Bonjour,
Suite à lenteur de mon PC, également lenteur des fenêtres à s'ouvrir et connection internet très longues, vous trouverez ci-joints un rapport Hitjacthis et Combofix. Car je ne sais pas d'où viennent ces lenteurs.
ComboFix 09-10-08.04 - _ 12/10/2009 9:42.1.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.566 [GMT 2:00]
Lancé depuis: c:\documents and settings\_\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Installer\103be84.msi
c:\windows\Installer\11f2b32.msp
c:\windows\Installer\136742.msi
c:\windows\Installer\14e1a0a.msi
c:\windows\Installer\1614a6.msp
c:\windows\Installer\161ac0.msp
c:\windows\Installer\1623503.msi
c:\windows\Installer\184dfc.msi
c:\windows\Installer\192ca90.msp
c:\windows\Installer\1a4d951.msi
c:\windows\Installer\1aa7fa7.msi
c:\windows\Installer\1aa7fb6.msi
c:\windows\Installer\1c9c85a.msi
c:\windows\Installer\1c9c864.msi
c:\windows\Installer\1c9c86a.msi
c:\windows\Installer\1c9c874.msi
c:\windows\Installer\1c9c914.msi
c:\windows\Installer\1c9c91c.msi
c:\windows\Installer\1c9c922.msi
c:\windows\Installer\1c9c929.msi
c:\windows\Installer\1c9c930.msi
c:\windows\Installer\1c9c936.msi
c:\windows\Installer\1c9c93c.msi
c:\windows\Installer\1c9c943.msi
c:\windows\Installer\1c9c9b6.msi
c:\windows\Installer\1f10d1.msp
c:\windows\Installer\1f2053.msp
c:\windows\Installer\1f2054.msp
c:\windows\Installer\1f2055.msp
c:\windows\Installer\1f2056.msp
c:\windows\Installer\1f2057.msp
c:\windows\Installer\1f2058.msp
c:\windows\Installer\1f2059.msp
c:\windows\Installer\1f205a.msp
c:\windows\Installer\1f205b.msp
c:\windows\Installer\1f8323.msp
c:\windows\Installer\20a10a.msp
c:\windows\Installer\21eff24.msp
c:\windows\Installer\21f0b8.msp
c:\windows\Installer\22e9af.msp
c:\windows\Installer\22e9b0.msp
c:\windows\Installer\22e9b1.msp
c:\windows\Installer\22e9b2.msp
c:\windows\Installer\22e9b3.msp
c:\windows\Installer\22e9b4.msp
c:\windows\Installer\22e9b5.msp
c:\windows\Installer\22e9b6.msp
c:\windows\Installer\22e9b7.msp
c:\windows\Installer\2518a3a.msp
c:\windows\Installer\25fece.msp
c:\windows\Installer\28ef223.msp
c:\windows\Installer\29262.msp
c:\windows\Installer\29d4f.msp
c:\windows\Installer\2aad9e0.msp
c:\windows\Installer\2adba.msp
c:\windows\Installer\2be99d8.msp
c:\windows\Installer\2c365.msp
c:\windows\Installer\2dc6c.msp
c:\windows\Installer\34b5b.msi
c:\windows\Installer\34e0ed.msp
c:\windows\Installer\354350.msp
c:\windows\Installer\36bf42.msp
c:\windows\Installer\3844b9.msi
c:\windows\Installer\3db8c.msp
c:\windows\Installer\3f2d77.msp
c:\windows\Installer\3f2d78.msp
c:\windows\Installer\3f2d79.msp
c:\windows\Installer\3f2d7a.msp
c:\windows\Installer\3f2d7b.msp
c:\windows\Installer\3f2d7c.msp
c:\windows\Installer\3f2d7d.msp
c:\windows\Installer\3f2d7e.msp
c:\windows\Installer\3f2d7f.msp
c:\windows\Installer\4031f5.msp
c:\windows\Installer\442011.msp
c:\windows\Installer\442012.msp
c:\windows\Installer\442013.msp
