Voici! Je n'ai pas eu de problèmes particuliers mis à part que Combofix a automatiquement redémarré le pc en mode normal et j'ai cru comprendre que le nettoyage de CCleaner devait se faire en sans-échec. J'ai galéré pour redémarrer en sans-échec (j'ai du le redémarrer au moins 6 fois!^^). Le rapport de Combofix:
ComboFix 09-09-04.02 - Jérémy 05/09/2009 21:11.1.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.33.1036.18.3068.2454 [GMT 2:00]
Running from: c:usersJérémyDesktopComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:$recycle.binS-1-5-21-1283881387-3170061788-4188127329-500
c:$recycle.binS-1-5-21-3104540662-266364775-151224713-1143
c:$recycle.binS-1-5-21-3541030145-2230641323-1226403519-500
c:windowsInstaller1ce58.msi
c:windowsInstaller1ce5c.msi
c:windowsInstaller1ce60.msi
c:windowsInstaller1ce64.msi
c:windowsInstaller1ce68.msi
c:windowsInstaller25d569.msi
G:Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_kbiwkmfntkfcsb
-------Service_kbiwkmfntkfcsb
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.
2009-09-05 19:19 . 2009-09-05 19:19 -------- d-----w- c:usersDefaultAppDataLocal emp
2009-09-05 18:51 . 2009-09-05 18:51 -------- d-----w- C:GenProc
2009-09-05 12:25 . 2009-09-05 12:25 -------- d-----w- C:ackups
2009-09-05 12:13 . 2009-09-05 12:14 -------- d-----w- c:program filesCCleaner
2009-09-04 22:50 . 2009-09-04 22:50 401720 ----a-w- C:HiJackThis.exe
2009-09-04 20:01 . 2009-09-04 23:12 -------- d-----w- C:ToolBar SD
2009-09-04 19:04 . 2009-09-04 19:04 11952 ----a-w- c:windowssystem32avgrsstx.dll
2009-09-04 19:04 . 2009-09-04 19:04 108552 ----a-w- c:windowssystem32driversavgtdix.sys
2009-09-04 19:04 . 2009-09-04 19:04 335240 ----a-w- c:windowssystem32driversavgldx86.sys
2009-09-04 19:04 . 2009-09-04 19:04 27784 ----a-w- c:windowssystem32driversavgmfx86.sys
2009-09-04 19:04 . 2009-09-05 12:03 -------- d-----w- c:windowssystem32driversAvg
2009-09-04 19:03 . 2009-09-04 19:04 -------- d-----w- c:programdataAVG Security Toolbar
2009-09-04 19:03 . 2009-09-04 19:03 -------- d-----w- c:program filesAVG
2009-09-04 19:03 . 2009-09-04 19:03 -------- d-----w- c:programdataavg8
2009-09-04 17:13 . 2009-09-04 17:53 55656 ----a-w- c:windowssystem32driversavgntflt.sys
2009-09-03 14:16 . 2009-09-03 14:17 -------- d-----w- C:
sit
2009-09-03 13:37 . 2009-08-28 12:39 28672 ----a-w- c:windowssystem32Apphlpdm.dll
2009-09-03 13:37 . 2009-08-28 10:15 4240384 ----a-w- c:windowssystem32GameUXLegacyGDFs.dll
2009-09-03 13:34 . 2009-08-03 11:36 38160 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-09-03 13:34 . 2009-09-03 13:34 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-09-03 13:34 . 2009-09-03 13:34 -------- d-----w- c:programdataMalwarebytes
2009-09-03 13:34 . 2009-08-03 11:36 19096 ----a-w- c:windowssystem32driversmbam.sys
2009-08-31 20:00 . 2009-08-31 20:00 -------- d-----w- c:programdataWindowsSearch
2009-08-31 17:43 . 2009-08-31 18:20 -------- d-----w- c:programdataKaspersky Lab
2009-08-27 21:31 . 2009-06-15 15:24 175104 ----a-w- c:windowssystem32wdigest.dll
2009-08-27 21:31 . 2009-06-15 15:24 270848 ----a-w- c:windowssystem32schannel.dll
2009-08-27 21:31 . 2009-06-15 15:23 1256448 ----a-w- c:windowssystem32lsasrv.dll
2009-08-27 21:31 . 2009-06-15 15:22 213504 ----a-w- c:windowssystem32msv1_0.dll
2009-08-27 21:31 . 2009-06-15 15:21 499712 ----a-w- c:windowssystem32kerberos.dll
2009-08-27 21:31 . 2009-06-15 18:20 439896 ----a-w- c:windowssystem32driversksecdd.sys
2009-08-27 21:31 . 2009-06-15 15:24 72704 ----a-w- c:windowssystem32secur32.dll
2009-08-27 21:31 . 2009-06-15 12:57 9728 ----a-w- c:windowssystem32lsass.exe
2009-08-27 21:07 . 2009-08-27 21:07 -------- d-----w- c:programdataALM
2009-08-27 20:45 . 2008-04-07 03:38 22872 ----a-r- c:windowssystem32AdobePDFUI.dll
2009-08-27 20:35 . 2009-08-27 20:35 -------- d-----w- c:program filesAdobe Media Player
2009-08-27 20:33 . 2009-08-27 20:33 -------- d-----w- c:program filesCommon FilesAdobe AIR
2009-08-27 07:07 . 2009-06-22 10:22 2048 ----a-w- c:windowssystem32 zres.dll
2009-08-16 17:33 . 2009-09-04 18:55 -------- d-----w- c:programdataAvira
2009-08-16 16:25 . 2008-12-11 06:38 159600 ----a-w- c:windowssystem32driverspctgntdi.sys
2009-08-16 16:24 . 2009-09-01 16:21 206256 ----a-w- c:windowssystem32driversPCTCore.sys
2009-08-16 16:24 . 2008-12-18 09:16 73840 ----a-w- c:windowssystem32driversPCTAppEvent.sys
