Bonjour,
Je ne sais pas ou s'est installé Combofix !, ce que j'ai vu c'est que lorsque j'ai accepté sa licence tout s'est enchainé !.....
Comodo n'aime pas ce logiciel....enfin voilà les 2 rapports ;
Rapport OTLAll processes killed
========== OTL ==========
C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Real\Update\setup3.13\setup.exe moved successfully.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} scheduled to be moved on reboot.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
Unable to fix default_search_provider items.
C:\Documents and Settings\All Users.WINDOWS\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275} folder moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: All Users.WINDOWS
User: bataille
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: BATAILLE.UNICORNI-AC7163
->Temp folder emptied: 2912629 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 612962 bytes
->Google Chrome cache emptied: 6269235 bytes
->Flash cache emptied: 343 bytes
User: BATAIL~1~UNI
User: bonato
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Brigitte
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: georgettbro
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService.AUTORITE NT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 0 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: NetworkService.AUTORITE NT
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 9,00 mb
Restore points cleared and new OTL Restore Point set!
OTL by OldTimer - Version 3.2.31.0 log created on 01272012_102447
Files\Folders moved on Reboot...
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources\English.lproj scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents\Resources scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin\Contents scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins\GarminGpsControl.plugin scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}\plugins scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} scheduled to be moved on reboot.
Folder move failed. C:\Documents and Settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\extensions scheduled to be moved on reboot.
Registry entries deleted on Reboot...
---------------------------------------------------------------------------------------------------------------------------------------------
Rapport COMBOFIXComboFix 12-01-21.02 - BATAILLE 27/01/2012 10:49:51.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1535.994 [GMT 1:00]
Lancé depuis: c:\documents and settings\BATAILLE.UNICORNI-AC7163\Mes documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
* Un nouveau point de restauration a été créé
.
/wow section - STAGE 32A
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\bonato\WINDOWS
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-12-27 au 2012-01-27 ))))))))))))))))))))))))))))))))))))
.
.
2012-01-26 12:23 . 2012-01-26 12:23 -------- d-----r- c:\documents and settings\LocalService.AUTORITE NT\Mes documents
2012-01-25 10:22 . 2012-01-25 10:22 -------- d-----w- C:\_OTL
2012-01-23 09:22 . 2012-01-26 13:04 512 ----a-w- C:\PhysicalMBR.bin
2012-01-20 12:56 . 2012-01-20 12:56 -------- d-----w- c:\program files\Garmin GPS Plugin
2012-01-14 13:34 . 2012-01-14 13:34 -------- d-----w- c:\program files\Ad-Remover
2012-01-11 13:23 . 2012-01-11 13:23 -------- d-----w- c:\documents and settings\BATAILLE.UNICORNI-AC7163\Local Settings\Application Data\Comodo
2012-01-11 12:39 . 2012-01-21 13:11 -------- d-----w- C:\ZHP
2012-01-11 12:39 . 2012-01-27 09:35 -------- d-----w- c:\program files\ZHPDiag
2012-01-10 13:56 . 2012-01-10 13:56 -------- d-----w- c:\documents and settings\BATAILLE.UNICORNI-AC7163\Application Data\Malwarebytes
2012-01-10 13:56 . 2012-01-10 13:56 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2012-01-10 13:55 . 2012-01-14 12:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-09 10:53 . 2012-01-10 13:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Comodo
2012-01-03 13:10 . 2012-01-03 13:10 182672 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2012-01-03 13:10 . 2012-01-03 13:10 182672 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-19 18:58 . 2011-12-20 14:02 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-12-19 17:59 . 2011-12-19 17:59 97760 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-12-19 17:59 . 2011-12-19 17:59 494816 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-12-19 17:59 . 2011-12-19 17:59 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-12-19 17:59 . 2011-12-19 17:59 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-12-19 17:58 . 2011-12-19 17:58 301224 ----a-w- c:\windows\system32\guard32.dll
2011-12-16 16:08 . 2011-09-13 15:54 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-25 21:57 . 2004-08-03 22:54 293888 ----a-w- c:\windows\system32\winsrv.dll
2011-11-23 14:40 . 2004-08-03 22:45 1859712 ----a-w- c:\windows\system32\win32k.sys
2011-11-20 06:12 . 2004-08-03 22:55 61952 ----a-w- c:\windows\system32\packager.exe
2011-11-03 15:28 . 2004-08-03 22:54 387072 ----a-w- c:\windows\system32\qdvd.dll
2011-11-03 15:28 . 2004-08-03 22:54 1298432 ------w- c:\windows\system32\quartz.dll
2011-11-01 20:35 . 2004-08-03 22:54 671232 ----a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2004-08-03 20:59 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-11-01 20:35 . 2004-08-03 22:54 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-11-01 20:34 . 2004-08-03 22:41 371200 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-03 22:54 1288192 ----a-w- c:\windows\system32\ole32.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-02-23 2251064]
"Connexion SFR 9props.exe"="c:\program files\SFR\Kit\9props.exe" [2009-10-15 959808]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
"gStart"="c:\garmin\gStart.exe" [2008-08-13 1891416]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-22 39408]
"Neuf Media Center"="c:\program files\SFR\Media Center\MediaCenter.exe" [2010-04-29 742720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-11-02 1349392]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2009-11-02 905208]
"Seagate Scheduler2 Service"="c:\program files\Fichiers communs\Seagate\Schedule2\schedhlp.exe" [2009-11-02 136544]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-25 185640]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-10-31 273528]
"COMODO"="c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe" [2011-11-23 208184]
"CPA"="c:\program files\COMODO\COMODO GeekBuddy\VALA.exe" [2011-11-23 182584]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-20 6676808]
.
