Décidemment tu as vraiment réponse à tout
Voici le rapport de Combofix.
ComboFix 08-11-12.02 - HP_Propriétaire 2008-11-18 20:09:13.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.298 [GMT 1:00]
.
ADS - svchost.exe: deleted 25088 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Gillou\Application Data\HbTools
c:\documents and settings\HP_Propriétaire\Application Data\gadcom
c:\documents and settings\HP_Propriétaire\Application Data\gadcom\gadcom.exe
c:\documents and settings\HP_Propriétaire\Application Data\SystemDoctor 2006 Free
c:\documents and settings\HP_Propriétaire\Application Data\SystemDoctor 2006 Free\Logs\update.log
c:\documents and settings\HP_Propriétaire\Cookies\quxamefyj.vbs
c:\documents and settings\HP_Propriétaire\Cookies\taboqi.db
c:\documents and settings\HP_Propriétaire\Local Settings\Application Data\lujfttmf.dat
c:\documents and settings\HP_Propriétaire\Local Settings\Application Data\lujfttmf_nav.dat
c:\documents and settings\HP_Propriétaire\Local Settings\Application Data\lujfttmf_navps.dat
c:\documents and settings\HP_Propriétaire\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\HP_Propriétaire\Local Settings\Temporary Internet Files\kyte.db
c:\documents and settings\HP_Propriétaire\Local Settings\Temporary Internet Files\utug.ban
c:\program files\License_Manager
c:\program files\SystemDoctor 2006 Free
c:\program files\SystemDoctor 2006 Free\lock.dat
c:\windows\brastk.exe
c:\windows\system32\cbepghmw.ini
c:\windows\system32\cixgec.dll
c:\windows\system32\DelSelf.bat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\ati4vbxx.sys
c:\windows\system32\Drivers\TDSSpqlt.sys
c:\windows\system32\iifefEvT.dll
c:\windows\system32\iiqtlhgk.dll
c:\windows\system32\karna.dat
c:\windows\system32\kghltqii.ini
c:\windows\system32\MSINET.oca
c:\windows\system32\nvs2.inf
c:\windows\system32\OYFgPqss.ini
c:\windows\system32\OYFgPqss.ini2
c:\windows\system32\rs32net.exe
c:\windows\system32\sivgawxw.dll
c:\windows\system32\ssqPgFYO.dll
c:\windows\system32\TDSShrsr.dll
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSoiqt.log
c:\windows\system32\TDSSorvd.dll
c:\windows\system32\TDSSpqlt.dat
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\tufjrpes32.dll
c:\windows\system32\tuvWmJbA.dll
c:\windows\system32\ubosruhi.dll
c:\windows\system32\winjjq32.dll
c:\windows\system32\wmhgpebc.dll
c:\windows\system32\ybgepy.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_BOONTY_GAMES
-------\Legacy_fci
-------\Legacy_icf
-------\Service_ati4vbxx
-------\Service_Boonty Games
-------\Service_fci
-------\Service_icf
-------\Service_restore
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-18 au 2008-11-18 ))))))))))))))))))))))))))))))))))))
.
2014-10-21 22:43 . 2014-10-21 22:43 3,120 --a------ c:\windows\MF_C421.lfa
2014-10-21 22:43 . 2014-10-21 22:43 3,120 --a------ c:\windows\MF_C420.lfa
2008-11-17 22:24 . 2008-11-17 23:24 5,178 --a------ c:\windows\system32\tmp.reg
2008-11-17 22:23 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-11-17 22:23 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-11-17 22:23 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-11-17 22:23 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-11-17 22:23 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-11-17 22:23 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-11-17 22:23 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-11-17 22:23 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
2008-11-17 22:23 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-11-17 22:23 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-11-17 21:48 . 2008-11-18 20:22 5,760 --a------ c:\windows\system32\drivers\restore.sys
2008-11-17 21:26 . 2008-11-17 21:26 126,976 --a------ c:\windows\War3Unin.exe
2008-11-17 21:26 . 2008-11-17 21:29 23,688 --a------ c:\windows\War3Unin.dat
2008-11-17 21:26 . 2008-11-17 21:26 2,829 --a------ c:\windows\War3Unin.pif
2008-11-17 21:21 . 2008-11-17 21:30 <REP> d-------- c:\program files\Warcraft III
2008-11-17 18:21 . 2008-11-17 18:21 19,366 --a------ c:\windows\uzotov.reg
2008-11-17 18:21 . 2008-11-17 18:21 19,306 --a------ c:\windows\system32\cecozefire.bat
2008-11-17 18:21 . 2008-11-17 18:21 19,302 --a------ c:\documents and settings\HP_Propriétaire\Application Data\odoz.dat
2008-11-17 18:21 . 2008-11-17 18:21 18,745 --a------ c:\windows\lilyvogi.bin
2008-11-17 18:21 . 2008-11-17 18:21 18,314 --a------ c:\windows\uhyvyvi._dl
2008-11-17 18:21 . 2008-11-17 18:21 16,370 --a------ c:\windows\ijaqobajul._sy
