bonsoir rubised
En ce qui concerne mon antivirus, je l'avais désinstallé, mais je l'ai réinstallé aujourd'hui. j'utilise gdata
voici le rapport combofix, je te posterai celui de bitdefender dés que possible:
ComboFix 09-10-25.02 - Thierry 26/10/2009 21:45.3.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.33.1036.18.3327.2310 [GMT 1:00]
Lancé depuis: c:\users\Thierry\Desktop\ComboFix.exe
AV: G Data AntiVirus 2010 *On-access scanning disabled* (Updated) {71310606-6F3B-49F2-9A81-8315AA75FBB3}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-26 au 2009-10-26 ))))))))))))))))))))))))))))))))))))
.
2009-10-26 20:52 . 2009-10-26 20:52 -------- d-----w- c:\users\Thierry\AppData\Local\temp
2009-10-26 20:52 . 2009-10-26 20:52 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-10-26 20:52 . 2009-10-26 20:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-26 20:45 . 2008-06-26 12:01 21560 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-10-26 12:13 . 2009-10-26 12:13 34248 ----a-w- c:\windows\system32\drivers\HookCentre.sys
2009-10-26 12:12 . 2009-10-26 12:12 27720 ----a-w- c:\windows\system32\drivers\GDBehave.sys
2009-10-26 12:11 . 2009-10-26 12:12 -------- d-----w- c:\program files\Common Files\G DATA
2009-10-26 12:11 . 2009-10-26 12:11 -------- d-----w- c:\program files\G Data
2009-10-25 22:22 . 2009-10-25 22:37 -------- d-----w- C:\UsbFix
2009-10-24 09:09 . 2009-10-24 09:09 -------- d-----w- c:\users\Thierry\AppData\Roaming\Malwarebytes
2009-10-24 09:09 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-24 09:09 . 2009-10-24 09:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-24 09:09 . 2009-10-24 09:09 -------- d-----w- c:\programdata\Malwarebytes
2009-10-24 09:09 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-23 14:30 . 2009-10-24 09:20 -------- d-----w- C:\FindyKill
2009-10-23 08:26 . 2009-08-05 14:28 3502152 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-23 08:26 . 2009-08-05 14:28 3467864 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-22 22:16 . 2009-10-22 22:16 -------- d-----w- C:\%APPDATA%
2009-10-22 15:35 . 2009-10-22 15:35 -------- d-----w- c:\program files\Alwil Software
2009-10-22 14:45 . 2009-10-22 14:45 -------- d-----w- c:\windows\RestoreSafeDeleted
2009-10-22 14:44 . 2009-10-22 14:44 2 --shatr- c:\windows\winstart.bat
2009-10-22 14:43 . 2009-10-22 14:43 -------- d-----w- c:\program files\Greatis
2009-10-22 08:29 . 2009-10-22 22:16 -------- d-----w- c:\program files\trend micro
2009-10-22 08:29 . 2009-10-22 13:06 -------- d-----w- C:\rsit
2009-10-20 07:00 . 2009-08-31 15:16 428032 ----a-w- c:\windows\system32\EncDec.dll
2009-10-20 07:00 . 2009-08-31 15:21 292352 ----a-w- c:\windows\system32\psisdecd.dll
2009-10-20 07:00 . 2009-08-31 15:17 1244672 ----a-w- c:\windows\system32\mcmde.dll
2009-10-20 06:59 . 2009-09-10 17:38 216576 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-20 06:58 . 2009-09-04 12:38 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-20 06:58 . 2009-09-14 09:50 130048 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-20 06:56 . 2009-04-02 11:50 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-16 17:47 . 2009-10-22 18:40 -------- d-----w- c:\windows\BDOSCAN8
2009-10-16 17:18 . 2009-10-24 14:26 -------- d-----w- c:\users\Thierry\.housecall6.6
2009-10-16 16:16 . 2009-10-16 17:56 -------- d-----w- c:\users\Thierry\AppData\Roaming\HouseCall 6.6
2009-10-16 16:16 . 2009-10-16 16:16 -------- d-----w- c:\windows\Sun
2009-10-13 13:55 . 2009-10-13 13:55 -------- d-----w- c:\programdata\BSD
2009-10-13 13:54 . 2009-10-13 13:55 -------- d-----w- c:\users\Thierry\AppData\Roaming\BSD Concept
2009-10-13 13:51 . 2009-10-13 13:51 -------- d-----w- c:\programdata\BSD Concept
2009-10-13 13:51 . 2009-10-13 13:51 -------- d-----w- c:\program files\BSD Concept
2009-10-13 12:48 . 2009-10-13 12:48 -------- d-----w- C:\Programs
2009-10-13 12:48 . 2009-10-13 12:48 -------- d-----w- c:\temp\3FR52OBV
2009-10-13 12:48 . 2009-10-13 12:48 -------- d-----w- C:\Temp
2009-10-05 11:38 . 2009-10-05 11:38 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-03 09:13 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-03 09:05 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-03 09:05 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-03 09:05 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-03 09:05 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-03 09:05 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-03 09:05 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-03 09:05 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-03 09:05 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-03 09:05 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-01 14:19 . 2009-10-01 14:19 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-01 14:19 . 2009-10-01 14:19 -------- d-sh--w- c:\windows\system32\%APPDATA%
2009-10-01 13:40 . 2009-10-03 14:39 -------- d-----w- c:\program files\Microsoft Works
