desole de ne pas avoir repondu plus tot le travaille
bref eorezo bho a ete enleve et voici le compte rendu
ComboFix 09-01-08.05 - cyril 2009-01-09 15:46:03.1 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.999 [GMT 1:00]
Lancé depuis: c:userscyrilDesktopComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-Secure
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-SecureSpyware-Secure trial.lnk
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-SecureWebsite.lnk
c:userscyrilAppDataLocalqgacg.dat
c:userscyrilAppDataLocalqgacg.exe
c:userscyrilAppDataLocalqgacg_nav.dat
c:userscyrilAppDataLocalqgacg_navps.dat
c:usersmathisDesktopSpyware-Secure trial.lnk
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-09 au 2009-01-09 ))))))))))))))))))))))))))))))))))))
.
2009-01-08 16:33 . 2009-01-08 16:33 <REP> d-------- c:program filesFree.fr
2009-01-07 12:33 . 2008-12-13 07:23 1,659,392 --a------ c:windowsSystem32mshtml.tlb
2009-01-06 20:11 . 2009-01-06 20:11 <REP> d-------- c:program filesPackard Bell ImageWriter
2009-01-06 14:13 . 2008-08-22 11:08 1,415,680 --a------ c:windowsSystem32inetcpl.cpl
2009-01-06 14:13 . 2008-08-22 11:08 878,592 --a------ c:windowsSystem32wininet.dll
2009-01-06 14:13 . 2008-08-22 11:08 385,024 --a------ c:windowsSystem32html.iec
2009-01-06 14:13 . 2008-08-22 11:05 168,960 --a------ c:windowsSystem32iexpress.exe
2009-01-06 14:13 . 2008-08-22 11:04 45,568 --a------ c:windowsSystem32mshta.exe
2009-01-05 15:29 . 2009-01-05 15:29 <REP> d-------- C:inetpub
2009-01-05 15:16 . 2009-01-05 15:40 <REP> d-------- c:program filesmozilla.org
2009-01-03 17:20 . 2009-01-03 17:20 <REP> d-------- c:userscyrilAppDataRoamingPeerNetworking
2009-01-03 15:51 . 2009-01-05 15:17 8,273 --a------ c:windowsmozver.dat
2009-01-03 15:51 . 2009-01-03 15:51 335 --a------ c:windows
sreg.dat
2009-01-02 19:15 . 2009-01-02 19:15 <REP> d-------- c:usersarbaraAppDataRoamingInstallShield
2009-01-02 16:16 . 2009-01-02 16:16 <REP> d-------- C:fbxusb
2008-12-31 11:19 . 2008-12-31 11:19 <REP> d-------- C:pnp
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:usersAll UsersSymantec Temporary Files
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:programdataSymantec Temporary Files
2008-12-29 13:18 . 2008-12-29 13:18 <REP> d-------- c:program filesCommon FilesCanon
2008-12-29 12:43 . 2008-12-29 13:27 <REP> d-------- c:userscyrilAppDataRoamingU3
2008-12-19 18:32 . 2008-10-22 02:22 2,048 --a------ c:windowsSystem32 zres.dll
2008-12-19 16:18 . 2008-11-01 02:21 4,240,384 --a------ c:windowsSystem32GameUXLegacyGDFs.dll
2008-12-19 16:18 . 2008-10-29 07:29 2,927,104 --a------ c:windowsexplorer.exe
2008-12-19 16:18 . 2008-09-05 06:14 1,191,936 --a------ c:windowsSystem32msxml3.dll
2008-12-19 16:18 . 2008-10-21 06:25 296,960 --a------ c:windowsSystem32gdi32.dll
2008-12-19 16:18 . 2008-10-22 04:57 241,152 --a------ c:windowsSystem32PortableDeviceApi.dll
2008-12-19 16:18 . 2008-08-27 02:05 212,480 --a------ c:windowsSystem32driversmrxsmb10.sys
2008-12-19 16:18 . 2008-09-18 05:56 147,456 --a------ c:windowsSystem32Faultrep.dll
2008-12-19 16:18 . 2008-09-18 05:56 125,952 --a------ c:windowsSystem32wersvc.dll
2008-12-19 16:18 . 2008-11-01 04:44 28,672 --a------ c:windowsSystem32Apphlpdm.dll
2008-12-19 16:17 . 2008-06-23 02:59 2,868,736 --a------ c:windowsSystem32mf.dll
2008-12-19 16:17 . 2008-10-21 06:25 1,645,568 --a------ c:windowsSystem32connect.dll
2008-12-19 16:17 . 2008-09-10 04:40 1,334,272 --a------ c:windowsSystem32msxml6.dll
