Voila le rapport de combofix, apré pas mal de redémarrage ,(j'ai du redémaré mon ordinateur on mode sans echek car si je redémarre en mode normal mon ordinateur se bloque p.s pouré tu m'éclairé sur ce probleme)
merci.
ComboFix 09-05-26.02 - karim 26/05/2009 22:20.2 - NTFSx86 NETWORK
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.511.349 [GMT 2:00]
Lancé depuis: c:\documents and settings\karim\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090525-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Exécution préalable -------
.
c:\documents and settings\karim\Local Settings\Application Data\eqmwg.dat
c:\documents and settings\karim\Local Settings\Application Data\eqmwg.exe
c:\documents and settings\karim\Local Settings\Application Data\eqmwg_navps.dat
c:\documents and settings\karim\protect.dll
c:\documents and settings\LocalService\Application Data\sysproc64
c:\documents and settings\LocalService\Application Data\sysproc64\sysproc32.sys
c:\documents and settings\LocalService\protect.dll
c:\documents and settings\Mr et Mme ADJADJ\Application Data\pidle
c:\documents and settings\Mr et Mme ADJADJ\Application Data\pidle\pidle.exe
c:\documents and settings\Mr et Mme ADJADJ\Application Data\QUAD Backups
c:\documents and settings\Mr et Mme ADJADJ\Favoris\Online Security Test.url
c:\documents and settings\Mr et Mme ADJADJ\Local Settings\Application Data\sigqy.dat
c:\documents and settings\Mr et Mme ADJADJ\Local Settings\Application Data\sigqy.exe
c:\documents and settings\Mr et Mme ADJADJ\Local Settings\Application Data\sigqy_nav.dat
c:\documents and settings\Mr et Mme ADJADJ\Local Settings\Application Data\sigqy_navps.dat
c:\documents and settings\Mr et Mme ADJADJ\protect.dll
c:\documents and settings\NetworkService\Application Data\sysproc64
c:\documents and settings\NetworkService\Application Data\sysproc64\sysproc32.sys
c:\documents and settings\NetworkService\protect.dll
c:\program files\Online Video Add-on
c:\program files\Online Video Add-on\isfmm.exe
c:\program files\Online Video Add-on\ot.ico
c:\program files\Online Video Add-on\ts.ico
c:\program files\QUAD Utilities
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
c:\program files\ThunMail
c:\program files\ThunMail\testabd.dll
c:\program files\video activex access
c:\windows\cookies.ini
c:\windows\ld08.exe
c:\windows\pack.epk
c:\windows\pp10.exe
c:\windows\st_1242783347.exe
c:\windows\system32\__c00C6B10.dat
c:\windows\system32\a9k.bin
c:\windows\system32\acuvsdsy.ini
c:\windows\system32\aeapqija.ini
c:\windows\system32\agjfwyfd.ini
c:\windows\system32\agoplyiv.ini
c:\windows\system32\ahtn.htm
c:\windows\system32\ahxsjyeq.ini
c:\windows\system32\aicubcal.ini
c:\windows\system32\akpbvelf.ini
c:\windows\system32\aondiwpl.ini
c:\windows\system32\appgkecx.ini
c:\windows\system32\aucwgrja.ini
c:\windows\system32\autochk.dll
c:\windows\system32\btvycrsr.ini
c:\windows\system32\buuctphi.ini
c:\windows\system32\bvuwjgsj.ini
c:\windows\system32\cjyweepo.ini