2009-10-01 13:39 . 2009-10-01 13:39 -------- d-----w- c:\program files\Microsoft.NET
2009-10-01 13:36 . 2009-10-01 13:36 -------- d-----w- c:\users\Thierry\AppData\Local\Microsoft Help
2009-10-01 13:36 . 2009-10-20 07:06 -------- d-----w- c:\programdata\Microsoft Help
2009-10-01 13:34 . 2009-10-01 13:34 -------- d-----r- C:\MSOCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 20:40 . 2008-06-26 20:09 699984 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-26 20:40 . 2008-06-26 20:09 121814 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-26 13:51 . 2009-03-30 16:59 -------- d-----w- c:\programdata\Google Updater
2009-10-26 13:30 . 2009-08-25 21:59 -------- d-----w- c:\users\Thierry\AppData\Roaming\vlc
2009-10-26 12:48 . 2009-04-28 07:43 -------- d-----w- c:\program files\Microsoft
2009-10-26 12:38 . 2009-06-19 13:35 29992 ----a-w- c:\windows\system32\drivers\GRD.sys
2009-10-26 12:34 . 2009-06-19 12:57 40904 ----a-w- c:\windows\system32\drivers\gdwfpcd32.sys
2009-10-26 12:19 . 2009-06-19 12:58 -------- d-----w- c:\programdata\G DATA
2009-10-26 12:13 . 2009-06-19 12:58 53320 ----a-w- c:\windows\system32\drivers\MiniIcpt.sys
2009-10-26 12:07 . 2009-02-05 21:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-22 13:24 . 2009-09-25 09:29 -------- d-----w- c:\program files\vghd
2009-10-22 13:01 . 2009-09-25 09:29 -------- d-----w- c:\users\Thierry\AppData\Roaming\vghd
2009-10-20 07:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-17 15:38 . 2009-02-27 19:55 -------- d-----w- c:\users\Thierry\AppData\Roaming\TeraCopy
2009-10-16 13:20 . 2008-06-26 12:32 -------- d-----w- c:\programdata\NVIDIA
2009-10-13 13:08 . 2008-07-28 14:54 -------- d-----w- c:\users\Thierry\AppData\Roaming\Azureus
2009-10-13 12:54 . 2009-08-30 21:09 -------- d-----w- c:\users\Thierry\AppData\Roaming\BitTorrent
2009-10-12 12:08 . 2008-07-28 16:45 -------- d-----w- c:\users\Thierry\AppData\Roaming\OpenOffice.org2
2009-10-07 12:47 . 2008-09-18 21:30 -------- d-----w- c:\users\Thierry\AppData\Roaming\MAGIX
2009-10-03 17:15 . 2008-06-26 10:48 166312 ----a-w- c:\users\Thierry\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-25 13:28 . 2008-08-02 23:56 -------- d-----w- c:\programdata\ma-config.com
2009-09-25 13:28 . 2008-08-02 23:56 -------- d-----w- c:\program files\ma-config.com
2009-09-25 09:29 . 2009-09-25 09:29 152904 ----a-w- c:\windows\system32\vghd.scr
2009-09-25 08:36 . 2008-08-01 14:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-24 13:27 . 2009-09-24 13:27 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2009-09-17 20:07 . 2009-01-29 20:53 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-15 12:31 . 2009-09-13 14:19 -------- d-----w- c:\users\Thierry\AppData\Roaming\deluge
2009-09-13 17:48 . 2009-09-13 17:48 -------- d-----w- c:\program files\Common Files\Apple
2009-09-13 17:47 . 2009-09-13 17:47 -------- d-----w- c:\programdata\Apple Computer
2009-09-13 13:19 . 2009-06-14 07:00 -------- d-----w- c:\program files\Vuze
2009-09-11 11:24 . 2009-09-11 11:24 -------- d-----w- c:\users\Thierry\AppData\Roaming\Todae
2009-09-10 19:02 . 2008-10-03 08:22 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-31 22:32 . 2009-01-10 23:29 -------- d-----w- c:\users\Thierry\AppData\Roaming\dvdcss
2009-08-29 03:41 . 2009-09-02 16:43 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-08-29 03:40 . 2009-09-02 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 23:31 . 2009-09-02 16:43 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 05:22 . 2009-10-26 12:46 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-26 12:46 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-26 12:46 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-26 12:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-25 17:36 . 2009-06-14 13:16 48461 ----a-w- c:\programdata\nvModes.dat
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-16 22:36 . 2009-07-15 10:50 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-16 22:35 . 2009-07-15 10:49 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-08-16 00:32 . 2009-09-10 07:55 214104 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-15 23:58 . 2009-09-10 07:55 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-15 23:54 . 2009-09-10 07:55 416768 ----a-w- c:\windows\system32\IKEEXT.DLL
2009-08-15 23:54 . 2009-09-10 07:55 543232 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2009-08-15 23:53 . 2009-09-10 07:55 317440 ----a-w- c:\windows\system32\BFE.DLL
