Salut!
Voici mon rapport combofix, mais j’ai un petit problème pour la suite, le lien vers AD-remover est mort! J’ai cherché sur plusieurs autres forum, et tjs la même chose, j’arrive sur une erreur 404!
Aurais-tu une solution, ou tout simplement est-ce que je peux sauter cette étape?
ComboFix 09-11-07.02 - Michelet 09.11.2009 11:14.1.2 - NTFSx86
Microsoft® Windows Vista Édition Familiale Premium 6.0.6002.2.1252.41.1036.18.3069.1459 [GMT 1:00]
Lancé depuis: c:\users\Michelet\Desktop\kodorduhl.com.exe
SP: Windows Defender enabled (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:$recycle.bin\S-1-5-21-2967930971-2189869607-64227303-500
c:$recycle.bin\S-1-5-21-3082474585-2865157143-1589036794-500
c:\windows\Downloaded Program Files\IDropPTB.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-09 au 2009-11-09 ))))))))))))))))))))))))))))))))))))
.
2009-11-09 10:23 . 2009-11-09 10:23 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-08 11:25 . 2009-11-08 12:04 4096 d-----w- C:\FindyKill
2009-11-06 16:36 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-06 16:36 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-05 13:55 . 2009-11-05 13:55 -------- d-----w- c:\program files\Trend Micro
2009-11-05 11:39 . 2009-11-05 11:48 -------- d-----w- C:$AVG
2009-11-05 11:37 . 2009-11-09 10:09 4096 d-----w- c:\programdata\avg9
2009-11-04 15:37 . 2009-11-04 15:37 -------- d-----w- c:\users\Michelet\AppData\Roaming\Malwarebytes
2009-11-04 15:36 . 2009-11-06 16:36 4096 d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-11-04 15:36 . 2009-11-04 15:36 -------- d-----w- c:\programdata\Malwarebytes
2009-11-01 22:31 . 2009-11-01 22:31 -------- d-----w- c:\program files\CHRYOPROD
2009-10-31 20:51 . 2009-11-01 13:28 8192 d-----w- c:\program files\Eufloria Demo
2009-10-27 08:03 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-27 08:03 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-27 08:03 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-27 08:03 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-27 08:03 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-27 08:03 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-27 08:03 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-27 08:03 . 2009-08-06 18:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-27 08:03 . 2009-08-06 17:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-21 17:06 . 2009-10-21 17:10 -------- d-----w- c:\windows\system32\ca-ES
2009-10-21 17:06 . 2009-10-21 17:10 -------- d-----w- c:\windows\system32\eu-ES
2009-10-21 17:06 . 2009-10-21 17:10 -------- d-----w- c:\windows\system32\vi-VN
2009-10-21 16:59 . 2009-07-21 20:33 490496 ------w- c:\windows\system32\stapi32.dll
2009-10-21 11:38 . 2009-10-21 11:38 4096 d-----w- c:\windows\system32\EventProviders
2009-10-21 10:44 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2009-10-21 10:42 . 2009-04-11 06:28 1183232 ----a-w- c:\windows\system32\msxml3.dll
2009-10-21 10:40 . 2009-04-11 06:28 996352 ----a-w- c:\windows\system32\WMNetMgr.dll
2009-10-21 10:39 . 2009-04-11 06:28 99840 ----a-w- c:\windows\system32\ulib.dll
2009-10-21 10:38 . 2009-04-11 06:28 68096 ----a-w- c:\windows\system32\fdSSDP.dll
2009-10-21 10:36 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2009-10-21 10:36 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2009-10-21 10:36 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2009-10-21 10:36 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2009-10-21 10:36 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2009-10-21 10:36 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-10-21 10:36 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\esscli.dll
2009-10-21 10:36 . 2009-04-11 06:28 705536 ----a-w- c:\windows\system32\SmiEngine.dll
2009-10-21 10:35 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-10-21 10:35 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-10-21 10:34 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-10-16 10:20 . 2009-10-16 10:20 -------- d-----w- c:\users\Michelet\AppData\Roaming\Unigraphics Solutions
2009-10-16 10:19 . 2009-10-16 10:20 4096 d-----w- C:\Solid Edge Standard Parts
2009-10-16 10:10 . 2009-10-16 10:10 -------- d-----w- c:\users\Michelet\AppData\Local\Femap