2009-08-16 16:24 . 2009-08-16 16:25 -------- d-----w- c:program filesCommon FilesPC Tools
2009-08-16 16:24 . 2008-12-10 09:36 64392 ----a-w- c:windowssystem32driverspctplsg.sys
2009-08-16 16:24 . 2009-09-01 19:32 -------- d-----w- c:program filesSpyware Doctor
2009-08-16 16:24 . 2009-08-16 16:24 -------- d-----w- c:programdataPC Tools
2009-08-16 13:38 . 2009-08-16 13:38 -------- d--h--w- c:windowsmsdownld.tmp
2009-08-14 20:58 . 2009-08-14 20:58 -------- d-----w- c:program filesAudacity
2009-08-13 16:57 . 2009-07-17 14:35 71680 ----a-w- c:windowssystem32atl.dll
2009-08-13 16:57 . 2009-06-10 12:12 160256 ----a-w- c:windowssystem32wkssvc.dll
2009-08-13 16:57 . 2009-06-04 12:34 2066432 ----a-w- c:windowssystem32mstscax.dll
2009-08-13 16:57 . 2009-06-10 12:07 91136 ----a-w- c:windowssystem32avifil32.dll
2009-08-13 16:57 . 2009-07-14 13:00 313344 ----a-w- c:windowssystem32wmpdxm.dll
2009-08-13 16:57 . 2009-07-14 12:58 7680 ----a-w- c:windowssystem32spwmp.dll
2009-08-13 16:57 . 2009-07-14 12:59 4096 ----a-w- c:windowssystem32dxmasf.dll
2009-08-13 16:57 . 2009-07-14 10:59 8147456 ----a-w- c:windowssystem32wmploc.DLL
2009-08-10 07:17 . 2008-06-20 01:14 97800 ----a-w- c:windowssystem32infocardapi.dll
2009-08-10 07:17 . 2008-06-20 01:14 105016 ----a-w- c:windowssystem32PresentationCFFRasterizerNative_v0300.dll
2009-08-10 07:17 . 2008-06-20 01:14 43544 ----a-w- c:windowssystem32PresentationHostProxy.dll
2009-08-10 07:17 . 2008-06-20 01:14 11264 ----a-w- c:windowssystem32icardres.dll
2009-08-10 07:17 . 2008-06-20 01:14 622080 ----a-w- c:windowssystem32icardagt.exe
2009-08-10 07:17 . 2008-06-20 01:14 781344 ----a-w- c:windowssystem32PresentationNative_v0300.dll
2009-08-10 07:17 . 2008-06-20 01:14 326160 ----a-w- c:windowssystem32PresentationHost.exe
2009-08-10 07:09 . 2008-07-27 18:03 96760 ----a-w- c:windowssystem32dfshim.dll
2009-08-10 07:09 . 2008-07-27 18:03 282112 ----a-w- c:windowssystem32mscoree.dll
2009-08-10 07:09 . 2008-07-27 18:03 41984 ----a-w- c:windowssystem32
etfxperf.dll
2009-08-10 07:09 . 2008-07-27 18:03 158720 ----a-w- c:windowssystem32mscorier.dll
2009-08-10 07:09 . 2008-07-27 18:03 83968 ----a-w- c:windowssystem32mscories.dll
2009-08-08 16:03 . 2009-08-09 16:32 1944 ----a-w- c:windowseReg.dat
2009-08-08 15:47 . 2009-08-08 15:48 -------- d-----w- c:program filesMaxis
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 12:16 . 2009-07-25 17:33 -------- d-----w- c:program filesSteam
2009-09-05 12:01 . 2009-07-25 17:36 -------- d-----w- c:program filesCommon FilesSteam
2009-09-04 09:42 . 2009-01-21 05:18 669566 ----a-w- c:windowssystem32perfh00C.dat
2009-09-04 09:42 . 2009-01-21 05:18 123556 ----a-w- c:windowssystem32perfc00C.dat
2009-09-03 14:15 . 2009-01-20 22:23 -------- d-----w- c:program filesCommon FilesAdobe
2009-09-01 16:21 . 2009-09-01 16:21 7396 ----a-w- c:windowssystem32driverspctcore.cat
2009-08-27 21:42 . 2009-07-29 08:49 -------- d-----w- c:programdataFLEXnet
2009-08-27 21:02 . 2009-07-25 15:52 -------- d-----w- c:program filesCommon FilesPX Storage Engine
2009-08-16 20:29 . 2009-01-20 22:37 -------- d-----w- c:program filesSMINST
2009-08-16 17:40 . 2009-07-25 16:01 -------- d-----w- c:program filesSpybot - Search & Destroy
2009-08-16 17:29 . 2009-01-20 21:25 -------- d-----w- c:programdataNorton
2009-08-16 16:41 . 2009-07-25 16:01 -------- d-----w- c:programdataSpybot - Search & Destroy
2009-08-14 07:55 . 2009-01-20 22:17 -------- d-----w- c:programdataMicrosoft Help
2009-08-14 07:54 . 2006-11-02 11:18 -------- d-----w- c:program filesWindows Mail
2009-08-09 16:17 . 2009-01-20 21:22 -------- d--h--w- c:program filesInstallShield Installation Information
2009-08-08 15:47 . 2009-01-20 21:22 -------- d-----w- c:program filesCommon FilesInstallShield
2009-08-03 20:58 . 2009-08-03 20:58 -------- d-----w- c:program filesCommon FilesControl Panels
2009-08-03 19:41 . 2009-08-03 19:41 -------- d-----w- c:program filesBonjour
2009-08-03 19:36 . 2009-08-03 19:36 -------- d-----w- c:program filesCommon FilesMacrovision Shared
2009-07-31 19:13 . 2009-07-31 19:13 -------- d-----w- c:program filesCommon FilesINCA Shared
2009-07-31 18:05 . 2009-07-31 18:05 -------- d-----w- c:program filesSubagames
2009-07-31 17:47 . 2009-07-31 17:47 -------- d-----w- c:programdataPMB Files
2009-07-31 17:46 . 2009-07-31 17:46 -------- d-----w- c:program filesPando Networks
2009-07-31 15:05 . 2009-07-25 13:44 -------- d-----w- c:program filesOrangeHSS
