Voici mon LOG de COMBO...
ComboFix 09-08-29.01 - Gwen 30/08/2009 13:34.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.513 [GMT 2:00]
Running from: c:\documents and settings\Gwen\Bureau\GWEN.exe
AV: avast! antivirus 4.8.1229 [VPS 080723-1] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\10550154
c:\documents and settings\All Users\Application Data\10550154\10550154
c:\documents and settings\All Users\Application Data\10550154\10550154.exe
c:\documents and settings\All Users\Application Data\10550154\pc10550154ins
c:\documents and settings\All Users\Application Data\axucaheru.sys
c:\documents and settings\All Users\Application Data\byqozeniwa.reg
c:\documents and settings\All Users\Application Data\dadicag.ban
c:\documents and settings\All Users\Application Data\evidohove.pif
c:\documents and settings\All Users\Application Data\ifysowif.dl
c:\documents and settings\All Users\Application Data\igugu.dl
c:\documents and settings\All Users\Application Data\jiqevy.bat
c:\documents and settings\All Users\Application Data\loxysav.exe
c:\documents and settings\All Users\Application Data\nahe.scr
c:\documents and settings\All Users\Application Data\ofinatita.dll
c:\documents and settings\All Users\Application Data\osuzil.reg
c:\documents and settings\All Users\Application Data\yhatoruwik._dl
c:\documents and settings\All Users\Documents\bago.exe
c:\documents and settings\All Users\Documents\bepekuh.vbs
c:\documents and settings\All Users\Documents\cuqapu.bat
c:\documents and settings\All Users\Documents\dodemozizo.reg
c:\documents and settings\All Users\Documents\esetahu.sys
c:\documents and settings\All Users\Documents\genuxyh.reg
c:\documents and settings\All Users\Documents\hecinepu.dl
c:\documents and settings\All Users\Documents\ituqo.sys
c:\documents and settings\All Users\Documents\jiditecocu.inf
c:\documents and settings\All Users\Documents\uheryhohok.scr
c:\documents and settings\All Users\Documents\viruki.vbs
c:\documents and settings\Gwen\Application Data\agiciqub.sys
c:\documents and settings\Gwen\Application Data\apaxelunif.bat
c:\documents and settings\Gwen\Application Data\bofuny.exe
c:\documents and settings\Gwen\Application Data\exosodoli.dl
c:\documents and settings\Gwen\Application Data\fuhi._dl
c:\documents and settings\Gwen\Application Data\gukigovy.bin
c:\documents and settings\Gwen\Application Data\iqycavyk.dll
c:\documents and settings\Gwen\Application Data\lynotityme.com
c:\documents and settings\Gwen\Application Data\Microsoft\Internet Explorer\Quick Launch\PC_Antispyware2010.lnk
c:\documents and settings\Gwen\Application Data\oholawusu.dll
c:\documents and settings\Gwen\Application Data\qepuj.bat
c:\documents and settings\Gwen\Application Data\rylovulero._sy
c:\documents and settings\Gwen\Application Data\utiqydehej.ban
c:\documents and settings\Gwen\Application Data\wiaserva.log
c:\documents and settings\Gwen\Application Data\wygu.sys
c:\documents and settings\Gwen\Application Data\ywutegi.pif
c:\documents and settings\Gwen\Cookies\aguqeryji.scr
c:\documents and settings\Gwen\Cookies\awyqikog.sys
c:\documents and settings\Gwen\Cookies\cato.pif
c:\documents and settings\Gwen\Cookies\cygyf.sys
c:\documents and settings\Gwen\Cookies\giredewyqi.exe
c:\documents and settings\Gwen\Cookies\hevuri.bin
c:\documents and settings\Gwen\Cookies\ijevozaq.dl
c:\documents and settings\Gwen\Cookies\johav.exe
c:\documents and settings\Gwen\Cookies\rumubojazo.sys
c:\documents and settings\Gwen\Cookies\ryhyhik.reg
c:\documents and settings\Gwen\Cookies\tymoz.exe
c:\documents and settings\Gwen\Cookies\vuwafuburi.exe
c:\documents and settings\Gwen\Cookies\ylizonumyh.dll
