Bonjour,j'ai pris acte de toutes les recommandations que tu m'as fait et je t'en remercie.Non ce n'est pas moi qui est installé ce programme
http://search.babylon.com .
Ci-dessous les trois rapports demandés(pour le rapport "hijackthis" je n'avais pas d'antivirus ,ni d'antispyware ni de pare feu)
Bonne reception.Cordialement
xxxxxxxxxxxxxxxxxx
ComboFix 09-11-02.02 - Poussardin 03/11/2009 15:19.1.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1319 [GMT 1:00]
Lancé depuis: c:\documents and settings\Poussardin\Bureau\ABCDE.exe
Commutateurs utilisés :: c:\documents and settings\Poussardin\Bureau\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FILE ::
"c:\windows\system32\drivers\75e5ad92.sys"
"c:\windows\system32\drivers\sqotsppv.sys"
.
ADS - WINDOWS: deleted 0 bytes in 1 streams. (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SQOTSPPV
-------\Service_75e5ad92
-------\Service_sqotsppv
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-03 au 2009-11-03 ))))))))))))))))))))))))))))))))))))
.
2009-11-02 20:53 . 2009-11-02 20:53 261416 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-02 20:43 . 2009-11-02 20:44 -------- d-----w- c:\windows\system32\URTTemp
2009-11-02 17:55 . 2009-02-27 11:55 111992 ----a-w- c:\windows\system32\acaptuser32.dll
2009-11-02 17:04 . 2009-11-02 17:04 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2009-11-02 16:40 . 2009-11-02 16:52 -------- d-----w- C:\ABCDE
2009-10-30 17:50 . 2001-08-23 16:46 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-10-29 18:44 . 2009-10-29 18:44 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-26 13:59 . 2009-10-26 13:59 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-25 09:52 . 2009-10-25 09:52 -------- d-----w- c:\program files\Trend Micro
2009-10-24 16:27 . 2009-10-24 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-10-23 21:50 . 2009-10-23 21:52 -------- dc-h--w- c:\windows\ie8
2009-10-22 18:45 . 2008-11-10 09:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2009-10-22 18:42 . 2009-10-22 18:42 -------- d-----w- c:\program files\Microsoft.NET
2009-10-22 18:39 . 2009-10-22 18:39 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-10-21 09:04 . 2009-10-21 09:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-10-21 09:03 . 2009-08-06 18:24 53472 -c--a-w- c:\windows\system32\dllcache\wuauclt.exe
2009-10-21 09:03 . 2009-08-06 18:24 53472 ------w- c:\windows\system32\wuauclt.exe
2009-10-21 08:58 . 2009-10-21 09:05 -------- d-----w- C:\AULOGS
2009-10-18 17:51 . 2009-10-18 18:02 44544 ------w- c:\windows\AWuninstall.exe
2009-10-17 16:54 . 2009-10-17 16:54 -------- d-----w- c:\program files\PhotoZoom Pro 3
2009-10-17 07:52 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-10-17 07:52 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-10-17 07:01 . 2009-10-17 07:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-15 11:08 . 2009-10-15 11:08 -------- d-----w- c:\documents and settings\Poussardin\Local Settings\Application Data\PCHealth
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-03 14:29 . 2008-11-18 15:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-11-03 14:29 . 2008-10-21 18:58 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-03 14:27 . 2008-11-18 15:18 2121760 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-03 14:27 . 2008-11-18 15:18 10428 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-03 14:27 . 2008-11-18 15:18 13694496 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-03 14:27 . 2008-11-18 15:18 111212 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-03 12:36 . 2009-04-10 21:15 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-11-03 07:18 . 2008-12-27 19:48 -------- d-----w- c:\program files\Spyware Doctor
2009-11-02 21:06 . 2006-03-02 12:00 85180 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-02 21:06 . 2006-03-02 12:00 511204 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-02 21:01 . 2008-10-15 14:17 122496 ----a-w- c:\documents and settings\Poussardin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-02 18:23 . 2008-10-21 17:27 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-11-02 08:44 . 2008-11-23 11:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-02 08:26 . 2008-11-02 09:01 -------- d-----w- c:\program files\MSBuild
2009-10-31 19:40 . 2008-10-26 08:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-28 11:20 . 2008-08-14 05:57 73312 ----a-w- c:\windows\system32\drivers\adfs.sys
