PAR CONTRE 1 NOUVEAU COMBIFIX VOICI LE RAPPORT
ComboFix 09-02-15.01 - utilisateur 2009-02-16 21:27:59.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.674 [GMT 1:00]
Lancé depuis: c:\documents and settings\utilisateur.6876B149DC4149A\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\utilisateur.6876B149DC4149A\Bureau\CFscript
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated)
FW: Bitdefender Firewall *enabled*
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
c:\windows\Fonts\BB35673A.DLL
c:\windows\system32\drivers\Connexion secondaire seclogonTermService.sys
c:\windows\system32\drivers\Ebb30.sys
c:\windows\system32\drivers\Txb82.sys
c:\windows\system32\drivers\Uyc03.sys
c:\windows\system32\drivers\Vyc60.sys
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Fonts\BB35673A.DLL
c:\windows\system32\dllcache\http.sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-16 au 2009-02-16 ))))))))))))))))))))))))))))))))))))
.
2009-02-16 21:10 . 2008-04-14 03:33 116,736 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2009-02-16 21:10 . 2001-08-23 17:47 99,865 --a--c--- c:\windows\system32\dllcache\xlog.exe
2009-02-16 21:10 . 2004-08-05 13:00 28,288 --a--c--- c:\windows\system32\dllcache\OLDA72.tmp
2009-02-16 21:10 . 2001-08-23 17:47 27,648 --a--c--- c:\windows\system32\dllcache\xrxftplt.exe
2009-02-16 21:10 . 2001-08-23 17:47 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-02-16 21:10 . 2008-04-14 03:33 18,944 --a--c--- c:\windows\system32\dllcache\xrxscnui.dll
2009-02-16 21:10 . 2001-08-23 17:47 4,608 --a--c--- c:\windows\system32\dllcache\xrxflnch.exe
2009-02-16 21:09 . 2004-08-03 21:29 19,455 --a--c--- c:\windows\system32\dllcache\wvchntxx.sys
2009-02-16 21:09 . 2001-08-17 20:11 16,970 --a--c--- c:\windows\system32\dllcache\xem336n5.sys
2009-02-16 21:09 . 2004-08-03 21:29 12,063 --a--c--- c:\windows\system32\dllcache\wsiintxx.sys
2009-02-16 21:09 . 2008-04-14 03:33 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2009-02-16 21:08 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\OLDA61.tmp
2009-02-16 21:08 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\OLDA5E.tmp
2009-02-16 21:08 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\OLDA5B.tmp
2009-02-16 21:08 . 2004-08-03 21:31 154,624 --a--c--- c:\windows\system32\dllcache\wlluc48.sys
2009-02-16 21:08 . 2008-04-14 03:32 72,704 --a--c--- c:\windows\system32\dllcache\OLDA55.tmp
2009-02-16 21:08 . 2008-04-14 03:33 65,536 --a--c--- c:\windows\system32\dllcache\OLDA58.tmp
2009-02-16 21:08 . 2001-08-23 17:05 35,402 --a--c--- c:\windows\system32\dllcache\wlandrv2.sys
2009-02-16 21:08 . 2008-04-13 19:36 8,832 --a--c--- c:\windows\system32\dllcache\wmiacpi.sys
2009-02-16 21:06 . 2001-08-17 21:28 765,884 --a--c--- c:\windows\system32\dllcache\usrti.sys
2009-02-16 21:05 . 2001-08-17 21:28 794,654 --a--c--- c:\windows\system32\dllcache\usr1801.sys
2009-02-16 21:04 . 2001-08-23 17:47 525,568 --a--c--- c:\windows\system32\dllcache\tridxp.dll
2009-02-16 21:03 . 2008-04-14 03:33 571,392 --a--c--- c:\windows\system32\dllcache\OLD9B3.tmp
2009-02-16 21:02 . 2001-08-23 16:57 286,848 --a--c--- c:\windows\system32\dllcache\stlnata.sys
2009-02-16 21:01 . 2004-08-05 13:00 143,422 --a--c--- c:\windows\system32\dllcache\OLD959.tmp
2009-02-16 21:00 . 2001-08-23 17:47 238,592 --a--c--- c:\windows\system32\dllcache\sisgrv.dll
2009-02-16 20:59 . 2001-08-23 17:46 386,560 --a--c--- c:\windows\system32\dllcache\sgiul50.dll
2009-02-16 20:58 . 2001-08-23 17:47 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2009-02-16 20:57 . 2001-08-23 17:18 899,914 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-02-16 20:56 . 2008-04-14 03:33 482,304 --a--c--- c:\windows\system32\dllcache\OLD824.tmp