c:\windows\system32\cmkcxplg.ini
c:\windows\system32\cnqlkjhg.ini
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\cqbqyjyv.ini
c:\windows\system32\cvqvjknw.ini
c:\windows\system32\cwwjmlsv.ini
c:\windows\system32\cwyeayrv.ini
c:\windows\system32\dbbatsqh.ini
c:\windows\system32\dfjqerfq.ini
c:\windows\system32\dgtlryap.ini
c:\windows\system32\dhbfwsgj.ini
c:\windows\system32\dlggwqaf.ini
c:\windows\system32\dlgkojsr.ini
c:\windows\system32\dnlesllt.ini
c:\windows\system32\dosojosl.ini
c:\windows\system32\drivers\ovfsthptnkpkbpfovmatimlwfbfolwxscdjbav.sys
c:\windows\system32\drxcyfkm.ini
c:\windows\system32\dsxgimsu.ini
c:\windows\system32\eegakwvf.ini
c:\windows\system32\eeogbwsi.ini
c:\windows\system32\eeuyssax.ini
c:\windows\system32\eidqurkg.ini
c:\windows\system32\ekvgrvpa.ini
c:\windows\system32\emrdniul.ini
c:\windows\system32\enqfhdbs.ini
c:\windows\system32\epbutcrl.ini
c:\windows\system32\epcmwmkg.ini
c:\windows\system32\ertiyvxt.ini
c:\windows\system32\etewvcgi.ini
c:\windows\system32\ewcvqgxg.ini
c:\windows\system32\fbtvpmwj.ini
c:\windows\system32\fhanexyi.ini
c:\windows\system32\fhjyojph.ini
c:\windows\system32\fmeniqrx.ini
c:\windows\system32\fnrgfjhv.ini
c:\windows\system32\fqlongjq.ini
c:\windows\system32\frmwrk32.exe
c:\windows\system32\fsiwtqvl.ini
c:\windows\system32\fsqecbsd.ini
c:\windows\system32\fsxmgkei.ini
c:\windows\system32\ftoajvxx.ini
c:\windows\system32\fvhyuopk.ini
c:\windows\system32\fvlfcjns.ini
c:\windows\system32\fwrucrew.ini
c:\windows\system32\fxadjpqj.ini
c:\windows\system32\gaeldlqn.ini
c:\windows\system32\gbiqvcoa.ini
c:\windows\system32\gbpceqhq.ini
c:\windows\system32\gcakkqlo.ini
c:\windows\system32\gcalbxku.ini
c:\windows\system32\gdfcoywp.ini
c:\windows\system32\gfgkxqbk.ini
c:\windows\system32\glsetup.exe
c:\windows\system32\gpbubkpp.ini
c:\windows\system32\gsdbuepc.ini
c:\windows\system32\gsugitxg.ini
c:\windows\system32\gsvsykwy.ini
c:\windows\system32\gteiwgeg.ini
c:\windows\system32\gwqnnmni.ini
c:\windows\system32\hamfgmhs.ini
c:\windows\system32\hbqxlnnc.ini
c:\windows\system32\hdupgibb.ini
c:\windows\system32\hhaiebaq.ini
c:\windows\system32\hhcqjtia.ini
c:\windows\system32\hhummwlc.ini
c:\windows\system32\hjvgrujr.ini
c:\windows\system32\hofyvjsi.ini
c:\windows\system32\hoobqqtn.ini
c:\windows\system32\hqoghifn.ini
c:\windows\system32\huagrmrv.ini
c:\windows\system32\hutnhqsg.ini
c:\windows\system32\icdhiqce.ini
c:\windows\system32\ihhhyhpb.ini
c:\windows\system32\ijrjlbeq.ini
c:\windows\system32\ikpmlnfh.ini
c:\windows\system32\indtkhnm.ini
c:\windows\system32\ioktascj.ini
c:\windows\system32\iotpmexe.ini
c:\windows\system32\ipfwrd.sys
c:\windows\system32\ivtqnvch.ini
c:\windows\system32\jbwhdxps.ini
c:\windows\system32\jesmmqev.ini
c:\windows\system32\jfcvpthm.ini
c:\windows\system32\jjimupyo.ini
c:\windows\system32\jtveuhtn.ini
c:\windows\system32\kakbpqso.ini
c:\windows\system32\kfqejrwm.ini
c:\windows\system32\kjligvtn.ini
c:\windows\system32\kjtwftsy.ini
c:\windows\system32\knjtpuhq.ini
