Joyeuse Paques !
ComboFix 09-04-04.01 - YVES 2009-04-11 19:16:53.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2047.1355 [GMT 2:00]
Lancé depuis: d:\utilitaires\combofix\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090410-0] *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\InfoSat.txt
D:\install.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-11 au 2009-04-11 ))))))))))))))))))))))))))))))))))))
.
2009-04-11 19:19 . 2009-04-11 19:19 <REP> d--hs---- i:\windows\system32\dllcache
2009-04-11 11:01 . 2009-04-11 11:01 <REP> d-------- I:\rsit
2009-04-11 11:01 . 2009-04-11 11:01 <REP> d-------- i:\program files\trend micro
2009-04-07 11:31 . 2009-04-07 11:44 <REP> d-------- i:\program files\Project64 1.6
2009-04-06 13:16 . 2009-04-06 13:30 <REP> d-------- i:\program files\WowCartographe
2009-04-06 10:59 . 2009-04-06 10:59 <REP> d-------- i:\program files\Smoky City Design
2009-04-04 15:02 . 2009-04-05 09:12 <REP> d-------- i:\program files\PremierOpinion
2009-04-04 15:01 . 2009-04-04 15:01 <REP> d-------- i:\program files\NudgeMania
2009-04-04 09:38 . 2009-04-11 19:20 54,156 --ah----- i:\windows\QTFont.qfn
2009-04-04 09:38 . 2009-04-04 09:38 1,409 --a------ i:\windows\QTFont.for
2009-04-03 17:25 . 2009-04-03 17:25 <REP> d-------- i:\windows\system32\QuickTime
2009-04-03 17:25 . 2009-04-03 17:25 <REP> d-------- i:\program files\QuickTime
2009-04-03 17:24 . 2009-04-03 17:24 0 --a------ i:\windows\PowerReg.dat
2009-04-03 17:22 . 2009-04-03 17:22 <REP> d-------- i:\program files\Ubi Soft
2009-04-03 13:14 . 2009-04-03 13:14 27 --a------ i:\windows\ic.ini
2009-04-02 19:23 . 2009-04-02 19:23 <REP> d-------- i:\program files\Passware
2009-04-01 18:12 . 2009-04-01 18:12 <REP> d-------- i:\documents and settings\YVES\Application Data\KyuubiGame
2009-04-01 18:12 . 2009-04-01 18:12 <REP> d-------- i:\documents and settings\YVES\Application Data\Kyuubi-Game
2009-04-01 18:12 . 2009-04-01 18:12 <REP> d-------- i:\documents and settings\YVES\.kyuubigamesc
2009-04-01 18:10 . 2009-04-01 18:10 <REP> d-------- i:\documents and settings\YVES\Application Data\KyuubiBarre
2009-04-01 18:10 . 2009-04-01 18:10 <REP> d-------- i:\documents and settings\YVES\Application Data\Kyuubi-Barre
2009-04-01 18:10 . 2009-04-01 18:10 <REP> d-------- i:\documents and settings\YVES\.kyuubibarrec
2009-04-01 18:10 . 2006-12-29 04:51 45,056 --a------ i:\windows\system32\jniwrap.dll
2009-04-01 18:10 . 2008-04-04 10:19 293 --a------ i:\windows\system32\jniwrap.lic
2009-04-01 18:10 . 2008-04-04 10:19 292 --a------ i:\windows\system32\jexplorer.lic
2009-04-01 18:10 . 2008-04-04 10:19 289 --a------ i:\windows\system32\comfyj.lic
2009-04-01 17:57 . 2009-04-01 17:57 <REP> d-------- i:\program files\ManyCam 2.4
2009-04-01 17:57 . 2009-04-01 17:57 <REP> d-------- i:\documents and settings\YVES\Application Data\ManyCam
2009-04-01 17:41 . 2002-12-11 15:16 384,512 --a------ i:\windows\system32\mp4sdmod.dll
2009-04-01 17:41 . 2002-12-11 19:12 316,040 --a------ i:\windows\system32\mp43dmod.dll
2009-04-01 17:40 . 2009-04-01 17:40 <REP> d-------- i:\program files\Logitech
2009-04-01 17:40 . 2004-01-21 03:26 360,448 --a------ i:\windows\system32\LVUI2RC.dll
2009-04-01 17:40 . 2004-01-21 03:14 271,360 --a------ i:\windows\system32\drivers\LV302AV.SYS
2009-04-01 17:40 . 2004-01-21 03:25 172,032 --a------ i:\windows\system32\lvcodec2.dll
2009-04-01 17:40 . 2004-01-21 03:24 135,214 --a------ i:\windows\system32\LVComS.exe
2009-04-01 17:40 . 2004-01-21 03:26 122,880 --a------ i:\windows\system32\LVUI2.dll
2009-04-01 17:40 . 2004-01-21 03:28 86,016 --a------ i:\windows\system32\lvcoinst.dll
