ComboFix 09-03-27.02 - christian 2009-03-28 12:04:33.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1279.625 [GMT 1:00]
Lancé depuis: c:\documents and settings\christian\Bureau\ComboFix.exe
FW: ZoneAlarm Firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\patch.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
E:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
-------\Service_PCIDump
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-28 ))))))))))))))))))))))))))))))))))))
.
2009-03-27 22:00 . 2009-03-27 22:00 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-27 22:00 . 2009-03-27 22:00 <REP> d-------- c:\documents and settings\christian\Application Data\Malwarebytes
2009-03-27 22:00 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-27 22:00 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-27 06:51 . 2004-10-15 09:20 1,654,784 --a------ c:\windows\system32\W29MLRES.DLL
2009-03-27 06:51 . 2004-01-02 14:58 13 --a------ c:\windows\system32\drivers\verfile.tic
2009-03-26 20:28 . 2009-03-26 20:29 <REP> d-------- C:\rsit
2009-03-26 20:24 . 2009-03-27 21:54 <REP> d-------- C:\ToolBar SD
2009-03-25 21:09 . 2009-03-25 21:09 <REP> d-------- c:\windows\tiinst
2009-03-25 08:25 . 2009-03-25 08:25 <REP> d-------- c:\documents and settings\Invité\Application Data\Windows Desktop Search
2009-03-25 08:24 . 2009-03-25 08:24 <REP> d-------- c:\documents and settings\Invité\Application Data\Intel
2009-03-25 08:23 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Invité\Voisinage réseau
2009-03-25 08:23 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Invité\Voisinage réseau
2009-03-25 08:23 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Invité\Voisinage d'impression
2009-03-25 08:23 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Invité\Voisinage d'impression
2009-03-25 08:23 . 2009-03-22 09:55 <REP> d--h----- c:\documents and settings\Invité\Modèles
2009-03-25 08:23 . 2009-03-22 09:55 <REP> d--h----- c:\documents and settings\Invité\Modèles
2009-03-25 08:23 . 2009-03-25 08:25 <REP> dr------- c:\documents and settings\Invité\Mes documents
2009-03-25 08:23 . 2009-03-25 08:25 <REP> dr------- c:\documents and settings\Invité\Mes documents
2009-03-25 08:23 . 2009-03-22 09:41 <REP> dr------- c:\documents and settings\Invité\Menu Démarrer
2009-03-25 08:23 . 2009-03-22 09:41 <REP> dr------- c:\documents and settings\Invité\Menu Démarrer
2009-03-25 08:23 . 2009-03-25 08:25 <REP> dr------- c:\documents and settings\Invité\Favoris
2009-03-25 08:23 . 2009-03-25 08:25 <REP> dr------- c:\documents and settings\Invité\Favoris
2009-03-25 08:23 . 2009-03-22 09:55 <REP> d-------- c:\documents and settings\Invité\Bureau
2009-03-25 08:23 . 2009-03-22 09:55 <REP> d-------- c:\documents and settings\Invité\Bureau
2009-03-25 08:23 . 2009-03-25 08:23 <REP> d-------- c:\documents and settings\Invité
2009-03-24 17:39 . 2009-03-24 17:39 <REP> d--hs---- c:\documents and settings\Papa\IETldCache
2009-03-23 20:21 . 2009-03-23 20:21 <REP> d--hs---- c:\documents and settings\christian\IECompatCache
2009-03-22 19:08 . 2009-03-22 19:11 <REP> d--h-c--- c:\windows\ie8
2009-03-22 18:03 . 2009-03-22 18:03 <REP> d--hs---- c:\documents and settings\christian\PrivacIE
2009-03-22 17:59 . 2009-03-22 17:59 <REP> d--hs---- c:\documents and settings\LocalService\IETldCache
2009-03-22 17:59 . 2009-03-22 17:59 <REP> d--hs---- c:\documents and settings\christian\IETldCache
2009-03-22 17:56 . 2009-03-22 19:13 <REP> d-------- c:\windows\ie8updates
2009-03-22 17:50 . 2009-02-28 05:55 105,984 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-03-22 17:02 . 2009-03-22 17:02 <REP> d-------- C:\O2C
2009-03-22 14:54 . 2009-03-22 14:54 <REP> d-------- c:\documents and settings\Maxime\Application Data\Windows Desktop Search
2009-03-22 14:53 . 2009-03-22 14:54 <REP> dr------- c:\documents and settings\Maxime\Favoris
2009-03-22 14:53 . 2009-03-22 15:01 <REP> d-------- c:\documents and settings\Maxime\Bureau
2009-03-22 14:53 . 2009-03-22 14:53 <REP> d-------- c:\documents and settings\Maxime\Application Data\Intel