2008-12-19 16:17 . 2008-06-23 02:59 996,352 --a------ c:windowsSystem32WMNetMgr.dll
2008-12-19 16:17 . 2008-08-28 04:40 712,704 --a------ c:windowsSystem32WindowsCodecs.dll
2008-12-19 16:17 . 2008-08-12 04:39 443,392 --a------ c:windowsSystem32win32spl.dll
2008-12-19 16:17 . 2008-08-28 04:40 425,472 --a------ c:windowsSystem32PhotoMetadataHandler.dll
2008-12-19 16:17 . 2008-08-28 04:40 347,136 --a------ c:windowsSystem32WindowsCodecsExt.dll
2008-12-19 16:17 . 2008-06-23 02:58 94,720 --a------ c:windowsSystem32logagent.exe
2008-12-19 16:05 . 2008-10-16 22:13 1,809,944 --a------ c:windowsSystem32wuaueng.dll
2008-12-19 16:05 . 2008-10-16 21:56 1,524,736 --a------ c:windowsSystem32wucltux.dll
2008-12-19 16:05 . 2008-10-16 22:09 51,224 --a------ c:windowsSystem32wuauclt.exe
2008-12-19 16:05 . 2008-10-16 22:09 43,544 --a------ c:windowsSystem32wups2.dll
2008-12-19 16:04 . 2008-10-16 22:12 561,688 --a------ c:windowsSystem32wuapi.dll
2008-12-19 16:04 . 2008-10-16 14:08 162,064 --a------ c:windowsSystem32wuwebv.dll
2008-12-19 16:04 . 2008-10-16 21:55 83,456 --a------ c:windowsSystem32wudriver.dll
2008-12-19 16:04 . 2008-10-16 22:08 34,328 --a------ c:windowsSystem32wups.dll
2008-12-19 16:04 . 2008-10-16 13:56 31,232 --a------ c:windowsSystem32wuapp.exe
2008-12-19 14:58 . 2007-06-01 18:36 870,400 --a------ c:windowsSystem32driversWPN111v.sys
2008-12-12 22:47 . 2008-12-12 22:47 3,751,995 --a------ c:windowsSystem32GPhotos.scr
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 15:55 --------- d-----w c:program filesGoogle
2009-01-08 14:43 --------- d-----w c:program filesHDReg
2009-01-07 20:56 --------- d--h--w c:program filesInstallShield Installation Information
2009-01-06 19:11 --------- d-----w c:program filesPackard Bell
2009-01-02 16:56 --------- d-----w c:usersarbaraAppDataRoamingPackard Bell
2009-01-02 15:07 --------- d-----w c:program filesCyberLink
2008-12-31 16:16 --------- d-----w c:usersarbaraAppDataRoamingSymantec
2008-12-31 15:30 --------- d-----w c:usersarbaraAppDataRoamingEoRezo
2008-12-31 12:41 --------- d-----w c:programdataNVIDIA
2008-12-31 11:43 --------- d-----w c:userscyrilAppDataRoamingSkype
2008-12-31 10:19 --------- d-----w c:programdataTemplates
2008-12-31 10:19 --------- d-----w c:programdataStart Menu
2008-12-31 10:19 --------- d-----w c:programdataFavorites
2008-12-31 10:19 --------- d-----w c:programdataDocuments
2008-12-31 10:19 --------- d-----w c:programdataDesktop
2008-12-31 10:19 --------- d-----w c:programdataApplication Data
2008-12-31 09:22 --------- d-----w c:userscyrilAppDataRoamingEoRezo
2008-12-31 09:18 --------- d-----w c:userscyrilAppDataRoamingskypePM
2008-12-30 14:17 --------- d-----w c:programdataSymantec
2008-12-30 14:17 --------- d-----w c:program filesCommon FilesSymantec Shared
2008-12-21 16:50 --------- d-----w c:program filesWindows Mail
2008-12-19 17:39 --------- d-----w c:programdataMicrosoft Help
2008-11-01 03:44 541,696 ----a-w c:windowsAppPatchAcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:windowsAppPatchiebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:windowsAppPatchAcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:windowsAppPatchAcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:windowsAppPatchAcXtrnal.dll
2008-10-16 13:07 208,744 ----a-w c:windowsSystem32muweb.dll
2008-06-21 22:32 174 --sha-w c:program filesdesktop.ini
2008-05-18 19:15 56 ---ha-w c:usersAll Usersezsidmv.dat
2008-05-18 19:15 56 ---ha-w c:programdataezsidmv.dat
2008-05-18 13:21 0 ----a-w c:usersarbaraAppDataRoamingwklnhst.dat
