j'expose le problème : j'ai des redémarrages sauvages fréquents sur le compte utilisateur & administrateur
depuis plusieurs semaines. J'ai d'abord pensé à un problème de compatibilité HardWare avec un carte son Terratec
une carte TV ou une nouvelle souris, j'ai passé en revue tous les programmes installés, rien à signaler de ce côté là.
Le support Microsoft ne peut identifier les rapports d'erreurs et de plantage envoyés depuis ... au moins çà
Comme seule réponse généraliste : http://support.microsoft.com/?kbid=322205 ...
Plusieurs signalement de plantage de la console Java, j'ai donc tous désinstallé, vidé les différents fichiers
temporaires, "cache" ou autres & réinstallé la Java VS 6.21 à partir d'un fichier téléchargé sur le site officiel.
La semaine passée, ma bécanne traine & les sessions utilisateurs peinent à démarrer (+ plantage Explorer.exe & SfCtlCom.exe) & l'interface de TrendInternetSecurity n'est ni accessible via l'icône de la barre des tâches(icône avec le sigle "Attention"), ni via le menu contextuel(scan) ou le menu démarrer ... Tous les périphériques Son(2 cartes) ont sauté & sont HS, j'ai dû réinstaller la plupart de pilotes/drivers ... A ce stade, l'ordinateur démarrait une fois sur trois + 5 bonnes minutes lors de l'ouverture d'une session ...
=> Mode Sans Echec avec prise en charge réseau, Trend est dépassé & amplifie le plantage & désinstallation
impossible en mode classique(cf. PrtScr). J'ai passé ATFcleaner, refais le tour de tous les endroits stratégiques
mais j'ai aussi vidé le dossier "C:\WINDOWS\SoftwareDistribution\Download\" et viré les désinstallateurs
de correctifs Windows à la racine du répertoire "C:\Windows\$...." ... puis j'ai passé l'outil ComboFix, voici les rapports :
log a écrit :ComboFix 10-07-31.04 - FreddyX 01/08/2010 16:07:15.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.3327.2717 [GMT 2:00]
Lancé depuis: c:\documents and settings\FreddyX\Bureau\COLAL.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Pare-feu personnel Trend Micro *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\install.exe
c:\windows\system32\service
c:\windows\system32\service\31052010_TIS17_SfFniAU.log
c:\windows\system32\VB6KO.DLL
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-07-01 au 2010-08-01 ))))))))))))))))))))))))))))))))))))
.
2010-11-30 06:23 . 2010-08-01 03:23 219128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-11-30 06:23 . 2010-04-15 08:12 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-11-30 06:13 . 2010-11-30 06:13 -------- d-----w- c:\program files\Activision
2010-11-28 22:45 . 2010-07-28 20:26 -------- d-sh--w- c:\documents and settings\FreddyX\PrivacIE
2010-11-28 21:52 . 2010-11-30 06:24 22328 ----a-w- c:\documents and settings\FreddyX\Application Data\PnkBstrK.sys
2010-11-28 21:52 . 2010-07-31 21:12 138592 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-11-28 21:52 . 2010-11-28 21:52 -------- d-----w- c:\windows\system32\LogFiles
2010-11-28 21:37 . 2010-11-28 21:37 -------- d-sh--w- c:\windows\ftpcache
2010-11-20 17:36 . 2010-11-20 17:36 -------- d-----w- c:\documents and settings\FreddyX\Local Settings\Application Data\GHISLER
2010-11-16 18:07 . 2010-07-28 20:10 -------- d-----w- c:\program files\lg_fwupdate
2010-11-16 18:07 . 2010-04-12 23:58 16384 ----a-w- c:\windows\system32\lgfwunis.exe
2010-11-16 18:07 . 1998-07-21 23:00 102912 ----a-w- c:\windows\system32\Vb6stkit.dll
2010-11-16 17:53 . 2002-11-25 03:46 16896 ----a-w- c:\windows\system32\drivers\synasUSB.sys
2010-11-16 17:44 . 2010-11-16 17:44 -------- d-----w- c:\program files\Smart Projects
2010-11-16 17:34 . 2002-10-09 12:21 566272 ----a-w- c:\windows\system32\wmvdmoe.dll
2010-11-16 17:34 . 2001-10-19 14:40 1683792 ----a-w- c:\windows\system32\wmvcore2.dll
2010-11-16 17:34 . 2001-10-19 14:40 438608 ----a-w- c:\windows\system32\wmv8dmod.dll