c:\windows\system32\krucyvcl.ini
c:\windows\system32\kvvwobhr.ini
c:\windows\system32\lbvwpjbx.ini
c:\windows\system32\ldgutjjn.ini
c:\windows\system32\ldijggui.ini
c:\windows\system32\ldnecrlw.ini
c:\windows\system32\leojajoj.ini
c:\windows\system32\lfoqsgkk.ini
c:\windows\system32\lhnojbfe.ini
c:\windows\system32\linjfbew.ini
c:\windows\system32\lkiobwvc.ini
c:\windows\system32\lmllm.bak1
c:\windows\system32\lmllm.bak2
c:\windows\system32\lmllm.ini
c:\windows\system32\lmllm.ini2
c:\windows\system32\lmllm.tmp
c:\windows\system32\lmn_setup.exe
c:\windows\system32\lmppcsetup.exe
c:\windows\system32\loader49.exe
c:\windows\system32\lrldwvja.ini
c:\windows\system32\lrtwmule.ini
c:\windows\system32\luaxkxvf.ini
c:\windows\system32\lvpcrbcc.ini
c:\windows\system32\lwagivrl.ini
c:\windows\system32\lxqxutrl.ini
c:\windows\system32\lyghqisl.ini
c:\windows\system32\makhxdjy.ini
c:\windows\system32\maldsvrg.ini
c:\windows\system32\mckmiocn.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\mejejuir.ini
c:\windows\system32\mgauowij.ini
c:\windows\system32\mictnfsh.ini
c:\windows\system32\mjafasoy.ini
c:\windows\system32\mkfsmqpd.ini
c:\windows\system32\mqsnrcko.ini
c:\windows\system32\mwgivwnk.ini
c:\windows\system32\ncbyiawt.ini
c:\windows\system32\ndcklwhx.ini
c:\windows\system32\ndwxomla.ini
c:\windows\system32\nebigygo.ini
c:\windows\system32\niekvhkd.ini
c:\windows\system32\nihtnows.ini
c:\windows\system32\nmhnctgr.ini
c:\windows\system32\ntdll64.exe
c:\windows\system32\nuqwkmmr.ini
c:\windows\system32\nvs2.inf
c:\windows\system32\nwipyatl.ini
c:\windows\system32\obitez.dat
c:\windows\system32\obitez_nav.dat
c:\windows\system32\obitez_navps.dat
c:\windows\system32\ocfkmrns.ini
c:\windows\system32\oembios.exe
c:\windows\system32\olmcariq.ini
c:\windows\system32\oosvaghl.ini
c:\windows\system32\oqsbsklw.ini
c:\windows\system32\otwngcri.ini
c:\windows\system32\ovfsthajcexbaanlswuwwxpsmtcmkdgasipbtq.dat
c:\windows\system32\ovfsthauesayujrqvglxocmbwsbfridmtqtmyu.dll
c:\windows\system32\ovfsthhrakxsonkpnrnbutjldswggobpostrbh.dll
c:\windows\system32\ovfsthrgosayxlhowrnrkfatkdksotwfxhyffj.dat
c:\windows\system32\ovfsthymrqroxxwfixmasrqupqmmmxewqlyxeu.dll
c:\windows\system32\p2hhr.bat
c:\windows\system32\pcupiogl.ini
c:\windows\system32\pekchpht.ini
c:\windows\system32\pidblhwl.ini
c:\windows\system32\pjjujcwc.ini
c:\windows\system32\pqnwtxav.ini
c:\windows\system32\ptsnjusj.ini
c:\windows\system32\pyikqqeq.ini
c:\windows\system32\qboidlsb.ini
c:\windows\system32\qgyebvpo.ini
c:\windows\system32\qivshpil.ini
c:\windows\system32\qkvcneuj.ini
c:\windows\system32\qmhspqsc.ini
c:\windows\system32\qnarvanl.ini
c:\windows\system32\qqojnwny.ini
c:\windows\system32\qvkvkoim.ini
c:\windows\system32\qxistjcd.ini
c:\windows\system32\rahcpvay.ini
c:\windows\system32\ramphlid.ini
c:\windows\system32\ratdtkou.ini
c:\windows\system32\rckyrbxs.ini
c:\windows\system32\rdccxvpv.ini
c:\windows\system32\rhtqrgew.ini
c:\windows\system32\rkreqkjm.ini
