re_bjr
1ooo excuses x le retard mais pbs connexion FAI...pour ne pas changer!!
je précise que j'ai tjrs cette page "douteuse" de démarrage d'IE7 et j'ai des doutes que l'URL incriminé soit en réalité un virus...sauf meilleur avis...quoiqu'il en soit, en réponse à ton dernier post, ci-joint log*txt édité par ComboFix :
ComboFix 09-04-04.01 - MARIE 2009-04-06 8:59:56.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2046.1039 [GMT 2:00]
Lancé depuis: c:\users\MARIE\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-06 au 2009-04-06 ))))))))))))))))))))))))))))))))))))
.
2009-04-05 17:09 . 2009-04-05 17:09 <REP> d-------- c:\windows\System32\Kaspersky Lab
2009-04-05 10:11 . 2009-04-05 10:11 <REP> d-------- c:\users\MARIE\AppData\Roaming\vlc
2009-04-05 09:04 . 2009-04-05 09:04 <REP> d-------- c:\program files\CaptEcran
2009-04-05 09:04 . 2006-05-03 20:14 372,736 --a------ c:\windows\System32\ijl15.dll
2009-04-05 09:04 . 2006-05-03 20:13 119,568 --a------ c:\windows\System32\vb6fr.DLL
2009-04-04 10:22 . 2009-04-04 10:22 <REP> d-------- c:\program files\IrfanView
2009-04-04 10:11 . 2009-04-04 10:20 <REP> d-------- c:\users\MARIE\AppData\Roaming\Ethereal
2009-04-04 10:09 . 2009-04-04 10:09 <REP> d-------- C:\Temp
2009-04-04 10:09 . 2009-04-04 10:09 <REP> d-------- c:\program files\WinPcap
2009-04-03 15:46 . 2008-04-14 04:12 1,384,479 --a------ c:\windows\System32\temp.00C
2009-04-03 15:46 . 2008-05-09 14:53 172,032 --a------ c:\windows\System32\temp.00B
2009-04-03 15:46 . 2008-04-13 19:42 16,896 --a------ c:\windows\System32\temp.00A
2009-04-03 15:39 . 2009-04-03 15:41 <REP> d--h----- c:\users\MARIE\AppData\Roaming\User Recycle Bin.{645FF040-5081-101B-9F08-00AA002F954E}
2009-04-03 15:37 . 2008-04-14 04:12 1,384,479 --a------ c:\windows\System32\temp.009
2009-04-03 15:37 . 2008-05-09 14:53 172,032 --a------ c:\windows\System32\temp.008
2009-04-03 15:37 . 2008-04-13 19:42 16,896 --a------ c:\windows\System32\temp.007
2009-04-03 15:36 . 2009-04-04 09:11 <REP> d-------- c:\users\MARIE\AppData\Roaming\SEDE
2009-04-03 15:36 . 2009-04-03 15:46 <REP> d-------- c:\program files\Secret Disk
2009-04-03 15:36 . 2008-04-14 04:12 1,384,479 --a------ c:\windows\System32\temp.006
2009-04-03 15:36 . 2008-04-14 04:12 1,384,479 --a------ c:\windows\System32\temp.003
2009-04-03 15:36 . 2008-05-09 14:53 172,032 --a------ c:\windows\System32\temp.005
2009-04-03 15:36 . 2008-05-09 14:53 172,032 --a------ c:\windows\System32\temp.002
2009-04-03 15:36 . 2008-04-13 19:42 16,896 --a------ c:\windows\System32\temp.004
2009-04-03 15:36 . 2008-04-13 19:42 16,896 --a------ c:\windows\System32\temp.001
2009-04-03 14:05 . 2009-04-03 14:05 <REP> d-------- c:\users\MARIE\AppData\Roaming\BinarySense
2009-04-03 14:05 . 2009-04-03 14:05 <REP> d-------- c:\program files\Common Files\BinarySense
2009-04-03 14:05 . 2009-04-03 14:05 <REP> d-------- c:\program files\BinarySense
2009-04-03 13:54 . 2001-11-27 18:27 210,200 --a------ c:\windows\System32\TWNPRO3.DLL
2009-03-31 18:01 . 2009-03-31 18:01 603,904 --a------ c:\windows\System32\TUProgSt.exe
2009-03-31 18:01 . 2009-03-31 18:01 360,192 --a------ c:\windows\System32\TuneUpDefragService.exe
2009-03-31 18:01 . 2008-12-11 14:31 27,904 --a------ c:\windows\System32\uxtuneup.dll
2009-03-31 18:01 . 2008-12-11 14:31 17,152 --a------ c:\windows\System32\authuitu.dll
2009-03-31 10:35 . 2009-03-31 10:35 <REP> d-------- c:\users\MARIE\AppData\Roaming\TuneUp Software
2009-03-31 10:34 . 2009-03-31 10:34 <REP> d-------- c:\users\All Users\TuneUp Software
2009-03-31 10:34 . 2009-03-31 10:34 <REP> d-------- c:\programdata\TuneUp Software
2009-03-31 10:34 . 2009-03-31 18:01 <REP> d-------- c:\program files\TuneUp Utilities 2009
2009-03-31 10:33 . 2009-03-31 10:33 <REP> d--hs---- c:\users\All Users\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-31 10:33 . 2009-03-31 10:33 <REP> d--hs---- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-28 17:37 . 2009-03-28 17:37 <REP> d-------- c:\users\All Users\Kaspersky Lab Setup Files
2009-03-28 17:37 . 2009-03-28 17:37 <REP> d-------- c:\programdata\Kaspersky Lab Setup Files
2009-03-24 11:09 . 2009-03-24 11:09 <REP> d-------- c:\users\All Users\My Music
2009-03-24 11:09 . 2009-03-24 11:09 <REP> d-------- c:\programdata\My Music
2009-03-24 11:08 . 2009-03-24 11:08 1,365,584 --a------ c:\users\All Users\pswi_preloaded.exe
2009-03-24 11:08 . 2009-03-24 11:08 1,365,584 --a------ c:\programdata\pswi_preloaded.exe
2009-03-23 10:14 . 2009-03-23 14:40 <REP> d-------- c:\program files\TomTom HOME 2
