Voila :
ComboFix 09-10-26.03 - Administrateur 27/10/2009 11:12.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.588 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: avast! antivirus 4.8.1356 [VPS 091026-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Application Data\02000000dd9c1207691C.manifest
c:\documents and settings\Administrateur\Application Data\02000000dd9c1207691O.manifest
c:\documents and settings\Administrateur\Application Data\02000000dd9c1207691P.manifest
c:\documents and settings\Administrateur\Application Data\02000000dd9c1207691S.manifest
c:\windows\system32\LocalService
c:\windows\system32\LocalService\11.tmp
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-27 au 2009-10-27 ))))))))))))))))))))))))))))))))))))
.
2009-10-26 20:16 . 2009-10-26 20:16 -------- d-----w- c:\windows\Sun
2009-10-26 18:22 . 2009-10-26 19:25 -------- d-----w- C:\ToolBar SD
2009-10-26 18:12 . 2009-10-27 09:08 -------- d-----w- c:\program files\Ad-Remover
2009-10-26 09:10 . 2009-10-26 09:13 -------- d-----w- c:\program files\ZHPDiag
2009-10-25 14:22 . 2009-10-25 14:26 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-25 14:22 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-25 14:22 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-25 14:22 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-25 14:21 . 2009-10-25 14:21 -------- d-----w- c:\program files\Avira
2009-10-25 14:21 . 2009-10-25 14:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-10-24 15:17 . 2009-10-24 15:17 268288 ----a-w- c:\windows\system32\dpnwsock32.dll
2009-10-24 15:17 . 2009-10-24 15:17 268288 ----a-w- c:\windows\system32\d3dx9_2532.dll
2009-10-24 15:12 . 2009-10-24 15:12 268288 ----a-w- c:\windows\system32\CMDLGFR32.dll
2009-10-24 15:10 . 2009-10-24 15:10 268288 ----a-w- c:\windows\system32\d3dx9_2932.dll
2009-10-24 15:10 . 2009-10-24 15:10 125440 ----a-w- c:\windows\system32\d3dx9_2432.dll
2009-10-24 14:37 . 2009-10-24 15:21 -------- d-----w- c:\documents and settings\Administrateur\Application Data\LimeWire
2009-10-21 17:40 . 2009-10-21 17:41 -------- d-----w- c:\program files\GeoGebra
2009-10-21 17:39 . 2009-10-21 17:41 -------- d--h--w- c:\program files\Zero G Registry
2009-10-21 17:39 . 2009-10-21 17:39 -------- d--h--w- c:\documents and settings\Administrateur\InstallAnywhere
2009-10-20 20:11 . 2009-10-25 20:31 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
2009-10-20 19:07 . 2009-10-26 19:35 -------- d-----w- c:\documents and settings\Administrateur\Application Data\vlc
2009-10-20 19:06 . 2009-10-20 19:06 -------- d-----w- c:\program files\VideoLAN
2009-10-19 20:13 . 2009-10-26 09:16 -------- d-----w- c:\documents and settings\Administrateur\Application Data\GrabIt
2009-10-19 20:10 . 2009-10-19 20:10 -------- d-----w- c:\program files\GrabIt
2009-10-17 11:26 . 2009-10-17 11:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Apple
2009-10-17 11:26 . 2009-10-17 11:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Apple Computer
2009-10-17 10:26 . 2009-10-17 10:27 -------- d-----w- c:\program files\QuickTime
2009-10-17 10:26 . 2009-10-17 10:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-17 10:26 . 2009-10-17 10:26 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-10-17 10:26 . 2009-10-17 10:26 -------- d-----w- c:\program files\Apple Software Update
2009-10-17 10:26 . 2009-10-17 10:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-17 10:22 . 2007-11-06 07:06 32080 ----a-w- c:\windows\system32\drivers\UimBus.sys
2009-10-17 10:22 . 2007-11-06 07:06 11568 ----a-w- c:\windows\system32\drivers\UimFIO.sys
2009-10-17 10:22 . 2007-11-06 07:06 131672 ----a-w- c:\windows\system32\drivers\Uim_IM.sys
2009-10-17 10:22 . 2008-10-29 18:25 40368 ----a-w- c:\windows\system32\drivers\hotcore3.sys
2009-10-17 10:22 . 2008-10-29 18:25 247560 ----a-w- c:\windows\system32\prgiso.dll
2009-10-17 10:22 . 2008-10-29 18:25 4244744 ----a-w- c:\windows\system32\qtp-mt334.dll
2009-10-17 10:22 . 2008-10-29 18:25 13576 ----a-w- c:\windows\system32\wnaspi32.dll
2009-10-16 16:45 . 2009-10-16 16:45 -------- d-----w- c:\program files\PhotoFiltre
