Le scan avec combofix est terminé.
Rapport :
ComboFix 10-08-28.02 - Valentin 29/08/2010 23:04:44.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1022.511 [GMT 2:00]
Lancé depuis: c:\documents and settings\Valentin\Mes documents\Téléchargements\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Splitcam Toolbar\tbHElper.dll
c:\windows\system32\scrrnfr.dll
c:\windows\system32\scvideo.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-07-28 au 2010-08-29 ))))))))))))))))))))))))))))))))))))
.
2010-08-29 20:59 . 2010-08-29 20:59 -------- d-----w- c:\windows\system32\LogFiles
2010-08-29 20:52 . 2010-08-29 20:52 -------- d-----w- c:\documents and settings\Valentin\Application Data\Avira
2010-08-29 16:12 . 2010-08-29 16:12 -------- d-----w- c:\documents and settings\Valentin\Application Data\Malwarebytes
2010-08-29 16:12 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-29 16:12 . 2010-08-29 16:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-29 16:12 . 2010-08-29 16:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-29 16:12 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-29 14:34 . 2010-08-29 15:57 -------- d-----w- c:\program files\ZHPDiag
2010-08-28 22:49 . 2004-08-04 04:54 907776 ----a-w- c:\windows\system32\zipfldr.dll
2010-08-28 22:49 . 2004-08-03 22:54 116736 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-08-28 22:49 . 2001-08-23 15:47 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-08-28 22:49 . 2001-08-23 15:47 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-08-28 22:49 . 2001-08-23 15:47 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-08-28 22:49 . 2001-08-23 15:47 17408 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-08-28 22:49 . 2001-08-23 15:47 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2010-08-28 22:48 . 2001-08-17 18:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-08-28 22:48 . 2004-08-03 20:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-08-28 22:48 . 2004-08-04 04:55 288768 ----a-w- c:\windows\system32\wuauclt1.exe
2010-08-28 22:47 . 2004-08-03 22:54 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2010-08-28 22:47 . 2004-08-03 20:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-08-28 22:47 . 2004-08-03 21:07 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-08-28 22:47 . 2004-08-03 20:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-08-28 22:47 . 2001-08-23 15:05 35402 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-08-28 22:46 . 2004-08-04 04:54 292352 ----a-w- c:\windows\system32\winsrv.dll
2010-08-28 22:46 . 2001-08-17 19:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2010-08-28 22:45 . 2004-08-04 04:54 774656 ----a-w- c:\windows\system32\wiashext.dll
2010-08-28 22:45 . 2001-08-23 15:47 87040 -c--a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-08-28 22:45 . 2001-08-23 15:47 54272 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-08-28 22:44 . 2004-08-04 04:55 890880 ----a-w- c:\windows\system32\wiaacmgr.exe
2010-08-28 22:43 . 2002-09-07 00:00 31360 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2010-08-28 22:43 . 2001-08-17 19:28 701386 -c--a-w- c:\windows\system32\dllcache\wdhaalba.sys
2010-08-28 22:43 . 2004-08-03 22:45 32128 -c--a-w- c:\windows\system32\dllcache\wceusbsh.sys
2010-08-28 22:43 . 2004-08-03 20:29 23615 -c--a-w- c:\windows\system32\dllcache\wch7xxnt.sys
2010-08-28 22:43 . 2001-08-17 18:10 35871 -c--a-w- c:\windows\system32\dllcache\wbfirdma.sys
2010-08-28 22:41 . 2004-08-04 04:54 366592 -c--a-w- c:\windows\system32\dllcache\w3svc.dll
2010-08-28 22:39 . 2004-08-03 21:07 44672 -c--a-w- c:\windows\system32\dllcache\uagp35.sys
2010-08-28 22:38 . 2004-08-04 04:54 393728 ----a-w- c:\windows\system32\themeui.dll
2010-08-28 22:37 . 2002-09-07 00:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll
2010-08-28 22:37 . 2001-08-23 15:46 81408 -c--a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-08-28 22:37 . 2001-08-17 18:51 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-08-28 22:37 . 2004-08-03 21:00 149376 -c--a-w- c:\windows\system32\dllcache\tffsport.sys
