merci pour votre reponse, voila le rapport de combofix :
ComboFix 08-05-12.1 - ETOILE 2008-05-13 15:06:39.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1704 [GMT 2:00]
Endroit: C:\Users\ETOILE\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\msetup
C:\Windows\msetup\BASW-00500A09\Install.exe
C:\Windows\msetup\BASW-00500A09\install.ini
C:\Windows\msetup\BASW-00500A09\setup.exe
C:\Windows\msetup\BASW-00500A09\SWDesc.txt
C:\Windows\msetup\BASW-00503A34\data1.cab
C:\Windows\msetup\BASW-00503A34\data1.hdr
C:\Windows\msetup\BASW-00503A34\data2.cab
C:\Windows\msetup\BASW-00503A34\engine32.cab
C:\Windows\msetup\BASW-00503A34\layout.bin
C:\Windows\msetup\BASW-00503A34\mpg4c32.dll
C:\Windows\msetup\BASW-00503A34\msgsm32.acm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Click.wav
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_chs_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_cht_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_deu_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_eng_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_esp_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_fra_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_ita_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_kor_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_ptg_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_rus_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\Help\PlayCamera_ukr_s.chm
C:\Windows\msetup\BASW-00503A34\PlayCamera\HookDllPS2.dll
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\Back_Big.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\Back_Small.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbCancel.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbHelp.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbOk.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbOpen.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbPreviewOff.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbPreviewOn.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbRecordOff.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbRecordOn.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\gbSnap.bmp
C:\Windows\msetup\BASW-00503A34\PlayCamera\Images\PlayCamera.ico
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_chs.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_cht.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_deu.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_eng.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_esp.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_fra.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_ita.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_kor.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_ptg.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_rus.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\Language\PlayCamera_ukr.txt
C:\Windows\msetup\BASW-00503A34\PlayCamera\PlayCamera.exe
C:\Windows\msetup\BASW-00503A34\PlayCamera\SSHook.dll
C:\Windows\msetup\BASW-00503A34\PlayCamera\Uninst.ico
C:\Windows\msetup\BASW-00503A34\setup.exe
C:\Windows\msetup\BASW-00503A34\setup.ibt
C:\Windows\msetup\BASW-00503A34\setup.ini
C:\Windows\msetup\BASW-00503A34\setup.iss
C:\Windows\msetup\BASW-00503A34\SWDesc.txt
C:\Windows\msetup\MSetup.exe
C:\Windows\msetup\MSetupLog.log
C:\Windows\system32\HiiiQqss.ini
C:\Windows\System32\HiiiQqss.ini2
C:\Windows\system32\ssqQiiiH.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-13 to 2008-05-13 ))))))))))))))))))))))))))))))))))))
.
2008-05-12 23:11 . 2008-05-12 23:11 <REP> d-------- C:\Windows\System32\Kaspersky Lab
2008-05-12 22:04 . 2008-05-12 22:04 2,112 --a------ C:\Windows\System32\utheflpr.exe
2008-05-12 19:57 . 2008-05-13 15:09 5,206 --a------ C:\Windows\System32\PerfStringBackup.TMP
2008-05-12 19:46 . 2008-05-12 19:46 <REP> d-------- C:\Users\ETOILE\AppData\Roaming\Malwarebytes
2008-05-12 19:46 . 2008-05-12 19:46 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-05-12 19:46 . 2008-05-12 19:46 <REP> d-------- C:\ProgramData\Malwarebytes
2008-05-12 19:46 . 2008-05-12 19:46 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-12 19:46 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-12 19:46 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-12 16:00 . 2008-05-12 16:00 <REP> d-------- C:\Program Files\Trend Micro
2008-05-12 01:18 . 2008-05-12 18:44 413 --a------ C:\Windows\wininit.ini
2008-05-12 01:05 . 2008-05-12 01:35 524,288 --ahs---- C:\Users\Public\NTUSER.DAT{b8ffeea6-1faa-11dd-9f1a-0013773c3db0}.TMContainer00000000000000000002.regtrans-ms
2008-05-12 01:05 . 2008-05-12 01:35 524,288 --ahs---- C:\Users\Public\NTUSER.DAT{b8ffeea6-1faa-11dd-9f1a-0013773c3db0}.TMContainer00000000000000000001.regtrans-ms
2008-05-12 01:05 . 2008-05-12 01:35 65,536 --ahs---- C:\Users\Public\NTUSER.DAT{b8ffeea6-1faa-11dd-9f1a-0013773c3db0}.TM.blf
2008-05-11 01:46 . 2008-05-11 01:46 <REP> d-------- C:\Users\All Users\Avira
2008-05-11 01:46 . 2008-05-11 01:46 <REP> d-------- C:\ProgramData\Avira
2008-05-11 01:46 . 2008-05-11 01:46 <REP> d-------- C:\Program Files\Avira
2008-05-11 01:23 . 2008-05-11 01:21 102,664 --a------ C:\Windows\System32\drivers\tmcomm.sys
2008-05-11 00:27 . 2006-12-22 09:02 170,408 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-05-11 00:27 . 2006-07-24 03:50 125,744 --a------ C:\Windows\System32\MSSTDFMT.DLL
2008-05-11 00:27 . 2007-01-09 09:44 117,848 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-05-11 00:27 . 2006-11-02 11:45 99,840 --a------ C:\Windows\System32\poqexec.exe
2008-05-11 00:27 . 2006-12-22 09:02 71,496 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-05-11 00:27 . 2006-07-24 03:50 47,920 --a------ C:\Windows\System32\VBAME.DLL
2008-05-11 00:27 . 2006-07-24 03:50 39,728 --a------ C:\Windows\System32\SCP32.DLL
2008-05-11 00:27 . 2006-12-22 09:02 37,480 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-05-11 00:27 . 2006-12-22 09:02 34,184 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-05-11 00:27 . 2006-12-22 09:02 32,008 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-05-10 21:38 . 2008-05-10 21:45 <REP> d-a------ C:\Users\All Users\TEMP
2008-05-10 21:38 . 2008-05-10 21:45 <REP> d-a------ C:\ProgramData\TEMP
