Voilà le rapport combofix
ComboFix 08-11-26.03 - YANNICK 2008-11-26 13:23:58.1 - NTFSx86
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
Manual Fix is required for restoring CommonStartup
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\aibohovd.ini
c:\windows\system32\aorrimok.ini
c:\windows\system32\btfmnkyh.ini
c:\windows\system32\bttgxsxl.ini
c:\windows\system32\burwwnrv.ini
c:\windows\system32\byXQHwTK.dll
c:\windows\system32\ccbeg.bak1
c:\windows\system32\ccbeg.bak2
c:\windows\system32\ccbeg.ini
c:\windows\system32\ccbeg.ini2
c:\windows\system32\ccbeg.tmp
c:\windows\system32\cfpypcvs.ini
c:\windows\system32\cgwtho.dll
c:\windows\system32\cxohsbnr.ini
c:\windows\system32\dgxtmqof.dll
c:\windows\system32\dianutgi.ini
c:\windows\system32\drivers\TDSSkxoe.sys
c:\windows\system32\edeeg.bak1
c:\windows\system32\edeeg.bak2
c:\windows\system32\edeeg.ini
c:\windows\system32\edeeg.ini2
c:\windows\system32\edeeg.tmp
c:\windows\system32\eiriyncw.ini
c:\windows\system32\ekdetjkw.ini
c:\windows\system32\emmjashj.ini
c:\windows\system32\emoewl.dll
c:\windows\system32\ffccuulo.ini
c:\windows\system32\fmlbhbww.ini
c:\windows\system32\henugucs.dll
c:\windows\system32\hgGvtUmK.dll
c:\windows\system32\hmfrvgbt.ini
c:\windows\system32\hmlrwtqt.ini
c:\windows\system32\hpfgsnhw.ini
c:\windows\system32\htqemtas.ini
c:\windows\system32\ibptbycn.ini
c:\windows\system32\ivkuiqcl.ini
c:\windows\system32\ivvhmcto.ini
c:\windows\system32\jaofqhaa.ini
c:\windows\system32\jbckipbf.ini
c:\windows\system32\kxjqbcge.ini
c:\windows\system32\lcqiukvi.dll
c:\windows\system32\lrygtmdg.ini
c:\windows\system32\lunjtvqv.ini
c:\windows\system32\mpqpwifj.ini
c:\windows\system32\mqqidlcd.ini
c:\windows\system32\MTBHRqss.ini
c:\windows\system32\MTBHRqss.ini2
c:\windows\system32\oqqwmotb.ini
c:\windows\system32\pcyvnteo.dll
c:\windows\system32\pfxdhebk.ini
c:\windows\system32\pgwfoidr.ini
c:\windows\system32\pnadgjax.ini
c:\windows\system32\pqoabhhf.ini
c:\windows\system32\qobowmli.ini
c:\windows\system32\qodreqak.ini
c:\windows\system32\qoujpnea.ini
c:\windows\system32\rdjsyniq.ini
c:\windows\system32\roqrjhfu.ini
c:\windows\system32\rrrbgdcm.ini
c:\windows\system32\rs32net.exe
c:\windows\system32\ruxgrwky.ini
c:\windows\system32\scuguneh.ini
c:\windows\system32\shmndqdc.ini
c:\windows\system32\sjeaasun.ini
c:\windows\system32\spugndyw.ini
c:\windows\system32\ssqRHBTM.dll
c:\windows\system32\swkgkfng.ini
c:\windows\system32\TDSSehts.log
c:\windows\system32\TDSSirwy.dll
c:\windows\system32\TDSSmugf.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSqqyk.dll
c:\windows\system32\TDSSqspa.dll
c:\windows\system32\TDSSsdhc.dll
c:\windows\system32\TDSSxcem.dll
c:\windows\system32\TDSSxghd.log
c:\windows\system32\TDSSyavu.dll
c:\windows\system32\thjaejjp.ini
c:\windows\system32\ueejdtbn.ini
c:\windows\system32\utrlglgf.ini
c:\windows\system32\vijdutrb.ini
c:\windows\system32\vmkndgak.ini
c:\windows\system32\vthvxjwi.ini
c:\windows\system32\vwdpgjks.ini
c:\windows\system32\vwtqlmhj.ini
c:\windows\system32\xpbynmpb.ini
c:\windows\system32\yruqjbpm.ini
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_CLBDRIVER
-------\Legacy_DOMAINSERVICE
-------\Legacy_OREANS32
-------\Service_oreans32
-------\Service_restore
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-26 au 2008-11-26 ))))))))))))))))))))))))))))))))))))
.