2009-07-29 21:12 . 2009-07-29 21:13 410984 ----a-w- c:windowssystem32deploytk.dll
2009-07-29 21:12 . 2009-01-20 22:33 -------- d-----w- c:program filesJava
2009-07-29 09:01 . 2009-07-29 09:01 0 ---ha-w- c:windowssystem32driversMsft_User_WpdFs_01_00_00.Wdf
2009-07-28 17:13 . 2009-01-20 22:06 -------- d-----w- c:program filesMicrosoft Works
2009-07-28 17:13 . 2006-11-02 12:37 -------- d-----w- c:program filesMSBuild
2009-07-28 17:11 . 2009-07-28 17:11 -------- d-----w- c:program filesMicrosoft.NET
2009-07-28 17:10 . 2009-07-28 17:10 -------- d-----w- c:program filesMicrosoft Visual Studio 8
2009-07-28 17:03 . 2009-07-28 17:03 -------- d-----w- c:programdataDAEMON Tools Lite
2009-07-28 17:03 . 2009-07-28 17:03 -------- d-----w- c:program filesDAEMON Tools Lite
2009-07-26 21:35 . 2009-07-26 21:35 -------- d-----w- c:program filesQuickTime
2009-07-26 21:35 . 2009-07-26 21:35 -------- d-----w- c:programdataApple Computer
2009-07-26 21:33 . 2009-07-26 21:33 -------- d-----w- c:program filesApple Software Update
2009-07-26 21:33 . 2009-07-26 21:33 -------- d-----w- c:programdataApple
2009-07-26 20:33 . 2009-07-26 20:33 -------- d-----w- c:program filesConduit
2009-07-26 20:33 . 2009-07-26 20:33 -------- d-----w- c:program filesAlcohol Soft
2009-07-26 20:29 . 2009-07-26 20:29 721904 ----a-w- c:windowssystem32driverssptd.sys
2009-07-26 20:23 . 2009-07-26 20:23 -------- d-----w- c:program files7-Zip
2009-07-26 17:46 . 2009-07-26 17:46 -------- d-----w- c:program filesBitTorrent
2009-07-25 16:25 . 2009-07-25 16:25 -------- d-----w- c:program filesMSXML 4.0
2009-07-25 16:08 . 2009-07-25 16:08 -------- d-----w- c:programdataeMule
2009-07-25 16:01 . 2009-01-20 21:25 -------- d-----w- c:programdataSymantec
2009-07-25 16:00 . 2009-07-25 16:00 -------- d-----w- c:program fileseMule
2009-07-25 15:59 . 2009-07-25 15:59 -------- d-----w- c:program filesMicrosoft
2009-07-25 15:59 . 2009-07-25 15:58 -------- d-----w- c:program filesWindows Live
2009-07-25 15:59 . 2009-07-25 15:59 -------- d-----w- c:program filesWindows Live SkyDrive
2009-07-25 15:55 . 2009-07-25 15:55 -------- d-----w- c:program filesCommon FilesWindows Live
2009-07-25 15:52 . 2009-07-25 15:52 -------- d-----w- c:program filesWinamp
2009-07-25 13:42 . 2009-07-25 13:42 -------- d-----w- c:program filesInventel
2009-07-25 13:29 . 2006-11-02 12:37 -------- d-----w- c:program filesWindows Sidebar
2009-07-25 13:27 . 2009-07-25 13:27 0 --sha-r- c:windowssystem32drivers103C_HP_cNB_Pavilion dv7 Notebook PC_Y5335KV_0U_QCNF91552W5_E510505-051_4A_I3624_SQuanta_V18.27_F.12_T090323_WV3-1_L40C_M3069_J250_7Intel_867A_92.40_#090408_N10EC8168;80864237_(NL860EA#ABF)_XMOBILE_CN10_Z_2Rev 1.MRK
2009-07-25 13:26 . 2009-07-25 13:26 -------- d-sh--we c:programdataModèles
2009-07-25 13:26 . 2009-07-25 13:26 -------- d-sh--we c:programdataMenu Démarrer
2009-07-25 13:26 . 2009-07-25 13:26 -------- d-sh--we c:programdataFavoris
2009-07-25 13:26 . 2009-07-25 13:26 -------- d-sh--we c:programdataBureau
2009-07-25 13:26 . 2009-07-25 13:26 -------- d-sh--we c:program filesFichiers communs
2009-07-21 21:52 . 2009-08-16 13:36 915456 ----a-w- c:windowssystem32wininet.dll
2009-07-21 21:47 . 2009-08-16 13:36 109056 ----a-w- c:windowssystem32iesysprep.dll
2009-07-21 21:47 . 2009-08-16 13:36 71680 ----a-w- c:windowssystem32iesetup.dll
2009-07-21 20:13 . 2009-08-16 13:36 133632 ----a-w- c:windowssystem32ieUnatt.exe
2009-06-15 15:24 . 2009-07-25 15:56 156672 ----a-w- c:windowssystem32 2embed.dll
2009-06-15 15:20 . 2009-07-25 15:56 72704 ----a-w- c:windowssystem32fontsub.dll
2009-06-15 15:20 . 2009-07-25 15:56 10240 ----a-w- c:windowssystem32dciman32.dll
2009-06-15 12:52 . 2009-07-25 15:56 289792 ----a-w- c:windowssystem32atmfd.dll
2009-01-21 05:37 . 2009-01-21 05:21 8192 --sha-w- c:windowsUsersDefaultNTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerURLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:program filesAVGAVG8ToolbarIEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOTclsid{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE~Browser Helper Objects{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:55 1090816 ----a-w- c:program filesAVGAVG8ToolbarIEToolbar.dll
