Apres execution des insstructions; voici le rapport combofix
ComboFix 09-03-01.01 - Administrateur 2009-03-03 11:36:24.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1014.439 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFscript.txt
* Un nouveau point de restauration a été créé
FILE ::
c:\i6g6x.cmd
c:\progra~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\olhrwef.exe
c:\windows\temp\sig2d.tmp
c:\windows\temp\sig3.tmp
F:\2fiji.com
F:\2u.com
F:\i6g6x.cmd
F:\iq.bat
F:\lky.exe
F:\m9ma.exe
F:\RECYCLER
f:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\ine32.exe
f:\recycler\S-1-6-21-2434476501-1644491937-600003330-1213\USB-Helper.exe
F:\u2.cmd
F:\usdeiect.com
F:\ve.exe
F:\zPharaoh.exe
H:\taipingtianguov1.1.exe
M:\usdeiect.com
O:\zPharaoh.exe
Q:\usdeiect.com
T:\usdeiect.com
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-03 au 2009-03-03 ))))))))))))))))))))))))))))))))))))
.
2009-03-02 14:48 . 2009-03-02 14:48 <REP> d-------- c:\program files\trend micro
2009-03-02 12:45 . 2009-03-02 12:45 <REP> d-------- c:\program files\Prevx
2009-03-02 12:45 . 2009-03-02 12:45 22,536 --a------ c:\windows\system32\drivers\pxscan.sys
2009-03-02 12:37 . 2009-03-02 13:42 <REP> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-02-27 21:13 . 2009-02-27 21:13 54,156 --ah----- c:\windows\QTFont.qfn
2009-02-27 21:13 . 2009-02-27 21:13 1,409 --a------ c:\windows\QTFont.for
2009-02-27 21:08 . 2009-02-27 21:11 <REP> d-------- c:\documents and settings\Administrateur\Application Data\ArcSoft
2009-02-27 21:03 . 2004-08-03 22:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-02-27 21:01 . 2009-02-27 21:01 <REP> d-------- c:\documents and settings\All Users\Application Data\SSScanWizard
2009-02-27 21:01 . 2009-02-28 14:39 <REP> d-------- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-02-27 21:01 . 2009-02-27 21:01 <REP> d-------- c:\documents and settings\Administrateur\Application Data\ScanSoft
2009-02-27 21:00 . 2009-02-27 21:00 <REP> d-------- c:\program files\ScanSoft
2009-02-27 21:00 . 2009-02-27 21:01 <REP> d-------- c:\program files\Fichiers communs\ScanSoft Shared
2009-02-27 21:00 . 2009-02-27 21:00 525 --a------ c:\windows\MAXLINK.INI
2009-02-27 20:58 . 2009-02-28 14:40 <REP> d-------- c:\program files\ArcSoft
2009-02-27 20:58 . 1996-07-01 00:00 77,312 --a------ c:\windows\system32\TWAIN_32.DLL
2009-02-27 20:55 . 2009-02-27 20:55 <REP> d--h----- C:\CanoScan
2009-02-27 20:55 . 2002-05-24 03:04 389,180 --a------ c:\windows\system32\UCS32P.DLL
2009-02-27 20:55 . 2002-04-12 20:17 339,968 --a------ c:\windows\system32\N067UFW.DLL
2009-02-27 20:55 . 2002-09-27 14:56 69,632 --a------ c:\windows\system32\CNQU70.DLL
2009-02-26 20:50 . 2009-02-26 20:50 <REP> d-------- c:\program files\Business-in-a-Box
2009-02-07 20:51 . 2009-02-09 22:39 <REP> d-------- c:\documents and settings\Administrateur\Application Data\LimeWire
2009-02-05 13:39 . 2009-02-05 13:39 <REP> d--h----- c:\windows\PIF
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-03 10:33 --------- d-----w c:\documents and settings\Administrateur\Application Data\DNA
2009-03-03 10:32 --------- d-----w c:\program files\WeFi
2009-03-03 08:03 --------- d-----w c:\program files\DNA
2009-03-02 14:15 --------- d-----w c:\program files\MSN Messenger
2009-03-02 12:29 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-01 08:31 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 21:35 --------- d-----w c:\program files\LimeWire
2009-02-07 06:59 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-01 19:53 --------- d-----w c:\program files\Hotspot_Shield
2009-02-01 18:48 --------- d-----w c:\program files\Camfrog
2009-01-29 10:19 --------- d-----w c:\documents and settings\All Users\Application Data\Autodesk
2009-01-29 09:01 --------- d-----w c:\documents and settings\Administrateur\Application Data\Autodesk
2009-01-28 09:30 --------- d-----w c:\program files\IVT Corporation
2009-01-26 16:00 --------- d-----w c:\program files\ma-config.com
2009-01-26 16:00 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-01-25 23:27 --------- d-----w c:\program files\Micro Application