2009-10-21 09:38 . 2009-08-30 19:43 -------- d-----w- c:\documents and settings\Poussardin\Application Data\Nik Software
2009-10-19 20:13 . 2009-06-21 20:21 1470 ----a-w- c:\program files\GenesisConfig.dat
2009-10-18 18:35 . 2008-10-30 12:12 -------- d-----w- c:\program files\PhotomatixPro3
2009-10-18 17:48 . 2008-10-15 15:26 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-17 15:21 . 2008-11-15 20:04 -------- d-----w- c:\program files\onOne Software
2009-10-17 15:20 . 2009-02-07 23:01 -------- d-----w- c:\documents and settings\Poussardin\Application Data\onOne Software
2009-10-17 15:20 . 2008-10-15 14:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 08:23 . 2009-04-27 16:04 -------- d-----w- c:\program files\Topaz Labs
2009-10-16 20:43 . 2009-02-01 17:35 -------- d-----w- c:\program files\DivX
2009-10-16 20:40 . 2009-08-05 18:32 -------- d-----w- c:\program files\MAGIX
2009-10-16 20:34 . 2008-10-15 15:48 -------- d-----w- c:\program files\CyberLink
2009-10-15 19:55 . 2009-01-31 20:28 -------- d-----w- c:\program files\Pinnacle
2009-10-15 18:49 . 2009-08-05 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\MAGIX
2009-10-14 13:23 . 2008-11-18 15:29 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 13:23 . 2008-11-18 15:29 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-12 18:29 . 2008-12-10 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-10-02 06:40 . 2009-04-20 14:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-30 20:07 . 2009-08-09 09:46 -------- d-----w- c:\documents and settings\Poussardin\Application Data\bibble
2009-09-30 20:01 . 2009-06-27 20:03 -------- d-----w- c:\program files\HP Wireless Adapter
2009-09-30 20:01 . 2009-02-15 15:42 -------- d-----w- c:\program files\eChanblard
2009-09-30 20:01 . 2008-10-15 15:26 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-30 20:01 . 2009-01-31 22:23 -------- d-----w- c:\program files\AdorageI-GfxDatas
2009-09-30 19:59 . 2009-02-08 11:08 -------- d-----w- c:\program files\Fichiers communs\onOne Software Shared
2009-09-29 16:37 . 2009-09-29 16:37 -------- d-----w- c:\documents and settings\Poussardin\Application Data\theimagingfactory
2009-09-27 09:22 . 2009-09-27 09:19 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-09-26 17:32 . 2009-09-26 17:31 -------- d-----w- c:\program files\Rapidown
2009-09-16 10:05 . 2009-09-16 10:05 -------- d-----w- c:\program files\NVIDIA Corporation
2009-09-16 10:05 . 2009-09-16 10:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-09-16 09:36 . 2009-09-16 09:35 -------- d-----w- c:\program files\SystemRequirementsLab
2009-09-16 09:35 . 2009-09-16 09:35 -------- d-----w- c:\documents and settings\Poussardin\Application Data\SystemRequirementsLab
2009-09-14 08:16 . 2009-01-24 19:58 -------- d-----w- c:\program files\QuickTime
2009-09-14 08:15 . 2008-12-25 16:03 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-09-13 14:35 . 2009-09-13 14:28 -------- d-----w- c:\program files\DAZ
2009-09-13 14:28 . 2009-09-13 14:28 -------- d-----w- c:\program files\Fichiers communs\DAZ
2009-09-11 15:44 . 2009-09-11 15:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Phase One
2009-09-11 15:42 . 2009-09-11 15:42 -------- d-----w- c:\program files\Phase One
2009-09-11 14:37 . 2009-09-11 14:37 -------- d-----w- c:\program files\JRE
2009-09-11 14:36 . 2009-01-10 18:04 -------- d-----w- c:\program files\OpenOffice.org 3
2009-09-11 14:18 . 2006-03-02 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 17:30 . 2008-11-25 20:05 -------- d-----w- c:\documents and settings\Poussardin\Application Data\Alien Skin
2009-09-10 17:04 . 2008-11-25 20:00 -------- d-----w- c:\program files\Alien Skin
2009-09-10 12:54 . 2009-04-20 14:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-04-20 14:03 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 14:49 . 2009-09-01 09:38 -------- d-----w- c:\documents and settings\Poussardin\Application Data\HpUpdate
2009-09-06 19:41 . 2009-04-26 16:37 -------- d-----w- c:\program files\PluginGalaxy
2009-09-06 06:00 . 2009-09-06 06:00 -------- d-----w- c:\program files\Sqirlz Water Reflections
