C’est fait ! Rapport ComboFix :
ComboFix 08-11-26.03 - Utilisateur 2008-11-26 23:52:06.1 - NTFSx86
Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2154 [GMT 1:00]
Lancé depuis: c:\users\Utilisateur\Desktop\C-Fix.exe
- Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-26 au 2008-11-26 ))))))))))))))))))))))))))))))))))))
.
2008-11-26 22:59 . 2008-11-26 22:59 d-------- C:\rsit
2008-11-26 19:38 . 2008-06-19 17:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2008-11-26 19:37 . 2008-11-26 19:37 d-------- c:\program files\Panda Security
2008-11-26 19:17 . 2008-11-26 19:31 d-------- c:\windows\BDOSCAN8
2008-11-26 16:51 . 2008-11-26 17:52 d-------- c:\users\All Users\comodo
2008-11-26 16:51 . 2008-11-26 17:52 d-------- c:\programdata\comodo
2008-11-26 16:51 . 2008-11-26 16:58 143,096 --a------ c:\windows\System32\guard32.dll
2008-11-26 16:51 . 2008-11-26 16:58 97,808 --a------ c:\windows\System32\drivers\cmdguard.sys
2008-11-26 16:51 . 2008-11-26 16:58 25,104 --a------ c:\windows\System32\drivers\cmdhlp.sys
2008-11-26 10:27 . 2008-11-26 11:49 d-------- c:\program files\EsetOnlineScanner
2008-11-26 10:16 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-26 10:16 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-26 10:16 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 10:16 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 10:16 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-25 18:47 . 2008-11-25 23:33 d-------- c:\users\Alexis\AppData\Roaming\dvdcss
2008-11-25 13:05 . 2008-11-25 13:05 d-------- c:\users\Utilisateur\AppData\Roaming\Apple Computer
2008-11-25 13:04 . 2008-11-25 13:04 d-------- c:\users\All Users\Apple
2008-11-25 13:04 . 2008-11-25 13:04 d-------- c:\programdata\Apple
2008-11-25 13:04 . 2008-11-25 13:04 d-------- c:\program files\Bonjour
2008-11-24 23:14 . 2008-11-24 23:15 d-------- c:\users\Alexis\AppData\Roaming\vlc
2008-11-24 23:06 . 2008-11-24 23:14 d-------- c:\users\Utilisateur\AppData\Roaming\vlc
2008-11-24 18:45 . 2008-11-24 18:45 d-------- c:\users\Alexis\AppData\Roaming\OpenOffice.org
2008-11-24 18:36 . 2008-11-24 18:36 d-------- c:\users\Alexis\AppData\Roaming\KeePass
2008-11-24 18:25 . 2008-11-24 18:25 d-------- c:\program files\OpenOffice.org 3
2008-11-24 18:14 . 2008-11-24 18:14 d-------- c:\users\Utilisateur\AppData\Roaming\eMule
2008-11-24 18:04 . 2008-11-24 18:04 d-------- c:\program files\filehippo.com
2008-11-24 17:23 . 2008-11-24 17:23 d-------- c:\program files\Java
2008-11-24 17:11 . 2008-11-24 17:11 d-------- c:\program files\Common Files\Adobe
2008-11-22 18:58 . 2008-10-27 18:37 192,307 --a------ C:\wubildr
2008-11-22 18:58 . 2008-10-27 18:37 8,192 --a------ C:\wubildr.mbr
2008-11-22 18:52 . 2008-11-22 18:52 d-------- C:\ubuntu
2008-11-20 19:18 . 2008-11-20 19:19 d-------- c:\program files\Microsoft IntelliType Pro
2008-11-19 15:05 . 2008-11-19 15:06 d-------- c:\users\Alexis.housecall6.6
2008-11-19 13:36 . 2008-11-26 17:49 d-------- c:\users\All Users\BOC425
2008-11-19 13:36 . 2008-11-26 17:49 d-------- c:\programdata\BOC425
2008-11-19 13:36 . 2007-08-08 20:02 235,008 --a------ c:\windows\UNBOC.EXE
2008-11-19 13:36 . 2007-05-08 17:01 208,896 --a------ c:\windows\CMDLIC.DLL
2008-11-19 13:36 . 2008-01-19 08:37 15,360 --a------ c:\windows\System32\wsock32.dlb
2008-11-19 13:36 . 2008-11-26 11:51 383 --a------ c:\windows\BOC425.INI
2008-11-18 23:24 . 2008-11-19 13:21 d-------- c:\program files\BHODemon 2
2008-11-18 22:23 . 2008-11-18 22:23 d-------- c:\windows\Sun
2008-11-18 22:22 . 2008-11-24 17:23 410,976 --a------ c:\windows\System32\deploytk.dll
2008-11-17 21:54 . 2008-11-17 21:54 28,812,800 --a------ c:\windows\System32\imageres.dll
2008-11-17 21:26 . 2008-11-17 21:26 d-------- c:\users\All Users\Stardock
