Salut Antony,
Voici le rapport de combo fix.Je tiens juste a te dire,que j ai un truc bizarre qui est apparu sur mon fond d'ecran pendant le scan de combo,c est la barre kiwee qui me dit you have just disabled the kiwee toolbar,veux tu la remettre oui ou non.J ai de gros soupsons que c est le virus car quand il s est installé sur l ordinateur,il a installé cette barre qui est devenu incontrolable.Je ne touche rien pour l instant.J espere que tu te connecteras ce soir.Merci d avance
ComboFix 08-12-14.05 - LIONEL 2008-12-15 18:44:34.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.958.525 [GMT 1:00]
Lancé depuis: c:\documents and settings\LIONEL\Bureau\C-FIX.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Application Data\vlc-0.9.4-win32.exe
c:\documents and settings\All Users\Application Data\vlc-0.9.4-win32.exe
c:\program files\Internet Explorer\fxavx.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-15 au 2008-12-15 ))))))))))))))))))))))))))))))))))))
.
2008-12-15 10:43 . 2008-12-15 10:43 <REP> d-------- C:\VundoFix Backups
2008-12-14 18:19 . 2008-12-14 18:19 <REP> dr------- c:\documents and settings\LocalService\Favoris
2008-12-14 18:11 . 2008-12-14 18:31 <REP> d-------- c:\documents and settings\All Users\Application Data\MailFrontier
2008-12-14 18:11 . 2008-12-14 18:13 4,212 ---h----- c:\windows\system32\zllictbl.dat
2008-12-14 18:10 . 2004-04-27 04:40 11,264 --a------ c:\windows\system32\SpOrder.dll
2008-12-14 18:09 . 2008-12-14 18:36 <REP> d-------- c:\windows\Internet Logs
2008-12-14 17:38 . 2008-12-14 17:38 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-14 17:38 . 2008-12-14 17:38 <REP> d-------- c:\documents and settings\LIONEL\Application Data\Malwarebytes
2008-12-14 17:38 . 2008-12-14 17:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-14 17:38 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-14 17:38 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-14 17:29 . 2008-12-14 17:37 <REP> d-------- c:\program files\MSNFix
2008-12-14 14:49 . 2008-12-14 22:35 <REP> d-------- c:\program files\a-squared Free
2008-12-14 12:34 . 2008-12-14 12:34 21,415,977 --a------ c:\windows\VPTNFILE.707
2008-12-14 12:34 . 2008-12-14 12:34 21,415,977 --a------ c:\windows\LPT$VPN.707
2008-12-14 12:33 . 2008-12-14 12:34 <REP> d-------- c:\windows\AU_Temp
2008-12-14 04:14 . 2008-12-14 04:19 <REP> d-------- c:\windows\avxoscan
2008-12-09 08:54 . 2008-12-09 08:54 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-08 23:59 . 2008-12-14 20:28 <REP> d-------- c:\program files\PeerGuardian2
2008-12-05 10:52 . 2008-12-05 10:52 <REP> dr------- c:\documents and settings\LIONEL\Application Data\Brother
2008-12-02 21:53 . 2008-12-02 21:53 <REP> d-------- c:\documents and settings\LIONEL\Application Data\Template
2008-12-02 21:53 . 2008-12-02 22:01 138 --a------ c:\documents and settings\LIONEL\Application Data\wklnhst.dat
2008-12-02 09:49 . 2008-12-02 09:49 <REP> d-------- c:\program files\Comptes et Budget Free V5.0
2008-12-02 09:49 . 2008-12-02 09:49 <REP> d-------- c:\documents and settings\LIONEL\Application Data\AlauxSoft
2008-11-24 20:53 . 2008-11-24 20:53 <REP> dr------- c:\documents and settings\erienne\Application Data\Brother
2008-11-24 19:48 . 2008-11-24 19:48 <REP> d-------- c:\documents and settings\erienne\Application Data\OpenOffice.org
2008-11-22 22:59 . 2008-11-22 22:59 <REP> d-------- c:\documents and settings\LIONEL\Application Data\vlc
2008-11-22 19:20 . 2008-12-03 18:22 <REP> d-------- c:\documents and settings\LIONEL\Application Data\Azureus
2008-11-22 19:12 . 2008-11-22 19:20 <REP> d-------- c:\documents and settings\erienne\Application Data\Azureus
2008-11-22 15:51 . 2008-11-22 16:15 <REP> d-------- c:\documents and settings\erienne\Application Data\vlc
2008-11-22 15:50 . 2008-11-22 15:51 <REP> d-------- c:\documents and settings\erienne\Application Data\dvdcss
2008-11-22 13:14 . 2008-11-22 13:14 <REP> d-------- c:\documents and settings\erienne\Application Data\CyberLink
2008-11-21 20:23 . 2008-12-05 14:02 <REP> d-------- c:\documents and settings\LIONEL\Contacts
