Salut. Combofix à finalement répondu. Je l'envoie.ComboFix 08-05-15.3 - Alexandre 2008-05-18 0:15:15.5 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.171 [GMT -4:00]
Endroit: C:\Documents and Settings\Alexandre\Bureau\ComboFix.exe
[color=red]
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-18 to 2008-05-18 ))))))))))))))))))))))))))))))))))))
.
2008-05-16 13:22 . 2008-05-16 13:24 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-16 11:00 . 2008-05-17 11:29 <REP> d-------- C:\Program Files\a-squared Free
2008-05-16 10:13 . 2008-05-16 10:13 <REP> d-------- C:\Program Files\CCleaner
2008-05-14 16:36 . 2008-05-14 16:36 <REP> d-------- C:\Program Files\Lavasoft
2008-05-13 19:37 . 2008-05-13 19:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-05-13 12:37 . 2008-05-13 12:37 <REP> d-------- C:\Documents and Settings\Alexandre\DoctorWeb
2008-05-12 15:52 . 2008-05-13 19:57 <REP> d-------- C:\Program Files\Uniblue
2008-05-12 09:24 . 2008-05-12 09:24 <REP> d-------- C:\Program Files\Trend Micro
2008-05-12 09:19 . 2008-05-12 09:36 <REP> d-------- C:\Program Files\RamBoost XP
2008-05-10 10:29 . 2008-05-16 16:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-10 10:29 . 2008-05-10 10:29 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-09 18:19 . 2008-05-09 18:23 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-09 18:19 . 2008-05-09 18:19 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-09 18:19 . 2008-05-09 18:19 <REP> d-------- C:\Program Files\MSBuild
2008-05-09 18:17 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-09 17:57 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\
000001_.tmp
2008-05-09 13:08 . 2008-05-09 13:08 <REP> d-------- C:\Program Files\Windows Sidebar
2008-05-09 13:08 . 2008-05-09 15:26 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-09 13:08 . 2008-05-09 15:26 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-09 13:08 . 2008-05-09 15:26 10,740 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-09 13:08 . 2008-05-09 15:26 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-09 12:47 . 2008-05-14 13:45 <REP> d-------- C:\Documents and Settings\Alexandre\SecurityScans
2008-05-09 12:46 . 2008-05-09 12:46 <REP> d-------- C:\Program Files\Microsoft Baseline Security Analyzer 2
2008-05-08 16:10 . 2008-05-08 16:25 <REP> d-------- C:\
09924d572d43589b6be3
2008-05-08 13:40 . 2008-05-08 13:40 <REP> d-------- C:\Documents and Settings\Alexandre\IASViewer
2008-05-07 15:12 . 2008-04-13 19:33 116,736 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-05-07 15:12 . 2008-04-13 19:33 18,944 --a--c--- C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-05-07 15:12 . 2008-04-13 11:36 8,832 --a--c--- C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-05-07 15:12 . 2008-04-13 19:33 8,192 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
2008-05-06 16:48 . 2008-05-06 16:48 657,408 --a------ C:\WINDOWS\is-DNPPR.exe
2008-05-06 16:48 . 2008-05-06 16:48 13,715 --a------ C:\WINDOWS\is-DNPPR.msg
2008-05-06 16:48 . 2008-05-06 16:48 166 --a------ C:\WINDOWS\is-DNPPR.lst
2008-05-06 16:43 . 2008-05-08 16:27 <REP> d-------- C:\Program Files\Unlocker
2008-05-06 16:43 . 2008-05-06 16:44 <REP> d-------- C:\Documents and Settings\Alexandre\Application Data\Desktopicon
2008-05-06 13:15 . 2008-05-06 13:14 85,520 --a------ C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-05-05 17:23 . 2008-05-06 10:09 121 --a------ C:\WINDOWS\bdagent.INI
2008-05-05 10:39 . 2008-05-05 10:39 657,408 --a------ C:\WINDOWS\is-IDA3O.exe
2008-05-05 10:39 . 2008-05-05 10:39 13,715 --a------ C:\WINDOWS\is-IDA3O.msg
2008-05-05 10:39 . 2008-05-05 10:39 166 --a------ C:\WINDOWS\is-IDA3O.lst
2008-05-04 17:54 . 2008-05-04 17:54 657,408 --a------ C:\WINDOWS\is-G39N2.exe
2008-05-04 17:54 . 2008-05-04 17:54 13,715 --a------ C:\WINDOWS\is-G39N2.msg
2008-05-04 17:54 . 2008-05-04 17:54 166 --a------ C:\WINDOWS\is-G39N2.lst
2008-05-01 13:51 . 2008-04-13 18:57 32,128 --a--c--- C:\WINDOWS\system32\dllcache\wceusbsh.sys
2008-05-01 13:50 . 2008-04-13 11:40 5,376 --a--c--- C:\WINDOWS\system32\dllcache\viaide.sys