2009-04-01 17:40 . 2004-01-21 03:24 57,344 --a------ i:\windows\system32\LVComC.dll
2009-04-01 17:40 . 2004-01-21 02:51 17,191 --a------ i:\windows\system32\lvcoinst.ini
2009-04-01 17:40 . 2004-01-21 03:16 12,080 --a------ i:\windows\system32\drivers\LVUSBSta.sys
2009-04-01 17:40 . 2004-01-21 03:14 5,915 --a------ i:\windows\system32\drivers\lv302af.sys
2009-04-01 17:39 . 2009-04-01 17:39 <REP> d-------- i:\program files\Fichiers communs\Labtec
2009-04-01 17:39 . 2009-04-01 17:39 256 --a------ i:\windows\_delis32.ini
2009-04-01 16:07 . 2009-04-03 07:36 <REP> d-------- i:\program files\FlashGet
2009-03-28 16:01 . 2009-03-28 16:01 <REP> d-------- i:\documents and settings\YVES\Application Data\Babylon
2009-03-28 16:01 . 2009-03-28 16:01 <REP> d-------- i:\documents and settings\All Users\Application Data\Babylon
2009-03-28 15:04 . 2004-08-04 00:07 59,264 --a------ i:\windows\system32\drivers\USBAUDIO.sys
2009-03-28 15:03 . 2004-08-04 00:08 31,616 --a------ i:\windows\system32\drivers\usbccgp.sys
2009-03-27 15:36 . 2009-03-27 15:36 754 --a------ i:\windows\WORDPAD.INI
2009-03-25 17:36 . 2009-04-11 16:10 <REP> d-------- i:\documents and settings\YVES\Application Data\XnView
2009-03-22 14:39 . 2009-03-22 14:39 <REP> d-------- i:\program files\Gif2swf
2009-03-22 14:39 . 1999-12-17 10:13 86,016 --a------ i:\windows\unvise32.exe
2009-03-22 12:50 . 2009-03-22 12:50 <REP> d-------- i:\program files\Aleo Software
2009-03-22 12:50 . 2009-03-22 12:50 <REP> d-------- i:\documents and settings\YVES\Application Data\Aleo Software
2009-03-22 12:36 . 2009-03-22 12:36 <REP> d-------- i:\program files\Convertor
2009-03-17 14:43 . 2009-03-17 14:43 <REP> d-------- I:\~QTWTMP.TMP
2009-03-16 20:33 . 2009-03-16 20:33 <REP> d-------- i:\documents and settings\All Users\Application Data\QuickTime
2009-03-16 20:28 . 2009-03-30 21:43 381 --a------ i:\windows\QTW.ini
2009-03-16 20:23 . 2009-03-30 21:44 <REP> d-------- i:\program files\Riven
2009-03-16 20:17 . 2009-03-16 20:17 <REP> d-------- i:\windows\BBSTORE
2009-03-16 20:08 . 2009-03-17 14:44 824 --a------ i:\windows\QT$INST$.~32
2009-03-16 20:08 . 2009-03-17 14:43 30 --a------ i:\windows\RESULT.QTW
2009-03-16 10:12 . 2009-03-16 10:12 <REP> d-------- i:\program files\Apowersoft
2009-03-16 10:12 . 2009-03-16 10:12 <REP> d-------- i:\documents and settings\All Users\Application Data\Apowersoft
2009-03-15 14:57 . 2009-03-15 14:57 <REP> d-------- i:\documents and settings\YVES\Application Data\Microsoft Games
2009-03-15 14:57 . 2009-03-15 14:57 <REP> d-------- i:\documents and settings\All Users\Application Data\Microsoft Games
2009-03-14 19:59 . 2009-03-14 19:59 <REP> d-------- i:\program files\VDOWNLOADER
2009-03-12 09:53 . 2009-03-12 09:53 <REP> d-------- i:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-11 18:49 . 2009-03-11 18:49 <REP> d-------- i:\program files\MSNImageText
2009-03-11 18:47 . 2009-03-11 18:47 <REP> d-------- i:\program files\MSN Reaper
2009-03-11 14:51 . 2009-04-02 19:34 <REP> d-------- i:\program files\Messenger Plus! Live
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 17:20 --------- d---a-w i:\documents and settings\All Users\Application Data\TEMP
2009-04-11 15:34 --------- d-----w i:\program files\Mozilla Thunderbird
2009-04-11 08:19 --------- d-----w i:\program files\LogMeIn
2009-04-10 08:08 --------- d-----w i:\program files\Lexmark X1100 Series
2009-04-04 11:52 --------- d-----w i:\documents and settings\YVES\Application Data\FileZilla
2009-04-03 20:25 --------- d-----w i:\documents and settings\YVES\Application Data\uTorrent