2010-11-16 17:34 . 2001-10-19 14:40 665424 ----a-w- c:\windows\system32\wmv8dmoe.dll
2010-11-16 15:31 . 2010-11-16 15:32 -------- d-----w- c:\program files\Cobian Backup 10
2010-11-16 15:21 . 2010-11-16 15:21 368640 ------w- c:\windows\system32\ReWire.dll
2010-11-16 15:21 . 2010-11-16 15:21 233472 ------w- c:\windows\system32\REX Shared Library.dll
2010-11-16 15:17 . 2010-11-16 15:22 -------- d-----w- c:\documents and settings\FreddyX\Application Data\Propellerhead Software
2010-11-16 15:17 . 2010-11-16 15:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Propellerhead Software
2010-11-16 15:17 . 2010-11-16 15:17 -------- d-----w- c:\program files\Propellerhead
2010-11-16 14:58 . 2003-11-08 05:07 46976 ------r- c:\windows\system32\drivers\mstart-2drv.sys
2010-11-15 06:34 . 2010-11-15 06:34 -------- d-----w- c:\documents and settings\Internet\Local Settings\Application Data\GHISLER
2010-11-14 21:33 . 2010-11-14 21:33 -------- d-----w- c:\program files\PrivacyEraser Computing
2010-11-14 21:21 . 2010-11-14 21:21 -------- d-----w- c:\documents and settings\FreddyX\Local Settings\Application Data\Mozilla
2010-11-14 21:17 . 2010-11-15 06:37 -------- d-sh--w- c:\documents and settings\Internet\IECompatCache
2010-11-14 21:13 . 2010-11-14 21:13 -------- d-----w- c:\documents and settings\Internet\Application Data\GHISLER
2010-11-14 21:06 . 2010-11-14 21:06 -------- d-----w- c:\documents and settings\Internet\Local Settings\Application Data\Mozilla
2010-11-14 21:01 . 2010-11-14 21:33 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2010-11-14 21:01 . 2010-08-01 14:01 -------- d-----w- c:\program files\MozillaFirefox
2010-11-14 20:51 . 2009-03-27 00:16 12672 ------w- c:\windows\system32\drivers\cpuz132_x32.sys
2010-11-14 20:51 . 2010-11-14 20:51 -------- d-----w- c:\program files\CPUID
2010-11-14 20:49 . 2010-11-14 20:49 -------- d-----w- c:\windows\system32\Adobe
2010-11-14 19:53 . 2010-07-28 20:26 -------- d-sh--w- c:\documents and settings\FreddyX\IECompatCache
2010-11-14 19:37 . 2010-11-14 19:38 -------- dc-h--w- c:\windows\ie8
2010-11-14 19:32 . 2010-07-29 18:46 -------- d-sh--w- c:\documents and settings\FreddyX\IETldCache
2010-11-14 19:30 . 2009-01-07 17:21 26144 ------w- c:\windows\system32\spupdsvc.exe
2010-11-14 19:27 . 2007-07-19 23:57 267112 ------w- c:\windows\system32\xactengine2_9.dll
2010-11-14 19:25 . 2010-11-14 19:25 -------- d-----w- c:\windows\Logs
2010-11-14 18:29 . 2010-11-14 18:29 -------- d-----w- c:\program files\VideoLAN
2010-11-14 18:11 . 2010-11-14 18:11 20898 ------w- c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2010-11-14 18:11 . 2010-11-14 18:11 164352 ------w- c:\windows\system32\SpoonUninstall.exe
2010-11-14 18:11 . 2010-11-14 18:11 -------- d-----w- c:\program files\Illustrate
2010-11-14 18:09 . 2010-11-14 18:09 503808 ------w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-18807651-n\msvcp71.dll
2010-11-14 18:09 . 2010-11-14 18:09 499712 ------w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-18807651-n\jmc.dll
2010-11-14 18:09 . 2010-11-14 18:09 348160 ------w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-18807651-n\msvcr71.dll
2010-11-14 18:09 . 2010-11-14 18:09 61440 ------w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-66482e0a-n\decora-sse.dll
2010-11-14 18:09 . 2010-11-14 18:09 12800 ------w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-66482e0a-n\decora-d3d.dll
2010-11-14 18:07 . 2010-11-14 18:07 -------- d-----w- c:\program files\SuperCopier2
2010-11-14 18:05 . 2010-11-14 18:05 -------- d-----w- c:\documents and settings\FreddyX\Application Data\Malwarebytes
2010-11-14 18:05 . 2010-11-14 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-14 18:05 . 2010-07-08 06:55 -------- d-----w- c:\program files\Malwarebytes
2010-11-14 18:00 . 2010-07-29 19:04 -------- d-----w- c:\program files\CCleaner
