ccleaner c'est fait et voici le rapport de combo fix
merci bow quand pense tu je suis infecté ? ComboFix 09-01-08.05 - cyril 2009-01-10 12:15:50.4 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1033 [GMT 1:00]
Lancé depuis: c:userscyrilDesktopComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-10 au 2009-01-10 ))))))))))))))))))))))))))))))))))))
.
2009-01-10 11:54 . 2009-01-10 11:54 6,736 --a------ c:windowsSystem32driversPROCEXP90.SYS
2009-01-10 11:41 . 2009-01-10 11:41 <REP> d-------- c:program filesCCleaner
2009-01-09 16:31 . 2009-01-09 16:41 250 --a------ c:windowsgmer.ini
2009-01-08 16:33 . 2009-01-08 16:33 <REP> d-------- c:program filesFree.fr
2009-01-07 12:33 . 2008-12-13 07:23 1,659,392 --a------ c:windowsSystem32mshtml.tlb
2009-01-06 20:11 . 2009-01-06 20:11 <REP> d-------- c:program filesPackard Bell ImageWriter
2009-01-06 14:13 . 2008-08-22 11:08 1,415,680 --a------ c:windowsSystem32inetcpl.cpl
2009-01-06 14:13 . 2008-08-22 11:08 878,592 --a------ c:windowsSystem32wininet.dll
2009-01-06 14:13 . 2008-08-22 11:08 385,024 --a------ c:windowsSystem32html.iec
2009-01-06 14:13 . 2008-08-22 11:05 168,960 --a------ c:windowsSystem32iexpress.exe
2009-01-06 14:13 . 2008-08-22 11:04 45,568 --a------ c:windowsSystem32mshta.exe
2009-01-05 15:29 . 2009-01-05 15:29 <REP> d-------- C:inetpub
2009-01-05 15:16 . 2009-01-05 15:40 <REP> d-------- c:program filesmozilla.org
2009-01-03 17:20 . 2009-01-03 17:20 <REP> d-------- c:userscyrilAppDataRoamingPeerNetworking
2009-01-03 15:51 . 2009-01-05 15:17 8,273 --a------ c:windowsmozver.dat
2009-01-03 15:51 . 2009-01-03 15:51 335 --a------ c:windows
sreg.dat
2009-01-02 19:15 . 2009-01-02 19:15 <REP> d-------- c:usersarbaraAppDataRoamingInstallShield
2009-01-02 16:16 . 2009-01-02 16:16 <REP> d-------- C:fbxusb
2008-12-31 11:19 . 2008-12-31 11:19 <REP> d-------- C:pnp
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:usersAll UsersSymantec Temporary Files
2008-12-30 15:15 . 2008-12-30 15:15 <REP> d-------- c:programdataSymantec Temporary Files
2008-12-29 13:18 . 2008-12-29 13:18 <REP> d-------- c:program filesCommon FilesCanon
2008-12-29 12:43 . 2008-12-29 13:27 <REP> d-------- c:userscyrilAppDataRoamingU3
2008-12-19 18:32 . 2008-10-22 02:22 2,048 --a------ c:windowsSystem32 zres.dll
2008-12-19 16:18 . 2008-11-01 02:21 4,240,384 --a------ c:windowsSystem32GameUXLegacyGDFs.dll
2008-12-19 16:18 . 2008-10-29 07:29 2,927,104 --a------ c:windowsexplorer.exe
2008-12-19 16:18 . 2008-09-05 06:14 1,191,936 --a------ c:windowsSystem32msxml3.dll
2008-12-19 16:18 . 2008-10-21 06:25 296,960 --a------ c:windowsSystem32gdi32.dll
2008-12-19 16:18 . 2008-10-22 04:57 241,152 --a------ c:windowsSystem32PortableDeviceApi.dll
2008-12-19 16:18 . 2008-08-27 02:05 212,480 --a------ c:windowsSystem32driversmrxsmb10.sys
2008-12-19 16:18 . 2008-09-18 05:56 147,456 --a------ c:windowsSystem32Faultrep.dll
2008-12-19 16:18 . 2008-09-18 05:56 125,952 --a------ c:windowsSystem32wersvc.dll
2008-12-19 16:18 . 2008-11-01 04:44 28,672 --a------ c:windowsSystem32Apphlpdm.dll
2008-12-19 16:17 . 2008-06-23 02:59 2,868,736 --a------ c:windowsSystem32mf.dll