2008-11-18 00:14 . 2008-11-25 00:31 <REP> d-------- c:\program files\FindyKill
2008-11-17 21:49 . 2008-11-17 21:49 104,448 --a------ C:\jwwgtuh.exe
2008-11-17 21:46 . 2008-11-17 21:46 104,448 --a------ C:\dnenvq.exe
2008-11-17 21:46 . 2008-11-18 17:59 32,768 --a------ c:\windows\system32\drivers\ati5quxx.sys
2008-11-17 21:46 . 2008-11-17 21:48 2 --a------ C:\-2139826666
2008-11-17 21:45 . 2007-02-09 18:34 420,816 --a------ c:\documents and settings\YANNICK\Application Data\wunauclt.exe
2008-11-13 10:01 . 2008-11-13 10:01 1,393 --a------ c:\windows\imsins.BAK
2008-11-10 13:07 . 2008-11-10 13:07 <REP> d-------- c:\program files\Anti-Malware
2008-11-10 13:07 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-07 12:30 . 2008-11-07 12:30 <REP> d-------- c:\program files\CCleaner
2008-11-06 20:08 . 2007-06-08 17:15 1,519,616 --a------ c:\windows\system32\mxpvct25.dat
2008-11-06 20:08 . 2004-03-08 21:00 662,288 --a------ c:\windows\system32\mscomct2.ocx
2008-11-06 20:08 . 2004-03-09 16:45 132,880 --a------ c:\windows\system32\mxpvct22.dat
2008-11-05 13:23 . 2008-11-17 21:45 <REP> d-------- C:\Downloads
2008-11-05 12:19 . 2008-11-05 22:06 630 --a------ c:\windows\system32\tmp.reg
2008-11-02 04:38 . 2008-11-02 04:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive
2008-11-02 04:38 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-02 04:38 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-02 04:38 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-02 04:38 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-02 01:27 . 2008-11-09 13:08 <REP> d-------- c:\program files\Steam
2008-11-02 01:26 . 2008-11-02 01:27 <REP> d-------- c:\documents and settings\marc\steam
2008-11-02 01:26 . 2008-11-02 01:40 <REP> d-------- c:\documents and settings\marc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-26 12:07 --------- d-----w c:\documents and settings\YANNICK\Application Data\AVG7
2008-11-25 06:41 --------- d-----w c:\documents and settings\YANNICK\Application Data\Azureus
2008-11-17 20:47 --------- d-----w c:\program files\eMule
2008-11-16 17:45 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-02 12:52 --------- d-----w c:\program files\IsoBuster
2008-11-02 03:38 --------- d-----w c:\documents and settings\YANNICK\Application Data\Sports Interactive
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-05 16:43 --------- d-----w c:\documents and settings\YANNICK\Application Data\MAGIX
2008-10-04 08:00 --------- d-----w c:\program files\MSXML 4.0
2008-10-03 13:13 101,376 ----a-w c:\windows\system32\drivers\ACEDRV07.sys
2008-10-03 13:12 --------- d-----w c:\program files\Fichiers communs\MAGIX Shared
2008-10-03 13:10 --------- d-----w c:\documents and settings\All Users\Application Data\MAGIX
2008-09-27 08:55 --------- d-----w c:\program files\Fichiers communs\AOL
2008-09-27 08:55 --------- d-----w c:\documents and settings\All Users\Application Data\AOL OCP
2008-03-02 18:38 22,328 ----a-w c:\documents and settings\YANNICK\Application Data\PnkBstrK.sys
2007-02-24 08:11 92,064 ----a-w c:\documents and settings\YANNICK\mqdmmdm.sys
2007-02-24 08:11 9,232 ----a-w c:\documents and settings\YANNICK\mqdmmdfl.sys
2007-02-24 08:11 79,328 ----a-w c:\documents and settings\YANNICK\mqdmserd.sys
2007-02-24 08:11 66,656 ----a-w c:\documents and settings\YANNICK\mqdmbus.sys
2007-02-24 08:11 6,208 ----a-w c:\documents and settings\YANNICK\mqdmcmnt.sys
2007-02-24 08:11 5,936 ----a-w c:\documents and settings\YANNICK\mqdmwhnt.sys
2007-02-24 08:11 4,048 ----a-w c:\documents and settings\YANNICK\mqdmcr.sys
2007-02-24 08:11 25,600 ----a-w c:\documents and settings\YANNICK\usbsermptxp.sys
2007-02-24 08:11 22,768 ----a-w c:\documents and settings\YANNICK\usbsermpt.sys
.