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:program filesAVGAVG8ToolbarIEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOTclsid{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:program filesAVGAVG8ToolbarIEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOTclsid{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"LightScribe Control Panel"="c:program filesCommon FilesLightScribeLightScribeControlPanel.exe" [2008-06-09 2363392]
"HPAdvisor"="c:program filesHewlett-PackardHP AdvisorHPAdvisor.exe" [2008-11-18 966656]
"msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2009-02-06 3885408]
"AlcoholAutomount"="c:program filesAlcohol SoftAlcohol 120axcmd.exe" [2009-04-24 203928]
"DAEMON Tools Lite"="c:program filesDAEMON Tools Litedaemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"StartCCC"="c:program filesATI TechnologiesATI.ACECore-StaticCLIStart.exe" [2008-08-29 61440]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2008-07-24 1348904]
"SysTrayApp"="c:program filesIDTWDMsttray.exe" [2008-10-26 450659]
"DVDAgent"="c:program filesHewlett-PackardMediaDVDDVDAgent.exe" [2008-11-28 1148200]
"TSMAgent"="c:program filesHewlett-PackardTouchSmartMediaTSMAgent.exe" [2008-12-25 1316136]
"CLMLServer for HP TouchSmart"="c:program filesHewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe" [2008-12-25 189736]
"TVAgent"="c:program filesHewlett-PackardMediaTVTVAgent.exe" [2009-01-21 210216]
"UCam_Menu"="c:program filesHewlett-PackardMediaWebcamMUITransferMUIStartMenu.exe" [2008-11-14 218408]
"SmartMenu"="c:program filesHewlett-PackardHP MediaSmartSmartMenu.exe" [2008-11-18 914224]
"UpdateLBPShortCut"="c:program filesCyberLinkLabelPrintMUITransferMUIStartMenu.exe" [2008-06-13 210216]
"UpdatePSTShortCut"="c:program filesCyberLinkDVD SuiteMUITransferMUIStartMenu.exe" [2008-11-26 210216]
"DpAgent"="c:program filesDigitalPersonaBindpagent.exe" [2008-12-10 842816]
"Windows Defender"="c:program filesWindows DefenderMSASCui.exe" [2008-01-21 1008184]
"QlbCtrl.exe"="c:program filesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe" [2008-10-10 206128]
"UpdateP2GoShortCut"="c:program filesCyberLinkPower2GoMUITransferMUIStartMenu.exe" [2008-10-30 210216]
"UpdatePDIRShortCut"="c:program filesCyberLinkPowerDirectorMUITransferMUIStartMenu.exe" [2008-06-13 210216]
"SunJavaUpdateSched"="c:program filesJavajre6injusched.exe" [2009-07-29 148888]
"HP Health Check Scheduler"="c:program filesHewlett-PackardHP Health CheckHPHC_Scheduler.exe" [2008-10-09 75008]
"WirelessAssistant"="c:program filesHewlett-PackardHP Wireless AssistantHPWAMain.exe" [2008-12-08 432432]
"GrooveMonitor"="c:program filesMicrosoft OfficeOffice12GrooveMonitor.exe" [2008-10-25 31072]
"ISTray"="c:program filesSpyware DoctorpctsTray.exe" [2009-07-22 1181064]
"AdobeCS4ServiceManager"="c:program filesCommon FilesAdobeCS4ServiceManagerCS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:program filesAdobeAcrobat 9.0AcrobatAcrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:program filesAdobeAcrobat 9.0AcrobatAcrotray.exe" [2008-06-11 640376]
"AVG8_TRAY"="c:progra~1AVGAVG8avgtray.exe" [2009-09-04 2007832]
c:usersJ,r,myAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
OneNote 2007 Screen Clipper and Launcher.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2008-10-25 98696]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:windowsSystem32avgrsstx.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrollsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdauxservice]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsdcoreservice]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWinDefend]
@="Service"
[HKLM~servicessharedaccessparametersfirewallpolicyFirewallRules]
"{08BDAF68-55F3-4121-BB29-2F13B873373D}"= c:program filesCyberLinkPowerDirectorPDR.EXE:CyberLink PowerDirector
"{DE2CEE9D-9321-4227-AAB0-58E1E6257646}"= c:program filesHewlett-PackardMediaDVDHPTouchSmartMusic.exe:HP TouchSmart Music
"{CB367A9B-C87A-41EC-A1C2-A6D15B3FEF0F}"= c:program filesHewlett-PackardMediaDVDHPTouchSmartPhoto.exe:HP TouchSmart Photo
"{C562C992-9450-4E18-883D-3435881D2F4D}"= c:program filesHewlett-PackardMediaDVDHPTouchSmartVideo.exe:HP TouchSmart Video
"{1A81E2A1-8738-42D1-AB92-2B0F9C74C540}"= c:program filesHewlett-PackardMediaDVDTSMAgent.exe:HP TouchSmart Media Resident Program
"{9270F252-1697-491D-BD37-130886841509}"= c:program filesHewlett-PackardMediaDVDKernelCLMLCLMLSvc.exe:CyberLink Media Service
"{04626E5E-B82C-44CA-AA03-1DA32AB9D577}"= c:program filesHewlett-PackardMediaDVDHPDVDSmart.exe:HP MediaSmart DVD