2008-11-17 21:26 . 2008-11-17 21:26 d-------- c:\programdata\Stardock
2008-11-17 21:26 . 2007-06-05 11:26 567,040 --a------ c:\windows\System32\wbocx.ocx
2008-11-17 21:26 . 2007-06-05 11:26 56,496 --a------ c:\windows\System32\wbhelp2.dll
2008-11-17 21:18 . 2008-11-17 21:18 2,560 --a------ c:\windows_MSRSTRT.EXE
2008-11-17 21:11 . 2008-11-17 21:11 0 --------- c:\windows\WB.ini
2008-11-17 21:10 . 2008-11-17 21:10 29 --a------ c:\windows.wb4
2008-11-17 21:09 . 2008-11-17 21:09 d-------- c:\program files\Stardock
2008-11-17 21:09 . 2008-04-26 16:14 58,792 --------- c:\windows\System32\wbload.dll
2008-11-17 21:09 . 2008-04-26 16:14 42,672 --------- c:\windows\System32\wbsys.dll
2008-11-17 21:00 . 2008-11-24 22:44 d-------- c:\users\Alexis\AppData\Roaming\Vista Start Menu
2008-11-16 22:04 . 2008-11-16 22:04 d-------- c:\program files\Opera
2008-11-16 15:51 . 2008-11-26 17:49 d-------- c:\program files\SyllabiK
2008-11-15 19:50 . 2008-11-25 22:22 d-------- C:\Tgl0beSCRIPT
2008-11-14 17:18 . 2008-11-18 16:53 d-------- c:\program files\CCleaner
2008-11-14 17:08 . 2008-11-14 17:08 d-------- c:\program files\Glary Utilities
2008-11-14 11:33 . 2008-11-14 11:33 d-------- c:\users\Utilisateur\AppData\Roaming\InstallShield
2008-11-14 11:33 . 2008-09-12 13:32 327,192 --a------ c:\windows\System32\drivers\iaStor.sys
2008-11-14 11:33 . 2006-11-10 09:25 319,456 --a------ c:\windows\System32\difxapi.dll
2008-11-14 11:27 . 2008-05-01 16:35 53,248 --a------ c:\windows\System32\CSVer.dll
2008-11-14 11:26 . 2008-11-14 11:26 d-------- C:\Intel
2008-11-14 11:07 . 2008-11-14 11:16 d–h----- c:\program files\Temp
2008-11-14 10:56 . 2008-11-14 10:56 d-------- c:\windows\System32\AGEIA
2008-11-14 10:56 . 2008-11-14 10:56 d-------- c:\program files\Common Files\Wise Installation Wizard
2008-11-14 10:56 . 2008-11-14 10:56 d-------- c:\program files\AGEIA Technologies
2008-11-14 10:53 . 2008-11-14 10:53 d-------- C:\NVIDIA
2008-11-14 10:43 . 2008-11-24 19:41 d-------- c:\users\All Users\ma-config.com
2008-11-14 10:43 . 2008-11-24 19:41 d-------- c:\programdata\ma-config.com
2008-11-14 10:43 . 2008-11-24 19:41 d-------- c:\program files\ma-config.com
2008-11-12 14:41 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 14:41 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 14:41 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-09 19:39 . 2008-11-09 19:39 d-------- c:\users\Alexis\AppData\Roaming\Malwarebytes
2008-11-09 19:32 . 2008-11-09 19:32 d-------- c:\program files\Trend Micro
2008-11-09 19:19 . 2008-11-09 19:19 d-------- c:\users\Alexis\AppData\Roaming\Comodo
2008-11-09 19:12 . 2008-11-19 13:19 d-------- c:\users\Alexis\AppData\Roaming\Spyware Terminator
2008-11-09 18:58 . 2008-11-24 15:51 d-------- c:\users\Utilisateur\AppData\Roaming\Comodo
2008-11-09 17:33 . 2008-11-09 17:33 d-------- c:\users\Utilisateur\AppData\Roaming\Malwarebytes
2008-11-09 17:33 . 2008-11-09 17:33 d-------- c:\users\All Users\Malwarebytes
2008-11-09 17:33 . 2008-11-09 17:33 d-------- c:\programdata\Malwarebytes
2008-11-09 17:33 . 2008-11-13 15:01 d-------- c:\program files\Malwarebytes’ Anti-Malware
2008-11-09 17:33 . 2008-10-22 16:10 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-09 17:33 . 2008-10-22 16:10 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-09 16:47 . 2008-11-26 17:01 249,592 --a------ c:\windows\System32\cssdll32.dll
2008-11-09 16:45 . 2008-11-26 17:01 d-------- c:\program files\COMODO
2008-11-09 16:34 . 2008-11-09 16:34 507,904 --a------ c:\windows\TMUPDATE.DLL
2008-11-09 16:34 . 2008-11-09 16:34 286,720 --a------ c:\windows\PATCH.EXE
2008-11-09 16:34 . 2008-11-09 16:34 69,689 --a------ c:\windows\UNZIP.DLL
2008-11-09 15:20 . 2008-11-09 15:20 d-------- c:\users\All Users\Avira
