Voila
ComboFix 09-06-15.07 - Virginie 16/06/2009 19:03.2 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2047.1516 [GMT 2:00]
Lancé depuis: c:\documents and settings\Virginie\Bureau\combofix.exe
AV: avast! antivirus 4.8.1201 [VPS 090615-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\install.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-16 au 2009-06-16 ))))))))))))))))))))))))))))))))))))
.
2009-06-15 19:41 . 2009-06-15 19:41 -------- d-----w- C:\UsbFix
2009-06-15 19:32 . 2009-06-15 19:32 -------- d-----w- c:\program files\Navilog1
2009-06-15 19:28 . 2009-06-15 19:28 -------- d-----w- c:\program files\CCleaner
2009-06-15 19:20 . 2009-06-15 19:20 -------- d-----w- C:\GenProc
2009-06-15 16:46 . 2009-06-15 16:46 -------- d-----w- c:\program files\Activision
2009-06-13 18:30 . 2009-06-13 18:30 20480 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
2009-06-11 22:29 . 2009-06-11 22:29 41808 ----a-w- c:\windows\system32\xfcodec.dll
2009-06-11 06:30 . 2009-06-11 06:30 -------- d-----w- c:\program files\QuickTime
2009-06-10 16:28 . 2009-06-10 16:29 1878984 ----a-w- c:\documents and settings\Virginie\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-07 18:32 . 2009-06-07 18:32 88944 ---ha-w- c:\windows\system32\mlfcache.dat
2009-06-07 16:17 . 2009-06-07 16:17 -------- d-----w- c:\documents and settings\Virginie\Application Data\ZoomBrowser EX
2009-06-07 16:12 . 2009-06-07 16:12 -------- d-----w- c:\documents and settings\Virginie\Application Data\Canon
2009-06-07 16:12 . 2001-08-23 15:47 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-06-07 16:12 . 2008-04-14 02:33 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-06-07 14:44 . 2009-06-07 14:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-06-07 14:43 . 2009-06-07 14:43 -------- d-----w- c:\program files\Canon
2009-06-07 14:43 . 2009-06-07 14:43 -------- d-----w- c:\program files\Fichiers communs\Canon
2009-06-06 09:59 . 2009-06-06 09:59 -------- d-----w- c:\program files\Audacity
2009-06-03 18:20 . 2009-06-03 18:20 20480 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
2009-05-29 18:39 . 2009-05-29 18:39 7114736 ----a-w- c:\documents and settings\Virginie\Application Data\Azureus\plugins\azemp\azmplay.exe
2009-05-29 18:37 . 2009-05-29 18:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-05-29 18:37 . 2009-05-29 18:37 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Azureus
2009-05-26 21:04 . 2009-05-26 21:04 20480 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
2009-05-23 15:11 . 2009-05-23 15:14 136514 ----a-w- c:\windows\hpqins00.dat
2009-05-20 16:51 . 2009-05-20 16:51 -------- d-----w- C:\eJay
2009-05-20 16:14 . 2003-04-18 14:29 44544 ----a-w- c:\windows\system32\msxml4a.dll
2009-05-20 16:12 . 2009-05-20 16:12 -------- d-----w- c:\windows\system32\MAGIX
2009-05-20 16:12 . 2006-09-13 11:44 643072 ----a-w- c:\windows\system32\mgxoschk.dll
2009-05-20 16:08 . 2009-06-07 18:01 698903 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\unins000.exe
2009-05-20 16:08 . 2008-12-09 08:13 368224 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
2009-05-20 16:08 . 2008-12-09 08:12 499296 ----a-w- c:\documents and settings\Virginie\Application Data\EoRezo\SoftwareUpdate\SoftwareUpdate.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 15:01 . 2007-08-22 16:15 189072 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-16 14:52 . 2008-11-25 15:06 138920 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-15 18:13 . 2008-11-25 15:05 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-06-15 16:56 . 2007-12-29 12:39 22328 ----a-w- c:\documents and settings\Virginie\Application Data\PnkBstrK.sys
2009-06-15 16:56 . 2007-12-29 12:39 22328 ----a-w- c:\documents and settings\Virginie\Application Data\PnkBstrK.sys
2009-06-08 05:23 . 2001-08-24 01:00 83634 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-08 05:23 . 2001-08-24 01:00 505242 ----a-w- c:\windows\system32\perfh00C.dat
2009-05-20 16:55 . 2006-09-09 12:15 117472 ----a-w- c:\documents and settings\Virginie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-20 16:32 . 2009-01-03 09:00 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-20 16:13 . 2009-05-20 16:13 -------- d-----w- c:\program files\Fichiers communs\MAGIX Shared
2009-05-14 17:53 . 2009-05-14 17:53 -------- d-----w- c:\documents and settings\Virginie\Application Data\gtk-2.0
2009-05-14 17:21 . 2009-05-14 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-05-07 15:33 . 2001-08-24 01:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:45 . 2001-08-24 01:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:45 . 2006-08-26 17:22 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-26 19:13 . 2008-01-08 21:01 1 ----a-w- c:\documents and settings\Virginie\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-04-26 10:49 . 2009-04-26 10:49 -------- d-----w- c:\program files\WordBiz
2009-04-20 15:16 . 2009-04-20 15:16 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-04-19 19:50 . 2001-08-24 01:00 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:53 . 2001-08-24 01:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-01 08:20 . 2009-04-01 08:20 152576 ----a-w- c:\documents and settings\Virginie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2007-01-08 13:56 . 2007-01-08 13:45 22845992 ----a-w- c:\program files\AdbeRdr80_fr_FR.exe
2006-12-19 08:31 . 2006-12-19 08:31 16179264 ----a-w- c:\program files\divxinstaller.exe
2004-07-22 08:51 . 2004-07-22 08:51 3432656 ----a-w- c:\program files\ManagedDX.CAB
