Slt kduc! Merci pour le coup de main. Voici le rapport
ComboFix 09-07-19.02 - Administrateur 19/07/2009 22:27.1.1 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.254.97 [GMT 1:00]
Running from: c:\documents and settings\Administrateur\Bureau\Combo-Fix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\instant access
c:\program files\instant access\Center\NoCreditCard.lnk
c:\program files\instant access\DesktopIcons\NoCreditCard.lnk
c:\program files\instant access\Multi\20090309100315\Common\module.php
c:\program files\instant access\Multi\20090309100315\dialerexe.ini
c:\program files\instant access\Multi\20090309100315\js\js_api_dialer.php
c:\program files\instant access\Multi\20090309100315\medias\button1.gif
c:\program files\instant access\Multi\20090309100315\medias\button2.gif
c:\program files\instant access\Multi\20090309100315\medias\button3.gif
c:\program files\instant access\Multi\20090309100315\medias\button4.gif
c:\program files\instant access\Multi\20090309100315\medias\dialer.ico
c:\windows\dialerexe.ini
c:\windows\Installer\1fc71.msp
c:\windows\Installer\1fca4.msp
c:\windows\Installer\1fca5.msp
c:\windows\Installer\1fcae.msp
c:\windows\Installer\1fcfb.msp
c:\windows\Installer\1fcfc.msp
c:\windows\Installer\2b3a6.msp
c:\windows\Installer\362e1.msp
c:\windows\Installer\387fd.msp
c:\windows\system32\bycool1
c:\windows\system32\bycool1\windo.exe
c:\windows\system32\Cache
c:\windows\system32\msconfig.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.
2009-07-18 12:57 . 2009-07-18 12:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2009-07-13 07:59 . 2008-04-13 10:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-07-13 07:59 . 2008-04-13 10:45 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-07-12 20:12 . 2009-07-12 20:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-12 20:12 . 2009-07-12 20:12 -------- d-----w- c:\windows\Setup2K
2009-07-12 20:12 . 2005-06-25 09:04 53248 ----a-w- c:\windows\ap561.exe
2009-07-12 20:12 . 2002-11-22 14:56 118784 ----a-w- c:\windows\ShowBmp.exe
2009-07-12 20:12 . 2002-10-01 13:43 119798 ----a-w- c:\windows\system32\drivers\spca561.sys
2009-07-12 06:09 . 2009-07-12 06:09 -------- d-sh--w- C:\FOUND.035
2009-07-06 14:49 . 2009-07-06 14:49 -------- d-sh--w- C:\FOUND.034
2009-07-01 14:32 . 2009-07-01 14:33 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-30 17:16 . 2009-06-30 17:16 -------- d-sh--w- C:\FOUND.033
2009-06-28 14:44 . 2009-06-28 14:44 -------- d-sh--w- C:\FOUND.032
2009-06-24 17:51 . 2009-06-24 17:51 -------- d-sh--w- C:\FOUND.031
2009-06-24 13:18 . 2009-06-24 13:18 -------- d-----w- c:\program files\Windows Live Safety Center
2009-06-23 19:11 . 2009-06-23 19:11 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Bandoo
2009-06-23 19:10 . 2009-06-23 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Bandoo
2009-06-23 19:09 . 2009-06-23 19:09 -------- d-----w- c:\program files\Bandoo
2009-06-20 08:02 . 2009-06-20 08:02 -------- d-sh--w- C:\FOUND.030
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 18:33 . 2003-10-19 23:40 66352 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-23 16:26 . 2001-08-28 13:00 86898 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-23 16:26 . 2001-08-28 13:00 509446 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-07 14:34 . 2009-06-07 14:34 52536 ---ha-w- c:\windows\system32\mlfcache.dat
2009-06-06 13:28 . 2009-06-06 13:28 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Apple Computer
2009-06-06 13:09 . 2009-06-06 13:09 -------- d-----w- c:\program files\Safari
2009-06-06 13:09 . 2009-06-06 13:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-06 13:08 . 2009-06-06 13:08 -------- d-----w- c:\program files\Bonjour
2009-06-06 13:07 . 2009-06-06 13:07 -------- d-----w- c:\program files\Apple Software Update
2009-06-06 13:07 . 2009-06-06 13:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-06-04 16:35 . 2009-06-04 16:35 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Tomato
2009-06-04 16:35 . 2009-06-04 16:35 -------- d-----w- c:\program files\Fichiers communs\Tomato
2009-06-04 16:35 . 2009-06-04 16:35 -------- d-----w- c:\program files\Tomato