2008-11-09 15:20 . 2008-11-09 15:20 d-------- c:\programdata\Avira
2008-11-09 15:20 . 2008-11-09 15:20 d-------- c:\program files\Avira
2008-11-03 15:03 . 2008-11-03 15:03 d-------- c:\users\All Users\WindowsSearch
2008-11-03 15:03 . 2008-11-03 15:03 d-------- c:\programdata\WindowsSearch
2008-10-28 20:53 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-28 20:53 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-28 20:53 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-24 17:27 --------- d-----w c:\users\Utilisateur\AppData\Roaming\Skype
2008-11-24 17:24 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-11-24 17:16 --------- d-----w c:\program files\KeePass Password Safe
2008-11-24 14:54 --------- d-----w c:\users\Utilisateur\AppData\Roaming\OpenOffice.org2
2008-11-22 15:32 --------- d-----w c:\users\Alexis\AppData\Roaming\OpenOffice.org2
2008-11-21 21:25 --------- d-----w c:\users\Alexis\AppData\Roaming\Skype
2008-11-21 20:22 --------- d-----w c:\users\Alexis\AppData\Roaming\skypePM
2008-11-21 16:43 --------- d-----w c:\users\Utilisateur\AppData\Roaming\CyberLink
2008-11-21 12:15 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-18 23:32 54,680 ----a-w c:\windows\System32\jureg.exe
2008-11-18 23:32 382,384 ----a-w c:\windows\System32\jucheck.exe
2008-11-18 23:32 136,600 ----a-w c:\windows\System32\jusched.exe
2008-11-14 10:33 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-14 10:27 --------- d-----w c:\program files\Intel
2008-11-14 10:07 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-11-14 10:00 --------- d-----w c:\programdata\NVIDIA
2008-11-13 18:10 --------- d-----w c:\program files\Orange
2008-11-12 16:29 --------- d-----w c:\programdata\Microsoft Help
2008-10-24 11:54 --------- d-----w c:\program files\Common Files\L&H
2008-10-24 11:53 --------- d-----w c:\program files\Microsoft Reader
2008-10-23 14:59 --------- d-----w c:\programdata\Skype
2008-10-23 14:59 --------- d-----w c:\program files\Skype
2008-10-23 14:59 --------- d-----w c:\program files\Common Files\Skype
2008-10-22 01:03 --------- d-----w c:\program files\MSXML 4.0
2008-10-21 17:19 56 —ha-w c:\users\All Users\ezsidmv.dat
2008-10-21 17:19 56 —ha-w c:\programdata\ezsidmv.dat
2008-10-21 16:53 --------- d-----w c:\program files\Labtec
2008-10-21 16:53 --------- d-----w c:\program files\Common Files\LogiShrd
2008-10-21 16:53 --------- d-----w c:\program files\Common Files\Labtec
2008-10-20 22:01 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-17 01:02 --------- d-----w c:\program files\Windows Mail
2008-10-02 09:07 453,152 ----a-w c:\windows\System32\nvuninst.exe
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-09-04 12:25 170 ----a-w c:\users\Alexis\AppData\Roaming\wklnhst.dat
2008-09-04 08:31 288,024 ----a-w c:\windows\System32\PhysXCplUI.exe
2008-08-29 09:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 08:53 65,536 ----a-w c:\windows\System32\jdns_sd.dll
2008-08-29 08:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-08-29 07:57 70,936 ----a-w c:\windows\System32\PhysXLoader.dll
2008-08-01 20:30 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“filehippo.com”=“c:\program files\filehippo.com\UpdateChecker.exe” [2008-10-22 147968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“hpsysdrv”=“c:\hp\support\hpsysdrv.exe” [2007-04-18 65536]
“KBD”=“c:\hp\KBD\KbdStub.EXE” [2006-12-08 65536]
“IAAnotif”=“c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe” [2008-09-12 182808]
“SunJavaUpdateReg”=“c:\windows\system32\jureg.exe” [2008-11-19 54680]
“LogitechCommunicationsManager”=“c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe” [2007-03-06 488984]
“avgnt”=“c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” [2008-06-12 266497]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-10-07 13584928]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-10-07 92704]