2009-02-16 20:55 . 2008-04-14 03:32 259,328 --a--c--- c:\windows\system32\dllcache\perm3dd.dll
2009-02-16 20:54 . 2001-08-17 22:05 351,616 --a--c--- c:\windows\system32\dllcache\ovcodek2.sys
2009-02-16 20:53 . 2008-08-14 14:23 2,025,984 --a--c--- c:\windows\system32\dllcache\OLD7BC.tmp
2009-02-16 20:52 . 2004-08-05 13:00 1,875,968 --a--c--- c:\windows\system32\dllcache\OLD774.tmp
2009-02-16 20:51 . 2001-08-23 17:03 320,384 --a--c--- c:\windows\system32\dllcache\mgaum.sys
2009-02-16 20:50 . 2004-08-05 13:00 1,158,818 --a--c--- c:\windows\system32\dllcache\OLD712.tmp
2009-02-16 20:49 . 2004-08-05 13:00 471,102 --a--c--- c:\windows\system32\dllcache\OLD67A.tmp
2009-02-16 20:48 . 2008-04-14 03:31 811,064 --a--c--- c:\windows\system32\dllcache\OLD64A.tmp
2009-02-16 20:47 . 2008-04-14 03:31 13,463,552 --a--c--- c:\windows\system32\dllcache\OLD604.tmp
2009-02-16 20:46 . 2001-08-23 17:19 908,000 --a--c--- c:\windows\system32\dllcache\hcf_msft.sys
2009-02-16 20:45 . 2001-08-23 17:46 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-02-16 20:44 . 2001-08-23 17:16 630,016 --a--c--- c:\windows\system32\dllcache\eqn.sys
2009-02-16 20:43 . 2001-08-17 20:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-02-16 20:42 . 2001-08-23 17:47 422,429 --a--c--- c:\windows\system32\dllcache\dgconfig.dll
2009-02-16 20:41 . 2004-08-05 13:00 1,677,824 --a--c--- c:\windows\system32\dllcache\OLD413.tmp
2009-02-16 20:40 . 2001-08-17 21:28 871,388 --a--c--- c:\windows\system32\dllcache\OLD2DF.tmp
2009-02-16 20:39 . 2001-08-17 21:28 762,780 --a--c--- c:\windows\system32\dllcache\OLD1BA.tmp
2009-02-16 20:38 . 2008-08-14 14:23 2,147,328 --a--c--- c:\windows\system32\dllcache\OLD1A6.tmp
2009-02-16 20:37 . 2008-08-14 14:23 2,147,328 --a--c--- c:\windows\system32\dllcache\OLD10E.tmp
2009-02-16 20:36 . 2009-02-16 21:10 <REP> d-------- c:\windows\LastGood
2009-02-16 20:36 . 2008-04-14 03:33 20,540 --a--c--- c:\windows\system32\dllcache\OLDD5.tmp
2009-02-16 20:36 . 2008-04-14 03:33 20,540 --a--c--- c:\windows\system32\dllcache\OLDCF.tmp
2009-02-16 20:36 . 2008-04-14 03:33 16,439 --a--c--- c:\windows\system32\dllcache\OLDD2.tmp
2009-02-16 17:42 . 2009-02-16 17:42 <REP> d-------- c:\program files\Microsoft LifeCam
2009-02-16 15:27 . 2001-08-23 17:46 19,456 --a--c--- c:\windows\system32\dllcache\brbidiif.dll
2009-02-16 15:27 . 2001-08-23 17:46 9,728 --a--c--- c:\windows\system32\dllcache\brcoinst.dll
2009-02-16 14:20 . 2001-08-17 22:07 55,168 --a--c--- c:\windows\system32\dllcache\aic78u2.sys
2009-02-16 14:20 . 2001-08-23 17:47 24,576 --a--c--- c:\windows\system32\dllcache\agcgauge.ax
2009-02-16 14:20 . 2001-08-17 21:52 12,800 --a--c--- c:\windows\system32\dllcache\aha154x.sys
2009-02-16 14:09 . 2001-08-23 17:46 66,048 --a--c--- c:\windows\system32\dllcache\s3legacy.dll
2009-02-15 22:15 . 2009-02-15 22:15 <REP> d-------- c:\program files\Microsoft Silverlight
2009-02-15 16:08 . 2009-02-15 19:30 1,374 --a------ c:\windows\imsins.BAK
2009-02-13 21:57 . 2009-02-13 21:57 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 21:57 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 21:57 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-08 21:07 . 2009-02-08 21:07 <REP> d-------- c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Malwarebytes
2009-02-08 21:07 . 2009-02-08 21:07 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-02-08 17:52 . 2009-02-08 17:52 <REP> d-------- c:\program files\Trend Micro
2009-02-07 15:04 . 2009-02-07 15:04 <REP> d-------- c:\program files\Microsoft.NET
2009-02-07 14:48 . 2009-02-07 14:48 <REP> d-------- c:\program files\BitDefender