c:\documents and settings\Gwen\Cookies\ytypavawo.bin
c:\documents and settings\Gwen\Cookies\ziwi.inf
c:\documents and settings\Gwen\delself.bat
c:\documents and settings\Gwen\Local Settings\Application Data\fegemanoc.sys
c:\documents and settings\Gwen\Local Settings\Application Data\gegun.reg
c:\documents and settings\Gwen\Local Settings\Application Data\ifyl.reg
c:\documents and settings\Gwen\Local Settings\Application Data\uvuki.bat
c:\documents and settings\Gwen\Local Settings\Application Data\vurihyno.sys
c:\documents and settings\Gwen\Local Settings\Application Data\wymekimuny.reg
c:\documents and settings\Gwen\Local Settings\Temporary Internet Files\hilo.exe
c:\documents and settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd
C:\G8K.EXE
c:\program files\Fichiers communs\ajysagiq.reg
c:\program files\Fichiers communs\akerilisoz._dl
c:\program files\Fichiers communs\apucy.reg
c:\program files\Fichiers communs\caqa.bat
c:\program files\Fichiers communs\ecyhozyw.com
c:\program files\Fichiers communs\jyjaf.sys
c:\program files\Fichiers communs\kofoc.ban
c:\program files\Fichiers communs\mamimup.inf
c:\program files\Fichiers communs\ominiga.bin
c:\program files\Fichiers communs\tywykefoli.dl
c:\program files\Fichiers communs\usynuwy.dl
c:\program files\Fichiers communs\vehevadufo.reg
c:\program files\INSTAFINK
c:\program files\PC_Antispyware2010
c:\program files\PC_Antispyware2010\AVEngn.dll
c:\program files\PC_Antispyware2010\data\daily.cvd
c:\program files\PC_Antispyware2010\htmlayout.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
c:\program files\PC_Antispyware2010\pthreadVC2.dll
c:\program files\PC_Antispyware2010\Uninstall.exe
c:\program files\PC_Antispyware2010\wscui.cpl
c:\program files\RXToolBar
c:\program files\RXToolBar\sfcont.bin
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\ajasis.dll
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\cynusixy._dl
c:\windows\daqakoxu.scr
c:\windows\disowur.scr
c:\windows\enaquluhup.exe
c:\windows\Fonts\Wendelin-Fett.ttf
c:\windows\Fonts\WendelinBreitfett.ttf
c:\windows\Fonts\WendelinNormal.ttf
c:\windows\Fonts\WendelinNormalKapitaelchen.ttf
c:\windows\Fonts\WendelinNormalKursiv.ttf
c:\windows\Installer\12e955d.msp
c:\windows\Installer\12e95a6.msp
c:\windows\iqupydyk.dl
c:\windows\isibowy.bin
c:\windows\ixuxuwib.bat
c:\windows\jiry.dl
c:\windows\jysune.ban
c:\windows\kyzon.bat
c:\windows\nelyqup.dl
c:\windows\ocivu.bat
c:\windows\pevawifo.dll
c:\windows\rufymaxin._dl
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\bazasop.scr
c:\windows\system32\bilysukedi.dll
c:\windows\system32\braviax.exe
c:\windows\system32\bylel.scr
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\dllcache\figaro.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\elehykuq.sys
c:\windows\system32\hysimi.pif
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\ijofahi.ban
c:\windows\system32\isytejun.dl
c:\windows\system32\o4Patch.exe
c:\windows\system32\Packet.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\ufoho.bat
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\wisdstr.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
c:\windows\tumiremiga.dl
c:\windows\uwenifozi.bin
c:\windows\uzemyva.vbs
c:\windows\veqiq.sys
c:\windows\wuhakahi.vbs
c:\windows\zeqygyte.exe
Infected copy of c:\windows\system32\drivers\beep.sys was found and disinfected
Restored copy from - c:\system volume information\_restore{7AFA028C-E8F6-455F-A5ED-7F0B3AC5359A}\RP829\A0072514.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_npf
-------\Service_npf
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.
