Bonjour nardino,
Voilà le rapport Combofix
Bonne journée
ComboFix 10-09-19.02 - J-Luc 20.09.2010 8:45.4.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.41.1036.18.2037.1019 [GMT 2:00]
Lancé depuis: c:\users\J-Luc\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-20 au 2010-09-20 ))))))))))))))))))))))))))))))))))))
.
2010-09-20 06:57 . 2010-09-20 06:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-20 06:57 . 2010-09-20 06:57 -------- d-----w- c:\users\Fabien!!!\AppData\Local\temp
2010-09-20 06:57 . 2010-09-20 06:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-20 06:57 . 2010-09-20 06:57 -------- d-----w- c:\users\Audrey\AppData\Local\temp
2010-09-20 06:57 . 2010-09-20 06:57 -------- d-----w- c:\users\Administrateur\AppData\Local\temp
2010-09-19 12:09 . 2010-09-19 12:14 -------- d-----w- c:\program files\Ad-Remover
2010-09-18 06:28 . 2010-09-19 09:32 -------- d-----w- c:\program files\ZHPDiag
2010-09-17 17:31 . 2010-09-17 17:31 -------- d-----w- c:\programdata\Sony Corporation
2010-09-17 17:24 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-17 17:24 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-17 17:24 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-17 17:23 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-15 17:25 . 2010-09-15 17:25 -------- d-----w- c:\users\Fabien!!!\AppData\Roaming\Common Toolkit Suite
2010-09-14 10:44 . 2010-09-14 10:44 -------- d-----w- c:\users\Fabien!!!\AppData\Local\Mozilla
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\Public\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\J-Luc\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\Fabien!!!\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\Default\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\Audrey\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\users\Administrateur\Roaming
2010-09-09 13:13 . 2010-09-09 13:13 -------- d-----w- c:\programdata\Roaming
2010-09-09 13:12 . 2010-09-09 13:12 -------- d-----w- c:\program files\Cisco(0)
2010-09-09 13:07 . 2010-09-09 13:07 -------- d-----w- c:\program files\ma-config.com
2010-09-09 13:07 . 2010-09-09 13:07 -------- d-----w- c:\programdata\ma-config.com
2010-09-08 20:09 . 2010-09-09 10:39 -------- d-----w- c:\windows\BDOSCAN8
2010-09-05 10:32 . 2010-09-05 10:32 -------- d-----w- c:\users\Audrey\AppData\Local\Adobe
2010-09-05 06:12 . 2010-09-05 06:12 -------- d-----w- c:\users\J-Luc\AppData\Roaming\Sony Corporation
2010-09-03 20:27 . 2010-09-03 20:27 -------- d-----w- c:\users\Fabien!!!\AppData\Roaming\Sony Corporation
2010-09-03 13:13 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2010-09-03 13:06 . 2010-09-17 17:31 -------- d-----w- c:\program files\Sony
2010-08-29 22:15 . 2010-08-29 22:15 680 ----a-w- c:\users\J-Luc\AppData\Local\d3d9caps.dat
2010-08-29 10:57 . 2010-08-30 02:40 -------- d-----w- c:\users\J-Luc\DoctorWeb
2010-08-29 09:29 . 2010-09-20 06:59 -------- d-----w- c:\users\J-Luc\AppData\Local\temp
2010-08-27 06:32 . 2010-08-27 06:32 -------- d-----w- c:\users\J-Luc\AppData\Local\FixItCenter
2010-08-27 06:25 . 2010-08-27 06:25 -------- d-----w- c:\windows\MATS
2010-08-27 06:25 . 2010-08-27 06:25 -------- d-----w- c:\program files\Microsoft Fix it Center
2010-08-26 07:42 . 2010-09-18 14:27 -------- d-----w- c:\windows\system32\catroot2
2010-08-25 22:17 . 2010-08-25 22:17 -------- d-----w- c:\users\Administrateur\AppData\Local\Mozilla
2010-08-25 22:15 . 2010-08-25 22:15 -------- d-----w- c:\users\Administrateur\AppData\Roaming\Fighters
2010-08-25 22:14 . 2010-09-11 07:32 -------- d-----w- c:\users\Administrateur
2010-08-21 21:06 . 2010-08-21 21:06 -------- d-----w- c:\users\J-Luc\AppData\Roaming\AVG9
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 06:33 . 2010-03-13 08:30 -------- d-----w- c:\program files\Common Files\Common Toolkit Suite
2010-09-20 06:32 . 2010-02-06 10:56 -------- d-----w- c:\users\J-Luc\AppData\Roaming\LimeWire
2010-09-19 12:37 . 2010-01-24 19:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-19 11:45 . 2006-11-02 15:48 679042 ----a-w- c:\windows\system32\perfh00C.dat
2010-09-19 11:45 . 2006-11-02 15:48 126626 ----a-w- c:\windows\system32\perfc00C.dat
2010-09-19 10:21 . 2010-01-31 15:18 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-19 10:21 . 2010-01-30 11:53 -------- d-----w- c:\users\J-Luc\AppData\Roaming\Media Player Classic
2010-09-19 10:20 . 2010-01-19 15:48 -------- d-----w- c:\program files\CCleaner
2010-09-17 17:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-11 07:31 . 2010-01-19 15:23 -------- d-----w- c:\programdata\Intel