2009-10-12 18:00 . 2009-10-12 18:00 -------- d-----w- c:\program files\VirginMega
2009-10-12 18:00 . 2009-10-12 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-10-11 15:52 . 2009-10-11 15:52 -------- d-----w- c:\program files\CalcCF_Standart
2009-10-11 11:42 . 2009-10-27 09:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-11 11:42 . 2009-10-11 11:42 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-11 11:39 . 2009-09-15 10:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-10-11 11:39 . 2009-09-15 10:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-10-11 11:39 . 2009-09-15 10:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-10-11 11:39 . 2009-09-15 10:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-11 11:39 . 2009-09-15 10:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-11 11:39 . 2009-09-15 10:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-10-11 11:39 . 2009-09-15 10:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-10-11 11:39 . 2009-09-15 10:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-10-11 11:39 . 2009-09-15 10:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-11 11:39 . 2009-10-11 11:39 -------- d-----w- c:\program files\Alwil Software
2009-10-11 09:25 . 2008-04-13 17:33 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2009-10-11 09:25 . 2008-04-13 17:33 21504 ----a-w- c:\windows\system32\hidserv.dll
2009-10-11 09:25 . 2001-08-23 15:04 12288 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-10-11 09:25 . 2001-08-23 15:04 12288 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-10-11 09:12 . 2009-10-25 16:38 -------- d-----w- c:\windows\system32\NtmsData
2009-10-11 09:11 . 2008-04-13 09:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-10-11 09:11 . 2008-04-13 09:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-10-09 19:39 . 2009-10-26 18:09 -------- d-----w- c:\documents and settings\Administrateur\Tracing
2009-10-09 18:38 . 2009-10-09 18:38 -------- d-----w- c:\program files\Microsoft
2009-10-09 18:37 . 2009-10-09 18:37 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-09 18:37 . 2009-10-09 18:37 -------- d-----w- c:\program files\Windows Live
2009-10-09 18:34 . 2009-10-09 18:34 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-10-04 13:37 . 2009-10-04 13:37 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Leadertech
2009-10-04 12:17 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll
2009-10-04 12:17 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2009-10-04 12:17 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2009-10-04 12:17 . 2007-04-04 16:53 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2009-10-04 12:17 . 2007-03-12 14:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2009-10-04 12:17 . 2006-11-29 11:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-04 12:17 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-10-04 12:16 . 2005-05-26 13:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2009-10-04 12:16 . 2009-10-04 12:16 -------- d-----w- c:\program files\EA Sports
2009-10-04 11:46 . 2009-10-04 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-10-04 11:45 . 2009-10-09 18:26 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-10-04 11:29 . 2009-10-04 13:00 -------- d-----w- c:\documents and settings\Administrateur\Application Data\DAEMON Tools Lite
2009-10-04 10:30 . 2009-10-04 10:30 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 09:46 . 2008-04-14 12:00 75704 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-27 09:46 . 2008-04-14 12:00 468728 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-26 21:09 . 2009-02-09 19:49 -------- d-----w- c:\program files\Unlocker
2009-10-24 15:10 . 2009-10-24 15:10 0 ----a-w- c:\windows\system32\11A.tmp
2009-10-20 18:46 . 2009-10-20 18:46 -------- d-----w- c:\program files\Free Audio Pack
2009-10-17 10:39 . 2009-02-09 19:38 -------- d-----w- c:\program files\CCleaner
2009-10-17 10:22 . 2009-02-11 13:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 10:21 . 2009-02-11 13:52 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-10-11 16:29 . 2009-02-09 19:50 -------- d-----w- c:\program files\7-Zip
