re
rapport log de combofix
ComboFix 12-06-03.01 - Utilisateur 03/06/2012 13:42:38.1.1 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2815.1827 [GMT 2:00]
Lancé depuis: c:\users\Utilisateur\Desktop\fei.exe.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Public\Windows Live Messenger .lnk
c:\windows\system32\avisynth.dll
c:\windows\system32\devil.dll
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-05-03 au 2012-06-03 ))))))))))))))))))))))))))))))))))))
.
.
2012-06-03 11:49 . 2012-06-03 11:49 -------- d-----w- c:\users\Thomas\AppData\Local\temp
2012-06-02 14:12 . 2012-05-08 16:40 6737808 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{53419786-817E-48E1-9B26-CD33DE842F39}\mpengine.dll
2012-06-02 11:45 . 2012-06-02 11:46 -------- d-----w- c:\program files\ZHPDiag
2012-06-02 11:14 . 2012-06-02 11:14 1984 ----a-w- C:\FixitRegBackup.reg
2012-05-31 21:06 . 2012-05-31 21:06 -------- d-----w- C:\FyK
2012-05-30 22:28 . 2012-05-30 22:28 -------- d-----w- c:\program files\trend micro
2012-05-30 22:28 . 2012-05-30 22:28 -------- d-----w- C:\rsit
2012-05-30 04:05 . 2012-05-30 04:05 -------- d--h--w- c:\windows\msdownld.tmp
2012-05-29 22:25 . 2012-05-29 22:25 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\38d8bf41cd3dea03\MeshBetaRemover.exe
2012-05-29 22:25 . 2012-05-29 22:25 89944 ----a-w- c:\program files\Common Files\Windows Live\.cache\c655a41cd3dea02\DSETUP.dll
2012-05-29 22:25 . 2012-05-29 22:25 537432 ----a-w- c:\program files\Common Files\Windows Live\.cache\c655a41cd3dea02\DXSETUP.exe
2012-05-29 22:25 . 2012-05-29 22:25 1801048 ----a-w- c:\program files\Common Files\Windows Live\.cache\c655a41cd3dea02\dsetup32.dll
2012-05-29 21:54 . 2011-11-18 20:23 1205064 ----a-w- c:\windows\system32\ntdll.dll
2012-05-22 19:24 . 2012-06-01 22:44 -------- d-----w- c:\users\Utilisateur\AppData\Roaming\QuickScan
2012-05-22 16:23 . 2012-05-22 16:23 -------- d-----w- c:\program files\VS Revo Group
2012-05-22 16:11 . 2012-05-22 16:11 -------- d-----w- c:\users\Utilisateur\AppData\Roaming\Malwarebytes
2012-05-22 16:11 . 2012-05-22 16:11 -------- d-----w- c:\programdata\Malwarebytes
2012-05-22 16:11 . 2012-05-22 16:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-05-22 16:11 . 2012-04-04 13:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-22 15:43 . 2012-05-22 15:43 -------- d-----w- c:\users\Utilisateur\AppData\Local\Windows Live Writer
2012-05-22 15:43 . 2012-05-22 15:43 -------- d-----w- c:\users\Utilisateur\AppData\Roaming\Windows Live Writer
2012-05-22 15:38 . 2012-05-22 15:38 -------- d-----w- c:\users\Utilisateur\AppData\Local\Mozilla
2012-05-22 15:38 . 2012-05-22 15:38 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-05-22 15:33 . 2008-01-18 21:34 89600 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPLHN.DLL
2012-05-12 23:19 . 2012-05-13 07:27 -------- d-----w- c:\users\Utilisateur\DoctorWeb
2012-05-12 14:44 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2012-05-11 20:31 . 1999-11-12 03:11 183808 ----a-w- c:\windows\system32\BDEADMIN.CPL
2012-05-11 20:31 . 1999-01-20 03:01 210032 ----a-w- c:\windows\system32\DBCLIENT.DLL
2012-05-11 20:31 . 2012-05-11 20:31 -------- d-----w- c:\program files\Common Files\Borland Shared
2012-05-11 20:24 . 2012-06-02 11:46 -------- d-----w- C:\ZHP
2012-05-11 18:47 . 2012-06-01 15:29 -------- d-----w- c:\program files\CCleaner
2012-05-11 17:41 . 2012-05-11 17:41 -------- d-----w- c:\program files\Lavalys
2012-05-11 17:16 . 2012-05-11 17:16 -------- d-----w- c:\program files\Common Files\Java
2012-05-11 17:15 . 2012-05-11 17:15 476960 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-05-11 17:12 . 2012-04-03 08:16 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-11 17:12 . 2012-04-03 08:16 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-11 17:12 . 2012-04-02 13:36 2044928 ----a-w- c:\windows\system32\win32k.sys
2012-05-11 17:12 . 2012-03-20 23:28 53120 ----a-w- c:\windows\system32\drivers\partmgr.sys
2012-05-11 17:05 . 2012-05-11 17:05 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2012-05-07 18:33 . 2012-05-07 18:33 -------- d-----w- c:\program files\Dealio Toolbar(47)
2012-05-07 18:33 . 2012-05-07 18:33 -------- d-----w- c:\program files\Common Files\Spigot(46)
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-02 11:13 . 2012-03-30 17:39 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-02 11:13 . 2011-05-23 18:34 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-11 17:15 . 2010-09-20 18:06 472864 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-21 01:18 . 2012-05-22 15:38 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 4186112]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2006-11-23 319488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-19 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-19 92704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-02-04 281768]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Assistant du gestionnaire de contenu pour PlayStation(R).lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Assistant du gestionnaire de contenu pour PlayStation(R).lnk
