Voici le contenu du log :
ComboFix 09-04-25.A3 - Mathieu 27/04/2009 15:18.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.1163 [GMT 2:00]
Lancé depuis: E:\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated)
FW: Norton Internet Security *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\AutoRun.inf
c:\windows\system32\durunora.dll
c:\windows\system32\ejigopiv.ini
c:\windows\system32\gahehani.dll
c:\windows\system32\negonito.dll
c:\windows\system32\tadebava.dll
c:\windows\system32\vipogije.dll
c:\windows\system32\yemikome.dll
----- BITS: Il y a peut-être des sites infectés -----
hxxp://83.149.105.228
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-27 au 2009-4-27 ))))))))))))))))))))))))))))))))))))
.
2009-04-27 08:24 . 2009-04-27 08:24 -------- d-----w c:\program files\Trend Micro
2009-04-27 07:39 . 2009-04-27 08:08 -------- d---a-w c:\users\All Users\TEMP
2009-04-27 07:39 . 2009-04-27 08:08 -------- d---a-w c:\programdata\TEMP
2009-04-27 07:39 . 2009-04-27 08:08 -------- d-----w c:\program files\Common Files\PC Tools
2009-04-27 07:39 . 2009-04-27 08:08 -------- d-----w c:\program files\Spyware Doctor
2009-04-26 18:18 . 2009-04-26 18:18 -------- d-----w c:\program files\Enigma Software Group
2009-04-17 18:30 . 2009-02-13 08:49 72704 ----a-w c:\windows\system32\secur32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 13:27 . 2008-09-30 20:00 -------- d-----w c:\users\Mathieu\AppData\Roaming\DNA
2009-04-27 13:27 . 2008-09-30 20:00 -------- d-----w c:\program files\DNA
2009-04-27 13:25 . 2007-12-27 21:33 1660 ----a-w c:\windows\bthservsdp.dat
2009-04-27 11:40 . 2006-11-02 15:48 681712 ----a-w c:\windows\System32\perfh00C.dat
2009-04-27 11:40 . 2006-11-02 15:48 128882 ----a-w c:\windows\System32\perfc00C.dat
2009-04-27 11:24 . 2008-09-30 20:00 -------- d-----w c:\users\Mathieu\AppData\Roaming\BitTorrent
2009-04-27 10:31 . 2009-02-27 12:54 -------- d-----w c:\programdata\FLEXnet
2009-04-27 07:17 . 2009-01-27 07:17 60928 --sha-w c:\windows\System32\motipewo.exe
2009-04-26 18:07 . 2009-01-26 18:07 59904 --sha-w c:\windows\System32\niwofuzu.exe
2009-04-18 19:35 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-18 19:27 . 2007-08-30 18:24 -------- d-----w c:\programdata\Microsoft Help
2009-03-28 12:35 . 2009-03-28 12:35 -------- d-----w c:\program files\Microsoft
2009-03-28 12:35 . 2009-03-28 12:35 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-28 12:35 . 2008-03-01 13:01 -------- d-----w c:\program files\Windows Live
2009-03-28 12:33 . 2009-03-28 12:33 -------- d-----w c:\program files\Common Files\Windows Live
2009-03-24 13:38 . 2008-08-13 16:21 -------- d-----w c:\users\Mathieu\AppData\Roaming\Canon
2009-03-22 13:26 . 2007-08-30 16:51 1356 ----a-w c:\users\Mathieu\AppData\Local\d3d9caps.dat
2009-03-17 03:38 . 2009-04-17 18:30 40960 ----a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-17 18:30 13824 ----a-w c:\windows\System32\apilogen.dll
2009-03-17 03:38 . 2009-04-17 18:30 24064 ----a-w c:\windows\System32\amxread.dll
2009-03-09 17:24 . 2007-08-29 16:16 120248 ----a-w c:\users\Mathieu\AppData\Local\GDIPFONTCACHEV1.DAT
2009-03-03 04:46 . 2009-04-17 18:31 3599328 ----a-w c:\windows\System32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-17 18:31 3547632 ----a-w c:\windows\System32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-17 18:30 827392 ----a-w c:\windows\System32\wininet.dll
2009-03-03 04:39 . 2009-04-17 18:31 183296 ----a-w c:\windows\System32\sdohlp.dll
2009-03-03 04:39 . 2009-04-17 18:31 551424 ----a-w c:\windows\System32\rpcss.dll