c:\windows\system32\roiejnuo.ini
c:\windows\system32\rqqqwfri.ini
c:\windows\system32\rsgsijev.ini
c:\windows\system32\rvgjnmvh.ini
c:\windows\system32\rvhcwwcm.ini
c:\windows\system32\rxivxksq.ini
c:\windows\system32\scvrtfdk.ini
c:\windows\system32\service-466.exe
c:\windows\system32\skkfsdjy.ini
c:\windows\system32\slucausp.ini
c:\windows\system32\ssdayxgy.ini
c:\windows\system32\suunyprv.ini
c:\windows\system32\swwsatrd.ini
c:\windows\system32\sxnxgyik.ini
c:\windows\system32\SYSDLL.exe
c:\windows\system32\sysproc64
c:\windows\system32\sysproc64\sysproc32.sys
c:\windows\system32\sysproc64\sysproc86.sys
c:\windows\system32\tbkkwkcw.ini
c:\windows\system32\tdmnpslk.ini
c:\windows\system32\tj.exe
c:\windows\system32\tksuookj.ini
c:\windows\system32\trjamxtp.ini
c:\windows\system32\tuvtoxqx.ini
c:\windows\system32\twpyjbcn.ini
c:\windows\system32\twylrcjh.ini
c:\windows\system32\udavwsdl.ini
c:\windows\system32\udvkabvj.ini
c:\windows\system32\uhpejwbi.ini
c:\windows\system32\unatcpwe.ini
c:\windows\system32\uniq.tll
c:\windows\system32\usluuigm.ini
c:\windows\system32\uuihcphm.ini
c:\windows\system32\uvcyxpns.ini
c:\windows\system32\uwchtbmd.ini
c:\windows\system32\uwtkohye.ini
c:\windows\system32\vgroxuki.ini
c:\windows\system32\vgyswlbx.ini
c:\windows\system32\vjdnepgu.ini
c:\windows\system32\vkhwasww.ini
c:\windows\system32\vkqxpclx.ini
c:\windows\system32\vmalngcx.ini
c:\windows\system32\vmycalsc.ini
c:\windows\system32\vp_setup.exe
c:\windows\system32\vpiulwjy.ini
c:\windows\system32\vpnsbvob.ini
c:\windows\system32\vuooflhp.ini
c:\windows\system32\vvvxsmdg.ini
c:\windows\system32\warning.gif
c:\windows\system32\wawimtbb.ini
c:\windows\system32\wcieknlw.ini
c:\windows\system32\wetyjbff.ini
c:\windows\system32\wgrlgwkx.ini
c:\windows\system32\wgvstmyp.ini
c:\windows\system32\wihxgcnm.ini
c:\windows\system32\wikcbbsi.ini
c:\windows\system32\wsibeveo.ini
c:\windows\system32\wttqsehc.ini
c:\windows\system32\wvuiiemc.ini
c:\windows\system32\wxnybmec.ini
c:\windows\system32\wyoqkfbg.ini
c:\windows\system32\xegxlafd.ini
c:\windows\system32\xenmevbb.ini
c:\windows\system32\xfaxnxkc.ini
c:\windows\system32\xgcynjsx.ini
c:\windows\system32\xhttowtt.ini
c:\windows\system32\xibnjmwo.ini
c:\windows\system32\xnobjrba.ini
c:\windows\system32\xorvurok.ini
c:\windows\system32\xpelcjcy.ini
c:\windows\system32\xtmaihcl.ini
c:\windows\system32\xvtmxomt.ini
c:\windows\system32\xybeg.bak1
c:\windows\system32\xybeg.ini
c:\windows\system32\xycdd.bak1
c:\windows\system32\xycdd.bak2
c:\windows\system32\xycdd.ini
c:\windows\system32\xycdd.ini2
c:\windows\system32\xycdd.tmp
c:\windows\system32\ybvivttr.ini
c:\windows\system32\yccpiipk.ini
c:\windows\system32\yeiifuyr.ini
c:\windows\system32\ytovotxs.ini
c:\windows\system32\ytygokoo.ini
c:\windows\system32\yxjonsyx.ini
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
-------\Service_asc3550p
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-26 au 2009-05-26 ))))))))))))))))))))))))))))))))))))
.