2009-03-22 14:52 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Maxime\Voisinage réseau
2009-03-22 14:52 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Maxime\Voisinage d'impression
2009-03-22 14:52 . 2009-03-22 09:55 <REP> d--h----- c:\documents and settings\Maxime\Modèles
2009-03-22 14:52 . 2009-03-22 14:54 <REP> dr------- c:\documents and settings\Maxime\Mes documents
2009-03-22 14:52 . 2009-03-22 09:41 <REP> dr------- c:\documents and settings\Maxime\Menu Démarrer
2009-03-22 14:52 . 2009-03-22 14:53 <REP> d-------- c:\documents and settings\Maxime
2009-03-22 12:47 . 2009-03-22 12:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-03-22 12:26 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2009-03-22 12:25 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Papa\Voisinage réseau
2009-03-22 12:25 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Papa\Voisinage d'impression
2009-03-22 12:25 . 2009-03-22 09:55 <REP> d--h----- c:\documents and settings\Papa\Modèles
2009-03-22 12:25 . 2009-03-24 17:39 <REP> dr------- c:\documents and settings\Papa\Mes documents
2009-03-22 12:25 . 2009-03-22 09:41 <REP> dr------- c:\documents and settings\Papa\Menu Démarrer
2009-03-22 12:25 . 2009-03-24 17:39 <REP> dr------- c:\documents and settings\Papa\Favoris
2009-03-22 12:25 . 2009-03-27 23:10 <REP> d-------- c:\documents and settings\Papa\Bureau
2009-03-22 12:25 . 2009-03-22 12:25 <REP> d-------- c:\documents and settings\Papa\Application Data\Windows Desktop Search
2009-03-22 12:25 . 2009-03-22 12:25 <REP> d-------- c:\documents and settings\Papa\Application Data\Intel
2009-03-22 12:25 . 2009-03-24 17:39 <REP> d-------- c:\documents and settings\Papa
2009-03-22 12:23 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-03-22 12:20 . 2008-10-16 02:01 1,499,648 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2009-03-22 12:20 . 2009-03-08 04:34 1,206,784 --a--c--- c:\windows\system32\dllcache\urlmon.dll
2009-03-22 12:20 . 2009-03-08 04:34 914,944 --a--c--- c:\windows\system32\dllcache\wininet.dll
2009-03-22 12:18 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-22 12:18 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-22 12:18 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-22 12:18 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-22 12:16 . 2009-03-08 04:41 5,937,152 --a--c--- c:\windows\system32\dllcache\mshtml.dll
2009-03-22 12:13 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Marion\Voisinage réseau
2009-03-22 12:13 . 2009-03-22 09:41 <REP> d--h----- c:\documents and settings\Marion\Voisinage d'impression
2009-03-22 12:13 . 2009-03-22 09:55 <REP> d--h----- c:\documents and settings\Marion\Modèles
2009-03-22 12:13 . 2009-03-22 12:13 <REP> dr------- c:\documents and settings\Marion\Mes documents
2009-03-22 12:13 . 2009-03-22 09:41 <REP> dr------- c:\documents and settings\Marion\Menu Démarrer
2009-03-22 12:13 . 2009-03-22 12:13 <REP> dr------- c:\documents and settings\Marion\Favoris
2009-03-22 12:13 . 2009-03-22 09:55 <REP> d-------- c:\documents and settings\Marion\Bureau
2009-03-22 12:13 . 2009-03-22 12:13 <REP> d-------- c:\documents and settings\Marion\Application Data\Windows Desktop Search
2009-03-22 12:13 . 2009-03-22 12:13 <REP> d-------- c:\documents and settings\Marion\Application Data\Intel
2009-03-22 12:13 . 2009-03-22 12:13 <REP> d-------- c:\documents and settings\Marion
2009-03-22 12:13 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-22 12:12 . 2008-12-11 11:57 333,952 -----c--- c:\windows\system32\dllcache\srv.sys
2009-03-22 12:12 . 2008-05-01 15:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-03-22 12:10 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-03-22 12:07 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-03-22 12:07 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-03-22 12:05 . 2009-01-09 20:19 1,089,883 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-03-22 12:02 . 2009-03-22 12:02 <REP> d-------- c:\documents and settings\NetworkService\Menu Démarrer
