Labtec\MagicKey.exe [2008-10-10 258048]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"msacm.l3codec"= l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Activer l'ensemble clavier et souris sans fil Labtec.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Activer l'ensemble clavier et souris sans fil Labtec.lnk
backup=c:\windows\pss\Activer l'ensemble clavier et souris sans fil Labtec.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Rappels du Calendrier Microsoft Works.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Rappels du Calendrier Microsoft Works.lnk
backup=c:\windows\pss\Rappels du Calendrier Microsoft Works.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jean Luc^Menu Démarrer^Programmes^Démarrage^Barre d'Outils Olitec.lnk]
path=c:\documents and settings\Jean Luc\Menu Démarrer\Programmes\Démarrage\Barre d'Outils Olitec.lnk
backup=c:\windows\pss\Barre d'Outils Olitec.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Jean Luc^Menu Démarrer^Programmes^Démarrage^Moniteur.lnk]
path=c:\documents and settings\Jean Luc\Menu Démarrer\Programmes\Démarrage\Moniteur.lnk
backup=c:\windows\pss\Moniteur.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eQoonMessenger]
--a--c--- 2006-10-19 09:39 53248 c:\program files\eQoon\Tools\Messenger\eQoonMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
--a--c--- 2003-08-19 15:48 57344 c:\program files\Lexmark X1100 Series\lxbkbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-06-29 05:24 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a--c--- 2007-11-24 18:12 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eQoon\\Tools\\Service\\eQoonService.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
R1 cpuidlep;CpuIdle Pro System Driver;c:\windows\system32\drivers\cpuidlep.sys [2008-07-21 4484]
R1 kbfilter;Keyboard Filter Driver;c:\windows\system32\drivers\kbfilter.sys [2003-03-27 11776]
R2 eQoon Service;eQoon Service;c:\program files\eqoon\tools\service\eqoonservice.exe [2006-10-25 45056]
S1 F-Secure HIPS;F-Secure HIPS;c:\program files\Securitoo\av_fw\HIPS\fshs.sys [ ]
S1 Isecdrv;Isecdrv;c:\windows\system32\drivers\Isecdrv.sys [ ]
S2 Ca536av;DV AIPTEK CAUET(Video);c:\windows\system32\Drivers\Ca536av.sys [ ]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Securitoo\av_fw\Anti-Virus\minifilter\fsgk.sys [ ]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [ ]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
S3 USBAV191;Instant VideoXpress;c:\windows\system32\DRIVERS\USBAV191.SYS [2005-04-28 120128]
S3 USBCamera;DV AIPTEK CAUET(Still);c:\windows\system32\Drivers\Bulk536.sys [ ]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys [ ]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys [ ]
S4 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ea7a116-b65f-11dc-91b0-00030d000001}]
\Shell\Auto\command - Windows.scr
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Windows.scr
.
Contenu du dossier 'Tâches planifiées'
2008-10-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
2008-10-08 c:\windows\Tasks\cleanmgr.job
- c:\windows\system32\cleanmgr.exe [2008-04-14 03:33]
2008-10-30 c:\windows\Tasks\dfrg.job
- c:\windows\system32\dfrg.msc [2001-08-28 13:00]
2008-09-13 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
2008-11-08 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\SECURI~1\av_fw\ANTI-V~1\fsav.exe [2008-11-11 04:27]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{14ECE1FA-31AE-463C-80D7-FADB00E5AC17} - (no file)
HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
HKCU-Run-RegistryBooster 2 d’Uniblue - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKLM-Run-ORAHSSSessionManager - c:\program files\Orange\SessionManager\SessionManager.exe
SSODL-tdomgafw-{755EC199-6756-4604-9C23-C63F63D53501} - (no file)
SSODL-wetkadmr-{7E215B6E-58A4-43E2-B67D-71FEBD1974D8} - (no file)
Notify-iifcDWpN - iifcDWpN.dll
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
MSConfigStartUp-bochadqfue - c:\documents and settings\jean luc\local settings\application data\bochadqfue.exe
MSConfigStartUp-spywareisolator - c:\program files\SpywareIsolator\spywareisolator.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-Ultimate Cleaner - c:\program files\Ultimate Cleaner\UltimateCleaner.exe
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.conduit.com/Results.aspx?q={searchTerms}&meta=all&hl=fr&gl=fr&SelfSearch=1&SearchSourceOrigin=1&ctid=CT1472949
R0 -: HKCU-Main,Start Page = hxxp://lo.st/
R1 -: HKCU-SearchURL,(Default) = hxxp://search.conduit.com/Results.aspx?q=%s&meta=all&hl=fr&gl=fr&SelfSearch=1&SearchSourceOrigin=1&ctid=CT1472949
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-14 16:13:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\searchindexer.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
c:\program files\Ensemble clavier et souris sans fil Labtec\MulMouse.exe
c:\program files\Ensemble clavier et souris sans fil Labtec\OSD.exe
.
**************************************************************************
.
Heure de fin: 2008-11-14 16:15:54 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-14 15:15:51
Avant-CF: 36 452 728 832 octets libres
Après-CF: 36,492,365,824 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
397 --- E O F --- 2008-11-14 01:12:58