2009-02-07 14:48 . 2009-02-07 14:48 <REP> d-------- c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Bitdefender
2009-02-07 14:48 . 2009-02-07 14:50 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2009-02-07 14:47 . 2009-02-07 14:48 <REP> d-------- c:\program files\Fichiers communs\BitDefender
2009-02-01 10:43 . 2009-02-01 10:43 <REP> d-------- c:\program files\BarreConfCMCIC
2009-02-01 10:43 . 2009-02-01 10:43 <REP> d-------- c:\documents and settings\UTILIS~1~687\LOCALS~1
2009-02-01 10:43 . 2009-02-01 10:43 <REP> d-------- c:\documents and settings\UTILIS~1~687
2009-01-24 17:07 . 2009-01-24 17:07 <REP> d-------- c:\program files\Securitoo
2009-01-24 17:07 . 2009-01-24 17:07 <REP> d-------- c:\program files\SAGEM
2009-01-24 17:07 . 2009-01-24 17:07 <REP> d-------- c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\InstallShield
2009-01-24 16:33 . 2009-01-24 16:33 <REP> d-------- c:\program files\Fichiers communs\France Telecom
2009-01-24 16:33 . 2007-09-25 19:31 65,536 --a------ c:\windows\system32\Autodial2000.dll
2009-01-24 16:33 . 2003-09-23 11:38 34,688 --a------ c:\windows\system32\pcampr5.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 20:30 81,984 ----a-w c:\windows\system32\bdod.bin
2009-02-16 12:02 --------- d-----w c:\program files\eMule
2009-02-16 10:04 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-02-15 08:18 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\GamesBar
2009-02-07 14:04 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-02-07 13:34 --------- d-----w c:\program files\Common Files
2009-01-25 12:30 --------- d-----w c:\program files\CCleaner
2009-01-24 16:14 --------- d-----w c:\program files\Orange
2009-01-24 16:07 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-24 15:33 --------- d-----w c:\program files\Wanadoo
2009-01-24 11:20 --------- d-----w c:\program files\EA GAMES
2009-01-23 16:28 --------- d-----w c:\program files\Google
2008-12-24 10:58 --------- d-----w c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Media Player
2008-12-23 19:26 --------- d-----w c:\program files\Microsoft AutoRoute
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2007-07-29 08:40 144 ---ha-w c:\documents and settings\jean-claude\Application Data\wklnhst.dat
2007-04-07 19:39 66 ----a-w c:\documents and settings\manu\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-06 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-04 368640]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 7700480]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\documents and settings\jean-claude\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 61440]
[COLOR=RED] Les clés de Registre SafeBoot doivent être réparées. Cette machine ne peut pas utiliser le Mode Sans Échec. /COLOR
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^utilisateur.6876B149DC4149A^Menu Démarrer^Programmes^Démarrage^OneNote 2007 - Capture d'écran et lancement.lnk]
path=c:\documents and settings\utilisateur.6876B149DC4149A\Menu Démarrer\Programmes\Démarrage\OneNote 2007 - Capture d'écran et lancement.lnk
backup=c:\windows\pss\OneNote 2007 - Capture d'écran et lancement.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-12-23 18:05 143360 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDefender Antiphishing Helper]
--a------ 2007-10-09 15:46 61440 c:\program files\BitDefender\BitDefender 2008\IEShow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
--------- 2005-05-17 17:42 933888 c:\program files\Brother\ControlCenter2\brctrcen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
--a------ 2005-03-17 18:30 40960 c:\program files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
