Bonjour
Non, j'ai vu ça en potassant les forums de ci de là, mais vus les avertissements sur son utilisation, je ne m'en suis pas encore servi. Je me doutais bien que j'allais y passer !
Voici donc le rapport tout frais :
ComboFix 10-01-11.04 - Leon 13/01/2010 12:59:29.3.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3615.3181 [GMT 1:00]
Lancé depuis: c:\documents and settings\Leon\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Pare-feu Online Armor *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-13 au 2010-01-13 ))))))))))))))))))))))))))))))))))))
.
2010-01-12 22:11 . 2008-04-14 02:34 14336 ------w- c:\windows\system32\svchost.exe
2010-01-12 17:12 . 2010-01-12 17:12 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
2010-01-12 17:06 . 2010-01-12 17:06 -------- d-----w- c:\windows\ERUNT
2010-01-12 17:00 . 2010-01-12 22:38 -------- d-----w- C:\SDFix
2010-01-12 08:22 . 2010-01-12 08:23 -------- d-----w- C:\rsit
2010-01-11 23:07 . 2010-01-11 23:07 -------- d-----w- c:\program files\Trend Micro
2010-01-11 20:54 . 2010-01-12 23:52 52224 ----a-w- c:\documents and settings\Leon\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-11 20:54 . 2010-01-12 23:52 117760 ----a-w- c:\documents and settings\Leon\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-11 20:53 . 2010-01-11 20:53 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-11 20:53 . 2010-01-11 20:53 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-11 20:53 . 2010-01-11 20:53 -------- d-----w- c:\documents and settings\Leon\Application Data\SUPERAntiSpyware.com
2010-01-11 20:53 . 2010-01-11 20:53 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2010-01-11 16:13 . 2010-01-11 16:13 -------- d-----w- c:\program files\Image-Line
2010-01-11 13:36 . 2010-01-11 13:36 -------- d-----w- c:\program files\D16 Group
2010-01-07 09:41 . 2010-01-07 09:41 -------- d-----w- c:\documents and settings\Leon\Application Data\Malwarebytes
2010-01-07 09:41 . 2009-12-30 13:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 09:41 . 2010-01-07 09:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-07 09:41 . 2010-01-07 09:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-07 09:41 . 2009-12-30 13:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 09:05 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-07 00:18 . 2010-01-07 08:35 -------- d-----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2010-01-07 00:18 . 2010-01-07 00:18 -------- d-----w- c:\documents and settings\Leon\Application Data\OnlineArmor
2010-01-07 00:17 . 2009-12-05 06:28 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-01-07 00:17 . 2009-12-05 06:27 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-01-07 00:17 . 2009-12-05 06:27 223312 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-01-07 00:17 . 2010-01-07 00:17 -------- d-----w- c:\program files\Tall Emu
2010-01-06 18:12 . 2010-01-06 18:12 218736 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\patch.exe
2010-01-06 18:12 . 2010-01-06 18:12 189968 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\ciussi32.dll
2010-01-06 18:12 . 2010-01-06 18:12 170512 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\PATCHW32.DLL
2010-01-06 18:12 . 2010-01-06 18:12 1267320 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\TmUpdate.dll
2010-01-06 18:12 . 2010-01-06 18:12 61440 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\Toolkit.dll
2010-01-06 18:12 . 2010-01-06 18:12 832776 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\lea.dll
2010-01-06 18:12 . 2010-01-06 18:12 439560 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\jlea.dll
2010-01-06 18:12 . 2010-01-06 18:12 42320 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\dsvout.dll
2010-01-06 18:12 . 2010-01-06 18:12 183356 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\Uninstaller.exe
2010-01-06 18:12 . 2010-01-06 19:38 -------- d-----w- c:\documents and settings\Leon\Application Data\HouseCall 6.6
2009-12-28 01:21 . 2010-01-08 18:39 -------- d-----w- c:\program files\Handbrake
2009-12-27 14:34 . 2009-12-27 14:34 -------- d-----w- c:\documents and settings\All Users\Application Data\F4