2009-04-03 15:24 --------- d--h--w i:\program files\InstallShield Installation Information
2009-04-03 14:12 --------- d-----w i:\program files\uTorrent
2009-04-03 10:09 --------- d-----w i:\program files\Microsoft Games
2009-04-01 20:05 --------- d-----w i:\documents and settings\YVES\Application Data\AdobeUM
2009-04-01 12:14 --------- d-----w i:\program files\PFConfig
2009-03-25 19:36 --------- d-----w i:\program files\ma-config.com
2009-03-25 19:36 --------- d-----w i:\documents and settings\All Users\Application Data\ma-config.com
2009-03-25 12:19 --------- d-----w i:\program files\Didapages
2009-03-22 07:59 --------- d-----w i:\documents and settings\All Users\Application Data\Google Updater
2009-03-10 17:08 --------- d-----w i:\documents and settings\All Users\Application Data\LogMeIn
2009-03-08 19:25 --------- d-----w i:\program files\GameSpy Arcade
2009-03-08 19:25 --------- d-----w i:\program files\Cooking Academy
2009-03-07 09:31 --------- d-----w i:\documents and settings\YVES\Application Data\SQLyog
2009-03-03 18:09 --------- d-----w i:\program files\Fichiers communs\ParallelGraphics
2009-03-02 20:19 --------- d-----w i:\program files\Architecte_3D_Silver_Advanced
2009-03-02 15:51 --------- d-----w i:\program files\DAEMON Tools
2009-03-02 15:48 682,232 ----a-w i:\windows\system32\drivers\sptd.sys
2009-03-02 15:01 --------- d-----w i:\program files\Atari
2009-03-02 14:04 --------- d-----w i:\program files\FindyKill
2009-03-01 16:22 --------- d-----w i:\program files\Windows Live
2009-03-01 16:22 --------- d-----w i:\program files\Microsoft Silverlight
2009-03-01 16:21 --------- d-----w i:\program files\Microsoft Sync Framework
2009-03-01 08:25 --------- d-----w i:\program files\Intel
2009-03-01 08:25 --------- d-----w i:\program files\directx
2009-02-27 17:21 --------- d-----w i:\program files\Windows Live SkyDrive
2009-02-27 17:21 --------- d-----w i:\program files\Microsoft
2009-02-27 17:16 --------- d-----w i:\program files\Fichiers communs\Windows Live
2009-02-27 14:54 --------- d-----w i:\program files\SQLyog Enterprise Trial
2009-02-27 14:52 --------- d-----w i:\documents and settings\All Users\Application Data\Webyog
2009-02-25 17:49 --------- d-----w i:\program files\PremiumSoft
2009-02-25 16:37 --------- d-----w i:\program files\No-IP
2009-02-24 20:33 --------- d-----w i:\program files\K!TV
2009-02-23 20:44 --------- d-----w i:\program files\Alwil Software
2009-02-23 17:55 --------- d-----w i:\program files\FreeCell Light
2009-02-23 15:01 57,867 ----a-w I:\mdelk.exe
2009-02-23 13:21 --------- d-----w i:\documents and settings\All Users\Application Data\G DATA
2009-02-23 13:16 68,296 ----a-w i:\windows\system32\drivers\GRD.sys
2009-02-23 13:13 --------- d-----w i:\program files\G DATA
2009-02-23 13:13 --------- d-----w i:\program files\Fichiers communs\G DATA
2009-02-23 09:45 --------- d-----w i:\program files\Panda Security
2009-02-23 07:44 --------- d-----w i:\program files\CCleaner
2009-02-23 07:37 --------- d-----w i:\program files\Iminent
2009-02-16 11:03 --------- d-----w i:\program files\PhotoFiltre
2009-02-15 21:05 --------- d-----w i:\program files\Pinnacle
2009-02-15 21:05 --------- d-----w i:\program files\MSXML 4.0
2009-02-15 20:57 --------- d-----w i:\documents and settings\All Users\Application Data\Pinnacle
2009-02-15 18:25 --------- d-----w i:\program files\Google
2009-02-13 17:44 --------- d-----w i:\program files\Zylom Games
2009-02-13 17:41 --------- d-----w i:\documents and settings\YVES\Application Data\Ancient Quest of Saqqarah__bfg
2009-02-13 17:36 --------- d-----w i:\documents and settings\YVES\Application Data\Saqqarah