2009-03-22 11:26 . 2008-04-14 03:33 1,306,624 -----c--- c:\windows\system32\dllcache\msxml6.dll
2009-03-22 11:25 . 2007-06-26 07:00 457,607 -----c--- c:\windows\system32\dllcache\mdlib.wmv
2009-03-22 11:25 . 2008-04-14 03:34 380,928 --a------ c:\windows\system32\irprops.cpl
2009-03-22 11:25 . 2008-04-14 03:31 294,912 -----c--- c:\windows\system32\dllcache\msaud32.acm
2009-03-22 11:25 . 2008-04-14 03:31 290,816 -----c--- c:\windows\system32\dllcache\l3codeca.acm
2009-03-22 11:25 . 2007-06-26 06:59 97,117 -----c--- c:\windows\system32\dllcache\mplayer2.hlp
2009-03-22 11:25 . 2004-08-05 13:00 36,640 -----c--- c:\windows\system32\dllcache\mplayer2.inf
2009-03-22 11:25 . 2006-12-28 20:01 19,569 --a------ c:\windows\[u]0/u03204_.tmp
2009-03-22 11:25 . 2007-06-26 07:00 5,971 -----c--- c:\windows\system32\dllcache\events.js
2009-03-22 11:25 . 2004-08-05 13:00 2,778 -----c--- c:\windows\system32\dllcache\mplogoh.gif
2009-03-22 11:25 . 2004-08-05 13:00 2,545 -----c--- c:\windows\system32\dllcache\mplogo.gif
2009-03-22 11:25 . 2007-06-26 06:59 1,885 -----c--- c:\windows\system32\dllcache\mplayer2.cnt
2009-03-22 11:24 . 2007-06-26 07:00 381,425 -----c--- c:\windows\system32\dllcache\copycd.wmv
2009-03-22 11:24 . 2008-04-14 03:34 294,912 -----c--- c:\windows\system32\dllcache\dlimport.exe
2009-03-22 11:24 . 2004-07-17 10:34 184,107 -----c--- c:\windows\system32\dllcache\compact.wmz
2009-03-22 11:24 . 2007-06-26 07:00 9,585 -----c--- c:\windows\system32\dllcache\controls.css
2009-03-22 11:24 . 2007-06-26 07:00 8,298 -----c--- c:\windows\system32\dllcache\contents.htm
2009-03-22 11:24 . 2007-06-26 07:00 6,878 -----c--- c:\windows\system32\dllcache\controls.js
2009-03-22 11:24 . 2004-08-05 13:00 999 -----c--- c:\windows\system32\dllcache\bktrh.gif
2009-03-22 11:24 . 2004-08-05 13:00 773 -----c--- c:\windows\system32\dllcache\cnth.gif
2009-03-22 11:24 . 2004-08-05 13:00 773 -----c--- c:\windows\system32\dllcache\cnt.gif
2009-03-22 11:24 . 2004-08-05 13:00 772 -----c--- c:\windows\system32\dllcache\cntd.gif
2009-03-22 11:24 . 2004-08-05 13:00 760 -----c--- c:\windows\system32\dllcache\cloapph.gif
2009-03-22 11:24 . 2004-08-05 13:00 717 -----c--- c:\windows\system32\dllcache\cloapp.gif
2009-03-22 10:32 . 2009-03-22 10:32 2,422 --a------ c:\windows\system32\wpa.bak
2009-03-22 10:02 . 2008-04-14 03:32 426,041 --a--c--- c:\windows\system32\dllcache\voicepad.dll
2009-03-22 10:02 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\winzm.ime
2009-03-22 10:02 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\winsp.ime
2009-03-22 10:02 . 2008-04-14 03:32 156,672 --a--c--- c:\windows\system32\dllcache\winpy.ime
2009-03-22 10:02 . 2008-04-14 03:32 86,073 --a--c--- c:\windows\system32\dllcache\voicesub.dll
2009-03-22 10:02 . 2008-04-14 03:33 79,360 --a--c--- c:\windows\system32\dllcache\winar30.ime
2009-03-22 10:02 . 2008-04-14 03:32 72,704 --a--c--- c:\windows\system32\dllcache\wingb.ime
2009-03-22 10:02 . 2008-04-14 03:33 65,536 --a--c--- c:\windows\system32\dllcache\winime.ime
2009-03-22 10:02 . 2004-08-05 13:00 48,256 --a--c--- c:\windows\system32\dllcache\w32.dll
2009-03-22 10:02 . 2004-08-05 13:00 41,600 --a--c--- c:\windows\system32\dllcache\weitekp9.dll
2009-03-22 10:02 . 2004-08-05 13:00 31,360 --a--c--- c:\windows\system32\dllcache\weitekp9.sys
2009-03-22 10:02 . 2004-08-05 13:00 28,288 --a--c--- c:\windows\system32\dllcache\xjis.nls
2009-03-22 10:00 . 2008-04-14 03:31 13,463,552 --a--c--- c:\windows\system32\dllcache\hwxjpn.dll
2009-03-22 09:59 . 2004-08-05 13:00 1,677,824 --a--c--- c:\windows\system32\dllcache\chsbrkr.dll
2009-03-22 09:57 . 2004-08-05 13:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2009-03-22 09:57 . 2009-03-22 09:57 749 -rah----- c:\windows\WindowsShell.Manifest
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 11:12 794,656 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-28 11:08 11,312 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-27 21:57 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-03-27 21:32 --------- d-----w c:\program files\Trend Micro