2008-05-01 13:49 . 2008-04-13 11:45 26,112 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-05-01 13:49 . 2008-04-13 11:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-05-01 13:49 . 2008-04-13 11:45 17,152 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-05-01 13:47 . 2008-04-13 19:34 82,944 --a--c--- C:\WINDOWS\system32\dllcache\tp4mon.exe
2008-05-01 13:46 . 2008-04-13 11:40 149,376 --a--c--- C:\WINDOWS\system32\dllcache\tffsport.sys
2008-05-01 13:45 . 2008-05-01 13:45 9,896 --a------ C:\WINDOWS\system32\drivers\fiddrv.sys
2008-05-01 13:44 . 2008-04-13 11:40 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonyait.sys
2008-05-01 13:42 . 2008-04-13 11:36 16,000 --a--c--- C:\WINDOWS\system32\dllcache\smbbatt.sys
2008-05-01 13:42 . 2008-04-13 11:36 6,912 --a--c--- C:\WINDOWS\system32\dllcache\smbclass.sys
2008-05-01 13:41 . 2008-04-13 11:45 11,520 --a--c--- C:\WINDOWS\system32\dllcache\scsiscan.sys
2008-05-01 13:40 . 2008-04-13 11:40 43,904 --a--c--- C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-05-01 13:39 . 2008-04-13 19:33 29,696 --a--c--- C:\WINDOWS\system32\dllcache\rw450ext.dll
2008-05-01 13:39 . 2008-04-13 19:33 28,160 --a--c--- C:\WINDOWS\system32\dllcache\rw430ext.dll
2008-05-01 13:38 . 2008-04-13 18:58 79,360 --a--c--- C:\WINDOWS\system32\dllcache\rocket.sys
2008-05-01 13:37 . 2008-04-13 19:33 363,520 --a--c--- C:\WINDOWS\system32\dllcache\psisdecd.dll
2008-05-01 13:37 . 2008-04-13 19:33 159,232 --a--c--- C:\WINDOWS\system32\dllcache\ptpusd.dll
2008-05-01 13:37 . 2008-04-13 19:34 33,280 --a--c--- C:\WINDOWS\system32\dllcache\psisrndr.ax
2008-05-01 13:37 . 2008-04-13 11:41 17,664 --a--c--- C:\WINDOWS\system32\dllcache\ppa3.sys
2008-05-01 13:37 . 2008-04-13 11:40 8,832 --a--c--- C:\WINDOWS\system32\dllcache\powerfil.sys
2008-05-01 13:37 . 2008-04-13 11:40 6,016 --a--c--- C:\WINDOWS\system32\dllcache\qic157.sys
2008-05-01 13:36 . 2008-04-13 19:32 259,328 --a--c--- C:\WINDOWS\system32\dllcache\perm3dd.dll
2008-05-01 13:36 . 2008-04-13 19:32 211,584 --a--c--- C:\WINDOWS\system32\dllcache\perm2dll.dll
2008-05-01 13:36 . 2008-04-13 11:44 28,032 --a--c--- C:\WINDOWS\system32\dllcache\perm3.sys
2008-05-01 13:36 . 2008-04-13 11:44 27,904 --a--c--- C:\WINDOWS\system32\dllcache\perm2.sys
2008-05-01 13:33 . 2008-04-13 19:07 2,067,968 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-05-01 13:33 . 2008-04-13 11:46 61,696 --a--c--- C:\WINDOWS\system32\dllcache\ohci1394.sys
2008-05-01 13:32 . 2008-04-13 11:54 28,672 --a--c--- C:\WINDOWS\system32\dllcache\nscirda.sys
2008-05-01 13:31 . 2008-04-13 11:46 49,024 --a--c--- C:\WINDOWS\system32\dllcache\mstape.sys
2008-05-01 13:31 . 2008-04-13 11:54 22,016 --a--c--- C:\WINDOWS\system32\dllcache\msircomm.sys
2008-05-01 13:30 . 2008-04-13 19:34 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-05-01 13:30 . 2008-04-13 11:46 51,200 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-05-01 13:30 . 2008-04-13 11:41 26,112 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
2008-05-01 13:30 . 2008-04-13 11:46 15,232 --a--c--- C:\WINDOWS\system32\dllcache\mpe.sys
2008-05-01 13:29 . 2008-04-13 11:40 7,040 --a--c--- C:\WINDOWS\system32\dllcache\ltotape.sys
2008-05-01 13:28 . 2008-04-13 19:33 254,464 --a--c--- C:\WINDOWS\system32\dllcache\kdsusd.dll
2008-05-01 13:28 . 2008-04-13 19:33 49,152 --a--c--- C:\WINDOWS\system32\dllcache\kdsui.dll
2008-05-01 13:28 . 2008-04-13 11:40 34,688 --a--c--- C:\WINDOWS\system32\dllcache\lbrtfdc.sys
2008-05-01 13:28 . 2008-04-13 19:05 14,720 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-05-01 13:27 . 2008-04-13 19:34 153,088 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2008-05-01 13:27 . 2008-04-13 11:54 88,192 --a--c--- C:\WINDOWS\system32\dllcache\irda.sys
2008-05-01 13:27 . 2008-04-13 19:33 29,184 --a--c--- C:\WINDOWS\system32\dllcache\irmon.dll
2008-05-01 13:26 . 2008-04-13 19:33 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-05-01 13:26 . 2008-04-13 11:41 18,560 --a--c--- C:\WINDOWS\system32\dllcache\i2omp.sys
2008-05-01 13:26 . 2008-04-13 11:41 8,576 --a--c--- C:\WINDOWS\system32\dllcache\i2omgmt.sys