2009-02-13 12:19 --------- d-----w i:\documents and settings\YVES\Application Data\Ancient Quest of Saqqarah__gamehouse
2009-02-13 12:11 --------- d-----w i:\documents and settings\YVES\Application Data\Zylom
2002-07-01 14:13 224 --sha-w i:\documents and settings\YVES\Application Data\maildriver32.dat
.
------- Sigcheck -------
2005-06-28 19:56 359808 77c0c5e7d6cfe2052b8cf28b8722f528 i:\windows\system32\drivers\tcpip.sys
2005-03-02 20:13 2181632 3e2a0a4a0c0b19fc113618a9562a3b2a i:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2005-03-02 20:08 2181376 63729dd0f2aae36cc52b89c05505146c i:\windows\Driver Cache\i386\ntoskrnl.exe
2005-06-16 00:00 2321152 bebb29fbd9c14448a7bc12204a362d9e i:\windows\system32\ntoskrnl.exe
2005-06-16 00:01 1036288 cc5b99af6247175a151b0cc4e71c7f58 i:\windows\explorer.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="i:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"msnmsgr"="i:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DAEMON Tools"="i:\program files\DAEMON Tools\daemon.exe" [2007-04-04 165784]
"DownloadAccelerator"="i:\program files\DAP\DAP.EXE" [2008-12-18 3114496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X1100 Series"="i:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"SunJavaUpdateSched"="i:\program files\Java\jre6\bin\jusched.exe" [2008-12-20 136600]
"avast!"="i:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"LogMeIn GUI"="i:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-09-12 63048]
"LogitechVideoRepair"="i:\program files\Logitech\Video\ISStart.exe" [2004-02-12 188416]
"LogitechVideoTray"="i:\program files\Logitech\Video\LogiTray.exe" [2004-02-12 77824]
"QuickTime Task"="i:\program files\QuickTime\qttask.exe" [2009-04-03 77824]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 i:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="i:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"LSD_III"="i:\windows\LSD\end.cmd" [2005-07-14 2310]
"tscuninstall"="i:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 21:35 87352 i:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
--a------ 2008-12-18 17:56 3114496 i:\program files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\G DATA AntiVirus Trayapplication]
--a------ 2009-02-23 20:00 996424 i:\program files\G DATA\AntiVirus\AVKTray\AVKTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a------ 2008-12-09 12:12 234856 i:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\Program Files\\Metin2_France\\metin2.bin"=
"i:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"i:\\Program Files\\7-Zip\\7zFM.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Program Files\\Team17 Software Ltd\\Worms Forts Under Siege\\WF.exe"=
"c:\\Program Files\\Monte Cristo\\Fire Department 2\\Fire.exe"=
"i:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"i:\\Program Files\\TightVNC\\WinVNC.exe"=
"i:\\Program Files\\EasyPHP 3.0\\mysql\\bin\\mysqld.exe"=
"i:\\Program Files\\uTorrent\\uTorrent.exe"=
"i:\\Program Files\\RV House\\rv_house.exe"=
"i:\\WINDOWS\\system32\\dplaysvr.exe"=
"i:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\everest 1\\config\\zaap\\test\\Launcher.exe"=
"i:\\WINDOWS\\system32\\LEXPPS.EXE"=
"i:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"d:\\BAZARCESLAS\\serv\\core\\core mangos 3.0.9 final\\realmd.exe"=
"d:\\BAZARCESLAS\\serv\\core\\core mangos 3.0.9 final\\mangosd.exe"=
"i:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"i:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"i:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"i:\\Program Files\\PremierOpinion\\pmropn.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"37756:TCP"= 37756:TCP:emule