2009-03-27 17:03 --------- d-----w c:\program files\Java
2009-03-27 16:38 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-27 05:52 17,119 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-03-25 20:10 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-25 19:50 --------- d-----w c:\program files\Launch Manager
2009-03-24 19:09 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-22 14:37 --------- d-----w c:\program files\Micro Application
2009-03-19 20:25 33,786 ----a-w c:\documents and settings\christian\Application Data\wklnhst.dat
2009-02-02 05:43 --------- d-----w c:\documents and settings\christian\Application Data\GlarySoft
2009-01-31 07:19 --------- d-----w c:\program files\CDex_170b2
2009-01-30 18:09 --------- d-----w c:\program files\CCleaner
2008-03-30 15:18 96,176 ----a-w c:\documents and settings\christian\Application Data\GDIPFONTCACHEV1.DAT
2008-08-15 07:33 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-04-14 02:33 65,024 --sha-w c:\windows\system32\asycfilt.dll
2005-01-20 20:55 8 --sha-r c:\windows\system32\BCFCF81A7E.sys
2007-03-24 21:08 56 --sha-r c:\windows\system32\EEB141F368.sys
2008-03-29 15:29 9,552 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-04-14 02:33 1,028,096 --sha-w c:\windows\system32\mfc42.dll
2004-08-05 12:00 57,344 --sha-w c:\windows\system32\mfc42loc.dll
1995-09-20 15:16 35,088 --sha-w c:\windows\system32\msjint32.dll
1995-09-20 15:13 977,680 --sha-w c:\windows\system32\msjt3032.dll
1995-09-20 15:16 23,824 --sha-w c:\windows\system32\msjter32.dll
2008-04-14 02:33 413,696 --sha-w c:\windows\system32\msvcp60.dll
2008-04-14 02:33 343,040 --sha-w c:\windows\system32\msvcrt.dll
2004-08-05 12:00 253,952 --sha-w c:\windows\system32\msvcrt20.dll
2008-04-14 02:33 551,936 --sha-w c:\windows\system32\oleaut32.dll
2008-04-14 02:33 84,992 --sha-w c:\windows\system32\olepro32.dll
2008-04-14 02:33 30,749 --sha-w c:\windows\system32\vbajet32.dll
1995-09-24 10:02 243,472 --sha-w c:\windows\system32\vbar2232.dll
1998-05-18 02:06 368,912 --sha-w c:\windows\system32\vbar332.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-21 344064]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-05 688218]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2004-08-06 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2004-11-11 49152]
"LMgrOSD"="c:\program files\Launch Manager\OSD.exe" [2004-07-26 204800]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2004-11-23 73728]
"PCMService"="c:\program files\Home Cinema\PowerCinema\PCMService.exe" [2005-03-09 118926]
"RemoteControl"="c:\program files\Home Cinema\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" [2004-08-25 94208]
"McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 139320]
"Network Associates Error Reporting Service"="c:\program files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 147514]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AGRSMMSG"="AGRSMMSG.exe" [2004-07-22 c:\windows\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"SoundMan"="SOUNDMAN.EXE" [2004-01-02 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-05 44544]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\WIDCOMM\Logiciel Bluetooth\BTTray.exe [2004-11-29 569405]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\H:\[u]0/uautocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSConfig"=c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SoundMan"=SOUNDMAN.EXE
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe"
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"%WinDir%\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Network Associates\\VirusScan\\shcfg32.exe"=
"c:\\Program Files\\Network Associates\\VirusScan\\ScnCfg32.Exe"=
"c:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 Hotkey;Hotkey;c:\windows\system32\drivers\HOTKEY.sys [2008-05-10 9867]
R1 NaiAvTdi1;NaiAvTdi1;c:\windows\system32\drivers\mvstdi5x.sys [2009-03-03 58016]
S1 mailKmd;mailKmd; [x]
S1 Wbutton;Wbutton;c:\windows\system32\drivers\Wbutton.sys --> c:\windows\system32\drivers\Wbutton.sys [?]