2010-11-14 17:55 . 2010-07-29 19:03 -------- d-----w- c:\program files\Notepad++
2010-11-14 17:55 . 2010-07-29 19:03 -------- d-----w- c:\documents and settings\FreddyX\Application Data\Notepad++
2010-11-14 17:54 . 2010-11-14 17:54 -------- d-----w- c:\program files\7-Zip
2010-11-14 17:32 . 2010-11-14 17:32 -------- d-----w- c:\windows\SxsCaPendDel
2010-11-14 17:30 . 2008-11-12 06:52 18984 ------w- c:\windows\system32\drivers\mrdd.sys
2010-11-14 17:21 . 2010-11-14 17:21 -------- d-----w- c:\program files\Unibrain
2010-11-14 17:14 . 2010-11-14 17:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-11-14 17:13 . 2010-11-14 17:15 -------- d-----w- c:\program files\NVIDIA Corporation
2010-11-14 17:13 . 2010-01-12 04:03 61440 ------w- c:\windows\system32\OpenCL.dll
2010-11-14 17:13 . 2010-01-12 04:03 4077672 ------w- c:\windows\system32\nvcuvenc.dll
2010-11-14 17:13 . 2010-01-12 04:03 2259560 ------w- c:\windows\system32\nvcuvid.dll
2010-11-14 17:13 . 2010-01-12 04:03 11632640 ------w- c:\windows\system32\nvcompiler.dll
2010-11-14 17:13 . 2010-01-12 04:03 2283526 ------w- c:\windows\system32\nvdata.bin
2010-11-14 17:13 . 2010-11-14 17:13 -------- d-----w- C:\NVIDIA
2010-11-14 16:57 . 2010-08-01 12:46 -------- d-----w- c:\documents and settings\FreddyX\Local Settings\Application Data\CutePDF Writer
2010-11-14 16:56 . 2006-12-10 19:31 87800 ------w- c:\windows\system32\cpwmon2k.dll
2010-11-14 16:56 . 2010-11-14 16:56 -------- d-----w- c:\program files\Acro Software
2010-11-14 16:56 . 2010-11-14 16:56 -------- d-----w- c:\program files\GPLGS
2010-11-14 16:54 . 2010-11-14 16:54 -------- d--h--w- c:\windows\PIF
2010-11-14 16:47 . 2010-11-14 16:47 -------- d-----w- c:\program files\ma-config.com
2010-11-14 16:47 . 2010-11-14 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2010-11-14 16:41 . 2010-11-14 16:41 -------- d-----w- c:\documents and settings\NetworkService\Menu Démarrer
2010-11-14 16:37 . 2010-05-04 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\UC.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\RAR.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\PKZIP.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\PKUNZIP.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\NOCLOSE.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\LHA.PIF
2010-11-14 02:53 . 2009-09-24 06:50 545 ------w- c:\windows\ARJ.PIF
2010-11-14 02:53 . 2010-11-14 16:48 -------- d-----w- C:\totalcmd
2010-11-14 02:53 . 2010-11-14 02:53 -------- d-----w- c:\documents and settings\FreddyX\Application Data\GHISLER
2010-11-14 00:14 . 2010-11-14 17:14 -------- d-----w- c:\program files\AGEIA Technologies
2010-11-14 00:13 . 2010-11-14 17:14 -------- d-----w- c:\windows\nview
2010-11-14 00:13 . 2010-01-12 04:03 592488 ------w- c:\windows\system32\nvudisp.exe
2010-11-14 00:13 . 2009-11-19 20:42 592488 ------w- c:\windows\system32\nvuninst.exe
2010-11-13 23:35 . 2010-11-13 23:35 -------- d-----w- c:\windows\system32\Lang
2010-11-13 22:19 . 2010-04-21 01:32 -------- d-----w- c:\windows\system32\NtmsData
2010-11-13 22:00 . 2010-11-13 22:00 -------- d-----w- c:\windows\ASUSInstAll
2010-11-13 21:57 . 2010-11-13 21:57 -------- dc----w- c:\windows\system32\DRVSTORE
2010-11-13 21:57 . 2010-11-13 21:57 -------- d-----w- c:\program files\Intel
2010-11-13 21:57 . 2009-08-18 12:44 53248 ------w- c:\windows\system32\CSVer.dll
2010-11-13 21:56 . 2010-11-13 21:56 -------- d-----w- C:\Intel
2010-11-13 21:54 . 2010-11-13 21:54 -------- d-----w- c:\program files\ASUS
2010-11-13 21:53 . 1998-10-29 23:45 306688 ------w- c:\windows\IsUninst.exe
2010-11-13 21:53 . 2007-12-28 15:22 10296 ------w- c:\windows\system32\drivers\ASUSHWIO.SYS
2010-11-13 21:45 . 2010-11-13 21:45 -------- d-----w- c:\program files\ITE
2010-11-13 21:45 . 2002-10-29 10:40 25111 ------w- c:\windows\remove.exe