2008-05-10 14:01 . 2008-05-10 14:26 524,288 --ahs---- C:\Users\ETOILE\NTUSER.DAT{a856573f-1e86-11dd-ba3d-0013773c3db0}.TMContainer00000000000000000002.regtrans-ms
2008-05-10 14:01 . 2008-05-10 14:26 524,288 --ahs---- C:\Users\ETOILE\NTUSER.DAT{a856573f-1e86-11dd-ba3d-0013773c3db0}.TMContainer00000000000000000001.regtrans-ms
2008-05-10 14:01 . 2008-05-10 14:26 65,536 --ahs---- C:\Users\ETOILE\NTUSER.DAT{a856573f-1e86-11dd-ba3d-0013773c3db0}.TM.blf
2008-05-10 00:51 . 2002-07-08 00:14 1,294,336 --a------ C:\Windows\System32\vorbis.acm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-12 22:26 --------- d-----w C:\ProgramData\Google Updater
2008-05-11 21:16 --------- d-----w C:\Program Files\Windows Mail
2008-05-11 00:54 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-05-11 00:08 27,430 ----a-w C:\Users\ETOILE\AppData\Roaming\nvModes.dat
2008-05-10 13:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 13:34 --------- d-----w C:\Program Files\Samsung
2008-05-09 23:22 --------- d-----w C:\Program Files\Image-Line
2008-05-09 23:21 --------- d-----w C:\Program Files\VstPlugins
2008-03-21 12:44 --------- d-----w C:\Program Files\Windows Live
2008-03-21 12:43 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-21 12:42 --------- d-----w C:\ProgramData\WLInstaller
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-14 02:06 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 02:04 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 02:04 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 02:04 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 02:04 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 02:04 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 02:03 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 02:03 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 02:03 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 02:03 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-14 02:03 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 02:03 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 02:03 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2007-10-26 21:13 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{be7c19fa-edb9-4f1b-b8ed-657eb1fef2bb}]
C:\Windows\system32\ieieobfu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 04:01 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-26 22:27 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-02 05:23 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 08:50 4399104 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-06 11:17 839680]
"IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-05-08 10:45 33048]
"Play AVStation TV Scheduler"="C:\Program Files\Samsung\Play AVStation\TvScheduler.exe" [2007-01-08 11:09 73728]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-22 15:35 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-22 15:35 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-22 15:35 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 21:16 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 19:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-06 20:36 185632]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"NoHotStart"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-902405355-657265515-67507742-1003]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A958CED9-6ACE-4CB5-961E-785577364504}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{58B837D2-C454-4766-82B2-23216A9CDE99}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{8319FA73-52B4-4FD0-8149-9C64A2DA4118}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{6F8CDB03-F649-4CA4-93BE-CB882D859BDB}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"{AF504F33-BC2C-4732-A13C-DFAA519F4A38}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{9F42E7E6-C8B3-4358-A917-9EF30E52743D}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{036E226F-30C3-4D21-B40B-C0708774CAE9}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{E29D6E7D-B008-4EF5-BE4C-DA0B43BE7FE2}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{BE493BC0-897D-4CFC-BEAF-CD67C05FE61F}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 iaNvStor;Intel(R) Turbo Memory Technology NAND Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-05-04 04:21]
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:46]
R2 KMDFMEMIO;SAMSUNG Kernel Driver;C:\Windows\system32\DRIVERS\kmdfmemio.sys [2007-07-02 05:08]
R2 SQLWriter;Enregistreur VSS SQL Server;"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-15 02:12]
S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2006-12-20 04:08]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2006-12-20 04:04]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-12-20 04:07]
S3 MBAMCatchMe;MBAMCatchMe;C:\Windows\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
S3 mod7700;DiBcom DIB7700 based TV tuner device;C:\Windows\system32\Drivers\dvb7700all.sys [2007-04-19 08:02]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
S3 NETw2v32;Intel(R) PRO/Wireless 2915ABG Network Connection Driver for Windows Vista;C:\Windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 09:30]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-12 22:48:24 C:\Windows\Tasks\User_Feed_Synchronization-{E3D54A45-9D01-4DAF-8D99-8C154F0DC94D}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-13 15:11:39
Windows 6.0.6000 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Windows\System32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-13 15:14:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-13 13:14:11
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 84,831,141,888 octets libres
243 --- E O F --- 2008-05-11 00:59:29
et le hijack this :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:27:04, on 13/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Samsung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: {bb2fef1b-e756-de8b-b1f4-9bdeaf91c7eb} - {be7c19fa-edb9-4f1b-b8ed-657eb1fef2bb} - C:\Windows\system32\ieieobfu.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
O4 - HKLM\..\Run: [Play AVStation TV Scheduler] C:\Program Files\Samsung\Play AVStation\TvScheduler.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
--
End of file - 6109 bytes
merci encore de votre aide