voila c fait, cf ci-dessous stp
ComboFix 10-02-16.03 - xspaeth-adc 17/02/2010 21:10:29.3.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1919.1305 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\xspaeth-adc\Bureau\ComboFix.exe
AV: F-Secure Anti-Virus for Workstations 7.10 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Il y a peut-être des sites infectés -----
hxxp://marseille-bck.paca.rubis.alize
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-17 au 2010-02-17 ))))))))))))))))))))))))))))))))))))
.
2010-02-17 18:57:41 . 2010-02-17 19:08:49 -------- d-----w- C:\Program Files\ZHPDiag
2010-02-16 19:33:31 . 2010-02-16 19:33:31 -------- d-----w- C:\Documents and Settings\HelpAssistant\UserData
2010-02-16 19:33:31 . 2010-02-16 19:33:31 -------- d-----w- C:\Documents and Settings\HelpAssistant\Tracing
2010-01-31 14:10:08 . 2010-01-31 14:10:18 -------- d-----w- C:\Program Files\DivX
2010-01-31 14:10:08 . 2010-01-31 14:10:08 -------- d-----w- C:\Program Files\Fichiers communs\DivX Shared
2010-01-29 13:48:40 . 2010-01-29 13:48:40 0 ----a-w- C:\windows\nsreg.dat
2010-01-29 13:48:38 . 2010-01-29 13:48:38 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Local Settings\Application Data\Mozilla
2010-01-25 11:05:47 . 2010-01-07 15:07:14 38224 ----a-w- C:\windows\system32\drivers\mbamswissarmy.sys
2010-01-25 11:05:45 . 2010-01-07 15:07:04 19160 ----a-w- C:\windows\system32\drivers\mbam.sys
2010-01-25 09:49:39 . 2010-01-25 10:03:48 -------- d-----w- C:\rsit
2010-01-24 17:08:26 . 2010-01-24 17:08:26 -------- d-----w- C:\Program Files\Trend Micro
2010-01-23 21:56:55 . 2010-01-24 11:58:29 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-23 21:56:55 . 2010-01-23 21:59:17 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-01-23 21:44:01 . 2010-01-23 21:44:01 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Application Data\Malwarebytes
2010-01-23 21:43:46 . 2010-01-23 21:43:46 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-01-23 21:43:45 . 2010-01-25 11:05:50 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-23 17:00:24 . 2010-01-23 17:00:24 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Application Data\F-Secure
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-16 23:35:25 . 2009-10-26 15:17:44 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Application Data\vlc
2010-02-16 19:17:19 . 2004-08-05 12:00:00 88042 ----a-w- C:\windows\system32\perfc00C.dat
2010-02-16 19:17:19 . 2004-08-05 12:00:00 517358 ----a-w- C:\windows\system32\perfh00C.dat
2010-02-10 14:57:49 . 2009-10-18 15:06:31 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Application Data\dvdcss
2010-02-08 10:20:11 . 2009-11-04 15:35:04 -------- d-----w- C:\Documents and Settings\xspaeth-adc\Application Data\OpenOffice.org2
2010-02-08 09:48:03 . 2009-11-04 15:36:30 1 ----a-w- C:\Documents and Settings\xspaeth-adc\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2010-01-25 07:51:31 . 2009-10-18 15:29:57 -------- d-----w- C:\Program Files\eMule
2010-01-23 17:13:51 . 2009-12-22 20:07:18 -------- d-----w- C:\Program Files\Woonoz
2009-12-31 16:14:12 . 2004-08-05 12:00:00 352640 ----a-w- C:\windows\system32\drivers\srv.sys
2009-12-23 16:02:10 . 2008-11-27 12:53:43 -------- d-----w- C:\Program Files\Hewlett-Packard
2009-12-23 16:02:08 . 2009-12-23 16:02:08 82380 ----a-w- C:\windows\system32\drivers\AFS2K.SYS
2009-12-22 05:41:35 . 2004-08-05 12:00:00 666112 ------w- C:\windows\system32\wininet.dll
2009-12-22 05:41:30 . 2004-08-05 12:00:00 81920 ----a-w- C:\windows\system32\ieencode.dll
2009-12-17 07:59:41 . 2008-03-31 08:15:19 347648 ----a-w- C:\windows\system32\mspaint.exe
2009-12-14 07:36:38 . 2004-08-05 12:00:00 33280 ----a-w- C:\windows\system32\csrsrv.dll
