Merci pour ton aide,
Voici le rapport
ComboFix 09-02-08.02 - Administrateur 2009-02-09 21:39:02.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2047.1586 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
FW: Kaspersky Internet Security *enabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\303372.exe
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekaxrlnypvb.sys
c:\windows\system32\lsprst7.dll
c:\windows\system32\senekabpspmspj.dll
c:\windows\system32\senekaeccxoypi.dll
c:\windows\system32\senekaqvsyfwxp.dll
c:\windows\system32\senekaviyurqrx.dat
c:\windows\system32\senekaxvrbfpym.dat
c:\windows\system32\ssprs.dll
c:\windows\system32\test.ttt
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
c:\windows\system32\winlogon2.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-09 au 2009-02-09 ))))))))))))))))))))))))))))))))))))
.
2009-02-06 14:59 . 2009-02-09 18:36 <REP> d-------- c:\program files\RAM Booster Expert
2009-02-05 13:41 . 2009-02-05 13:42 <REP> d-------- c:\program files\DVD Decrypter
2009-02-01 10:15 . 2009-02-01 10:15 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-01 10:15 . 2009-02-01 10:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-01 10:15 . 2009-02-01 10:15 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-02-01 10:15 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-01 10:15 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-01 10:06 . 2009-02-01 10:14 <REP> d-------- c:\program files\trend micro
2009-01-22 17:08 . 2009-01-15 08:19 206,793 --a------ c:\windows\system32\nvapps.nvb
2009-01-22 16:52 . 2009-01-26 10:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-01-15 08:19 . 2009-01-15 08:19 1,253,376 --a------ c:\windows\system32\NvPVEnc.ax
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 20:45 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-09 09:18 --------- d-----w c:\documents and settings\Administrateur\Application Data\uTorrent
2009-02-04 15:55 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-04 11:21 --------- d-----w c:\documents and settings\Administrateur\Application Data\Sony
2009-02-04 09:36 --------- d-----w c:\program files\BSplayer
2009-02-03 17:20 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 17:20 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-03 11:52 --------- d-----w c:\program files\Fichiers communs\Logitech
2009-01-31 19:09 --------- d-----w c:\program files\DU Meter
2009-01-30 18:49 778,784 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-30 18:49 56,587,808 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-30 18:49 325,772 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-30 18:49 3,310,368 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-30 16:17 --------- d-----w c:\documents and settings\Administrateur\Application Data\Classes de site
2009-01-26 09:26 --------- d-----w c:\program files\Electronic Arts
2009-01-22 17:53 --------- d-----w c:\documents and settings\Administrateur\Application Data\U3
2009-01-22 16:35 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-22 16:09 --------- d-----w c:\program files\AGEIA Technologies
2009-01-22 13:08 --------- d-----w c:\documents and settings\Administrateur\Application Data\dvdcss
2009-01-20 10:29 --------- d-----w c:\program files\Dictionnaire
2009-01-15 07:19 6,301,248 ----a-w c:\windows\system32\drivers\nv4_mini.sys
2009-01-05 22:38 --------- d-----w c:\program files\MPlayer-1.0rc2
2009-01-01 20:17 --------- d-----w c:\program files\Enigma Software Group
2008-12-20 18:19 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-16 20:40 --------- d-----w c:\documents and settings\All Users\Application Data\ALM
2008-12-16 20:32 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-16 19:01 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-16 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-16 11:53 --------- d-----w c:\program files\QuickTime
2008-12-16 11:40 --------- d-----w c:\program files\NFO viewer
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 17:48 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2008-12-10 17:45 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-10 16:19 --------- d-----w c:\program files\RegCleaner
2008-12-10 16:03 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-06 19:05 22,328 -c--a-w c:\documents and settings\Administrateur\Application Data\PnkBstrK.sys
2008-04-20 21:20 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2003-08-16 09:07 172,032 ----a-w c:\program files\poweroff.exe
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 --sh--r c:\windows\system32\nbDX.dll
2008-11-03 19:16 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008110320081104\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-04-19 3297280]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"RGSC"="e:\jeux\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-12-13 306088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2002-12-04 1194496]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024]
"MAFWTaskbarApp"="c:\windows\system32\MAFWTray.exe" [2005-09-20 155648]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-02-04 206088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-07 805392]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.CDVC"= cdvccodc.dll
"vidc.CDVH"= cdvhcodc.dll
"vidc.CUVC"= cuvccodc.dll
"vidc.CLLC"= cllccodc.dll
"vidc.CDV5"= cdv5codc.dll
"Midi1"= ma_cmidn.dll
"midi2"= ma_cmidn.dll
"midi3"= ma_cmidn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Jeux\\PES2008\\PES2008.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis Wars\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Jeux\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"e:\\Jeux\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"e:\\Jeux\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\FTP Expert 3\\ftpxpert3.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14748:TCP"= 14748:TCP:UT
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 tvtool;tvtool;c:\program files\TVTool\TVTOOL.SYS [1996-04-03 5248]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2007-11-30 38656]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-01-09 33792]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-04-04 24592]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Fichiers communs\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
S3 MAFW;MAFW;c:\windows\system32\DRIVERS\mafw.sys --> c:\windows\system32\DRIVERS\mafw.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e4044a-d035-11dc-8efb-001d605584b8}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{76ea7cf9-e96a-11dc-aad0-001d605584b8}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9df99dcf-0e29-11dd-be6e-001d605584b8}]
\Shell\AutoRun\command - J:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b117e769-9f6e-11dc-a321-c22007063c8c}]
\Shell\AutoRun\command - D:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b5833417-9f6c-11dc-a320-fe9654143a3e}]
\Shell\AutoRun\command - I:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c19cb8f7-767a-11dd-bfab-001d605584b8}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb2c26a5-a894-11dc-9a52-001d605584b8}]
\Shell\AutoRun\command - I:\LaunchU3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-02-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-01 c:\windows\Tasks\Crysis Wars(R) Updates.job
- c:\windows\Installer\Crysis Wars(R) Updates for All Users.lnk [2008-10-06 20:04]
2009-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1035525444-839522115-500.job
- c:\documents and settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-08 19:56]
.