2008-12-19 16:17 . 2008-10-21 06:25 1,645,568 --a------ c:windowsSystem32connect.dll
2008-12-19 16:17 . 2008-09-10 04:40 1,334,272 --a------ c:windowsSystem32msxml6.dll
2008-12-19 16:17 . 2008-06-23 02:59 996,352 --a------ c:windowsSystem32WMNetMgr.dll
2008-12-19 16:17 . 2008-08-28 04:40 712,704 --a------ c:windowsSystem32WindowsCodecs.dll
2008-12-19 16:17 . 2008-08-12 04:39 443,392 --a------ c:windowsSystem32win32spl.dll
2008-12-19 16:17 . 2008-08-28 04:40 425,472 --a------ c:windowsSystem32PhotoMetadataHandler.dll
2008-12-19 16:17 . 2008-08-28 04:40 347,136 --a------ c:windowsSystem32WindowsCodecsExt.dll
2008-12-19 16:17 . 2008-06-23 02:58 94,720 --a------ c:windowsSystem32logagent.exe
2008-12-19 16:05 . 2008-10-16 22:13 1,809,944 --a------ c:windowsSystem32wuaueng.dll
2008-12-19 16:05 . 2008-10-16 21:56 1,524,736 --a------ c:windowsSystem32wucltux.dll
2008-12-19 16:05 . 2008-10-16 22:09 51,224 --a------ c:windowsSystem32wuauclt.exe
2008-12-19 16:05 . 2008-10-16 22:09 43,544 --a------ c:windowsSystem32wups2.dll
2008-12-19 16:04 . 2008-10-16 22:12 561,688 --a------ c:windowsSystem32wuapi.dll
2008-12-19 16:04 . 2008-10-16 14:08 162,064 --a------ c:windowsSystem32wuwebv.dll
2008-12-19 16:04 . 2008-10-16 21:55 83,456 --a------ c:windowsSystem32wudriver.dll
2008-12-19 16:04 . 2008-10-16 22:08 34,328 --a------ c:windowsSystem32wups.dll
2008-12-19 16:04 . 2008-10-16 13:56 31,232 --a------ c:windowsSystem32wuapp.exe
2008-12-19 14:58 . 2007-06-01 18:36 870,400 --a------ c:windowsSystem32driversWPN111v.sys
2008-12-12 22:47 . 2008-12-12 22:47 3,751,995 --a------ c:windowsSystem32GPhotos.scr
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 16:34 806 ----a-w c:windowssystem32driversSYMEVENT.INF
2009-01-09 16:34 124,464 ----a-w c:windowssystem32driversSYMEVENT.SYS
2009-01-09 16:34 10,635 ----a-w c:windowssystem32driversSYMEVENT.CAT
2009-01-09 16:34 --------- d-----w c:program filesSymantec
2009-01-08 15:55 --------- d-----w c:program filesGoogle
2009-01-08 14:43 --------- d-----w c:program filesHDReg
2009-01-07 20:56 --------- d--h--w c:program filesInstallShield Installation Information
2009-01-06 19:11 --------- d-----w c:program filesPackard Bell
2009-01-02 16:56 --------- d-----w c:usersarbaraAppDataRoamingPackard Bell
2009-01-02 15:07 --------- d-----w c:program filesCyberLink
2008-12-31 16:16 --------- d-----w c:usersarbaraAppDataRoamingSymantec
2008-12-31 15:30 --------- d-----w c:usersarbaraAppDataRoamingEoRezo
2008-12-31 12:41 --------- d-----w c:programdataNVIDIA
2008-12-31 11:43 --------- d-----w c:userscyrilAppDataRoamingSkype
2008-12-31 10:19 --------- d-----w c:programdataTemplates
2008-12-31 10:19 --------- d-----w c:programdataStart Menu
2008-12-31 10:19 --------- d-----w c:programdataFavorites
2008-12-31 10:19 --------- d-----w c:programdataDocuments
2008-12-31 10:19 --------- d-----w c:programdataDesktop
2008-12-31 10:19 --------- d-----w c:programdataApplication Data
2008-12-31 09:22 --------- d-----w c:userscyrilAppDataRoamingEoRezo
2008-12-31 09:18 --------- d-----w c:userscyrilAppDataRoamingskypePM
2008-12-30 14:17 --------- d-----w c:programdataSymantec