2009-01-22 21:25 --------- d-----w c:\program files\UltraMixer
2009-01-22 20:35 --------- d-----w c:\program files\DJ Mix Lite
2009-01-22 20:26 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-22 20:18 --------- d-----w c:\program files\Mightsoft
2009-01-22 09:25 --------- d-----w c:\program files\Microcal
2009-01-17 18:55 --------- d-----w c:\documents and settings\Administrateur\Application Data\TransRender
2009-01-17 18:55 --------- d-----w c:\documents and settings\Administrateur\Application Data\Temporary
2009-01-17 18:55 --------- d-----w c:\documents and settings\Administrateur\Application Data\Samsung
2009-01-17 18:55 --------- d-----w c:\documents and settings\Administrateur\Application Data\ConvertTemp
2009-01-17 18:52 --------- d-----w c:\program files\Samsung
2009-01-15 23:14 --------- d-----w c:\program files\Vuze
2009-01-15 23:13 --------- d-----w c:\documents and settings\Administrateur\Application Data\Azureus
2009-01-11 00:57 --------- d-----w c:\program files\Playboy - The Mansion
2009-01-10 19:03 --------- d-----w c:\documents and settings\All Users\Application Data\34203
2009-01-10 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\2CC1
2009-01-09 22:07 --------- d-----w c:\documents and settings\Administrateur\Application Data\uTorrent
2009-01-09 22:07 --------- d-----w c:\documents and settings\Administrateur\Application Data\BitTorrent
2009-01-09 19:01 --------- d-----w c:\documents and settings\All Users\Application Data\27271
2009-01-08 19:50 11,973 ----a-w c:\windows\system32\drivers\SECDRV.SYS
2009-01-08 19:37 --------- d-----w c:\documents and settings\All Users\Application Data\C2BF
2009-01-08 19:36 --------- d-----w c:\program files\Ubisoft
2009-01-08 19:20 --------- d-----w c:\documents and settings\All Users\Application Data\220
2009-01-06 18:58 --------- d-----w c:\documents and settings\All Users\Application Data\37186
2008-12-27 22:27 132 ----a-w C:\Delapp.bat
2008-12-04 08:31 53,248 ----a-w c:\windows\system32\CSVer.dll
.
------- Sigcheck -------
2007-06-26 21:18 360576 c7be59b07c6eb74bea6fd67c1b164015 c:\windows\system32\drivers\tcpip.sys
2004-08-04 05:54 1227264 e28d16a8d63eca6246921fdf7cbde42a c:\windows\explorer.exe
2004-08-04 05:54 1227264 e28d16a8d63eca6246921fdf7cbde42a c:\windows\icon_TMP\explorer.exe
2004-08-04 05:54 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa c:\windows\system_backup\explorer.exe
2007-06-14 15:31 80216 c7bcea1533be5c9e15884d6c39b667f1 c:\windows\icon_TMP\wuauclt.exe
2007-06-14 15:31 80216 c7bcea1533be5c9e15884d6c39b667f1 c:\windows\system32\wuauclt.exe
2007-06-14 15:31 53080 3a83a45e7dd5276315aa20245e7c32bf c:\windows\system_backup\wuauclt.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-02_15.56.36.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 04:52:58 3,584 ----a-w c:\windows\system32\dllcache\dpnaddr.dll
- 2009-03-02 10:03:11 64,894 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-03 08:07:51 65,794 ----a-w c:\windows\system32\perfc009.dat
- 2009-03-02 10:03:11 78,832 ----a-w c:\windows\system32\perfc00C.dat
+ 2009-03-03 08:07:51 80,004 ----a-w c:\windows\system32\perfc00C.dat
- 2009-03-02 10:03:11 405,204 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-03 08:07:51 406,488 ----a-w c:\windows\system32\perfh009.dat
- 2009-03-02 10:03:11 474,370 ----a-w c:\windows\system32\perfh00C.dat
+ 2009-03-03 08:07:51 476,438 ----a-w c:\windows\system32\perfh00C.dat
+ 2009-03-03 08:03:00 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_7ec.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "c:\program files\MyPlayCity\tbMyP0.dll" [2008-08-05 1610264]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
2008-08-05 02:13 1610264 --a------ c:\program files\MyPlayCity\tbMyP0.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
2008-09-15 06:47 1784856 --a------ c:\program files\Mininova-Vuze\tbMin0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}"= "c:\program files\MyPlayCity\tbMyP0.dll" [2008-08-05 1610264]