2009-09-04 21:04 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 05:20 . 2009-05-10 17:45 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-29 07:56 . 2006-03-02 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:01 . 2006-03-02 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-17 01:03 . 2009-08-17 01:03 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-08-17 01:02 . 2009-08-17 01:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-16 22:57 . 2009-08-16 22:57 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-08-16 22:57 . 2009-08-16 22:57 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-08-16 22:57 . 2009-08-16 22:57 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-08-16 22:57 . 2008-10-15 15:26 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-16 22:57 . 2008-10-07 11:33 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-16 22:57 . 2008-10-07 11:33 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-08-16 22:57 . 2008-10-07 11:33 5845760 ----a-w- c:\windows\system32\nv4_disp.dll
2009-08-16 22:57 . 2008-10-07 11:33 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-08-16 22:57 . 2008-10-07 11:33 155648 ----a-w- c:\windows\system32\nvcodins.dll
2009-08-16 22:57 . 2008-10-07 11:33 155648 ----a-w- c:\windows\system32\nvcod.dll
2009-08-16 22:57 . 2008-10-07 11:33 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-08-11 10:35 . 2008-10-15 15:26 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-08-06 18:24 . 2008-10-15 13:59 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 18:24 . 2008-10-15 13:59 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 18:24 . 2008-10-15 13:59 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 18:24 . 2007-07-30 17:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 18:24 . 2006-03-02 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 18:23 . 2008-10-15 13:59 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 18:23 . 2008-10-15 13:59 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2002-03-04 11:13 . 2002-02-25 11:16 1716736 ----a-w- c:\program files\AutoEye_PlugIn.8bf
2009-01-27 18:58 . 2009-01-24 20:46 56 --sha-r- c:\windows\system32\F063A3AFEA.sys
2009-07-07 16:36 . 2009-07-07 16:36 10856 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-07 247144]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"LaunchList"="c:\program files\Pinnacle\Studio 11\LaunchList2.exe" [2007-03-21 145496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-07-21 208616]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-10 406016]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2008-02-27 570664]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-08-24 1181064]
"HPWireless"="c:\program files\HP Wireless Adapter\HPWLAN.exe" [2006-10-04 618496]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-02-22 72192]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-10-28 611712]
"Dit"="Dit.exe" - c:\windows\Dit.exe [2003-05-19 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2006-03-02 44544]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
F1U201.401.lnk - c:\program files\Belkin\F1U201.401\usbshare.exe [2009-3-3 135168]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Poussardin^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Poussardin^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Poussardin^Menu Démarrer^Programmes^Démarrage^Outil de détection de support Picture Motion Browser.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2799:UDP"= 2799:UDP:Altova License Metering Port (UDP)
"2799:TCP"= 2799:TCP:Altova License Metering Port (TCP)
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"1969:UDP"= 1969:UDP:Windows Media Format SDK (Webradio.exe)
"1968:UDP"= 1968:UDP:Windows Media Format SDK (Webradio.exe)
"1970:UDP"= 1970:UDP:Windows Media Format SDK (Webradio.exe)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 18:29 33808]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/05/2009 18:45 206256]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [10/05/2009 18:51 51488]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [10/05/2009 18:51 39200]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [10/05/2009 18:46 159600]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16/09/2008 12:03 169312]
R2 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [06/04/2007 14:25 57344]
R2 HPEAPPkt;Realtek EAPPkt Protocol(HP);c:\windows\system32\drivers\HPEAPPkt.sys [27/06/2009 21:03 68864]
R2 sdauxservice;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [27/12/2008 20:48 348752]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [07/08/2009 15:31 92008]
R3 hpnuhst;HP NUSB Host;c:\windows\system32\drivers\hpnuhst.sys [24/06/2009 20:06 11136]