2009-10-10 13:35 . 2009-02-09 19:44 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-09 18:39 . 2009-02-09 19:57 9824 ------w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
[-] 2008-09-04 . 8E036EEC565910417EA020CE0962AA24 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-09-04 . DE669722494CF41F6E39A62B3B08525C . 561152 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
[-] 2008-09-04 . D449DF66B6335B443508A58B1E8DB996 . 647680 . . [5.82] . . c:\windows\system32\comctl32.dll
[-] 2008-09-04 . A29DB757495C2CF29CC6404A4FC2D95A . 2294784 . . [5.1.2600.5512] . . c:\windows\system32\ntoskrnl.exe
[-] 2008-09-10 . 51E08BBC577C2C097502D9E6F2C237F9 . 508928 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2008-09-04 . 3C127370AA63C7D9FD756BB4BE173427 . 1573888 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-09-04 . 6AC91D4616ABCA6447DB626815C820CC . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
[-] 2008-09-04 . 58DB2EE838D5B7BAD0F7F10A6C920390 . 40960 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[-] 2008-09-04 . 68ED954685FA2D5403B0ADCAE0745BFE . 2173440 . . [5.1.2600.5512] . . c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0114CD2F-47AE-44BA-9D4A-B4AF2C432C7e}]
2009-10-24 15:17 268288 ----a-w- c:\windows\system32\dpnwsock32.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-05 280779]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2006-06-23 225280]
"LogitechCameraAssistant"="c:\program files\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 331776]
"LogitechVideo[inspector]"="c:\program files\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 14:55 73728]
"LogitechCameraService(E)"="c:\windows\system32\ElkCtrl.exe" [2004-11-01 262144]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-30 13594624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-30 86016]
"avast!"="c:\program files\Alwil Software\Avast4\ashDisp.exe" [2009-09-15 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-01-11 15961088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-01-30 1657376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-09-04 40960]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2008-09-05 124928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):6c,00,6f,00,67,00,6f,00,6e,00,75,00,69,00,32,00,2e,00,65,00,78,\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\8020a991691]
2009-10-24 15:10 125440 ----a-w- c:\windows\system32\d3dx9_2432.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA Sports\\FIFA 10\\FIFA10.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [17/10/2009 11:22 40368]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/10/2009 12:39 114768]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [25/10/2009 15:22 108289]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/10/2009 12:39 20560]
R3 lv321av;Logitech USB PC Camera (VC0321);c:\windows\system32\drivers\lv321av.sys [14/02/2009 18:11 1097728]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [24/01/2009 14:46 216232]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contenu du dossier 'Tâches planifiées'
2009-10-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://free.fr/
mWindow Title =
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\xwx6apt4.default\
FF - prefs.js: browser.startup.homepage - hxxp://fr-fr.facebook.com/
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
Toolbar-{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - c:\program files\Dealio Toolbar\DealioToolbarIE.dll
HKLM-RunOnce-<NO NAME> - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-27 11:16
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\SETUPAPI.dll
c:\windows\System32\d3dx9_2432.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(732)
c:\windows\System32\d3dx9_2432.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\scecli.dll
.
Heure de fin: 2009-10-27 11:17
ComboFix-quarantined-files.txt 2009-10-27 10:17
Avant-CF: 49 190 113 280 octets libres
Après-CF: 49 261 068 288 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 2B284EAD7AF2BED15FE3E8E11ECBEAAD