2009-03-21 09:35 . 2009-03-21 09:35 <REP> d-------- c:\program files\TomTom International B.V
2009-03-13 10:40 . 2009-03-17 17:12 <REP> d-------- C:\GarminPOIUpdater
2009-03-12 10:43 . 2009-03-12 10:43 <REP> d-------- C:\WebUpdater
2009-03-11 09:35 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 09:35 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 09:35 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-11 09:35 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 09:35 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 09:35 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-08 18:40 . 2009-03-08 18:40 0 --ah----- c:\windows\System32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-03-08 13:46 . 2009-03-08 13:46 <REP> d-------- c:\users\All Users\GARMIN
2009-03-08 13:46 . 2009-03-08 13:46 <REP> d-------- c:\programdata\GARMIN
2009-03-08 13:24 . 2009-03-08 13:24 <REP> d-------- c:\users\MARIE\{cb5f830b-d414-46ae-a27d-28e5e7544ff1}
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 06:43 --------- d---a-w c:\programdata\TEMP
2009-04-05 11:56 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-05 11:52 --------- d-----w c:\program files\Trend Micro
2009-04-04 08:33 --------- d-----w c:\users\MARIE\AppData\Roaming\uTorrent
2009-04-04 07:59 --------- d-----w c:\users\MARIE\AppData\Roaming\IrfanView
2009-04-03 14:57 5,324 ----a-w c:\users\MARIE\AppData\Roaming\wklnhst.dat
2009-04-02 07:27 --------- d-----w c:\program files\SpywareBlaster
2009-03-31 15:37 --------- d-----w c:\program files\Windows Live
2009-03-31 15:34 --------- d-----w c:\program files\Dell Support Center
2009-03-31 15:25 --------- d-----w c:\programdata\SupportSoft
2009-03-30 13:27 --------- d-----w c:\users\MARIE\AppData\Roaming\Corel
2009-03-26 14:49 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 14:49 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-25 13:04 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-25 07:25 --------- d-----w c:\program files\Java
2009-03-25 07:10 --------- d-----w c:\program files\McAfee
2009-03-24 09:05 --------- d-----w c:\program files\Corel
2009-03-14 15:41 --------- d-----w c:\users\MARIE\AppData\Roaming\Nokia
2009-03-12 12:31 --------- d-----w c:\program files\Common Files\Adobe
2009-03-12 07:07 --------- d-----w c:\program files\Windows Mail
2009-03-09 04:19 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-03-08 11:58 --------- d-----w c:\users\MARIE\AppData\Roaming\GARMIN
2009-03-05 16:07 --------- d-----w c:\users\MARIE\AppData\Roaming\Megaupload
2009-03-05 16:06 --------- d-----w c:\users\MARIE\AppData\Roaming\MegauploadToolbar
2009-03-05 16:06 --------- d-----w c:\programdata\Megaupload
2009-03-05 16:06 --------- d-----w c:\programdata\EmailNotifier
2009-03-05 16:06 --------- d-----w c:\program files\MegauploadToolbar
2009-03-05 16:05 --------- d-----w c:\program files\Megaupload
2009-03-05 16:04 --------- d-----w c:\users\MARIE\AppData\Roaming\InstallShield
2009-03-05 11:59 --------- d-----w c:\programdata\McAfee
2009-03-03 14:12 --------- d-----w c:\program files\Flash 32
2009-03-03 12:42 --------- d-----w c:\program files\Microsoft
2009-03-03 12:41 --------- d-----w c:\program files\Windows Live SkyDrive
2009-02-27 07:12 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-26 07:45 --------- d-----w c:\program files\Simple PDF
2009-02-25 15:48 --------- d--h--w c:\programdata\CanonBJ
2009-02-25 15:35 --------- d-----w c:\programdata\metier2000Apps
2009-02-24 12:46 --------- d-----w c:\users\MARIE\AppData\Roaming\Snapter Images
2009-02-23 11:57 --------- d-----w c:\users\MARIE\AppData\Roaming\Azureus
2009-02-23 11:46 --------- d-----w c:\programdata\Azureus
2009-02-20 08:22 --------- d-----w c:\program files\Secunia
2009-02-20 08:15 --------- d-----w c:\program files\Pictomio
2009-02-20 08:08 --------- d-----w c:\users\MARIE\AppData\Roaming\KC Softwares
2009-02-20 08:08 --------- d-----w c:\program files\KC Softwares
2009-02-15 16:06 --------- d-----w c:\program files\Resco
2009-02-15 11:57 --------- d-----w c:\program files\MagicSS
2009-02-15 10:45 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-02-10 10:26 --------- d-----w c:\users\MARIE\AppData\Roaming\dvdcss
2009-02-06 18:39 308,600 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:52 49,504 ----a-w c:\windows\System32\sirenacm.dll
2009-01-26 13:17 695,642 ----a-w c:\windows\unins000.exe