"{540748A3-18FE-46D9-AB4A-76BAAD087475}"= c:program filesHewlett-PackardTouchSmartMediaHPTouchSmartMusic.exe:HP TouchSmart Music
"{7B1CD12D-F50B-4538-AEE6-F8549983C645}"= c:program filesHewlett-PackardTouchSmartMediaHPTouchSmartPhoto.exe:HP TouchSmart Photo
"{049DFB47-3690-41A4-A5FA-181A9E50C3F7}"= c:program filesHewlett-PackardTouchSmartMediaHPTouchSmartVideo.exe:HP TouchSmart Video
"{8EC4A3F0-4EE5-42EF-9ABE-323D912F8986}"= c:program filesHewlett-PackardTouchSmartMediaTSMAgent.exe:HP TouchSmart Media Resident Program
"{EE7C03C2-9517-4F21-BA17-C05E0CF20322}"= c:program filesHewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe:CyberLink Media Service
"{62675AB8-F84C-412E-9BFC-AE81AA570F19}"= c:program filesHewlett-PackardMediaTVQP.exe:Quick Play
"{E69F0C33-831E-485C-BD5B-DC562B975AFE}"= c:program filesHewlett-PackardMediaTVQPService.exe:Quick Play Resident Program
"{1B047EC0-6BA1-4181-8C68-DCFB9ACB65A4}"= UDP:c:program filesBitTorrentittorrent.exe:BitTorrent
"{855DC5F9-136F-491E-AA6E-4D499735E78C}"= TCP:c:program filesBitTorrentittorrent.exe:BitTorrent
"{03E43EFA-714F-4829-9BEE-018EF54456AD}"= TCP:6004|c:program filesMicrosoft OfficeOffice12outlook.exe:Microsoft Office Outlook
"{5FCE599A-B22E-4798-B82B-5F66BD6F3A8F}"= UDP:c:program filesMicrosoft OfficeOffice12GROOVE.EXE:Microsoft Office Groove
"{BF9978B8-5AC2-4298-8C08-C8C061E2FBB5}"= TCP:c:program filesMicrosoft OfficeOffice12GROOVE.EXE:Microsoft Office Groove
"{A3EA9076-9EC1-4A4A-9E4A-A399E626AA0F}"= UDP:c:program filesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{8C48552D-0A68-48CB-8BC5-DBD03CA395C8}"= TCP:c:program filesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{2F9C2E6E-34BE-46DD-AF83-7AE67F91E152}"= UDP:c:program filesPando NetworksMedia BoosterPMB.exe:Pando Media Booster
"{44CB829A-67DF-4FC0-AF3A-E1C02394ABC8}"= TCP:c:program filesPando NetworksMedia BoosterPMB.exe:Pando Media Booster
"{1B59B033-E7CD-4E07-BA33-ACCA84B076FC}"= UDP:c:program filesPando NetworksMedia BoosterPMB.exe:Pando Media Booster
"{876AE505-1769-47FC-851B-EC2D636DDE38}"= TCP:c:program filesPando NetworksMedia BoosterPMB.exe:Pando Media Booster
"{716BBB31-C1F1-4178-8485-6892B3E93218}"= c:program filesPando NetworksMedia BoosterPMB.exe:Pando Media Booster
"TCP Query User{AEADD17E-4BFE-45B3-A6CB-88716A093B42}c:\users\jérémy\downloads\half-life all\hl.exe"= UDP:c:usersjérémydownloadshalf-life allhl.exe:hl.exe
"UDP Query User{F1ECFBF8-8052-498F-970A-7E0E99E94A8C}c:\users\jérémy\downloads\half-life all\hl.exe"= TCP:c:usersjérémydownloadshalf-life allhl.exe:hl.exe
"TCP Query User{3C486731-B138-4ED0-BD7A-62F73D859621}c:\program files\steam\steamapps\joelrobuchon\half-life 2 deathmatch\hl2.exe"= UDP:c:program filessteamsteamappsjoelrobuchonhalf-life 2 deathmatchhl2.exe:hl2
"UDP Query User{044BBA2B-7CAA-49CC-8EB3-802B7558CD72}c:\program files\steam\steamapps\joelrobuchon\half-life 2 deathmatch\hl2.exe"= TCP:c:program filessteamsteamappsjoelrobuchonhalf-life 2 deathmatchhl2.exe:hl2
"{3409A97C-B435-4854-BF88-7AFAC649CAC4}"= UDP:5353:Adobe CSI CS4
"{AC70215B-24C2-4817-898B-F1F2147C95E7}"= UDP:c:program filesCommon FilesAdobeCS4ServiceManagerCS4ServiceManager.exe:Adobe CSI CS4
"{F3ED4FD9-CE7E-45EB-99A2-5B4D78796FBF}"= TCP:c:program filesCommon FilesAdobeCS4ServiceManagerCS4ServiceManager.exe:Adobe CSI CS4
"{4C419408-1573-443C-899C-333388CDD83E}"= UDP:3703:Adobe Version Cue CS4 Server
"{5B1EC251-4464-41DB-A50B-325925701CA9}"= UDP:3704:Adobe Version Cue CS4 Server
"{23BB9FA5-ADD7-4219-AD84-4E94CFF7C1F6}"= UDP:51000:Adobe Version Cue CS4 Server
"{9626E65C-4772-4523-91C6-9FAED7FF6FBF}"= UDP:51001:Adobe Version Cue CS4 Server
"{096FF436-F08D-44C6-A2DC-66772D004FFB}"= UDP:c:program filesCommon FilesAdobeAdobe Version Cue CS4ServerinVersionCueCS4.exe:Adobe Version Cue CS4 Server
"{BF4684B2-EDDF-4631-B4EA-72A5788FFED8}"= TCP:c:program filesCommon FilesAdobeAdobe Version Cue CS4ServerinVersionCueCS4.exe:Adobe Version Cue CS4 Server
"{60D59089-E2AF-4693-8AAE-3B5431D38365}"= c:program filesAVGAVG8avgupd.exe:avgupd.exe
"{E9354154-DBA7-4091-9963-1E9EE4EC766D}"= c:program filesAVGAVG8avgnsx.exe:avgnsx.exe
R0 PCTCore;PCTools KDS;c:windowsSystem32driversPCTCore.sys [16/08/2009 18:24 206256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:windowsSystem32driversavgldx86.sys [04/09/2009 21:04 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:windowsSystem32driversavgtdix.sys [04/09/2009 21:04 108552]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/04/08 04:18];c:program filesHewlett-PackardMediaDVD 00.fcl [28/11/2008 18:04 87536]
