Alors tout d'abord, un grand merci pour avoir pris le temps de répondre.
J'ai supprimé les lignes avec HiJackThis et enchainé avec combofix (a la suite de l'execution de HiJackTHis, j'ai perdu ma connection réseau. Pour la retrouver, j'ai du désactiver IPV6 et rester en IPV4, c'est bizzare. Pour info, j'ai la freebox V5 qui me permet de surfer en IPV6)
Voici le rapport de combofix
ComboFix 08-07-11.1 - philippe 2008-07-12 16:00:57.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate Edition 6.0.6001.1.1252.1.1036.18.2242 [GMT 2:00]
Endroit: C:UsersphilippeDownloadsComboFix.exe
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:Windowsinstall.exe
C:Windowsscvhost.exe
F:Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-12 to 2008-07-12 ))))))))))))))))))))))))))))))))))))
.
2008-07-12 10:45 . 2008-07-12 10:45 <REP> d-------- C:UsersphilippeAppDataRoamingTuneUp Software
2008-07-12 10:45 . 2008-07-12 10:45 <REP> d-------- C:UsersAll UsersTuneUp Software
2008-07-12 10:45 . 2008-07-12 10:45 <REP> d-------- C:ProgramDataTuneUp Software
2008-07-12 10:45 . 2008-07-12 10:45 <REP> d-------- C:Program FilesTuneUp Utilities 2008
2008-07-12 10:45 . 2008-07-12 10:45 <REP> d-------- C:Program FilesCommon FilesWise Installation Wizard
2008-07-12 10:45 . 2008-07-12 10:45 355,584 --a------ C:WindowsSystem32TuneUpDefragService.exe
2008-07-12 10:45 . 2008-05-29 09:28 28,416 --a------ C:WindowsSystem32uxtuneup.dll
2008-07-12 10:45 . 2008-05-29 09:28 16,640 --a------ C:WindowsSystem32authuitu.dll
2008-07-12 10:09 . 2008-07-12 10:09 <REP> d-------- C:UsersphilippeAppDataRoamingDruide
2008-07-12 10:00 . 2008-07-12 10:00 <REP> d-------- C:UsersphilippeAppDataRoamingUlead Systems
2008-07-12 09:34 . 2008-07-12 09:34 <REP> d-------- C:Program FilesvanBasco's Karaoke Player
2008-07-12 09:31 . 2008-07-12 09:31 <REP> d-------- C:UsersphilippeAppDataRoamingInstallShield
2008-07-12 09:30 . 2008-07-12 09:30 <REP> d-------- C:UsersAll UsersInterVideo
2008-07-12 09:30 . 2008-07-12 09:30 <REP> d-------- C:ProgramDataInterVideo
2008-07-12 09:30 . 2008-07-12 09:30 <REP> d-------- C:Program FilesWindows Media Components
2008-07-12 09:30 . 2008-07-12 09:30 <REP> d-------- C:Program FilesCommon FilesInterVideo
2008-07-12 09:30 . 2007-03-06 11:58 210,456 --a------ C:WindowsSystem32IVIresizeW7.dll
2008-07-12 09:30 . 2007-03-06 11:58 206,360 --a------ C:WindowsSystem32IVIresizeA6.dll
2008-07-12 09:30 . 2007-03-06 11:58 198,168 --a------ C:WindowsSystem32IVIresizeP6.dll
2008-07-12 09:30 . 2007-03-06 11:58 198,168 --a------ C:WindowsSystem32IVIresizeM6.dll
2008-07-12 09:30 . 2007-03-06 11:58 194,072 --a------ C:WindowsSystem32IVIresizePX.dll
2008-07-12 09:30 . 2007-03-06 11:58 26,136 --a------ C:WindowsSystem32IVIresize.dll
2008-07-12 09:29 . 2008-07-12 09:59 <REP> d-------- C:UsersAll UsersUlead Systems
2008-07-12 09:29 . 2008-07-12 09:59 <REP> d-------- C:ProgramDataUlead Systems
2008-07-12 09:29 . 2008-07-12 09:29 <REP> d-------- C:Program FilesUlead Systems
