c'est fait:
ComboFix 09-06-28.06 - utilisateur 29/06/2009 16:59.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2039.1597 [GMT 1:00]
Lancé depuis: c:\documents and settings\utilisateur\Bureau\Combo-Fix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Outdated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\utilisateur\Application Data\.#
c:\documents and settings\utilisateur\Application Data\.#\MBX@578@3D37C8.###
c:\documents and settings\utilisateur\Application Data\.#\MBX@578@3D37D8.###
c:\documents and settings\utilisateur\Application Data\.#\MBX@578@3D37E8.###
c:\documents and settings\utilisateur\Application Data\inst.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\OGACheckControl.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WgaLogon.dll
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-28 au 2009-06-29 ))))))))))))))))))))))))))))))))))))
.
2009-06-29 15:39 . 2009-06-29 15:41 -------- d-s---w- C:\ComboFix
2009-06-28 23:14 . 2009-06-28 23:14 -------- d-----w- c:\documents and settings\utilisateur\Application Data\Moyea
2009-06-28 23:14 . 2008-09-18 12:52 438272 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-28 23:14 . 2009-06-28 23:14 -------- d-----w- c:\program files\Moyea
2009-06-28 23:05 . 2009-06-28 23:05 -------- d-----w- C:\tmpDownload
2009-06-28 22:49 . 2009-06-28 22:51 -------- d-----w- c:\program files\Any Audio Converter
2009-06-28 22:11 . 2009-06-28 22:12 96047842 ----a-w- C:\Sauv.reg
2009-06-28 15:39 . 2009-06-28 15:39 -------- d-----w- c:\documents and settings\utilisateur\Application Data\XericDesign
2009-06-28 00:29 . 2009-06-28 00:30 -------- d-----w- c:\program files\QuickTime
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\documents and settings\utilisateur\Local Settings\Application Data\Apple
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\program files\Apple Software Update
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-28 00:29 . 2009-06-28 00:29 -------- d-----w- c:\documents and settings\utilisateur\Local Settings\Application Data\Apple Computer
2009-06-28 00:12 . 2009-06-28 00:12 -------- d-----w- c:\program files\XericDesign
2009-06-25 20:10 . 2009-06-25 20:10 95496 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav6\7.0.0.119\diffs.dll
2009-06-25 20:10 . 2009-06-25 20:10 673032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav6\7.0.0.119\updater.dll
2009-06-25 20:10 . 2009-06-25 20:10 341256 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav6\7.0.0.119\ckahum.dll
2009-06-25 20:10 . 2009-06-25 20:10 186640 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav6\7.0.0.119\klif.sys
2009-06-25 20:10 . 2009-06-25 20:10 110360 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\update\rollback\AutoPatches\kav6\7.0.0.119\X86\kl1.sys
2009-06-25 20:10 . 2009-06-25 20:10 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\X86\kl1.sys
2009-06-25 20:10 . 2009-06-25 20:10 682512 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\updater.dll
2009-06-25 20:09 . 2009-06-25 20:09 194320 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\klif.sys
2009-06-25 20:09 . 2009-06-25 20:09 150032 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\diffs.dll
2009-06-25 20:09 . 2009-06-25 20:09 342544 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\7.0.0.119\ckahum.dll
2009-06-17 22:45 . 2009-05-19 13:06 99840 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP7\Bases\avpcure1.dll
2009-06-17 10:09 . 2009-06-17 22:47 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-06-17 10:09 . 2009-06-17 22:47 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-06-17 10:08 . 2009-06-17 10:08 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-17 10:08 . 2009-06-29 16:04 7635744 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-17 10:08 . 2009-06-29 16:04 97056 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-02 16:59 . 2009-06-02 16:59 0 ----a-w- c:\windows\Infob.dat