2009-12-27 14:28 . 2008-12-17 18:22 57344 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-27 14:28 . 2008-12-11 12:26 60273 ----a-w- c:\windows\system32\pthreadGC2.dll
2009-12-27 14:28 . 2009-12-27 14:28 -------- d-----w- c:\program files\ffdshow
2009-12-27 14:27 . 2009-12-27 18:29 -------- d-----w- c:\windows\SxsCaPendDel
2009-12-27 13:23 . 2009-12-27 13:23 -------- d-----w- c:\program files\DVD Shrink
2009-12-27 12:26 . 2009-12-27 12:26 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-12-26 21:54 . 2009-12-26 22:01 -------- d-----w- c:\documents and settings\Leon\Application Data\Download Manager
2009-12-26 21:28 . 2009-12-26 21:28 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-26 21:27 . 2009-12-26 21:27 152576 ----a-w- c:\documents and settings\Leon\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-26 21:27 . 2009-12-26 21:27 79488 ----a-w- c:\documents and settings\Leon\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-24 10:52 . 2009-12-24 10:52 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData
2009-12-22 15:27 . 2009-12-22 15:27 -------- d-----w- c:\program files\Alcohol Soft
2009-12-21 21:37 . 2009-12-27 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-12-21 20:44 . 2009-12-21 20:44 -------- d-----w- c:\documents and settings\Leon\Local Settings\Application Data\ATI
2009-12-21 20:44 . 2009-12-21 20:44 -------- d-----w- c:\documents and settings\Leon\Application Data\ATI
2009-12-21 20:28 . 2006-05-03 10:57 520192 ------w- c:\windows\system32\ati2sgag.exe
2009-12-20 18:10 . 2009-12-20 18:13 -------- d-----w- c:\windows\$regcmp$
2009-12-18 13:28 . 2009-12-18 13:28 -------- d-----w- c:\documents and settings\Leon\Application Data\VST3 Presets
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 11:57 . 2008-04-14 21:22 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-01-12 23:08 . 2008-04-17 21:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-12 13:10 . 2008-04-19 15:03 -------- d-----w- c:\documents and settings\Leon\Application Data\uTorrent
2010-01-12 10:29 . 2009-07-14 18:07 -------- d-----w- c:\documents and settings\Leon\Application Data\vlc
2010-01-12 09:20 . 2009-04-16 09:33 -------- d-----w- c:\program files\Unlocker
2010-01-12 09:01 . 2009-02-17 12:00 -------- d-----w- c:\program files\PopCap Games
2010-01-12 08:54 . 2009-04-12 12:08 -------- d-----w- c:\program files\Ingava.com
2010-01-12 08:45 . 2008-04-25 18:05 -------- d-----w- c:\program files\Norton Ghost
2010-01-12 00:05 . 2009-01-19 08:39 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2010-01-12 00:05 . 2009-01-19 08:39 -------- d-----w- c:\program files\ma-config.com
2010-01-12 00:01 . 2009-06-17 15:53 -------- d-----w- c:\program files\Google
2010-01-11 15:44 . 2008-04-17 21:24 -------- d-----w- c:\program files\FlashGet
2010-01-11 13:37 . 2008-06-21 10:30 -------- d-----w- c:\program files\Vstplugins
2010-01-10 12:26 . 2008-11-01 16:16 -------- d-----w- c:\program files\ABC Amber BlackBerry Converter
2010-01-10 09:46 . 2008-04-21 06:59 32 ----a-w- c:\windows\msocreg32.dat
2010-01-07 11:19 . 2002-08-30 12:00 101888 ----a-w- c:\windows\system32\drivers\adpu160m.sys
2010-01-07 00:18 . 2002-08-30 12:00 98038 ----a-w- c:\windows\system32\perfc00C.dat
2010-01-07 00:18 . 2002-08-30 12:00 545420 ----a-w- c:\windows\system32\perfh00C.dat
2010-01-06 18:13 . 2010-01-06 18:13 116048 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\TmEngDrv.dll
2010-01-06 18:13 . 2010-01-06 18:13 98304 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\getMac.exe
2010-01-06 18:13 . 2010-01-06 18:13 69632 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\mfcm80.dll
2010-01-06 18:13 . 2010-01-06 18:13 626688 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\msvcr80.dll
2010-01-06 18:13 . 2010-01-06 18:13 57344 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\mfcm80u.dll
2010-01-06 18:13 . 2010-01-06 18:13 548864 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\msvcp80.dll
2010-01-06 18:13 . 2010-01-06 18:13 479232 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\msvcm80.dll