R3 HPNUHUB;HP NUSB Hub;c:\windows\system32\drivers\hpnuhub.sys [24/06/2009 20:06 37248]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 18:06 24592]
R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [10/05/2009 18:45 64392]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [10/05/2009 18:51 33056]
R3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\POUSSA~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys --> c:\docume~1\POUSSA~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe --> c:\program files\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 HPNUCMP;HP NUSB Composite;c:\windows\system32\drivers\hpnucmp.sys [24/06/2009 20:06 11648]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\9.tmp --> c:\windows\system32\9.tmp [?]
S3 RTLWUSB;Wireless Adapter;c:\windows\system32\drivers\HPL8187.SYS [27/06/2009 21:10 189440]
S3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [27/06/2009 21:03 13532]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mbr
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier 'Tâches planifiées'
2009-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.com/uInternet Settings,ProxyOverride = *.local
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{57E91B47-F40A-11D1-B792-444553540011}
LSP: c:\program files\Fichiers communs\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\Poussardin\Application Data\Mozilla\Firefox\Profiles\wm1bkvft.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Poussardin\Application Data\Mozilla\plugins\npPxPlay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin9.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin9.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-03 15:28
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\9.tmp"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1084)
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\program files\Spyware Doctor\TFEngine\TFNI.dll
- - - - - - - > 'lsass.exe'(1140)
c:\program files\Fichiers communs\PC Tools\LSP\PCTLsp.dll
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
- - - - - - - > 'explorer.exe'(3976)
c:\program files\Spyware Doctor\TFEngine\TFWAH.dll
c:\windows\system32\msi.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Spyware Doctor\TFEngine\TFService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Heure de fin: 2009-11-03 15:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-03 14:34
ComboFix2.txt 2009-11-02 16:52
Avant-CF: 76 869 824 512 octets libres
Après-CF: 76 783 271 936 octets libres
- - End Of File - - 9F01E3D271F98B1BB5E91239D50B3F90
xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
xxxxxxxxxxxxxxxxxxxxxxxxxxxx
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data : extended (2074 bytes)
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\Data : extended (2074 bytes)
C:\Documents and Settings\All Users\Application Data\Microsoft : A01815ufd8IlDnVI4ogJa (1010 bytes)
C:\Documents and Settings\All Users\Application Data\Microsoft : Rc28xFyEDtMcd7aNW4GH (1084 bytes)
C:\Documents and Settings\All Users\Application Data\Microsoft : A01815ufd8IlDnVI4ogJa (1010 bytes)
C:\Documents and Settings\All Users\Application Data\Microsoft : Rc28xFyEDtMcd7aNW4GH (1084 bytes)
C:\Documents and Settings\All Users\Application Data\Pinnacle Studio\Data\Render\mariage Martial FAC9018A\tmp.m2v : PinnacleIndex_0 (0 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 1CA73D29 (127 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 31D9EFCC (123 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 456A69E6 (129 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : DFC5A2B2 (153 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 1CA73D29 (127 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 31D9EFCC (123 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : 456A69E6 (129 bytes)
C:\Documents and Settings\All Users\Application Data\TEMP : DFC5A2B2 (153 bytes)
C:\Documents and Settings\Poussardin\Favoris\DVD Lab Pro\Bienvenue sur le site GEGE 92.URL : favicon (5174 bytes)
C:\Documents and Settings\Poussardin\Favoris\DVD Lab Pro\DVD-lab Manual.URL : favicon (15086 bytes)