2008-04-08 16:38 140 ----a-w c:userscyrilAppDataRoamingwklnhst.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SmpcSys"="c:program filesPackard BellSetUpMyPCSmpSys.exe" [2007-07-19 1120568]
"ehTray.exe"="c:windowsehomeehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2007-10-18 5724184]
"ISUSPM"="c:program filesCommon FilesInstallShieldUpdateServiceISUSPM.exe" [2007-08-30 205480]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:windowsSystem32oobefldr.dll]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"ccApp"="c:program filesCommon FilesSymantec SharedccApp.exe" [2008-10-17 51048]
"Norton Ghost 12.0"="c:program filesNorton GhostAgentVProTray.exe" [2008-05-07 2037088]
"HerculesCamService"="c:program filesHerculesHercules DualPix HD WebcamCamService.exe" [2007-02-26 102400]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2008-09-17 92704]
"toolbar_eula_launcher"="c:program filesPackard BellGOOGLE_EULAEULALauncher.exe" [2007-02-20 28672]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 c:windowsRtHDVCpl.exe]
c:userscyrilAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
OneNote 2007 - Capture d',cran et lancement.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2007-12-07 101440]
Sommaire de OneNote.onetoc2 [2008-10-21 3656]
Ubisoft register.lnk - c:program filesUbisoftRegisterschedule.exe [2008-03-31 28672]
c:programdataMicrosoftWindowsStart MenuProgramsStartup
NETGEAR WPN111 Smart Wizard.lnk - c:program filesNETGEARWPN111wpn111.exe [2008-12-19 995328]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:progra~1GoogleGOOGLE~3GOEC62~1.DLL
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerSvc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicyDomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyPublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:progra~2SymantecDEFINI~1SymcDataipsdefs20090102.001IDSvix86.sys [2009-01-06 270384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:program filesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys [2008-10-09 99376]
R3 fbxusb;FreeBox USB Network Adapter;c:windowsSystem32driversfbxusb.sys [2008-03-31 18848]
R3 SYMNDISV;SYMNDISV;c:windowsSystem32driverssymndisv.sys [2008-06-13 41008]
R4 fssfltr;FssFltr;c:windowsSystem32driversfssfltr.sys [2008-03-31 43816]
R4 fsssvc;Windows Live OneCare Contrôle parental;c:program filesWindows LiveContrôle parentalfsssvc.exe [2007-12-17 523816]
R4 LiveUpdate Notice;LiveUpdate Notice;c:program filesCommon FilesSymantec SharedCCSVCHST.EXE [2008-01-25 149352]
S3 APL531;Hercules Dualpix HD Webcam;c:windowsSystem32driversHDvid.sys [2008-10-23 275072]
S3 camfilt;camfilt;c:windowsSystem32driverscamfilt.sys [2008-10-23 24192]
S3 COH_Mon;COH_Mon;c:windowsSystem32driversCOH_Mon.sys [2008-01-12 23888]
S3 DNIMp50;DNIMp50 NDIS Protocol Driver;c:windowsSystem32driversDNIMP50.sys [2008-10-23 21504]
S3 DNISp50;DNISp50 NDIS Protocol Driver;c:windowsSystem32driversDNISP50.sys [2008-10-23 20480]
S3 QCEmerald;Logitech QuickCam Web(PID_0850);c:windowsSystem32driverslvce.sys [2008-05-18 44544]
S3 WMSvc;Service de gestion Web;c:windowsSystem32inetsrvWMSvc.exe [2008-06-20 11264]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:windowsSystem32driversWPN111v.sys [2008-12-19 870400]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - sptd
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{45b972e4-d2b7-11dd-930e-001c2551bbff}]
shellAutoRuncommand - I:setupSNK.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{8c4feb49-d59d-11dd-9995-001c2551bbff}]