backup=c:\windows\pss\Assistant du gestionnaire de contenu pour PlayStation(R).lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WiFi Station.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\WiFi Station.lnk
backup=c:\windows\pss\WiFi Station.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Utilisateur^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\users\Utilisateur\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]
??????????????e [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-02 09:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-20 20:28 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
2006-11-17 06:26 453120 ----a-w- c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4400 Series]
2007-03-01 04:01 180736 ----a-w- c:\windows\System32\spool\drivers\w32x86\3\E_FATICAE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-09-16 15:55 136176 ----atw- c:\users\Utilisateur\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-03-27 03:09 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2010-05-20 13:27 119152 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-02-28 16:38 1987976 ----a-w- c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2011-05-13 15:03 4283256 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\orangeinside]
2010-08-17 13:32 858624 ----a-w- c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 13:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-10 21:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 12:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
2010-05-20 13:27 762736 ----a-w- c:\windows\vVX1000.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-18 21:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-02 257696]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2012-06-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-30 11:13]
.
2012-06-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-17 12:49]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-17 12:49]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20981003-728860430-1708586717-1000Core.job
- c:\users\Utilisateur\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-20 15:55]
.
2012-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20981003-728860430-1708586717-1000UA.job
- c:\users\Utilisateur\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-20 15:55]
.
2012-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20981003-728860430-1708586717-1001Core.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-19 15:55]
.
2012-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-20981003-728860430-1708586717-1001UA.job
- c:\users\Thomas\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-19 15:55]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: _ajouter cette page à vos favoris Orange - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\addfavorites_html\addfavorites.html
IE: _envoyer le texte sélectionné par sms - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\sendsmsselectedtext_html\sendsmsselectedtext.html
IE: _envoyer par sms - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\sendsms_html\sendsms.html
IE: _envoyer un mail - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\sendmail_html\sendmail.html
IE: _orange.fr - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\orange_html\orange.html
IE: _rechercher le texte sélectionné - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\selectedsearch_html\selectedsearch.html
IE: _traduire la page - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\translate_html\translate.html
IE: _traduire le texte sélectionné - c:\users\Utilisateur\AppData\Roaming\Orange\OrangeInside\src\translateSelectedText_html\translateSelectedText.html
Trusted Zone: orange.fr\logicielsgratuits
DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - hxxp://logicielsgratuits.orange.fr/download_service/Install/OrangeInstaller.cab
FF - ProfilePath - c:\users\Utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\ufj03b5a.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.fr/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-10 - (no file)
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-Raptr - c:\progra~1\Raptr\raptrstub.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-06-03 13:49
Windows 6.0.6002 Service Pack 2 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_80c2ffa.dll"
.
Heure de fin: 2012-06-03 13:52:55
ComboFix-quarantined-files.txt 2012-06-03 11:52
.
Avant-CF: 17 180 704 768 octets libres
Après-CF: 26 025 754 624 octets libres
.
- - End Of File - - AE0345E64E7678CB030DE6868A665EEF
encore merci au intervenant
bon dimanche
merci roro zhpdiag fonctionne normalement
je te poste son rapport
http://cjoint.com/?BFdoFE1DSaV
a tout