2009-10-16 10:02 . 2009-10-16 10:48 4096 d-----w- c:\program files\Solid Edge ST
2009-10-15 16:55 . 2009-10-15 16:55 -------- d-----w- c:\users\Michelet\AppData\Local\Activision
2009-10-15 16:40 . 2009-10-15 16:40 682280 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-15 16:14 . 2009-10-15 16:14 -------- d-sh–w- c:\windows\ftpcache
2009-10-15 01:07 . 2009-10-15 01:07 8192 d-----w- c:\windows\SQLTools9_KB970892_ENU
2009-10-15 01:05 . 2009-10-15 01:05 8192 d-----w- c:\windows\SQL9_KB970892_ENU
2009-10-14 17:47 . 2009-10-14 17:47 -------- d-----w- c:\program files\Veetle
2009-10-14 17:36 . 2009-10-14 17:36 -------- d-----w- c:\users\Michelet\AppData\Local\TVU Networks
2009-10-14 17:36 . 2009-10-14 17:36 -------- d-----w- c:\programdata\TVU Networks
2009-10-14 17:36 . 2009-11-04 19:18 4096 d-----w- c:\program files\TVUPlayer
2009-10-14 10:32 . 2009-08-27 12:40 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-14 10:32 . 2009-08-27 13:29 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-14 08:14 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 08:14 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-14 07:38 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-14 06:54 . 2009-09-04 11:41 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-10-14 06:52 . 2009-09-14 09:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-14 06:41 . 2009-05-08 12:53 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-10 23:31 . 2009-10-10 23:31 -------- d-----w- c:\users\Michelet\AppData\Local\Apple Computer
2009-10-10 22:37 . 2009-11-04 19:18 4096 d-----w- c:\program files\TVAnts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-09 09:09 . 2008-11-24 12:02 699742 ----a-w- c:\windows\system32\perfh010.dat
2009-11-09 09:09 . 2008-11-24 12:02 137572 ----a-w- c:\windows\system32\perfc010.dat
2009-11-09 09:09 . 2008-11-24 11:57 654450 ----a-w- c:\windows\system32\perfh007.dat
2009-11-09 09:09 . 2008-11-24 11:57 140232 ----a-w- c:\windows\system32\perfc007.dat
2009-11-09 09:09 . 2008-11-24 11:52 716274 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-09 09:09 . 2008-11-24 11:52 141378 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-09 09:07 . 2009-06-06 03:08 124036 ----a-w- c:\programdata\nvModes.dat
2009-11-08 13:32 . 2009-08-08 09:41 4096 d-----w- c:\users\Michelet\AppData\Roaming\Winamp
2009-11-08 11:26 . 2008-11-24 03:41 1076 ----a-w- c:\windows\bthservsdp.dat
2009-11-08 11:26 . 2009-06-11 14:38 24576 d-----w- c:\users\Michelet\AppData\Roaming\Azureus
2009-11-07 13:37 . 2009-11-07 13:37 18696 ----a-w- c:\windows\Help\OEM\scripts\HC_BatteryAccessories.exe
2009-11-06 16:51 . 2009-09-23 09:51 8268 ----a-w- c:\users\Michelet\AppData\Local\d3d9caps.dat
2009-11-05 11:37 . 2009-08-04 22:51 -------- d-----w- c:\program files\AVG
2009-11-04 19:19 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Sidebar
2009-11-04 19:19 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Photo Gallery
2009-11-04 19:19 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Journal
2009-11-04 19:19 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-04 12:16 . 2009-06-13 10:34 4096 d-----w- c:\users\Michelet\AppData\Roaming\Skype
2009-11-04 12:03 . 2009-06-13 10:35 4096 d-----w- c:\users\Michelet\AppData\Roaming\skypePM
2009-11-02 22:24 . 2009-06-29 18:43 4096 d-----w- c:\users\Michelet\AppData\Roaming\Autodesk
2009-11-02 22:22 . 2009-06-29 18:45 4096 d-----w- c:\programdata\Autodesk
2009-10-30 17:43 . 2009-09-30 10:35 138464 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-30 17:42 . 2009-09-30 10:35 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-25 22:59 . 2009-06-11 14:37 4096 d-----w- c:\program files\Vuze
2009-10-22 12:18 . 2009-06-05 13:20 4096 d-----w- c:\program files\Common Files\Adobe
2009-10-21 17:27 . 2009-02-04 13:47 -------- d-----w- c:\programdata\NVIDIA
2009-10-21 17:12 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Calendar
2009-10-21 17:12 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Collaboration
2009-10-21 17:11 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Defender
2009-10-21 17:05 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-21 17:00 . 2009-10-21 17:00 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