c:\windows\Installer\442014.msp
c:\windows\Installer\442015.msp
c:\windows\Installer\442016.msp
c:\windows\Installer\442017.msp
c:\windows\Installer\442018.msp
c:\windows\Installer\442019.msp
c:\windows\Installer\44a09a.msp
c:\windows\Installer\496fc.msp
c:\windows\Installer\4bb20d.msp
c:\windows\Installer\4c38b.msp
c:\windows\Installer\4f9058.msp
c:\windows\Installer\500181.msi
c:\windows\Installer\53d5f.msp
c:\windows\Installer\53d60.msp
c:\windows\Installer\53d61.msp
c:\windows\Installer\53d62.msp
c:\windows\Installer\53d63.msp
c:\windows\Installer\53d64.msp
c:\windows\Installer\53d65.msp
c:\windows\Installer\53d66.msp
c:\windows\Installer\53d67.msp
c:\windows\Installer\547af.msp
c:\windows\Installer\57c54.msi
c:\windows\Installer\5ab0bc.msp
c:\windows\Installer\5d3275.msp
c:\windows\Installer\5d3276.msp
c:\windows\Installer\66f25e.msp
c:\windows\Installer\67c37.msp
c:\windows\Installer\70f581.msi
c:\windows\Installer\70f595.msp
c:\windows\Installer\70f5ab.msp
c:\windows\Installer\70f5c1.msp
c:\windows\Installer\70f5c3.msp
c:\windows\Installer\74ddf.msi
c:\windows\Installer\74de9.msi
c:\windows\Installer\76b930.msp
c:\windows\Installer\773094.msi
c:\windows\Installer\77309d.msi
c:\windows\Installer\7730a5.msi
c:\windows\Installer\7bc7fd.msp
c:\windows\Installer\7be479.msi
c:\windows\Installer\7be47a.msp
c:\windows\Installer\7be47b.msp
c:\windows\Installer\7be47c.msp
c:\windows\Installer\7be47d.msp
c:\windows\Installer\7be47e.msp
c:\windows\Installer\7be47f.msp
c:\windows\Installer\7be480.msp
c:\windows\Installer\7be481.msp
c:\windows\Installer\7be482.msp
c:\windows\Installer\7c002.msp
c:\windows\Installer\7c01a.msi
c:\windows\Installer\7d3e8.msi
c:\windows\Installer\82563.msi
c:\windows\Installer\82564.msp
c:\windows\Installer\82565.msp
c:\windows\Installer\82566.msp
c:\windows\Installer\82567.msp
c:\windows\Installer\82568.msp
c:\windows\Installer\82569.msp
c:\windows\Installer\8256a.msp
c:\windows\Installer\8256b.msp
c:\windows\Installer\8256c.msp
c:\windows\Installer\891c2.msi
c:\windows\Installer\8a6e11.msi
c:\windows\Installer\8bd5d.msi
c:\windows\Installer\92639.msi
c:\windows\Installer\9539cc.msi
c:\windows\Installer\9d260.msi
c:\windows\Installer\a02d6.msi
c:\windows\Installer\a49f8.msp
c:\windows\Installer\acea9.msp
c:\windows\Installer\b3581.msi
c:\windows\Installer\b6cec4.msp
c:\windows\Installer\bc1d68.msp
c:\windows\Installer\be5404.msi
c:\windows\Installer\c0b10a.msp
c:\windows\Installer\c4e54.msi
c:\windows\Installer\ccc37.msi
c:\windows\Installer\e5232.msp
c:\windows\Installer\ebb4d.msp
c:\windows\Installer\f143a.msp
c:\windows\Installer\f5fbae.msp
c:\windows\system\oeminfo.ini
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\AVSredirect.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Ijl11.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-12 au 2009-10-12 ))))))))))))))))))))))))))))))))))))
.