S3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2005-01-12 945152]
S3 flash;flash;c:\windows\system32\drivers\flash.sys [2008-05-10 7040]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-08-15 29744]
S3 K320bus;Sony Ericsson K320 driver (WDM);c:\windows\system32\drivers\K320bus.sys [2007-11-17 61504]
S3 K320mdfl;Sony Ericsson K320 USB WMC Modem Filter;c:\windows\system32\drivers\K320mdfl.sys [2007-11-17 9328]
S3 K320mdm;Sony Ericsson K320 USB WMC Modem Driver;c:\windows\system32\drivers\K320mdm.sys [2007-11-17 97056]
S3 K320mgmt;Sony Ericsson K320 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\K320mgmt.sys [2007-11-17 88560]
S3 K320obex;Sony Ericsson K320 USB WMC OBEX Interface;c:\windows\system32\drivers\K320obex.sys [2007-11-17 86368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mWindow Title =
IE: &Recherche AOL Toolbar - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Envoyer à &Bluetooth - c:\program files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\christian\Application Data\Mozilla\Firefox\Profiles\2s9386tz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10168&gct=&gc=1&q=
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 12:10:57
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\.Default\Software\Autodesk\Autodesk Digital Signatures]
@DACL=(02 0000)
[HKEY_USERS\.Default\Software\HotkeyPanel\1]
@DACL=(02 0000)
"Name"="c:\\Program Files\\Launch Manager\\hotkey.html"
[HKEY_USERS\.Default\Software\HotkeyPanel\11]
@DACL=(02 0000)
"Name"="\"c:\\Program Files\\Launch Manager\\fn.exe\""
"NameDesc"="Launch Manager"
[HKEY_USERS\.Default\Software\HotkeyPanel\12]
@DACL=(02 0000)
"Name"="\"c:\\Program Files\\Launch Manager\\fn.exe\""
"NameDesc"="Launch Manager"
[HKEY_USERS\.Default\Software\HotkeyPanel\31]
@DACL=(02 0000)
"Name"="\"c:\\Program Files\\Outlook Express\\msimn.exe\""
"NameDesc"="E-Mail"
[HKEY_USERS\.Default\Software\HotkeyPanel\36]
@DACL=(02 0000)
"Name"="\"c:\\Program Files\\Internet Explorer\\iexplore.exe\""
"NameDesc"="WWW"
[HKEY_USERS\.Default\Software\Local AppWizard-Generated Applications\LaunchAp]
@DACL=(02 0000)
[HKEY_USERS\.Default\Software\Local AppWizard-Generated Applications\Wbutton]
@DACL=(02 0000)
[HKEY_USERS\.Default\Software\Macromedia\FlashPlayer]
@DACL=(02 0000)
[HKEY_USERS\.Default\Software\Macromedia\Shockwave 10]
@DACL=(02 0000)
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Ahead\Nero - Burning Rom\Settings\NeroIsoListView]
@DACL=(02 0000)
@SACL=
"FILENAME"="0,120,0,1"
"FILESIZE"="1,90,1,1"
"FILETYPE"="2,60,0,1"
"FILEDATE"="3,70,0,1"
"FILEORIGIN"="4,150,0,1"
"FILEATTRIBUTE"="5,60,0,0"
"FILEPRIORITY"="6,80,0,0"
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Local AppWizard-Generated Applications\LaunchAp\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Local AppWizard-Generated Applications\MMDiag\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Local AppWizard-Generated Applications\Wbutton\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Microsoft\Internet Explorer\Default MHTML Editor\shell]
@DACL=(02 0000)
@SACL=
[HKEY_USERS\S-1-5-21-3958462218-115887364-3908271126-1010\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\ATI Technologies Inc.\Pilotes ATI]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Classes\Applications\PHOTOED.EXE\shell]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Classes\Software\RealNetworks\RealJukebox\1.0\Preferences\DisplayName]
@DACL=(02 0000)
@SACL=
@="RealPlayer"
[HKEY_LOCAL_MACHINE\software\Classes\Software\RealNetworks\RealJukebox\1.0\Preferences\MainApp]
@DACL=(02 0000)
@SACL=
@="c:\\Program Files\\Real\\RealPlayer\\realjbox.exe"
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.BrowseUI\RegBackup]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\10.0]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\7.0]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Monitors]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Monitors\//./DISPLAY1\[u]0/u,0,1280,768]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