------- Sigcheck -------
2005-03-02 19:20 578048 c34920eb988ce98910bd6b0417f334eb c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 16:50 579072 4d88aaf39adabfe45958ea1384e2c4ff c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2003-04-24 13:00 561152 0abf2f5280940d32d1d52bd3500b0c37 c:\windows\$NtServicePackUninstall$\user32.dll
2004-08-19 16:09 578048 61c8c283ad063bb697ae61a155c64a5a c:\windows\$NtUninstallKB890859$\user32.dll
2005-03-02 19:10 578048 0df75fb73f705b011630159a43d7c354 c:\windows\$NtUninstallKB925902$\user32.dll
2004-08-19 16:09 578048 61c8c283ad063bb697ae61a155c64a5a c:\windows\ServicePackFiles\i386\user32.dll
2008-04-14 03:33 579584 e853f84d3ce2faa2a802e33cf89ac023 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\user32.dll
2007-03-08 16:37 578560 753354f594809a9b96f73999b435a533 c:\windows\system32\user32.dll
2007-03-08 16:37 578560 753354f594809a9b96f73999b435a533 c:\windows\system32\dllcache\user32.dll
2003-04-24 13:00 75264 20c6d9f9522dda0f9a8e4b8641ca9245 c:\windows\$NtServicePackUninstall$\ws2_32.dll
2004-08-19 16:09 82944 eed74b969b2ca1acc558ff60fb420e28 c:\windows\ServicePackFiles\i386\ws2_32.dll
2008-04-14 03:33 82432 fb836f9e62d82904c983ad21296a5d9c c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ws2_32.dll
2004-08-19 16:09 82944 eed74b969b2ca1acc558ff60fb420e28 c:\windows\system32\ws2_32.dll
2006-10-23 16:34 668672 efa0c2870cba1747809a13e09f35bf82 c:\windows\$hf_mig$\KB925454\SP2QFE\wininet.dll
2007-03-23 10:29 823296 375b58a68a016546535a84060092325c c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
2007-04-25 09:26 823808 47ddad237f60729dea2b9e0e2382b58f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
2007-06-27 15:14 824320 7201d19b81883b57d5ffe8ebb5a83e8b c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 10:49 825344 2dd1b0f579c80562edcb8848ff7ea9f6 c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-11 00:22 825344 871ae10d6ae8877e9636ae5017953d52 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-07 02:42 825344 f4fd487241d3ac291046a22cebd2cf71 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 13:34 827392 5a0093f59b505c008ed0cee615563c72 c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-23 08:19 827392 78d3d2b0be6ad3e6d82ccb115cf74310 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 16:40 827904 52589bae67dd9859724287372668690b c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 10:10 827904 4b0e70d44297877a313045bd059770e1 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2003-04-24 13:00 603136 cbc50d46257c4a75644230507b488050 c:\windows\$NtServicePackUninstall$\wininet.dll
2006-10-23 16:18 663040 6091fee2b68974683d52119a98be3564 c:\windows\$NtUninstallKB925454$\wininet.dll
2004-08-19 16:09 660480 4e958b97efc3d801f49283d1820f48b7 c:\windows\$NtUninstallKB925454_0$\wininet.dll
2006-10-23 16:34 668672 efa0c2870cba1747809a13e09f35bf82 c:\windows\ie7\wininet.dll
2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
2007-02-27 14:26 822784 75de73e328e300caed5965faea2f5d3f c:\windows\ie7updates\KB933566-IE7\wininet.dll
2007-04-25 08:40 822784 2c138ab59e2ffa06e8952ae656e443c5 c:\windows\ie7updates\KB937143-IE7\wininet.dll
2007-06-27 14:24 823808 2274862267d7445e7010d9af826e89c3 c:\windows\ie7updates\KB939653-IE7\wininet.dll
2007-08-20 10:59 824832 f6dfceed3a7aa4c9eeb966d3f1adc70a c:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-11 00:49 824832 bc5119c53bdd48dabc628d448a3bdccb c:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-07 03:08 824832 4fc90bece54fac81b0090b94e27bfb6b c:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 13:58 826368 8e027981ddffa690d456fe18b37415a0 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-23 05:16 826368 02d6aabd5f5a32c61478b5cdfe50e4a8 c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 17:28 826368 ac0bd61dc2c64906fbfe50e005fefa2c c:\windows\ie7updates\KB956390-IE7\wininet.dll