2008-07-12 09:29 . 2008-07-12 09:34 <REP> d-------- C:Program FilesDoblon
2008-07-12 09:29 . 2008-07-12 09:29 <REP> d-------- C:Program FilesCommon FilesUlead Systems
2008-07-12 09:24 . 2008-07-12 09:24 108,336 --a------ C:Windowsmswinsck.ocx
2008-07-11 08:16 . 2008-01-19 09:35 3,104,768 --a------ C:WindowsSystem32NlsData004e.dll
2008-07-07 07:57 . 2008-07-07 07:57 <REP> d-------- C:WindowsSystem32zh-TW
2008-07-07 07:57 . 2008-07-07 07:57 <REP> d-------- C:WindowsSystem32zh-CN
2008-07-07 07:57 . 2008-07-07 07:57 <REP> d-------- C:WindowsSystem32ko-KR
2008-07-07 07:57 . 2008-07-07 07:57 <REP> d-------- C:WindowsSystem32ja-JP
2008-07-07 07:56 . 2008-04-23 06:42 428,544 --a------ C:WindowsSystem32EncDec.dll
2008-07-07 07:56 . 2008-04-23 06:42 293,376 --a------ C:WindowsSystem32psisdecd.dll
2008-07-07 07:56 . 2008-04-23 06:41 218,624 --a------ C:WindowsSystem32psisrndr.ax
2008-07-07 07:56 . 2008-04-23 06:41 57,856 --a------ C:WindowsSystem32MSDvbNP.ax
2008-07-03 13:14 . 2008-07-03 13:14 <REP> d-------- C:UsersphilippeAppDataRoamingNero
2008-07-03 08:07 . 2008-07-12 09:35 69 --a------ C:WindowsNeroDigital.ini
2008-07-02 23:51 . 2008-07-02 23:51 <REP> d-------- C:WindowsSun
2008-07-02 08:10 . 2008-03-08 04:08 4,240,384 --a------ C:WindowsSystem32GameUXLegacyGDFs.dll
2008-07-02 08:10 . 2008-03-08 06:21 1,695,744 --a------ C:WindowsSystem32gameux.dll
2008-07-01 07:59 . 2008-07-01 07:59 <REP> d-------- C:WindowsSystem32Adobe
2008-07-01 07:59 . 2008-06-17 15:14 499,712 --a------ C:WindowsSystem32msvcp71.dll
2008-06-29 07:58 . 2007-12-27 23:47 210,432 --a------ C:WindowsSystem32ifsdrives.dll
2008-06-29 07:58 . 2008-01-20 17:56 187,840 --a------ C:WindowsSystem32driversext2fs.sys
2008-06-29 07:58 . 2007-12-16 17:13 77,760 --a------ C:WindowsSystem32ifsdrives.exe
2008-06-29 07:58 . 2007-12-29 19:50 58,816 --a------ C:WindowsSystem32driversifsmount.sys
2008-06-29 07:58 . 2007-08-26 13:11 724 --a------ C:WindowsSystem32ifsdrives_tasks.xml
2008-06-29 00:09 . 2008-06-29 00:09 <REP> d-------- C:UsersphilippeAppDataRoamingMedia Player Classic
2008-06-29 00:09 . 2008-06-29 00:09 <REP> d-------- C:UsersphilippeAppDataRoamingDivX
2008-06-19 22:59 . 2008-07-12 09:41 <REP> d-------- C:Program FilesSamurize
2008-06-19 22:56 . 2008-06-29 23:04 <REP> d-------- C:UsersphilippeAppDataRoamingMiniDm
2008-06-19 22:51 . 2008-07-10 02:57 <REP> d-------- C:UsersphilippeAppDataRoamingGrabIt
2008-06-19 22:48 . 2008-06-19 22:48 <REP> d-------- C:Program FilesNT6tunnel
2008-06-19 10:38 . 2008-06-19 10:38 <REP> d-------- C:UsersAll UsersGoogle
2008-06-19 10:38 . 2008-06-20 18:52 <REP> d-------- C:Program FilesGoogle
2008-06-19 10:28 . 2008-06-19 10:28 <REP> d-------- C:Program FilesITECIR
2008-06-19 10:28 . 2006-12-14 19:22 656,896 --a------ C:WindowsSystem32RemoteControlService.exe
2008-06-19 10:28 . 2004-04-02 11:23 17,024 --a------ C:WindowsSystem32driversGeneric.sys
2008-06-19 10:28 . 2006-12-28 18:24 7,808 --a------ C:WindowsSystem32driversITECIR.sys