2010-11-13 21:45 . 2002-03-30 09:06 65536 ------w- c:\windows\system32\ntport.dll
2010-11-13 21:45 . 2001-01-22 13:23 6080 ------w- c:\windows\system32\zntport.sys
2010-11-13 21:43 . 2010-07-29 19:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-11-13 21:42 . 2010-07-29 19:51 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2010-11-13 21:30 . 2008-04-13 10:45 26368 -c----w- c:\windows\system32\dllcache\usbstor.sys
2010-11-13 18:41 . 2010-06-22 18:18 15512 ----a-w- c:\documents and settings\FreddyX\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-11-03 14:44 . 2010-11-03 14:44 552 ------w- c:\windows\system32\d3d8caps.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-03 13:22 . 2010-11-03 12:47 86331 ------w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-11-03 12:47 . 2010-11-03 12:47 -------- d-----w- c:\program files\microsoft frontpage
2010-11-03 12:46 . 2010-11-03 12:46 -------- d-----w- c:\program files\Services en ligne
2010-11-03 12:44 . 2010-11-03 12:44 21892 ------w- c:\windows\system32\emptyregdb.dat
2010-07-29 20:17 . 2010-07-29 20:17 -------- d-----w- c:\documents and settings\Internet\Application Data\Apple Computer
2010-07-29 19:55 . 2010-07-29 19:55 -------- d-----w- c:\program files\Fichiers communs\Java
2010-07-29 19:54 . 2010-05-04 01:06 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-29 19:54 . 2010-07-29 19:54 -------- d-----w- c:\program files\OracleJava
2010-07-29 19:51 . 2010-07-29 19:51 -------- d-----w- c:\program files\Realtek
2010-07-29 19:39 . 2010-05-04 01:12 -------- d-----w- c:\program files\Trend Micro
2010-07-29 19:38 . 2010-07-29 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Trend Micro
2010-07-29 19:33 . 2010-07-29 19:39 59920 ----a-w- c:\windows\system32\drivers\tmactmon.sys
2010-07-29 19:33 . 2010-07-29 19:39 50704 ----a-w- c:\windows\system32\drivers\tmevtmgr.sys
2010-07-29 19:33 . 2010-07-29 19:38 158224 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-07-29 19:33 . 2010-07-29 19:33 89872 ----a-w- c:\windows\system32\drivers\tmtdi.sys
2010-07-29 19:13 . 2010-07-29 19:13 9800 ---ha-w- c:\windows\system32\mlfcache.dat
2010-07-29 19:13 . 2010-07-29 19:13 -------- d-----w- c:\documents and settings\FreddyX\Application Data\Apple Computer
2010-07-29 19:12 . 2010-07-29 19:12 -------- d-----w- c:\program files\Safari
2010-07-29 19:12 . 2010-07-29 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-29 19:12 . 2010-07-29 19:12 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-07-29 19:12 . 2010-07-29 19:12 -------- d-----w- c:\program files\Apple Software Update
2010-07-29 19:12 . 2010-07-29 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-07-29 18:50 . 2008-04-14 12:00 49024 ----a-w- c:\windows\system32\perfc00C.dat
2010-07-29 18:50 . 2008-04-14 12:00 368318 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-29 18:49 . 2010-07-29 18:49 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-07-29 18:49 . 2010-07-29 18:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-07-29 18:47 . 2010-07-29 18:47 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-07-29 17:06 . 2010-07-29 17:06 27840488 ----a-w- c:\program files\Fichiers communs\Wise Installation Wizard.7z
2010-07-29 17:05 . 2010-07-29 17:05 1452060 ----a-w- c:\program files\AGEIA Technologies.7z
2010-07-27 23:42 . 2010-07-27 23:42 -------- d-----w- c:\documents and settings\FreddyX\Application Data\vlc
2010-07-27 23:39 . 2010-07-23 17:54 -------- d-----w- c:\documents and settings\Internet\Application Data\vlc
2010-07-23 04:13 . 2010-07-23 04:13 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-18 00:13 . 2010-07-18 00:13 15512 ----a-w- c:\documents and settings\Internet\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-14 14:45 . 2010-07-14 14:45 61440 ----a-w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5250386e-n\decora-sse.dll
