Bonsoir,
voici le rapport:
ComboFix 09-07-06.A0 - Greg 07/07/2009 19:00.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1445 [GMT 2:00]
Lancé depuis: e:\telechargements\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\emMON.exe
c:\windows\Installer\522daf.msi
c:\windows\Installer\d94a505.msp
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-07 au 2009-07-07 ))))))))))))))))))))))))))))))))))))
.
2009-07-07 08:29 . 2009-07-07 08:29 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-07 08:25 . 2008-06-27 07:39 332928 ----a-w- c:\windows\system32\drivers\RTL8187.sys
2009-07-05 16:47 . 2009-07-05 16:47 -------- d-----w- c:\program files\Fichiers communs\PocketSoft
2009-07-05 16:47 . 2002-02-27 16:50 197120 ----a-w- c:\windows\patchw32.dll
2009-07-05 16:38 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-05 16:38 . 2009-07-05 16:38 -------- d-----w- c:\program files\Panda Security
2009-07-05 09:28 . 2009-07-05 09:28 -------- d-----w- C:\rsit
2009-07-04 21:27 . 2009-07-04 21:27 -------- d-----w- c:\documents and settings\Greg\Application Data\Malwarebytes
2009-07-04 21:26 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-04 21:26 . 2009-07-04 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-04 21:26 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-30 07:50 . 2009-06-30 07:50 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\Microsoft Help
2009-06-23 20:42 . 2009-06-23 20:42 -------- d-----w- c:\program files\NVIDIA Corporation
2009-06-23 20:38 . 2009-04-30 20:02 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-06-23 20:38 . 2009-04-26 22:42 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-23 20:33 . 2009-05-18 09:00 208896 ----a-w- c:\windows\system32\WinSys2.exe
2009-06-23 20:33 . 2009-05-18 09:00 131072 ----a-w- c:\windows\system32\smdll.dll
2009-06-23 20:33 . 2009-04-30 20:02 9994240 ----a-w- c:\windows\system32\nvoglnt.dll
2009-06-23 20:33 . 2009-04-30 20:02 663552 ----a-w- c:\windows\system32\nvcuvid.dll
2009-06-23 20:33 . 2009-04-30 20:02 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-06-23 20:33 . 2009-04-30 20:02 1314816 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-06-23 20:33 . 2009-05-18 09:00 1798144 ----a-w- c:\windows\system32\msicpl.dll
2009-06-23 20:33 . 2009-05-18 09:00 130048 ----a-w- c:\windows\system32\MadCHook.dll
2009-06-23 20:33 . 2009-04-30 20:02 806912 ----a-w- c:\windows\system32\nvapi.dll
2009-06-23 20:33 . 2009-04-30 20:02 143360 ----a-w- c:\windows\system32\nvcodins.dll
2009-06-23 20:33 . 2009-04-30 20:02 143360 ----a-w- c:\windows\system32\nvcod.dll
2009-06-23 20:33 . 2009-05-18 09:00 32768 ----a-w- c:\windows\system32\Auxiliary.dll
2009-06-22 19:50 . 2009-04-30 20:02 1579630 ----a-w- c:\windows\system32\nvdata.bin
2009-06-22 14:08 . 2009-06-22 14:08 -------- d-----w- c:\documents and settings\Greg\Application Data\Sony Corporation
2009-06-22 13:45 . 2009-06-22 16:27 -------- d-----w- c:\documents and settings\Greg\Application Data\gtk-2.0
2009-06-22 13:45 . 2009-06-22 13:45 -------- d-----w- c:\documents and settings\Greg\.thumbnails
2009-06-22 13:43 . 2009-06-22 16:36 -------- d-----w- c:\documents and settings\Greg\.gimp-2.6
2009-06-22 13:43 . 2009-06-22 13:43 -------- d-----w- c:\documents and settings\Greg\.gegl-0.0
2009-06-21 22:53 . 2009-06-21 22:53 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-06-21 14:07 . 2006-06-12 01:30 89264 ----a-w- c:\windows\system32\drivers\DRVMCDB.SYS
2009-06-21 14:07 . 2006-03-17 06:35 5660 ----a-w- c:\windows\system32\drivers\DLACDBHM.SYS
2009-06-21 14:07 . 2006-03-17 06:34 22684 ----a-w- c:\windows\system32\drivers\DLARTL_N.SYS
2009-06-21 14:07 . 2006-03-17 03:20 40544 ----a-w- c:\windows\system32\drivers\DRVNDDM.SYS
2009-06-21 14:07 . 2009-06-21 14:07 -------- d-----w- c:\windows\system32\DLA
2009-06-21 14:07 . 2006-06-13 03:20 94263 ----a-w- c:\windows\DLA.EXE
2009-06-21 14:07 . 2006-06-13 03:20 61500 ----a-w- c:\windows\system32\DLAAPI_W.DLL
2009-06-21 14:06 . 2006-11-02 14:57 118520 ----a-w- c:\windows\system32\PxInsI64.exe
2009-06-21 14:06 . 2006-10-18 17:43 115960 ----a-w- c:\windows\system32\PxCpyI64.exe
2009-06-21 14:05 . 2009-06-21 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Corporation
2009-06-21 13:51 . 2009-06-21 13:51 -------- d-----w- c:\documents and settings\Greg\Application Data\Publish Providers