“BOC-425”=“c:\progra~1\Comodo\CBOClean\BOC425.exe” [2007-08-08 338432]
“itype”=“c:\program files\Microsoft IntelliType Pro\itype.exe” [2007-08-31 988584]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-11-24 136600]
“COMODO SafeSurf”=“c:\program files\COMODO\SafeSurf\cssurf.exe” [2008-11-26 278264]
“COMODO Internet Security”=“c:\program files\COMODO\COMODO Internet Security\cfp.exe” [2008-11-26 1796856]
c:\users\Alexis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“EnableShellExecuteHooks”= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”= c:\windows\system32\cssdll32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.l3codecp”= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{CF04EFCF-974A-4373-983A-FE10CDBBB393}”= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
“{C45D3B7E-968C-4E97-86CC-FB9EBC70141D}”= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
“TCP Query User{E7429429-198E-4AA0-8B04-2FBB99061FD5}c:\program files\emule\emule.exe”= UDP:c:\program files\emule\emule.exe:eMule
“UDP Query User{471D95DB-0CA3-4398-9DB6-CEBA287294AD}c:\program files\emule\emule.exe”= TCP:c:\program files\emule\emule.exe:eMule
“{9AF44E97-9416-4CCD-B328-ABF8BCA3DD32}”= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{5D11B9C5-FC29-4F8B-A794-C020637C4F0D}”= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
“{BA43B452-C8A0-4B51-8267-422907A73D7D}”= c:\program files\Skype\Phone\Skype.exe:Skype
“{6422C8C7-108C-485A-8B4B-4AAB7D4527E0}”= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
“{3D0C7757-863B-4352-BC19-58907804917A}”= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
“TCP Query User{68D269F3-94FA-4FE3-871F-F03D6CA7E43D}c:\program files\syllabik\mirc.exe”= UDP:c:\program files\syllabik\mirc.exe:mIRC
“UDP Query User{E66027FB-1A92-4830-96A5-66D5A30254E0}c:\program files\syllabik\mirc.exe”= TCP:c:\program files\syllabik\mirc.exe:mIRC
“{345CD8B9-4F12-4F98-B034-EDD50EFE4395}”= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
“{F52330EC-B972-49DA-88D6-DC8613DA8575}”= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
“{AE169F67-FC0A-4677-839E-5865F7488005}”= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
“{7D56DE26-389B-4729-8825-2F22EE9E59CB}”= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
[HKLM~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
“EnableFirewall”= 0 (0x0)
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-26 28544]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-11-26 97808]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-11-26 25104]
S3 maconfservice;Ma-Config Service;“c:\program files\ma-config.com\maconfservice.exe” [2008-11-17 195752]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2008-08-01 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50.sys [2008-08-01 27072]
Newly Created Service - PROCEXP90
.
Contenu du dossier ‘Tâches planifiées’
2008-11-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-29 17:58]
2008-11-20 c:\windows\Tasks\HPCeeScheduleForAlexis.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2007-12-06 12:10]
2008-11-26 c:\windows\Tasks\User_Feed_Synchronization-{3AA60397-4C53-45F3-B4EF-C1C596595925}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\erqhfpww.default
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\ma-config.com\nphardwaredetection.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-11-26 23:53:41
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
--------------------- DLLs chargées dans les processus actifs ---------------------
-
-
-
-
-
-
-
‘winlogon.exe’(864)
c:\windows\system32\cssdll32.dll
-
-
-
-
-
-
-
‘lsass.exe’(696)
c:\windows\system32\cssdll32.dll
.