2008-11-17 18:21 . 2008-11-17 18:21 16,161 --a------ c:\program files\Fichiers communs\ocobike.com
2008-11-17 18:21 . 2008-11-17 18:21 14,196 --a------ c:\windows\mifekafud._dl
2008-11-17 18:21 . 2008-11-17 18:21 13,703 --a------ c:\windows\system32\ezumewe.dl
2008-11-17 18:21 . 2008-11-17 18:21 13,469 --a------ c:\windows\lylewuwaju.dll
2008-11-17 18:19 . 2008-11-17 18:25 <REP> d-------- c:\program files\AntivirusPro2009
2008-11-17 16:37 . 2008-11-18 19:21 2,348 --a------ c:\windows\system32\TDSSxfum.dll
2008-11-17 16:36 . 2008-11-18 20:22 32,768 --a------ c:\windows\system32\drivers\ati2yexx.sys
2008-11-17 16:33 . 2008-11-17 16:33 104,448 --a------ C:\nriljal.exe
2008-11-17 16:33 . 2008-11-17 16:33 705 --a------ C:\psqrhqn.exe
2008-11-17 16:33 . 2008-11-17 16:33 2 --a------ C:\870640269
2008-11-17 16:33 . 2008-11-18 20:23 0 --a------ c:\windows\system32\drivers\6bdbb6f5.sys
2008-11-12 14:18 . 2008-11-12 14:18 <REP> d-------- c:\program files\Fichiers communs\Skype
2008-11-12 14:18 . 2008-11-12 14:22 <REP> d-------- c:\documents and settings\HP_Propriétaire\Application Data\Skype
2008-11-12 11:50 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 11:49 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-11 13:04 . 2008-11-11 13:04 <REP> d-------- c:\documents and settings\All Users\Application Data\IncrediMail
2008-11-09 15:37 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-11-09 15:37 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-11-09 15:36 . 2008-11-09 15:36 <REP> d-------- c:\program files\iTunes
2008-11-09 15:36 . 2008-11-09 15:36 <REP> d-------- c:\program files\iPod
2008-11-09 15:36 . 2008-11-09 15:36 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-09 15:35 . 2008-11-09 15:35 <REP> d-------- c:\program files\Bonjour
2008-11-09 15:34 . 2008-11-09 15:35 <REP> d-------- c:\program files\QuickTime
2008-11-09 15:32 . 2008-11-09 15:32 <REP> d-------- c:\program files\Apple Software Update
2008-11-09 15:32 . 2008-10-01 13:01 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys
2008-11-09 15:31 . 2008-11-09 15:31 <REP> d-------- c:\program files\Fichiers communs\Apple
2008-10-27 16:45 . 2008-10-27 16:47 3,094 --a------ c:\windows\system32\spupdsvc.inf
2008-10-27 16:40 . 2008-10-27 16:40 <REP> d-------- c:\windows\system32\bits
2008-10-27 16:40 . 2008-10-27 16:40 <REP> d-------- c:\windows\l2schemas
2008-10-27 16:37 . 2008-10-27 16:41 <REP> d-------- c:\windows\ServicePackFiles
2008-10-27 16:28 . 2008-10-27 16:28 <REP> d-------- c:\windows\EHome
2008-10-25 07:56 . 2004-08-03 23:38 701,440 --------- c:\windows\system32\drivers\ati2mtag.sys
2008-10-24 13:54 . 2008-10-15 17:35 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
2008-10-18 19:27 . 2004-08-03 23:54 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-10-18 19:27 . 2001-08-23 16:47 5,632 --a------ c:\windows\system32\ptpusb.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 17:21 10,520 ----a-w c:\program files\Fichiers communs\xerameho.ban
2008-11-16 15:33 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\U3
2008-11-14 11:54 --------- d-----w c:\program files\Wakfu
2008-11-12 13:20 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\skypePM
2008-11-12 13:18 --------- d-----w c:\program files\Skype
2008-11-12 13:18 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-11 12:04 --------- d-----w c:\program files\IncrediMail
2008-11-11 12:02 --------- d-----w c:\program files\Oberon Media
2008-11-09 14:34 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 16:25 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-23 12:25 --------- d-----w c:\program files\Incredijeux
2008-10-23 12:25 --------- d-----w c:\documents and settings\HP_Propriétaire\Application Data\PlayFirst
2008-10-23 12:25 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-10-15 12:36 --------- d-----w c:\program files\Dofus
2008-04-14 13:37 0 ----a-w c:\program files\temp01
2008-03-17 19:19 32 ----a-r c:\documents and settings\All Users\hash.dat
2007-05-28 12:25 774,144 ----a-w c:\program files\RngInterstitial.dll
2006-08-20 15:34 576 ----a-w c:\documents and settings\HP_Propriétaire\Application Data\wklnhst.dat
2006-05-20 12:50 49,465 ----a-w c:\program files\moviepass Terms.html
2005-07-02 16:09 22 --sha-w c:\windows\SMINST\HPCD.sys
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-30 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-10-19 243072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2004-11-05 106496]