2009-10-16 11:33 . 2009-06-05 13:29 152616 ----a-w- c:\users\Michelet\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-16 07:45 . 2009-08-13 13:53 -------- d-----w- c:\program files\KeyToPlay
2009-10-16 07:19 . 2009-06-11 15:20 -------- d-----w- c:\programdata\Media Center Programs
2009-10-16 07:17 . 2008-11-24 04:18 16384 d–h--w- c:\program files\InstallShield Installation Information
2009-10-15 16:40 . 2009-09-30 10:35 22328 ----a-w- c:\users\Michelet\AppData\Roaming\PnkBstrK.sys
2009-10-15 16:40 . 2009-09-30 10:35 22328 ----a-w- c:\users\Michelet\AppData\Roaming\PnkBstrK.sys
2009-10-15 16:18 . 2009-09-30 10:14 4096 d-----w- c:\program files\Activision
2009-10-15 01:09 . 2009-06-05 13:21 12288 d-----w- c:\programdata\Microsoft Help
2009-10-15 01:07 . 2009-06-29 19:46 -------- d-----w- c:\program files\Microsoft SQL Server
2009-10-09 15:21 . 2009-10-09 15:17 4096 d-----w- c:\program files\Dr.Kawashima_Demo
2009-10-09 08:25 . 2009-02-04 13:40 -------- d-----w- c:\program files\DigitalPersona
2009-10-09 08:22 . 2009-10-09 08:22 -------- d-----w- c:\programdata\Downloaded Installations
2009-10-07 14:14 . 2009-10-07 14:14 -------- d-----w- c:\program files\SecureW2
2009-10-05 08:11 . 2009-10-03 14:21 4096 d-----w- c:\program files\Microsoft Silverlight
2009-10-04 12:22 . 2009-07-03 15:23 4096 d-----w- c:\users\Michelet\AppData\Roaming\Nokia
2009-10-03 20:22 . 2009-10-03 20:22 1793288 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-10-03 14:21 . 2009-06-06 12:36 4096 d-----w- c:\program files\Windows Live
2009-10-03 14:16 . 2009-10-03 14:16 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-03 14:12 . 2009-10-03 14:12 -------- d-----w- c:\program files\Microsoft
2009-10-02 13:20 . 2009-09-30 10:35 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-01 08:29 . 2009-10-02 18:50 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-29 17:00 . 2009-09-29 17:00 -------- d-----w- c:\programdata\Apple Computer
2009-09-29 16:58 . 2009-09-29 16:58 -------- d-----w- c:\program files\Common Files\Apple
2009-09-29 16:58 . 2009-09-29 16:58 4096 d-----w- c:\program files\Apple Software Update
2009-09-29 16:58 . 2009-09-29 16:58 -------- d-----w- c:\programdata\Apple
2009-09-29 06:52 . 2009-09-29 06:52 474176 ----a-w- c:\windows\system32\DPSDApi.dll
2009-09-29 06:52 . 2009-09-29 06:52 334912 ----a-w- c:\windows\system32\DPFPApi.dll
2009-09-29 06:52 . 2009-09-29 06:52 150592 ----a-w- c:\windows\system32\DpPwdFlt.dll
2009-09-29 06:52 . 2009-09-29 06:52 592960 ----a-w- c:\windows\system32\DPCrProv.dll
2009-09-29 06:52 . 2009-09-29 06:52 240704 ----a-w- c:\windows\system32\DpClback.dll
2009-09-24 13:31 . 2008-11-24 05:32 4096 d-----w- c:\program files\Java
2009-09-23 15:45 . 2009-09-23 15:45 -------- d-----w- c:\program files\Electronic Arts
2009-09-23 15:41 . 2009-09-23 15:41 8192 d-----w- c:\program files\AGEIA Technologies
2009-09-23 14:21 . 2009-09-23 14:21 -------- d-----w- c:\users\Michelet\AppData\Roaming\Talkback
2009-09-23 14:21 . 2009-09-23 14:21 0 ----a-w- c:\windows\nsreg.dat
2009-09-23 14:21 . 2009-09-23 14:21 -------- d-----w- c:\users\Michelet\AppData\Roaming\Thunderbird
2009-09-23 14:21 . 2009-09-23 14:21 8192 d-----w- c:\program files\Mozilla Thunderbird
2009-09-23 11:25 . 2009-07-26 08:55 10686001 ----a-w- c:\users\Michelet\AppData\Roaming\Azureus\plugins\azump\mplayer.exe
2009-09-22 19:18 . 2009-09-22 19:18 -------- d-----w- c:\program files\KONAMI
2009-09-21 21:02 . 2009-09-21 21:02 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-09-18 15:20 . 2009-07-22 17:56 -------- d-----w- c:\users\Michelet\AppData\Roaming\gtk-2.0
2009-09-17 09:54 . 2009-09-17 09:54 2491192 ----a-w- c:\users\Michelet\AppData\Roaming\Mozilla\Firefox\Profiles\cwkojmlr.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
2009-09-15 18:53 . 2009-09-15 18:53 -------- d-----w- c:\users\Michelet\AppData\Roaming\StreamTorrent
2009-09-12 22:20 . 2009-09-12 22:20 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-09-12 22:04 . 2009-09-12 22:04 -------- d-----w- c:\program files\Fallout 3
2009-09-12 21:22 . 2009-06-09 09:21 4096 d-----w- c:\users\Michelet\AppData\Roaming\Bioshock
2009-09-11 15:17 . 2009-08-10 14:00 4096 d-----w- c:\programdata\TrackMania
2009-09-10 13:40 . 2009-09-10 13:39 4096 d-----w- c:\users\Michelet\AppData\Roaming\HpUpdate