Heure de fin: 2008-11-26 23:54:28
ComboFix-quarantined-files.txt 2008-11-26 22:54:25
Avant-CF: 249 156 177 920 octets libres
Après-CF: 249,125,515,264 octets libres
260 — E O F — 2008-11-26 10:52:22
Et celui de RIST :
Logfile of random’s system information tool 1.04 (written by random/random)
Run by Utilisateur at 2008-11-27 00:10:32
Microsoft® Windows Vista Édition Familiale Premium Service Pack 1
System drive C: has 238 GB (71%) free of 333 GB
Total RAM: 3071 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:10:34, on 27/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\System32\jureg.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\COMODO\CBOClean\BOC425.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\WINDOWS\Speech\Common\sapisvr.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Internet Explorer\IEUser.exe
C:\hp\kbd\kbd.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Alexis\Desktop\RSIT.exe
C:\Users\Utilisateur\Desktop\Utilisateur.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d’aide de l’Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM…\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM…\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM…\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM…\Run: [SunJavaUpdateReg] “C:\Windows\system32\jureg.exe”
O4 - HKLM…\Run: [LogitechCommunicationsManager] “C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe”
O4 - HKLM…\Run: [avgnt] “C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” /min
O4 - HKLM…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM…\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
O4 - HKLM…\Run: [itype] “C:\Program Files\Microsoft IntelliType Pro\itype.exe”
O4 - HKLM…\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM…\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM…\Run: [COMODO SafeSurf] “C:\Program Files\COMODO\SafeSurf\cssurf.exe” -s
O4 - HKLM…\Run: [COMODO Internet Security] “C:\Program Files\COMODO\COMODO Internet Security\cfp.exe” -h
O4 - HKCU…\Run: [filehippo.com] “C:\Program Files\filehippo.com\UpdateChecker.exe” /background
O4 - HKUS\S-1-5-21-4116081982-3728781140-3913541649-1001…\Run: [Speech Recognition] “C:\Windows\Speech\Common\sapisvr.exe” -SpeechUX -Startup (User ‘Alexis’)
O4 - HKUS\S-1-5-21-4116081982-3728781140-3913541649-1001…\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User ‘Alexis’)
O4 - HKUS\S-1-5-21-4116081982-3728781140-3913541649-1001…\Run: [MsnMsgr] “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background (User ‘Alexis’)
O4 - HKUS\S-1-5-21-4116081982-3728781140-3913541649-1001…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User ‘Alexis’)
O4 - HKUS\S-1-5-21-4116081982-3728781140-3913541649-1001…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User ‘Alexis’)
O4 - S-1-5-21-4116081982-3728781140-3913541649-1001 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User ‘Alexis’)
O4 - S-1-5-21-4116081982-3728781140-3913541649-1001 User Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User ‘Alexis’)
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE…
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra ‘Tools’ menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: www.orange.fr…
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - acs.pandasoftware.com…
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - cdn.scan.onecare.live.com…
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - www.eset.eu…
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - www.bitdefender.fr…
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com…
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\system32\cssdll32.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
–
End of file - 8596 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\HPCeeScheduleForAlexis.job
C:\Windows\tasks\User_Feed_Synchronization-{3AA60397-4C53-45F3-B4EF-C1C596595925}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-24 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d’aide de l’Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-24 34816]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“hpsysdrv”=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