2008-06-19 10:24 . 2008-06-19 10:24 <REP> d-------- C:Program FilesIEPro
2008-06-19 10:17 . 2008-06-19 10:17 <REP> d-------- C:Program FilesCanon
2008-06-19 10:16 . 2008-07-01 20:54 <REP> d-------- C:UsersphilippeAppDataRoamingTeraCopy
2008-06-19 10:11 . 2008-06-19 10:11 <REP> d-------- C:Program FilesGPLGS
2008-06-19 10:11 . 2008-06-19 10:11 <REP> d-------- C:Program FilesAcro Software
2008-06-19 10:11 . 2007-07-12 22:33 87,552 --a------ C:WindowsSystem32cpwmon2k.dll
2008-06-19 10:08 . 2008-06-19 10:08 <REP> d-------- C:UsersphilippeAppDataRoamingACD Systems
2008-06-19 10:04 . 2008-06-19 10:04 <REP> d-------- C:Program FilesTeraCopy
2008-06-19 10:01 . 2008-06-19 10:01 <REP> d-------- C:Program FilesuTorrent
2008-06-19 10:00 . 2008-07-12 09:55 <REP> d-------- C:UsersphilippeAppDataRoaminguTorrent
2008-06-19 09:54 . 2008-06-19 09:54 <REP> d-------- C:Program FilesCONEXANT
2008-06-19 09:34 . 2008-07-12 10:56 <REP> d--hs---- C:Boot
2008-06-19 09:34 . 2008-01-19 00:45 333,203 -rahs---- C:ootmgr
2008-06-19 09:34 . 2008-06-19 09:34 8,192 -ra-s---- C:BOOTSECT.BAK
2008-06-19 09:25 . 2008-06-19 09:25 <REP> dr------- C:WindowsSystem32configsystemprofileMusic
2008-06-19 09:18 . 2008-06-19 09:46 <REP> d-------- C:Program FilesOpenOffice.org 2.4
2008-06-19 09:17 . 2008-06-19 10:38 <REP> d-------- C:Program FilesJava
2008-06-19 09:17 . 2008-06-19 09:17 <REP> d-------- C:Program FilesCommon FilesJava
2008-06-19 09:10 . 2008-06-19 09:10 <REP> d-------- C:Program FilesCombined Community Codec Pack
2008-06-19 09:08 . 2008-02-29 09:11 988,216 --a------ C:WindowsSystem32winload.exe
2008-06-19 09:08 . 2008-02-29 09:11 927,288 --a------ C:WindowsSystem32winresume.exe
2008-06-19 09:08 . 2008-02-22 07:05 615,992 --a------ C:WindowsSystem32ci.dll
2008-06-19 09:08 . 2008-02-29 08:53 378,368 --a------ C:WindowsSystem32srcore.dll
2008-06-19 09:08 . 2008-02-29 06:12 318,464 --a------ C:WindowsSystem32
strui.exe
2008-06-19 09:08 . 2008-02-29 08:53 46,592 --a------ C:WindowsSystem32setbcdlocale.dll
2008-06-19 09:08 . 2008-02-29 08:53 40,960 --a------ C:WindowsSystem32srclient.dll
2008-06-19 09:08 . 2008-02-29 09:14 19,000 --a------ C:WindowsSystem32kd1394.dll
2008-06-19 09:08 . 2008-02-29 06:12 14,848 --a------ C:WindowsSystem32srdelayed.exe
2008-06-19 09:07 . 2008-06-19 09:07 <REP> d-------- C:UsersAll UsersWLInstaller
2008-06-19 09:07 . 2008-06-19 09:07 <REP> d-------- C:ProgramDataWLInstaller
2008-06-19 09:07 . 2008-06-19 09:07 <REP> d--hsc--- C:Program FilesCommon FilesWindowsLiveInstaller
2008-06-19 09:07 . 2008-02-29 06:21 2,032,128 --a------ C:WindowsSystem32win32k.sys
2008-06-19 09:07 . 2008-04-25 04:12 1,383,424 --a------ C:WindowsSystem32mshtml.tlb
2008-06-19 09:07 . 2008-04-26 10:08 1,314,816 --a------ C:WindowsSystem32quartz.dll
2008-06-19 09:07 . 2008-04-25 06:35 826,880 --a------ C:WindowsSystem32wininet.dll
2008-06-19 09:07 . 2008-02-22 06:57 295,936 --a------ C:WindowsSystem32gdi32.dll
2008-06-19 09:07 . 2008-05-10 03:33 113,664 --a------ C:WindowsSystem32drivers
