Voici le rapport de combofix (suite message 10 que je n'avais pas fini):
ComboFix 09-03-04.01 - Magali 2009-03-05 13:28:46.3 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.179 [GMT 1:00]
Lancé depuis: c:\documents and settings\Magali\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Magali\Bureau\CFscript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
FW: Pare-feu BitDefender *disabled*
* Un nouveau point de restauration a été créé
FILE ::
c:\program files\Defenza
c:\windows\118294.78
c:\windows\system32\118290.54
c:\windows\system32\Machnm32.sys
c:\windows\system32\Machnm64.sys
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\118294.78
c:\windows\system32\118290.54
c:\windows\system32\Machnm32.sys
c:\windows\system32\Machnm64.sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-05 au 2009-03-05 ))))))))))))))))))))))))))))))))))))
.
2094-03-10 14:19 . 2008-08-08 07:39 3,120 --a------ c:\windows\MF_C421.lfa
2094-03-10 14:19 . 2008-08-08 07:39 3,120 --a------ c:\windows\MF_C420.lfa
2009-03-05 13:27 . 2009-03-05 13:31 121 --a------ c:\windows\bdagent.INI
2009-03-05 12:00 . 2009-03-05 13:30 81,984 --a------ c:\windows\system32\bdod.bin
2009-03-05 11:47 . 2009-03-05 11:47 <REP> d-------- c:\documents and settings\Magali\Application Data\BitDefender
2009-03-05 11:46 . 2009-03-05 11:46 <REP> d-------- c:\program files\BitDefender
2009-03-05 11:46 . 2009-03-05 11:46 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2009-03-05 11:44 . 2009-03-05 11:44 <REP> d-------- c:\program files\Fichiers communs\BitDefender
2009-03-05 10:55 . 2009-03-05 10:55 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-05 10:55 . 2009-03-05 10:55 <REP> d-------- c:\documents and settings\Magali\Application Data\Malwarebytes
2009-03-05 10:55 . 2009-03-05 10:55 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-05 10:55 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-05 10:55 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-05 09:37 . 2009-03-05 09:37 <REP> d-------- C:\rsit
2009-03-05 08:41 . 2009-03-05 08:41 <REP> d--hs---- C:\FOUND.003
2009-03-05 02:36 . 2009-03-05 02:36 <REP> d-------- c:\program files\CCleaner
2009-03-05 01:57 . 2009-03-05 01:57 <REP> d-------- c:\program files\Uniblue
2009-03-05 01:57 . 2009-03-05 01:58 <REP> d-------- c:\documents and settings\Magali\Application Data\Uniblue
2009-03-05 01:56 . 2009-03-05 01:57 <REP> d--h----- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-03-05 01:48 . 2009-03-05 01:48 <REP> d-------- c:\program files\Defenza
2009-03-04 21:53 . 2009-03-04 21:53 <REP> d-------- c:\temp\google
2009-03-04 20:55 . 2009-03-04 20:55 <REP> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-03-04 20:51 . 2009-03-04 20:51 <REP> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-02-28 14:51 . 2009-02-28 14:51 <REP> d--hs---- C:\FOUND.002
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 16:03 104,328 ----a-w c:\windows\system32\drivers\bdfndisf.sys
2009-01-16 20:15 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-24 08:43 158,192 ------w c:\windows\system32\pxwma.dll
2008-12-21 07:07 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-12-20 22:47 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
2008-12-20 22:47 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 22:47 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 22:47 233,472 ----a-w c:\windows\system32\dllcache\webcheck.dll
2008-12-20 22:47 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
2008-12-20 22:47 105,984 ----a-w c:\windows\system32\dllcache\url.dll
2008-12-20 22:47 102,912 ----a-w c:\windows\system32\dllcache\occache.dll
2008-12-20 22:47 1,160,192 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-12-19 09:11 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-06-17 11:43 1,271,557 ----a-w c:\program files\wrar371fr.exe
2008-06-08 16:29 672,146 ----a-w c:\program files\SpywareSecure_setup.exe
2008-05-15 20:58 2,048,604 ----a-w c:\program files\PhotoWays.exe
2008-05-15 07:04 23,060,136 ----a-w c:\program files\setupfreavast.exe
2008-05-01 13:20 2,402,832 ----a-w c:\program files\WLinstaller.exe
2007-11-22 00:35 10,549,568 ----a-w c:\program files\copytodvd4_setup_403acheté.exe
2007-11-22 00:21 47,360 ----a-w c:\documents and settings\Magali\Application Data\pcouffin.sys
2007-11-19 19:48 3,919 ----a-w c:\program files\Nero_Burning_ROM_Ultra_Edition_v6[1].6.0.1.zip
2007-09-08 08:25 51,418,424 ----a-w c:\program files\iTunesSetup.exe
2007-07-30 20:50 4,212 ----a-w c:\program files\ReadMe.txt
2007-07-30 20:49 498,936 ----a-w c:\program files\NISDwnld.exe
2007-03-21 16:38 484,928 ----a-w c:\program files\magentic_install.exe
2007-03-04 16:02 877,976 ----a-w c:\program files\7zip.exe