2009-06-03 20:19 . 2009-06-03 20:20 512096 ----a-w- c:\windows\system32\drivers\amon.sys
2009-06-03 20:19 . 2009-06-03 20:20 298104 ----a-w- c:\windows\system32\imon.dll
2009-06-03 20:19 . 2009-06-03 20:20 15424 ----a-w- c:\windows\system32\drivers\nod32drv.sys
2009-06-03 20:19 . 2009-06-03 20:19 -------- d-----w- c:\program files\ESET
2009-06-02 19:36 . 2009-06-02 19:36 -------- d-----w- c:\program files\Kaspersky Lab
2009-06-02 19:08 . 2009-06-02 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-29 15:20 . 2009-05-29 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-13 20:00 . 2009-05-13 20:00 198064 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
2009-05-13 05:04 . 2008-05-24 00:35 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 18:44 . 2009-05-07 18:36 2916720 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\idmupdt.exe
2009-05-07 15:33 . 2008-04-13 18:33 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 10:42 . 2009-05-05 10:42 88576 ---ha-w- c:\documents and settings\Administrateur\Application Data\rbap550.dll
2009-05-05 10:42 . 2009-05-05 10:42 88576 ---ha-w- c:\documents and settings\Administrateur\Application Data\rbap550.dll
2009-05-05 10:42 . 2009-05-05 10:42 29184 ---ha-w- c:\documents and settings\Administrateur\Application Data\RBInternetEncodings550.dll
2009-05-05 10:42 . 2009-05-05 10:42 29184 ---ha-w- c:\documents and settings\Administrateur\Application Data\RBInternetEncodings550.dll
2009-04-30 08:15 . 2009-04-30 08:15 78080 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\vmAVGConnector.dll
2009-04-30 08:15 . 2009-04-30 08:15 563456 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\dtuser.exe
2009-04-30 08:15 . 2009-04-30 08:15 2223872 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtoolbar.dll
2009-04-24 08:23 . 2009-04-24 08:23 1083672 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-04-24 08:23 . 2009-04-24 08:23 1437464 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-04-24 08:23 . 2009-04-24 08:23 587032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgiproxy.exe
2009-04-24 08:23 . 2009-04-24 08:23 755992 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avginet.dll
2009-03-31 18:43 . 2009-01-24 12:57 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
------- Sigcheck -------
[-] 2008-06-01 22:09 1571840 F83D7C868B3D22FB33745D57CCC65684 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
2009-06-17 13:49 1858496 ----a-w- c:\program files\Bandoo\Plugins\IE\ieplugin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-23 68856]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-01-20 2823784]
"ares"="c:\program files\Ares\Ares.exe" [2009-01-21 968704]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"IDMan"="c:\documents and settings\Administrateur\Bureau\IDM516full\IDM516full\IDMan.exe" [2009-05-07 2790832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2008-06-01 196608]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2003-07-09 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-07-09 114688]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-06-03 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2009-1-10 208896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoFileUrl"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoFileUrl"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoFileUrl"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\CCP Client\\CCPClient.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\onenote.exe"=
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [24/05/2008 01:37 210224]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [03/06/2009 21:20 15424]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [24/03/2009 21:42 55152]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
S2 gupdate1c987856a8b5a8c;Google Update Service (gupdate1c987856a8b5a8c);c:\program files\Google\Update\GoogleUpdate.exe [05/02/2009 12:32 133104]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 mpr_freader;MPR FileReader Driver;\??\c:\program files\Multi Password Recovery\mpr_freader.sys --> c:\program files\Multi Password Recovery\mpr_freader.sys [?]