shellAutoRuncommand - J:LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2009-01-08 c:windowsTasksExtension de garantie.job
- c:program filesPackard BellSetupmyPCPBCarNot.exe [2006-11-21 17:38]
2008-04-06 c:windowsTasksHDReg.job
- c:program filesHDRegHDRegRem.exe []
2008-12-30 c:windowsTasksNorton Internet Security - Effectuer une analyse complète du système - cyril.job
- c:program filesNorton Internet SecurityNorton AntiVirusNavw32.exe [2008-02-07 07:05]
2008-12-30 c:windowsTasksUniblue SpeedUpMyPC Nag.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2008-04-24 c:windowsTasksUniblue SpeedUpMyPC.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2009-01-09 c:windowsTasksUser_Feed_Synchronization-{6EA0D4B9-DB82-4BA2-8E20-D7C0D7B5ED0C}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
2009-01-09 c:windowsTasksUser_Feed_Synchronization-{E5554789-FA57-4A5C-BFEC-D785A7D59F76}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-qgacg - c:userscyrilappdatalocalqgacg.exe
HKCU-RunOnce-Shockwave Updater - c:windowsSystem32AdobeSHOCKW~1SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; .NET
.
------- Examen supplémentaire -------
.
mStart Page =
hxxp://eo.st
uInternet Settings,ProxyOverride = localhost
IE: Add to Google Photos Screensa&ver - c:windowssystem32GPhotos.scr/200
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-09 15:49:43
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:windowsTEMPTMP00000062B972481030876173 524288 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
Heure de fin: 2009-01-09 15:52:14
ComboFix-quarantined-files.txt 2009-01-09 14:52:10
Avant-CF: 225,188,814,848 octets libres
Après-CF: 225,429,561,344 octets libres
219 --- E O F --- 2009-01-07 13:36:29
ComboFix 09-01-08.05 - cyril 2009-01-09 15:46:03.1 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.999 [GMT 1:00]
Lancé depuis: c:userscyrilDesktopComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-Secure
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-SecureSpyware-Secure trial.lnk
c:programdataMicrosoftWindowsStart MenuProgramsSpyware-SecureWebsite.lnk
c:userscyrilAppDataLocalqgacg.dat
c:userscyrilAppDataLocalqgacg.exe
c:userscyrilAppDataLocalqgacg_nav.dat
c:userscyrilAppDataLocalqgacg_navps.dat
c:usersmathisDesktopSpyware-Secure trial.lnk
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-09 au 2009-01-09 ))))))))))))))))))))))))))))))))))))
.
2009-01-08 16:33 . 2009-01-08 16:33 <REP> d-------- c:program filesFree.fr
2009-01-07 12:33 . 2008-12-13 07:23 1,659,392 --a------ c:windowsSystem32mshtml.tlb
2009-01-06 20:11 . 2009-01-06 20:11 <REP> d-------- c:program filesPackard Bell ImageWriter
2009-01-06 14:13 . 2008-08-22 11:08 1,415,680 --a------ c:windowsSystem32inetcpl.cpl
2009-01-06 14:13 . 2008-08-22 11:08 878,592 --a------ c:windowsSystem32wininet.dll
2009-01-06 14:13 . 2008-08-22 11:08 385,024 --a------ c:windowsSystem32html.iec
2009-01-06 14:13 . 2008-08-22 11:05 168,960 --a------ c:windowsSystem32iexpress.exe
2009-01-06 14:13 . 2008-08-22 11:04 45,568 --a------ c:windowsSystem32mshta.exe
2009-01-05 15:29 . 2009-01-05 15:29 <REP> d-------- C:inetpub
2009-01-05 15:16 . 2009-01-05 15:40 <REP> d-------- c:program filesmozilla.org
2009-01-03 17:20 . 2009-01-03 17:20 <REP> d-------- c:userscyrilAppDataRoamingPeerNetworking
2009-01-03 15:51 . 2009-01-05 15:17 8,273 --a------ c:windowsmozver.dat
2009-01-03 15:51 . 2009-01-03 15:51 335 --a------ c:windows
sreg.dat