2009-12-09 10:19:41 . 2004-08-05 12:00:00 2188032 ------w- C:\windows\system32\ntoskrnl.exe
2009-12-09 10:19:41 . 2004-08-04 00:49:04 2065152 ------w- C:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41:55 . 2004-08-05 12:00:00 453760 ----a-w- C:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:34:49 . 2004-08-05 12:00:00 1297408 ----a-w- C:\windows\system32\quartz.dll
2009-11-27 17:34:49 . 2004-08-04 00:54:36 17920 ----a-w- C:\windows\system32\msyuv.dll
2009-11-27 16:38:56 . 2004-08-05 12:00:00 85504 ----a-w- C:\windows\system32\avifil32.dll
2009-11-27 16:38:56 . 2004-08-05 12:00:00 28672 ----a-w- C:\windows\system32\msvidc32.dll
2009-11-27 16:38:56 . 2004-08-05 12:00:00 11264 ----a-w- C:\windows\system32\msrle32.dll
2009-11-27 16:38:56 . 2004-08-04 00:54:30 48128 ----a-w- C:\windows\system32\iyuv_32.dll
2009-11-27 16:38:56 . 2001-08-23 17:47:20 8704 ----a-w- C:\windows\system32\tsbyuv.dll
2009-11-21 16:42:10 . 2004-08-05 12:00:00 470528 ----a-w- C:\windows\AppPatch\aclayers.dll
2006-07-21 08:03:28 . 2009-10-22 07:19:02 360054 ----a-w- C:\Program Files\aa.bmp
.
((((((((((((((((((((((((((((( SnapShot@2010-01-25_18.28.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-17 17:45:40 . 2010-02-17 17:45:40 16384 C:\windows\temp\Perflib_Perfdata_d7c.dat
+ 2008-11-27 14:40:50 . 2009-05-26 11:40:58 18296 C:\windows\system32\spmsg.dll
- 2008-11-27 14:40:50 . 2008-07-08 13:03:54 18296 C:\windows\system32\spmsg.dll
- 2004-08-05 12:00:00 . 2010-01-25 18:29:47 73950 C:\windows\system32\perfc009.dat
+ 2004-08-05 12:00:00 . 2010-02-16 19:17:19 73950 C:\windows\system32\perfc009.dat
+ 2010-01-30 22:53:32 . 2010-01-30 22:53:32 85173 C:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2004-08-04 00:54:36 . 2009-11-27 17:34:49 17920 C:\windows\system32\dllcache\msyuv.dll
+ 2004-08-05 12:00:00 . 2009-11-27 16:38:56 28672 C:\windows\system32\dllcache\msvidc32.dll
+ 2004-08-05 12:00:00 . 2009-11-27 16:38:56 11264 C:\windows\system32\dllcache\msrle32.dll
- 2004-08-05 12:00:00 . 2004-08-05 12:00:00 11264 C:\windows\system32\dllcache\msrle32.dll
+ 2004-08-04 00:54:30 . 2009-11-27 16:38:56 48128 C:\windows\system32\dllcache\iyuv_32.dll
+ 2004-08-05 12:00:00 . 2009-12-14 07:36:38 33280 C:\windows\system32\dllcache\csrsrv.dll
- 2004-08-05 12:00:00 . 2009-06-10 14:23:48 85504 C:\windows\system32\dllcache\avifil32.dll
+ 2004-08-05 12:00:00 . 2009-11-27 16:38:56 85504 C:\windows\system32\dllcache\avifil32.dll
+ 2004-08-05 12:00:00 . 2008-11-27 14:37:18 95360 C:\windows\system32\dllcache\atapi.sys
- 2008-11-27 15:39:31 . 2010-01-13 10:53:48 27136 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:37 27136 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:37 11264 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-11-27 15:39:31 . 2010-01-13 10:53:48 11264 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-11-27 15:39:31 . 2010-01-13 10:53:48 12288 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:37 12288 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-02-12 09:30:08 . 2009-11-27 17:34:49 17920 C:\windows\Driver Cache\i386\msyuv.dll
+ 2010-02-12 09:30:04 . 2009-11-27 16:38:56 48128 C:\windows\Driver Cache\i386\iyuv_32.dll
+ 2001-08-23 17:47:20 . 2009-11-27 16:38:56 8704 C:\windows\system32\dllcache\tsbyuv.dll
- 2008-11-27 15:39:31 . 2010-01-13 10:53:48 4096 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:37 4096 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2010-02-12 09:30:04 . 2009-11-27 16:38:56 8704 C:\windows\Driver Cache\i386\tsbyuv.dll