R2 AESTFilters;Andrea ST Filters Service;c:windowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbAEstSrv.exe [08/04/2009 03:46 77824]
R2 avg8wd;AVG Free8 WatchDog;c:progra~1AVGAVG8avgwdsvc.exe [04/09/2009 21:03 297752]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:windowssystem32svchost.exe -k netsvcs [21/01/2008 04:23 21504]
R2 hpsrv;HP Service;c:windowsSystem32hpservice.exe [18/03/2008 16:24 19456]
R2 Recovery Service for Windows;Recovery Service for Windows;c:program filesSMINSTBLService.exe [21/01/2009 00:37 365952]
R2 sdAuxService;PC Tools Auxiliary Service;c:program filesSpyware DoctorpctsAuxs.exe [16/08/2009 18:24 348752]
R2 TVCapSvc;TV Background Capture Service (TVBCS);c:program filesHewlett-PackardMediaTVKernelTVTVCapSvc.exe [26/11/2008 17:13 296320]
R2 TVSched;TV Task Scheduler (TVTS);c:program filesHewlett-PackardMediaTVKernelTVTVSched.exe [26/11/2008 17:13 116096]
R2 vfsFPService;Validity Fingerprint Service;c:windowsSystem32vfsFPService.exe [18/11/2008 06:09 599344]
R3 enecir;ENE CIR Receiver;c:windowsSystem32driversenecir.sys [04/09/2008 19:47 54784]
R3 JMCR;JMCR;c:windowsSystem32driversjmcr.sys [23/10/2008 11:42 107360]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:windowsSystem32driversNETw5v32.sys [08/04/2009 03:48 3664384]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:program filesCommon FilesAdobeAdobe Version Cue CS4ServerinVersionCueCS4.exe [15/08/2008 05:46 284016]
S3 Com4QLBEx;Com4QLBEx;c:program filesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe [20/01/2009 23:38 222512]
S3 npggsvc;nProtect GameGuard Service;c:windowssystem32GameMon.des -service --> c:windowssystem32GameMon.des -service [?]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:windowsSystem32driversPCAMp50.sys [25/07/2009 17:47 28224]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:windowsSystem32
undll32.exe" "c:windowsSystem32iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:program filesCommon FilesLightScribeLSRunOnce.exe"
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-*{ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
HKLM-Run-SystrayORAHSS - c:program filesOrangeHSSSystraySystrayApp.exe
.
------- Supplementary Scan -------
.
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: &Recherche AOL Toolbar - c:programdataAOLieToolbar
esourcesfr-FRlocalsearch.html
IE: Ajouter la cible du lien à un fichier PDF existant - c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:program filesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xporter vers Microsoft Excel - c:progra~1MICROS~3Office12EXCEL.EXE/3000
TCP: {CA084F4B-1BFB-49A8-9D8F-E6DCD338A5CF} = 192.168.1.1
FF - ProfilePath - c:usersJérémyAppDataRoamingMozillaFirefoxProfilesh6vwfesu.default
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - prefs.js: keyword.URL -
hxxp://fr.yhs.search.yahoo.com/avg/sear ... -web_fr&p=
FF - plugin: c:program filesMozilla Firefoxplugins
pPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-05 21:22
Windows 6.0.6001 Service Pack 1 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINESYSTEMControlSet001Services
pggsvc]
"ImagePath"="c:windowssystem32GameMon.des -service"
[HKEY_LOCAL_MACHINESYSTEMControlSet001Services{55662437-DA8C-40c0-AADA-2C816A897A49}]
"ImagePath"="??c:program filesHewlett-PackardMediaDVD 00.fcl"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(716)
c:windowssystem32DPPWDFLT.dll
- - - - - - - > 'Explorer.exe'(2540)
c:program filesSpyware Doctorpctgmhk.dll
c:program filesMicrosoft OfficeOffice12GrooveUtil.DLL
c:program filesCommon FilesAdobeAdobe Drive CS4AdobeDriveCS4_NP.dll
.
------------------------ Other Running Processes ------------------------
.
c:windowsSystem32Ati2evxx.exe
c:windowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbstacsv.exe
c:windowsSystem32audiodg.exe
c:windowsSystem32Ati2evxx.exe
c:program filesDigitalPersonaBinDpHostW.exe
c:program filesBonjourmDNSResponder.exe
c:program filesCommon FilesLightScribeLSSrvc.exe
c:program filesCyberLinkShared filesRichVideo.exe
c:program filesSpyware DoctorpctsSvc.exe
c:progra~1AVGAVG8avgrsx.exe
c:progra~1AVGAVG8avgnsx.exe
c:program filesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe
c:program filesHewlett-PackardHP Health CheckHPHC_Service.exe
.
