bonjour Lazzzy,
pas de nouvelles alors j'ai fais comme je pensais en espérant pas avoir fais de bétises.
voici le resultat:
VundoFix V7.0.3
Scan started at 23:43:34 28/03/2008
Listing files found while scanning....
C:\WINDOWS\system32\beopfktu.dll
VundoFix V7.0.3
Scan started at 05:56:25 29/03/2008
Listing files found while scanning....
C:\WINDOWS\system32\beopfktu.dll
VundoFix V7.0.3
Scan started at 08:04:22 29/03/2008
Listing files found while scanning....
C:\WINDOWS\system32\beopfktu.dll
ComboFix 08-03-27.1 - Propriétaire 2008-03-29 18:26:51.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.324 [GMT 1:00]
Endroit: C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM83918344.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\beopfktu.dll
C:\WINDOWS\system32\hgghghh.dll
C:\WINDOWS\system32\pmnmlll.dll
C:\WINDOWS\system32\rqrss.dll
C:\WINDOWS\system32\ssrqr.ini
C:\WINDOWS\system32\ssrqr.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-29 ))))))))))))))))))))))))))))))))))))
.
2008-03-28 23:43 . 2008-03-29 05:56 <REP> d-------- C:\VundoFix Backups
2008-03-28 18:35 . 2008-03-28 18:35 <REP> d-------- C:\Program Files\Trend Micro
2008-03-28 06:22 . 2007-12-07 03:08 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-28 06:22 . 2007-12-07 03:08 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-28 06:22 . 2007-12-07 03:08 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-28 06:22 . 2007-12-07 03:08 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-28 06:22 . 2007-12-07 03:08 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-28 06:22 . 2007-12-07 03:08 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-28 06:22 . 2007-12-06 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-27 22:27 . 2008-03-27 22:27 36,248,233 --a------ C:\WINDOWS\LPT$VPN.189
2008-03-27 22:26 . 2008-03-27 22:27 36,248,233 --a------ C:\WINDOWS\VPTNFILE.189
2008-03-27 22:25 . 2008-03-27 22:27 <REP> d-------- C:\WINDOWS\AU_Temp
2008-03-27 22:17 . 2008-03-27 22:17 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-03-24 21:38 . 2008-03-24 21:38 446,976 --a------ C:\WINDOWS\system32\ShellMPD.dll
2008-03-24 21:37 . 2008-03-24 21:38 <REP> d-------- C:\Program Files\MSN Pictures Displayer
2008-03-23 08:56 . 2008-03-28 20:51 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2008-03-20 11:59 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-03-20 11:59 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-03-20 11:59 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-03-20 11:59 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-03-20 11:59 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-03-20 11:59 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-03-20 11:59 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-03-20 11:59 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-03-16 10:21 . 2004-08-04 00:55 20,992 --a------ C:\WINDOWS\system32\dshowext.ax
2008-03-16 10:21 . 2004-08-04 00:55 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-03-15 07:54 . 2008-03-15 07:54 <REP> d-------- C:\Program Files\Gadwin Systems
2008-03-15 07:33 . 2008-03-15 07:52 <REP> d-------- C:\Program Files\CaptEcran
2008-03-13 15:55 . 2008-03-15 18:27 <REP> dr------- C:\Documents and Settings\LocalService\Mes documents
2008-03-11 12:53 . 2008-03-11 13:57 <REP> d-------- C:\Program Files\MP3Gain
2008-03-08 15:03 . 2008-03-08 15:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-03-08 13:28 . 2008-03-08 13:31 24 ---hs---- C:\WINDOWS\S0A53EBB1.tmp
2008-03-08 13:27 . 2008-03-08 13:27 <REP> d-------- C:\Program Files\SlySoft
2008-03-05 22:03 . 2008-03-05 22:03 <REP> d-------- C:\Program Files\Lavalys
2008-03-05 11:15 . 2008-03-05 11:23 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-03-05 10:54 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-05 10:54 . 2007-07-01 04:36 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-03 14:34 . 2008-03-11 18:56 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-02-29 20:56 . 2008-03-02 21:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-29 20:52 . 2008-02-29 20:52 <REP> d-------- C:\Program Files\IObit
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-27 21:27 86,094 ----a-w C:\WINDOWS\BPMNT.dll
2008-03-27 21:27 1,163,344 ----a-w C:\WINDOWS\vsapi32.dll
2008-03-27 20:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-03-24 17:15 --------- d-----w C:\Program Files\LimeWire
2008-03-22 08:40 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-03-22 08:40 333,576 ----a-w C:\WINDOWS\tsc.exe
2008-03-19 19:16 --------- d-----w C:\Program Files\RogueRemover FREE
2008-03-19 19:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-03-16 17:06 --------- d-----w C:\Program Files\Java
2008-03-15 17:51 57,632 ----a-w C:\StiImg.dat
2008-02-29 19:52 --------- d-----w C:\Program Files\Yahoo!
2008-02-26 18:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-26 17:51 --------- d-----w C:\Program Files\DVD Shrink
2008-02-18 21:58 --------- d-----w C:\Program Files\a-squared Anti-Dialer
2008-02-16 16:09 --------- d-----w C:\Program Files\CyberLink
2008-02-16 15:54 --------- d-----w C:\Program Files\RamBoost XP
2008-02-13 19:07 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2008-02-12 17:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-10 23:22 --------- d-----w C:\Program Files\MSN Games
2008-02-10 23:21 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-10 22:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\NannyMania
2008-02-10 22:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Oberon Media
2008-02-07 11:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle VideoSpin
2008-02-07 09:44 --------- d-----w C:\Program Files\Pinnacle
2008-02-07 09:44 --------- d-----w C:\Program Files\Fichiers communs\Yahoo!
2008-02-07 09:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\VideoSpin
2008-02-07 09:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-02-05 19:30 --------- d-----w C:\Program Files\DivX
2008-01-28 19:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-28 19:11 --------- d-----w C:\Program Files\ArcSoft
2008-01-28 19:06 --------- d-----w C:\Program Files\DIFX
2008-01-28 19:05 --------- d-----w C:\Program Files\Mars
2008-01-28 09:50 --------- d-----w C:\Program Files\Trust
2008-01-28 09:50 --------- d-----w C:\Program Files\Fichiers communs\PCCamera
2008-01-14 16:18 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 10:21 153136]
"IncrediMail"="C:\PROGRA~1\INCRED~1\bin\IncMail.exe" [2007-12-04 18:01 214456]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"Gadwin PrintScreen"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 09:42 495616]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 14:28 577536 C:\WINDOWS\soundman.exe]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 09:05 579072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [ ]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-05 13:00 160768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-09 11:08 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmlll]
pmnmlll.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=C:\WINDOWS\pss\MSN Pictures Displayer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
C:\Program Files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 2004-08-05 13:00 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 20:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2007-04-19 13:26 484904 C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechGalleryRepair]
--a------ 2002-12-10 18:32 155648 C:\Program Files\Logitech\ImageStudio\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-12-10 18:31 61440 C:\Program Files\Logitech\ImageStudio\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
C:\Program Files\Pando Networks\Pando\Pando.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-12-13 05:03 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Pro