“KBD”=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
“IAAnotif”=C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [2008-09-12 182808]
“SunJavaUpdateReg”=C:\Windows\system32\jureg.exe [2008-11-19 54680]
“LogitechCommunicationsManager”=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2007-03-06 488984]
“avgnt”=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
“NvCplDaemon”=C:\Windows\system32\NvCpl.dll [2008-10-07 13584928]
“NvMediaCenter”=C:\Windows\system32\NvMcTray.dll [2008-10-07 92704]
“BOC-425”=C:\PROGRA~1\Comodo\CBOClean\BOC425.exe [2007-08-08 338432]
“itype”=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2007-08-31 988584]
“Adobe Reader Speed Launcher”=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
“SunJavaUpdateSched”=C:\Program Files\Java\jre6\bin\jusched.exe [2008-11-24 136600]
“COMODO SafeSurf”=C:\Program Files\COMODO\SafeSurf\cssurf.exe [2008-11-26 278264]
“COMODO Internet Security”=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2008-11-26 1796856]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
“filehippo.com”=C:\Program Files\filehippo.com\UpdateChecker.exe [2008-10-22 147968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
“AppInit_DLLS”=" C:\Windows\system32\cssdll32.dll"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
“dontdisplaylastusername”=0
“legalnoticecaption”=
“legalnoticetext”=
“shutdownwithoutlogon”=1
“undockwithoutlogon”=1
“EnableUIADesktopToggle”=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“NoDrives”=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
“EnableShellExecuteHooks”=
“NoDriveTypeAutoRun”=
“NoDrives”=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2008-11-26 23:54:30 ----D---- C:\Windows\temp
2008-11-26 23:54:29 ----A---- C:\ComboFix.txt
2008-11-26 23:50:33 ----A---- C:\Windows\zip.exe
2008-11-26 23:50:33 ----A---- C:\Windows\VFIND.exe
2008-11-26 23:50:33 ----A---- C:\Windows\SWXCACLS.exe
2008-11-26 23:50:33 ----A---- C:\Windows\SWSC.exe
2008-11-26 23:50:33 ----A---- C:\Windows\SWREG.exe
2008-11-26 23:50:33 ----A---- C:\Windows\sed.exe
2008-11-26 23:50:33 ----A---- C:\Windows\NIRCMD.exe
2008-11-26 23:50:33 ----A---- C:\Windows\grep.exe
2008-11-26 23:50:33 ----A---- C:\Windows\fdsv.exe
2008-11-26 23:50:31 ----D---- C:\Windows\ERDNT
2008-11-26 23:50:31 ----D---- C:\Qoobox
2008-11-26 23:50:31 ----D---- C:\C-Fix
2008-11-26 22:59:08 ----D---- C:\rsit
2008-11-26 19:37:57 ----D---- C:\Program Files\Panda Security
2008-11-26 19:17:57 ----D---- C:\Windows\BDOSCAN8
2008-11-26 16:51:15 ----D---- C:\ProgramData\comodo
2008-11-26 16:51:15 ----A---- C:\Windows\system32\guard32.dll
2008-11-26 10:27:54 ----D---- C:\Program Files\EsetOnlineScanner
2008-11-26 10:16:52 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2008-11-26 10:16:51 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2008-11-26 10:16:51 ----A---- C:\Windows\system32\WindowsCodecs.dll
2008-11-26 10:16:51 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2008-11-26 10:16:50 ----A---- C:\Windows\system32\connect.dll
2008-11-25 23:25:25 ----SHD---- C:\Config.Msi
2008-11-25 13:05:17 ----D---- C:\Users\Utilisateur\AppData\Roaming\Apple Computer
2008-11-25 13:04:09 ----D---- C:\Program Files\Bonjour
2008-11-25 13:04:02 ----D---- C:\ProgramData\Apple
2008-11-24 23:06:10 ----D---- C:\Users\Utilisateur\AppData\Roaming\vlc
2008-11-24 18:25:05 ----D---- C:\Program Files\OpenOffice.org 3
2008-11-24 18:14:55 ----D---- C:\Users\Utilisateur\AppData\Roaming\eMule
2008-11-24 18:04:19 ----D---- C:\Program Files\filehippo.com
2008-11-24 17:23:32 ----A---- C:\Windows\system32\javaws.exe
2008-11-24 17:23:32 ----A---- C:\Windows\system32\javaw.exe
2008-11-24 17:23:32 ----A---- C:\Windows\system32\java.exe
2008-11-24 17:23:19 ----D---- C:\Program Files\Java
2008-11-24 17:11:00 ----D---- C:\Program Files\Common Files\Adobe
2008-11-22 18:52:54 ----D---- C:\ubuntu
2008-11-20 19:18:58 ----D---- C:\Program Files\Microsoft IntelliType Pro
2008-11-19 13:36:46 ----A---- C:\Windows\UNBOC.EXE
2008-11-19 13:36:45 ----A---- C:\Windows\CMDLIC.DLL