2008-05-01 13:24 . 2008-04-13 18:59 28,544 --a--c--- C:\WINDOWS\system32\dllcache\grserial.sys
2008-05-01 13:24 . 2008-04-13 19:33 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-05-01 13:24 . 2008-04-13 11:36 20,352 --a--c--- C:\WINDOWS\system32\dllcache\hidbatt.sys
2008-05-01 13:23 . 2008-04-13 11:45 59,136 --a--c--- C:\WINDOWS\system32\dllcache\gckernel.sys
2008-05-01 13:20 . 2008-04-13 11:39 206,976 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-05-01 13:20 . 2008-04-13 19:34 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-05-01 13:20 . 2008-04-13 11:40 8,320 --a--c--- C:\WINDOWS\system32\dllcache\dlttape.sys
2008-05-01 13:19 . 2008-04-13 19:33 252,416 --a--c--- C:\WINDOWS\system32\dllcache\ctmasetp.dll
2008-05-01 13:19 . 2008-04-13 11:36 10,240 --a--c--- C:\WINDOWS\system32\dllcache\compbatt.sys
2008-05-01 13:18 . 2008-04-13 19:33 121,856 --a--c--- C:\WINDOWS\system32\dllcache\camext30.dll
2008-05-01 13:18 . 2008-04-13 11:36 13,952 --a--c--- C:\WINDOWS\system32\dllcache\cmbatt.sys
2008-05-01 13:18 . 2008-04-13 11:41 8,192 --a--c--- C:\WINDOWS\system32\dllcache\changer.sys
2008-05-01 13:17 . 2008-04-13 11:46 38,912 --a--c--- C:\WINDOWS\system32\dllcache\avc.sys
2008-05-01 13:17 . 2008-04-13 19:34 18,432 --a--c--- C:\WINDOWS\system32\dllcache\bdaplgin.ax
2008-05-01 13:17 . 2008-04-13 11:36 14,208 --a--c--- C:\WINDOWS\system32\dllcache\battc.sys
2008-05-01 13:17 . 2008-04-13 11:46 13,696 --a--c--- C:\WINDOWS\system32\dllcache\avcstrm.sys
2008-05-01 13:17 . 2008-04-13 11:46 11,776 --a--c--- C:\WINDOWS\system32\dllcache\bdasup.sys
2008-05-01 13:15 . 2008-04-13 19:08 2,191,104 --a--c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-05-01 13:15 . 2008-04-13 11:46 53,376 --a--c--- C:\WINDOWS\system32\dllcache\1394bus.sys
2008-05-01 13:15 . 2008-04-13 11:46 48,128 --a--c--- C:\WINDOWS\system32\dllcache\61883.sys
2008-05-01 13:15 . 2008-04-13 11:40 12,288 --a--c--- C:\WINDOWS\system32\dllcache\4mmdat.sys
2008-04-30 12:37 . 2008-05-07 13:50 <REP> d-------- C:\Documents and Settings\Alexandre\Application Data\WinPatrol
2008-04-30 10:37 . 2008-04-30 10:37 <REP> d-------- C:\WINDOWS\system32\fr
2008-04-30 10:36 . 2008-04-13 19:33 285,184 --a------ C:\WINDOWS\system32\fxscomex.dll
2008-04-30 10:36 . 2008-04-13 19:33 285,184 --a--c--- C:\WINDOWS\system32\dllcache\fxscomex.dll
2008-04-30 10:36 . 2008-04-13 19:34 26,112 --a--c--- C:\WINDOWS\system32\dllcache\evntcmd.exe
2008-04-30 10:36 . 2008-04-13 19:33 24,064 --a------ C:\WINDOWS\system32\fxsmon.dll
2008-04-30 10:36 . 2008-04-13 19:33 24,064 --a--c--- C:\WINDOWS\system32\dllcache\fxsmon.dll
2008-04-30 10:36 . 2007-04-02 11:26 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0411.dll
2008-04-30 10:36 . 2007-04-02 11:26 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0404.dll
2008-04-30 10:34 . 2008-04-13 19:33 563,712 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2008-04-30 10:33 . 2008-04-30 10:38 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-04-30 10:30 . 2008-04-13 11:23 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2008-04-30 10:20 . 2008-05-09 17:54 <REP> d-------- C:\WINDOWS\EHome
2008-04-30 09:39 . 2001-08-23 17:47 99,865 --a--c--- C:\WINDOWS\system32\dllcache\xlog.exe
2008-04-30 09:39 . 2001-08-23 17:47 27,648 --a--c--- C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-04-30 09:39 . 2001-08-23 17:47 23,040 --a--c--- C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-16 23:10 --------- d-----w C:\Documents and Settings\Alexandre\Application Data\LimeWire
2008-05-16 18:21 --------- d-----w C:\Program Files\BearShare MediaBar
2008-05-16 17:30 --------- d-----w C:\Program Files\3B Software
2008-05-16 17:26 --------- d-----w C:\Program Files\Yahoo!
2008-05-14 21:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-14 20:36 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-13 23:57 --------- d-----w C:\Documents and Settings\Alexandre\Application Data\Uniblue
2008-05-13 20:14 --------- d-----w C:\Program Files\Norton Security Scan
2008-05-13 13:25 --------- d-----w C:\Program Files\coolpro2