c:\documents and settings\BATAILLE.UNICORNI-AC7163\Menu Démarrer\Programmes\Démarrage\
OneNote 2007 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Outil de détection de support PMB.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-9-5 333088]
.
c:\documents and settings\BATAILLE.UNICORNI-AC7163\Menu Démarrer\Programmes\Démarrage\
OneNote 2007 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Outil de détection de support PMB.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-9-5 333088]
.
c:\documents and settings\BATAILLE.UNICORNI-AC7163\Menu Démarrer\Programmes\Démarrage\
OneNote 2007 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Outil de détection de support PMB.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-9-5 333088]
.
c:\documents and settings\BATAILLE.UNICORNI-AC7163\Menu Démarrer\Programmes\Démarrage\
OneNote 2007 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Outil de détection de support PMB.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-9-5 333088]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Kodak software updater.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnkCommon Startup
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\program files\SFR\Media Center\httpd\httpd.exe"= c:\program files\SFR\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.0/255.255.255.0:Enabled:Serveur de partage Media Center (Player SFR)
.
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [19/12/2011 18:59 494816]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [19/12/2011 18:59 31704]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [21/03/2011 14:01 340136]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [04/03/2011 16:47 136360]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [21/03/2011 14:01 428200]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO GeekBuddy\CLPSLS.exe [23/11/2011 11:27 1052472]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [25/09/2009 23:32 189736]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Fichiers communs\Seagate\Schedule2\schedul2.exe [02/11/2009 17:52 431456]
R3 BeWGU(BeWAN systems);Adaptateur WiFi(BeWAN systems);c:\windows\system32\drivers\BeWGU.sys [08/08/2008 18:31 489472]
S2 gupdate1c986eb67628f1e;Google Update Service (gupdate1c986eb67628f1e);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2009 18:09 133104]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2009 18:09 133104]
S3 TV_551805_Sp50;TV_551805_Sp50 NDIS Protocol Driver;c:\windows\system32\drivers\TV_551805_Sp50.sys [08/08/2008 18:34 27072]
.
Contenu du dossier 'Tâches planifiées'
.
2012-01-27 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-07-15 19:55]
.
2012-01-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-06 12:53]
.
2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 17:09]
.
2012-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-04 17:09]
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-527237240-1123561945-839522115-1003Core.job
- c:\documents and settings\BATAILLE.UNICORNI-AC7163\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-27 17:08]
.
2012-01-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-527237240-1123561945-839522115-1003UA.job
- c:\documents and settings\BATAILLE.UNICORNI-AC7163\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-27 17:08]
.
2012-01-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1123561945-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1123561945-839522115-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-20 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-1123561945-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-1123561945-839522115-1007.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 12:40]
.
2012-01-27 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-28 20:18]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext =
hxxp://www.sfr.fr/kit/adsl/uInternet Settings,ProxyOverride = local;*.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Tout télécharger avec Free Download Manager -
file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager -
file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager -
file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager -
file://c:\program files\Free Download Manager\dlfvideo.htm
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{573B127D-E1F0-4381-9389-7834EC0EF0A5}: NameServer = 8.26.56.26,156.154.70.22
FF - ProfilePath - c:\documents and settings\BATAILLE.UNICORNI-AC7163\Application Data\Mozilla\Firefox\Profiles\05a3r375.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=FF - prefs.js: browser.startup.homepage -
.
- - - - ORPHELINS SUPPRIMES - - - -
.
AddRemove-{18EF615A-5AAD-4944-B24E-6CD7863FC735} - c:\program files\InstallShield Installation Information\{18EF615A-5AAD-4944-B24E-6CD7863FC735}\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-01-27 10:59
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'lsass.exe'(1004)
c:\windows\system32\guard32.dll
c:\windows\system32\relog_ap.dll
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(2472)
c:\windows\system32\guard32.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'csrss.exe'(920)
c:\windows\system32\cmdcsr.dll
.
Heure de fin: 2012-01-27 11:03:21
ComboFix-quarantined-files.txt 2012-01-27 10:03
.
Avant-CF: 123 610 820 608 octets libres
Après-CF: 123 564 314 624 octets libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30
.
- - End Of File - - 316285D763C3F815E0C610DADC7F318D
Merci pour ta précieuse réponse
Cristaline