C:\Documents and Settings\Poussardin\Favoris\Electroménager\CyberBricoleur (Powered by Invision Power Board).URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Electroménager\Tout-electromenager.fr -Documentation technique- Presentation-des-organes-du-lave-vaisselle.URL : favicon (3638 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\- Parlons Photo.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\ArzaGraphie .URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\bkb-graphism.be - communauté graphique.URL : favicon (2038 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\deformations sur une photo.URL : favicon (15086 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Electroménager\CyberBricoleur (Powered by Invision Power Board).URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Electroménager\Tout-electromenager.fr -Documentation technique- Presentation-des-organes-du-lave-vaisselle.URL : favicon (3638 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Forum Geekeden - Communauté d'informatique et de graphisme.URL : favicon (4286 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Forum Thunderbird [Arobase.org].URL : favicon (5430 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Forums.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Forum\Photoshop-Création • Voir le forum - Tutoriels photoshop 7.0, CS, CS2 et CS3.URL : favicon (2238 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Assistance et dépannage informatique - Erreur - Mon Assistance.URL : favicon (318 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forum Linux\Framagora • Panneau de contrôle de l’utilisateur • Information.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forum Linux\Informations Panneau de l’utilisateur.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forum Linux\Le Site du Zéro, site communautaire de tutoriels gratuits pour débutants programmation, création de sites Web, Linux.URL : favicon (22486 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forum Linux\Linux - FORUM CrystalXP.net Français.URL : favicon (15086 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\FORUM AideOnline.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Forum d'assistance informatique.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Forum Geekeden - Communauté d'informatique et de graphisme.URL : favicon (4286 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Forum Linux, Mac et O.S. alternatifs.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Forum logiciels, programmes et jeux.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Forum Utilitaires système.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\gsiteg - Recherche Google.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Inscription terminée (depuis Firefox).URL : favicon (4286 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Inscription terminée.URL : favicon (6630 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Logiciel photoshop Lightroom ne s'ouvre plus.URL : favicon (3774 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\problème avec corel draw suite 4 - HaKwArA - Forum Maroc.URL : favicon (10134 bytes)
C:\Documents and Settings\Poussardin\Favoris\informatique\Forums\Sécurité.URL : favicon (822 bytes)
C:\Documents and Settings\Poussardin\Favoris\Italie 2009\Aire de (Veneto) VICENZA (VI).URL : favicon (766 bytes)
C:\Documents and Settings\Poussardin\Favoris\Italie 2009\Avis France Location de voitures et utilitaires - La Vénétie.URL : favicon (894 bytes)
C:\Documents and Settings\Poussardin\Favoris\Italie 2009\Città di Bassano del Grappa.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Italie 2009\VENISE, Forum Venise, Padoue, Verone, Vicenza, villas palladiennes, Trevise.URL : favicon (4286 bytes)
C:\Documents and Settings\Poussardin\Favoris\Liens\Sites suggérés.url : favicon (25214 bytes)
C:\Documents and Settings\Poussardin\Favoris\lightroom\Adobe - échange de Lightroom.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\lightroom\La gestion des couleurs à l'impression - Le monde de la Photo.URL : favicon (3638 bytes)
C:\Documents and Settings\Poussardin\Favoris\Mask pro\Version traduite de la page http
http://www.ononesoftware.com detail.php prodLine_id=8.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Mask pro\YouTube - MASK PRO FOR ADOBE PHOTOSHOP Nº1 .URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Météo Alsace\fluide mask\Version traduite de la page http
http://www.applelinks.com index.php more charles_moore_reviews_fluidmask_3_powerful_image_cutout_tool .URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Météo Alsace\fluide mask\Version traduite de la page http
