Il ne m'a pas demandé de taper 1... il s'est lancé automatiquement et m'a affiché le rapport... et je ne sais pas ou sont les fichiers à supprimer...
ComboFix 08-02-24.4 - Charly 2008-02-24 14:00:07.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1133 [GMT 1:00]
Endroit: C:\Users\Charly\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-24 to 2008-02-24 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 12:37 --------- d-----w C:\ProgramData\Apple Computer
2008-02-24 12:37 --------- d-----w C:\Program Files\iTunes
2008-02-24 12:37 --------- d-----w C:\Program Files\iPod
2008-02-24 12:35 --------- d-----w C:\Program Files\QuickTime
2008-02-24 12:35 --------- d-----w C:\Program Files\Bonjour
2008-02-24 12:29 45,056 ----a-w C:\Windows\System32\acovcnt.exe
2008-02-24 12:29 350,467 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-02-24 12:24 --------- d-----w C:\Users\Charly\AppData\Roaming\Azureus
2008-02-24 09:23 --------- d-----w C:\Users\Charly\AppData\Roaming\AVG7
2008-02-23 19:31 1,774,080 ----a-w C:\Windows\Internet Logs\xDBC217.tmp
2008-02-23 19:31 1,700,352 ----a-w C:\Windows\Internet Logs\xDBC322.tmp
2008-02-23 17:28 --------- d-----w C:\ProgramData\Google Updater
2008-02-23 17:16 --------- d-----w C:\Users\Charly\AppData\Roaming\MSN Pictures Displayer
2008-02-23 17:16 --------- d-----w C:\ProgramData\avg7
2008-02-23 17:16 --------- d-----w C:\Program Files\PowerForPhone
2008-02-23 17:16 --------- d-----w C:\Program Files\CCleaner
2008-02-22 09:06 --------- d-----w C:\Program Files\iPod(35)
2008-02-21 12:37 --------- d-----w C:\Program Files\Navilog1
2008-02-20 15:02 1,694,208 ----a-w C:\Windows\Internet Logs\xDBB73A.tmp
2008-02-15 13:36 --------- d-----w C:\Program Files\RegCleaner
2008-02-14 18:43 85,504 ----a-w C:\Windows\Internet Logs\xDB4188.tmp
2008-02-14 18:43 1,679,360 ----a-w C:\Windows\Internet Logs\xDB4235.tmp
2008-02-14 18:38 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 18:38 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 18:24 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-14 18:24 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 18:24 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 18:24 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 18:24 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 18:24 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-14 18:24 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 18:23 --------- d-----w C:\ProgramData\Microsoft Help
2008-02-14 18:20 806,400 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 18:20 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 18:20 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 18:20 217,144 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 18:20 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 18:19 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 18:19 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 18:19 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 18:19 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 18:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 18:19 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 18:13 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 18:12 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 18:12 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 18:12 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-11 17:55 38,912 ----a-w C:\Windows\Internet Logs\xDBA6BF.tmp
2008-02-11 17:55 1,674,240 ----a-w C:\Windows\Internet Logs\xDBA921.tmp
2008-02-11 15:21 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-08 18:44 --------- d-----w C:\ProgramData\WLInstaller
2008-02-07 17:47 2,662,400 ----a-w C:\Windows\Internet Logs\xDB8F6E.tmp
2008-02-07 17:47 1,669,632 ----a-w C:\Windows\Internet Logs\xDB91E0.tmp
2008-02-05 18:22 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-29 13:40 --------- d-----w C:\Program Files\BitLord2
2008-01-29 10:48 --------- d-----w C:\Program Files\Lavasoft
2008-01-29 10:47 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-20 19:05 --------- d-----w C:\Program Files\PDFCreator
2008-01-20 18:17 --------- d-----w C:\Program Files\Lavalys
2008-01-20 18:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-20 18:08 --------- d-----w C:\Program Files\ASUS
2008-01-20 11:12 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-20 11:10 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-01-20 11:09 --------- d-----w C:\Program Files\Common Files\Ahead
2008-01-20 11:08 --------- d-----w C:\Users\Charly\AppData\Roaming\Ahead
2008-01-19 11:17 --------- d-----w C:\Users\Charly\AppData\Roaming\Uniblue
2008-01-18 15:38 1,625,088 ----a-w C:\Windows\Internet Logs\xDBB239.tmp
2008-01-18 09:21 --------- d-----w C:\Program Files\Microsoft DirectX SDK (April 2007)
2008-01-18 09:21 --------- d-----w C:\Program Files\Common Files\aliaswavefront shared
2008-01-18 09:21 --------- d-----w C:\Program Files\Common Files\Alias Shared
2008-01-17 20:01 --------- d-----w C:\ProgramData\eMule
2008-01-17 20:01 --------- d-----w C:\Program Files\eMule
2008-01-16 12:22 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-01-15 21:12 --------- d-----w C:\Users\Charly\AppData\Roaming\Kptic
2008-01-15 16:37 --------- d-----w C:\Program Files\Neonumeric
2008-01-15 14:38 249,344 ----a-w C:\Windows\Internet Logs\xDBB277.tmp
2008-01-15 14:38 1,605,120 ----a-w C:\Windows\Internet Logs\xDBB4F9.tmp
2008-01-12 20:37 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-12 20:37 --------- d-----w C:\Program Files\Windows Mail
2008-01-12 20:37 --------- d-----w C:\Program Files\Cyanide
2008-01-11 12:01 --------- d-----w C:\ProgramData\Lavasoft
2008-01-11 08:32 12,800 ----a-w C:\Windows\Internet Logs\xDBB381.tmp
2008-01-11 08:32 1,587,200 ----a-w C:\Windows\Internet Logs\xDBB518.tmp
2008-01-11 08:29 1,652,736 ----a-w C:\Windows\Internet Logs\xDBA9DC.tmp
2008-01-11 08:29 1,587,200 ----a-w C:\Windows\Internet Logs\xDBAC3E.tmp
