oups en fait le rapport etait bien là
ComboFix 09-04-25.A1 - Garcia 25/04/2009 13:35:12.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.191.49 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\TEMP\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINNT\system32\AutoRun.inf
C:\WINNT\system32\dumphive.exe
C:\WINNT\system32\kr_done1
C:\WINNT\system32\SrchSTS.exe
C:\WINNT\system32\tmp.reg
C:\WINNT\system32\VCCLSID.exe
C:\WINNT\system32\WS2Fix.exe
C:\WINNT\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
-------\Service_IAS
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-25 au 2009-4-25 ))))))))))))))))))))))))))))))))))))
.
2009-04-25 11:44:47 . 2009-04-25 11:44:47 87720 ----a-w C:\Documents and Settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 11:44:01 . 2009-04-25 11:44:01 0 d-----w C:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft
2009-04-22 16:05:11 . 2009-04-22 16:05:11 244 ---ha-w C:\sqmnoopt02.sqm
2009-04-22 16:05:11 . 2009-04-22 16:05:11 232 ---ha-w C:\sqmdata02.sqm
2009-04-19 16:41:44 . 2009-04-19 16:41:44 38468 ----a-w C:\WINNT\Garcia008.acl
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 10:46:44 . 2007-08-13 14:53:05 0 d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2009-04-25 08:19:04 . 2009-04-25 08:19:04 0 d-----w C:\Program Files\Trend Micro
2009-04-13 14:14:20 . 1999-12-15 22:00:00 50088 ----a-w C:\WINNT\system32\perfc00C.dat
2009-04-13 14:14:20 . 1999-12-15 22:00:00 374070 ----a-w C:\WINNT\system32\perfh00C.dat
2009-03-23 08:15:03 . 2008-10-11 14:38:49 0 d-----w C:\Program Files\Lexmark X1100 Series
2006-07-14 18:26:58 . 2006-07-14 18:22:20 93663 --sha-w C:\Program Files\Fichiers communs\Y1220OU.exe
2006-03-22 10:48:40 . 2006-03-22 10:48:39 6690 ----a-w C:\Program Files\soso.MTP
2002-12-19 21:05:16 . 2001-04-19 00:57:15 271 --sha-w C:\Program Files\desktop.ini
2002-12-19 21:05:16 . 2001-04-19 00:57:15 22115 ---ha-w C:\Program Files\folder.htt
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" - C:\WINNT\system32\internat.exe [1999-12-15 22:00:00 20752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Iomega Startup Options"="C:\Program Files\Iomega\Common\ImgStart.exe" [2000-06-02 09:57:38 32768]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2000-06-13 06:48:58 36864]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-10-11 10:44:59 266497]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00:36 132496]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42:04 267064]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 20:34:40 49152]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 21:37:20 413696]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 08:48:56 57344]
"Synchronization Manager"="mobsync.exe" - C:\WINNT\system32\mobsync.exe [2004-08-20 00:09:56 144384]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" - C:\WINNT\system32\internat.exe [1999-12-15 22:00:00 20752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [2004-08-20 00:09:54 218624]
"tscuninstall"="C:\WINNT\system32\tscupgrd.exe" [2004-08-19 23:52:06 44544]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage d'Office.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-9-18 51984]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Recherche acc‚l‚r‚e.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-9-18 111376]
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [1999-8-6 53317]
Utilitaire r‚seau pour SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe [2006-3-5 835584]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave2"= serwvdrv.dll
"aux"= mmdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Kodak software updater.lnk
backup=C:\WINNT\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINNT\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logiciel Kodak EasyShare.lnk
backup=C:\WINNT\pss\Logiciel Kodak EasyShare.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
R3 ctlsb16;Pilote Creative SB16/AWE32/AWE64 (WDM);C:\WINNT\system32\drivers\ctlsb16.sys [2001-08-17 19:19:20 96256]
R3 KProcCheck;KProcCheck; [x]
R3 laguna;laguna;C:\WINNT\system32\DRIVERS\cl546xm.sys [2001-08-17 20:57:36 248064]
R3 mga64;mga64;C:\WINNT\system32\DRIVERS\mga64m.sys [1999-11-30 00:47:48 150960]
R3 NtApm;Pilote d'interface NT APM/hérité;C:\WINNT\system32\DRIVERS\NtApm.sys [2001-08-28 11:00:00 9472]
R3 scsiscan;Pilote de scanneur SCSI; [x]
R3 ZDCndis5;ZDCndis5 Protocol Driver; [x]
R4 ppa;Pilote de filtre de port parallèle Iomega;C:\WINNT\system32\DRIVERS\ppa.sys [2001-08-17 20:53:22 17792]
S3 G200;G200;C:\WINNT\system32\DRIVERS\G200m.sys [2001-08-23 16:18:04 320512]
S3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;C:\WINNT\system32\DRIVERS\WlanUZXP.sys [2005-07-13 15:37:18 260608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contenu du dossier 'Tâches planifiées'
2009-03-30 C:\WINNT\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 12:15:18 . 2007-08-29 13:57:52]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-SandIcon - C:\ImageMate CompactFlash USB\SandIcon.Exe
SafeBoot-sglfb.sys
SafeBoot-tga.sys
.
------- Examen supplémentaire -------
.
mStart Page = about:blank
DPF: DirectAnimation Java Classes -
file://C:\WINNT\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://C:\WINNT\Java\classes\xmldso.cab
.