2008-05-12 20:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-12 20:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-11 14:06 --------- d-----w C:\Program Files\LimeWire
2008-05-09 21:23 103,776 ----a-w C:\Documents and Settings\Alexandre\System_Restore.exe
2008-05-09 19:34 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-09 19:26 --------- d-----w C:\Program Files\Symantec
2008-05-09 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-05 14:01 --------- d-----w C:\Program Files\Tibia Auto
2008-05-01 20:49 --------- d-----w C:\Program Files\RogueRemover FREE
2008-04-30 17:06 --------- d-----w C:\Program Files\PKR
2008-04-30 17:06 --------- d-----w C:\Program Files\MoodLogic
2008-04-30 17:06 --------- d-----w C:\Program Files\ExplorerXP
2008-04-30 17:05 --------- d--h--w C:\Documents and Settings\Alexandre\Application Data\VideoGift2
2008-04-30 17:05 --------- d-----w C:\Program Files\TchecMeet
2008-04-30 17:05 --------- d-----w C:\Program Files\Revenu Québec 2007
2008-04-30 17:05 --------- d-----w C:\Documents and Settings\Alexandre\Application Data\uTorrent
2008-04-30 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-04-29 17:34 --------- d-----w C:\Documents and Settings\Alexandre\Application Data\Onlineteam
2008-04-25 19:59 --------- d-----w C:\Program Files\Google
2008-04-25 16:54 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-24 13:28 357,768 -c--a-w C:\Documents and Settings\Alexandre\SymXPep2.dll
2008-04-21 19:55 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-18 18:37 --------- d-----w C:\Program Files\Trellix2
2008-04-14 14:40 204,800 ----a-w C:\WINDOWS\system32\rwrhgymp.dll
2008-04-13 23:50 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-13 23:37 332,800 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-13 23:33 98,816 ----a-w C:\WINDOWS\system32\psbase.dll
2008-04-13 23:32 764,416 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-04-13 23:32 61,471 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-13 23:32 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
2008-04-13 23:10 73,600 ----a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-13 23:09 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-13 23:09 68,608 ----a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-13 23:09 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-13 23:09 120,576 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-13 23:07 2,147,328 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 23:07 2,025,984 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 23:06 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 23:05 800,256 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 23:05 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-13 23:05 154,496 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 23:04 93,184 ------w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 23:04 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-13 23:03 81,920 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 23:03 5,504 ----a-w C:\WINDOWS\system32\drivers\intelide.sys
2008-04-13 23:03 40,576 ----a-w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-13 23:02 50,688 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 23:02 40,960 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-13 23:01 572,416 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 23:00 66,048 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 23:00 54,144 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 22:59 25,856 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 22:59 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-13 22:58 273,664 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 22:58 1,845,760 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 22:58 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 22:57 70,144 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 22:57 58,752 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-04-13 22:57 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-13 22:56 53,376 