mcast.sys
2008-06-19 09:06 . 2008-06-19 09:06 <REP> d-------- C:Program FilesRadmin Viewer 3
2008-06-19 09:06 . 2008-06-19 09:06 <REP> d-------- C:Program FilesGrabIt
2008-06-19 09:05 . 2008-06-19 09:05 28,124 --a------ C:UsersphilippeAppDataRoaming
vModes.dat
2008-06-19 08:59 . 2008-06-19 08:59 <REP> d-------- C:Program FilesDIFX
2008-06-19 08:58 . 2008-06-19 08:58 <REP> d-------- C:drivers
2008-06-19 08:51 . 2008-06-19 08:51 <REP> d-------- C:Program FilesSynaptics
2008-06-19 08:51 . 2008-07-12 09:30 <REP> d--h----- C:Program FilesInstallShield Installation Information
2008-06-19 08:51 . 2008-06-19 08:51 0 --ah----- C:WindowsSystem32driversMsft_Kernel_SynTP_01000.Wdf
2008-06-19 08:49 . 2008-06-19 08:49 <REP> dr------- C:UsersphilippeVideos
2008-06-19 08:49 . 2008-06-19 08:49 <REP> dr------- C:UsersphilippeSearches
2008-06-19 08:49 . 2008-06-19 08:49 <REP> dr------- C:UsersphilippeSaved Games
2008-06-19 08:49 . 2008-06-19 10:09 <REP> dr------- C:UsersphilippePictures
2008-06-19 08:49 . 2008-06-19 09:18 <REP> dr------- C:UsersphilippeMusic
2008-06-19 08:49 . 2008-06-19 08:49 <REP> dr------- C:UsersphilippeLinks
2008-06-19 08:49 . 2008-07-12 15:59 <REP> dr------- C:UsersphilippeDownloads
2008-06-19 08:49 . 2008-07-03 08:19 <REP> dr------- C:UsersphilippeDocuments
2008-06-19 08:49 . 2008-06-19 10:08 <REP> dr------- C:UsersphilippeContacts
2008-06-19 08:49 . 2006-11-02 14:35 <REP> d-------- C:UsersphilippeAppDataRoamingMedia Center Programs
2008-06-19 08:49 . 2008-06-19 08:49 <REP> d--h----- C:UsersphilippeAppData
2008-06-19 08:49 . 2008-07-12 10:57 <REP> d-------- C:Usersphilippe
2008-06-19 08:49 . 2008-06-19 08:49 <REP> d--hs---- C:$RECYCLE.BIN
2008-06-19 08:46 . 2008-06-19 08:46 <REP> dr------- C:WindowsSystem32configsystemprofileContacts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 08:01 --------- d-----w C:Program FilesCCleaner
2008-07-12 07:30 --------- d-----w C:Program FilesCommon FilesInstallShield
2008-07-12 07:24 --------- d-----w C:Program FilesNod32
2008-07-11 06:20 --------- d-----w C:ProgramDataMicrosoft Help
2008-06-26 03:29 801,280 ----a-w C:WindowsSystem32NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:WindowsSystem32NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:WindowsSystem32NlsLexicons0007.dll
2008-06-19 07:07 --------- d-----w C:Program FilesWindows Live
2008-06-19 07:02 --------- d-----w C:ProgramDataNVIDIA
2008-06-19 06:47 --------- d-sh--w C:ProgramDataModèles
2008-06-19 06:47 --------- d-sh--w C:ProgramDataMenu Démarrer
2008-06-19 06:47 --------- d-sh--w C:ProgramDataFavoris
2008-06-19 06:47 --------- d-sh--w C:ProgramDataDocuments
2008-06-19 06:47 --------- d-sh--w C:ProgramDataBureau
2008-06-19 06:47 --------- d-sh--w C:ProgramDataApplication Data
2008-06-19 06:47 --------- d-sh--w C:Program FilesFichiers communs
2008-05-10 03:35 564,736 ----a-w C:WindowsSystem32emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:WindowsSystem32wshext.dll