2009-03-03 04:39 . 2009-04-17 18:31 26112 ----a-w c:\windows\System32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-17 18:30 78336 ----a-w c:\windows\System32\ieencode.dll
2009-03-03 04:37 . 2009-04-17 18:31 98304 ----a-w c:\windows\System32\iasrecst.dll
2009-03-03 04:37 . 2009-04-17 18:31 54784 ----a-w c:\windows\System32\iasads.dll
2009-03-03 04:37 . 2009-04-17 18:31 44032 ----a-w c:\windows\System32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-17 18:31 666624 ----a-w c:\windows\System32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-17 18:31 17408 ----a-w c:\windows\System32\iashost.exe
2009-03-03 02:28 . 2009-04-17 18:30 26624 ----a-w c:\windows\System32\ieUnatt.exe
2009-02-27 12:50 . 2008-05-26 12:22 -------- d-----w c:\program files\Common Files\Adobe
2009-02-27 12:46 . 2009-02-27 12:46 -------- d-----w c:\program files\Common Files\Adobe AIR
2009-02-27 12:41 . 2009-02-27 12:41 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-02-27 10:30 . 2007-04-18 05:56 -------- d--h--w c:\program files\InstallShield Installation Information
2009-02-16 21:32 . 2009-02-16 21:32 268 ---ha-w C:\sqmdata02.sqm
2009-02-16 21:32 . 2009-02-16 21:32 244 ---ha-w C:\sqmnoopt02.sqm
2009-02-16 12:57 . 2009-02-16 12:57 268 ---ha-w C:\sqmdata01.sqm
2009-02-16 12:57 . 2009-02-16 12:57 244 ---ha-w C:\sqmnoopt01.sqm
2009-02-13 08:49 . 2009-04-17 18:30 1255936 ----a-w c:\windows\System32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 08:45 2033152 ----a-w c:\windows\System32\win32k.sys
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\System32\sirenacm.dll
2008-10-07 06:55 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2008-07-08 17:47 . 2007-12-02 17:45 112792 ----a-w c:\users\Invité\AppData\Local\GDIPFONTCACHEV1.DAT
2008-02-04 17:15 . 2008-02-04 17:15 95 ----a-w c:\users\Mathieu\AppData\Local\fusioncache.dat
2007-12-23 22:42 . 2007-12-23 22:42 22328 ----a-w c:\users\Mathieu\AppData\Roaming\PnkBstrK.sys
2006-05-06 16:2007-10-08 19:25 42:04 . c:\program files\mozilla firefox\plugins\libvlc.dll
2007-09-12 15:42 . 2007-09-11 16:29 16384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-12 15:42 . 2007-09-11 16:29 32768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-12 15:42 . 2007-09-11 16:29 16384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2009-01-25 17:06 . 2009-01-25 17:06 2724 --sh--w c:\windows\System32\gomujude.exe
2009-01-25 17:05 . 2009-01-25 17:05 2724 --sh--w c:\windows\System32\rijiraza.dll
2009-01-25 17:05 . 2009-01-25 17:05 2724 --sh--w c:\windows\System32\weduriwi.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2006-11-13 413696]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 577536]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-05-23 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-07-27 898344]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-06-13 4489216]
"NDSTray.exe"="NDSTray.exe" [BU]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-06-12 56080]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Monitor.lnk - c:\program files\TOSHIBA\Bluetooth Monitor\BtMon2.exe [2007-12-27 69632]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-12-25 768528]
PDFCreator.lnk - c:\program files\PDFCreator\PDFCreator.exe [2008-8-22 2641920]
Privoxy.lnk - c:\program files\Privoxy\privoxy.exe [2008-1-20 302080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{C17FD58C-E468-43CF-8740-013F3BEE5AD4}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{01662EFA-5C0A-46EF-AAEF-E6C8A17683B8}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"{2F150D09-21B0-446F-99CA-1BB1262716AC}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DA20FF16-05E6-4FE9-BAAD-B8885CFA3202}"= UDP:c:\program files\THQ\Gas Powered Games\Supreme Commander\bin\SupremeCommander.exe:Supreme Commander