2004-08-19 16:09 660480 4e958b97efc3d801f49283d1820f48b7 c:\windows\ServicePackFiles\i386\wininet.dll
2008-04-14 03:33 670208 4a6e04ea20f48d750d9bfed8600d516b c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\wininet.dll
2006-06-23 13:28 581120 1f063bdbd1afef9ac0abd02384d40376 c:\windows\SoftwareDistribution\Download\73231fc5e2f4907698b91ecd0c870ff8\rtmgdr\wininet.dll
2006-06-23 20:46 593408 38a54870eced4c83f227a5c4be236709 c:\windows\SoftwareDistribution\Download\73231fc5e2f4907698b91ecd0c870ff8\RTMQFE\wininet.dll
2008-08-26 09:11 826368 e30cacd98479b36a3dbfa3267bf62dd0 c:\windows\system32\wininet.dll
2008-08-26 09:11 826368 e30cacd98479b36a3dbfa3267bf62dd0 c:\windows\system32\dllcache\wininet.dll
2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 11:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2003-04-24 13:00 332928 244a2f9816bc9b593957281ef577d976 c:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2007-03-30 17:55 359808 b4e29943b4b04bd5e7381546848e6669 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 18:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\ServicePackFiles\i386\TCPIP.SYS
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2003-04-24 13:00 520704 71820bc9ee6653c8748922459dfc384d c:\windows\$NtServicePackUninstall$\winlogon.exe
2004-08-19 16:10 506368 123eea158f74d0f67a51dcdf065d1091 c:\windows\ServicePackFiles\i386\winlogon.exe
2008-04-14 03:34 512000 dd73d6b9f6b4cb630cf35b438b540174 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\winlogon.exe
2004-08-19 16:10 506368 123eea158f74d0f67a51dcdf065d1091 c:\windows\system32\winlogon.exe
2003-04-24 13:00 167552 3b350e5a2a5e951453f3993275a4523a c:\windows\$NtServicePackUninstall$\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\ServicePackFiles\i386\ndis.sys
2008-04-13 20:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\ServicePackFiles\i386\ip6fw.sys
2008-04-13 19:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-02 19:13 2059008 5311776074b6c13f983dc75baeac9c0c c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 19:45 2061440 8b039efbe4c9aa23f152ffa0e238b8fa c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 17:08 2061440 7a56a64eb50399613587e90292dd2aab c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 14:39 2065024 dcbc1a6d150b5ee1bd6257186157b0f3 c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 14:23 2068096 8da71f1900721e1e4fcb5b02d55fb771 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 18:26 2068096 755b50949d0dbc0f0136b0db58765331 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2003-04-24 13:00 1951488 4560381fa3425b16f5df1a0de4814de7 c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-19 16:04 2058880 f252fae094c54572ece38a039f2103c4 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-02 19:07 2058880 73fa9c95d235844a36968c7852c7dbdd c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 19:22 2059648 06015d137b02542f07d5cd7b144df942 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 17:02 2059648 a1d5231403329478ae4fe2778c55c77f c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 14:44 2059776 f9720d61df1e3e47614c4fc891f3fe44 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2004-08-19 16:04 2058880 f252fae094c54572ece38a039f2103c4 c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
2008-04-14 03:07 2067968 b71a8f101cefaf82fc5ec16130a54a3f c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ntkrnlpa.exe
2008-08-14 14:44 2059776 f9720d61df1e3e47614c4fc891f3fe44 c:\windows\system32\ntkrnlpa.exe
2008-08-14 14:44 2059776 f9720d61df1e3e47614c4fc891f3fe44 c:\windows\system32\dllcache\ntkrnlpa.exe