"40812:UDP"= 40812:UDP:eemul
R1 aswSP;avast! Self Protection;i:\windows\system32\drivers\aswSP.sys [2009-04-08 114768]
R1 GRD;G DATA Rootkit Detector Driver;i:\windows\system32\drivers\GRD.sys [2009-02-23 68296]
R2 aswFsBlk;aswFsBlk;i:\windows\system32\drivers\aswFsBlk.sys [2009-04-08 20560]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\LogMeIn\x86\rainfo.sys [2007-09-12 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2009-03-10 47640]
R2 SeaPort;SeaPort;i:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?]
R3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;i:\windows\system32\drivers\3xHybrid.sys [2008-12-02 1121536]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;i:\windows\system32\drivers\ManyCam.sys [2008-01-14 21632]
S0 pavboot;pavboot;i:\windows\system32\drivers\pavboot.sys --> i:\windows\system32\drivers\pavboot.sys [?]
S2 gupdate1c98f9a83811942;Service Google Update (gupdate1c98f9a83811942);i:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
S3 Droppix Service;Droppix Service;i:\program files\Fichiers communs\Droppix\DxService.exe [2008-12-03 221184]
S3 maconfservice;Ma-Config Service;i:\program files\ma-config.com\maconfservice.exe [2009-03-15 216232]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f3b1086-c513-11dd-b74a-a624a08d4999}]
\Shell\AutoRun\command - K:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{467e6f41-e08b-11dd-b793-0019214c0161}]
\Shell\AutoRun\command - M:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4eaf1d58-d7fc-11dd-b784-0008d3300302}]
\Shell\AutoRun\command - L:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{905c2f36-fa74-11dd-b7be-0019214c0161}]
\Shell\AutoRun\command - L:\setupSNK.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-24 i:\windows\Tasks\Google Software Updater.job
- i:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 08:52]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{A6E9BAAF-53CD-4575-967B-2AF710A7D21F} - (no file)
HKCU-Run-PMCRemote - (no file)
MSConfigStartUp-Microsoft WinUpdate - i:\windows\system32\msupdte.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/home
uSearchURL,(Default) = hxxp://www.google.fr/keyword/%s
IE: &Clean Traces - i:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - i:\program files\DAP\dapextie.htm
IE: Download &all with DAP - i:\program files\DAP\dapextie2.htm
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - i:\program files\Skyline\TerraExplorer\TerraExplorerX.dll
FF - ProfilePath - i:\documents and settings\YVES\Application Data\Mozilla\Firefox\Profiles\[u]0/u67baopd.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: i:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: i:\program files\Mozilla Firefox\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}\components\avkwebfilterff.dll
FF - component: i:\program files\PremierOpinion\components\pmxg.dll
FF - plugin: i:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: i:\documents and settings\YVES\Application Data\Mozilla\Firefox\Profiles\[u]0/u67baopd.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: i:\documents and settings\YVES\Application Data\Mozilla\Firefox\Profiles\[u]0/u67baopd.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: i:\documents and settings\YVES\Application Data\Mozilla\Firefox\Profiles\[u]0/u67baopd.default\extensions\OberonGameHost@OberonGames.com\platform\WINNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: i:\program files\Fichiers communs\ParallelGraphics\Cortona\npCortona.dll