2009-08-29 10:37 . 2009-08-29 10:37 11615 ----a-w- c:\windows\josik.com
2009-08-27 18:53 . 2009-08-27 18:53 17603 ----a-w- c:\program files\Fichiers communs\jikapy.dat
2009-08-27 18:53 . 2009-08-27 18:53 17314 ----a-w- c:\windows\eleqenuwi.dat
2009-08-26 21:29 . 2009-08-26 21:29 -------- d-----w- C:\PC_Antispyware2010
2009-08-26 21:24 . 2009-08-30 10:25 94016 -c--a-w- c:\windows\system32\dllcache\agp440.sys
2009-08-26 21:20 . 2009-08-26 21:20 -------- d-----w- C:\sh4ldr
2009-08-26 21:19 . 2009-08-26 21:19 -------- d-----w- c:\program files\Enigma Software Group
2009-08-26 20:47 . 2009-08-26 20:50 -------- d-----w- C:\UsbFix
2009-08-26 20:39 . 2009-08-26 20:39 -------- d-----w- C:\ToolBar SD
2009-08-26 20:26 . 2009-08-26 20:26 -------- d-----w- c:\program files\CCleaner
2009-08-26 20:23 . 2009-08-26 20:23 -------- d-----w- C:\Genproc
2009-08-26 20:13 . 2009-08-30 11:00 -------- d-----w- c:\program files\trend micro
2009-08-26 20:13 . 2009-08-26 20:13 -------- d-----w- C:\rsit
2009-08-26 20:09 . 2009-08-26 20:09 19471 ----a-w- c:\windows\system32\ducoxymi.dat
2009-08-25 21:59 . 2009-08-25 21:59 19475 ----a-w- c:\documents and settings\Gwen\Local Settings\Application Data\dyxelyxu.dat
2009-08-25 21:59 . 2009-08-25 21:59 15228 ----a-w- c:\windows\osuloze.com
2009-08-25 21:15 . 2009-08-25 21:15 12658 ----a-w- c:\windows\ivyvyvyh.dat
2009-08-25 20:40 . 2009-08-25 20:40 626336 -c--a-w- c:\windows\system32\dllcache\ntfs.sys
2009-08-25 20:40 . 2009-08-25 20:40 29507 ----a-w- c:\windows\system32\mset.exe
2009-08-25 20:40 . 2009-08-25 20:40 29507 ----a-w- c:\documents and settings\Gwen\mset.exe
2009-08-25 19:53 . 2009-08-26 19:47 113233 --sh--r- C:\hx.exe
2009-08-22 15:59 . 2009-08-22 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-08-22 15:56 . 2009-08-22 15:56 -------- d-----w- c:\program files\Fichiers communs\Adobe Systems Shared
2009-08-22 15:53 . 2004-08-17 00:40 16384 ----a-w- c:\windows\system32\FileOps.exe
2009-08-22 15:53 . 2009-08-22 15:53 -------- d-----w- c:\windows\system32\Adobe
2009-08-12 16:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:00 . 2009-08-05 09:00 205312 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-30 10:25 . 2008-04-13 18:36 94016 ----a-w- c:\windows\system32\drivers\agp440.sys
2009-08-29 22:07 . 2005-09-16 14:51 -------- d-----w- c:\program files\eMule
2009-08-29 10:37 . 2009-08-29 10:37 12805 ----a-w- c:\program files\Fichiers communs\kyxabuqebi._sy
2009-08-29 10:37 . 2009-08-29 10:37 12022 ----a-w- c:\program files\Fichiers communs\usutyjy.db
2009-08-26 21:09 . 2005-05-27 00:53 65362 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-26 21:09 . 2005-05-27 00:53 449322 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-25 22:04 . 2007-06-29 12:56 -------- d-----w- c:\program files\Visicom Media
2009-08-25 21:59 . 2009-08-25 21:59 11181 ----a-w- c:\documents and settings\Gwen\Application Data\tugu.dat
2009-08-25 21:15 . 2009-08-25 21:15 10770 ----a-w- c:\program files\Fichiers communs\mefacif.db
2009-08-25 20:40 . 2005-05-27 00:53 626336 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-22 19:58 . 2005-06-06 18:58 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-08-05 09:00 . 2005-05-27 00:53 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:03 . 2005-05-27 00:53 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2005-05-27 00:53 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 15:57 . 2005-05-27 00:53 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:57 . 2005-05-27 00:53 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:57 . 2005-05-27 00:53 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:40 . 2005-05-27 00:53 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:40 . 2005-05-27 00:53 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 10:44 . 2005-05-27 00:53 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:14 . 2005-05-27 00:53 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:21 . 2005-06-06 18:31 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2005-05-27 00:53 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:10 . 2005-05-27 00:53 1297408 ----a-w- c:\windows\system32\quartz.dll
.
