salut
voila le rapport
ComboFix 08-10-21.04 - HP_Propriétaire 2008-10-22 15:25:26.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.235 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\HP_Propriétaire\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\HP_Propriétaire\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
K:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-22 au 2008-10-22 ))))))))))))))))))))))))))))))))))))
.
2008-10-20 01:41 . 2008-10-20 01:43 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\vlc
2008-10-20 01:12 . 2008-10-20 01:12 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-20 01:11 . 2005-01-01 12:21 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-10-20 01:11 . 2005-01-01 11:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-20 01:11 . 2005-01-01 11:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-20 01:11 . 2008-10-11 02:43 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-20 01:11 . 2008-10-11 02:42 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-10-20 01:11 . 2008-10-11 02:42 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-20 01:11 . 2008-10-10 18:59 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-10-20 01:11 . 2008-10-20 13:38 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-10-20 01:11 . 2005-01-01 14:07 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-10-20 01:11 . 2005-01-01 15:41 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2008-10-20 01:11 . 2005-01-01 12:12 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intervideo
2008-10-20 01:11 . 2005-01-01 12:20 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2008-10-20 01:11 . 2008-10-20 01:11 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-20 01:06 . 2008-10-20 01:06 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-20 01:06 . 2008-10-20 01:06 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-20 01:06 . 2008-10-20 01:06 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Malwarebytes
2008-10-20 01:05 . 2008-10-20 01:05 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-20 01:05 . 2008-10-20 01:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-20 01:05 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-20 01:05 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-18 02:30 . 2008-10-18 02:30 0 --a------ C:\WINDOWS\ODBC.INI
2008-10-15 15:52 . 2008-10-15 16:17 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-10-15 15:32 . 2008-10-16 15:40 <REP> d-------- C:\Program Files\ewido anti-spyware 4.0
2008-10-15 15:11 . 2008-10-19 16:18 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\dvdcss
2008-10-15 15:11 . 2008-10-19 16:18 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\dvdcss
2008-10-15 15:11 . 2008-10-19 16:18 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\dvdcss
2008-10-15 13:40 . 2008-09-15 17:26 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 13:40 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 13:39 . 2008-08-14 15:23 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 13:39 . 2008-08-14 15:23 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 13:39 . 2008-08-14 15:23 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 13:39 . 2008-08-14 15:23 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 23:30 . 2008-10-14 23:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\AdobeUM
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\AdobeUM
2008-10-12 19:27 . 2008-10-12 19:27 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\AdobeUM
2008-10-12 17:25 . 2008-10-15 17:47 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-10-12 16:36 . 2008-10-12 16:36 <REP> d-------- C:\Program Files\MSXML 4.0
2008-10-12 16:36 . 2008-10-12 16:36 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-12 02:57 . 2008-10-10 19:49 298 -rahs---- C:\boot.old
2008-10-11 19:32 . 2008-10-18 02:32 <REP> d-------- C:\Program Files\Symantec
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Program Files\ma-config.com
2008-10-11 18:48 . 2008-10-11 18:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-10-11 18:35 . 2008-04-14 04:34 92,160 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-10-11 18:35 . 2008-04-14 04:34 92,160 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-10-11 18:35 . 2008-04-14 04:34 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-10-11 18:35 . 2008-04-14 04:34 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-10-11 18:35 . 2008-04-14 04:33 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-11 18:35 . 2008-04-14 04:33 54,784 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-10-11 18:35 . 2008-04-14 04:34 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-10-11 18:35 . 2008-04-14 04:34 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-10-11 18:31 . 2008-10-11 18:31 <REP> d-------- C:\SXS