"{48842214-3FB3-4706-8E96-2FFF8B43055D}"= TCP:c:\program files\THQ\Gas Powered Games\Supreme Commander\bin\SupremeCommander.exe:Supreme Commander
"{6473950F-B1ED-47A5-A488-D715291C32BD}"= UDP:c:\program files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{896EA52F-F8ED-44E1-BDD5-13E1A4A72098}"= TCP:c:\program files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{DF2F36E9-FB0C-42EF-B319-2D2FA3AF8BB4}"= UDP:20647:BitComet 20647 TCP
"{1C24333C-F1C4-46F8-9330-16D4DF744720}"= TCP:20647:BitComet 20647 UDP
"TCP Query User{114A8054-8827-4FBE-A686-870C81C122A5}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{ECB23EBE-4290-49B8-9A8D-227C6B0B41E9}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{0B751855-E7FB-4BDA-B3B8-F6C116CBDE83}"= UDP:20647:BitComet 20647 TCP
"{6A6522EA-A91E-46E8-B894-71318D362EC7}"= TCP:20647:BitComet 20647 UDP
"TCP Query User{D44D6312-4F30-4DFC-AC54-0B26799D5036}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{179A0875-EA34-4457-A147-F03BA2765463}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{14BC9585-E946-42CF-A933-DFEC4486BCB7}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{46B28561-E2AA-4EAF-8B11-3DB44C85074B}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{BBA6320F-68DB-4F31-B1B3-1E9509F55A3E}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{88898F6B-5442-4432-8E1B-7CDFFCCA2FB2}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{B85B425A-4B16-4AFA-A3CA-FA27B8A4AA4F}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{1627BB75-3A2D-4AF1-9474-BC0221540FDF}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{43C8185D-13F3-4AD0-81E7-92289E3A198A}"= UDP:c:\program files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander - Forged Alliance
"{207C9F6E-2DD0-410B-9619-A42A1D6C5729}"= TCP:c:\program files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander - Forged Alliance
"TCP Query User{0A982CDF-0196-4400-B0F2-5D5963F783CF}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{A0CCB9F4-78F0-4BC0-807C-8AD70D4730FD}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"TCP Query User{BB50E6CE-63AB-471E-863E-B1C56BF26323}c:\\program files\\codemasters\\le seigneur des anneaux online\\lotroclient.exe"= UDP:c:\program files\codemasters\le seigneur des anneaux online\lotroclient.exe:lotroclient
"UDP Query User{8B05F3C3-1747-4AC7-8ACA-D41319923840}c:\\program files\\codemasters\\le seigneur des anneaux online\\lotroclient.exe"= TCP:c:\program files\codemasters\le seigneur des anneaux online\lotroclient.exe:lotroclient
"{0E6A817A-A2A7-4728-AA50-1A90F026C3F1}"= Disabled:UDP:c:\users\Mathieu\AppData\Local\Temp\7zS12D4.tmp\setup\HPZnui01.exe:hpznui01.exe
"{362FC288-C350-49D6-AD4C-0CABA375FCFC}"= Disabled:TCP:c:\users\Mathieu\AppData\Local\Temp\7zS12D4.tmp\setup\HPZnui01.exe:hpznui01.exe
"{1CFF4C16-07AB-4B9E-BF50-3FB60E6D1930}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{EF802440-19CE-4600-AD09-1EF76AC151F2}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"TCP Query User{BB36846E-BE37-4569-A6CB-BBB874B483E5}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{1F72A5FB-1D77-458B-8569-702EEDC29207}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{1BF966CD-17D1-4587-AEF1-ECF561A7B363}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{FE436A45-15A2-4765-B771-43766F4321C8}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"TCP Query User{4BB65AD7-8844-4F4C-9084-4D9CA84ABD6B}c:\\program files\\codemasters\\grid\\grid.exe"= UDP:c:\program files\codemasters\grid\grid.exe:GRID Executable