@SACL=
"NoServices"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\Settings]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\ShimInclusionList\FIREFOX.EXE]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\UIPlugins\{292AE934-4F49-40bb-9E7E-6F6398ED9C31}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Plug-in Nero Fast CD-Burning"
"Description"="Graver votre CD"
"Capabilities"=dword:40000001
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{3FDF25EE-E592-4495-8391-6E9C504DAC2B}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\\WMSET10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{3FDF25EE-E592-4495-8391-6E9C504DAC2B}\\wmset10.cat"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{60204BB3-7078-4F70-8F69-68297621941C}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{60204BB3-7078-4F70-8F69-68297621941C}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{60204BB3-7078-4F70-8F69-68297621941C}\\MPSTUB10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{60204BB3-7078-4F70-8F69-68297621941C}\\mpstub10.cat"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}\\MPCD10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{CFB4B314-0328-45E1-94AF-45A3F5F48E0B}\\mpcd10.cat"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{DD90D410-1823-43EB-9A16-A2331BF08799}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Windows Media Files"
"ComponentGUID"="{DD90D410-1823-43EB-9A16-A2331BF08799}"
"Version"=dword:000a0000
"Sub-Version"=dword:00000e3e
"ExceptionInfName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{DD90D410-1823-43EB-9A16-A2331BF08799}\\WMP10.inf"
"ExceptionCatalogName"=expand:"c:\\WINDOWS\\RegisteredPackages\\{DD90D410-1823-43EB-9A16-A2331BF08799}\\wmp10.cat"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\OptionalComponents\SwDir]
@DACL=(02 0000)
@SACL=
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Setup\OptionalComponents\SwFlash]
@DACL=(02 0000)
@SACL=
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SCP\SCPTRANS]
@DACL=(02 0000)
@SACL=
"ProgID"="MsScp.SCPTRANS.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Media Device Manager\Plugins\SP\NeroBurnPlugin]
@DACL=(02 0000)
@SACL=
"ProgID"="MDNeroBurnPlugin.MDNeroBurnPlugin"
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\MimeTypes]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\MozillaPlugins\@viewpoint.com/VMP\Suffixes]
@DACL=(02 0000)
@SACL=
"mtx"=""
"mtz"=""
"mts"=""
[HKEY_LOCAL_MACHINE\software\Obsidian\Star Wars(tm) Knights of the Old Republic(tm) II: The Sith Lords(tm)]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Realtek Semiconductor Corp.\Realtek AC'97 Audio]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\ViaMichelin\ViaMichelin Navigation]
@DACL=(02 0000)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1144)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'lsass.exe'(1200)
c:\windows\system32\EntApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\program files\Network Associates\VirusScan\Mcshield.exe
c:\program files\Network Associates\VirusScan\VsTskMgr.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\tcpsvcs.exe
c:\windows\system32\snmp.exe
c:\windows\system32\searchindexer.exe
c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\progra~1\COMMON~1\X10\Common\X10nets.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Heure de fin: 2009-03-28 12:16:04 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-28 11:15:56
Avant-CF: 5 783 957 504 octets libres
Après-CF: 5,750,374,400 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
Current=4 Default=4 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
533 --- E O F --- 2009-03-23 06:13:57