S3 printio;printio;\??\c:\documents and settings\Administrateur\Mes documents\Downloads\Compressed\kNok-Phoenix2100_support\kNok-Phoenix\printio.sys --> c:\documents and settings\Administrateur\Mes documents\Downloads\Compressed\kNok-Phoenix2100_support\kNok-Phoenix\printio.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HELPSVC
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-07-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-10 07:05]
2009-07-19 c:\windows\Tasks\User_Feed_Synchronization-{8FA6B771-5A4D-4301-BA22-672D7555801F}.job
- c:\windows\system32\msfeedssync.exe [2003-10-19 03:31]
2009-07-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 11:32]
2009-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 11:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DRIVESYS1 - c:\windows\System32\bycool1\windo.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://fr.yahoo.com/
uDefault_Search_URL = hxxp://www.google.fr/keyword/%s
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://fr.search.yahoo.com
IE: Download Video on This Page - c:\program files\Tomato\YouTube Video Downloader\MDIEEx.dll/211
IE: Download Video This Links To - c:\program files\Tomato\YouTube Video Downloader\MDIEEx.dll/212
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\documents and settings\Administrateur\Bureau\IDM516full\IDM516full\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - c:\documents and settings\Administrateur\Bureau\IDM516full\IDM516full\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - c:\documents and settings\Administrateur\Bureau\IDM516full\IDM516full\IEGetAll.htm
IE: {{11F19C45-9675-488A-A8E0-8E8234DC245D} - res://c:\program files\Tomato\YouTube Video Downloader\MDIEEx.dll/211
LSP: c:\windows\system32\imon.dll
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
TCP: {304C2309-B124-427E-8C76-68F1F44B4988} = 212.31.224.2,212.31.224.3
DPF: {E1342154-4889-42B5-BEF6-19237577048F} - hxxp://www.gamenext.fr/online/online2/zuma/oberongamesloader.cab
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\2ykayol9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://fr.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\documents and settings\Administrateur\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}\components\FFAlert.dll
FF - plugin: c:\documents and settings\Administrateur\Application Data\Vusion\npWARPVideoPlugin.311634.dll
FF - plugin: c:\documents and settings\Administrateur\Application Data\Vusion\warpvideo@vusion.com\platform\WINNT_x86-msvc\plugins\npWARPVideoPlugin.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Opera\program\plugins\nporbit.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 22:39
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc24.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1085031214-412668190-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c0,66,5d,d7,9c,af,51,4f,9f,75,f0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c0,66,5d,d7,9c,af,51,4f,9f,75,f0,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0b6d0af7-cba2-4509-b87d-ef63631a7c30}]
@Denied: (Full) (Everyone)
"Model"=dword:000000c6
"Therad"=dword:00000021
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,d3,ba,47,d9,ef,0f,e4,1e,83,43,a8,7a,57,bd,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{291257c2-0d4c-450d-a07c-5c71a4a53418}]
@Denied: (Full) (Everyone)
"Model"=dword:0000002e
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):30,86,72,26,4f,d1,bb,98,30,97,c2,92,4b,87,2a,23,68,94,58,47,e6,
b1,03,94,33,35,a1,80,25,44,ba,54,02,9b,60,b7,f6,72,e6,62,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):b1,3c,b3,8c,15,93,10,f4,e8,f3,0a,a3,85,eb,cf,ec,21,92,a0,ae,f5,
43,77,4f,83,36,9c,49,26,ab,86,1d,c5,df,19,72,70,97,f0,39,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(740)
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(1184)
c:\program files\SuperCopier2\SC2Hook.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\ESET\NOD32KRN.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\progra~1\BANDOO\BANDOO.EXE
c:\program files\Apoint2K\Apntex.exe
c:\documents and settings\Administrateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2009-07-19 22:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-19 21:44
Pre-Run: 2 253 258 752 octets libres
Post-Run: 2 994 323 456 octets libres
295 --- E O F --- 2009-07-18 12:22