2008-01-11 08:14 108,144 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-01-10 21:54 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-10 21:54 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-10 21:52 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-10 21:17 --------- d--h--r C:\Users\Charly\AppData\Roaming\SecuROM
2008-01-10 20:47 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-01-08 08:48 --------- d-----w C:\Users\Charly\AppData\Roaming\ESTsoft
2008-01-08 08:48 --------- d-----w C:\ProgramData\ESTsoft
2008-01-08 08:36 --------- d-----w C:\Program Files\7-Zip
2008-01-07 20:43 --------- d-----w C:\Program Files\BitLord
2008-01-07 19:31 1,794,048 ----a-w C:\Windows\Internet Logs\xDBA047.tmp
2008-01-07 17:07 33,280 ----a-w C:\Windows\Internet Logs\xDBAB72.tmp
2008-01-07 17:02 2,071,552 ----a-w C:\Windows\Internet Logs\xDBA2F6.tmp
2008-01-06 18:15 1,553,408 ----a-w C:\Windows\Internet Logs\xDBBD54.tmp
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 22:52 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-27 15:15 68856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 08:20 222080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-11 23:43 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 10:07 4390912 C:\Windows\RtHDVCpl.exe]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 10:31 630784]
"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 16:27 61440]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-22 22:27 815104]
"ASUSTPE"="C:\Windows\system32\ASUSTPE.exe" [2006-12-12 23:06 106496]
"ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2007-09-12 00:25 37232]
"ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2007-09-12 00:26 33136]
"PowerForPhone"="C:\Program Files\PowerForPhone\PowerForPhone.exe" [2007-06-26 18:10 778240]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-28 13:26 1836544]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-28 05:17 959976]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 11:45 63712]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-31 17:34 579072]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-31 17:34 219136]
C:\Users\Charly\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MSN Pictures Displayer.lnk - C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2007-11-23 15:39:16 4571136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 15:15:00 126136]
PDFCreator.lnk - C:\Program Files\PDFCreator\PDFCreator.exe [2008-01-20 20:03:41 2641920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-12-31 17:35 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A7C224B9-ED16-4E9E-B298-8900A4F84DD1}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{96BC5DBB-1E49-4276-8CD2-16015B32A0D9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{1AF8E2F1-DF93-45DC-B6CA-BFEA6C9EDEB8}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{B214DCBF-5DF5-4000-834E-904675EFBC12}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{E86E969D-F6BD-4994-97E0-8FD12E47185E}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"TCP Query User{2663C26C-60C8-4487-9E2F-D0F9D7A495A7}C:\program files\azureus\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{849BD603-97BC-4BB7-A5F6-EBAEA08D3918}C:\program files\azureus\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus|Desc=Azureus
"TCP Query User{82DF55A6-8669-4F0E-ACE4-4C1BDD1BB86E}C:\windows\system32\javaw.exe"= UDP:C:\windows\system32\javaw.exe:Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary
"UDP Query User{CB2CD7C6-83A9-4538-872E-B7AF525CD7CB}C:\windows\system32\javaw.exe"= TCP:C:\windows\system32\javaw.exe:Java(TM) Platform SE binary|Desc=Java(TM) Platform SE binary
"TCP Query User{FD11B86E-1F66-46A8-A48C-12A548702E25}C:\program files\tightvnc\winvnc.exe"= UDP:C:\program files\tightvnc\winvnc.exe:TightVNC Win32 Server|Desc=TightVNC Win32 Server
"UDP Query User{EC49498F-382D-4CD3-A1B6-27B9D950E0B0}C:\program files\tightvnc\winvnc.exe"= TCP:C:\program files\tightvnc\winvnc.exe:TightVNC Win32 Server|Desc=TightVNC Win32 Server
"{A79DA2B6-54AB-4428-959E-F8E5751AAA40}"= UDP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{1403B88D-1D52-4644-9E40-B962C76C22F9}"= TCP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{F87288C2-E6CB-4C09-80EB-2279BBC55D30}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{02082EB1-EECE-45EB-85A2-85786F522DF4}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{FF69D818-F928-402A-A2D8-992E17E24012}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{9F758BC6-15B2-4EAF-906C-90337E592381}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{76F2E18C-4CCB-4904-AF0F-AEC0BE50B0EA}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{70880648-0384-4DFD-ACE0-72B83330E383}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 ASLDRService;ASLDR Service;C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-02-06 02:13]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\Windows\System32\StkCSrv.exe [2006-12-10 17:31]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-12-11 01:32]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-06 16:04]
R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-01-11 02:18]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2007-01-19 16:19]
S2 ghaio;ghaio;C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2006-11-16 03:02]
S3 NETw3v32;Intel(R) PRO/Wireless 3945BG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 08:30]
S3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 08:30]
S3 TaurusUsb;ADSL Modem USB Service;C:\Windows\system32\DRIVERS\torususb.sys [2003-09-29 10:42]
S3 TPM;TPM;C:\Windows\system32\drivers\tpm.sys [2006-11-02 10:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6db3e699-c386-11dc-ba05-001d607dedce}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-24 11:32:06 C:\Windows\Tasks\User_Feed_Synchronization-{EB9281C9-4FA2-452A-896C-6348BE48FF0F}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 14:18:20
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-24 14:19:18
.
2008-02-24 09:30:23 --- E O F ---