+ 2009-07-12 00:12:06 . 2009-07-12 00:12:06 632656 C:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 00:09:20 . 2009-07-12 00:09:20 554832 C:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 00:08:14 . 2009-07-12 00:08:14 479232 C:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2008-03-31 08:15:17 . 2008-03-31 08:15:17 297984 C:\windows\system32\termsrv32.dll
- 2004-08-05 12:00:00 . 2010-01-25 18:29:48 447996 C:\windows\system32\perfh009.dat
+ 2004-08-05 12:00:00 . 2010-02-16 19:17:19 447996 C:\windows\system32\perfh009.dat
+ 2009-10-28 03:40:16 . 2009-10-28 03:40:16 257440 C:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2004-08-05 12:00:00 . 2009-12-31 16:14:12 352640 C:\windows\system32\dllcache\srv.sys
+ 2008-03-31 08:15:19 . 2009-12-17 07:59:41 347648 C:\windows\system32\dllcache\mspaint.exe
- 2008-03-31 08:15:19 . 2004-08-05 12:00:00 347648 C:\windows\system32\dllcache\mspaint.exe
+ 2006-05-05 09:41:45 . 2009-12-04 14:41:55 453760 C:\windows\system32\dllcache\mrxsmb.sys
+ 2008-03-31 08:29:24 . 2010-01-25 19:02:16 294912 C:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-31 14:10:13 . 2010-01-31 14:10:13 169472 C:\windows\Installer\59da27.msi
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:38 794624 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-11-27 15:39:31 . 2010-01-13 10:53:49 794624 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-11-27 15:39:31 . 2010-01-13 10:53:48 135168 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-11-27 15:39:31 . 2010-02-12 13:23:37 135168 C:\windows\Installer\{90E0040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2004-10-28 01:14:18 . 2009-12-04 14:41:55 453760 C:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-10-28 03:40:14 . 2009-10-28 03:40:14 3885984 C:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2004-08-05 12:00:00 . 2009-11-27 17:34:49 1297408 C:\windows\system32\dllcache\quartz.dll
+ 2008-11-27 16:04:35 . 2009-12-09 10:19:41 2188032 C:\windows\system32\dllcache\ntoskrnl.exe
- 2008-11-27 16:04:35 . 2009-08-04 17:16:20 2188032 C:\windows\system32\dllcache\ntoskrnl.exe
- 2008-11-27 16:04:34 . 2009-08-04 17:16:17 2022912 C:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-11-27 16:04:34 . 2009-12-09 10:19:37 2022912 C:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-11-27 16:04:35 . 2009-12-09 10:19:41 2065152 C:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-11-27 16:04:36 . 2009-08-04 17:16:19 2144768 C:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-11-27 16:04:36 . 2009-12-09 10:19:37 2144768 C:\windows\system32\dllcache\ntkrnlmp.exe
+ 2010-01-19 16:51:12 . 2010-01-19 16:51:12 5524480 C:\windows\Installer\14706cd.msp
- 2008-11-27 13:03:47 . 2009-08-04 17:16:20 2188032 C:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-11-27 13:03:47 . 2009-12-09 10:19:41 2188032 C:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-11-27 13:03:47 . 2009-12-09 10:19:37 2022912 C:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-11-27 13:03:47 . 2009-08-04 17:16:17 2022912 C:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-11-27 13:03:47 . 2009-12-09 10:19:41 2065152 C:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2008-11-27 13:03:47 . 2009-08-04 17:16:19 2144768 C:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-11-27 13:03:47 . 2009-12-09 10:19:37 2144768 C:\windows\Driver Cache\i386\ntkrnlmp.exe
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35:24 90112]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 15:07:20 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE" [2007-01-09 14:52:32 145184]
"CognizanceTS"="C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 17:12:00 17920]