2009-06-02 16:59 . 2009-06-02 16:59 0 ----a-w- c:\windows\Infoa.dat
2009-05-31 09:47 . 2009-05-31 09:47 -------- d-----w- c:\program files\Fichiers communs\xing shared
2009-05-31 09:05 . 2009-05-31 09:05 390664 ----a-w- c:\documents and settings\utilisateur\Application Data\Real\RealPlayer\setup\AU_setup6.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 16:02 . 2009-06-17 10:08 12188 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-29 16:02 . 2009-06-17 10:08 111572 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-29 15:38 . 2008-12-07 16:15 -------- d-----w- c:\documents and settings\utilisateur\Application Data\DMCache
2009-06-29 13:25 . 2008-12-07 13:53 -------- d-----w- c:\documents and settings\utilisateur\Application Data\Skype
2009-06-29 11:40 . 2009-04-19 14:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-28 17:37 . 2009-05-19 01:23 -------- d-----w- c:\program files\Google
2009-06-25 20:10 . 2007-04-28 15:51 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
2009-06-25 20:07 . 2008-04-14 12:00 74032 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-25 20:07 . 2008-04-14 12:00 464466 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-25 19:46 . 2009-02-09 14:44 -------- d-----w- c:\program files\trend micro
2009-06-17 17:31 . 2009-05-07 19:12 -------- d-----w- c:\program files\CCleaner
2009-06-14 17:58 . 2009-05-26 00:22 70 ---ha-w- C:\aaw7boot.cmd
2009-06-14 17:08 . 2008-12-10 18:38 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-07 17:52 . 2009-01-22 12:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-07 15:50 . 2009-03-05 09:14 -------- d-----w- c:\program files\Mawsoaat Hadeeth
2009-06-04 14:17 . 2008-12-07 09:54 84920 ----a-w- c:\documents and settings\utilisateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-31 09:47 . 2008-12-07 20:23 -------- d-----w- c:\program files\Fichiers communs\Real
2009-05-31 09:47 . 2008-12-07 09:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-05-24 23:26 . 2009-05-24 23:15 -------- d-----w- c:\documents and settings\utilisateur\Application Data\Vso
2009-05-24 23:26 . 2009-05-24 23:15 47360 ----a-w- c:\documents and settings\utilisateur\Application Data\pcouffin.sys
2009-05-24 23:26 . 2009-05-24 23:15 47360 ----a-w- c:\documents and settings\utilisateur\Application Data\pcouffin.sys
2009-05-24 23:15 . 2009-05-24 23:15 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-05-21 23:06 . 2008-12-07 10:48 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-19 01:33 . 2009-05-19 01:33 -------- d-----w- c:\documents and settings\utilisateur\Application Data\GRETECH
2009-05-19 01:32 . 2009-05-14 01:19 -------- d-----w- c:\program files\GRETECH
2009-05-18 15:44 . 2009-05-18 15:44 198064 ----a-w- c:\documents and settings\utilisateur\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-05-18 15:44 . 2009-01-22 14:41 -------- d-----w- c:\documents and settings\utilisateur\Application Data\IDM
2009-05-18 15:44 . 2009-01-22 14:41 -------- d-----w- c:\program files\Internet Download Manager
2009-05-14 01:28 . 2009-05-14 01:28 -------- d-----w- c:\program files\ÇáÞÑÂä ÇáßÑíã
2009-05-13 15:12 . 2009-05-13 15:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2009-05-11 12:37 . 2009-05-11 12:37 -------- d-----w- c:\documents and settings\utilisateur\Application Data\BlackBean
2009-05-10 01:21 . 2009-05-10 01:21 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-07 15:33 . 2008-04-14 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:34 . 2008-04-14 12:00 670720 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:34 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 19:50 . 2008-04-14 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:53 . 2008-04-14 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-11 17:16 . 2008-12-07 09:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-03-02 18:41 . 2009-03-02 17:00 2008 --sha-w- c:\windows\system32\sys_drv.dat
.
