Voilà le rapport ComboFix:
ComboFix 09-10-21.02 - Real 2009-10-23 0:04.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.245 [GMT -4:00]
Lancé depuis: c:\documents and settings\Real\Bureau\XaTon.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Real\Application Data\inst.exe
c:\recycler\S-1-5-21-436374069-299502267-725345543-1009
c:\windows\Fonts\acrsec.fon
c:\windows\pack.epk
c:\windows\system32\clrviddc.dll
c:\windows\system32\NTSVc.ocx
E:\resycled
e:\resycled\boot.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SVCPROC
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-23 au 2009-10-23 ))))))))))))))))))))))))))))))))))))
.
2009-10-22 22:58 . 2009-10-23 03:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-22 22:27 . 2009-10-22 22:28 -------- d-----w- c:\windows\4761EB82E8BD45A4B19B586FA9D1D7E6.TMP
2009-10-19 22:51 . 2009-10-19 22:51 -------- d-----w- c:\program files\SBaGen
2009-10-19 22:11 . 2009-10-19 22:11 -------- d-----w- c:\documents and settings\Real\Application Data\SharePod
2009-10-14 06:00 . 2009-08-04 17:27 2147328 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-14 06:00 . 2009-08-04 17:27 2025984 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-14 06:00 . 2009-08-04 17:28 2068096 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-13 16:41 . 2009-10-13 16:41 -------- d-sh--w- c:\documents and settings\Real\IECompatCache
2009-10-13 16:03 . 2009-10-14 17:04 -------- d-----w- c:\windows\ie8updates
2009-10-13 10:39 . 2009-08-29 07:56 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-13 10:39 . 2009-08-29 07:56 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-10-12 22:12 . 2009-10-12 22:12 -------- d-sh--w- c:\documents and settings\Real\PrivacIE
2009-10-12 22:01 . 2009-10-12 22:01 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-12 21:56 . 2009-10-12 21:56 -------- d-sh--w- c:\documents and settings\Real\IETldCache
2009-10-12 20:52 . 2009-10-12 20:52 -------- d--h--w- c:\windows\msdownld.tmp
2009-10-12 20:44 . 2009-10-12 20:52 -------- dc-h--w- c:\windows\ie8
2009-10-11 21:53 . 2009-10-11 21:53 -------- d-----w- C:\rsit
2009-10-11 03:15 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-11 03:15 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-11 03:15 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-11 03:15 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-11 03:14 . 2009-10-11 03:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-09 22:43 . 2009-10-09 22:44 -------- d-----w- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-23 04:55 . 2008-10-11 22:53 -------- d-----w- c:\program files\DNA
2009-10-23 04:55 . 2008-10-11 22:53 -------- d-----w- c:\documents and settings\Real\Application Data\DNA
2009-10-22 22:37 . 2009-02-10 02:42 96 ---ha-w- c:\windows\system32\HsInfo.dat
2009-10-22 22:30 . 2009-02-27 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-10-19 22:49 . 2007-04-15 19:48 -------- d-----w- c:\documents and settings\Real\Application Data\utorrent
2009-10-17 17:59 . 2009-01-23 16:23 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-10-15 23:40 . 2008-04-21 23:43 -------- d-----w- c:\documents and settings\Real\Application Data\FileZilla
2009-10-14 17:19 . 2003-04-24 12:00 85354 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-14 17:19 . 2003-04-24 12:00 511248 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-14 16:28 . 2008-04-10 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-10 22:50 . 2009-02-03 20:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-10 16:44 . 2009-07-15 20:49 -------- d-----w- c:\documents and settings\Real\Application Data\Skype
2009-10-10 16:07 . 2009-07-15 22:01 -------- d-----w- c:\documents and settings\Real\Application Data\skypePM
2009-10-05 12:35 . 2009-09-03 23:47 -------- d-----w- c:\documents and settings\Real\Application Data\FrostWire
2009-09-27 19:04 . 2007-12-12 20:31 -------- d-----w- c:\documents and settings\Real\Application Data\AdobeUM
2009-09-19 22:09 . 2009-09-19 22:09 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-19 22:09 . 2009-09-19 22:09 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-19 22:08 . 2009-09-19 22:08 -------- d-----w- c:\documents and settings\Real\Application Data\TuneUp Software
2009-09-19 22:07 . 2009-09-19 22:05 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-09-19 22:06 . 2009-09-19 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-09-19 22:03 . 2009-09-19 22:03 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-09-11 14:18 . 2003-04-24 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 18:54 . 2009-02-03 20:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-02-03 20:59 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 16:26 . 2008-04-09 22:08 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 21:19 . 2004-12-06 21:44 -------- d-----w- c:\program files\Google