2009-01-02 19:15 . 2009-01-02 19:15 <REP> d-------- c:usersarbaraAppDataRoamingInstallShield
2009-01-02 16:16 . 2009-01-02 16:16 <REP> d-------- C:fbxusb
2008-12-31 11:19 . 2008-12-31 11:19 <REP> d-------- C:pnp
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:usersAll UsersSymantec Temporary Files
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:programdataSymantec Temporary Files
2008-12-29 13:18 . 2008-12-29 13:18 <REP> d-------- c:program filesCommon FilesCanon
2008-12-29 12:43 . 2008-12-29 13:27 <REP> d-------- c:userscyrilAppDataRoamingU3
2008-12-19 18:32 . 2008-10-22 02:22 2,048 --a------ c:windowsSystem32 zres.dll
2008-12-19 16:18 . 2008-11-01 02:21 4,240,384 --a------ c:windowsSystem32GameUXLegacyGDFs.dll
2008-12-19 16:18 . 2008-10-29 07:29 2,927,104 --a------ c:windowsexplorer.exe
2008-12-19 16:18 . 2008-09-05 06:14 1,191,936 --a------ c:windowsSystem32msxml3.dll
2008-12-19 16:18 . 2008-10-21 06:25 296,960 --a------ c:windowsSystem32gdi32.dll
2008-12-19 16:18 . 2008-10-22 04:57 241,152 --a------ c:windowsSystem32PortableDeviceApi.dll
2008-12-19 16:18 . 2008-08-27 02:05 212,480 --a------ c:windowsSystem32driversmrxsmb10.sys
2008-12-19 16:18 . 2008-09-18 05:56 147,456 --a------ c:windowsSystem32Faultrep.dll
2008-12-19 16:18 . 2008-09-18 05:56 125,952 --a------ c:windowsSystem32wersvc.dll
2008-12-19 16:18 . 2008-11-01 04:44 28,672 --a------ c:windowsSystem32Apphlpdm.dll
2008-12-19 16:17 . 2008-06-23 02:59 2,868,736 --a------ c:windowsSystem32mf.dll
2008-12-19 16:17 . 2008-10-21 06:25 1,645,568 --a------ c:windowsSystem32connect.dll
2008-12-19 16:17 . 2008-09-10 04:40 1,334,272 --a------ c:windowsSystem32msxml6.dll
2008-12-19 16:17 . 2008-06-23 02:59 996,352 --a------ c:windowsSystem32WMNetMgr.dll
2008-12-19 16:17 . 2008-08-28 04:40 712,704 --a------ c:windowsSystem32WindowsCodecs.dll
2008-12-19 16:17 . 2008-08-12 04:39 443,392 --a------ c:windowsSystem32win32spl.dll
2008-12-19 16:17 . 2008-08-28 04:40 425,472 --a------ c:windowsSystem32PhotoMetadataHandler.dll
2008-12-19 16:17 . 2008-08-28 04:40 347,136 --a------ c:windowsSystem32WindowsCodecsExt.dll
2008-12-19 16:17 . 2008-06-23 02:58 94,720 --a------ c:windowsSystem32logagent.exe
2008-12-19 16:05 . 2008-10-16 22:13 1,809,944 --a------ c:windowsSystem32wuaueng.dll
2008-12-19 16:05 . 2008-10-16 21:56 1,524,736 --a------ c:windowsSystem32wucltux.dll
2008-12-19 16:05 . 2008-10-16 22:09 51,224 --a------ c:windowsSystem32wuauclt.exe
2008-12-19 16:05 . 2008-10-16 22:09 43,544 --a------ c:windowsSystem32wups2.dll
2008-12-19 16:04 . 2008-10-16 22:12 561,688 --a------ c:windowsSystem32wuapi.dll
2008-12-19 16:04 . 2008-10-16 14:08 162,064 --a------ c:windowsSystem32wuwebv.dll
2008-12-19 16:04 . 2008-10-16 21:55 83,456 --a------ c:windowsSystem32wudriver.dll
2008-12-19 16:04 . 2008-10-16 22:08 34,328 --a------ c:windowsSystem32wups.dll
2008-12-19 16:04 . 2008-10-16 13:56 31,232 --a------ c:windowsSystem32wuapp.exe
2008-12-19 14:58 . 2007-06-01 18:36 870,400 --a------ c:windowsSystem32driversWPN111v.sys
2008-12-12 22:47 . 2008-12-12 22:47 3,751,995 --a------ c:windowsSystem32GPhotos.scr
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 15:55 --------- d-----w c:program filesGoogle
2009-01-08 14:43 --------- d-----w c:program filesHDReg
2009-01-07 20:56 --------- d--h--w c:program filesInstallShield Installation Information
2009-01-06 19:11 --------- d-----w c:program filesPackard Bell
2009-01-02 16:56 --------- d-----w c:usersarbaraAppDataRoamingPackard Bell
2009-01-02 15:07 --------- d-----w c:program filesCyberLink