2009-06-21 13:51 . 2009-06-21 13:51 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\Sony
2009-06-21 13:51 . 2009-06-21 13:51 -------- d-----w- c:\documents and settings\Greg\Application Data\Sony
2009-06-21 13:47 . 2009-06-21 14:14 -------- d-----w- c:\program files\Sony
2009-06-21 13:41 . 2009-06-21 13:41 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\WMTools Downloaded Files
2009-06-21 13:18 . 2009-06-21 13:18 -------- d-----w- c:\documents and settings\Greg\Application Data\Xilisoft Corporation
2009-06-21 13:17 . 2009-06-21 13:17 -------- d-----w- c:\program files\Xilisoft
2009-06-21 10:54 . 2009-06-21 10:54 -------- d-----w- c:\program files\Music NFO Builder
2009-06-18 23:22 . 2009-06-18 23:22 -------- d-----w- c:\program files\YouTUBE (TM) movie downloader
2009-06-18 20:38 . 2009-06-18 20:43 -------- d-----w- c:\program files\No-IP
2009-06-17 23:20 . 2009-06-18 18:00 -------- d-----w- C:\Poker
2009-06-14 19:05 . 2009-06-14 19:05 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\Bizarre Creations
2009-06-11 16:33 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 16:33 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 22:17 . 2009-06-17 23:27 -------- d-----w- c:\program files\PartyGaming
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 17:06 . 2009-05-25 10:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-07-07 17:03 . 2009-05-25 10:06 917536 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-07-07 17:03 . 2009-05-25 10:06 6383136 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-07 17:03 . 2009-05-25 10:06 6312 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-07-07 17:03 . 2009-05-25 10:06 54092 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-07 09:29 . 2008-06-23 20:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-05 17:24 . 2008-12-02 18:28 -------- d-----w- c:\documents and settings\Greg\Application Data\Atari
2009-07-05 17:24 . 2008-12-16 23:47 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-07-05 16:32 . 2008-06-24 17:18 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-07-05 16:06 . 2008-06-26 16:35 -------- d-----w- c:\documents and settings\Greg\Application Data\Azureus
2009-07-02 08:09 . 2008-12-04 00:09 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-23 20:41 . 2009-01-05 20:47 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-06-23 20:41 . 2009-01-05 20:49 -------- d-----w- c:\program files\AGEIA Technologies
2009-06-22 15:09 . 2009-03-11 15:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Test Drive Unlimited
2009-06-21 22:53 . 2008-10-05 15:08 -------- d-----w- c:\program files\DivX
2009-06-18 23:26 . 2009-01-10 14:38 -------- d-----w- c:\documents and settings\Greg\Application Data\Apple Computer
2009-06-18 20:59 . 2008-07-08 22:22 -------- d-----w- c:\program files\ma-config.com
2009-06-18 20:59 . 2008-07-08 22:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2009-06-17 16:18 . 2008-06-23 22:51 -------- d-----w- c:\program files\RocketDock
2009-06-14 00:52 . 2008-06-23 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-08 17:46 . 2008-06-23 20:56 76280 ----a-w- c:\documents and settings\Greg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-01 23:11 . 2009-06-01 23:11 -------- d-----w- c:\program files\iPod
2009-06-01 23:11 . 2009-01-10 14:34 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-06-01 23:09 . 2009-01-10 14:35 -------- d-----w- c:\program files\QuickTime
2009-06-01 23:05 . 2009-06-01 23:05 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-29 11:36 . 2009-03-18 17:58 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-29 11:36 . 2009-01-10 14:35 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-25 10:13 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-05-25 10:13 . 2009-05-25 10:06 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-25 10:13 . 2009-05-25 10:06 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-25 10:13 . 2009-05-25 10:13 33808 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-05-25 10:13 . 2009-05-25 10:13 206088 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-05-25 10:13 . 2009-05-25 10:13 226832 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-05-25 10:06 . 2009-05-25 10:06 -------- d-----w- c:\program files\Kaspersky Lab