2009-10-09 16:38 . 2009-10-09 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-10-09 09:50 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-09 09:50 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-09 09:50 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-08 10:55 . 2009-10-09 06:34 -------- d-----w- c:\windows\SxsCaPendDel
2009-10-08 09:19 . 2009-10-08 09:21 -------- d-----w- c:\documents and settings\_\Application Data\FILEminimizer
2009-10-08 09:19 . 2009-10-08 09:19 -------- d-----w- c:\program files\FILEminimizer Office
2009-10-08 07:26 . 2009-10-08 07:26 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\ScreenCapture
2009-10-07 17:55 . 2004-01-24 22:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2009-10-07 17:52 . 2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
2009-10-07 17:52 . 2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2009-10-07 17:52 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2009-10-07 17:07 . 2009-10-07 17:08 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2009-10-07 11:53 . 2009-10-09 09:09 -------- d-----w- c:\documents and settings\_\Application Data\vlc
2009-10-07 11:51 . 2009-10-07 11:51 -------- d-----w- c:\program files\VideoLAN
2009-10-06 17:33 . 2009-10-06 17:33 -------- d-----w- c:\program files\Xi
2009-10-06 11:11 . 2009-10-06 11:11 107104 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-10-06 11:11 . 2009-10-06 11:11 124 ----a-w- c:\documents and settings\_\Local Settings\Application Data\fusioncache.dat
2009-10-02 14:27 . 2009-10-02 14:27 -------- d-----w- c:\documents and settings\_\Application Data\Todae
2009-10-02 09:18 . 2009-10-02 09:18 -------- d-----w- c:\program files\Real Alternative
2009-10-02 08:46 . 2009-10-02 08:46 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2009-10-02 08:43 . 2009-10-02 08:43 -------- d-----w- c:\documents and settings\_\Local Settings\Application Data\Downloaded Installations
2009-10-01 08:22 . 2009-10-08 17:03 -------- d-----w- c:\program files\MediaCoder
2009-09-28 12:20 . 2009-10-09 10:20 -------- d-----w- c:\documents and settings\_\Application Data\dvdcss
2009-09-23 17:13 . 2009-09-23 17:13 -------- d-----w- c:\documents and settings\_\Application Data\GlarySoft
2009-09-23 17:10 . 2009-09-23 17:10 -------- d-----w- c:\program files\Glary Utilities
2009-09-23 07:09 . 2009-09-23 07:09 -------- d-----w- c:\documents and settings\_\Local Settings\Application Data\MAGIX
2009-09-22 16:24 . 2009-09-22 16:24 -------- d-----w- c:\documents and settings\_\Application Data\Canneverbe_Limited
2009-09-22 16:24 . 2009-09-22 16:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2009-09-22 16:24 . 2008-11-28 13:13 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-09-22 16:24 . 2009-09-22 16:24 -------- d-----w- c:\program files\CDBurnerXP
2009-09-16 08:49 . 2009-09-16 08:49 -------- d-----w- c:\program files\VirtualDub
2009-09-16 08:45 . 2009-09-16 08:45 -------- d-----w- c:\program files\VirtualDubMOD
2009-09-16 07:01 . 2009-09-16 07:02 -------- d-----w- c:\documents and settings\All Users\Application Data\MAGIX
2009-09-16 07:01 . 2009-09-16 07:01 -------- d-----w- c:\program files\ALDI
2009-09-16 06:57 . 2007-04-27 08:43 120200 ----a-w- c:\windows\system32\DLLDEV32i.dll
2009-09-16 06:57 . 2009-09-16 07:01 -------- d-----w- c:\windows\system32\MAGIX
2009-09-16 06:57 . 2007-07-11 09:53 697560 ----a-w- c:\windows\system32\mgxoschk.dll
2009-09-15 16:30 . 2009-10-08 18:47 -------- d-----w- c:\program files\Free Video Converter
2009-09-15 15:45 . 2009-09-15 15:45 -------- d-----w- c:\documents and settings\_\Application Data\Bitdefender
2009-09-15 15:45 . 2009-09-15 15:45 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-09-15 15:45 . 2009-09-15 15:45 -------- d-----w- c:\program files\BitDefender
2009-09-15 15:42 . 2009-09-15 15:45 -------- d-----w- c:\program files\Fichiers communs\BitDefender
2009-09-15 13:43 . 2009-09-15 13:43 180344 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-15 13:42 . 2009-09-15 13:42 -------- d-----w- c:\program files\Reference Assemblies
2009-09-14 16:42 . 2009-10-02 13:32 -------- d-----w- c:\program files\AviSynth 2.5
2009-09-14 16:18 . 2009-09-14 16:18 -------- d-----w- c:\documents and settings\_\Application Data\Broad Intelligence
2009-09-14 16:05 . 2009-09-14 16:05 -------- d-----w- c:\program files\Fichiers communs\SWF Studio
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-12 07:51 . 2008-09-06 13:27 81984 ----a-w- c:\windows\system32\bdod.bin
2009-10-09 09:44 . 2009-06-10 05:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-09 09:43 . 2009-09-05 11:02 -------- d-----w- c:\program files\BitComet
2009-10-08 11:48 . 2009-06-10 12:01 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-10-07 16:53 . 2009-04-04 08:59 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-10-06 11:57 . 2009-05-05 12:48 -------- d-----w- c:\documents and settings\_\Application Data\Azureus