2010-07-14 14:45 . 2010-07-14 14:45 503808 ----a-w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2c07cbb6-n\msvcp71.dll
2010-07-14 14:45 . 2010-07-14 14:45 499712 ----a-w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2c07cbb6-n\jmc.dll
2010-07-14 14:45 . 2010-07-14 14:45 348160 ----a-w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2c07cbb6-n\msvcr71.dll
2010-07-14 14:45 . 2010-07-14 14:45 12800 ----a-w- c:\documents and settings\FreddyX\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-5250386e-n\decora-d3d.dll
2010-06-27 20:39 . 2010-06-27 20:39 388096 ----a-r- c:\documents and settings\FreddyX\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-22 18:46 . 2010-05-26 17:53 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-06-22 17:38 . 2010-06-22 17:38 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-06-22 17:30 . 2010-06-22 17:30 -------- d-----w- c:\program files\Fichiers communs\Control Panels
2010-06-22 17:28 . 2010-06-22 17:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ALM
2010-06-22 17:18 . 2010-06-22 17:18 -------- d-----w- c:\program files\QuickTime
2010-06-22 17:07 . 2010-06-22 17:07 -------- d-----w- c:\program files\Bonjour
2010-06-22 17:04 . 2010-06-22 17:04 -------- d-----w- c:\program files\Fichiers communs\Macrovision Shared
2010-06-14 14:31 . 2010-11-03 12:45 744448 ------w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-07 15:50 . 2010-06-07 15:50 -------- d-----w- c:\documents and settings\FreddyX\Application Data\Nero
2010-05-06 10:33 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 01:08 . 2010-05-04 01:08 339984 ----a-w- c:\windows\system32\drivers\TM_CFW.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2009-08-16 955392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2010-06-16 624056]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-01-26 1020248]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"=mstart-2int.cpl
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RAID Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\RAID Manager.lnk
backup=c:\windows\pss\RAID Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LGODDFU]
2010-04-12 23:57 557056 ----a-w- c:\program files\lg_fwupdate\fwupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-11 21:17 13666408 ------w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-11 21:17 110696 ------w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Fichiers communs\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
R0 ub1394;Unibrain 1394 Class Driver;c:\windows\system32\drivers\UB1394.sys [21/12/2004 13:48 115200]
R0 ubsbm;Unibrain 1394 SBM Driver;c:\windows\system32\drivers\UBSBM.sys [21/12/2004 13:51 12032]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [29/07/2010 21:37 36368]
R2 ubumapi;Unibrain 1394 FireAPI Driver;c:\windows\system32\drivers\UBUMAPI.sys [21/12/2004 13:49 29824]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [4/05/2010 3:08 339984]
R3 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [29/07/2010 21:39 50704]
R3 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [29/07/2010 21:39 497008]
R3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [29/07/2010 21:39 689416]
R3 ubohci;Unibrain 1394 OHCI Driver;c:\windows\system32\drivers\ubohci.sys [21/12/2004 13:46 72320]
R3 ubsbp2;Unibrain SBP2 Bus Driver;c:\windows\system32\drivers\ubsbp2.sys [21/12/2004 13:47 32768]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [29/07/2010 21:51 1684736]
S3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\system32\drivers\AVerBDA3x.sys [14/11/2010 19:59 1171456]
S3 ews88mt;EWS88 WDM Audio;c:\windows\system32\drivers\ews88wdm.sys [14/03/2007 2:04 95712]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [26/01/2010 18:45 243056]
S3 MIDUSB;Driver for Midistart-2;c:\windows\system32\drivers\mstart-2drv.sys [16/11/2010 16:58 46976]
.
