Desole pour le retard ca a l'air de mieux fonctionner
ComboFix 08-12-29.02 - PC 2008-12-30 18:09:43.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.895.442 [GMT 1:00]
Lancé depuis: c:\documents and settings\PC\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\AutoRun.inf
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
----- BITS: Il y a peut-être des sites infectés -----
hxxp://i5i.in
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-28 au 2008-12-30 ))))))))))))))))))))))))))))))))))))
.
2008-12-30 17:36 . 2008-12-30 17:36 <REP> d-------- c:\program files\Trojan Remover
2008-12-30 17:36 . 2008-12-30 17:36 <REP> d-------- c:\documents and settings\PC\Application Data\Simply Super Software
2008-12-30 17:36 . 2008-12-30 17:36 <REP> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2008-12-30 17:36 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2008-12-30 17:36 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2008-12-30 17:36 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2008-12-30 17:36 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2008-12-30 17:36 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2008-12-29 20:21 . 2008-12-29 20:31 664 --a------ c:\windows\system32\d3d9caps.dat
2008-12-29 18:48 . 2008-12-30 18:02 <REP> d-------- c:\program files\a-squared Anti-Malware
2008-12-29 18:47 . 2008-12-29 18:47 <REP> d-------- c:\program files\Anti-Spy.Info
2008-12-29 18:47 . 2008-12-29 18:56 <REP> d-------- c:\documents and settings\All Users\Application Data\AntiSpyInfo
2008-12-29 18:22 . 2008-12-29 18:22 <REP> d-------- c:\documents and settings\PC\Application Data\s_5849_NTN8fHx8NTN8fHwxMjQzMTc1NzUwfA_
2008-12-29 18:09 . 2008-12-29 18:09 176,128 --a------ c:\windows\system32\xsl54261.dll
2008-12-29 18:09 . 2008-12-29 18:09 176,128 --a------ c:\windows\system32\sl54261.dll
2008-12-28 23:05 . 2008-12-29 00:21 <REP> d-------- c:\program files\a-squared Free
2008-12-28 22:15 . 2008-12-28 22:15 <REP> d-------- c:\program files\Lavasoft
2008-12-28 22:15 . 2008-12-28 22:15 <REP> d-------- c:\documents and settings\PC\Application Data\Lavasoft
2008-12-28 22:04 . 2008-12-28 22:04 <REP> d-------- c:\program files\Microsoft Silverlight
2008-12-28 20:36 . 2008-12-28 20:36 84,310 --a------ c:\windows\system32\nxuucxlkipugkt.dll-uninst.exe
2008-12-28 19:34 . 2008-12-28 19:34 <REP> d-------- c:\windows\system32\Kaspersky Lab
2008-12-28 17:02 . 2008-12-28 17:08 <REP> d-------- C:\backups
2008-12-25 23:32 . 2008-12-25 23:32 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-12-25 22:08 . 2008-12-25 22:08 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-25 22:08 . 2008-12-25 22:08 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2008-12-25 22:03 . 2008-12-25 22:06 <REP> d-------- c:\program files\Avanquest update
2008-12-25 22:03 . 2008-04-13 20:45 26,112 --a------ c:\windows\system32\drivers\usbser.sys
2008-12-25 22:03 . 2008-04-13 20:45 26,112 --a--c--- c:\windows\system32\dllcache\usbser.sys
2008-12-25 22:02 . 2008-12-25 22:13 <REP> d-------- c:\program files\Motorola Phone Tools
2008-12-25 22:02 . 2008-12-25 22:03 <REP> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2008-12-25 22:02 . 2008-12-25 22:02 92,064 --a------ c:\documents and settings\PC\mqdmmdm.sys
2008-12-25 22:02 . 2008-12-25 22:02 79,328 --a------ c:\documents and settings\PC\mqdmserd.sys
2008-12-25 22:02 . 2008-12-25 22:02 66,656 --a------ c:\documents and settings\PC\mqdmbus.sys
2008-12-25 22:02 . 2008-12-25 22:02 25,600 --a------ c:\documents and settings\PC\usbsermptxp.sys
2008-12-25 22:02 . 2008-12-25 22:02 22,768 --a------ c:\documents and settings\PC\usbsermpt.sys
2008-12-25 22:02 . 2008-12-25 22:02 9,232 --a------ c:\documents and settings\PC\mqdmmdfl.sys
2008-12-25 22:02 . 2008-12-25 22:02 6,208 --a------ c:\documents and settings\PC\mqdmcmnt.sys
2008-12-25 22:02 . 2008-12-25 22:02 5,936 --a------ c:\documents and settings\PC\mqdmwhnt.sys