2010-08-28 22:37 . 2001-08-17 18:13 37961 -c--a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-08-28 22:37 . 2001-08-17 18:13 17129 -c--a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-08-28 22:37 . 2002-09-07 00:00 13192 -c--a-w- c:\windows\system32\dllcache\tdasync.sys
2010-08-28 22:37 . 2001-08-17 19:49 30464 -c--a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-08-28 22:36 . 2001-08-17 19:52 7040 -c--a-w- c:\windows\system32\dllcache\tandqic.sys
2010-08-28 22:36 . 2001-08-17 18:50 36640 -c--a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-08-28 22:36 . 2001-08-23 15:46 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-08-28 22:36 . 2004-08-04 04:54 1261568 ----a-w- c:\windows\system32\syssetup.dll
2010-08-28 22:35 . 2001-08-17 20:07 30688 -c--a-w- c:\windows\system32\dllcache\sym_u3.sys
2010-08-28 22:35 . 2001-08-17 20:07 32640 -c--a-w- c:\windows\system32\dllcache\symc8xx.sys
2010-08-28 22:35 . 2001-08-17 20:07 16256 -c--a-w- c:\windows\system32\dllcache\symc810.sys
2010-08-28 22:35 . 2001-08-23 15:47 94293 -c--a-w- c:\windows\system32\dllcache\sxports.dll
2010-08-28 22:35 . 2001-08-17 20:07 28384 -c--a-w- c:\windows\system32\dllcache\sym_hi.sys
2010-08-28 22:35 . 2001-08-17 20:02 3968 -c--a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-08-28 22:35 . 2001-08-17 19:50 103936 -c--a-w- c:\windows\system32\dllcache\sx.sys
2010-08-28 22:35 . 2001-08-23 15:47 53760 -c--a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-08-28 22:35 . 2001-08-23 15:47 41472 -c--a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-08-28 22:35 . 2001-08-23 15:47 10240 -c--a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-08-28 22:35 . 2001-08-23 15:47 10240 -c--a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-08-28 22:33 . 2004-08-03 20:41 95424 -c--a-w- c:\windows\system32\dllcache\slnthal.sys
2010-08-28 22:32 . 2001-08-23 15:17 16512 -c--a-w- c:\windows\system32\dllcache\pscr.sys
2010-08-28 22:31 . 2004-08-03 20:29 452736 -c--a-w- c:\windows\system32\dllcache\mtxparhm.sys
2010-08-28 22:30 . 2001-08-23 15:47 37888 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2010-08-28 22:29 . 2004-08-03 20:41 1041536 -c--a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2010-08-28 22:28 . 2001-08-17 19:52 7040 -c--a-w- c:\windows\system32\dllcache\exabyte2.sys
2010-08-28 22:27 . 2001-08-17 19:58 9344 -c--a-w- c:\windows\system32\dllcache\compbatt.sys
2010-08-28 22:26 . 2001-08-17 18:11 26568 -c--a-w- c:\windows\system32\dllcache\bcm4e5.sys
2010-08-28 22:25 . 2004-08-03 22:54 3775 -c--a-w- c:\windows\system32\dllcache\adv11nt5.dll
2010-08-28 22:22 . 2001-08-23 15:46 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-08-28 22:22 . 2004-08-03 22:48 2150400 -c--a-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-08-28 21:37 . 2010-08-28 21:37 -------- d-----w- c:\program files\ma-config.com
2010-08-28 21:37 . 2010-08-28 21:37 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2010-08-28 20:22 . 2004-08-03 20:59 5376 -c--a-w- c:\windows\system32\dllcache\viaide.sys
2010-08-28 20:22 . 2004-08-03 20:59 5376 ----a-w- c:\windows\system32\drivers\viaide.sys
2010-08-26 21:23 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-08-26 21:23 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-08-26 21:09 . 2010-08-26 21:09 -------- d-----w- c:\program files\iPod
2010-08-26 21:08 . 2010-08-26 21:14 -------- d-----w- c:\program files\iTunes
2010-08-26 21:01 . 2010-08-26 21:01 -------- d-----w- c:\program files\Apple Software Update
2010-08-26 20:57 . 2010-04-16 06:33 41472 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-08-26 20:57 . 2010-04-16 06:33 3003680 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-08-26 20:37 . 2010-08-26 21:09 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-08-26 06:36 . 2010-08-26 06:52 -------- d-----w- c:\program files\QuickTime
2010-08-26 03:13 . 2010-08-26 03:13 -------- d-----w- c:\program files\Bonjour
