voici le rapport de combofix merci:
ComboFix 08-11-05.02 - LILIA 2008-11-06 20:20:37.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.514 [GMT 1:00]
Lancé depuis: c:\documents and settings\LILIA\Bureau\ComboFix.exe
- Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\windows\system32\cmtxga.dll
c:\windows\system32\fuuqfjyk.dll
c:\windows\system32\iwkaxvmf.ini
c:\windows\system32\kfeayjyl.dll
c:\windows\system32\lojbarwm.ini
c:\windows\system32\owxxjj.dll
c:\windows\system32\pafvytxb.ini
c:\windows\system32\szsyih.dll
c:\windows\system32\tjrrgsyi.dll
c:\windows\system32\vpcagv.dll
c:\windows\system32\ynuamwsy.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-06 au 2008-11-06 ))))))))))))))))))))))))))))))))))))
.
2008-11-06 09:28 . 2008-11-06 09:28 d-------- C:\VundoFix Backups
2008-11-05 19:56 . 2008-11-05 19:56 d-------- c:\program files\Malwarebytes’ Anti-Malware
2008-11-05 19:56 . 2008-11-05 19:56 d-------- c:\documents and settings\LILIA\Application Data\Malwarebytes
2008-11-05 19:56 . 2008-11-05 19:56 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-05 19:56 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-05 19:56 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-04 23:11 . 2008-11-04 23:11 d-------- c:\program files\Sun
2008-11-04 23:11 . 2008-06-10 02:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-03 23:23 . 2008-11-03 23:23 d-------- c:\program files\Ihsv
2008-11-02 14:14 . 2008-11-02 14:14 d-------- c:\program files\Fichiers communs\CyberLink
2008-11-01 22:43 . 2008-11-01 22:43 d-------- c:\documents and settings\LILIA\Application Data\CyberLink
2008-11-01 22:42 . 2008-11-01 22:42 d-------- c:\documents and settings\All Users\Application Data\CyberLink
2008-11-01 22:41 . 2008-11-02 14:10 d-------- c:\program files\CyberLink
2008-11-01 22:41 . 2008-11-02 14:12 29,480 --a------ c:\windows\system32\msxml3a.dll
2008-11-01 22:40 . 2008-11-01 22:40 d-------- c:\documents and settings\All Users\Application Data\Temp
2008-10-31 10:43 . 2008-10-31 10:52 d-------- C:\MsgPlusDebug
2008-10-25 19:20 . 2008-10-25 20:49 d-------- c:\program files\TimeAdjuster
2008-10-22 23:11 . 2008-10-22 23:11 d-------- c:\program files\RayV
2008-10-21 20:12 . 2008-10-22 23:22 d-------- c:\program files\SLD Codec Pack
2008-10-21 19:47 . 2008-10-21 19:47 d-------- c:\windows\report
2008-10-21 19:47 . 2008-10-21 19:17 20,521,845 --a------ c:\windows\LPT$VPN.609
2008-10-21 19:17 . 2008-10-21 19:17 d-------- c:\windows\AU_Backup
2008-10-21 19:17 . 2008-10-21 19:17 1,968,443 --a------ c:\windows\tsc.ptn
2008-10-21 19:17 . 2008-10-21 19:17 1,213,784 --a------ c:\windows\vsapi32.dll
2008-10-21 19:17 . 2008-10-21 19:17 348,229 --a------ c:\windows\TSC.exe
2008-10-21 19:17 . 2008-10-21 19:17 91,744 --a------ c:\windows\BPMNT.dll
2008-10-21 19:17 . 2008-10-21 19:17 71,749 --a------ c:\windows\hcextoutput.dll
2008-10-21 19:17 . 2008-10-21 19:53 823 --a------ c:\windows\tsc.ini
2008-10-21 19:16 . 2008-10-21 19:17 d-------- c:\windows\AU_Temp
2008-10-21 19:16 . 2008-10-21 19:16 d-------- c:\windows\AU_Log
2008-10-21 19:16 . 2008-10-21 19:17 20,521,845 --a------ c:\windows\VPTNFILE.609
2008-10-21 19:16 . 2008-10-21 19:16 507,904 --a------ c:\windows\TMUPDATE.DLL
2008-10-21 19:16 . 2008-10-21 19:16 170 --a------ c:\windows\GetServer.ini
2008-10-21 19:15 . 2008-10-21 19:15 286,720 --a------ c:\windows\PATCH.EXE
2008-10-21 19:15 . 2008-10-21 19:15 69,689 --a------ c:\windows\UNZIP.DLL
2008-10-20 22:21 . 2008-08-14 14:23 2,191,232 -----c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-20 22:21 . 2008-08-14 14:23 2,147,328 -----c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-20 22:21 . 2008-08-14 14:23 2,068,096 -----c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-20 22:21 . 2008-08-14 14:23 2,025,984 -----c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-20 22:21 . 2008-09-08 11:41 333,824 -----c— c:\windows\system32\dllcache\srv.sys
2008-10-20 22:20 . 2008-09-15 16:26 1,846,528 -----c— c:\windows\system32\dllcache\win32k.sys