2008-12-30 14:17 --------- d-----w c:program filesCommon FilesSymantec Shared
2008-12-21 16:50 --------- d-----w c:program filesWindows Mail
2008-12-19 17:39 --------- d-----w c:programdataMicrosoft Help
2008-11-01 03:44 541,696 ----a-w c:windowsAppPatchAcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:windowsAppPatchiebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:windowsAppPatchAcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:windowsAppPatchAcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:windowsAppPatchAcXtrnal.dll
2008-10-16 13:07 208,744 ----a-w c:windowsSystem32muweb.dll
2008-06-21 22:32 174 --sha-w c:program filesdesktop.ini
2008-05-18 19:15 56 ---ha-w c:usersAll Usersezsidmv.dat
2008-05-18 19:15 56 ---ha-w c:programdataezsidmv.dat
2008-05-18 13:21 0 ----a-w c:usersarbaraAppDataRoamingwklnhst.dat
2008-04-08 16:38 140 ----a-w c:userscyrilAppDataRoamingwklnhst.dat
2008-10-09 16:08 16,384 --sha-w c:windowsServiceProfilesNetworkServiceAppDataLocalMicrosoftWindowsHistoryHistory.IE5index.dat
2008-10-09 16:08 32,768 --sha-w c:windowsServiceProfilesNetworkServiceAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5index.dat
2008-10-09 16:08 32,768 --sha-w c:windowsServiceProfilesNetworkServiceAppDataRoamingMicrosoftWindowsCookiesindex.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SmpcSys"="c:program filesPackard BellSetUpMyPCSmpSys.exe" [2007-07-19 1120568]
"ehTray.exe"="c:windowsehomeehTray.exe" [2008-01-19 125952]
"msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2007-10-18 5724184]
"ISUSPM"="c:program filesCommon FilesInstallShieldUpdateServiceISUSPM.exe" [2007-08-30 205480]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2008-01-19 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:windowsSystem32oobefldr.dll]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"ccApp"="c:program filesCommon FilesSymantec SharedccApp.exe" [2008-10-17 51048]
"Norton Ghost 12.0"="c:program filesNorton GhostAgentVProTray.exe" [2008-05-07 2037088]
"HerculesCamService"="c:program filesHerculesHercules DualPix HD WebcamCamService.exe" [2007-02-26 102400]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2008-09-17 92704]
"toolbar_eula_launcher"="c:program filesPackard BellGOOGLE_EULAEULALauncher.exe" [2007-02-20 28672]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 c:windowsRtHDVCpl.exe]
c:userscyrilAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
OneNote 2007 - Capture d',cran et lancement.lnk - c:program filesMicrosoft OfficeOffice12ONENOTEM.EXE [2007-12-07 101440]
Sommaire de OneNote.onetoc2 [2008-10-21 3656]
Ubisoft register.lnk - c:program filesUbisoftRegisterschedule.exe [2008-03-31 28672]
c:programdataMicrosoftWindowsStart MenuProgramsStartup
NETGEAR WPN111 Smart Wizard.lnk - c:program filesNETGEARWPN111wpn111.exe [2008-12-19 995328]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:progra~1GoogleGOOGLE~3GOEC62~1.DLL
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerSvc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicyDomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyPublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:progra~2SymantecDEFINI~1SymcDataipsdefs20090102.001IDSvix86.sys [2009-01-06 270384]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:program filesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys [2008-10-09 99376]