2009-05-26 16:17 . 2009-05-26 16:17 2 ---h--w c:\windows\sonce122730.dat
2009-05-26 16:17 . 2009-05-26 16:17 -------- d-----w c:\windows\system32\sysloc
2009-05-26 13:57 . 2009-05-26 13:57 -------- d-----w c:\program files\Trend Micro
2009-05-26 13:52 . 2009-03-09 19:06 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-05-26 13:52 . 2009-05-26 13:52 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-26 13:52 . 2009-03-12 08:17 2902048 -c--a-w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-26 13:51 . 2009-05-26 13:51 -------- d-----w c:\program files\Lavasoft
2009-05-26 13:51 . 2009-05-26 13:51 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-24 16:36 . 2009-05-24 16:36 2272 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-24 16:32 . 2009-05-24 16:33 -------- dc----w C:\c2536f6845e6d9ef93f737
2009-05-23 22:14 . 2009-05-24 16:36 -------- d-----w c:\documents and settings\karim\Application Data\dvdcss
2009-05-23 14:35 . 2009-05-23 14:35 -------- d-----w c:\documents and settings\karim\Application Data\Red Kawa
2009-05-23 11:53 . 2009-05-23 11:53 -------- d-----w c:\program files\MSBuild
2009-05-23 11:41 . 2009-05-24 16:34 -------- d-----w c:\windows\system32\XPSViewer
2009-05-23 11:40 . 2009-05-23 11:40 -------- d-----w c:\program files\Reference Assemblies
2009-05-23 11:39 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-05-22 21:27 . 2009-05-22 21:27 -------- d-----w c:\program files\Regensoft
2009-05-22 21:26 . 2009-05-22 21:26 -------- d-----w c:\program files\AviSynth 2.5
2009-05-22 21:26 . 2009-05-22 21:26 -------- d-----w c:\program files\Red Kawa
2009-05-22 15:20 . 2009-05-22 15:20 -------- d-----w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Mozilla
2009-05-21 10:14 . 2009-05-21 10:14 -------- d-----w c:\documents and settings\karim\Application Data\vlc
2009-05-21 09:43 . 2009-05-21 09:43 -------- d-----w c:\program files\PCOptimizer
2009-05-21 09:41 . 2009-05-21 09:41 -------- d-----w c:\program files\ma-config.com
2009-05-21 09:41 . 2009-05-21 09:41 -------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-05-21 09:40 . 2009-05-23 22:24 -------- d-----w c:\documents and settings\karim\Application Data\Apple Computer
2009-05-21 09:39 . 2009-03-19 14:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-21 09:39 . 2008-04-17 10:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-05-21 09:39 . 2009-05-21 09:39 -------- d-----w c:\program files\iPod
2009-05-21 09:38 . 2009-05-21 09:39 -------- d-----w c:\program files\iTunes
2009-05-21 09:38 . 2009-05-21 09:39 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-21 09:33 . 2009-05-21 09:33 -------- d-----w c:\program files\Apple Software Update
2009-05-21 09:30 . 2009-03-26 13:23 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-05-21 08:36 . 2009-05-21 08:37 -------- d-----w c:\program files\jv16 PowerTools
2009-05-21 08:34 . 2004-06-14 12:56 427864 ----a-w c:\windows\system32\XceedZip.dll
2009-05-21 08:32 . 2009-05-21 08:32 -------- d-----w c:\documents and settings\karim\Local Settings\Application Data\Downloaded Installations
2009-05-20 17:57 . 2009-05-20 17:57 -------- d-----w c:\program files\Intel Desktop Board
2009-05-20 17:02 . 2009-05-20 17:02 -------- d-----w c:\documents and settings\karim\Local Settings\Application Data\Apple
2009-05-19 17:16 . 2009-05-19 17:16 -------- d-----w c:\documents and settings\karim\Local Settings\Application Data\Identities
2009-05-17 20:51 . 2009-05-20 18:50 -------- d-----w c:\windows\system32\796525
2009-05-17 20:51 . 2009-05-17 20:51 190 -c--a-w C:\43214354.bat
2009-05-17 17:35 . 2009-05-17 17:35 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-05-15 18:40 . 2009-05-15 18:40 -------- d-----w c:\program files\Cyanide
2009-05-10 03:50 . 2009-05-10 03:50 -------- d-----w c:\windows\CACHE
2009-05-03 16:57 . 2009-05-03 16:58 -------- d-----w c:\documents and settings\karim\Local Settings\Application Data\ChessBase
2009-05-03 16:57 . 2009-05-03 16:58 -------- d-----w c:\documents and settings\karim\Application Data\ChessBase
2009-05-03 16:57 . 2009-05-10 17:05 -------- d-----w c:\program files\Fichiers communs\ChessBase
2009-05-03 16:57 . 2009-05-10 17:05 -------- d-----w c:\program files\ChessBase
2009-05-03 15:52 . 2009-05-26 19:41 -------- d-----w c:\documents and settings\karim\Application Data\Free Download Manager
2009-05-01 18:18 . 2009-05-01 18:18 -------- d-----w c:\documents and settings\karim\Local Settings\Application Data\Installer3124
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 16:43 . 2009-04-19 17:48 57960 ----a-w c:\documents and settings\karim\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-24 16:29 . 2004-08-05 12:00 84874 ----a-w c:\windows\system32\perfc00C.dat
2009-05-24 16:29 . 2004-08-05 12:00 510656 ----a-w c:\windows\system32\perfh00C.dat
2009-05-23 15:25 . 2009-04-07 10:52 -------- d-----w c:\documents and settings\Mr et Mme ADJADJ\Application Data\Free Download Manager