2008-05-08 21:59 430,080 ----a-w C:WindowsSystem32vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:WindowsSystem32scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:WindowsSystem32scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:WindowsSystem32wscript.exe
2008-05-08 21:58 135,168 ----a-w C:WindowsSystem32cscript.exe
2008-04-26 08:25 3,600,952 ----a-w C:WindowsSystem32
tkrnlpa.exe
2008-04-26 08:25 3,549,240 ----a-w C:WindowsSystem32
toskrnl.exe
2008-04-12 03:32 784,896 ----a-w C:WindowsSystem32
pcrt4.dll
2008-01-19 20:00 174 --sha-w C:Program Filesdesktop.ini
.
------- Sigcheck -------
2008-01-19 22:00 3145216 e8d4c4f97b638a1f8045a5895dcc0da3 C:Windowsexplorer.exe
2008-01-19 22:00 3145216 e8d4c4f97b638a1f8045a5895dcc0da3 C:Windowswinsxsx86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebfexplorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"swg"="C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe" [2008-06-19 22:23 171448]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableInstallerDetection"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.YV12"= yv12vfw.dll
"VIDC.FFDS"= C:PROGRA~1COMBIN~1FiltersFFDShowff_vfw.dll
"msacm.dvacm"= C:PROGRA~1COMMON~1ULEADS~1VioDvacm.acm
"msacm.MPEGacm"= C:PROGRA~1COMMON~1ULEADS~1MPEGMPEGacm.acm
"msacm.ulmp3acm"= C:PROGRA~1COMMON~1ULEADS~1MPEGulmp3acm.acm
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversion
un-]
"msnmsgr"="C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
"Sidebar"=C:Program FilesWindows Sidebarsidebar.exe /autoRun
"swg"=C:Program FilesGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
un-]
"AntiVir"=C:Windowsscvhost.exe
"icq lite"=C:Windowsscvhost.exe
"msconfig"=C:Windowsscvhost.exe
"Update Checker"=C:Windowsscvhost.exe
"Windows Update"=C:Windowsscvhost.exe
"SynTPEnh"=C:Program FilesSynapticsSynTPSynTPEnh.exe
"NvCplDaemon"=RUNDLL32.EXE C:Windowssystem32NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE C:Windowssystem32NvMcTray.dll,NvTaskbarInit
"NvSvc"=RUNDLL32.EXE C:Windowssystem32
vsvc.dll,nvsvcStart
"nod32kui"="C:Program FilesNod32
od32kui.exe" /WAITSERVICE
"NVHotkey"=rundll32.exe C:Windowssystem32
vHotkey.dll,Start
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
unservices-]
"AntiVir"=C:Windowsscvhost.exe
"icq lite"=C:Windowsscvhost.exe
"msconfig"=C:Windowsscvhost.exe
"Update Checker"=C:Windowsscvhost.exe
"Windows Update"=C:Windowsscvhost.exe
[HKLM~servicessharedaccessparametersfirewallpolicyFirewallRules]
"{61E5C0E6-9D9C-4C92-956F-86971074D53A}"= C:Program FilesWindows LiveMessengerlivecall.exe:Windows Live Messenger (Phone)
"{8CDB64E8-D2D2-4EE0-ABEF-FB8A576EDF81}"= TCP:6004|C:Program FilesMicrosoft OfficeOffice12outlook.exe:Microsoft Office Outlook
"{758FB37B-F84B-4661-864C-2C9B83D941EF}"= UDP:C:Program FilesuTorrentuTorrent.exe:µTorrent
"{CEF2725E-3F8D-4958-9CDC-01061A3066D8}"= TCP:C:Program FilesuTorrentuTorrent.exe:µTorrent
"TCP Query User{C123EF10-3D8D-40F1-AE22-E4F30A4E7A18}C:\program files\nt6tunnel\nt6tunnel.exe"= UDP:C:program files