2008-10-19 13:25 . 2006-10-26 18:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-10-19 13:20 . 2008-10-19 13:20 d-------- c:\program files\Microsoft Works
2008-10-19 13:18 . 2008-10-19 13:18 d-------- c:\program files\Microsoft.NET
2008-10-19 13:11 . 2008-10-19 13:11 d-------- c:\program files\Microsoft Visual Studio 8
2008-10-19 13:10 . 2008-10-20 22:30 d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-16 22:18 . 2008-10-16 22:18 d-------- c:\windows\system32\LogFiles
2008-10-16 22:18 . 2008-10-16 22:19 d-------- c:\windows\system32\drivers\UMDF
2008-10-16 22:15 . 2003-03-19 05:28 2,179,072 --------- c:\windows\system32\mfc71d.dll
2008-10-16 22:15 . 2003-03-19 04:04 765,952 --------- c:\windows\system32\msvcp71d.dll
2008-10-16 22:15 . 2002-01-05 20:16 737,280 --------- c:\windows\system32\msvcp70d.dll
2008-10-16 22:15 . 2003-03-19 04:03 544,768 --------- c:\windows\system32\msvcr71d.dll
2008-10-16 22:15 . 2002-01-05 20:16 536,576 --------- c:\windows\system32\msvcr70d.dll
2008-10-16 22:15 . 2004-06-03 11:47 385,100 --------- c:\windows\system32\MSVCRTD.DLL
2008-10-16 22:15 . 2007-10-18 11:59 201,488 --------- c:\windows\system32\MACD32.DLL
2008-10-16 22:15 . 2007-10-18 11:59 144,144 --------- c:\windows\system32\MASE32.DLL
2008-10-16 22:15 . 2007-10-18 11:59 141,584 --------- c:\windows\system32\MAMC32.DLL
2008-10-16 22:15 . 2007-10-18 11:59 63,248 --------- c:\windows\system32\MASD32.DLL
2008-10-16 22:15 . 2007-10-18 11:59 33,040 --------- c:\windows\system32\MA32.DLL
2008-10-16 22:13 . 2008-10-16 22:14 d-------- c:\program files\Pinnacle
2008-10-16 22:12 . 2008-10-16 22:12 d-------- c:\documents and settings\LILIA\Pinnacle
2008-10-15 22:35 . 2008-10-15 22:35 d-------- C:\Rain
2008-10-15 21:47 . 2008-10-15 21:47 4,484 --a------ c:\windows\system32\drivers\cpuidlep.sys
2008-10-14 08:46 . 2008-10-14 08:47 d-------- c:\program files\PDFCreator
2008-10-14 08:46 . 2004-03-09 00:00 662,288 --a------ c:\windows\system32\MSCOMCT2.OCX
2008-10-14 08:46 . 2001-10-28 16:42 116,224 --a------ c:\windows\system32\pdfcmnnt.dll
2008-10-14 08:46 . 1998-07-13 01:08 59,904 --a------ c:\windows\system32\MSCC2FR.DLL
2008-10-14 08:46 . 1998-07-06 00:00 23,552 --a------ c:\windows\system32\MSMPIDE.DLL
2008-10-13 21:23 . 2008-10-13 21:23 d-------- c:\program files\MSECache
2008-10-13 08:44 . 2008-10-13 08:44 d-------- c:\program files\K-Lite Codec Pack
2008-10-13 08:44 . 2008-07-04 07:34 860,160 --a------ c:\windows\system32\lameACM.acm
2008-10-13 08:44 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2008-10-13 08:44 . 2007-09-04 17:56 164,352 --a------ c:\windows\system32\unrar.dll
2008-10-13 08:44 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2008-10-13 08:44 . 2008-06-12 19:36 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-10-13 08:44 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-10-13 08:44 . 2007-10-03 16:03 414 --a------ c:\windows\system32\lame_acm.xml
2008-10-13 08:44 . 2008-07-30 20:09 38 --a------ c:\windows\avisplitter.ini
2008-10-06 16:16 . 2008-10-06 16:16 d-------- c:\documents and settings\LocalService\Application Data\DivX
2008-10-06 16:16 . 2007-06-14 13:41 466,048 --a------ c:\windows\system32\drivers\Ltn_stk7070P.sys
2008-10-06 16:16 . 2008-04-14 03:34 18,432 --a–c— c:\windows\system32\dllcache\bdaplgin.ax
2008-10-06 16:16 . 2008-04-14 03:34 18,432 --a------ c:\windows\system32\BdaPlgIn.ax
2008-10-06 16:16 . 2008-04-13 19:46 15,232 --a------ c:\windows\system32\drivers\MPE.sys
2008-10-06 16:16 . 2008-04-13 19:46 15,232 --a–c— c:\windows\system32\dllcache\mpe.sys
2008-10-06 16:16 . 2007-06-13 18:30 13,440 --a------ c:\windows\system32\drivers\Ltn_stkrc.sys
2008-10-06 16:16 . 2008-04-13 19:46 11,776 --a------ c:\windows\system32\drivers\BdaSup.sys
2008-10-06 16:16 . 2008-04-13 19:46 11,776 --a–c— c:\windows\system32\dllcache\bdasup.sys
2008-10-06 16:14 . 2004-07-23 08:00 446,464 --------- c:\windows\system32\HHActiveX.dll
2008-10-06 16:13 . 2006-12-01 22:54 626,688 --------- c:\windows\system32\msvcr80.dll