2008-10-11 18:31 . 2004-01-21 03:26 360,448 --a------ C:\WINDOWS\system32\LVUI2RC.dll
2008-10-11 18:31 . 1998-11-13 13:16 308,224 --a------ C:\WINDOWS\IsUn040c.exe
2008-10-11 18:31 . 2004-01-21 03:14 271,360 --a------ C:\WINDOWS\system32\drivers\LV302AV.SYS
2008-10-11 18:31 . 2004-01-21 03:25 172,032 --a------ C:\WINDOWS\system32\lvcodec2.dll
2008-10-11 18:31 . 2004-01-21 03:24 135,214 --a------ C:\WINDOWS\system32\LVComS.exe
2008-10-11 18:31 . 2004-01-21 03:26 122,880 --a------ C:\WINDOWS\system32\LVUI2.dll
2008-10-11 18:31 . 2004-01-21 03:28 86,016 --a------ C:\WINDOWS\system32\lvcoinst.dll
2008-10-11 18:31 . 2004-01-21 03:24 57,344 --a------ C:\WINDOWS\system32\LVComC.dll
2008-10-11 18:31 . 2004-01-21 02:51 17,191 --a------ C:\WINDOWS\system32\lvcoinst.ini
2008-10-11 18:31 . 2004-01-21 03:16 12,080 --a------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-10-11 18:31 . 2004-01-21 03:14 5,915 --a------ C:\WINDOWS\system32\drivers\lv302af.sys
2008-10-11 18:30 . 2008-10-11 18:30 272 --a------ C:\WINDOWS\_delis32.ini
2008-10-11 17:19 . 2008-10-11 17:19 <REP> d-------- C:\Program Files\Fichiers communs\Labtec
2008-10-11 17:15 . 2008-10-11 17:15 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-10-11 17:13 . 2008-10-11 17:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-10-11 17:12 . 2008-10-11 17:12 <REP> d-------- C:\Program Files\Fichiers communs\Sonic Shared
2008-10-11 17:12 . 2008-10-11 17:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-10-11 17:11 . 2008-10-11 17:11 <REP> d-------- C:\Program Files\Fichiers communs\HP
2008-10-11 17:09 . 2008-10-11 17:09 <REP> d-------- C:\Program Files\Hewlett-Packard
2008-10-11 17:08 . 2005-03-08 07:52 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-10-11 17:08 . 2005-03-08 07:52 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-10-11 17:07 . 2005-03-15 22:36 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-10-11 17:07 . 2005-05-05 08:51 37,376 --a------ C:\WINDOWS\system32\hpz3l3xu.dll
2008-10-11 17:07 . 2005-03-08 07:52 21,744 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-10-11 17:07 . 2008-04-13 20:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-11 17:07 . 2008-04-13 20:45 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-11 17:04 . 2008-10-11 17:13 <REP> d-------- C:\Program Files\HP
2008-10-11 17:04 . 2008-04-13 20:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-11 17:04 . 2008-04-13 20:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-11 17:03 . 2008-10-11 17:14 90,398 --a------ C:\WINDOWS\hpoins06.dat
2008-10-11 17:03 . 2005-06-03 07:53 5,389 --------- C:\WINDOWS\hpomdl06.dat
2008-10-11 17:02 . 2008-10-11 17:16 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\HP
2008-10-11 17:02 . 2008-10-11 17:16 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\HP
2008-10-11 17:02 . 2008-10-11 17:16 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\HP
2008-10-11 16:39 . 2008-10-15 15:12 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\vlc
2008-10-11 16:39 . 2008-10-15 15:12 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\vlc
2008-10-11 16:39 . 2008-10-15 15:12 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\vlc
2008-10-11 02:45 . 2004-06-02 10:54 7,406 --a------ C:\WINDOWS\system32\doc.ico
2008-10-11 02:43 . 2008-10-10 19:05 <REP> d-------- C:\WINDOWS\I386
2008-10-11 02:37 . 2008-10-20 01:05 <REP> dr------- C:\Program Files
2008-10-11 02:37 . 2008-10-11 02:42 <REP> dr------- C:\Documents and Settings\Default User\Menu Démarrer
2008-10-11 02:37 . 2008-10-11 17:11 <REP> dr------- C:\Documents and Settings\All Users\Menu Démarrer
2008-10-11 02:37 . 2008-10-10 20:04 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-10-11 02:36 . 2008-10-15 14:50 <REP> d----c--- C:\WINDOWS\system32\dllcache
2008-10-11 02:36 . 2008-10-11 02:42 <REP> dr------- C:\WINDOWS\system32\config\systemprofile\Menu Démarrer
2008-10-11 02:20 . 2004-08-04 21:00 4,399,505 --a--c--- C:\WINDOWS\system32\dllcache\nls302en.lex
2008-10-11 02:19 . 2004-08-04 21:00 3,440,660 --a------ C:\WINDOWS\system32\drivers\gm.dls
2008-10-11 02:18 . 2004-08-04 21:00 1,817,687 --a--c--- C:\WINDOWS\system32\dllcache\bckgres.dll
2008-10-11 02:14 . 2004-08-04 21:00 352,256 --a------ C:\WINDOWS\system32\drivers\atmuni.sys
2008-10-10 20:29 . 2008-10-10 20:29 <REP> d-------- C:\WINDOWS\system32\bits
2008-10-10 20:29 . 2008-10-10 20:29 <REP> d-------- C:\WINDOWS\l2schemas
2008-10-10 20:17 . 2008-10-10 20:17 <REP> d-------- C:\Program Files\Fichiers communs\LogiShared