2009-09-10 13:39 . 2008-11-24 05:54 -------- d-----w- c:\program files\HP
2009-08-29 00:27 . 2009-09-10 21:48 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-10 21:48 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:27 . 2009-09-09 15:52 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-09 15:52 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-09 15:52 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-09 15:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-09 15:52 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-09 15:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-09 15:52 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-09 15:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-09 15:52 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-09 15:52 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-09 15:52 105984 ----a-w- c:\windows\system32\netiohlp.dll
2008-11-24 12:22 . 2008-11-24 12:03 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ISUSPM”=“c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe” [2007-07-12 226904]
“PC Suite Tray”=“c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe” [2009-06-25 1414144]
“Google Update”=“c:\users\Michelet\AppData\Local\Google\Update\GoogleUpdate.exe” [2009-08-19 133104]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DVDAgent”=“c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe” [2008-09-26 1148200]
“TSMAgent”=“c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe” [2008-09-25 1152296]
“CLMLServer for HP TouchSmart”=“c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe” [2008-09-25 189736]
“UCam_Menu”=“c:\program files\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“SmartMenu”=“c:\program files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe” [2008-09-23 912688]
“UpdatePSTShortCut”=“c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe” [2008-09-26 210216]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-21 1008184]
“QlbCtrl.exe”=“c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe” [2008-08-01 202032]
“UpdateP2GoShortCut”=“c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“UpdatePDIRShortCut”=“c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe” [2008-06-13 210216]
“HP Health Check Scheduler”=“c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe” [2008-06-16 75008]
“hpWirelessAssistant”=“c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe” [2008-04-15 488752]
“WinampAgent”=“c:\program files\Winamp\winampa.exe” [2009-07-01 37888]
“SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe” [2008-03-28 1045800]
“HP Software Update”=“c:\program files\Hp\HP Software Update\HPWuSchd2.exe” [2008-12-08 54576]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2009-07-31 149280]
“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe” [2009-09-04 417792]
“DpAgent”=“c:\program files\DigitalPersona\Bin\dpagent.exe” [2009-09-29 842816]
“SysTrayApp”=“c:\program files\IDT\WDM\sttray.exe” [2009-07-21 458844]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-09-13 13584928]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-09-13 92704]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-10-03 35696]
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2009-09-04 935288]
“Malwarebytes Anti-Malware (reboot)”=“c:\program files\Malwarebytes’ Anti-Malware\mbam.exe” [2009-09-10 1312080]
“Kernel and Hardware Abstraction Layer”=“KHALMNPR.EXE” - c:\windows\KHALMNPR.Exe [2008-12-18 76304]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-19 727592]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-7-12 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
“UacDisableNotify”= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”
[HKLM~\startupfolder\C:^Users^Michelet^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^PowerMenu.lnk]
path=c:\users\Michelet\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerMenu.lnk
backup=c:\windows\pss\PowerMenu.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):a8,ce,a3,15,73,52,ca,01
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\Hewlett-Packard\Media\DVD\000.fcl [26.09.2008 02:36 59376]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21.01.2008 03:23 21504]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [18.03.2008 16:24 19456]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [24.11.2008 07:04 365952]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [16.09.2008 10:33 599344]