2009-10-06 11:11 . 2008-09-08 15:17 8224 ----a-w- c:\documents and settings\_\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-28 10:06 . 2009-08-02 19:09 -------- d-----w- c:\program files\Lavalys
2009-09-16 11:48 . 2008-12-24 08:19 -------- d-----w- c:\program files\Java
2009-09-16 07:04 . 2008-09-09 08:13 -------- d-----w- c:\documents and settings\_\Application Data\XnView
2009-09-15 17:04 . 2007-07-20 13:54 77824 ----a-w- c:\windows\system32\xcomm.dll
2009-09-15 16:27 . 2009-07-04 07:15 -------- d-----w- c:\program files\DVDVIDEOSOFT
2009-09-15 13:21 . 2008-10-27 10:30 -------- d-----w- c:\program files\Fichiers communs\DVDVideoSoft
2009-09-11 16:36 . 2009-09-11 16:36 33533 ----a-w- c:\windows\system32\CoreVorbis-uninstall.exe
2009-09-11 16:35 . 2009-02-23 12:10 -------- d-----w- c:\program files\AC3Filter
2009-09-11 16:34 . 2009-09-11 16:34 56 --sh--r- c:\windows\system32\BD9F9C1399.sys
2009-09-11 16:34 . 2009-09-11 16:34 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-11 16:30 . 2009-02-22 19:01 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-11 08:01 . 2009-04-02 07:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 12:54 . 2009-04-02 07:17 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-04-02 07:17 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-02 16:25 . 2009-05-05 12:47 -------- d-----w- c:\program files\Vuze
2009-09-01 06:43 . 2009-08-25 12:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-08-30 07:36 . 2009-08-29 13:12 -------- d-----w- c:\program files\AskBarDis
2009-08-28 10:44 . 2009-08-28 10:44 265797 ----a-w- c:\windows\system32\pdvcodec.dll
2009-08-26 11:44 . 2009-08-26 11:44 -------- d-----w- c:\program files\VirtualDJ
2009-08-25 15:17 . 2008-09-05 13:14 569784 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-25 15:17 . 2008-09-05 13:14 110180 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-25 14:21 . 2009-08-25 12:47 603904 ----a-w- c:\windows\system32\TUProgSt.exe
2009-08-25 14:21 . 2009-08-25 12:47 360192 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-08-21 18:45 . 2009-01-16 14:47 -------- d-----w- c:\program files\MyHeritage
2009-08-21 18:38 . 2009-08-21 18:38 -------- d-----w- c:\program files\Family Toolbar
2009-08-21 13:45 . 2009-08-21 13:44 -------- d-----w- c:\documents and settings\_\Application Data\Ahead
2009-08-21 13:37 . 2009-08-21 13:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-08-21 13:36 . 2009-08-21 13:34 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-08-21 13:34 . 2009-08-21 13:34 -------- d-----w- c:\program files\Nero
2009-08-21 13:34 . 2009-08-21 13:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-08-20 13:30 . 2009-08-20 13:30 -------- d-----w- c:\program files\Belarc
2009-08-19 14:48 . 2009-08-19 14:48 351248 ----a-w- c:\windows\system32\FTBSaver.scr
2009-08-17 19:34 . 2009-08-17 18:00 -------- d-----w- c:\program files\Fichiers communs\Nero
2009-08-14 19:26 . 2008-10-13 12:01 -------- d-----w- c:\program files\IEPro
2009-08-14 13:15 . 2008-09-05 10:26 23756 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-06 17:24 . 2008-09-05 10:26 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 17:24 . 2008-09-05 10:26 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 17:24 . 2008-10-16 12:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 17:24 . 2008-09-05 10:26 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 17:24 . 2008-09-05 10:26 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 17:24 . 2008-04-13 17:33 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 17:23 . 2008-09-05 10:26 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 17:23 . 2008-09-05 10:26 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:00 . 2008-04-13 17:33 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-31 13:23 . 2008-12-24 08:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-29 04:35 . 2008-04-13 17:33 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:35 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:03 . 2008-04-13 17:33 58880 ----a-w- c:\windows\system32\atl.dll
2009-06-17 19:07 . 2009-06-17 19:07 23 ----a-w- c:\program files\hfkud16.sys
2007-02-16 09:31 . 2009-07-15 09:46 227328 ----a-w- c:\program files\mpTrim.exe
2004-03-11 12:27 . 2008-11-17 18:07 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2009-01-22 16:16 . 2009-01-22 16:16 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2006-05-03 09:06 . 2009-10-07 17:52 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-10-07 17:52 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-10-07 17:52 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48}"= "c:\program files\Family Toolbar\tbhelper.dll" [2009-05-07 355840]
[HKEY_CLASSES_ROOT\clsid\{1c4ab6a5-595f-4e86-b15f-f93cce2bbd48}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{1EA6B471-CAD2-419a-9539-0586EEFE2D09}]
[HKEY_CLASSES_ROOT\URLSearchHook.MHURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0C37B053-FD68-456a-82E1-D788EE342E6F}]