2007-02-01 21:31 14,994,392 ----a-w c:\program files\GoogleEarthWin.exe
2007-01-13 13:20 1,104,734 ----a-w c:\program files\dvdshrink_3.2.0.16_fr.zip
2007-01-11 09:51 2,916,417 ----a-w c:\program files\Setup_EComo_v1.00j.exe
2006-12-21 22:00 19,666,504 ----a-w c:\program files\QuickTimeInstaller.exe
2006-12-07 07:37 23,375,521 ----a-w c:\program files\fotofacil2.exe
2006-09-07 13:47 15,921,323 ----a-w c:\program files\ps701up-f.exe
2006-07-11 18:12 11,981,422 ----a-w c:\program files\Gordian.Knot.Codec.Pack.1.9.Setup.exe
2006-02-12 15:57 774,144 ----a-w c:\program files\RngInterstitial.dll
2005-09-11 17:30 3,835,424 ----a-w c:\program files\mxblst4win.EXE
2005-09-11 16:48 526 ----a-w c:\program files\ACERBACKUPCDLog.TXT
2005-09-11 16:19 9,964,393 ----a-w c:\program files\nero_nero_6.6.0.16_language_pack_francais_francais_10297.exe
2005-09-11 16:13 34,235,626 ----a-w c:\program files\Nero-6.6.0.16.exe
2005-05-24 08:11 756,167 ----a-w c:\program files\lunbio15.exe
2005-05-06 20:14 885 ----a-w c:\program files\eula.txt
2005-02-19 11:40 1,661 ----a-w c:\program files\[u]0
/u00851DB.key
2005-02-18 11:55 458 ----a-w c:\program files\file_id.diz
2005-02-18 11:48 2,322 ----a-w c:\program files\black.nfo
2008-12-16 16:52 61,440 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
2006-07-11 18:13 56 --sh--r c:\windows\system32\A3B59919B6.sys
2008-04-14 03:34 12,288 --sh--w c:\windows\system32\regsvr32.exe
2008-04-14 03:33 413,696 --sha-w c:\windows\system32\msvcp60.dll
2008-09-03 12:41 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090320080904\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-05_10.44.00.67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 10:47:28 61,440 ----a-r c:\windows\Installer\{076C87CD-CAB3-42FB-94D7-EF98A0C33BFC}\helpicon.exe
+ 2009-03-05 10:47:28 32,768 ----a-r c:\windows\Installer\{076C87CD-CAB3-42FB-94D7-EF98A0C33BFC}\maintenance_icon.exe
+ 2009-03-05 10:47:28 22,486 ----a-r c:\windows\Installer\{076C87CD-CAB3-42FB-94D7-EF98A0C33BFC}\register_icon.exe
+ 2009-03-05 10:47:28 57,344 ----a-r c:\windows\Installer\{076C87CD-CAB3-42FB-94D7-EF98A0C33BFC}\texticon.exe
+ 2007-12-12 14:06:42 295,606 ----a-r c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A90000000001}\SC_Reader.exe
- 2007-09-26 09:56:14 511,328 ----a-w c:\windows\system32\capicom.dll
+ 2007-04-11 09:11:20 511,328 ----a-w c:\windows\system32\capicom.dll
+ 2008-09-18 10:09:12 111,112 ----a-w c:\windows\system32\drivers\bdfm.sys
+ 2008-12-10 18:42:46 242,184 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
+ 2008-10-06 16:16:16 82,696 ----a-w c:\windows\system32\drivers\BDVEDISK.sys
- 2004-08-05 04:00:00 112,128 ----a-w c:\windows\system32\mapi32.dll
+ 2004-03-31 11:28:00 131,072 ----a-w c:\windows\system32\mapi32.dll
- 2002-01-05 13:48:16 974,848 ------w c:\windows\system32\MFC70.DLL
+ 2002-01-05 01:48:16 974,848 ----a-w c:\windows\system32\mfc70.dll
- 2002-01-05 13:36:36 964,608 ------w c:\windows\system32\MFC70U.DLL
+ 2002-01-05 01:36:38 964,608 ----a-w c:\windows\system32\mfc70u.dll
- 2007-03-21 19:39:00 1,060,864 ----a-w c:\windows\system32\MFC71.DLL
+ 2003-03-18 19:20:00 1,060,864 ----a-w c:\windows\system32\mfc71.dll
- 2003-03-18 21:12:12 1,047,552 ----a-w c:\windows\system32\MFC71u.dll
+ 2003-03-18 19:12:12 1,047,552 ----a-w c:\windows\system32\MFC71u.dll
- 2002-01-05 12:38:36 54,784 ------w c:\windows\system32\MSVCI70.DLL
+ 2002-01-05 01:38:38 54,784 ----a-w c:\windows\system32\msvci70.dll
- 2002-01-05 12:40:18 487,424 ------w c:\windows\system32\MSVCP70.DLL
+ 2002-01-05 01:40:20 487,424 ----a-w c:\windows\system32\msvcp70.dll
- 2007-03-21 19:33:00 503,808 ----a-w c:\windows\system32\MSVCP71.DLL
+ 2003-03-18 18:14:52 499,712 ----a-w c:\windows\system32\msvcp71.dll
- 2002-01-05 12:37:26 344,064 ------w c:\windows\system32\MSVCR70.DLL
+ 2002-01-05 00:37:28 344,064 ----a-w c:\windows\system32\msvcr70.dll
- 2008-12-21 14:51:08 348,160 ----a-w c:\windows\system32\msvcr71.dll
+ 2003-02-21 02:42:22 348,160 ----a-w c:\windows\system32\msvcr71.dll
+ 2008-10-09 14:31:54 192,512 ----a-w c:\windows\system32\txmlutil.dll
+ 2007-01-31 12:50:32 913,408 ----a-w c:\windows\system32\xreglib.dll
+ 2009-03-05 10:49:22 16,384 ----a-w c:\windows\Temp\Perflib_Perfdata_6bc.dat
- 2006-12-01 21:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:32 479,232 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
- 2006-12-01 21:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