R3 AVerAF15;HP DVB-T TV Tuner;c:\windows\System32\drivers\AVerAF15.sys [04.02.2009 13:48 280320]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [24.11.2008 05:33 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [29.04.2008 02:54 54784]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\System32\drivers\NETw5v32.sys [17.11.2008 14:40 3668480]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [26.06.2009 21:55 66080]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [16.09.2008 10:33 40752]
S2 gupdate1ca20c13978b770;Service Google Update (gupdate1ca20c13978b770);c:\program files\Google\Update\GoogleUpdate.exe [19.08.2009 12:35 133104]
S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [21.07.2008 11:53 100184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
— Autres Services/Pilotes en mémoire —
NewlyCreated - MBR
NewlyCreated - PROCEXP113
Deregistered - AvgLdx86
Deregistered - mbr
Deregistered - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenu du dossier ‘Tâches planifiées’
2009-11-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-19 11:35]
2009-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 11:35]
2009-11-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-19 11:35]
2009-11-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3082474585-2865157143-1589036794-1000Core.job
- c:\users\Michelet\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-17 11:45]
2009-11-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3082474585-2865157143-1589036794-1000UA.job
- c:\users\Michelet\AppData\Local\Google\Update\GoogleUpdate.exe [2009-09-17 11:45]
2009-11-09 c:\windows\Tasks\User_Feed_Synchronization-{ED9B0722-E0FF-41A6-B344-B1B9A7061F0C}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Examen supplémentaire -------
.
uStart Page = www.daemon-search.com…
mStart Page = ie.redirect.hp.com…
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l’&image au périphérique Bluetooth… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\users\Michelet\AppData\Roaming\Mozilla\Firefox\Profiles\cwkojmlr.default
FF - prefs.js: browser.search.defaulturl - www.fastbrowsersearch.com…
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Michelet\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Michelet\AppData\Roaming\Mozilla\Firefox\Profiles\cwkojmlr.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref(“security.ssl3.rsa_seed_sha”, true);
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
AddRemove-AVerMedia A309 (MiniCard, DVB-T) - c:\program files\AVerMedia\AVerMedia A309 (MiniCard
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés:
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
“ImagePath”=“c:\windows\system32\GameMon.des -service”
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services{55662437-DA8C-40c0-AADA-2C816A897A49}]
“ImagePath”="??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3082474585-2865157143-1589036794-1000\Software\SecuROM!CAUTION! NEVER A OR CHANGE ANY KEY*]
“??”=hex:27,be,bb,e8,96,b1,a5,b9,6b,3b,d9,0d,fc,88,fc,e2,3a,f9,96,91,c8,c1,93,
f5,25,3b,e7,e4,ab,b5,31,17,03,0c,39,1e,b2,d9,7a,c6,26,19,88,21,9a,77,49,8c,
“??”=hex:b8,a0,63,9b,9e,01,45,21,c2,b0,21,0b,c7,97,cd,27
[HKEY_USERS\S-1-5-21-3082474585-2865157143-1589036794-1000\Software\SecuROM\License information*]
“datasecu”=hex:98,f8,e9,96,74,ea,c8,e1,9d,f1,d6,38,89,0c,66,30,ad,90,13,b6,07,
14,6a,ae,55,e0,60,d5,f5,fe,82,35,99,37,dd,13,08,c8,de,19,45,b4,4d,2d,25,99,
“rkeysecu”=hex:82,c3,15,4f,bb,1d,3b,7f,84,f5,53,93,76,d6,d1,ff
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
“BlindDial”=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
-
-
-
-
-
-
-
‘lsass.exe’(720)
c:\windows\system32\DPPWDFLT.dll
-
-
-
-
-
-
-
‘Explorer.exe’(2216)
c:\program files\DigitalPersona\Bin\DpoFeedb.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\btmmhook.dll
c:\program files\DigitalPersona\Bin\DpoSet.dll
.
Heure de fin: 2009-11-09 11:29
ComboFix-quarantined-files.txt 2009-11-09 10:27
Avant-CF: 84’904’976’384 octets libres
Après-CF: 86’301’319’168 octets libres
-
- End Of File - - B071A115A460FCF6EA66FCA131C4C721