2009-05-07 21:46 2642432 ----a-w- c:\program files\Family Toolbar\tbcore3.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}"= "c:\program files\Family Toolbar\tbcore3.dll" [2009-05-07 2642432]
[HKEY_CLASSES_ROOT\clsid\{fd2fd708-1f6f-4b68-b141-c5778f0c19bb}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar.3]
[HKEY_CLASSES_ROOT\TypeLib\{EC4085F2-8DB3-45a6-AD0B-CA289F3C5D7E}]
[HKEY_CLASSES_ROOT\MHToolbar.MHToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-09-15 368640]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-21 86016]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2006-05-04 2808832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-05 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
backup=c:\windows\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^_^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ALDI_FotoSuite_Download
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Real Alternative\\Media Player Classic\\mplayerc.exe"=
"c:\\Program Files\\Media Player Classic\\mplayerc_fr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9916:TCP"= 9916:TCP:BitComet 9916 TCP
"9916:UDP"= 9916:UDP:BitComet 9916 UDP
"26736:TCP"= 26736:TCP:BitComet 26736 TCP
"26736:UDP"= 26736:UDP:BitComet 26736 UDP
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [25/08/2009 14:47 603904]
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;c:\windows\system32\drivers\hcw88rc5.sys [08/09/2008 18:53 10305]
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;c:\windows\system32\drivers\hcw88tun.sys [08/09/2008 18:53 116801]
R3 HCW88VID;Hauppauge WinTV 88x Video;c:\windows\system32\drivers\hcw88vid.sys [08/09/2008 18:53 569116]
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;c:\windows\system32\drivers\hcw88bar.sys [08/09/2008 18:53 26972]
R3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\system32\drivers\RTL2831UBDA.sys [31/01/2008 06:08 94112]
R3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\system32\drivers\RTL2831UUSB.sys [31/01/2008 06:08 31776]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S2 WinDefend;WinDefend; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-10-12 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-09-23 17:27]
2009-10-12 c:\windows\Tasks\User_Feed_Synchronization-{87103949-CE65-4417-9E04-EBBB554BD286}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.itdsystem.com/
mWindow Title =
IE: &Télécharger avec NetTransport - c:\program files\Xi\NetTransport 2\NTAddLink.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Tout t&élécharger avec NetTransport - c:\program files\Xi\NetTransport 2\NTAddList.html
IE: Tout télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Télécharger toutes les vidéos avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
Trusted Zone: secuser.com\www
DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.fr/Genoogle/Components/ActiveX/SearchEngineQuery.dll
FF - ProfilePath - c:\documents and settings\_\Application Data\Mozilla\Firefox\Profiles\fn5yc8d8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://www.itdsystem.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=2&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\_\Application Data\Mozilla\Firefox\Profiles\fn5yc8d8.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
---- PARAMETRES FIREFOX ----
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
URLSearchHooks-{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-12 09:51
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Heure de fin: 2009-10-12 9:54
ComboFix-quarantined-files.txt 2009-10-12 07:54
Avant-CF: 57 708 384 256 octets libres
Après-CF: 57 351 131 136 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Mode sans echec" /noexecute=optin /fastdetect >/sos /bootlog
447 --- E O F --- 2009-09-26 18:25
of Trend Micro HijackThis v2.0.2
Scan saved at 10:40:28, on 12/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\_\Mes documents\Hijackthis 2\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.itdsystem.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dll
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - (no file)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: (no name) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Tout télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Télécharger avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Télécharger toutes les vidéos avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.3.2.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.fr/Genoogle/Componen...EngineQuery.dll
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - (no file)
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Unknown owner - C:\Program Files\Avira\AntiVir Desktop\sched.exe (file missing)
O23 - Service: Avira AntiVir Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8429 byteslenteurs et qu'est-ce que je dois faire? Merci