**************************************************************************
.
Completion time: 2009-09-05 21:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 19:30
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 102 097 776 640 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
372 --- E O F --- 2009-09-04 01:00
Le rapport Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:05, on 05/09/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:WindowsSystem32smss.exe
C:Windowssystem32csrss.exe
C:Windowssystem32wininit.exe
C:Windowssystem32csrss.exe
C:Windowssystem32services.exe
C:Windowssystem32lsass.exe
C:Windowssystem32lsm.exe
C:Windowssystem32winlogon.exe
C:Windowssystem32svchost.exe
C:Windowssystem32svchost.exe
C:WindowsSystem32svchost.exe
C:Windowssystem32Ati2evxx.exe
C:WindowsSystem32svchost.exe
C:WindowsSystem32svchost.exe
C:Windowssystem32svchost.exe
C:WindowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbSTacSV.exe
C:Windowssystem32svchost.exe
C:Windowssystem32SLsvc.exe
C:Windowssystem32svchost.exe
C:Windowssystem32Hpservice.exe
C:Windowssystem32Ati2evxx.exe
C:Windowssystem32vfsFPService.exe
C:Windowssystem32svchost.exe
C:WindowsSystem32spoolsv.exe
C:Program FilesDigitalPersonaBinDpHostW.exe
C:Windowssystem32Dwm.exe
C:Windowssystem32 askeng.exe
C:WindowsExplorer.EXE
C:Windowssystem32svchost.exe
C:WindowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbaestsrv.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesCommon FilesLightScribeLSSrvc.exe
C:Windowssystem32svchost.exe
C:Program FilesSMINSTBLService.exe
C:Program FilesCyberLinkShared filesRichVideo.exe
C:Windowssystem32 askeng.exe
C:Program FilesSpyware DoctorpctsAuxs.exe
C:Program FilesSpyware DoctorpctsSvc.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesIDTWDMsttray.exe
C:Program FilesHewlett-PackardMediaDVDDVDAgent.exe
C:Program FilesHewlett-PackardTouchSmartMediaTSMAgent.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticMOM.exe
C:Program FilesHewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe
C:Program FilesHewlett-PackardHP MediaSmartSmartMenu.exe
C:PROGRA~1AVGAVG8avgrsx.exe
C:PROGRA~1AVGAVG8avgnsx.exe
C:Program FilesDigitalPersonaBinDpAgent.exe
C:Program FilesWindows DefenderMSASCui.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQLBCTRL.exe
C:Program FilesJavajre6injusched.exe
C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe
C:Program FilesSpyware DoctorpctsTray.exe
C:Windowssystem32svchost.exe
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe
C:Program FilesHewlett-PackardMediaTVKernelTVTVCapSvc.exe
C:Program FilesAdobeAcrobat 9.0Acrobatacrotray.exe
C:Program FilesHewlett-PackardMediaTVKernelTVTVSched.exe
C:WindowsSystem32svchost.exe
C:Windowssystem32SearchIndexer.exe
C:Program FilesAVGAVG8avgtray.exe
C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe
C:Program FilesHewlett-PackardHP AdvisorHPAdvisor.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesDAEMON Tools Litedaemon.exe
C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
C:Program FilesHewlett-PackardSharedhpqwmiex.exe
C:Windowssystem32wbemwmiprvse.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe
C:Program FilesSynapticsSynTPSynTPHelper.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticCCC.exe
C:WindowsMicrosoft.NetFrameworkv3.0WPFPresentationFontCache.exe
C:Program FilesHewlett-PackardSharedhpqToaster.exe
C:Windowssystem32conime.exe
c:Program FilesHewlett-PackardHP Health Checkhphc_service.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesWindows LiveContactswlcomm.exe
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32SearchFilterHost.exe
C:HiJackThis.exe
C:Windowssystem32wbemwmiprvse.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:Program FilesAVGAVG8ToolbarIEToolbar.dll
R3 - URLSearchHook: (no name) - *{08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:Program FilesAdobe/Adobe Contribute CS4/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:Program FilesAVGAVG8avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:Program FilesAOLAOL Toolbar 5.0aoltb.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:Program FilesAVGAVG8ToolbarIEToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6injp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:Program FilesAOLAOL Toolbar 5.0aoltb.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:Program FilesAdobe/Adobe Contribute CS4/contributeieplugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:Program FilesAVGAVG8ToolbarIEToolbar.dll
O4 - HKLM..Run: [StartCCC] "C:Program FilesATI TechnologiesATI.ACECore-StaticCLIStart.exe" MSRun
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [SysTrayApp] %ProgramFiles%IDTWDMsttray.exe
O4 - HKLM..Run: [DVDAgent] "C:Program FilesHewlett-PackardMediaDVDDVDAgent.exe"
O4 - HKLM..Run: [TSMAgent] "C:Program FilesHewlett-PackardTouchSmartMediaTSMAgent.exe"
O4 - HKLM..Run: [CLMLServer for HP TouchSmart] "C:Program FilesHewlett-PackardTouchSmartMediaKernelCLMLCLMLSvc.exe"
O4 - HKLM..Run: [TVAgent] "C:Program FilesHewlett-PackardMediaTVTVAgent.exe"
O4 - HKLM..Run: [UCam_Menu] "C:Program FilesHewlett-PackardMediaWebcamMUITransferMUIStartMenu.exe" "C:Program FilesHewlett-PackardMediaWebcam" update "SoftwareHewlett-PackardMediaWebcam"
O4 - HKLM..Run: [SmartMenu] %ProgramFiles%Hewlett-PackardHP MediaSmartSmartMenu.exe
O4 - HKLM..Run: [UpdateLBPShortCut] "C:Program FilesCyberLinkLabelPrintMUITransferMUIStartMenu.exe" "C:Program FilesCyberLinkLabelPrint" UpdateWithCreateOnce "SoftwareCyberLinkLabelPrint2.5"
