A priori, le scan s'est bien passé.
Si t'as l'occasion de jeter un petit coup d'oeil sur le rapport et me dire quoi, ce matin, ce serait bien cool.
Quoi qu'il en soit... c'est cool !
En tout cas, on dirait qu'on est repartis dans la bonne direction.
A + et bonne journée !
- Code: Tout sélectionner
ComboFix 10-08-31.03 - Famille 02/09/2010 4:03.7.1 - x86
Lancé depuis: g:\documents\ComboFix.exe
Commutateurs utilisés :: g:\documents\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\documents and settings\Famille\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_2cd672ae.exe"
"c:\program files\btguard-1-00.exe"
"c:\program files\qsetup.html"
"c:\windows\.tm155.tmp"
"c:\windows\.tm27.tmp"
"c:\windows\.tm4.tmp"
"c:\windows\.tm41.tmp"
"c:\windows\.tm44.tmp"
"c:\windows\.tm75.tmp"
"c:\windows\.tm8D.tmp"
"c:\windows\.tm8E.tmp"
"c:\windows\.tm95.tmp"
"c:\windows\.tmA6.tmp"
"c:\windows\.tmB5.tmp"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Famille\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_2cd672ae.exe
c:\program files\btguard-1-00.exe
c:\program files\qsetup.html
c:\windows\.tm155.tmp
c:\windows\.tm27.tmp
c:\windows\.tm4.tmp
c:\windows\.tm41.tmp
c:\windows\.tm44.tmp
c:\windows\.tm75.tmp
c:\windows\.tm8D.tmp
c:\windows\.tm8E.tmp
c:\windows\.tm95.tmp
c:\windows\.tmA6.tmp
c:\windows\.tmB5.tmp
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-02 au 2010-09-02 ))))))))))))))))))))))))))))))))))))
.
2010-09-02 00:58 . 2010-09-02 00:58 -------- d-----w- c:\documents and settings\Famille\Application Data\Avira
2010-09-02 00:48 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-02 00:48 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-09-02 00:48 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-09-02 00:48 . 2010-09-02 00:48 -------- d-----w- c:\program files\Avira
2010-09-02 00:48 . 2010-09-02 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-09-01 04:00 . 2008-04-14 02:34 1037824 ----a-w- c:\windows\explorer.exe
2010-08-30 13:50 . 2010-08-30 13:50 -------- d-----w- C:\_OTL
2010-08-19 20:55 . 2010-08-19 20:56 -------- d-----w- C:\CSysFiles
2010-08-19 20:46 . 2010-08-19 20:46 -------- d-----w- C:\Medion
2010-08-16 11:29 . 2010-08-16 11:29 -------- d-----w- c:\documents and settings\All Users\Application Data\U3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 01:04 . 2010-09-02 01:04 139264 ----a-w- c:\windows\NERF.tmp
2010-09-02 01:01 . 2010-09-02 01:01 0 ----a-w- c:\windows\.tmE.tmp
2010-08-26 14:58 . 2006-12-24 13:24 -------- d-----w- c:\program files\CCleaner
2010-08-18 19:08 . 2004-10-27 15:54 21638 ----a-w- c:\documents and settings\Famille\Application Data\wklnhst.dat
2010-08-18 09:20 . 2009-09-08 18:18 -------- d-----w- c:\documents and settings\Famille\Application Data\uTorrent
2010-08-16 11:26 . 2009-12-23 18:15 -------- d-----w- c:\documents and settings\Famille\Application Data\U3
2010-08-12 01:17 . 2004-08-19 21:58 92700 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-12 01:17 . 2004-08-19 21:58 529198 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-26 16:45 . 2009-10-23 12:31 -------- d-----w- c:\documents and settings\Famille\Application Data\Vso
2010-07-26 16:45 . 2009-10-23 12:31 47360 ----a-w- c:\documents and settings\Famille\Application Data\pcouffin.sys
2010-07-26 16:45 . 2009-10-23 12:31 47360 ----a-w- c:\documents and settings\Famille\Application Data\pcouffin.sys
2010-07-15 11:43 . 2005-04-11 21:23 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-07-15 10:09 . 2010-03-02 16:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-13 17:19 . 2009-10-23 12:31 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2010-06-30 12:32 . 2004-08-19 21:57 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:17 . 2004-08-19 21:58 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:17 . 2004-08-19 21:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:17 . 2004-08-19 21:57 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-24 09:02 . 2004-08-19 21:58 1852032 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-19 21:58 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-19 21:57 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2004-08-19 13:12 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:42 . 2004-08-19 21:57 1172480 ----a-w- c:\windows\system32\msxml3.dll
2006-08-03 22:22 . 2005-04-11 21:11 11270 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 65024]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2004-08-06 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2004-07-26 49152]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2004-07-26 204800]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2004-08-06 73728]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-07-25 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-07-25 618496]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-17 339968]
"PCMService"="c:\program files\Home Cinema\PowerCinema\PCMService.exe" [2004-09-09 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-11 282624]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-24 149280]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2009-12-23 233472]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmjb.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Tiscali\\Tiscali Internet\\Tiscali Inet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Bluetooth\\BlueSoleil\\BlueSoleil.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:*:Disabled:Adobe CSI CS4
"19129:TCP"= 19129:TCP:UTorrent
S3 MEMSWEEP2;MEMSWEEP2; [x]
.
Contenu du dossier 'Tâches planifiées'
2010-09-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 17:20]
2010-08-17 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-03-23 13:23]
2010-08-24 c:\windows\Tasks\wavepadDowngrade.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-03-23 13:24]
2010-08-24 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2010-03-23 13:24]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.be/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &eBay Search
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Translate this web page with Babylon
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
FF - ProfilePath - c:\documents and settings\Famille\Application Data\Mozilla\Firefox\Profiles\o5iwgn3a.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.be/
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\utilitaires\RealPlayer8\Netscape6\nppl3260.dll
FF - plugin: c:\utilitaires\RealPlayer8\Netscape6\nprjplug.dll
FF - plugin: c:\utilitaires\RealPlayer8\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-02 04:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2917347797-3027105718-829246846-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3844)
c:\program files\CyberLink\Shared Files\CLRCEngine.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Windows Defender\MsMpEng.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\SOUNDMAN.EXE
c:\progra~1\COMMON~1\X10\Common\x10nets.exe
.
**************************************************************************
.
Heure de fin: 2010-09-02 04:29:33 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-02 02:29
ComboFix2.txt 2010-09-02 00:33
Avant-CF: 7.599.087.616 octets libres
Après-CF: 7.584.903.168 octets libres
- - End Of File - - 429A4512D70876856A19511C748B397F