2008-12-25 22:02 . 2008-12-25 22:02 4,048 --a------ c:\documents and settings\PC\mqdmcr.sys
2008-12-25 20:59 . 2008-12-25 20:59 <REP> d-------- c:\program files\Fichiers communs\Motorola Shared
2008-12-25 20:59 . 2008-12-29 19:42 <REP> d-------- c:\program files\Common Files
2008-12-25 20:59 . 2006-11-13 15:45 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-12-25 20:59 . 2007-06-18 15:18 23,680 --a------ c:\windows\system32\drivers\motmodem.sys
2008-12-14 11:09 . 2008-12-14 11:09 <REP> d-------- c:\program files\WinISO
2008-11-26 18:11 . 2008-11-26 18:12 <REP> d-------- c:\program files\iTunes
2008-11-26 18:11 . 2008-11-26 18:11 <REP> d-------- c:\program files\iPod
2008-11-26 18:11 . 2008-11-26 18:12 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-26 18:09 . 2008-11-26 18:10 <REP> d-------- c:\program files\QuickTime
2008-11-23 23:14 . 2008-11-24 00:10 <REP> d-------- C:\f
2008-11-23 23:10 . 2008-11-23 23:10 <REP> d-------- c:\program files\AusLogics Disk Defrag
2008-11-14 08:54 . 2008-11-14 08:54 296,448 --a------ c:\windows\system32\lpubhmqvdsam.dll
2008-11-12 18:59 . 2007-06-28 14:36 401,720 --------- C:\HijackThis.exe
2008-11-11 21:13 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 21:12 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:36 . 2008-11-11 21:37 <REP> d-------- c:\program files\Cacheman
2008-11-06 18:40 . 2008-06-25 20:06 160,283 --------- c:\windows\hpoins14.dat.temp
2008-11-06 18:40 . 2007-09-20 02:14 2,000 --------- c:\windows\hpomdl14.dat.temp
2008-11-04 10:30 . 2008-11-04 10:30 90,112 --a------ c:\windows\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 --a------ c:\windows\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 17:04 --------- d-----w c:\documents and settings\PC\Application Data\Free Download Manager
2008-12-30 16:50 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-30 16:41 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-29 23:13 --------- d-----w c:\program files\HOTALBUMMyBOX
2008-12-29 22:41 --------- d-----w c:\program files\CCleaner
2008-12-29 17:26 --------- d-----w c:\program files\SpywareGuard
2008-12-29 16:24 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-28 21:23 --------- d-----w c:\program files\Free Download Manager
2008-12-25 21:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 18:35 --------- d-----w c:\program files\VirtualDJ
2008-12-11 18:11 --------- d-----w c:\program files\TuneUp Utilities 2008
2008-12-10 22:30 --------- d-----w c:\program files\IncrediMail
2008-12-06 12:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-03 18:54 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:54 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-11-26 17:11 --------- d-----w c:\program files\Fichiers communs\Apple
2008-11-22 20:28 --------- d-----w c:\program files\adslTV
2008-11-20 22:30 --------- d-----w c:\program files\Copernic Agent
2008-11-20 22:29 --------- d-----w c:\documents and settings\PC\Application Data\Copernic
2008-11-14 17:22 --------- d-----w c:\documents and settings\PC\Application Data\OpenOffice.org2
2008-11-11 20:39 --------- d-----w c:\program files\free-downloads.net
2008-11-10 16:40 --------- d-----w c:\program files\DivX
2008-11-06 17:23 --------- d-----w c:\program files\HP
2008-11-01 10:56 --------- d-----w c:\program files\GénéaTique
2008-10-28 07:50 --------- d-----w c:\program files\Dactylo
2008-01-06 17:53 56 --sh--r c:\windows\system32\9B1A429404.sys
2008-01-06 17:53 12,518 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-06-05 19:24 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008060520080606\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"PhotoJoy"="c:\program files\PhotoJoy\bin\PhotoJoy.exe" [2008-09-22 918840]
"Cacheman"="c:\progra~1\Cacheman\Cacheman.exe" [2003-07-31 1290752]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2008-12-29 2782352]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-27 185896]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2008-12-10 1230728]