O4 - HKLM..Run: [UpdatePSTShortCut] "C:Program FilesCyberLinkDVD SuiteMUITransferMUIStartMenu.exe" "C:Program FilesCyberLinkDVD Suite" UpdateWithCreateOnce "SoftwareCyberLinkPowerStarter"
O4 - HKLM..Run: [DpAgent] C:Program FilesDigitalPersonaBindpagent.exe
O4 - HKLM..Run: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
O4 - HKLM..Run: [QlbCtrl.exe] C:Program FilesHewlett-PackardHP Quick Launch ButtonsQlbCtrl.exe /Start
O4 - HKLM..Run: [UpdateP2GoShortCut] "C:Program FilesCyberLinkPower2GoMUITransferMUIStartMenu.exe" "C:Program FilesCyberLinkPower2Go" UpdateWithCreateOnce "SOFTWARECyberLinkPower2Go6.0"
O4 - HKLM..Run: [UpdatePDIRShortCut] "C:Program FilesCyberLinkPowerDirectorMUITransferMUIStartMenu.exe" "C:Program FilesCyberLinkPowerDirector" UpdateWithCreateOnce "SOFTWARECyberLinkPowerDirector7.0"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6injusched.exe"
O4 - HKLM..Run: [HP Health Check Scheduler] c:Program FilesHewlett-PackardHP Health CheckHPHC_Scheduler.exe
O4 - HKLM..Run: [WirelessAssistant] C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
O4 - HKLM..Run: [GrooveMonitor] "C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe"
O4 - HKLM..Run: [ISTray] "C:Program FilesSpyware DoctorpctsTray.exe"
O4 - HKLM..Run: [AdobeCS4ServiceManager] "C:Program FilesCommon FilesAdobeCS4ServiceManagerCS4ServiceManager.exe" -launchedbylogin
O4 - HKLM..Run: [Adobe Acrobat Speed Launcher] "C:Program FilesAdobeAcrobat 9.0AcrobatAcrobat_sl.exe"
O4 - HKLM..Run: [Acrobat Assistant 8.0] "C:Program FilesAdobeAcrobat 9.0AcrobatAcrotray.exe"
O4 - HKLM..Run: [Adobe_ID0ENQBO] C:PROGRA~1COMMON~1AdobeADOBEV~2ServerinVERSIO~2.EXE
O4 - HKLM..Run: [AVG8_TRAY] C:PROGRA~1AVGAVG8avgtray.exe
O4 - HKCU..Run: [LightScribe Control Panel] C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe -hidden
O4 - HKCU..Run: [HPAdvisor] C:Program FilesHewlett-PackardHP AdvisorHPAdvisor.exe autorun=AUTORUN
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [AlcoholAutomount] "C:Program FilesAlcohol SoftAlcohol 120axcmd.exe" /automount
O4 - HKCU..Run: [DAEMON Tools Lite] "C:Program FilesDAEMON Tools Litedaemon.exe" -autorun
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O8 - Extra context menu item: &Recherche AOL Toolbar - C:ProgramDataAOLieToolbar
esourcesfr-FRlocalsearch.html
O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant -
res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Ajouter à un fichier PDF existant -
res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir au format Adobe PDF -
res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF -
res://C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O17 - HKLMSystemCCSServicesTcpip..{CA084F4B-1BFB-49A8-9D8F-E6DCD338A5CF}: NameServer = 192.168.1.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:Program FilesAVGAVG8avgpp.dll
O20 - AppInit_DLLs: C:WindowsSystem32avgrsstx.dll
O23 - Service: Adobe Version Cue CS4 - Adobe Systems Incorporated - C:Program FilesCommon FilesAdobeAdobe Version Cue CS4ServerinVersionCueCS4.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:WindowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbaestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:Windowssystem32Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:PROGRA~1AVGAVG8avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:Program FilesBonjourmDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardHP Quick Launch ButtonsCom4QLBEx.exe
O23 - Service: @C:Program FilesDigitalPersonaBinDpHostW.exe,-128 (DpHost) - DigitalPersona, Inc. - C:Program FilesDigitalPersonaBinDpHostW.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:Program FilesCommon FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:Program FilesHP GamesMy HP Game ConsoleGameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:Program FilesHewlett-PackardHP Health Checkhphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:Program FilesHewlett-PackardSharedhpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:Windowssystem32Hpservice.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program FilesCommon FilesLightScribeLSSrvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:Windowssystem32GameMon.des.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:Program FilesSMINSTBLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared filesRichVideo.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware DoctorpctsSvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:WindowsSystem32DriverStoreFileRepositorystwrt.inf_52c73ccbSTacSV.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:Program FilesCommon FilesSteamSteamService.exe
O23 - Service: TV Background Capture Service (TVBCS) (TVCapSvc) - Unknown owner - C:Program FilesHewlett-PackardMediaTVKernelTVTVCapSvc.exe
O23 - Service: TV Task Scheduler (TVTS) (TVSched) - Unknown owner - C:Program FilesHewlett-PackardMediaTVKernelTVTVSched.exe
O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:Windowssystem32vfsFPService.exe
--
End of file - 15521 bytes
Le rapport GenProc :
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
Etape 1/ Télécharge :
ToolsCleaner! (A.Rothstein & Dj QUIOU) sur ton Bureau.
Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:TCleaner.txt
Etape 3/
Poste un rapport Nod32 (il faut utiliser Internet Explorer)
- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
C:Program FilesEsetOnlineScannerlog.txt