2005-03-02 19:13 2181632 3e2a0a4a0c0b19fc113618a9562a3b2a c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 19:45 2184064 1f3fa2065e6e043a1d82a487b5da309c c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 17:08 2184192 8e244108562e0e452eb68dff64cb08a9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 14:39 2188032 c6649255e51f145b6e15c505ab68e459 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 14:23 2191232 c8d4d5974f9671da0a37175650912960 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 18:26 2191232 d79210549bbf09b7638e860440504299 c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2003-04-24 13:00 2045824 f58b3ce36566d6061a496dc595a8aaa3 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-19 16:04 2183040 7d38ce4398e6aa6339b4644feadcc0d8 c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-02 19:08 2181376 63729dd0f2aae36cc52b89c05505146c c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 19:22 2182400 d27929db7b7f92f9d0f8ec9ba01c601c c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 17:02 2182400 7d6d19aac51a4325f6039f083c22303c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 14:44 2182400 449566d74b5c261a3a54aa216f0c532b c:\windows\Driver Cache\i386\ntoskrnl.exe
2004-08-19 16:04 2183040 7d38ce4398e6aa6339b4644feadcc0d8 c:\windows\ServicePackFiles\i386\ntoskrnl.exe
2008-04-14 03:08 2191104 099d639da1ef6968d4e41795bb507e6b c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ntoskrnl.exe
2008-08-14 14:44 2182400 449566d74b5c261a3a54aa216f0c532b c:\windows\system32\ntoskrnl.exe
2008-08-14 14:44 2182400 449566d74b5c261a3a54aa216f0c532b c:\windows\system32\dllcache\ntoskrnl.exe
2007-06-13 14:22 1037312 d0288319660edcfed07c7e74c4ea38a5 c:\windows\explorer.exe
2007-06-13 14:10 1037312 b795475444d6d57a572c14b9e1a29839 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2003-04-24 13:00 1008128 82fe0d400cb1ac937234467b927b867a c:\windows\$NtServicePackUninstall$\explorer.exe
2004-08-19 16:09 1036288 2a7bd330924252a2fd80344fc949bb72 c:\windows\$NtUninstallKB938828$\explorer.exe
2004-08-19 16:09 1036288 2a7bd330924252a2fd80344fc949bb72 c:\windows\ServicePackFiles\i386\explorer.exe
2008-04-14 03:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\explorer.exe
2007-06-13 14:22 1037312 d0288319660edcfed07c7e74c4ea38a5 c:\windows\system32\dllcache\explorer.exe
2003-04-24 13:00 101888 fc0691097471ee374907e1024edcbd43 c:\windows\$NtServicePackUninstall$\services.exe
2004-08-19 16:10 108544 63dcde1a0d86eeb8924d6738ff616ead c:\windows\ServicePackFiles\i386\services.exe
2008-04-14 03:34 109056 54cb50058851d95e56ec70d09f70857f c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\services.exe
2004-08-19 16:10 108544 63dcde1a0d86eeb8924d6738ff616ead c:\windows\system32\services.exe
2003-04-24 13:00 11776 b7b1c150aff59455db4df082815f88f5 c:\windows\$NtServicePackUninstall$\lsass.exe
2004-08-19 16:09 13312 259af82a0932eea4f316f92db94707b6 c:\windows\ServicePackFiles\i386\lsass.exe
2008-04-14 03:34 13312 91e6024d6d4dcdecdb36c43ecf9bbecb c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\lsass.exe
2004-08-19 16:09 13312 259af82a0932eea4f316f92db94707b6 c:\windows\system32\lsass.exe
2003-04-24 13:00 13312 2c856908ee61424238772508e9fbcbc8 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2004-08-19 16:09 15360 64e41e8fee655b03e3f19ded21ba5118 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 03:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ctfmon.exe
2004-08-19 16:09 15360 64e41e8fee655b03e3f19ded21ba5118 c:\windows\system32\ctfmon.exe
2005-06-11 01:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2003-04-24 13:00 51200 b1ce5287f096895d9be26eb86f4d5faf c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-19 16:10 57856 df9fc62ad51cb082b0ae371919a232cb c:\windows\$NtUninstallKB896423$\spoolsv.exe