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 22:55 701,440 ------w C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-04-13 22:55 40,064 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-13 22:55 327,168 ------w C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-04-13 22:54 41,856 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-13 22:54 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-13 22:54 103,936 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 22:53 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 22:53 23,680 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-13 22:52 188,672 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 16:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 16:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 16:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 16:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 16:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 16:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 16:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 16:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 16:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 16:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 16:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 16:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 16:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 16:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 16:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 16:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 16:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 16:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 16:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 16:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 16:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 16:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-05-09 13:40 116088 --a------ C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [ ]
"Uniblue SpeedUpMyPC"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:34 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-12 20:02 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-08-02 08:30 7110656]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 19:34 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-12 20:02 68856]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceActiveDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJCrQji]
ljJCrQji.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnnmkh]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rwrhgymp]
rwrhgymp.dll 2008-04-14 10:40 204800 C:\WINDOWS\system32\rwrhgymp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.DVSD"= pdvcodec.dll
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 18:01]
S2 MKEMUSB;Panasonic Digital Palmcorder;C:\WINDOWS\system32\Drivers\Mkemusb.sys [2001-08-08 19:52]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 DCamUSBMke;USB Video Camera for Panasonic Digital Palmcorder;C:\WINDOWS\system32\Drivers\Mkeusbi.sys [2001-12-18 12:38]
S3 EzInstall;EzInstall;D:\ezinstall\EzInstall.sys []
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-16 13:10:00 C:\WINDOWS\Tasks\alexandre.job"
- C:\Program Files\BitDefender\BitDefender Backup\backup.exe
"2008-05-13 00:03:40 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - Alexandre.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
"2008-05-13 23:33:38 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-05-13 23:33:37 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-05-17 04:42:35 C:\WINDOWS\Tasks\User_Feed_Synchronization-{C17F134B-3553-486F-BACE-25024C360C2F}.job"
- C:\WINDOWS\system32\msfeedssync.exe
"2008-05-18 03:23:02 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-18 00:17:41
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\rwrhgymp.dll
.
Temps d'accomplissement: 2008-05-18 0:18:43
ComboFix-quarantined-files.txt 2008-05-18 04:18:32
Pre-Run: 116,198,772,736 octets libres
Post-Run: 116,181,082,112 octets libres
315 --- E O F --- 2008-04-12 14:33:18