2010-09-11 07:31 . 2010-01-19 15:24 -------- d-----w- c:\program files\Common Files\Intel
2010-09-11 07:31 . 2010-01-19 15:24 -------- d-----w- c:\program files\Cisco
2010-09-09 10:37 . 2010-01-17 17:52 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-30 20:42 . 2007-03-08 10:51 -------- d-----w- c:\program files\myphotobook
2010-08-18 11:02 . 2010-04-05 07:26 -------- d-----w- c:\users\J-Luc\AppData\Roaming\uTorrent
2010-08-18 07:11 . 2010-08-18 07:11 63488 ----a-w- c:\users\J-Luc\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-18 07:11 . 2010-08-18 07:11 52224 ----a-w- c:\users\J-Luc\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-18 07:11 . 2010-08-18 07:11 117760 ----a-w- c:\users\J-Luc\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-18 07:10 . 2010-08-18 07:10 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-08-18 07:10 . 2010-08-18 07:10 -------- d-----w- c:\users\J-Luc\AppData\Roaming\SUPERAntiSpyware.com
2010-08-18 07:10 . 2010-08-18 07:10 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-17 16:57 . 2010-02-21 10:23 -------- d-----w- c:\programdata\Lavasoft
2010-08-17 11:19 . 2010-02-06 10:55 -------- d-----w- c:\program files\LimeWire
2010-08-16 18:48 . 2010-08-15 10:34 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-16 18:48 . 2007-03-08 09:45 -------- d-----w- c:\program files\Java
2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\system32\REN49A1.tmp
2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\system32\REN49A0.tmp
2010-08-16 18:46 . 2010-08-16 18:46 0 ----a-w- c:\windows\system32\REN499F.tmp
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REN7774.tmp
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REN7773.tmp
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REN7762.tmp
2010-08-15 10:31 . 2007-03-08 09:45 -------- d-----w- c:\program files\Common Files\Java
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REND636.tmp
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REND635.tmp
2010-08-15 10:31 . 2010-08-15 10:31 0 ----a-w- c:\windows\system32\REND634.tmp
2010-08-15 10:06 . 2010-01-24 18:54 -------- d-----w- c:\program files\Trend Micro
2010-08-14 09:39 . 2010-01-26 16:35 145064 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-08-14 06:48 . 2010-01-17 19:28 145064 ----a-w- c:\users\Fabien!!!\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-13 17:59 . 2010-08-13 15:35 -------- d-----w- c:\program files\Microsoft Works
2010-08-13 15:26 . 2010-01-17 18:55 -------- d-----w- c:\program files\Microsoft.NET
2010-08-13 15:06 . 2010-07-08 13:26 -------- d-----w- c:\programdata\Microsoft Help
2010-08-13 15:05 . 2010-01-17 17:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-08-13 15:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\MSBuild
2010-08-12 13:00 . 2007-03-08 09:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-12 12:58 . 2010-08-12 12:58 -------- d-----w- c:\programdata\Atheros
2010-07-31 09:43 . 2010-07-31 09:43 -------- d-----w- c:\program files\HooTech WAV MP3 Converter
2010-07-31 08:56 . 2010-06-02 23:25 -------- d-----w- c:\program files\BearShare Applications
2010-07-31 08:40 . 2010-05-13 14:22 -------- d-----w- c:\program files\Common Files\Apple
2010-07-31 07:02 . 2010-07-30 07:45 -------- d-----w- c:\users\J-Luc\AppData\Roaming\NCH Swift Sound
2010-07-31 06:49 . 2010-07-31 06:49 -------- d-----w- c:\users\J-Luc\AppData\Roaming\Recordpad
2010-07-30 11:03 . 2010-01-20 21:05 -------- d-----w- c:\users\J-Luc\AppData\Roaming\FrostWire
2010-07-30 11:00 . 2010-07-30 07:45 -------- d-----w- c:\programdata\NCH Swift Sound
2010-07-30 08:10 . 2010-07-30 08:10 52224 ----a-w- c:\users\J-Luc\AppData\Roaming\Mozilla\Firefox\Profiles\owy3xzn3.J-Luc\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}\components\FFExternalAlert.dll
2010-07-30 08:10 . 2010-07-30 08:10 101376 ----a-w- c:\users\J-Luc\AppData\Roaming\Mozilla\Firefox\Profiles\owy3xzn3.J-Luc\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}\components\RadioWMPCore.dll
2010-07-30 08:07 . 2010-04-13 07:08 -------- d-----w- c:\program files\Lame for Audacity
2010-07-30 07:46 . 2010-07-30 07:46 -------- d-----w- c:\program files\NCH Software
2010-07-28 20:52 . 2010-07-28 20:52 -------- d-----w- c:\programdata\mquadr.at
2010-07-28 20:51 . 2010-07-28 20:51 -------- dc-h--w- c:\programdata\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}
2010-07-28 20:51 . 2010-07-28 20:51 -------- d-----w- c:\program files\Swisscom
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\Application Data\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-28 20:51 2892824 -c--a-w- c:\programdata\{D61DF0B8-23A1-439C-84C4-35F3EF31A430}\SwisscomQuickHelp_Setup.exe