"RTHDCPL"="RTHDCPL.EXE" [2008-03-26 c:\windows\RTHDCPL.exe]
c:\documents and settings\PC\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]
UberIcon.lnk - c:\windows\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 180224]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D-Link AirPlus G+ Wireless Utility.lnk - c:\d-link\AirPlusG+\AirPlus.exe [2007-08-29 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^PC^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\PC\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^PC^Menu Démarrer^Programmes^Démarrage^TransBar.lnk]
path=c:\documents and settings\PC\Menu Démarrer\Programmes\Démarrage\TransBar.lnk
backup=c:\windows\pss\TransBar.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^PC^Menu Démarrer^Programmes^Démarrage^Y'z Shadow.lnk]
path=c:\documents and settings\PC\Menu Démarrer\Programmes\Démarrage\Y'z Shadow.lnk
backup=c:\windows\pss\Y'z Shadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--------- 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
--------- 2006-08-16 15:56 339968 c:\program files\AGEIA Technologies\TrayIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]
--------- 2008-05-20 16:27 2474031 c:\program files\Free Download Manager\fdm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--------- 2007-09-20 07:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--------- 2007-03-01 13:57 153136 c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-r-hs---- 2008-01-28 10:43 2097488 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"UVS10 Preload"=c:\program files\Ulead Systems\Ulead Movie Wizard 3.2 SE VCD\uvPL.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\PhotoJoy\\Bin\\PjApp.exe"=
"c:\\Program Files\\PhotoJoy\\Bin\\PjImp.exe"=
"c:\\Program Files\\PhotoJoy\\Bin\\PhotoJoy.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 PzWDM;PzWDM;c:\windows\system32\Drivers\PzWDM.sys [2007-11-05 15172]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\DRIVERS\A3AB.sys [2005-03-22 547744]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2008-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-30 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 08:23]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mystart.incredimail.com/french/
uSearch Page =
uSearch Bar =
uInternet Settings,ProxyOverride = *.local
mSearchAssistant =
IE: Convertir les liens sélectionnés en fichier Adobe PDF
c:\windows\Downloaded Program Files\ewidoOnlineScan.dll - O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1}
hxxp://downloads.ewido.net/ewidoOnlineScan.cab
FF - ProfilePath - c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\86u4rzsh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - MyStart Rechercher
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - component: c:\documents and settings\PC\Application Data\Mozilla\Firefox\Profiles\86u4rzsh.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}\components\FFAlert.dll
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npalnn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
[color=red]ATTENTION: FIREFOX POLICES IS IN FORCE /color
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDA9FC132B-096D-460B-B7D5-1DB0FAE0C062", "AllAccess");
.
.
------- Associations de fichier -------
.
scrfile="%1" %*
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 18:12:46
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\IncrediMail\bin\ImApp.exe
c:\program files\a-squared Anti-Malware\a2service.exe
c:\program files\PhotoJoy\Bin\PjApp.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-12-30 18:18:34 - La machine a redémarré [PC]
ComboFix-quarantined-files.txt 2008-12-30 17:18:32
Avant-CF: 42,403,946,496 octets libres
Après-CF: 42,860,265,472 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
303 --- E O F --- 2008-12-29 16:21:21