--a------ 2008-08-04 16:22 160800 c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2006-06-26 08:46 497200 c:\program files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
--a------ 2009-02-11 10:19 399504 c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mon Widget RMC]
--a------ 2008-10-13 11:59 185872 c:\program files\Nosibay\Mon Widget RMC\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-04-19 13:26 7700480 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-04-19 13:26 86016 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSSessionManager]
--a------ 2007-09-25 19:10 102400 c:\program files\Orange\SessionManager\SessionManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
--a------ 2005-03-17 18:17 57393 c:\program files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
--------- 2005-01-26 18:02 49152 c:\program files\Brother\Brmfl05a\BrStDvPt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
--a------ 2003-07-30 09:08 143360 c:\program files\Analog Devices\SoundMAX\SMTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperCopier2.exe]
--a------ 2006-07-07 17:45 1052672 c:\program files\SuperCopier2\SuperCopier2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-08-06 22:37 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystrayORAHSS]
--a------ 2007-09-25 20:08 94208 c:\program files\Orange\Systray\SystrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-04-19 13:26 1626112 c:\windows\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\EA GAMES\\MOHDA\\moh_Breakthrough.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\Program Files\\EA GAMES\\MOHDA\\MOHAA.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\EA GAMES\\MOHDA\\moh_spearhead.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\MOHDA\\fpupdate.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [2008-01-23 51840]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [2008-01-23 44928]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-06-02 86792]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [2008-09-06 33808]
R3 ULI5261;ULi Based Ethernet NT Driver;c:\windows\system32\drivers\ULILAN.SYS [2008-01-23 28160]
S0 Ebb30;Ebb30; [x]
S0 Txb82;Txb82; [x]
S0 Uyc03;Uyc03; [x]
S0 Vyc60;Vyc60; [x]
S2 seclogonTermService;Connexion secondaire seclogonTermService; [x]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-15 33752]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - 77FD3F81
*NewlyCreated* - ACABE017
*Deregistered* - 77fd3f81
*Deregistered* - acabe017
*Deregistered* - D39905C
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Tâches planifiées'
2009-02-16 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {9226EC1F-5FA1-4DE3-8644-6CA9342A0F43} = 192.168.1.1
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Mozilla\Firefox\Profiles\v3yb5j50.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
FF - component: c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Mozilla\Firefox\Profiles\v3yb5j50.default\extensions\glasser@sixxgate.com\components\dwmxpcom.dll
FF - plugin: c:\documents and settings\utilisateur.6876B149DC4149A\Application Data\Mozilla\Firefox\Profiles\v3yb5j50.default\extensions\OberonGameHost@OberonGames.com\platform\WINNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-16 21:30:48
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1004336348-2000478354-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Heure de fin: 2009-02-16 21:35:09
ComboFix-quarantined-files.txt 2009-02-16 20:35:07
Avant-CF: 56 081 272 832 octets libres
Après-CF: 56,166,039,552 octets libres
296 --- E O F --- 2009-02-12 02:02:56