http://www.photographyblog.com reviews_fluid_mask_3.php.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Météo Alsace\Météo Cernay (68).URL : favicon (3638 bytes)
C:\Documents and Settings\Poussardin\Favoris\Météo Alsace\Photo numérique - Télécharger des logiciels pour Windows Multimédia Photo numérique - Page 6.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photos\Digital Art & Photo.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photos\Photocase - Photos.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photos\Picasa Albums Web - Jean-Pierre - Tempête du 24 janvier 2009.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photos\Suivi,vigilance pour Tempête - Page 12.URL : favicon (23814 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photos\TEMPETE KLAUS SUR BISCARROSSE PLAGE.URL : favicon (2862 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\. Klondik . Tutoriaux - Détourer des cheveux avec Photoshop.URL : favicon (32038 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Graphisme Delphine ~ La caverne des tutoriaux Photoshop.URL : favicon (29926 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\- Les masques sous photoshop - tutoriel absolut photo.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Adobe - tutorial Master advanced adjustment layer techniques.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Comprendre les calques (photoshop, gimp, et les autres...) Communauté pour apprendre et comprendre.URL : favicon (29926 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Créer un fondu ou dégradé entre deux ou trois images Tutorial Photoshop - TutoMaker.com.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Google.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\l'exposure blending ou comment simuler un filtre ND sous photoshop.URL : favicon (3638 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Sommaire Photoshop.URL : favicon (5174 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\Tutoriaux Photoshop Les masques de fusion Généralités Chez Sweety.URL : favicon (3774 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\tutoriel les masques de fusion ! ( avec photoshop ).URL : favicon (15086 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Nouveau dossier\[Documentation] Utilisation des masques sous Photoshop - Paperblog.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Photoshop élément – Faire un blend fondu.URL : favicon (15086 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Photoshoplus accueil.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Photoshoplus partenaires.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\Photoshop tuto\Résultats Google Recherche d'images correspondant à http
http://www.e-kiwi.net donnees pages photo 103.jpg.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Adobe - échange de Lightroom.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Photos\Digital Art & Photo.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Photos\Photocase - Photos.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Photos\Picasa Albums Web - Jean-Pierre - Tempête du 24 janvier 2009.URL : favicon (1406 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Photos\Suivi,vigilance pour Tempête - Page 12.URL : favicon (23814 bytes)
C:\Documents and Settings\Poussardin\Favoris\plugins\Photos\TEMPETE KLAUS SUR BISCARROSSE PLAGE.URL : favicon (2862 bytes)
C:\Documents and Settings\Poussardin\Favoris\RealDraw\Real-DRAW, le seul 2D, 3D et d'édition de vecteur Bitmap.URL : favicon (1150 bytes)
C:\Documents and Settings\Poussardin\Local Settings\Application Data\HGfNqyj7qHkdXe : NoNRy86V71eZuue5Ri67HO (1067 bytes)
C:\Documents and Settings\Poussardin\Local Settings\Application Data\HGfNqyj7qHkdXe : NoNRy86V71eZuue5Ri67HO (1067 bytes)
C:\Program Files\Fichiers communs\Microsoft Shared : Svl2gUsg7jjkxrYgSUy (1125 bytes)
C:\Program Files\Fichiers communs\Microsoft Shared : Svl2gUsg7jjkxrYgSUy (1125 bytes)
C:\Program Files\Outlook Express\UhOZH9DaIXpklLZ : 6A3NlT7kUCftS8PuD (1108 bytes)
C:\Program Files\Outlook Express\UhOZH9DaIXpklLZ : 6A3NlT7kUCftS8PuD (1108 bytes)
C:\Program Files\WindowsUpdate\87e5vqrD4uXbJh : ZHWLn9A4mA7Tt2IYjFOEo944bwpm (1051 bytes)
C:\Program Files\WindowsUpdate\87e5vqrD4uXbJh : ZHWLn9A4mA7Tt2IYjFOEo944bwpm (1051 bytes)
C:\WINDOWS : AstInfo (0 bytes)
C:\WINDOWS : AstInfo (0 bytes)
C:\WINDOWS\system32\´ó : pctlsp.log (142 bytes)