2010-01-06 18:13 . 2010-01-06 18:13 1093632 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\mfc80.dll
2010-01-06 18:13 . 2010-01-06 18:13 1079808 ----a-w- c:\documents and settings\Leon\Application Data\HouseCall 6.6\mfc80u.dll
2010-01-06 12:58 . 2008-07-26 13:48 -------- d-----w- c:\documents and settings\Leon\Application Data\dvdcss
2010-01-05 17:21 . 2008-04-19 09:33 -------- d-----w- c:\documents and settings\Leon\Application Data\UseNeXT
2009-12-28 21:31 . 2009-01-09 16:02 -------- d-----w- c:\program files\Ray Adams
2009-12-28 16:42 . 2008-06-22 14:25 -------- d-----w- c:\program files\SyncBack
2009-12-26 21:28 . 2008-05-02 09:46 -------- d-----w- c:\program files\Java
2009-12-21 20:29 . 2008-05-27 08:09 -------- d-----w- c:\program files\ATI Technologies
2009-12-21 16:28 . 2009-07-05 12:09 -------- d-----w- c:\program files\IObit
2009-12-18 15:42 . 2009-04-20 12:28 -------- d-----w- c:\program files\XtremSplit
2009-12-14 11:24 . 2008-04-15 07:42 -------- d-----w- c:\program files\XnView
2009-12-13 14:19 . 2008-07-13 21:24 -------- d-----w- c:\documents and settings\Leon\Application Data\FileZilla
2009-12-12 21:49 . 2009-09-26 15:09 24340 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-10 20:49 . 2009-05-09 10:00 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-10 20:34 . 2008-04-17 21:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-08 19:25 . 2008-05-01 22:21 1 ----a-w- c:\documents and settings\Leon\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-12-08 19:24 . 2008-05-01 22:21 -------- d-----w- c:\documents and settings\Leon\Application Data\OpenOffice.org2
2009-12-07 21:09 . 2008-04-21 06:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-07 21:09 . 2009-12-07 21:09 -------- d-----w- c:\program files\CyberLink
2009-12-03 19:47 . 2009-12-03 19:44 -------- d-----w- c:\program files\ABC Amber Text Converter
2009-12-03 19:42 . 2008-11-01 15:14 -------- d-----w- c:\program files\ABC Amber BlackBerry Editor
2009-12-03 19:31 . 2008-04-19 08:56 33696 ----a-w- c:\documents and settings\Leon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-03 19:22 . 2009-05-29 18:33 -------- d-----w- c:\program files\Ask & Record Toolbar
2009-12-03 19:18 . 2008-05-17 15:55 -------- d-----w- c:\program files\Fichiers communs\Roxio Shared
2009-12-03 19:18 . 2008-05-17 15:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-12-03 18:58 . 2009-02-17 12:00 10 ----a-w- c:\windows\popcinfo.dat
2009-12-03 10:34 . 2008-04-18 19:39 -------- d-----w- c:\program files\UseNeXT
2009-12-01 18:05 . 2009-12-01 18:05 -------- d-----w- c:\program files\laetjr
2009-12-01 17:56 . 2009-12-01 17:51 -------- d-----w- c:\program files\ABC Amber PDF Merger
2009-11-28 15:57 . 2009-11-28 15:57 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-27 10:24 . 2009-11-27 10:24 -------- d-----w- c:\program files\Recuva
2009-11-23 19:47 . 2009-11-23 19:43 -------- d-----w- c:\program files\Html to Jpg
2009-11-23 18:20 . 2009-11-23 17:52 -------- d-----w- c:\program files\Monster Truck Nitro 2
2009-11-21 18:38 . 2009-11-21 18:38 -------- d-----w- c:\program files\AviSynth 2.5
2009-11-21 18:38 . 2009-11-21 18:38 -------- d-----w- c:\program files\eRightSoft
2009-11-21 15:58 . 2002-08-30 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-10-29 05:25 . 2002-08-30 12:00 671232 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:39 . 2008-04-19 08:43 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-21 05:39 . 2008-04-19 08:43 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-20 16:20 . 2008-04-19 08:44 265728 ------w- c:\windows\system32\drivers\http.sys
2009-10-15 16:32 . 2002-08-30 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-10-15 16:32 . 2002-08-30 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2006-12-15 09:50 . 2008-04-14 21:03 934054 ----a-w- c:\program files\xnview wallpaper.bmp
2006-05-03 09:06 . 2009-11-21 18:38 163328 --sh--r- c:\windows\system32\flvDX.dll