"UDP Query User{4119E5A7-A1FE-40CD-BBC1-DB348B6A0F65}c:\\program files\\codemasters\\grid\\grid.exe"= TCP:c:\program files\codemasters\grid\grid.exe:GRID Executable
"TCP Query User{3A6A3401-5871-41B6-A747-16953FF7A9F1}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{8895B15A-C1AB-401E-A710-60EAC434F557}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{AB88740D-9BC2-43E2-A31F-DA37BEF41A1D}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{D6A0A412-19E7-4F9D-9987-458232D862D6}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{92B21884-1870-4B56-ABD5-75ECCEEEB12C}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire Demo\Sins of a Solar Empire.exe:Sins of a Solar Empire Demo
"{BD48339A-AA18-4F46-8EFB-23B8DD99118E}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire Demo\Sins of a Solar Empire.exe:Sins of a Solar Empire Demo
"{8DFD3D7C-75A0-4A05-A895-4FA34BFB2E9E}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{2174B509-A80E-430D-92A7-06F98CC4D292}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{05FCD87F-D6D7-43CA-A95A-F59ABC1A39EA}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{DC5F63C1-3F94-4DD8-8E75-4D236591FF73}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"{3926622F-D394-44CC-9C1E-307A1511B426}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{62C3D44A-3333-4E5D-A929-D92A618810DE}"= TCP:c:\program files\DNA\btdna.exe:DNA
"TCP Query User{75FA424E-C52F-4A95-BB97-46B92DA1E4B2}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:µTorrent
"UDP Query User{10F98339-9AA9-4FB1-9DB2-53EB1E9DA68B}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:µTorrent
"{FCC77B0A-DB7C-4DB7-A23D-3763A78B883C}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{F83FE272-10B5-4D05-B039-5FCB38FA050F}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{E4A7DE03-493B-45EC-A939-8809CB0308C8}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{9A24A6A4-91D8-4D74-A61F-5D8761B06698}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{88D12974-3423-42AC-9DAA-C0C124A91C69}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{693AEB08-C45B-4A2A-8F50-0CAEBA4583B3}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"TCP Query User{19465AEE-93B5-4FAB-AEF9-F30D70DE5CB3}e:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= UDP:e:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"UDP Query User{80370109-CBFB-4552-9BAD-E86982824A3C}e:\\jeux\\rockstar games\\grand theft auto iv\\gtaiv.exe"= TCP:e:\jeux\rockstar games\grand theft auto iv\gtaiv.exe:Grand Theft Auto IV
"{31CBE5F3-F11E-449E-8E90-FBED1E231398}"= UDP:e:\jeux\Empire of Sports\NetworkDiagnostic.exe:Empire of Sports Network Diagnostic
"{C7308AC7-AD07-4F28-A47E-CFB5311FFB92}"= TCP:e:\jeux\Empire of Sports\NetworkDiagnostic.exe:Empire of Sports Network Diagnostic
"{DA3D4369-1A96-476B-AE39-A76BC7E53CC0}"= UDP:e:\jeux\Empire of Sports\EmpireOfSports.exe:Empire of Sports
"{9D1E6B58-C090-4D27-BE91-AEA627A62ABA}"= TCP:e:\jeux\Empire of Sports\EmpireOfSports.exe:Empire of Sports
"{48F041E2-AE01-4BE9-97C8-FBEEDF7ADBED}"= UDP:c:\users\Mathieu\AppData\Local\F4\ClientUpdater\ClientUpdater.exe:F4 Game Client Updater
"{D815693D-6C67-47B8-A2F9-FF4A183EAB6D}"= TCP:c:\users\Mathieu\AppData\Local\F4\ClientUpdater\ClientUpdater.exe:F4 Game Client Updater
"{13481FA8-189A-4E5B-B964-BFC19C082EF0}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{B6564680-1063-452F-B437-57B3FE69E349}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{76A68C4C-8638-4373-8921-29C09B60F26F}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{482F48B7-C5A7-455A-B6A4-753BEA112E50}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{2798D282-9245-424A-9FDD-F978E1587BB2}"= UDP:5353:Adobe CSI CS4