2008-11-19 13:36:39 ----D---- C:\ProgramData\BOC425
2008-11-19 13:36:35 ----A---- C:\Windows\BOC425.INI
2008-11-18 23:24:08 ----D---- C:\Program Files\BHODemon 2
2008-11-18 22:23:54 ----D---- C:\Windows\Sun
2008-11-18 22:22:47 ----A---- C:\Windows\system32\deploytk.dll
2008-11-17 21:54:28 ----A---- C:\Windows\system32\imageres.dll
2008-11-17 21:26:24 ----D---- C:\ProgramData\Stardock
2008-11-17 21:26:11 ----A---- C:\Windows\system32\wbhelp2.dll
2008-11-17 21:18:49 ----A---- C:\Windows_MSRSTRT.EXE
2008-11-17 21:11:29 ----N---- C:\Windows\WB.ini
2008-11-17 21:09:05 ----N---- C:\Windows\system32\wbload.dll
2008-11-17 21:09:04 ----N---- C:\Windows\system32\wbsys.dll
2008-11-17 21:09:04 ----D---- C:\Program Files\Stardock
2008-11-17 00:49:52 ----D---- C:\Program Files\Adobe
2008-11-16 22:04:33 ----D---- C:\Users\Utilisateur\AppData\Roaming\Opera
2008-11-16 22:04:05 ----D---- C:\Program Files\Opera
2008-11-16 15:51:00 ----D---- C:\Program Files\SyllabiK
2008-11-15 19:50:51 ----D---- C:\Tgl0beSCRIPT
2008-11-14 17:18:19 ----D---- C:\Program Files\CCleaner
2008-11-14 17:08:06 ----D---- C:\Program Files\Glary Utilities
2008-11-14 11:33:39 ----A---- C:\Windows\system32\difxapi.dll
2008-11-14 11:33:14 ----D---- C:\Users\Utilisateur\AppData\Roaming\InstallShield
2008-11-14 11:27:22 ----A---- C:\Windows\system32\CSVer.dll
2008-11-14 11:26:33 ----D---- C:\Intel
2008-11-14 11:07:17 ----HD---- C:\Program Files\Temp
2008-11-14 10:56:42 ----D---- C:\Windows\system32\AGEIA
2008-11-14 10:56:41 ----D---- C:\Program Files\AGEIA Technologies
2008-11-14 10:56:24 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-14 10:53:16 ----D---- C:\NVIDIA
2008-11-14 10:43:52 ----D---- C:\Program Files\ma-config.com
2008-11-14 10:43:51 ----D---- C:\ProgramData\ma-config.com
2008-11-12 14:41:21 ----A---- C:\Windows\system32\msxml6.dll
2008-11-12 14:41:19 ----A---- C:\Windows\system32\msxml3.dll
2008-11-09 19:32:25 ----D---- C:\Program Files\Trend Micro
2008-11-09 18:58:59 ----D---- C:\Users\Utilisateur\AppData\Roaming\Comodo
2008-11-09 17:33:20 ----D---- C:\Users\Utilisateur\AppData\Roaming\Malwarebytes
2008-11-09 17:33:10 ----D---- C:\ProgramData\Malwarebytes
2008-11-09 17:33:09 ----D---- C:\Program Files\Malwarebytes’ Anti-Malware
2008-11-09 16:47:51 ----A---- C:\Windows\system32\cssdll32.dll
2008-11-09 16:45:09 ----D---- C:\Program Files\COMODO
2008-11-09 16:34:00 ----A---- C:\Windows\UNZIP.DLL
2008-11-09 16:34:00 ----A---- C:\Windows\TMUPDATE.DLL
2008-11-09 16:34:00 ----A---- C:\Windows\PATCH.EXE
2008-11-09 15:20:12 ----D---- C:\ProgramData\Avira
2008-11-09 15:20:12 ----D---- C:\Program Files\Avira
2008-11-03 15:03:23 ----D---- C:\ProgramData\WindowsSearch
2008-10-28 20:53:13 ----A---- C:\Windows\system32\wersvc.dll
2008-10-28 20:53:13 ----A---- C:\Windows\system32\Faultrep.dll
2008-10-28 20:53:12 ----A---- C:\Windows\system32\win32spl.dll
======List of files/folders modified in the last 1 months======
2008-11-27 00:09:40 ----D---- C:\Windows\System32
2008-11-27 00:09:40 ----D---- C:\Windows\inf
2008-11-27 00:09:40 ----A---- C:\Windows\system32\PerfStringBackup.INI
2008-11-27 00:06:20 ----D---- C:\Windows\Prefetch
2008-11-27 00:02:18 ----D---- C:\WINDOWS
2008-11-26 23:54:31 ----D---- C:\Windows\system32\fr-FR
2008-11-26 23:53:43 ----A---- C:\Windows\system.ini
2008-11-26 23:53:13 ----D---- C:\Windows\system32\drivers
2008-11-26 23:53:12 ----D---- C:\Windows\AppPatch
2008-11-26 23:53:12 ----D---- C:\Program Files\Common Files
2008-11-26 23:51:34 ----SHD---- C:\System Volume Information
2008-11-26 21:50:52 ----D---- C:\Windows\system32\catroot2
2008-11-26 19:37:57 ----RD---- C:\Program Files
2008-11-26 19:37:41 ----SD---- C:\Windows\Downloaded Program Files
2008-11-26 18:35:33 ----D---- C:\Windows\system32\Tasks
2008-11-26 18:34:17 ----D---- C:\Program Files\Mozilla Firefox
2008-11-26 16:51:15 ----HD---- C:\ProgramData
2008-11-26 11:52:10 ----D---- C:\Windows\winsxs
2008-11-26 10:16:47 ----D---- C:\Windows\system32\catroot
2008-11-25 23:25:31 ----SHD---- C:\Windows\Installer
2008-11-24 18:27:55 ----D---- C:\Users\Utilisateur\AppData\Roaming\Skype
2008-11-24 18:25:40 ----RSD---- C:\Windows\assembly