R3 fbxusb;FreeBox USB Network Adapter;c:windowsSystem32driversfbxusb.sys [2008-03-31 18848]
R3 SYMNDISV;SYMNDISV;c:windowsSystem32driverssymndisv.sys [2008-06-13 41008]
R4 fssfltr;FssFltr;c:windowsSystem32driversfssfltr.sys [2008-03-31 43816]
R4 fsssvc;Windows Live OneCare Contrôle parental;c:program filesWindows LiveContrôle parentalfsssvc.exe [2007-12-17 523816]
R4 LiveUpdate Notice;LiveUpdate Notice;c:program filesCommon FilesSymantec SharedCCSVCHST.EXE [2008-01-25 149352]
S3 APL531;Hercules Dualpix HD Webcam;c:windowsSystem32driversHDvid.sys [2008-10-23 275072]
S3 camfilt;camfilt;c:windowsSystem32driverscamfilt.sys [2008-10-23 24192]
S3 COH_Mon;COH_Mon;c:windowsSystem32driversCOH_Mon.sys [2008-01-12 23888]
S3 DNIMp50;DNIMp50 NDIS Protocol Driver;c:windowsSystem32driversDNIMP50.sys [2008-10-23 21504]
S3 DNISp50;DNISp50 NDIS Protocol Driver;c:windowsSystem32driversDNISP50.sys [2008-10-23 20480]
S3 QCEmerald;Logitech QuickCam Web(PID_0850);c:windowsSystem32driverslvce.sys [2008-05-18 44544]
S3 WMSvc;Service de gestion Web;c:windowsSystem32inetsrvWMSvc.exe [2008-06-20 11264]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:windowsSystem32driversWPN111v.sys [2008-12-19 870400]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - sptd
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{8c4feb49-d59d-11dd-9995-001c2551bbff}]
shellAutoRuncommand - J:LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2009-01-10 c:windowsTasksExtension de garantie.job
- c:program filesPackard BellSetupmyPCPBCarNot.exe [2006-11-21 17:38]
2008-04-06 c:windowsTasksHDReg.job
- c:program filesHDRegHDRegRem.exe []
2008-12-30 c:windowsTasksNorton Internet Security - Effectuer une analyse complète du système - cyril.job
- c:program filesNorton Internet SecurityNorton AntiVirusNavw32.exe [2008-02-07 07:05]
2009-01-09 c:windowsTasksUniblue SpeedUpMyPC Nag.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2008-04-24 c:windowsTasksUniblue SpeedUpMyPC.job
- c:program filesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe []
2009-01-10 c:windowsTasksUser_Feed_Synchronization-{6EA0D4B9-DB82-4BA2-8E20-D7C0D7B5ED0C}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
2009-01-10 c:windowsTasksUser_Feed_Synchronization-{E5554789-FA57-4A5C-BFEC-D785A7D59F76}.job
- c:windowssystem32msfeedssync.exe [2008-08-22 11:05]
.
.
------- Examen supplémentaire -------
.
mStart Page =
hxxp://eo.st
uInternet Settings,ProxyOverride = localhost
IE: Add to Google Photos Screensa&ver - c:windowssystem32GPhotos.scr/200
LSP: c:windowssystem32wpclsp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-10 12:18:41
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-10 12:20:59
ComboFix-quarantined-files.txt 2009-01-10 11:20:53
ComboFix2.txt 2009-01-10 11:03:33
ComboFix3.txt 2009-01-09 14:52:15
Avant-CF: 225,362,964,480 octets libres
Après-CF: 225,328,594,944 octets libres
214 --- E O F --- 2009-01-10 10:35:46