2008-11-21 20:22 . 2008-11-21 20:38 <REP> d-------- c:\documents and settings\LIONEL\Application Data\agi
2008-11-21 19:18 . 2008-11-21 19:18 <REP> d-------- c:\documents and settings\LIONEL\Application Data\OpenOffice.org
2008-11-21 19:02 . 2006-06-20 10:22 <REP> d-------- c:\documents and settings\LIONEL\WINDOWS
2008-11-21 19:02 . 2005-10-20 20:05 <REP> d-------- c:\documents and settings\LIONEL\Voisinage réseau
2008-11-21 19:02 . 2005-10-20 20:05 <REP> d-------- c:\documents and settings\LIONEL\Voisinage d'impression
2008-11-21 19:02 . 2005-10-26 23:35 <REP> d-------- c:\documents and settings\LIONEL\Modèles
2008-11-21 19:02 . 2008-12-14 14:49 <REP> dr------- c:\documents and settings\LIONEL\Mes documents
2008-11-21 19:02 . 2005-10-26 23:35 <REP> d-------- c:\documents and settings\LIONEL\Menu Démarrer
2008-11-21 19:02 . 2008-12-14 22:23 <REP> dr------- c:\documents and settings\LIONEL\Favoris
2008-11-21 19:02 . 2008-12-15 18:35 <REP> d-------- c:\documents and settings\LIONEL\Bureau
2008-11-21 19:02 . 2008-12-15 10:41 <REP> d-------- c:\documents and settings\LIONEL
2008-11-17 11:45 . 2008-11-17 11:45 <REP> dr-h----- c:\documents and settings\erienne\Application Data\SecuROM
2008-11-16 20:27 . 2008-11-22 17:26 <REP> d-------- c:\documents and settings\erienne\Contacts
2008-11-16 20:27 . 2008-11-16 21:30 <REP> d-------- c:\documents and settings\erienne\Application Data\agi
2008-11-16 20:14 . 2006-06-20 10:22 <REP> d-------- c:\documents and settings\erienne\WINDOWS
2008-11-16 20:14 . 2005-10-20 20:05 <REP> d-------- c:\documents and settings\erienne\Voisinage réseau
2008-11-16 20:14 . 2005-10-20 20:05 <REP> d-------- c:\documents and settings\erienne\Voisinage d'impression
2008-11-16 20:14 . 2005-10-26 23:35 <REP> d-------- c:\documents and settings\erienne\Modèles
2008-11-16 20:14 . 2008-11-30 18:47 <REP> dr------- c:\documents and settings\erienne\Mes documents
2008-11-16 20:14 . 2005-10-26 23:35 <REP> d-------- c:\documents and settings\erienne\Menu Démarrer
2008-11-16 20:14 . 2008-12-04 02:01 <REP> dr------- c:\documents and settings\erienne\Favoris
2008-11-16 20:14 . 2008-12-05 14:23 <REP> d-------- c:\documents and settings\erienne\Bureau
2008-11-16 20:14 . 2008-12-11 23:52 <REP> d-------- c:\documents and settings\erienne
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 10:03 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-14 17:20 --------- d-----w c:\program files\MSN Messenger
2008-12-14 11:34 91,744 ----a-w c:\windows\BPMNT.dll
2008-12-14 11:34 1,213,784 ----a-w c:\windows\vsapi32.dll
2008-12-13 17:31 --------- d-----w c:\program files\akboot
2008-12-09 07:54 --------- d-----w c:\program files\Java
2008-12-03 21:59 --------- d-----w c:\program files\scrabbleproB1.0.8
2008-11-30 20:46 --------- d-----w c:\program files\Vuze
2008-11-18 21:16 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\Azureus
2008-11-11 12:34 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\ScanSoft
2008-11-11 12:13 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\HP
2008-11-07 08:15 --------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-11-05 22:50 --------- d-----w c:\program files\EA GAMES
2008-11-05 13:32 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-04 16:40 --------- d-----w c:\program files\Mio Technology
2008-11-04 14:41 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-03 10:17 --------- d-----w c:\program files\Brother
2008-11-03 10:16 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\InstallShield
2008-11-02 15:00 --------- d-----w c:\program files\NOS
2008-11-02 15:00 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-10-27 14:40 71,749 ----a-w c:\windows\hcextoutput.dll
2008-10-27 14:40 348,229 ----a-w c:\windows\TSC.exe
2008-10-27 14:39 69,689 ----a-w c:\windows\UNZIP.DLL
2008-10-27 14:39 507,904 ----a-w c:\windows\TMUPDATE.DLL
2008-10-27 14:39 286,720 ----a-w c:\windows\PATCH.EXE
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-24 00:20 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-10-23 23:20 --------- d-----w c:\program files\Yahoo!