2010-07-12 06:31 . 2010-07-12 06:31 944512 ----a-w- c:\windows\system32\M2ElevatedNetworkAdapters.dll
2010-06-26 06:05 . 2010-08-13 10:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-13 10:20 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 06:02 . 2010-08-13 10:20 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 04:25 . 2010-08-13 10:20 133632 ----a-w- c:\windows\system32\ieUnatt.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-13 413696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PopUp Destroy"="c:\program files\PopUp Destroy\Popup-Destroy.exe" [2003-04-22 1806336]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"sfagent"="c:\program files\Fighters\SPAMfighter\sfagent.exe" [2010-04-20 386696]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 4349952]
"PMBVolumeWatcher"="c:\program files\Sony\PMB\PMBVolumeWatcher.exe" [2009-11-04 597792]
c:\users\J-Luc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-7-29 503808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
"eMuleAutoStart"=c:\program files\eMule\emule.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"MSConfig"="c:\windows\system32\msconfig.exe" /auto
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"Swisscom LiveUpdate"=c:\program files\Swisscom\LiveUpdate\SwisscomLiveUpdate.exe
"Swisscom Quick Help"=c:\program files\Swisscom\Quick Help\SwisscomQuickHelp.exe /auto
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2792706820-3056514634-2879212400-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2792706820-3056514634-2879212400-1001]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000002
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2792706820-3056514634-2879212400-1002]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-06 135664]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2010-08-13 259440]
R3 MatSvc;Service automatisé de résolution de problèmes Microsoft;c:\program files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-05-03 52872]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-01-28 24856]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-06-22 216400]
S1 AvgTdiX;AVG Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-22 243024]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-06-22 2331032]
S2 Common Toolkit Service;Common Toolkit Service;c:\program files\Common Files\Common Toolkit Suite\FighterSuiteService.exe [2010-04-20 684680]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files\Sony\PMB\PMBDeviceInfoProvider.exe [2009-10-24 360224]
S2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\Fighters\SPAMfighter\sfus.exe service [x]
S3 NETw5v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits ;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-09-15 6000640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2}]
2010-02-16 17:02 114688 ----a-w- c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier 'Tâches planifiées'
2010-08-25 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-14 18:44]
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-06 07:12]
2010-08-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-06 07:12]
2010-08-25 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-11-16 16:04]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyServer = http=ZillaPopupKiller:8100
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office14\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MI1933~1\Office14\ONBttnIE.dll/105
FF - ProfilePath - c:\users\J-Luc\AppData\Roaming\Mozilla\Firefox\Profiles\owy3xzn3.J-Luc\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.ch/webhp?hl=fr
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - component: c:\users\J-Luc\AppData\Roaming\Mozilla\Firefox\Profiles\owy3xzn3.J-Luc\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}\components\FFExternalAlert.dll
FF - component: c:\users\J-Luc\AppData\Roaming\Mozilla\Firefox\Profiles\owy3xzn3.J-Luc\extensions\{c2db4fe6-8409-45ce-8010-189a7b5cce86}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\users\J-Luc\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-20 08:59
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9m.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9m.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
.
Heure de fin: 2010-09-20 09:08:14
ComboFix-quarantined-files.txt 2010-09-20 07:08
Avant-CF: 121'283'682'304 octets libres
Après-CF: 120'086'106'112 octets libres
- - End Of File - - 9DA72812554CAEBE9A1F825BE3609B92