2008-10-06 16:13 . 2006-12-01 22:54 548,864 --------- c:\windows\system32\msvcp80.dll
2008-10-06 16:13 . 2002-01-05 12:40 487,424 --------- c:\windows\system32\MSVCP70.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 19:26 729,120 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-06 19:26 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-06 19:24 3,572 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-06 19:24 3,412,000 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-06 19:24 27,736 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-06 08:13 --------- d-----w c:\documents and settings\LILIA\Application Data\BitTorrent
2008-11-06 08:06 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-05 17:55 --------- d-----w c:\program files\Navilog1
2008-11-04 22:11 --------- d-----w c:\program files\Java
2008-11-04 22:05 --------- d-----w c:\program files\URUSoft
2008-11-04 22:01 --------- d-----w c:\program files\eMule
2008-11-04 21:10 --------- d-----w c:\program files\Zylom Games
2008-11-04 21:10 --------- d-----w c:\documents and settings\LILIA\Application Data\Zylom
2008-11-01 21:07 --------- d–h--w c:\program files\InstallShield Installation Information
2008-10-31 09:44 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-29 09:30 --------- d-----w c:\documents and settings\LILIA\Application Data\Skype
2008-10-27 10:24 --------- d-----w c:\program files\Power IE
2008-10-20 23:31 --------- d-----w c:\program files\Google
2008-10-19 13:06 --------- d-----w c:\program files\Nero
2008-10-19 13:06 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-10-19 13:00 --------- d-----w c:\program files\Red Kawa
2008-10-19 12:59 --------- d-----w c:\program files\Notepad++
2008-10-19 12:59 --------- d-----w c:\program files\AbiSuite2
2008-10-19 12:59 --------- d-----w c:\documents and settings\LILIA\Application Data\Notepad++
2008-10-19 12:58 --------- d-----w c:\program files\CVitae
2008-10-19 12:58 --------- d-----w c:\documents and settings\LILIA\Application Data\Samsung
2008-10-19 12:56 --------- d-----w c:\program files\Online TV Player 4
2008-10-19 12:20 --------- d-----w c:\program files\MSBuild
2008-10-16 21:19 --------- d-----w c:\documents and settings\All Users\Application Data\Pinnacle
2008-10-16 21:04 --------- d-----w c:\program files\Super Internet TV
2008-10-16 21:04 --------- d-----w c:\program files\SpeedFan
2008-10-16 18:45 --------- d-----w c:\documents and settings\LILIA\Application Data\DNA
2008-10-13 07:43 --------- d-----w c:\documents and settings\LILIA\Application Data\DivX
2008-10-07 21:54 --------- d-----w c:\program files\DNA
2008-10-04 14:22 --------- d-----w c:\program files\BitTorrent
2008-09-20 09:28 --------- d-----w c:\documents and settings\LILIA\Application Data\skypePM
2008-09-19 17:06 --------- d-----w c:\documents and settings\LILIA\Application Data\vlc
2008-09-19 14:56 --------- d-----w c:\documents and settings\LILIA\Application Data\Sony Corporation
2008-09-18 22:36 --------- d-----w c:\program files\Sony
2008-09-18 22:35 --------- d-----w c:\documents and settings\All Users\Application Data\Sony Corporation
2008-09-18 22:34 --------- d-----w c:\program files\Fichiers communs\Sony Shared
2008-09-17 22:07 --------- d-----w c:\program files\inKline Global
2008-09-16 12:05 --------- d-----w c:\program files\MIKSOFT
2008-09-15 00:59 --------- d-----w c:\program files\SiSoftware
2008-09-15 00:58 --------- d-----w c:\program files\Reference Assemblies
2008-09-14 20:34 --------- d-----w c:\program files\Fichiers communs\Vbox
2008-09-12 07:46 --------- d-----w c:\program files\Trend Micro
2008-09-12 07:28 --------- d-----w c:\program files\PC Inspector File Recovery
2008-09-12 07:27 --------- d-----w c:\program files\DivX
2008-09-11 19:05 --------- d-----w c:\documents and settings\LILIA\Application Data\U3
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-09-06 22:22 --------- d-----w c:\program files\Softick