2009-10-02 11:20 . 2009-10-02 11:14 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 . 2009-11-21 18:38 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-11-21 18:38 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-06_20.16.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-09-22 16:12 . 2009-05-26 11:40 18296 c:\windows\system32\spmsg.dll
+ 2009-09-22 16:12 . 2008-07-08 13:03 18296 c:\windows\system32\spmsg.dll
+ 2002-08-30 12:00 . 2010-01-07 00:18 80780 c:\windows\system32\perfc009.dat
+ 2002-08-30 12:00 . 2008-04-14 02:34 14336 c:\windows\system32\dllcache\svchost.exe
- 2009-09-23 07:29 . 2009-07-29 04:35 81920 c:\windows\system32\dllcache\fontsub.dll
+ 2009-09-23 07:29 . 2009-10-15 16:32 81920 c:\windows\system32\dllcache\fontsub.dll
- 2009-12-24 10:52 . 2010-01-06 20:17 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
+ 2009-12-24 10:52 . 2010-01-12 08:27 32768 c:\windows\system32\config\systemprofile\UserData\index.dat
+ 2010-01-12 08:26 . 2010-01-12 08:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012010011220100113\index.dat
+ 2010-01-12 08:26 . 2010-01-12 08:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012010010420100111\index.dat
+ 2010-01-09 12:51 . 2010-01-09 12:51 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012009122820100104\index.dat
+ 2008-04-14 17:54 . 2010-01-13 11:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
- 2008-04-14 17:54 . 2010-01-06 20:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
+ 2008-04-14 17:54 . 2010-01-13 11:31 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-04-14 17:54 . 2010-01-06 20:12 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-01-11 20:53 . 2010-01-11 20:53 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2010-01-11 20:53 . 2010-01-11 20:53 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2010-01-11 20:53 . 2010-01-11 20:53 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2002-08-30 12:00 . 2010-01-07 00:18 470006 c:\windows\system32\perfh009.dat
- 2009-09-23 07:29 . 2009-07-29 04:35 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2009-09-23 07:29 . 2009-10-15 16:32 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2002-08-30 12:00 . 2010-01-07 11:19 101888 c:\windows\system32\dllcache\adpu160m.sys
+ 2008-04-14 17:54 . 2010-01-13 11:31 180224 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-11 13:36 . 2010-01-11 13:36 911360 c:\windows\Installer\8815b8.msi
+ 2010-01-12 17:06 . 2010-01-12 17:06 274432 c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2010-01-12 17:06 . 2008-08-07 14:27 163328 c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2010-01-12 17:07 . 2010-01-12 17:07 274432 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2010-01-12 17:07 . 2008-08-07 14:27 163328 c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2010-01-11 20:53 . 2010-01-11 20:53 1583616 c:\windows\Installer\121f1c7.msi
+ 2009-01-15 20:17 . 2010-01-04 15:17 29634504 c:\windows\system32\MRT.exe
+ 2010-01-12 17:06 . 2010-01-12 17:06 13152256 c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2010-01-12 17:07 . 2010-01-12 17:07 13152256 c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RMETray"="digi96.exe" [2005-06-14 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-12-05 6622920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-12-05 923336]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave"=digi96.dll
"wave4"=digi96.dll
"wave5"=digi96.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^MOTU Pedal Handler.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\MOTU Pedal Handler.lnk
backup=c:\windows\pss\MOTU Pedal Handler.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Leon^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
path=c:\documents and settings\Leon\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2009-12-22 14:50 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATnotes.exe]
2005-01-05 13:45 1015808 ----a-w- c:\program files\ATnotes\ATnotes.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2004-12-13 13:30 58992 ----a-w- c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 14:06 1840424 ----a-w- c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2006-09-11 02:40 218032 ----a-w- c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-06-19 07:53 570664 ----a-w- c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 10.0]