2010-08-18 17:01 . 2010-08-26 12:53 -------- d-----w- c:\documents and settings\Valentin\Application Data\Apple Computer
2010-08-18 16:52 . 2010-08-18 16:58 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-18 16:35 . 2010-08-18 16:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-18 16:26 . 2010-08-18 16:26 -------- d-----w- c:\documents and settings\Valentin\Local Settings\Application Data\Apple
2010-08-18 15:50 . 2010-08-22 12:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-08-18 15:40 . 2010-08-18 17:01 -------- d-----w- c:\documents and settings\Valentin\Local Settings\Application Data\Apple Computer
2010-08-18 14:44 . 2010-08-18 14:44 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-08-13 16:12 . 2010-08-23 10:30 -------- d-----w- c:\documents and settings\Valentin\Application Data\Media Player Classic
2010-08-10 11:44 . 2004-08-03 21:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-08-10 11:44 . 2004-08-03 21:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2010-08-07 21:20 . 2010-08-07 21:20 -------- d-----w- c:\documents and settings\Valentin\Local Settings\Application Data\Identities
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-29 21:07 . 2010-07-30 03:17 -------- d-----w- c:\program files\Splitcam Toolbar
2010-08-29 18:52 . 2010-06-08 00:23 -------- d-----w- c:\documents and settings\Valentin\Application Data\vlc
2010-08-29 15:57 . 2010-07-30 02:41 -------- d-----w- c:\program files\AutocompletePro
2010-08-29 15:21 . 2010-06-07 22:32 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-08-24 21:01 . 2010-06-08 00:15 -------- d-----w- c:\documents and settings\Valentin\Application Data\Dofus 2
2010-08-18 13:56 . 2010-08-18 13:56 20 ----a-w- c:\documents and settings\NetworkService\Application Data\bawuho.dat
2010-08-18 13:50 . 2010-08-18 13:49 20 ----a-w- c:\documents and settings\Valentin\Application Data\bawuho.dat
2010-08-18 01:38 . 2010-06-22 06:17 -------- d-----w- c:\program files\Dofus
2010-08-18 01:17 . 2010-06-08 00:23 -------- d-----w- c:\documents and settings\Valentin\Application Data\dvdcss
2010-08-01 17:22 . 2010-07-21 19:29 -------- d-----w- c:\program files\Steam
2010-07-30 03:31 . 2010-07-30 03:31 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-07-30 03:17 . 2010-07-30 02:42 -------- d-----w- c:\documents and settings\Valentin\Application Data\Toolbar4
2010-07-30 03:17 . 2010-07-30 03:17 59174 ----a-w- c:\documents and settings\Valentin\Application Data\Toolbar4\{338B4DFE-2E2C-4338-9E41-E176D497299E}\UninstallToolbar.exe
2010-07-30 03:17 . 2010-07-30 03:17 13824 ----a-w- c:\windows\system32\drivers\splitcam.sys
2010-07-30 03:17 . 2010-07-30 03:17 -------- d-----w- c:\program files\SplitCam
2010-07-30 03:17 . 2010-06-07 21:01 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-30 02:34 . 2010-07-30 02:10 -------- d-----w- c:\program files\Fake Webcam
2010-07-26 06:44 . 2010-07-26 06:44 -------- d-----w- c:\program files\Realtek AC97
2010-07-26 06:44 . 2010-07-26 06:27 -------- d-----w- c:\program files\Realtek AC97(2)
2010-07-14 08:00 . 2010-07-30 03:31 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-07-13 16:05 . 2010-07-13 16:05 64680 ----a-w- c:\windows\BricoPackUninst.cmd
2010-07-13 16:05 . 2010-07-13 16:04 6120 ----a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-07-13 16:05 . 2004-08-04 04:54 219648 ----a-w- c:\windows\system32\uxtheme.dll
2010-07-13 15:16 . 2010-07-03 02:03 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
2010-07-07 21:44 . 2010-07-07 21:44 -------- d-----w- c:\program files\Microsoft Silverlight
2010-07-06 23:11 . 2010-07-06 23:11 -------- d-----w- c:\documents and settings\Valentin\Application Data\teamspeak2
2010-07-06 21:26 . 2010-07-06 21:26 0 ----a-w- c:\documents and settings\Valentin\errorlog.tmp