2008-10-23 23:18 --------- d-----w c:\program files\7-Zip
2008-10-23 19:33 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\OpenOffice.org
2008-10-23 19:30 --------- d-----w c:\program files\OpenOffice.org 3
2008-10-23 19:30 --------- d-----w c:\program files\JRE
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-22 22:15 --------- d-----w c:\program files\HP
2008-10-22 22:14 --------- d-----w c:\program files\Hewlett-Packard
2008-10-22 20:06 928 ----a-w c:\documents and settings\HP_Propriétaire\Application Data\wklnhst.dat
2008-10-17 00:48 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-10-16 20:03 --------- d-----w c:\program files\PC-Doctor 5 for Windows
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:11 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-10-13 10:40 339,968 ----a-w c:\windows\system32\pythoncom25.dll
2008-10-13 10:40 2,117,632 ----a-w c:\windows\system32\python25.dll
2008-10-13 10:40 114,688 ----a-w c:\windows\system32\pywintypes25.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-23 16:46 245,408 ----a-w c:\windows\system32\unicows.dll
2008-09-16 16:26 1,332,197 ----a-w c:\windows\system32\pythondll.zip
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2008-12-04 21:14 277648 --a------ c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll" [2008-12-04 277648]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll" [2008-12-04 277648]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="c:\program files\CyberLink\PowerCinema\PCMService.exe" [2006-02-25 147456]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-27 77824]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-06-20 180269]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"PCDrSmartMonitor"="c:\program files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe" [2006-02-02 360448]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-06-20 27136]
c:\documents and settings\erienne\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-06-20 27136]
c:\documents and settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\LIONEL\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-06-20 27136]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Sagem - Utilitaire r‚seau pour Cl‚ USB Wi-Fi 802.11g.lnk - c:\program files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe [2007-12-30 679936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=bukbtg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
--a------ 2005-06-02 07:35 49152 c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\CyberLink\\PowerCinema\\PowerCinema.exe"=
"c:\\Program Files\\CyberLink\\PowerCinema\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-05 111184]
R2 AGWinService;AG Windows Service;"c:\program files\AGI\common\win32\PythonService.exe" [2008-10-13 10240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-05 20560]
R2 CKService;CKService;c:\windows\system32\CKService.exe [2006-03-22 107008]
R2 litsgt;litsgt;c:\windows\system32\DRIVERS\litsgt.sys [2006-10-21 137344]
R2 tansgt;tansgt;c:\windows\system32\DRIVERS\tansgt.sys [2006-10-21 12032]
R3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [2006-02-08 21120]
R3 WN5301;LIteon Wireless PCI Network Adapter Service;c:\windows\system32\DRIVERS\wn5301.sys [2006-06-20 468768]
S3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\DRIVERS\WlanUIG.sys [2007-12-30 379456]
*Newly Created Service* - PCANDIS5
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2007-05-07 c:\windows\Tasks\Connexion facile à Internet.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-08 18:23]
2008-12-15 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
HKLM-Run-Workflow - E:\Workflow.exe
MSConfigStartUp-JeticoPFStartup - c:\program files\Jetico\Jetico Personal Firewall\fwsrv.exe
MSConfigStartUp-Numericable Controle Parental - c:\program files\Numericable Controle Parental\Numericable Controle Parental.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=63&bd=PAVILION&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=63&bd=PAVILION&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=63&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=63&bd=PAVILION&pf=desktop
IE: &Traduire à partir de l'anglais - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Recherche &Google - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: {{B1474CCB-9FAF-45D8-B831-84F9A77EEE43} - c:\windows\system32\Suggestion.exe
IE: {{B1474CCB-9FAF-45D8-B831-84F9A77EEE43} - c:\windows\system32\Suggestion.exe -
c:\windows\Downloaded Program Files\InstallerControl.dll - O16 -: CabBuilder
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
c:\windows\Downloaded Program Files\OSDC5.OSD
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 18:47:57
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2008-12-15 18:48:57
ComboFix-quarantined-files.txt 2008-12-15 17:48:44
Avant-CF: 223 888 855 040 octets libres
Après-CF: 223,905,169,408 octets libres
295 --- E O F --- 2008-12-11 13:08:05