FF - plugin: i:\program files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll
FF - plugin: i:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: i:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npCortona.dll
FF - plugin: i:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-11 19:20:33
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-448539723-926492609-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E183DADE-E696-524A-E24A-36193F048FD8}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abhjmajeicebplkbbkhapliflcdeognakd"=hex:61,62,66,69,6c,6a,62,6b,6d,6c,6f,6d,
63,6e,70,70,64,6c,6b,63,64,61,6e,6f,65,68,65,70,6b,62,67,6a,6c,61,00,77
"bbhjmajeicebplkbbkabmjgabegcejekcgnh"=hex:61,62,61,69,6c,6b,65,64,6e,65,66,69,
66,6b,65,64,65,64,6d,6e,70,68,6f,68,61,6a,61,63,61,6f,70,6d,61,61,00,77
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,5d,3b,89,ae,1d,
77,a4,e4,e2,63,26,f1,3f,c8,ff,68,1a,af,67,9d,96,93,c1,bb,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,8f,32,01,f5,41,
ee,c0,48,6a,9c,d6,61,af,45,84,18,f5,04,0a,af,6f,71,b6,e2,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,1d,91,e5,c0,3d,
33,31,c5,ff,7c,85,e0,43,d4,0e,fe,b9,ac,f6,e2,dd,63,e8,3b,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,ba,12,bf,52,33,
a0,c8,25,86,8c,21,01,be,91,eb,e7,41,42,c8,d2,f6,29,f8,3e,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,4d,ee,0c,85,b0,
9d,d7,10,f5,1d,4d,73,a8,13,5c,05,26,80,9e,4d,1d,a4,a3,89,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,90,22,b4,b3,fd,
df,95,2b,df,20,58,62,78,6b,cf,c8,12,49,92,89,8f,05,d2,bc,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,47,e3,de,57,e8,
d3,af,bb,fb,a7,78,e6,12,2f,9a,ea,51,43,d9,71,e6,0d,08,51,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,7e,9c,d7,f7,32,
ed,dd,aa,01,3a,48,fc,e8,04,4a,f1,af,8e,42,a5,5c,49,10,33,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,45,de,54,aa,7f,
d9,a8,cd,f6,0f,4e,58,98,5b,89,c9,c8,de,af,32,c3,00,0f,54,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,ae,69,b7,93,84,
fc,f8,c1,3d,ce,ea,26,2d,45,aa,78,c2,16,1f,17,b3,16,ac,b8,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,d7,8c,e0,77,ac,
8f,57,3e,2a,b7,cc,b5,b9,7f,41,e7,7a,87,4a,cd,ff,a5,af,83,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="i:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,37,8c,d6,1e,29,
47,a5,06,6c,43,2d,1e,aa,22,2f,9c,7e,81,be,25,20,cc,20,d3,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(968)
i:\windows\system32\Ati2evxx.dll
i:\windows\system32\LMIinit.dll
.
------------------------ Autres processus actifs ------------------------
.
i:\program files\Alwil Software\Avast4\aswUpdSv.exe
i:\program files\Alwil Software\Avast4\ashServ.exe
i:\windows\system32\LEXBCES.EXE
i:\windows\system32\LEXPPS.EXE
i:\windows\system32\netdde.exe
i:\windows\system32\dllhost.exe
i:\windows\system32\imapi.exe
i:\program files\Java\jre6\bin\jqs.exe
i:\program files\LogMeIn\x86\ramaint.exe
i:\program files\LogMeIn\x86\LogMeIn.exe
i:\program files\LogMeIn\x86\LMIGuardian.exe
i:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
i:\windows\system32\rundll32.exe
i:\program files\Lexmark X1100 Series\lxbkbmon.exe
i:\program files\LogMeIn\x86\LMIGuardian.exe
i:\windows\system32\LVComS.exe
i:\program files\Alwil Software\Avast4\ashMaiSv.exe
i:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Heure de fin: 2009-04-11 19:23:16 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-11 17:23:13
Avant-CF: 8 500 862 976 octets libres
Après-CF: 8,439,902,208 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
406