2009-08-15 21:30 . 2009-09-10 07:55 816640 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-15 21:30 . 2009-09-10 07:55 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-08-15 21:29 . 2009-09-10 07:55 85504 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2009-08-14 16:40 . 2009-09-10 07:55 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-10 07:55 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-10 07:55 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-10 07:55 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-10 07:55 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-10 07:55 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-10 07:55 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-10 07:55 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-10 07:55 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-03 13:07 . 2009-08-03 13:07 403816 ----a-w- c:\windows\system32\OGACheckControl.DLL
2009-08-03 13:07 . 2009-08-03 13:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 13:07 . 2009-08-03 13:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2006-05-03 09:06 . 2009-04-02 13:24 163328 --sh--r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 . 2009-04-02 13:24 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 . 2009-04-02 13:24 216064 --sh--r- c:\windows\System32\nbDX.dll
2007-08-01 14:22 . 2007-08-01 14:22 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot_2009-10-26_20.32.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-26 12:32 . 2009-10-26 20:36 13862 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-897275449-672298967-433210542-1000_UserData.bin
- 2009-10-26 20:17 . 2009-10-26 20:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-10-26 20:17 . 2009-10-26 20:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-10-26 20:17 . 2009-10-26 20:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-10-26 20:17 . 2009-10-26 20:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 13:05 . 2009-10-26 20:36 120308 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2006-11-02 10:33 . 2009-10-26 20:25 618272 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-10-26 20:40 618272 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-10-26 20:40 107416 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-10-26 20:25 107416 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-06-26 1232896]
"PeerGuardian"="d:\logiciels\Téléchargement\PeerGuardian2\pg2.exe" [2009-10-22 1421824]
"DAEMON Tools Lite"="d:\logiciels\Utilitaires\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-06-26 1006264]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-11-06 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-06 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-06 81920]
"QuickTime Task"="d:\logiciels\Multimédia\Vidéo\QuickTime\QTTask.exe" [2009-09-04 417792]
"Adobe Reader Speed Launcher"="d:\logiciels\Utilitaires\Acrobat 9\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"G DATA AntiVirus Trayapplication"="c:\program files\G Data\AntiVirus\AVKTray\AVKTray.exe" [2009-09-07 925768]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"UnHackMe"="c:\progra~1\Greatis\REGRUN~1\UnHackMe.exe" [BU]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-13 113664]
NkbMonitor.exe.lnk - d:\logiciels\Multim‚dia\Photo\Picture Project\NkbMonitor.exe [2008-8-1 118784]
Privoxy.lnk.disabled [2009-4-27 880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^StupAssist.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\StupAssist.lnk
backup=c:\windows\pss\StupAssist.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Thierry^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Thierry\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="d:\logiciels\Utilitaires\Acrobat 9\Reader\Reader_sl.exe"
"NBKeyScan"="d:\logiciels\Multimédia\Gravure\Nero 8\Nero BackItUp\NBKeyScan.exe"
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"QuickTime Task"="d:\logiciels\Multimédia\Vidéo\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-897275449-672298967-433210542-1000]
"EnableNotificationsRef"=dword:00000001
R0 GDBehave;GDBehave;c:\windows\System32\drivers\GDBehave.sys [26/10/2009 13:12 27720]
R1 gdwfpcd;G DATA WFP CD;c:\windows\System32\drivers\gdwfpcd32.sys [19/06/2009 13:57 40904]
R1 GRD;G Data Rootkit Detector Driver;c:\windows\System32\drivers\GRD.sys [19/06/2009 14:35 29992]
R2 AVKProxy;G Data AntiVirus Proxy;c:\program files\Common Files\G DATA\AVKProxy\AVKProxy.exe [12/08/2009 09:04 1046088]
R2 AVKService;Planificateur G Data;c:\program files\G Data\AntiVirus\AVK\AVKService.exe [12/08/2009 09:04 397896]
R2 AVKWCtl;G Data Gardien;c:\program files\G Data\AntiVirus\AVK\AVKWCtl.exe [30/07/2009 12:33 1244760]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [15/07/2009 11:50 604488]
R3 fhlppppoe;PPPOE/ADSL miniport;c:\windows\System32\drivers\fhlpppoe.sys [27/07/2008 14:20 49200]
R3 GDMnIcpt;GDMnIcpt;c:\windows\System32\drivers\MiniIcpt.sys [19/06/2009 13:58 53320]
R3 GDScan;G Data Scanner;c:\program files\Common Files\G DATA\GDScan\GDScan.exe [27/07/2009 03:03 300616]
R3 HookCentre;HookCentre;c:\windows\System32\drivers\HookCentre.sys [26/10/2009 13:13 34248]
S2 gupdate1c9b15936aeb9e0;Service Google Update (gupdate1c9b15936aeb9e0);c:\program files\Google\Update\GoogleUpdate.exe [30/03/2009 18:01 133104]