2009-09-07 16:30 . 2009-09-07 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-04 21:04 . 2003-04-24 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:56 . 2004-07-07 22:59 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:01 . 2003-04-24 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-15 22:48 . 2007-02-01 00:12 15440 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-08-08 22:37 . 2004-09-24 10:39 280352 ----a-w- c:\documents and settings\Real\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:00 . 2004-07-24 19:50 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:58 . 2003-04-24 12:00 2191232 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 17:28 . 2002-08-29 11:42 2068096 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-04-06 19:36 . 2004-12-06 21:44 104 --sh--r- c:\windows\system32\548975A7D3.sys
2006-07-11 21:08 . 2006-07-11 21:08 8 --sh--r- c:\windows\system32\D426C53B9E.sys
2006-07-11 21:13 . 2004-12-06 21:44 5018 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-03 3882312]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Google Update"="c:\documents and settings\Real\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-29 133104]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-04-28 692224]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-18 342848]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-10-17 2920632]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150600.exe" [2009-06-05 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Symantec PIF AlertEng"="c:\program files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-09-25 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"SetDefPrt"="e:\brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]
"avgnt"="e:\avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-22 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-08-15 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\Real\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-9-20 110592]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-9-24 282624]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-6-8 16432]
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 630915]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="e:\itunes\iTunesHelper.exe"
"BrMfcWnd"=c:\program files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\uTorrent\\uTorrent.exe"=
"e:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"64801:TCP"= 64801:TCP:*:Disabled:SolidNetworkManager
"64801:UDP"= 64801:UDP:*:Disabled:SolidNetworkManager
"44405:TCP"= 44405:TCP:MU
"55901:TCP"= 55901:TCP:Mu
"58253:TCP"= 58253:TCP:Pando Media Booster
"58253:UDP"= 58253:UDP:Pando Media Booster
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
"57728:TCP"= 57728:TCP:Pando Media Booster
"57728:UDP"= 57728:UDP:Pando Media Booster
"23530:TCP"= 23530:TCP:*:Disabled:SolidNetworkManager
"23530:UDP"= 23530:UDP:*:Disabled:SolidNetworkManager
"56987:TCP"= 56987:TCP:Pando Media Booster
"56987:UDP"= 56987:UDP:Pando Media Booster
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;e:\avira\AntiVir Desktop\sched.exe [2009-10-10 108289]
R2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CAMTHWDM.sys [2009-07-16 1051136]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-09-19 604488]
R2 wmcmgc;Windows Management Configuration;c:\windows\System32\svchost.exe -k netsvcs [2003-04-24 14336]
S2 gupdate1c9f5e055f9e57c;Google Update Service (gupdate1c9f5e055f9e57c);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-25 133104]
S3 cheetah1;cheetah1;\??\c:\documents and settings\Real\Mes documents\Marco\OK_hack_pack\Cheetah Engine\cheetah.sys --> c:\documents and settings\Real\Mes documents\Marco\OK_hack_pack\Cheetah Engine\cheetah.sys [?]
S3 DBKDRVR54;DBKDRVR54;\??\c:\program files\Cheat Engine\dbk32.sys --> c:\program files\Cheat Engine\dbk32.sys [?]
S3 geebers12;geebers12;\??\c:\documents and settings\Real\Mes documents\Marco\Hack\nvid888.sys --> c:\documents and settings\Real\Mes documents\Marco\Hack\nvid888.sys [?]
S3 Ndisprot;ArcNet NDIS Protocol Driver;c:\windows\system32\drivers\ndisprot.sys [2008-10-21 27904]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 Revolution1;Revolution1;\??\c:\documents and settings\Real\Bureau\Jeu Marco\GBhacks\SHAK3.sys --> c:\documents and settings\Real\Bureau\Jeu Marco\GBhacks\SHAK3.sys [?]
S3 sejt1;sejt1;\??\c:\documents and settings\Real\Mes documents\Marco\AkumaEngine33\sejt.sys --> c:\documents and settings\Real\Mes documents\Marco\AkumaEngine33\sejt.sys [?]