2004-08-19 16:10 57856 df9fc62ad51cb082b0ae371919a232cb c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 03:34 57856 460e4ce148bd07218da0b6a3d31885a9 c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\spoolsv.exe
2005-06-11 00:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
2003-04-24 13:00 22528 f4127a2a00825c69a870035da1264ae0 c:\windows\$NtServicePackUninstall$\userinit.exe
2004-08-19 16:10 25088 84717891f0734c611721f56c60b5fbc3 c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 03:34 26624 e74ddb12188c2ff57a78624dbf7332fc c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\userinit.exe
2004-08-19 16:10 25088 84717891f0734c611721f56c60b5fbc3 c:\windows\system32\userinit.exe
2003-04-24 13:00 202752 cd31ea24bc9a1b9f3dfe3b54eef4d1d0 c:\windows\$NtServicePackUninstall$\termsrv.dll
2004-08-19 16:09 297984 78f90c3e230ad122bcb116abad5fefe9 c:\windows\ServicePackFiles\i386\termsrv.dll
2008-04-14 03:33 297984 710bc85a8c22626ee094439e3ea0d38c c:\windows\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\termsrv.dll
2004-08-19 16:09 297984 78f90c3e230ad122bcb116abad5fefe9 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-06 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2007-10-26 219136]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 36040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=emoewl.dll cgwtho.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5quxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AOL 9.0a\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Fichiers communs\\AOL\\1170939609\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\WINDOWS\\system32\\drivers\\Wingen\\system.exe"=
"c:\\Jeux\\Football Manager 2008\\fm.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
Contenu du dossier 'Tâches planifiées'
2008-11-17 c:\windows\Tasks\At1.job
- c:\documents and settings\YANNICK\Application Data\wunauclt.exe [2007-02-09 18:34]
2008-11-17 c:\windows\Tasks\At2.job
- c:\documents and settings\YANNICK\Application Data\wunauclt.exe [2007-02-09 18:34]
2008-11-17 c:\windows\Tasks\At3.job
- c:\documents and settings\YANNICK\Application Data\wunauclt.exe [2007-02-09 18:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{47080957-7903-41FC-B655-CEBA0A65E64A} - c:\windows\system32\byXQHwTK.dll
BHO-{B95D86BA-5ADF-418F-B49E-2C6719EE4388} - c:\windows\system32\ssqRHBTM.dll
HKCU-Run-MSMSGS - c:\program files\Messenger\msmsgs.exe
HKCU-Run-Uniblue RegistryBooster 2 - c:\program files\RegistryBooster 2\RegistryBooster.exe
HKCU-Run-update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 - %AppData%\wunauclt.exe
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
ShellExecuteHooks-{47080957-7903-41FC-B655-CEBA0A65E64A} - c:\windows\system32\byXQHwTK.dll
Notify-AtiExtEvent - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\YANNICK\Application Data\Mozilla\Firefox\Profiles\hw472ra5.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.fr/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF -: plugin - c:\program files\ma-config.com\nphardwaredetection.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-26 13:29:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
.
**************************************************************************
.
Heure de fin: 2008-11-26 13:33:15 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-26 12:31:58
Avant-CF: 13,850,955,776 octets libres
Après-CF: 13,739,425,792 octets libres
388 --- E O F --- 2008-11-13 22:58:49
Par contre, dès que j'enlève la fenêtre de ce rapport, il ne me met plus rien, plus de bureau ni rien, donc je ne peux pas faire de rapport hijackthis