- 2006-12-01 21:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-01 22:25:52 1,101,824 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-01 22:25:56 1,093,120 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 22:25:58 69,632 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-01 22:26:00 57,856 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 22:08:00 40,960 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 22:08:00 45,056 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 22:08:00 65,536 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 22:08:00 57,344 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 22:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 22:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 22:08:00 61,440 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 22:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 22:08:00 49,152 ----a-w c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-01-27 251264]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-14 1961984]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-26 2019624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-21 136600]
"AspireService"="c:\program files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 110592]
"MediaSync"="c:\program files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 421888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-02-24 86016]
"Symantec PIF AlertEng"="c:\program files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-15 196608]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 32768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"Motive SmartBridge"="c:\progra~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2005-08-24 438359]
"PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-04-26 237568]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-12-21 185872]
"PCDAS"="c:\program files\Defenza\pcd-as.exe" [2006-12-15 1359872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-09 741376]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 c:\windows\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
"VTTimer"="VTTimer.exe" [2005-05-13 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-05-13 c:\windows\system32\VTTrayp.exe]
"nwiz"="nwiz.exe" [2005-02-24 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\documents and settings\Magali\Menu D‚marrer\Programmes\D‚marrage\
Registration-PCTV.lnk - c:\program files\Pinnacle\Pinnacle PCTV\ERegister\RegTool.exe [2005-09-11 245760]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
NkvMon.exe.lnk - c:\program files\Nikon\NkView5\NkvMon.exe [2005-12-21 233472]
FotoStation Easy AutoLaunch.lnk - c:\program files\FotoStation Easy\FotoStation Easy AutoLaunch.exe [2005-12-21 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= c:\program files\ffdshow\ffdshow.ax
"VIDC.I420"= c:\windows\system32\i263_32.drv
"vidc.I263"= I263_32.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\Pinnacle\\Pinnacle PCTV\\TeleText\\WebServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2009-02-03 104328]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [2005-09-11 6400]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 ICAM3NT5;Caméra vidéo Intel USB III;c:\windows\system32\drivers\Icam3.sys [2005-10-16 141056]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - 21AF6A87
*NewlyCreated* - BDFM
*NewlyCreated* - BDFSFLTR
*NewlyCreated* - BDFTDIF
*NewlyCreated* - BDSELFPR
*NewlyCreated* - BDVEDISK
*NewlyCreated* - LIVESRV
*NewlyCreated* - PROFOS
*NewlyCreated* - TRUFOS
*NewlyCreated* - VSSERV
*Deregistered* - 21af6a87
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Tâches planifiées'
2009-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2009-03-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-04 20:51]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://portail.club-internet.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Ouvrir l'image dans &Microsoft PhotoDraw - c:\progra~1\MICROS~2\Office\1036\phdintl.dll/phdContext.htm
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {B9907873-6560-4A36-B76B-9DADE84A7F55} - hxxps://www.fnacmusic.com/telechargementFnacmusic/FnacmusicDnl.CAB
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game06.zylom.com/activex/zylomgamesplayer.cab
FF - ProfilePath - c:\documents and settings\Magali\Application Data\Mozilla\Firefox\Profiles\tfixdzmy.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - MyStart Rechercher
FF - prefs.js: browser.startup.homepage - hxxp://portail.club-internet.fr/
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1508.6312\npCIDetect13.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-05 13:31:12
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-03-05 13:32:41
ComboFix-quarantined-files.txt 2009-03-05 12:32:40
ComboFix3.txt 2009-03-05 09:44:44
ComboFix2.txt 2009-03-05 09:51:16
Avant-CF: 61 547 085 824 octets libres
Après-CF: 61,541,941,248 octets libres
309 --- E O F --- 2009-03-05 06:57:32