2008-12-31 16:16 --------- d-----w c:usersarbaraAppDataRoamingSymantec
2008-12-31 15:30 --------- d-----w c:usersarbaraAppDataRoamingEoRezo
2008-12-31 12:41 --------- d-----w c:programdataNVIDIA
2008-12-31 11:43 --------- d-----w c:userscyrilAppDataRoamingSkype
2008-12-31 10:19 --------- d-----w c:programdataTemplates
2008-12-31 10:19 --------- d-----w c:programdataStart Menu
2008-12-31 10:19 --------- d-----w c:programdataFavorites
2008-12-31 10:19 --------- d-----w c:programdataDocuments
2008-12-31 10:19 --------- d-----w c:programdataDesktop
2008-12-31 10:19 --------- d-----w c:programdataApplication Data
2008-12-31 09:22 --------- d-----w c:userscyrilAppDataRoamingEoRezo
2008-12-31 09:18 --------- d-----w c:userscyrilAppDataRoamingskypePM
2008-12-30 14:17 --------- d-----w c:programdataSymantec
2008-12-30 14:17 --------- d-----w c:program filesCommon FilesSymantec Shared
2008-12-21 16:50 --------- d-----w c:program filesWindows Mail
2008-12-19 17:39 --------- d-----w c:programdataMicrosoft Help
2008-11-01 03:44 541,696 ----a-w c:windowsAppPatchAcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:windowsAppPatchiebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:windowsAppPatchAcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:windowsAppPatchAcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:windowsAppPatchAcXtrnal.dll
2008-10-16 13:07 208,744 ----a-w c:windowsSystem32muweb.dll
2008-06-21 22:32 174 --sha-w c:program filesdesktop.ini
2008-05-18 19:15 56 ---ha-w c:usersAll Usersezsidmv.dat
2008-05-18 19:15 56 ---ha-w c:programdataezsidmv.dat
2008-05-18 13:21 0 ----a-w c:usersarbaraAppDataRoamingwklnhst.dat
2008-04-08 16:38 140 ----a-w c:userscyrilAppDataRoamingwklnhst.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SmpcSys"="c:program filesPackard BellSetUpMyPCSmpSys.exe" [2007-07-19 1120568]
"ehTray.exe"="c:windowsehomeehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2007-10-18 5724184]
"ISUSPM"="c:program filesCommon FilesInstallShieldUpdateServiceISUSPM.exe" [2007-08-30 205480]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:windowsSystem32oobefldr.dll]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"ccApp"="c:program filesCommon FilesSymantec SharedccApp.exe" [2008-10-17 51048]
"Norton Ghost 12.0"="c:program filesNorton GhostAgentVProTray.exe" [2008-05-07 2037088]
"HerculesCamService"="c:program filesHerculesHercules DualPix HD WebcamCamService.exe" [2007-02-26 102400]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2008-09-17 92704]
"toolbar_eula_launcher"="c:program filesPackard BellGOOGLE_EULAEULALauncher.exe" [2007-02-20 28672]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 c:windowsRtHDVCpl.exe]
c:userscyrilAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
OneNote 2007 - Capture d',cran et lancement.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2007-12-07 101440]
Sommaire de OneNote.onetoc2 [2008-10-21 3656]
Ubisoft register.lnk - c:program filesUbisoftRegisterschedule.exe [2008-03-31 28672]
c:programdataMicrosoftWindowsStart MenuProgramsStartup
NETGEAR WPN111 Smart Wizard.lnk - c:program filesNETGEARWPN111wpn111.exe [2008-12-19 995328]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:progra~1GoogleGOOGLE~3GOEC62~1.DLL
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerSvc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicyDomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyPublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:progra~2SymantecDEFINI~1SymcDataipsdefs20090102.001IDSvix86.sys [2009-01-06 270384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:program filesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys [2008-10-09 99376]