2008-09-06 17:13 --------- d-----w c:\program files\Ulead Systems
2008-09-06 17:13 --------- d-----w c:\documents and settings\LILIA\Application Data\Ulead Systems
2008-09-06 17:13 --------- d-----w c:\documents and settings\All Users\Application Data\Ulead Systems
2008-09-06 16:46 --------- d—a-w c:\program files\Offre Wanadoo
2008-09-06 16:38 --------- d-----w c:\program files\Fichiers communs\Ulead Systems
2008-08-17 19:54 74,752 ----a-w c:\windows\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360]
“IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe” [2008-02-28 1828136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“c:\windows\ehome\ehtray.exe” [2005-08-05 64512]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2006-05-01 7557120]
“NVRotateSysTray”=“c:\windows\system32\nvsysrot.dll” [2006-05-01 49152]
“DLA”=“c:\windows\System32\DLA\DLACTRLW.EXE” [2005-10-06 122940]
“snpstd3”=“c:\windows\vsnpstd3.exe” [2006-09-19 827392]
“GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2007-08-24 33648]
“Tvs”=“c:\program files\TOSHIBA\Tvs\TvsTray.exe” [2006-02-02 73728]
“QuickTime Task”=“c:\program files\QuickTime\qttask.exe” [2008-05-27 413696]
“RemoteControl8”=“c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe” [2008-03-20 83240]
“PDVD8LanguageShortcut”=“c:\program files\CyberLink\PowerDVD8\Language\Language.exe” [2007-12-14 50472]
“SunJavaUpdateSched”=“c:\program files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 144784]
“AVP”=“c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe” [2008-07-29 206088]
“nwiz”=“nwiz.exe” [2006-05-01 c:\windows\system32\nwiz.exe]
“RTHDCPL”=“RTHDCPL.EXE” [2006-05-05 c:\windows\RTHDCPL.exe]
“AGRSMMSG”=“AGRSMMSG.exe” [2005-12-13 c:\windows\agrsmmsg.exe]
“TPSMain”=“TPSMain.exe” [2005-08-03 c:\windows\system32\TPSMain.exe]
“NDSTray.exe”=“NDSTray.exe” [BU]
“TFncKy”=“TFncKy.exe” [BU]
“BluetoothAuthenticationAgent”=“bthprops.cpl” [2008-04-14 c:\windows\system32\bthprops.cpl]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]
c:\documents and settings\LILIA\Menu D?marrer\Programmes\D?marrage
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Rain.lnk - c:\rain\Rain.exe [2008-10-15 183296]
c:\documents and settings\All Users\Menu D?marrer\Programmes\D?marrage
Pinnacle Streaming Server.lnk - c:\program files\Pinnacle\Shared Files\Programs\StrmServer\StrmServer.exe [2008-03-25 603408]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2006-03-26 257752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= c:\windows\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= c:\windows\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{56F9679E-7826-4C84-81F3-532071A8BCC5}”= “c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll” [2006-03-13 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.l3acm”= l3codecp.acm
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Ralink Wireless Utility.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Ralink Wireless Utility.lnk
backup=c:\windows\pss\Ralink Wireless Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a------ 2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
–a------ 2008-10-07 22:54 289088 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a------ 2008-02-28 16:07 1828136 c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
–a------ 2004-08-18 11:37 184320 c:\program files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
–a------ 2008-02-18 15:29 2221352 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2008-02-28 08:59 570664 c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCLoader]
–a------ 2008-06-23 14:24 644368 c:\program files\Pinnacle\TVCenter Pro\PMCLoader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
--------- 2008-06-12 13:14 214288 c:\program files\Pinnacle\Shared Files\Programs\Remote\remoterm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a------ 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