2009-05-25 09:59 . 2009-05-25 09:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-25 09:49 . 2008-07-15 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-18 09:00 . 2008-10-16 16:46 614400 ----a-w- c:\windows\system32\msvcr80.dll
2009-05-14 17:05 . 2001-08-28 12:00 91540 ----a-w- c:\windows\system32\perfc00C.dat
2009-05-14 17:05 . 2001-08-28 12:00 525078 ----a-w- c:\windows\system32\perfh00C.dat
2009-05-14 17:04 . 2008-06-23 22:52 -------- d-----w- c:\program files\MSBuild
2009-05-14 17:04 . 2009-05-14 17:04 166744 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 17:01 . 2009-05-14 17:01 -------- d-----w- c:\program files\Reference Assemblies
2009-05-14 16:59 . 2009-05-14 16:58 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-05-13 14:21 . 2008-06-23 22:05 121249 ----a-w- c:\windows\hpoins11.dat
2009-05-12 19:33 . 2008-10-21 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2009-05-12 13:12 . 2008-06-23 21:15 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-05-07 15:33 . 2001-08-28 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-04-30 22:30 . 2009-04-30 22:30 1194528 ----a-w- c:\windows\system32\nvcplui.exe
2009-04-30 20:02 . 2008-06-23 20:53 8055584 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-04-30 20:02 . 2008-06-23 20:53 5896320 ----a-w- c:\windows\system32\nv4_disp.dll
2009-04-29 04:45 . 2001-08-28 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:45 . 2009-04-16 11:11 78336 ------w- c:\windows\system32\ieencode.dll
2009-04-22 16:51 . 2009-04-22 16:51 307200 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\lyrics\SeekLyrics.dll
2009-04-22 16:51 . 2009-04-22 16:51 286720 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\lyrics\LyricsOnDemand.dll
2009-04-22 16:51 . 2009-04-22 16:50 311296 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\lyrics\LyricsVault.dll
2009-04-22 16:50 . 2009-04-22 16:50 307200 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\lyrics\LyricsDemon.dll
2009-04-22 16:50 . 2009-04-22 16:50 286720 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\lyrics\AstraLyrics.dll
2009-04-22 16:50 . 2009-04-22 16:50 339968 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\allmusic.dll
2009-04-22 16:50 . 2009-04-22 16:50 413696 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\amazon.dll
2009-04-22 16:50 . 2009-04-22 16:50 331776 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\sonybmg.dll
2009-04-22 16:50 . 2009-04-22 16:50 311296 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\musicline.dll
2009-04-22 16:50 . 2009-04-22 16:50 339968 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\connect.dll
2009-04-22 16:50 . 2009-04-22 16:50 311296 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Radiotracker4\general\mp3com.dll
2009-04-21 22:20 . 2009-04-21 22:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-21 22:20 . 2009-04-21 22:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-19 19:50 . 2001-08-28 12:00 1847296 ----a-w- c:\windows\system32\win32k.sys
2009-04-18 12:57 . 2008-09-21 10:49 15100943 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-04-17 10:46 . 2009-04-17 10:46 171566 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2009_04_17_12_40_37_small.dmp.zip
2009-04-15 14:53 . 2001-08-28 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2002-08-29 08:44 165376 A0EE5C06390357FEE7B7949DBCA156D3 c:\windows\system32\appmgmts.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-06-02 385024]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-05-25 206088]
"WinSys2"="c:\windows\system32\winsys2.exe" [2009-05-18 208896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-04-30 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\GRID\\GRID.exe"=
"e:\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"e:\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"e:\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"e:\\Steam\\steamapps\\common\\gti racing\\GTIRacing.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\iTunes\\iTunes.exe"=
"e:\\Tom Clancy's H.A.W.X\\HAWX.exe"=
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [31/07/2008 21:45 20616]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 17:29 33808]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [05/07/2009 18:38 28544]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [28/04/2009 02:40 4440064]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?]