2009-05-23 15:11 . 2005-06-14 09:46 57960 ----a-w c:\documents and settings\Mr et Mme ADJADJ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-23 12:21 . 2009-04-24 17:05 8224 ----a-w c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-05-21 09:38 . 2008-01-26 20:07 -------- d-----w c:\program files\Fichiers communs\Apple
2009-05-21 09:37 . 2009-04-08 09:09 -------- d-----w c:\program files\Bonjour
2009-05-21 09:36 . 2005-09-30 17:22 -------- d-----w c:\program files\QuickTime
2009-05-20 19:24 . 2009-05-20 19:23 -------- d-----w c:\documents and settings\Administrateur\Application Data\Free Download Manager
2009-05-17 19:34 . 2008-05-29 12:20 -------- d-----w c:\program files\Steinberg
2009-05-08 12:31 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP85aa.tmp
2009-05-08 12:21 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8f01.tmp
2009-05-08 11:59 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8666.tmp
2009-05-08 11:50 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPd820.tmp
2009-05-08 11:45 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8f6e.tmp
2009-05-08 11:43 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9412.tmp
2009-05-08 11:36 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP90a7.tmp
2009-05-08 11:32 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9154.tmp
2009-05-08 11:30 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8feb.tmp
2009-05-08 11:28 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP90e6.tmp
2009-05-08 11:26 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP91df.tmp
2009-05-08 11:24 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9162.tmp
2009-05-08 11:22 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9153.tmp
2009-05-08 11:20 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP90e5.tmp
2009-05-08 11:18 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9173.tmp
2009-05-08 11:16 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9114.tmp
2009-05-08 11:14 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9903.tmp
2009-05-08 11:11 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP954c.tmp
2009-05-08 11:09 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9bd2.tmp
2009-05-08 10:31 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP954b.tmp
2009-05-08 10:28 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP954a.tmp
2009-05-08 10:25 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9450.tmp
2009-05-08 10:23 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP97fa.tmp
2009-05-08 10:18 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP91c0.tmp
2009-05-08 10:15 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9172.tmp
2009-05-08 10:13 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9376.tmp
2009-05-08 10:10 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP948f.tmp
2009-05-08 10:07 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP92aa.tmp
2009-05-08 10:04 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9829.tmp
2009-05-08 10:00 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa037.tmp
2009-05-08 09:56 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa317.tmp
2009-05-08 09:53 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa170.tmp
2009-05-08 09:49 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPbbfd.tmp
2009-05-08 09:46 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa2a8.tmp
2009-05-08 09:41 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa316.tmp
2009-05-08 09:37 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa7d8.tmp
2009-05-08 09:34 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPaad6.tmp
2009-05-08 09:33 . 2009-04-08 15:07 0 ----a-w c:\windows\system32\jqzgfpy.sys
2009-05-08 09:29 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa7c9.tmp
2009-05-08 09:26 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa72c.tmp
2009-05-08 09:24 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa73c.tmp
2009-05-08 09:22 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPabff.tmp
2009-05-08 09:18 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa70d.tmp
2009-05-08 09:16 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa6af.tmp
2009-05-08 09:14 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa817.tmp
2009-05-08 09:12 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa690.tmp
2009-05-08 09:10 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa681.tmp
2009-05-08 09:08 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa652.tmp
2009-05-08 09:06 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa865.tmp
2009-05-08 09:03 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa74c.tmp
2009-05-08 08:55 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPaf89.tmp
2009-05-08 08:50 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa0f3.tmp
2009-05-08 08:46 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa44e.tmp
2009-05-08 08:44 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa279.tmp
2009-05-08 08:41 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa43e.tmp