------- Sigcheck -------
[-] 2007-02-09 11:23 574976 05AB81909514BFD69CBB1F2C147CF6B9 c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2007-02-09 11:10 574464 19A811EF5F1ED5C926A028CE107FF1AF c:\windows\$NtServicePackUninstall$\ntfs.sys
[7] 2004-08-05 12:00 574592 B78BE402C3F63DD55521F73876951CDD c:\windows\$NtUninstallKB930916$\ntfs.sys
[7] 2004-08-05 12:00 574592 B78BE402C3F63DD55521F73876951CDD c:\windows\I386\NTFS.SYS
[7] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01C5CDCA c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2009-08-25 20:40 626336 48B9B606133A0444E29E7D445A90AAFC c:\windows\system32\dllcache\ntfs.sys
[-] 2009-08-25 20:40 626336 48B9B606133A0444E29E7D445A90AAFC c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fsc-reminder.exe"="c:\windows\reminder\fsc-reminder.exe" [2005-01-19 28672]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 307200]
"mset"="c:\documents and settings\Gwen\mset.exe" [2009-08-25 29507]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-11-19 282624]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-21 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"mset"="c:\windows\system32\mset.exe" [2009-08-25 29507]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-04-02 868352]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-04-21 14291456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Gwen\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-8-10 110592]
ikowin32.exe [2008-4-14 23040]
c:\documents and settings\Gwen\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-8-10 110592]
ikowin32.exe [2008-4-14 23040]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe [2008-1-9 43520]
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-8-10 110592]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2005-9-7 962663]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-4-30 394856]
c:\documents and settings\Gwen\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-8-10 110592]
ikowin32.exe [2008-4-14 23040]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [18/02/2009 20:28 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18/02/2009 20:28 20560]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
HKLM-Run-Easy PDF Creator - c:\program files\Easy PDF Creator\EasyPDFCreator.exe
HKLM-Run-10550154 - c:\documents and settings\All Users\Application Data\10550154\10550154.exe
HKLM-Run-PC Antispyware 2010 - c:\program files\PC_Antispyware2010\PC_Antispyware2010.exe
HKLM-Run-adiras - adiras.exe
.
------- Supplementary Scan -------
.
uStart Page = www.google.com
mStart Page = hxxp://www.google.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {42E1F024-ECC3-456F-B98A-4CE5ACDBF25C} - hxxps://ssl-tb.sitadelle.com/selfcare.cegetel.net/templates/static/ocx/AFAutoConfig.ocx
FF - ProfilePath - c:\documents and settings\Gwen\Application Data\Mozilla\Firefox\Profiles\axuhr9g8.default\
FF - prefs.js: browser.startup.homepage - hxxp://msn.fr/
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-30 14:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(536)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
- - - - - - - > 'lsass.exe'(592)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
- - - - - - - > 'explorer.exe'(4412)
c:\program files\Enigma Software Group\SpyHunter\SpyHunterMonitor.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-30 14:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-30 12:07
Pre-Run: 34 291 482 624 octets libres
Post-Run: 34 304 716 800 octets libres
355 --- E O F --- 2009-08-29 21:36
http://translate.google.com/...
Si vous savez comment lire l'anglais, voir ici:
http://www.geekpolice.net/...