"{7D133794-3BC8-4514-89E1-4015E50F402C}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{319A937B-ED38-4C5D-94DA-9A0A2F964CA9}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{D4207203-9F0C-40C1-B769-239C55D66A8F}"= UDP:c:\windows\explorer.exe:Explorer
"{3900517F-B44E-4A45-9B2C-A2CE53670195}"= UDP:c:\windows\explorer.exe:Explorer
"{03209B5B-5060-41C8-AB88-679CC8301D90}"= TCP:c:\windows\explorer.exe:Explorer
"{366FB8B1-FAAF-46A9-A0B6-C95FC48D7EBD}"= TCP:c:\windows\explorer.exe:Explorer
"{5623D4C4-CD28-4FAC-A61C-304FDDA2603B}"= UDP:c:\windows\explorer.exe:Explorer
"{9A7E3C20-A3DD-4745-8BCB-E68CE256AA79}"= TCP:c:\windows\explorer.exe:Explorer
"{454ADF16-C3E2-40B9-93D5-6358356D8337}"= UDP:c:\windows\System32\wininit.exe:wininit
"{C89483DC-0F10-4050-B180-A51413F921D6}"= TCP:c:\windows\System32\wininit.exe:wininit
"{88B1A3F1-4254-4AEE-A7D1-471F6C8E66C4}"= UDP:c:\windows\System32\wininit.exe:wininit
"{97544B1E-428F-4C19-BAFB-807F0C1BEBD5}"= TCP:c:\windows\System32\wininit.exe:wininit
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R3 ACSET;XIRING USB Smart Card Reader;c:\windows\system32\DRIVERS\acr30up.sys [2007-07-23 31488]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]
R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
R3 TpChoice;Touch Pad Detection Filter driver; [x]
S0 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b47c047e-e6a8-11dc-8cad-000272c929e8}]
\shell\AutoRun\command - D:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-26 c:\windows\Tasks\User_Feed_Synchronization-{F421484C-BC9D-4FAC-8E10-41A0402A3929}.job
- c:\windows\system32\msfeedssync.exe [2008-06-25 07:33]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{da058c55-726e-49e5-bcac-a388c65cff33} - c:\windows\system32\gahehani.dll
HKCU-Run-AdobeBridge - (no file)
HKLM-Run-HWSetup - \HWSetup.exe
.
------- Examen supplémentaire -------
.
uStart Page = go.microsoft.com/fwlink/?LinkId=69157
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer à &Bluetooth - c:\program files\MSI\BToes Logiciel Bluetooth\btsendto_ie_ctx.htm
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR
Trusted Zone: mappy.com
Trusted Zone: orange.fr
Trusted Zone: voila.fr\rw.search.ke
Trusted Zone: weborama.fr\orange
DPF: {C85DB634-9EDE-11D4-BC59-00A04B0658BF} - hxxp://www.escrime-ffe.fr/support/NPSiAuth.cab
FF - ProfilePath - c:\users\Mathieu\AppData\Roaming\Mozilla\Firefox\Profiles\sfk1tyhh.default\
FF - prefs.js: browser.startup.homepage - hxxp://escrime-peronnas.over-blog.com/
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvlc.dll
FF - plugin: c:\users\Mathieu\AppData\Roaming\Mozilla\Firefox\Profiles\sfk1tyhh.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-27 15:28
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0
/u000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0
/u001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(4996)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\System32\conime.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\System32\PnkBstrA.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Logitech\KhalShared\KHALMNPR.exe
c:\program files\TOSHIBA\ConfigFree\CFSwMgr.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-04-27 15:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-27 13:33
Avant-CF: 5 220 298 752 octets libres
Après-CF: 5 083 111 424 octets libres
343 --- E O F --- 2009-04-21 08:08