------- Sigcheck -------
[-] 2008-12-06 15:36 1571840 33578A738C564B4F84D906EFD91025E5 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-06-03 177456]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-05-31 198160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-04-14 101888]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\Huawei Technologies\Huawei SmartAX MT810\dslmon.exe [2009-2-16 946270]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Larousse Expression.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Larousse Expression.lnk
backup=c:\windows\pss\Larousse Expression.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\French\\setup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\avp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9913:TCP"= 9913:TCP:aqmeakry
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [07/12/2008 12:09 193840]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [04/04/2007 14:58 24344]
S2 evrddmizy;Center Update;c:\windows\system32\svchost.exe -k netsvcs [14/04/2008 13:00 14336]
S2 jlckglq;Task System;c:\windows\system32\svchost.exe -k netsvcs [14/04/2008 13:00 14336]
S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\drivers\adiusbae.sys [16/02/2009 13:19 117289]
S3 ahzbzkuuy;ahzbzkuuy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 attnlh;attnlh;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 axkveiogf;axkveiogf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ayboahm;ayboahm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 cutlxmx;cutlxmx;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 dafcaxamt;dafcaxamt;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 dgljm;dgljm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 dqztv;dqztv;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 fexxcye;fexxcye;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 frduruk;frduruk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 fwbpw;fwbpw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gnlzuw;gnlzuw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gouez;gouez;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 guljzro;guljzro;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 gxpflvpf;gxpflvpf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jfgpmhbe;jfgpmhbe;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 jhnaiaz;jhnaiaz;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 kxcthd;kxcthd;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 kyoduxqcf;kyoduxqcf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 llbegfliy;llbegfliy;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lrjoedni;lrjoedni;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lufqi;lufqi;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lvkqgib;lvkqgib;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 lxjzgrbq;lxjzgrbq;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 miecf;miecf;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 nijox;nijox;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 olhzwcew;olhzwcew;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 olterr;olterr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 omvtowyi;omvtowyi;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 pkosv;pkosv;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 przuwlpd;przuwlpd;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qddbm;qddbm;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qfcnr;qfcnr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qipjkon;qipjkon;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 qusciumee;qusciumee;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 rbolc;rbolc;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 rdaat;rdaat;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 rqhvyhqwr;rqhvyhqwr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 skigaoo;skigaoo;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 stllvukk;stllvukk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tdqnskrvp;tdqnskrvp;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tflirteit;tflirteit;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 tvrsx;tvrsx;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 uhcsmca;uhcsmca;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 utzfdv;utzfdv;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 vibftejas;vibftejas;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 vzridpyb;vzridpyb;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 wcafigsv;wcafigsv;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xbuntsua;xbuntsua;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xhscczquo;xhscczquo;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xorslqk;xorslqk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xpknatlk;xpknatlk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xunwalxhk;xunwalxhk;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 xxsix;xxsix;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yecfn;yecfn;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 yosganlr;yosganlr;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 ypnvsrjd;ypnvsrjd;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 zorgg;zorgg;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 zsaffw;zsaffw;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
S3 zsexs;zsexs;\??\c:\windows\system32\01.tmp --> c:\windows\system32\01.tmp [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
evrddmizy
jlckglq
.
Contenu du dossier 'Tâches planifiées'
2009-06-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = hxxp://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareDescription.jsp?lang=en&cc=us&prodTypeId=321957&prodSeriesId=3442832&prodNameId=3442833&swEnvOID=1093&swLang=17&mode=2&taskId=135&swItem=ob-56416-1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Download with Rapget - c:\docume~1\UTILIS~1\MESDOC~1\DOWNLO~1\COMPRE~1\RAPGET~1.FR_\RAPGET~1.FRB\rapget.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
FF - ProfilePath - c:\documents and settings\utilisateur\Application Data\Mozilla\Firefox\Profiles\oxei6klf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - MediaDICO
FF - prefs.js: browser.startup.homepage - hxxp://fr.yahoo.com/?fr=fptb-cclean
FF - component: c:\documents and settings\utilisateur\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-29 17:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ahzbzkuuy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\attnlh]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\axkveiogf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ayboahm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cutlxmx]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dafcaxamt]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dgljm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\dqztv]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fexxcye]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\frduruk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fwbpw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gnlzuw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gouez]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\guljzro]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gxpflvpf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jfgpmhbe]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\jhnaiaz]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kxcthd]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kyoduxqcf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\llbegfliy]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lrjoedni]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lufqi]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lvkqgib]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\lxjzgrbq]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\miecf]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\nijox]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\olhzwcew]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\olterr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\omvtowyi]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pkosv]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\przuwlpd]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qddbm]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qfcnr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qipjkon]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\qusciumee]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rbolc]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rdaat]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rqhvyhqwr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\skigaoo]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\stllvukk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tdqnskrvp]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tflirteit]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\tvrsx]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\uhcsmca]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\utzfdv]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vibftejas]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vzridpyb]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wcafigsv]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xbuntsua]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xhscczquo]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xorslqk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xpknatlk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xunwalxhk]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xxsix]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yecfn]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yosganlr]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ypnvsrjd]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zorgg]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zsaffw]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zsexs]
"ImagePath"="\??\c:\windows\system32\01.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\evrddmizy]
"ServiceDll"="c:\windows\system32\surjqims.dll"