"AccelerometerSysTrayApplet"="C:\windows\system32\AccelerometerSt.exe" [2007-01-24 13:28:58 124928]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 00:28:00 1040384]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-05-03 09:52:22 57344]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18:36 472776]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-11-08 08:00:00 1116920]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-11-06 15:34:02 177456]
"F-Secure Manager"="C:\Program Files\F-Secure\Common\FSM32.EXE" [2007-11-21 10:25:46 182936]
"F-Secure TNB"="C:\Program Files\F-Secure\FSGUI\TNBUtil.exe" [2007-11-21 10:25:34 895584]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 01:38:00 34672]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 16:36:48 872448]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-07-25 03:23:12 149280]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2002-12-17 10:40:22 49152]
"HPDJ Taskbar Utility"="C:\windows\system32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-11 10:08:52 172032]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 19:56:10 40960]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2007-05-23 10:00:08 192512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\windows\system32\CTFMON.EXE" [2004-08-05 12:00:00 15360]
C:\Documents and Settings\admin\Menu D‚marrer\Programmes\D‚marrage\
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-9-29 49152]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2008-11-27 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-07 01:30:00 74240 ----a-r- C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\APSHook.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ SbHpNp scecli
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-240932477-1890555809-1926171595-1549\Scripts\Logon\0\0]
"Script"=LoginScript_marseille.vbs
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3997:TCP"= 3997:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"7474:TCP"= 7474:TCP:Services
R0 SafeBoot;SafeBoot;C:\WINDOWS\system32\drivers\SafeBoot.sys [07/02/2007 11:22:46 100495]
R0 SbAlg;SbAlg;C:\WINDOWS\system32\drivers\SbAlg.sys [09/10/2006 13:31:46 44720]
R0 SbFsLock;SbFsLock;C:\WINDOWS\system32\drivers\SbFsLock.sys [29/03/2007 16:54:00 13696]
R1 RsvLock;RsvLock;C:\WINDOWS\system32\drivers\rsvlock.sys [07/02/2007 11:23:20 5808]
R2 ASBroker;Courtier de session de connexion;C:\windows\System32\svchost.exe -k Cognizance [05/08/2004 13:00:00 14336]
R2 ASChannel;Canal de communication local;C:\windows\System32\svchost.exe -k Cognizance [05/08/2004 13:00:00 14336]
R2 HpFkCryptService;Drive Encryption Service;C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe [29/03/2007 17:50:50 221184]
R2 SWIHPWMI;SWIHPWMI;C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [04/12/2006 16:13:16 292384]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys [27/11/2008 16:04:01 62048]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\drivers\ifxtpm.sys [27/11/2008 15:56:58 41216]
S3 camfilt2;Hercules Filter Driver;C:\windows\system32\Drivers\camfilt2.sys --> C:\windows\system32\Drivers\camfilt2.sys [?]
S3 HP24X;HP PC Card Smart Card Reader;C:\WINDOWS\system32\drivers\HP24X.sys [27/11/2008 14:25:49 33024]
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\F-Secure\Anti-Virus\win2k\fsfilter.sys [27/11/2008 16:04:01 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\F-Secure\Anti-Virus\win2k\fsrec.sys [27/11/2008 16:04:01 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Connection Wizard,ShellNext = iexplore
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
DPF: {B2CC4BA0-08EB-4AF9-A532-1295DF0C8A07} - hxxp://rome:8080/webquartz/ocx/WebQuartz.cab
FF - ProfilePath - C:\Documents and Settings\xspaeth-adc\Application Data\Mozilla\Firefox\Profiles\fefshlst.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.