2009-01-15 06:11 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-17 16:14 174 --sha-w c:\program files\desktop.ini
2008-09-17 08:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-09-17 08:19 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-09-17 08:19 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-06_ 8.53.45,38 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-04-06 06:53:01 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-04-06 06:55:46 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-04-06 06:53:01 98,304 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-04-06 06:55:46 98,304 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-04-06 06:53:01 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-04-06 06:55:46 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"gStart"="c:\garmin\gStart.exe" [2009-04-06 23052]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-05 23052]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-04-06 23052]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-08 645328]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-03-26 401040]
c:\users\MARIE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
HDDlife.lnk - c:\program files\BinarySense\HDDlife 3\HDDlifePro.exe [2008-02-15 2278648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2009-02-27 18:10 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
--a------ 2006-07-11 18:12 90112 c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
--a------ 2007-03-15 12:09 460784 c:\program files\DellSupport\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
--a------ 2006-11-17 23:13 17920 c:\dell\E-Center\EULALauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-09-29 08:33 29744 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2006-10-03 12:37 81920 c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 10:47 289064 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-11-10 16:07 1253376 c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
--a------ 2008-12-03 13:47 1205760 c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
--a------ 2006-11-02 11:45 215552 c:\windows\WindowsMobile\wmdSync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--a------ 2007-02-08 07:11 303104 c:\windows\sttray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1549740449-2313478069-2629033981-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6AE93875-2274-4977-B867-4126C877A2C3}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{75111A90-EE04-407A-B293-00A966F140C6}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{2340E488-8EF6-454F-9A50-3DBF211A00C1}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{E55647FF-4DE6-49A1-B801-409908F3E612}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{15E1A816-1225-4839-9B1C-C964DBB8A861}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{88321D30-DAE5-4E0E-B960-354AE1269215}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{D85D5B18-3C2A-498E-83B9-EDF4F327472F}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B304C1A5-2436-443C-A4F1-3AAF6B1C7303}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{9FE39B4B-9C3C-4809-B42D-8E1C2D43171E}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{711C1F36-7668-4D61-B37D-8C5CB43AA677}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{44051520-22E7-4F24-82E4-4E93D5845DF4}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{995B049D-06D3-4EFA-92DC-DFDD12D60269}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E183E357-1F34-4656-AB2F-F1B0138BDE23}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{89F6DC5D-A11C-46D2-BB0B-990F062E6AE7}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{147204E0-478E-4CEE-96FB-74FD492351F5}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{82426D94-8695-4979-9C3B-9E4B482E2CFB}"= UDP:5721:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{56BAA04B-F4B7-49FD-8886-1F7EE389A1D3}"= UDP

LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{107C363C-AF67-4792-9BE6-1860EFA41130}"= UDP:5678:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{62D73315-C03D-4207-851E-A59820C5B49C}"= UDP:999:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{97C9C766-EAD7-437A-A47F-803F31D13532}"= UDP

LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{5ABBD0A7-C1EF-4988-9379-D045B1E6474A}"= UDP:990:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
"{20E218E4-EF05-46A6-B0AE-07DA19FFC35C}"= UDP:5721:LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{1EA318D4-DCB8-4B68-BDBA-A221766AC69E}"= UDP

LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{BD59A982-AA61-42CF-9A81-73C0B12EE0D8}"= UDP:5678:LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{89F56D50-7C15-411D-8A55-BE729A165BB1}"= UDP:999:LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{44088F30-8B41-40EE-9EBE-9B86CEA1826F}"= UDP

LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{0088A1CD-C61C-4FEB-BDA4-368A86B525BC}"= UDP:990:LocalSubnet:LocalSubnet|IF={3E2B244E-6983-48CF-A66B-590BE6C66475}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
"{24F6D7D1-3479-430F-ACDA-1669E9F951B1}"= UDP:5721:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{117BE3E9-5F6D-4CB9-AA2C-9B5CEE34DAEF}"= UDP

LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{10D555ED-A515-44D8-B192-62CDCAD130D7}"= UDP:5678:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{6A012E3D-B3E4-473A-AB3A-2076EF59C2E2}"= UDP:999:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{2D2BB76A-4A5E-47F3-A9B2-805CECDCCC96}"= UDP

LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{8A208EDF-7586-4AD2-9879-52E31DF6C86B}"= UDP:990:LocalSubnet:LocalSubnet|IF={925F752D-78F0-46A0-9A8B-4DA12CC3EACD}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R2 HDDlife HDD Access service;HDDlife HDD Access service;c:\program files\Common Files\BinarySense\hldasvc.exe [2008-02-15 832760]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-10-21 179856]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-10-14 210216]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-03-18 92008]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-03-31 603904]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [2008-10-21 15504]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [2008-08-29 3664384]
S2 SCRCAMDRV;ScreenCamera IM Device;c:\windows\System32\drivers\SCRCAMDRV.sys [2009-03-03 225536]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-05-31 29744]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-11-17 195752]
S3 NANMp50;NANMp50 NDIS Protocol Driver;c:\windows\System32\drivers\NANMp50.sys [2009-01-21 28224]
S3 NANSp50;NANSp50 NDIS Protocol Driver;c:\windows\System32\drivers\NANSp50.sys [2009-01-21 27072]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\System32\drivers\npf.sys [2005-08-02 32512]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-01-20 28224]
S3 PSI;PSI;c:\windows\System32\drivers\psi_mf.sys [2008-11-18 7808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{913f391e-5bdf-11dd-bf51-00188bd030e4}]
\shell\AutoRun\command - F:\Setup.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-05 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 16:04]
2008-10-14 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]
2008-10-14 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-09 11:53]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://
www.orange.fr/
uDefault_Search_URL = hxxp://
www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.search.yahoo.com/search?fr=mcafee&p=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
Trusted Zone: divx.com\go
Trusted Zone: orange.fr\www
Handler: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - c:\program files\Common Files\BinarySense\hlAPP.dll
DPF: Garmin Internet Explorer Plug-In - hxxps://my.garmin.com/mygarmin/m/GarminAxControl.CAB
DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} - hxxps://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://
www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {BA3BAF69-72B1-4BCE-BE96-A4D304EAFBB4} - hxxp://assets.photobox.com/assets/aurigma/ImageUploader4.cab?20080908082415
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-06 09:01:59
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1549740449-2313478069-2629033981-1000_Classes\CLSID\{5937c266-45ed-4aa5-85bf-7c60d7b1daf9}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:000000ee
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,7a,4a,a8,7e,24,0e,49,5a,96,94,16,7a,19,d5,dc,a7,3f,cb,c4,3f,5b,b9,\
[HKEY_USERS\S-1-5-21-1549740449-2313478069-2629033981-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):a0,f7,15,9b,3a,31,98,14,54,4b,7d,2e,1e,8a,06,51,b3,f5,16,b5,a7,
c3,0d,d0,85,de,44,bc,1f,93,89,16,4a,d9,ad,0d,0b,93,71,ae,00,00,00,00,00,00,\
.
Heure de fin: 2009-04-06 9:04:24
ComboFix-quarantined-files.txt 2009-04-06 07:04:19
ComboFix2.txt 2009-04-06 06:55:32
Avant-CF: 79 145 062 400 octets libres
Après-CF: 79,094,591,488 octets libres
304 --- E O F --- 2009-04-03 06:23:06
@++