R3 fbxusb;FreeBox USB Network Adapter;c:windowsSystem32driversfbxusb.sys [2008-03-31 18848]
R3 SYMNDISV;SYMNDISV;c:windowsSystem32driverssymndisv.sys [2008-06-13 41008]
R4 fssfltr;FssFltr;c:windowsSystem32driversfssfltr.sys [2008-03-31 43816]
R4 fsssvc;Windows Live OneCare Contrôle parental;c:program filesWindows LiveContrôle parentalfsssvc.exe [2007-12-17 523816]
R4 LiveUpdate Notice;LiveUpdate Notice;c:program filesCommon FilesSymantec SharedCCSVCHST.EXE [2008-01-25 149352]
S3 APL531;Hercules Dualpix HD Webcam;c:windowsSystem32driversHDvid.sys [2008-10-23 275072]
S3 camfilt;camfilt;c:windowsSystem32driverscamfilt.sys [2008-10-23 24192]
S3 COH_Mon;COH_Mon;c:windowsSystem32driversCOH_Mon.sys [2008-01-12 23888]
S3 DNIMp50;DNIMp50 NDIS Protocol Driver;c:windowsSystem32driversDNIMP50.sys [2008-10-23 21504]
S3 DNISp50;DNISp50 NDIS Protocol Driver;c:windowsSystem32driversDNISP50.sys [2008-10-23 20480]
S3 QCEmerald;Logitech QuickCam Web(PID_0850);c:windowsSystem32driverslvce.sys [2008-05-18 44544]
S3 WMSvc;Service de gestion Web;c:windowsSystem32inetsrvWMSvc.exe [2008-06-20 11264]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:windowsSystem32driversWPN111v.sys [2008-12-19 870400]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - sptd
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{45b972e4-d2b7-11dd-930e-001c2551bbff}]
shellAutoRuncommand - I:setupSNK.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{8c4feb49-d59d-11dd-9995-001c2551bbff}]
shellAutoRuncommand - J:LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2009-01-08 c:windowsTasksExtension de garantie.job
- c:program filesPackard BellSetupmyPCPBCarNot.exe [2006-11-21 17:38]
2008-04-06 c:windowsTasksHDReg.job
- c:program filesHDRegHDRegRem.exe []
2008-12-30 c:windowsTasksNorton Internet Security - Effectuer une analyse complète du système - cyril.job
- c:program filesNorton Internet SecurityNorton AntiVirusNavw32.exe [2008-02-07 07:05]
2008-12-30 c:windowsTasksUniblue SpeedUpMyPC Nag.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2008-04-24 c:windowsTasksUniblue SpeedUpMyPC.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2009-01-09 c:windowsTasksUser_Feed_Synchronization-{6EA0D4B9-DB82-4BA2-8E20-D7C0D7B5ED0C}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
2009-01-09 c:windowsTasksUser_Feed_Synchronization-{E5554789-FA57-4A5C-BFEC-D785A7D59F76}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-qgacg - c:userscyrilappdatalocalqgacg.exe
HKCU-RunOnce-Shockwave Updater - c:windowsSystem32AdobeSHOCKW~1SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; .NET
.
------- Examen supplémentaire -------
.
mStart Page =
hxxp://eo.st
uInternet Settings,ProxyOverride = localhost
IE: Add to Google Photos Screensa&ver - c:windowssystem32GPhotos.scr/200
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-09 15:49:43
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:windowsTEMPTMP00000062B972481030876173 524288 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
Heure de fin: 2009-01-09 15:52:14
ComboFix-quarantined-files.txt 2009-01-09 14:52:10
Avant-CF: 225,188,814,848 octets libres
Après-CF: 225,429,561,344 octets libres
219 --- E O F --- 2009-01-07 13:36:29
dans l'attente de vos nouvelles coordialement cyril
ps: je remet tous les securités anti virus ......en route ou non???