R3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO;c:\windows\system32\drivers\BUSB2902.sys [24/06/2008 19:13 110272]
R3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8XX.sys [24/06/2008 00:36 433732]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 18:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 17:06 24592]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [07/07/2009 10:25 332928]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [30/07/2008 15:02 120472]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys --> c:\windows\system32\DRIVERS\EAPPkt.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [02/07/2008 15:58 26248]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 17:13 234864]
S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;\??\c:\windows\system32\PLCMPR5.SYS --> c:\windows\system32\PLCMPR5.SYS [?]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\PLCNDIS5.SYS [23/06/2008 23:14 17280]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier 'Tâches planifiées'
2009-07-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: bitdefender.com\kb
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
Trusted Zone: com.tw\www.msi
TCP: {94391837-E9E6-46AA-BC33-B6E19D4C0135} = 192.168.0.1
TCP: {C0FEA7D6-E801-4DFD-AA41-D14F47BE3710} = 192.168.0.1
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
FF - ProfilePath - c:\documents and settings\Greg\Application Data\Mozilla\Firefox\Profiles\mgqo95mq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: c:\documents and settings\Greg\Application Data\Mozilla\Firefox\Profiles\mgqo95mq.default\extensions\npfax@microgaming.co.uk\platform\WINNT_x86-msvc\plugins\npfax.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: e:\itunes\Mozilla Plugins\npitunes.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-07 19:06
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-839522115-1303643608-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:58,dc,97,a5,fd,07,e7,62,ae,1b,ef,e8,46,1c,ea,6f,c4,fd,df,bc,d5,6e,9d,
b2,b0,dc,18,0c,02,d3,05,c9,b7,ab,cd,64,10,b8,23,c0,03,36,0d,5a,5d,2b,11,c5,\
"??"=hex:59,e5,97,70,47,08,a5,1e,f6,13,83,cc,52,0d,a6,6c
[HKEY_USERS\S-1-5-21-839522115-1303643608-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:9a,14,af,ec,85,6a,be,ba,81,0b,4e,43,89,38,9b,5f,07,2c,01,1b,f7,
db,a0,57,59,17,87,3e,76,8b,e0,5d,4d,6e,e3,6d,99,9c,92,28,19,e4,61,22,c7,64,\
"rkeysecu"=hex:83,12,9d,05,a7,65,b0,ec,cd,9b,51,7f,f2,d3,f5,ee
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,09,85,dd,c5,17,
bd,71,67,e2,63,26,f1,3f,c8,ff,68,94,9e,43,83,99,05,63,1c,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,7e,ee,45,ab,c5,
a1,a3,38,6a,9c,d6,61,af,45,84,18,7a,de,54,49,81,3a,3f,7c,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,f3,49,fe,8a,fe,
c3,43,26,ff,7c,85,e0,43,d4,0e,fe,fd,e1,f1,62,df,9a,02,39,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,5f,13,d9,20,7d,
4f,8e,ac,86,8c,21,01,be,91,eb,e7,0d,e0,ae,8b,d0,e4,ea,de,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,2a,69,a9,c3,87,
25,48,77,f5,1d,4d,73,a8,13,5c,05,71,fb,50,ae,0f,bb,69,ee,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,4e,cb,fb,96,78,
8e,68,b8,df,20,58,62,78,6b,cf,c8,41,70,36,0d,ca,a6,7d,10,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,6e,75,d2,de,ba,
82,08,32,fb,a7,78,e6,12,2f,9a,ea,fb,8a,e6,2f,fd,5a,6c,6e,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,54,c9,17,78,db,
1a,79,3e,01,3a,48,fc,e8,04,4a,f1,4e,cf,67,f1,08,bb,04,51,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,f1,a4,8d,75,da,
5f,00,3d,f6,0f,4e,58,98,5b,89,c9,88,f0,f5,d8,e9,ff,2e,21,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,c0,da,67,8b,5c,
8c,f1,40,3d,ce,ea,26,2d,45,aa,78,61,d8,12,7b,e2,ce,20,21,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,25,a4,83,e5,3a,
37,8e,85,2a,b7,cc,b5,b9,7f,41,e7,10,ef,a3,3a,f7,96,f7,f3,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,dd,c3,e8,13,20,
47,6e,04,6c,43,2d,1e,aa,22,2f,9c,14,5a,02,12,43,d6,21,2d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2652)
c:\program files\RocketDock\RocketDock.dll
c:\windows\system32\msi.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Heure de fin: 2009-07-07 19:09 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-07 17:09
Avant-CF: 1 457 831 936 octets libres
Après-CF: 2 351 153 152 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
Current=4 Default=4 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5
371 --- E O F --- 2009-07-07 01:07
J'y comprends pas grand chose là... que faire?
Merci
Stoukboy
"Qui fait le malin tombe dans le ravin!"