2004-07-19 20:58 . 2004-07-19 20:58 1156363 ----a-w- c:\program files\BDANT.cab
2004-07-19 20:53 . 2004-07-19 20:53 976020 ----a-w- c:\program files\BDAXP.cab
2004-07-09 12:17 . 2004-07-09 12:17 13265040 ----a-w- c:\program files\dxnt.cab
2004-07-09 07:13 . 2004-07-09 07:13 15493481 ----a-w- c:\program files\DirectX.cab
2004-07-09 07:13 . 2004-07-09 07:13 703080 ----a-w- c:\program files\BDA.cab
2004-07-09 02:08 . 2004-07-09 02:08 472576 ----a-w- c:\program files\dxsetup.exe
2004-07-09 02:08 . 2004-07-09 02:08 2242560 ----a-w- c:\program files\dsetup32.dll
2004-07-09 01:03 . 2004-07-09 01:03 62976 ----a-w- c:\program files\DSETUP.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-03-10 09:47 2079256 ----a-w- c:\program files\free-downloads.net\tbfree.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="c:\progra~1\WANADOO\Shell.exe" [2004-08-23 122880]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-24 203928]
"AdobeUpdater"="c:\program files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"WOOWATCH"="c:\progra~1\WANADOO\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\WANADOO\GestMaj.exe" [2004-10-14 32768]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-08-15 271672]
"razer"="c:\program files\Razer\razerhid.exe" [2005-05-17 147456]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"EoEngine"="c:\program files\EoRezo\EoEngine.exe" [2009-02-23 472872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SoftwareHelper"="c:\documents and settings\Virginie\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2004-07-27 68096]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
c:\documents and settings\Virginie\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\documents and settings\Virginie\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\documents and settings\Virginie\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sncf26\\counter-strike\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sncf26\\condition zero\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sncf26\\day of defeat\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sncf26\\ricochet\\hl.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\sncf26\\deathmatch classic\\hl.exe"=
"c:\\WINDOWS\\System32\\PnkBstrA.exe"=
"c:\\WINDOWS\\System32\\PnkBstrB.exe"=
"c:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe"=
"f:\\Soldier of Fortune II - Double Helix\\SoF2MP.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\flat\\flatout2.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr.exe"=
"c:\\Program Files\\eMule\\eMule0.49b\\emule.exe"=
"c:\\WINDOWS\\System32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"42362:TCP"= 42362:TCP:azureus
"42362:UDP"= 42362:UDP:azureus
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [25/08/2008 17:40 45056]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [27/04/2008 20:08 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [27/04/2008 20:08 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/12/2008 13:07 55136]
R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [28/11/2006 19:51 28672]
S3 Razerlow;Razerlow USB Filter Driver;c:\windows\system32\drivers\Razerlow.sys [11/09/2007 18:59 13225]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-06-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-01 20:18]
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://y.lo.st
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: { - c:\program files\Messenger\msmsgs.exe
TCP: {59F813E6-FD3B-4F3D-A2C8-C0FA8D724A59} = 192.168.1.1
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 19:10
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2025429265-1645522239-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:07,b7,50,88,7c,d5,ad,32,ae,c5,31,05,ad,a6,29,93,21,7d,41,ee,25,d7,0b,
68,12,7d,0d,78,91,9e,11,bc,b3,0c,ee,2f,da,e3,21,d8,b5,f7,df,d0,a8,73,25,52,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(7468)
c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
c:\program files\FICHIERS COMMUNS\LOGISHRD\LVMVFM\LVPRCSRV.EXE
c:\program files\FICHIERS COMMUNS\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\windows\SYSTEM32\FTRTSVC.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\FICHIERS COMMUNS\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\program files\FICHIERS COMMUNS\LOGISHRD\LVCOMSER\LVCOMSER.EXE
c:\windows\SYSTEM32\PNKBSTRA.EXE
c:\windows\SYSTEM32\PNKBSTRB.EXE
c:\program files\MICROSOFT\SEARCH ENHANCEMENT PACK\SEAPORT\SEAPORT.EXE
c:\program files\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
c:\windows\SYSTEM32\UASERVICE7.EXE
c:\program files\CANON\CAL\CALMAIN.EXE
c:\windows\system32\CF25271.exe
c:\progra~1\WANADOO\TaskBarIcon.exe
c:\program files\Razer\razerofa.exe
c:\windows\system32\rundll32.exe
c:\progra~1\WANADOO\GestionnaireInternet.exe
c:\progra~1\WANADOO\ComComp.exe
c:\progra~1\WANADOO\Toaster.exe
c:\progra~1\WANADOO\Inactivity.exe
c:\progra~1\WANADOO\PollingModule.exe
c:\program files\OpenOffice.org 2.3\program\soffice.exe
c:\program files\OpenOffice.org 2.3\program\soffice.BIN
c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
c:\program files\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
c:\windows\System32\wbem\wmiapsrv.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Heure de fin: 2009-06-16 19:12 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-16 17:12
Avant-CF: 10 468 868 096 octets libres
Après-CF: 10 453 237 760 octets libres
260 --- E O F --- 2009-06-10 06:38