2008-11-24 18:25:15 ----RSD---- C:\Windows\Fonts
2008-11-24 18:24:44 ----D---- C:\Program Files\OpenOffice.org 2.4
2008-11-24 18:16:09 ----D---- C:\Program Files\KeePass Password Safe
2008-11-24 17:11:40 ----D---- C:\ProgramData\Adobe
2008-11-24 15:54:13 ----D---- C:\Users\Utilisateur\AppData\Roaming\OpenOffice.org2
2008-11-22 13:29:51 ----SD---- C:\ProgramData\Microsoft
2008-11-22 13:29:48 ----SD---- C:\Users\Utilisateur\AppData\Roaming\Microsoft
2008-11-21 18:15:35 ----D---- C:\Windows\system32\LogFiles
2008-11-21 17:43:21 ----D---- C:\Users\Utilisateur\AppData\Roaming\CyberLink
2008-11-21 13:15:14 ----D---- C:\Program Files\Windows Live Safety Center
2008-11-19 14:15:44 ----D---- C:\Windows\Tasks
2008-11-19 11:22:40 ----D---- C:\Windows\system32\Macromed
2008-11-19 00:32:01 ----A---- C:\Windows\system32\jusched.exe
2008-11-19 00:32:01 ----A---- C:\Windows\system32\jureg.exe
2008-11-19 00:32:01 ----A---- C:\Windows\system32\jucheck.exe
2008-11-14 11:33:15 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-14 11:27:22 ----D---- C:\Program Files\Intel
2008-11-14 11:07:55 ----A---- C:\Windows\DIFxAPI.dll
2008-11-14 11:00:40 ----D---- C:\ProgramData\NVIDIA
2008-11-13 19:10:09 ----D---- C:\Program Files\Orange
2008-11-13 18:22:51 ----RD---- C:\Program Files\Online Services
2008-11-12 21:02:19 ----D---- C:\Windows\Debug
2008-11-12 17:29:59 ----D---- C:\ProgramData\Microsoft Help
2008-11-04 18:19:22 ----D---- C:\Windows\system32\WDI
2008-11-04 01:10:25 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; ??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2007-02-27 11840]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2008-11-25 75072]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\System32\DRIVERS\cmdguard.sys [2008-11-26 97808]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2008-11-26 25104]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R3 avgntflt;avgntflt; ??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2008-05-20 52032]
R3 BOCDRIVE;BOClean Kernel Monitor.; ??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys [2007-04-17 15376]
R3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
R3 Inspect;Comodo Firewall Network Driver; C:\Windows\system32\DRIVERS\inspect.sys [2008-11-26 72720]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\Windows\system32\drivers\LVUSBSta.sys [2007-03-06 41376]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-10-07 7380896]
R3 PID_0928;Logitech QuickCam Express(PID_0928); C:\Windows\system32\DRIVERS\LV561AV.SYS [2007-03-06 491168]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2007-10-03 99840]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S3 catchme;catchme; ??\C:\C-Fix\catchme.sys []
S3 driverhardwarev2;driverhardwarev2; ??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [2008-11-17 15360]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys []
S3 LVcKap;Logitech AEC Driver; C:\Windows\system32\DRIVERS\LVcKap.sys [2007-03-06 1669664]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\Windows\system32\DRIVERS\LVMVDrv.sys [2007-03-06 2261792]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Proxy d’horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
S3 Ser2pl;Prolific Serial port driver; C:\Windows\system32\DRIVERS\ser2pl.sys []
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 BOCore;BOCore; C:\Program Files\Comodo\CBOClean\BOCORE.exe [2007-08-07 69632]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2008-11-26 618232]
R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-09-19 65536]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2008-09-12 354840]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-11-19 79136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-10-07 203296]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S2 LVSrvLauncher;LVSrvLauncher; C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe [2007-03-06 105248]
S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2008-11-17 195752]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
-----------------EOF-----------------
J'ai eu aucun problème, merci de tes explications très claires :)