2009-05-08 08:37 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMPa76b.tmp
2009-05-08 08:32 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9932.tmp
2009-05-08 08:26 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP9c11.tmp
2009-05-08 08:23 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88be.tmp
2009-05-08 08:21 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8976.tmp
2009-05-08 08:19 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89a3.tmp
2009-05-08 08:17 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8983.tmp
2009-05-08 08:14 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89e0.tmp
2009-05-08 08:12 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89b2.tmp
2009-05-08 08:10 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88bd.tmp
2009-05-08 08:08 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89c1.tmp
2009-05-08 08:06 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88bc.tmp
2009-05-08 08:04 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP86c4.tmp
2009-05-08 08:02 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88a9.tmp
2009-05-08 08:00 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8919.tmp
2009-05-08 07:58 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP885c.tmp
2009-05-08 07:56 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88bb.tmp
2009-05-08 07:54 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8975.tmp
2009-05-08 07:52 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8dd8.tmp
2009-05-08 07:50 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP87de.tmp
2009-05-08 07:48 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88d7.tmp
2009-05-08 07:47 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8974.tmp
2009-05-08 07:45 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8918.tmp
2009-05-08 07:43 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89d1.tmp
2009-05-08 07:41 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8906.tmp
2009-05-08 07:39 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88e6.tmp
2009-05-08 07:37 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88a8.tmp
2009-05-08 07:35 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP887b.tmp
2009-05-08 07:33 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP883d.tmp
2009-05-08 07:31 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP89a2.tmp
2009-05-08 07:29 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP88c9.tmp
2009-05-08 07:27 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP887a.tmp
2009-05-08 07:25 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP8751.tmp
2009-05-08 07:23 . 2005-06-14 11:10 90112 ----a-w c:\windows\DUMP880d.tmp
2009-04-08 19:10 . 2009-04-08 19:10 211456 ----a-w c:\program files\mozilla firefox\components\wbff.dll
2003-06-09 04:38 . 2007-03-29 18:02 106496 ----a-w c:\program files\mozilla firefox\plugins\cdrPeops.dll
2003-07-31 20:20 . 2007-03-29 18:02 385024 ----a-w c:\program files\mozilla firefox\plugins\gpuPeteD3D.dll
2003-07-31 20:21 . 2007-03-29 18:02 401408 ----a-w c:\program files\mozilla firefox\plugins\gpuPeteDX6D3D.dll
2003-07-31 20:19 . 2007-03-29 18:02 397312 ----a-w c:\program files\mozilla firefox\plugins\gpuPeteOpenGL.dll
2003-06-09 04:38 . 2007-03-29 18:02 77824 ----a-w c:\program files\mozilla firefox\plugins\spuPeopsDSound.dll
2008-11-30 20:46 . 2008-03-08 01:10 88 -csh--r c:\windows\system32\DAD4F0BF01.sys
2008-11-30 20:47 . 2008-03-08 01:10 2516 -csha-w c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2008-04-14 02:34 14336 E4BDF223CD75478BF44567B4D5C2634D c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\svchost.exe
[-] 2004-08-05 12:00 17408 7F565A8D7D87611976D19BBFD1E1C79B c:\windows\system32\svchost.exe
[-] 2008-04-14 02:34 512000 DD73D6B9F6B4CB630CF35B438B540174 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\winlogon.exe
[-] 2004-08-05 12:00 510464 C32E7FA2FC0DD00B70B67C1C72FDCE07 c:\windows\system32\winlogon.exe
[-] 2007-06-13 13:22 1039872 47E53B5FF4A9C77B7E81F445DD25E497 c:\windows\explorer.exe
[7] 2007-06-13 13:10 1037312 B795475444D6D57A572C14B9E1A29839 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[7] 2004-08-05 12:00 1036288 4C33E5B9A6197B6ED215F6CFBA0A2DAA c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2008-04-14 02:34 1037824 F2317622D29F9FF0F88AEECD5F60F0DD c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\explorer.exe
[-] 2008-04-14 02:34 109056 54CB50058851D95E56EC70D09F70857F c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\services.exe
[-] 2004-08-05 12:00 110592 8435129018EC40DDD0CA749DF08D86EF c:\windows\system32\services.exe
[-] 2008-04-14 02:34 13312 91E6024D6D4DCDECDB36C43ECF9BBECB c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\lsass.exe
[-] 2004-08-05 12:00 14848 934ECF925E1B41095F8D615E127D5BD4 c:\windows\system32\lsass.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{437A43D5-E5C3-4959-BBD0-F2BFB1EDC6FD}]