S2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 16:28 1533808]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;d:\logiciels\Multimédia\Vidéo\Common\Database\bin\fbserver.exe [01/09/2008 13:30 1527900]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [28/04/2009 08:48 55280]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 17:08 533360]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [19/09/2008 23:41 544768]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mbr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-10-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-30 16:59]
2009-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-30 17:01]
2009-10-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-30 17:01]
2009-10-26 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:00]
2009-10-26 c:\windows\Tasks\User_Feed_Synchronization-{E93FDD29-8461-46EF-9586-D0A493ED9D72}.job
- c:\windows\system32\msfeedssync.exe [2009-10-26 03:41]
.
.
------- Examen supplémentaire -------
.
uDefault_Search_URL =
hxxp://www.google.com/ie
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Thierry\AppData\Roaming\Mozilla\Firefox\Profiles\8mhxcle5.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - DataLife Engine Demo
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF - component: d:\logiciels\Internet\Firefox 3\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\AvkWebFilterFF.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: d:\logiciels\Internet\Firefox 3\plugins\NPAskSBr.dll
FF - plugin: d:\logiciels\Utilitaires\Acrobat 9\Reader\browser\nppdf32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-26 21:52
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.032"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.arw"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.bay"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.bw"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.cr2"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.crw"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.cs1"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.dcr"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.dcx"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.djv"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.djvu"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.dng"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.eps"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.erf"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.fff"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.fpx"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.hdr"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.icn"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.ilbm"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.int"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.inta"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.iw4"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.j2c"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.j2k"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.jp2"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.jpc"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.jpk"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.jpx"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.mef"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.mos"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.mrw"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.orf"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pct"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pef"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pgm"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pic"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pict"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pix"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.psp"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.pspimage"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.raf"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.ras"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.raw"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.rgb"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.rgba"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.rsb"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.sgi"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.sr2"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.srf"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.xif"
[HKEY_USERS\S-1-5-21-897275449-672298967-433210542-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ACDSee 10.0.xpm"
.
Heure de fin: 2009-10-26 21:54
ComboFix-quarantined-files.txt 2009-10-26 20:54
Avant-CF: 211 879 976 960 octets libres
Après-CF: 211 835 547 648 octets libres
- - End Of File - - A14188F1E1BDC5B516BD7BE72E0606B1