.
------- Examen supplémentaire -------
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\gdh9q8qz.default\
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - plugin: c:\documents and settings\Administrateur\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\VLC\npvlc.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-09 21:45:45
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\Administrator\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:87,74,e3,b8,a0,6a,24,7f,a4,08,48,6f,f6,c2,0d,e7,e1,6e,27,b7,a6,1c,c2,
ff,76,1f,07,87,fb,5c,2f,c6,16,92,7e,68,3b,73,68,02,d9,b2,52,81,09,f7,a8,41,\
"??"=hex:de,76,16,ad,71,b8,9a,83,0d,cf,d8,7d,3c,29,57,9c
[HKEY_USERS\Administrator\Software\SecuROM\License information*]
"datasecu"=hex:10,1b,e7,f4,de,69,30,c6,b7,34,f1,b8,17,52,82,94,30,34,6f,09,a3,
09,c9,1f,66,c0,a8,e4,a1,69,b5,77,61,73,a4,8e,65,d6,c1,f6,0e,61,05,98,27,bc,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:8d,b7,bb,2e,9f,29,cd,c0,0a,1d,e1,64,7b,6c,d6,a7,ae,71,60,9c,56,
cc,64,db,58,41,cc,9b,7a,dd,c2,9a,56,33,f8,91,5f,15,a0,be,6d,4a,2d,5c,cc,da,\
[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{4E41A485-04D4-CF7C-6CE3-27F7BEAE7048}\Data*]
@DACL=
"CTE_32 Name"="45862:{C3B8A1BC-8B18-94D5-AD04-2B3354994626}"
[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{7F91A45B-6B5F-C2EA-301C-C31FD25A9C54}\Data*]
@DACL=
"Templates"="0:{5FD13A4A-FC54-8A9D-247A-7153B0B91418}"
[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"
[HKEY_LOCAL_MACHINE\software\Microsoft\DirectInput\Compatibility\CLIENT2._EXE35FEFABD00088200*]
@DACL=
"MaxDeviceNameLen"="46\[u]0/udÖa7¸0000Ì\13ª45b4Ñ"
"NoPollSucceed"="{C121B495-C1C5-315C-EDD3-107665B6F6F5}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2454817:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{974B9511-91D5-AEE4-5E77-0AF54DD3BA55}\Install*Loc\VxDs]
@DACL=
"Templates"="2454487:{E1E6CBBC-E7CA-AB6C-D7EB-63563C5B204D}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{8D6E5670-12F8-C05A-300B-6A981CBE8DBE}\Version 1.1]
@DACL=
"dat"="806585365:{1ADAEC8B-9551-9B89-2F08-D44747FCB86D}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"AB141C35E9F4BF344B9FC010BB17F68A"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{53C141BA-4F9E-43FB-B4F9-0C01BB716FA8}\\Registered"
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2454838:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{62148CCA-49D6-61B1-542F-6B093502D815}}]
@DACL=
"WinXP"="2048:{83CB76E3-95AF-3149-EB35-9E15F6375F54}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{155D1703-4264-3828-011A-07C57033D9E4}*\Install*Loc\xga-3\dat]
@DACL=
"default"="516233173:{3597DED8-26EE-97A6-CFC0-B96B09E9CFEF}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{8D6E5670-12F8-C05A-300B-6A981CBE8DBE}\Version 3.x]
@DACL=
"dat"="1767914624:{2DA97E47-4582-7218-9E23-04518AEABCC5}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smase._dll*]
@DACL=
"AplicationGoo"="46)#ba¾6055?álc10cÖ"
"ChkAppHelp"="{25C8E496-F307-53E5-49B6-13F83C3F53C6}"
[HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-3\ver]
@DACL=
"KnownSvcs"="923713834:{07536800-D050-2137-3A19-6EBD1F28FD26}"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:c9,28,28,34,da,e0,61,91,5b,9c,63,aa,45,ae,10,37,6f,78,3b,0a,58,
0e,18,b0,29,12,d0,3c,1b,11,d2,cf,f6,94,17,be,50,79,75,85,76,d8,e8,95,32,e0,\
[HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{8E701CA7-E9FC-37A6-DEC3-853D68FE11DA}\xga-3\Install*Loc]
@DACL=
"{19620715-0001-1211-574574-30001}"="234520830:{5F524439-4D32-5547-ECE7-922FDEC9FA73}"
[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="7:{19C42D30-D844-8A07-12A4-E783E7D228F7}"
[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{C0984C48-3A57-C216-0D35-7D09B0A0D97E}]
@DACL=
"Templates"="-4600:{7E0C5D36-BFDD-4B84-F80D-AAF2A0F840A6}"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1248)
c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logitech\bluetooth\LBTServ.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\savedump.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
.
**************************************************************************
.
Heure de fin: 2009-02-09 21:49:19 - La machine a redémarré [Administrateur]
ComboFix-quarantined-files.txt 2009-02-09 20:49:16
Avant-CF: 15,855,874,048 octets libres
Après-CF: 25,851,875,328 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn /usepmtimer
Current=6 Default=6 Failed=5 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
323 --- E O F --- 2009-01-15 10:32:15