Contenu du dossier 'Tâches planifiées'
2010-07-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Examen supplémentaire -------
.
IE: Ajouter au fichier PDF existant - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir en Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en Adobe PDF - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - e:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
FF - ProfilePath - c:\documents and settings\FreddyX\Application Data\Mozilla\Firefox\Profiles\i0tyd071.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\OracleJava\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\OracleJava\jre6\bin\new_plugin\npjp2.dll
FF - plugin: e:\program files\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
---- PARAMETRES FIREFOX ----
c:\program files\MozillaFirefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\MozillaFirefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\MozillaFirefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\MozillaFirefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\MozillaFirefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\MozillaFirefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\MozillaFirefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\MozillaFirefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\MozillaFirefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\MozillaFirefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-nwiz - nwiz.exe
**************************************************************************
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1016)
c:\windows\system32\mstart-2int.cpl
- - - - - - - > 'lsass.exe'(1080)
c:\windows\system32\mstart-2int.cpl
.
Heure de fin: 2010-08-01 16:09:14
ComboFix-quarantined-files.txt 2010-08-01 14:09
Avant-CF: 37.806.415.872 octets libres
Après-CF: 37.989.347.328 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 6DA981DEA8E25501F7EF7343CFFC3CD9
mbr a écrit :Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
\Driver\ACPI -> ACPI.sys @ 0xb7f7ecb8
\Driver\atapi -> atapi.sys @ 0xb7f10852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb7e2ebb0
PacketIndicateHandler -> NDIS.sys @ 0xb7e3ba21
SendHandler -> NDIS.sys @ 0xb7e1987b
user & kernel MBR OK
RootkitReveal a écrit :HKU\S-1-5-21-789336058-839522115-682003330-1003\Console 29/07/2010 20:43 0 bytes Security mismatch.
HKU\S-1-5-21-789336058-839522115-682003330-1003\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1002\Filename 16/11/2010 19:37 11 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-789336058-839522115-682003330-1003\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1002\Description 16/11/2010 19:37 25 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-789336058-839522115-682003330-1003\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1003\Filename 20/11/2010 19:56 11 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-789336058-839522115-682003330-1003\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1003\Description 20/11/2010 19:56 25 bytes Data mismatch between Windows API and raw hive data.
HKU\S-1-5-21-789336058-839522115-682003330-1003\Software\Adobe\MediaBrowser\MRU\illustrator\ApplicationPath 27/06/2010 22:50 91 bytes Data mismatch between Windows API and raw hive data.