2005-09-09 17:09 1537648 ----a-w- c:\program files\Norton Ghost\Agent\GhostTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 19:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-26 21:28 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-04-19 11:45 185896 ----a-w- c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 amdagpxp;AMD NB AGP Bus Filter;c:\windows\system32\drivers\amdagpxp.sys [19/01/2009 10:34 27776]
R0 amdeide;amdeide;c:\windows\system32\drivers\amdeide.sys [19/01/2009 10:34 4864]
R0 DigiFilter;DigiFilter;c:\windows\system32\drivers\DigiFilt.sys [02/05/2008 18:27 16384]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [17/04/2008 22:45 11264]
R1 atitray;atitray;c:\program files\Ray Adams\ATI Tray Tools\atitray.sys [25/11/2009 13:11 19232]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [07/01/2010 01:17 223312]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [07/01/2010 01:17 24656]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [07/01/2010 01:17 29776]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 07:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 07:56 74480]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [09/05/2009 11:00 108289]
R2 digi96;RME Digi Audio Device;c:\windows\system32\drivers\digi96.sys [21/07/2005 16:55 48768]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [15/06/2008 15:58 16400]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [07/01/2010 01:17 1282248]
R2 tyansmb;tyansmb;c:\windows\system32\drivers\tyansmb.sys [26/09/2009 15:56 12751]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [14/04/2008 21:41 33792]
R3 motubus;MOTU Audio MIDI Extension;c:\windows\system32\drivers\motubus.sys [13/06/2008 12:04 23600]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/11/2009 16:57 721904]
S2 ALIEHCD;ULi PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\AliEhci.sys [22/05/2008 18:32 83596]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [07/01/2010 01:17 3291336]
S3 aliroothub;USB 2.0 Root Hub;c:\windows\system32\drivers\AliRtHub.sys [22/05/2008 18:32 5331]
S3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [02/05/2008 18:26 97808]
S3 mfwagsif;MOTU Audio GSIF;c:\windows\system32\drivers\mfwagsif.sys [13/06/2008 12:04 22576]
S3 mfwamidi;MOTU Audio MIDI;c:\windows\system32\drivers\mfwamidi.sys [13/06/2008 12:04 26160]
S3 mfwawave;MOTU Audio Wave;c:\windows\system32\drivers\mfwawave.sys [13/06/2008 12:04 62000]
S3 MotuFWA;MotuFWA;c:\windows\system32\drivers\motufwa.sys [13/06/2008 12:04 438320]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 07:56 7408]
S4 gupdate1c9ef63de99bb6c;Service Google Update (gupdate1c9ef63de99bb6c);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
.
Contenu du dossier 'Tâches planifiées'
2010-01-13 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Leon\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-23 09:17]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.talti.com
uInternet Settings,ProxyOverride = *.local
IE: &Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Leon\Application Data\Mozilla\Firefox\Profiles\stv2pt3f.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.GOOGLE.fr
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\documents and settings\Leon\Local Settings\Application Data\Google\Update\1.2.131.11\npGoogleOneClick5.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npornap.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-13 13:06
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(508)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2572)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Heure de fin: 2010-01-13 13:10:06
ComboFix-quarantined-files.txt 2010-01-13 12:10
ComboFix2.txt 2010-01-13 11:51
ComboFix3.txt 2010-01-06 20:23
Avant-CF: 2 324 176 896 octets libres
Après-CF: 2 308 366 336 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 9D838D76CE304AC2BAB35082431AE254
Merci de ton attention, je commence doucement à fatiguer là.... ;O)