2009-05-26 16:17 22528 ----a-w c:\windows\system32\sysloc\sysloc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2002-11-23 631362]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-14 148888]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-18 28672]
"Logon Loader Random"="c:\program files\Logon Loader\LogonLoader.exe" [2005-03-02 204800]
"Logon Loader"="c:\program files\Logon Loader\LogonLoader.exe" [2005-03-02 204800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-22 1622016]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2006-10-22 86016]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2002-11-08 19968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SYSDLL"="SYSDLL" [X]
c:\documents and settings\karim\Menu D‚marrer\Programmes\D‚marrage\
ChkDisk.dll [2009-5-26 23552]
ChkDisk.lnk - c:\windows\system32\rundll32.exe [2004-8-5 33792]
c:\documents and settings\Mr et Mme ADJADJ\Menu D‚marrer\Programmes\D‚marrage\
chkdisk.dll [2009-5-10 24064]
ChkDisk.lnk - c:\windows\system32\rundll32.exe [2004-8-5 33792]
c:\documents and settings\karim\Menu D‚marrer\Programmes\D‚marrage\
ChkDisk.dll [2009-5-26 23552]
ChkDisk.lnk - c:\windows\system32\rundll32.exe [2004-8-5 33792]
c:\documents and settings\karim\Menu D‚marrer\Programmes\D‚marrage\
ChkDisk.dll [2009-5-26 23552]
ChkDisk.lnk - c:\windows\system32\rundll32.exe [2004-8-5 33792]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ipfwrd.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
[HKLM\~\Services\\_common\\RWVoice.exe"=]
"c:\\Documents and Settings\\Mr et Mme ADJADJ\\Bureau\\DOC\\eMule\\emule.exe"=
"c:\\Program Files\\eMule\\eMule.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Free Download Manager\\fdm.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4672:UDP"= 4672:UDP:emulea
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [26/05/2009 15:52 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 21:06 951632]
S1 aswsp;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [09/04/2009 14:31 114768]
S1 b3fde0de;b3fde0de;c:\windows\system32\drivers\b3fde0de.sys [08/04/2009 01:04 0]
S1 ipfwrd;TDIFilter Driver;c:\windows\system32\ipfwrd.sys --> c:\windows\system32\ipfwrd.sys [?]
S1 jqzgfpy;jqzgfpy;c:\windows\system32\jqzgfpy.sys [08/04/2009 17:07 0]
S2 aswfsblk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/04/2009 14:31 20560]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/04/2009 06:19 55152]
S2 gupdate1c9b7ad3c0be02a;Google Update Service (gupdate1c9b7ad3c0be02a);c:\program files\Google\Update\GoogleUpdate.exe [07/04/2009 20:18 133104]
S2 PCO scheduler service;PCO scheduler service;c:\program files\PCOptimizer\PCoptimizerService.exe [21/05/2009 11:43 266968]
S2 X4HSX32Ex;X4HSX32Ex;c:\program files\Metaboli Player\X4HSX32Ex.sys [07/04/2009 13:16 29856]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 getplus(r) helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [17/06/2005 18:50 14156]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [13/05/2009 14:37 234864]
.
Contenu du dossier 'Tâches planifiées'
2009-05-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2009-05-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-05-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-07 18:18]
2009-05-22 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-19 21:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-eqmwg - c:\documents and settings\karim\local settings\application data\eqmwg.exe
HKU-Default-Run-autochk - c:\windows\system32\config\SYSTEM~1\protect.dll
SSODL-DiwIDfScQg-{04AB843D-AE01-2E97-0C78-F40A4BEBC4F0} - c:\windows\system32\owmk.dll
Notify-__c00C1553 - c:\windows\system32\__c00C1553.dat
Notify-__c00C6B10 - c:\windows\system32\__c00C6B10.dat
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.cooxer.com/
mStart Page = hxxp://www.cooxer.com/
uInternet Settings,ProxyOverride = *.local
IE: tout télécharger avec free download manager - file://c:\program files\Free Download Manager\dlall.htm
IE: télécharger avec free download manager - file://c:\program files\Free Download Manager\dllink.htm
IE: télécharger la sélection avec free download manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: télécharger la vidéo avec free download manager - file://c:\program files\Free Download Manager\dlfvideo.htm
FF - ProfilePath - c:\documents and settings\karim\Application Data\Mozilla\Firefox\Profiles\5xye1cof.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\program files\Mozilla Firefox\components\wbff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npExentCtl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-26 22:25
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\USB]
@DACL=(02 0000)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2044)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
.
Heure de fin: 2009-05-26 22:30
ComboFix-quarantined-files.txt 2009-05-26 20:30
Avant-CF: 4 797 505 536 octets libres
Après-CF: 4 794 535 936 octets libres
669 --- E O F --- 2009-04-07 22:07