"{d51d388b-f5dc-471a-a1ce-5e2d671091c0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{4724C5D8-DFA7-417A-A2F5-1EABFEE9B4AC}"= "c:\program files\MyPlayCity\tbMyP0.dll" [2008-08-05 1610264]
"{D51D388B-F5DC-471A-A1CE-5E2D671091C0}"= "c:\program files\Mininova-Vuze\tbMin0.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{4724c5d8-dfa7-417a-a2f5-1eabfee9b4ac}]
[HKEY_CLASSES_ROOT\clsid\{d51d388b-f5dc-471a-a1ce-5e2d671091c0}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"wefi"="c:\program files\WeFi\WeFi.exe" [2008-12-01 427008]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-25 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 69216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"CopernicPerUserTaskMgr"="c:\windows\system32\CopernicPerUserTaskMgr.exe" [2002-02-01 69632]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-03 458752]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"HiYo"="c:\program files\HiYo\bin\HiYo.exe" [2008-10-23 300336]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-11-22 185872]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-14 623992]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-17 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-17 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-17 131072]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2008-04-16 229888]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2007-06-26 c:\windows\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.FFDS"= ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2008-01-21 21512]
R0 iastor75;iastor75;c:\windows\system32\drivers\iastor75.sys [2007-06-26 304920]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-03-02 22536]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-01 114768]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\[u]0/u00.fcl [2008-10-28 16:53:52 13560]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-01 20560]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2009-03-02 4150840]
R2 FLEXlm Service 1;FLEXlm Service 1;c:\abaqus\License\lmgrd.exe [2008-11-01 659456]
R2 Texis Monitor;Texis Monitor;c:\abaqus\Documentation\monitor.exe [2008-11-01 4210688]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-01-21 26248]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6a3ca432-f1c9-11dd-818f-001a6bf6ffff}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-03-03 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
IE: &Search
IE: Ajouter au fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Consulter les dictionnaires (SYSTRAN) - c:\program files\SYSTRAN\6\\GUIres.dll/lookup.js
IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Traduire (SYSTRAN) - c:\program files\SYSTRAN\6\\GUIres.dll/translate.js
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFAlert.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJPI141.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-03 11:37:39
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\[u]0/u00.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\Administrator\Software\SecuROM\License information*]
"datasecu"=hex:c5,44,28,ec,d3,e6,2f,25,61,f1,52,0a,87,b6,7e,29,3e,de,92,b7,39,
5f,ed,d1,23,b7,e1,8c,11,05,44,5b,60,9f,56,de,a4,33,7c,c7,2c,ae,43,23,b4,bd,\
"rkeysecu"=hex:a4,6d,a7,ab,3a,a9,37,70,ca,99,c8,da,70,37,7a,5d
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{29D83109-D499-A3EF-54ABD4209B2D5F0C}\{354D4B2F-7299-D6B0-F9DE68C9556AEC8D}\{1096A586-413B-60D3-8347C002DC18071C}*]
"N3ON3SCQTOHKQM23SBHY163HKH1"=hex:01,00,01,00,00,00,00,00,fa,de,c6,7c,16,d0,d3,
6d,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{484F515E-F5F4-CAE2-00797FFBC1B1DB0A}\{B5BB857C-6143-5E3C-4B14653578135B7A}\{14E971F7-0C0F-F2F4-35B0BAA5D2098273}*]
"N3ON3SCQTOHKQM23SBHY163HKH1"=hex:01,00,01,00,00,00,00,00,fa,de,c6,7c,16,d0,d3,
6d,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
Heure de fin: 2009-03-03 11:39:13
ComboFix-quarantined-files.txt 2009-03-03 10:38:50
Avant-CF: 10 424 537 088 octets libres
Après-CF: 10,413,817,856 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
313