t6tunnel
t6tunnel.exe:nt6tunnel.exe
"UDP Query User{6817F3E3-0E14-4337-9CED-7F2D8AD1B384}C:\program files\nt6tunnel\nt6tunnel.exe"= TCP:C:program files
t6tunnel
t6tunnel.exe:nt6tunnel.exe
"TCP Query User{D4BC644D-7732-457E-B577-9F0DF8A196F9}C:\program files\iepro\minidm.exe"= UDP:C:program filesieprominidm.exe:MiniDM
"UDP Query User{4742EED6-2FC3-4AC4-A47B-9CCE0AAFFFDF}C:\program files\iepro\minidm.exe"= TCP:C:program filesieprominidm.exe:MiniDM
"{44BF2059-BEB7-4FB2-B9A2-D5908AEA4576}"= UDP:C:Windowsscvhost.exe:Microsoft Windows
"{672464A1-0AD2-4715-BEB6-E615C4534E10}"= TCP:C:Windowsscvhost.exe:Microsoft Windows
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfileAuthorizedApplicationsList]
"C:\Program Files\IEPro\MiniDM.exe"= C:Program FilesIEProMiniDM.exe:*:Enabled:MiniDM
R1 Ext2fs;Ext2fs;C:Windowssystem32DRIVERSext2fs.sys [2008-01-20 17:56]
R1 IfsMount;IfsMount;C:Windowssystem32DRIVERSifsmount.sys [2007-12-29 19:50]
R2 AESTFilters;Andrea ST Filters Service;C:Windowssystem32aestsrv.exe [2007-08-29 14:25]
R2 UxTuneUp;TuneUp Extension de thème;C:WindowsSystem32svchost.exe [2008-01-19 22:00]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service;C:Windowssystem32driversCHDRT32.sys [2008-03-04 02:32]
R3 ITECIR;ITE EC CIR Driver (PMC);C:Windowssystem32DRIVERSITECIR.sys [2006-12-28 18:24]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:Windowssystem32DRIVERSyk60x86.sys [2007-12-06 09:51]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:Windowssystem32DRIVERS57nd60x.sys [2008-01-19 22:00]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:WindowsSystem32TuneUpDefragService.exe [2008-07-12 10:45]
S4 ITECIRService;ITE Remote Controler service;C:Program FilesITECIRRemoteControlService.exe [2006-12-15 11:59]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{4834f4b6-3dcb-11dd-8807-001b24a38b6c}]
shellAutoRuncommand - PortableAppsPortableAppsMenuPortableAppsMenu.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - DPS
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%system32soundschemes.exe /AddRegistration
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{FB1C4005-E01F-BF08-CD20-A6DE05E7081F}]
C:Windowsscvhost.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-07-12 14:00:00 C:WindowsTasksMaintenance en 1 clic.job"
- C:Program FilesTuneUp Utilities 2008OneClickStarter.exe
.
- - - - ORPHANS REMOVED - - - -
Toolbar-ITBar7Layout - (no file)
Toolbar-ITBar7Position - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-12 16:02:42
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-12 16:03:57
ComboFix-quarantined-files.txt 2008-07-12 14:03:55
Pre-Run: 91,213,316,096 octets libres
Post-Run: 91,193,626,624 octets libres
264 --- E O F --- 2008-07-11 06:22:44
Ensuite, j'ai lancé le scan avec gmer. Apparement, pas de soucis de ce coté la (je n'ai lancé la scan que sur le disque C)
JE vais essayer de redemarrer comme ca, pour voir.
Je vous tiens au courant.
Merci