HKLM\SECURITY\Policy\Secrets\SAC* 3/11/2010 15:04 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3/11/2010 15:04 0 bytes Key name contains embedded nulls (*)
md5 a écrit :FichSYS : Somme MD5 de fichiers système
------------------------------------------
OS: Microsoft Windows XP
SP: Service Pack 3
Architecture: 32Bits
------------------------------------------
C:\WINDOWS\explorer.exe=F2317622D29F9FF0F88AEECD5F60F0DD
C:\WINDOWS\System32\winlogon.exe=DD73D6B9F6B4CB630CF35B438B540174
C:\WINDOWS\System32\csrss.exe=E0E8A531CFCE1C2E5D79F683282C10C3
C:\WINDOWS\System32\svchost.exe=E4BDF223CD75478BF44567B4D5C2634D
C:\WINDOWS\System32\spoolsv.exe=460E4CE148BD07218DA0B6A3D31885A9
C:\WINDOWS\System32\lsass.exe=91E6024D6D4DCDECDB36C43ECF9BBECB
C:\WINDOWS\System32\services.exe=C3FB1D70CB88722267949694BA51759E
C:\WINDOWS\System32\smss.exe=48E430297DA757F5CC2793CCFACAD5E7
C:\WINDOWS\System32\alg.exe=5E9A6658A2A69AE7EB195113B7A2E7A9
C:\WINDOWS\System32\TCPSVCS.exe=50F22575C0FB5D85A9D41EF963610C32
C:\WINDOWS\System32\userinit.exe=E74DDB12188C2FF57A78624DBF7332FC
C:\WINDOWS\System32\USER.exe=480CF2ED3D2B2BDF45B287CD0DB16430
C:\WINDOWS\System32\ws2_32.dll=FB836F9E62D82904C983AD21296A5D9C
C:\WINDOWS\System32\spoolsv.exe=460E4CE148BD07218DA0B6A3D31885A9
C:\WINDOWS\System32\smss.exe=48E430297DA757F5CC2793CCFACAD5E7
C:\WINDOWS\System32\shutdown.exe=65123E22156BA77A62D7E128A671845E
C:\WINDOWS\System32\systray.exe=A58E0673FB15CDBB82851224A526A985
C:\WINDOWS\System32\user32.dll=E853F84D3CE2FAA2A802E33CF89AC023
C:\WINDOWS\System32\drivers\atapi.sys=9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\System32\drivers\ndis.sys=1DF7F42665C94B825322FAE71721130D
C:\WINDOWS\System32\drivers\beep.sys=DA1F27D85E0D1525F6621372E7B685E9
C:\WINDOWS\System32\drivers\pci.sys=043410877BDA580C528F45165F7125BC
C:\WINDOWS\System32\drivers\pciide.sys=F4BFDE7209C14A07AAA61E4D6AE69EAC
C:\WINDOWS\System32\drivers\pciidex.sys=52E60F29221D0D1AC16737E8DBF7C3E9
C:\WINDOWS\System32\drivers\USBSTOR.sys=A32426D9B14A089EAA1D922E0C5801A9
C:\WINDOWS\System32\drivers\ntfs.sys=78A08DD6A8D65E697C18E1DB01C5CDCA
C:\WINDOWS\System32\drivers\TCPIP.sys=9AEFA14BD6B182D61E3119FA5F436D3D
J'ai réinstallé la Suite Trend juste après le nettoyage et l'ordinateur a retrouvé sa jeunesse d'autre foisCSysFiles a écrit :===============================================
Rapport CSysFiles 2.0 [2] - 29/07/2010 à 20:29,15
Microsoft Windows XP - Mode Normal
Navigateur: Inconnu 3.6.6 (fr) [Navigateur par défaut]
Utilisateur: FreddyX - Administrateur
Option: Automatique + Script
Lancement: C:\CSysFiles\CSysFiles.exe
===============================================
¤¤¤¤ [Fichiers non signés] ¤¤¤¤
¤¤¤¤ [Fichiers indiqués dans le script] ¤¤¤¤
===============================================
Rapport CSysFiles 2.0 [1] - 29/07/2010 à 20:28,59
Microsoft Windows XP - Mode Normal
Navigateur: Inconnu 3.6.6 (fr) [Navigateur par défaut]
Utilisateur: FreddyX - Administrateur
Option: /!\ Aucune option choisie /!\
Lancement: C:\CSysFiles\CSysFiles.exe
===============================================
¤¤¤¤ [Fichiers non signés] ¤¤¤¤
** 0 Fichiers non signés **
Remarque: la présence de rootkit peut cacher un fichier patché
==========================
Fin du rapport - 20:28,59
==========================
** 0 Fichiers non signés **
Remarque: la présence de rootkit peut cacher un fichier patché
==========================
Fin du rapport - 20:29,15
==========================

Ma question est la suivante, il y a t'il un risque de fichiers patchés ou de restes ? Explorer.exe par exemple ...
D'avance merci, @ bientôt