S3 XDva008;XDva008;\??\c:\windows\system32\XDva008.sys --> c:\windows\system32\XDva008.sys [?]
S3 XDva009;XDva009;\??\c:\windows\system32\XDva009.sys --> c:\windows\system32\XDva009.sys [?]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva042;XDva042;\??\c:\windows\system32\XDva042.sys --> c:\windows\system32\XDva042.sys [?]
S3 XDva068;XDva068;\??\c:\windows\system32\XDva068.sys --> c:\windows\system32\XDva068.sys [?]
S3 XDva072;XDva072;\??\c:\windows\system32\XDva072.sys --> c:\windows\system32\XDva072.sys [?]
S3 XDva076;XDva076;\??\c:\windows\system32\XDva076.sys --> c:\windows\system32\XDva076.sys [?]
S3 XDva189;XDva189;\??\c:\windows\system32\XDva189.sys --> c:\windows\system32\XDva189.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
wmcmgc
wmcmgc
.
Contenu du dossier 'Tâches planifiées'
2009-10-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-28 16:28]
2009-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-25 22:00]
2009-10-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-25 22:00]
2009-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-299502267-725345543-1004Core.job
- c:\documents and settings\Real\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-29 05:30]
2009-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-299502267-725345543-1004UA.job
- c:\documents and settings\Real\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-29 05:30]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Download with Xilisoft Download YouTube Video - c:\program files\Xilisoft\Download YouTube Video\upod_link.HTM
IE: E&xporter vers Microsoft Excel - e:\micros~1\Office12\EXCEL.EXE/3000
Trusted Zone: wolfteam.net
FF - ProfilePath - c:\documents and settings\Real\Application Data\Mozilla\Firefox\Profiles\7p7x44ml.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.shinysearch.com/randomlogo.php?ltext=Marco<ext=Marco
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff35\gears.dll
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\Real\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\np32asw.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npaudio.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npavi32.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPBeatSP.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npdrmv2.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npdsplay.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJava11.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJava12.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJava13.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJava14.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJava32.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPJPI142.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npnul32.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPOFF12.DLL
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPOFFICE.DLL
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPOJI610.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\nppl3260.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin2.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin3.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin4.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin5.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin6.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npqtplugin7.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\nprfxins.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\nprjplug.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\nprpjplug.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\NPSVG3.dll
FF - plugin: c:\progra~1\SYMPAT~1\COMMUN~1\Program\Plugins\npwmsdrm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1698.5652\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npagent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npssn.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\windows\system32\SolidStateNetworks\SolidStateION\npssn.dll
FF - plugin: e:\itunes\Mozilla Plugins\npitunes.dll
FF - plugin: e:\opera\program\plugins\npdsplay.dll
FF - plugin: e:\opera\program\plugins\NPSWF32.dll
FF - plugin: e:\opera\program\plugins\npwmsdrm.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.00.19);user_pref(general.useragent.extra.zencast, .
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-CmPCIaudio - CMICNFG3.CPL
AddRemove-HijackThis - E:\HijackThis.exe
AddRemove-SolidStateIONMozilla - c:\windows\system32\SolidStateNetworks\SolidStateION\soliduninstall
AddRemove-SWF & FLV Toolbox_is1 - e:\swf & flv toolbox\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-23 00:54
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-436374069-299502267-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:4f,bb,a2,a7,72,68,de,d8,3f,c3,7d,b8,1c,be,f5,1d,cb,e9,d0,07,56,
cc,7a,88,23,d9,67,80,62,dc,5b,67,fd,13,78,c4,41,d8,a9,07,c2,ef,d4,9a,f6,3b,\
"rkeysecu"=hex:ea,7f,a3,81,37,8f,c8,4c,67,90,51,4d,d0,51,61,6b
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(584)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(704)
E:\tmpIadHide3.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
e:\avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\xaton\CF5138.exe
e:\maplestory\npkcmsvc.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\documents and settings\Real\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\xaton\PEV.cfxxe
.
**************************************************************************
.
Heure de fin: 2009-10-23 1:15 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-23 05:14
Avant-CF: 1 203 994 624 octets libres
Après-CF: 405 651 456 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptOut
- - End Of File - - A6370AD084659D918185D72C249544E5