2008-10-10 20:13 . 2008-10-10 20:13 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Logitech
2008-10-10 20:13 . 2008-10-10 20:13 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Logitech
2008-10-10 20:13 . 2008-10-10 20:13 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\Logitech
2008-10-10 20:11 . 2008-10-10 20:11 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-10 20:11 . 2008-10-10 20:11 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-10-10 20:11 . 2008-10-10 20:11 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2008-10-10 20:10 . 2007-04-11 15:33 1,419,024 --a------ C:\WINDOWS\system32\WdfCoInstaller01005.dll
2008-10-10 20:10 . 2007-04-23 04:00 163,840 --a------ C:\WINDOWS\system32\kemutb.dll
2008-10-10 20:10 . 2007-04-23 04:00 135,168 --a------ C:\WINDOWS\system32\KemUtil.dll
2008-10-10 20:10 . 2007-04-23 04:00 110,592 --a------ C:\WINDOWS\system32\KemWnd.dll
2008-10-10 20:10 . 2007-04-23 04:00 69,632 --a------ C:\WINDOWS\system32\KemXML.dll
2008-10-10 20:10 . 2007-04-11 15:32 56,080 --a------ C:\WINDOWS\KHALMNPR.Exe
2008-10-10 20:10 . 2007-04-11 15:32 36,112 --a------ C:\WINDOWS\system32\drivers\LMouFilt.Sys
2008-10-10 20:10 . 2007-04-11 15:32 34,832 --a------ C:\WINDOWS\system32\drivers\LHidFilt.Sys
2008-10-10 20:09 . 2008-10-11 17:19 <REP> d-------- C:\Program Files\Logitech
2008-10-10 20:09 . 2008-10-10 20:15 <REP> d-------- C:\Program Files\Fichiers communs\Logitech
2008-10-10 20:09 . 2008-10-10 20:09 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\InstallShield
2008-10-10 20:09 . 2008-10-10 20:09 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 14:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-10 17:07 --------- d-----w C:\Program Files\Easy Internet signup
2008-10-10 16:38 --------- d-----w C:\Program Files\Java
2008-10-10 16:24 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-10 16:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-10-10 16:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:23 2,191,232 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-10 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 155648]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 61440]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-09-29 4603904]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-10-10 917504]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"nwiz"="nwiz.exe" [2004-09-29 C:\WINDOWS\system32\nwiz.exe]
"SiSPower"="SiSPower.dll" [2004-09-24 C:\WINDOWS\system32\SiSPower.dll]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 C:\WINDOWS\AGRSMMSG.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 C:\WINDOWS\ALCXMNTR.EXE]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\WINDOWS\KHALMNPR.Exe]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-10-10 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.ffds"= C:\PROGRA~1\ffdshow\ffdshow.ax
"vidc.DIV3"= DivXc32.dll
"vidc.MJPG"= m3jpeg32.dll
"msacm.DivXa32"= DivXa32.acm
"vidc.div4"= DivXc32f.dll
"vidc.xvid"= xvid.dll
"vidc.dmb1"= m3jpeg32.dll
"vidc.jpeg"= m3jpeg32.dll
"VIDC.HFYU"= huffyuv.dll
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-09-02 191656]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-10-22 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job
- C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe [2005-04-22 17:36]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-VTTimer - VTTimer.exe
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page =
hxxp://home.neuf.fr/
R0 -: HKCU-Main,Default_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&(...)
R0 -: HKCU-Main,SearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R0 -: HKLM-Main,Search Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&(...)
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
C:\WINDOWS\Downloaded Program Files\oscan8.inf
C:\WINDOWS\bdoscandellang.ini
C:\WINDOWS\bdoscandel.exe
C:\WINDOWS\Downloaded Program Files\live.ini
C:\WINDOWS\Downloaded Program Files\scanoptions.tsi
C:\WINDOWS\Downloaded Program Files\lang.ini
C:\WINDOWS\Downloaded Program Files\ipsupd.dll
C:\WINDOWS\Downloaded Program Files\bdupd.dll
C:\WINDOWS\Downloaded Program Files\libfn.dll
C:\WINDOWS\Downloaded Program Files\bdcore.dll
C:\WINDOWS\Downloaded Program Files\oscan8.ocx
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetecti(...)
C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-22 15:27:21
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Heure de fin: 2008-10-22 15:28:50
ComboFix-quarantined-files.txt 2008-10-22 13:28:42
Avant-CF: 19 474 952 192 octets libres
Après-CF: 19,650,203,648 octets libres
269 --- E O F --- 2008-10-15 12:51:24