–a------ 2005-05-17 08:24 118784 c:\program files\Toshiba\Utilitaire de zoom TOSHIBA\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a------ 2008-09-02 16:27 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
–a------ 2006-03-03 00:02 761948 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THotkey]
–a------ 2006-08-25 12:47 356352 c:\program files\Toshiba\TOSHIBA Applet\THotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a------ 2008-08-02 12:01 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
–a------ 2005-04-11 15:08 65536 c:\program files\Toshiba\TOSCDSPD\TOSCDSPD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
--------- 2005-07-28 07:32 94208 c:\program files\Fichiers communs\Ulead Systems\AutoDetector\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Calendar Checker]
–a------ 2005-08-22 08:10 69632 c:\program files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
–a------ 2008-09-26 18:14 3660848 c:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
“DisableMonitoring”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\Program Files\DNA\btdna.exe”=
“c:\Program Files\BitTorrent\bittorrent.exe”=
“c:\Program Files\Messenger\msmsgs.exe”=
“c:\Program Files\eMule\emule.exe”=
“c:\Program Files\Java\jre1.5.0_06\launch4j-tmp\RKMediaCenter.exe”=
“c:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
“c:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\RpcAgentSrv.exe”=
“c:\Program Files\Skype\Phone\Skype.exe”=
“c:\Program Files\Veoh Networks\Veoh\VeohClient.exe”=
“c:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“c:\Program Files\Microsoft Office\Office12\GROOVE.EXE”=
“c:\Program Files\Microsoft Office\Office12\ONENOTE.EXE”=
“c:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009\WNt500x86\RpcSandraSrv.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
“AllowInboundEchoRequest”= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 cpuidlep;CpuIdle Pro System Driver;c:\windows\system32\drivers\cpuidlep.sys [2008-10-15 4484]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 X10Hid;X10 Hid Device;c:\windows\system32\Drivers\x10hid.sys [2005-11-28 7040]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-06-26 31592]
S3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 466048]
S3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 13440]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009\RpcAgentSrv.exe [2008-09-08 98488]
S3 USBSTOR;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{62c54991-7c37-11dd-ba86-000e8e18892a}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contenu du dossier ‘Tâches planifiées’
2008-11-05 c:\windows\Tasks{F897AA24-BDC3-11D1-B85B-00C04FB93981}_YOUR-6FBB7B0EF0_LILIA.job
- c:\windows\system32\mobsync.exe [2008-04-14 03:34]
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
BHO-{5a1aa012-b5ba-48ea-b5f4-36ba635d21ce} - c:\windows\system32\szsyih.dll
HKCU-Run-PMCRemote - (no file)
MSConfigStartUp-!AVG Anti-Spyware - c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\LILIA\Application Data\Mozilla\Firefox\Profiles\42nz5p8y.default
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.fr…
FF -: plugin - c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - c:\program files\Opera\program\plugins\NPOFF12.DLL
FF -: plugin - c:\program files\Opera\program\plugins\nprayvplugin.dll
FF -: plugin - c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-11-06 20:26:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: c:\windows\explorer.exe
-> c:\windows\system32\nview.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
c:\progra~1\COMMON~1\X10\Common\X10nets.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\program files\Toshiba\Commandes TOSHIBA\TFncKy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
.
.
Heure de fin: 2008-11-06 20:31:03 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-06 19:30:59
Avant-CF: 41 124 515 840 octets libres
Après-CF: 41,037,918,208 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Windows XP Media Center Edition” /noexecute=optin /fastdetect
368 — E O F — 2008-08-30 20:48:31