2010-07-03 02:05 . 2010-07-03 02:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2010-06-29 14:49 . 2002-09-07 00:00 48856 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-29 14:49 . 2002-09-07 00:00 368076 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-18 21:33 . 2010-06-18 21:34 53632 ----a-w- c:\documents and settings\Valentin\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-06-08 23:05 . 2010-06-07 20:39 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-06-08 16:10 . 2010-07-30 03:31 790528 ----a-w- c:\windows\system32\xvidcore.dll
2010-06-08 16:10 . 2010-07-30 03:31 134144 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-07 22:20 . 2010-06-07 22:22 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-06-07 22:20 . 2010-06-07 22:22 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-06-07 22:20 . 2010-06-07 22:22 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-06-07 22:20 . 2010-06-07 22:22 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-06-07 22:07 . 2010-06-07 22:02 18304 ----a-w- c:\documents and settings\Valentin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-07 21:58 . 2010-06-07 21:58 0 ----a-w- c:\windows\nsreg.dat
2010-06-07 21:24 . 2010-06-07 21:24 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-06-07 20:37 . 2010-06-07 20:37 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2010-06-02 02:55 . 2010-06-26 01:05 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 02:55 . 2010-06-26 01:05 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 02:55 . 2010-06-26 01:05 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
.
------- Sigcheck -------
[-] 2004-08-04 . D295FF474863689522AF4728B39A8C6D . 102400 . . [5.4.3790.2180] . . c:\windows\system32\wuauclt.exe
[-] 2004-08-04 . F6AD4C0F992B3B51C044AD74D9E2E854 . 694784 . . [6.00.2900.2180] . . c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-06-07 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NETGEAR WG311v3 Smart Wizard.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\NETGEAR WG311v3 Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG311v3 Smart Wizard.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 04:54 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 20:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-01-11 20:17 13666408 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-01-11 20:17 110696 ----a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2007-04-16 13:28 577536 ----a-w- c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-07-21 19:30 1238352 ----a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 13:21 246504 ----a-w- c:\program files\Fichiers communs\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [08/06/2010 00:21 194817]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [08/06/2010 00:21 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [08/06/2010 00:21 434945]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [21/06/2010 02:18 136176]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [10/06/2010 16:57 271728]
.
Contenu du dossier 'Tâches planifiées'
2010-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-21 00:18]
2010-08-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-21 00:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.bigseekpro.com/splitcam/{25FC5A67-5026-45D9-91E0-12711E92C373}
mStart Page = hxxp://www.bigseekpro.com/splitcam/{25FC5A67-5026-45D9-91E0-12711E92C373}
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
FF - ProfilePath - c:\documents and settings\Valentin\Application Data\Mozilla\Firefox\Profiles\2t1cwlu1.default\
FF - prefs.js: browser.search.selectedEngine - BigSeekPro
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-klmdb.sys
MSConfigStartUp-nwiz - nwiz.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-29 23:09
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(716)
c:\program files\Avira\AntiVir Desktop\avsda.dll
- - - - - - - > 'explorer.exe'(3604)
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2010-08-29 23:11:10 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-08-29 21:11
Avant-CF: 264 435 560 448 octets libres
Après-CF: 264 549 076 992 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 970F11542E0C01E3F06C4E7C06505242