"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2004-11-05 192512]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-01-06 59040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2008-04-16 985440]
"HiYo"="c:\program files\HiYo\bin\HiYo.exe" [2008-05-21 143360]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VirusKeeper"="c:\program files\AxBx\VirusKeeper 2008 Pro Evaluation\VirusKeeper.exe" [2008-08-22 3000192]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Antivirus Pro 2009"="c:\program files\AntivirusPro2009\AntivirusPro2009.exe" [2008-11-15 597323]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"nwiz"="nwiz.exe" [2005-02-24 c:\windows\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-02-21 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-02-18 c:\windows\ALCWZRD.EXE]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
HotSync Manager.LNK - c:\program files\palmOne\HOTSYNC.EXE [2004-04-12 299008]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-01-01 286720]
Lancer l'utilitaire d'enregistrement.lnk - c:\program files\WiFiConnector\NintendoWFCReg.exe [2006-07-01 1073152]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-11 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-07-11 805392]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Fichiers communs\LogiShrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2yexx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\palmOne\\HOTSYNC.EXE"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"c:\\CaffeLatte\\CafeClient\\CafeProtocol.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 ati2yexx;ati2yexx;c:\windows\system32\Drivers\ati2yexx.sys [2008-11-18 32768]
R1 prodrv04;Star Force copy protection driver v4;c:\windows\system32\drivers\prodrv04.sys [2005-08-25 114496]
R2 vkservice;VirusKeeper antivirus/antispyware;c:\program files\AxBx\VirusKeeper 2008 Pro Evaluation\vk_service.exe [2008-05-22 1119576]
R3 Cap7134;ASUS TV7134 WDM Video Capture;c:\windows\system32\DRIVERS\Cap7134.sys [2004-10-27 335360]
R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-10-24 24544]
R3 PRISM_A00;Wireless PCI 802.11b/g adapter WN4201B Driver;c:\windows\system32\DRIVERS\PCTELSAP.SYS [2004-11-30 306560]
R3 USBSTOR;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 Arcadyan;Arcadyan NDIS Protocol Driver;c:\progra~1\PC-DOC~1\DIAGNO~1\Arcadyan.SYS [2004-08-19 17422]
S3 krdpdre;krdpdre;c:\docume~1\HP_PRO~1\LOCALS~1\Temp\krdpdre.sys [ ]
S3 restore;restore;c:\windows\system32\drivers\restore.sys [2008-11-18 5760]
S3 usbscan;Pilote de scanneur USB;c:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91af35e8-ddb3-11db-8d2d-0012bf08f355}]
\Shell\AutoRun\command - K:\LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2008-11-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-11-17 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
BHO-{3f0250b6-d702-4256-9ae8-5409ceb00094} - c:\windows\system32\ssqPgFYO.dll
BHO-{4fd130ae-d8d2-4137-a680-c5cf233be545} - c:\windows\system32\iifefEvT.dll
HKCU-Run-247Cams - c:\program files\247Cams\Camnotifier.exe
HKCU-Run-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
HKCU-Run-Magentic - c:\progra~1\Magentic\bin\Magentic.exe
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
ShellExecuteHooks-{4FD130AE-D8D2-4137-A680-C5CF233BE545} - c:\windows\system32\iifefEvT.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\k90val3p.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:f(...)
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://be.msn.com/default.aspx/?lang=fr-be
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 20:20:08
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal
c:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Ahead\Nero Home\indexstore.db-journal
Scan terminé avec succès
Fichiers cachés: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\6bdbb6f5]
"ImagePath"="\SystemRoot\System32\drivers\6bdbb6f5.sys"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Symantec Shared\CCSETMGR.EXE
c:\program files\Fichiers communs\Symantec Shared\CCEVTMGR.EXE
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Windows Live\Messenger\msnmsgr.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\program files\Fichiers communs\LogiShrd\KHAL2\KHALMNPR.exe
c:\program files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Heure de fin: 2008-11-18 20:36:35 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-18 19:36:27
Avant-CF: 184,895,283,200 octets libres
Après-CF: 185,927,819,264 octets libres
319 --- E O F --- 2008-11-12 14:57:41