Regis59,
Voilà le rapport de COMBOFIX
ComboFix 07-12-31.4 - clem 2008-01-01 19:25:10.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.506 [GMT 1:00]
Running from: C:\Documents and Settings\clem\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\All Users\Application Data\Starware354
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\748_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\748_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\750_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\Green_Card0.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\Rencontres0.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\buttons\Screensavers0.bmp
C:\Documents and Settings\All Users\Application Data\Starware354\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware354\contexts\Related.xml
C:\Documents and Settings\All Users\Application Data\Starware354\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware354\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354
C:\Documents and Settings\clem\Application Data\Starware354\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\clem\Application Data\Starware354\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Configurator\Configurator.xml
C:\Documents and Settings\clem\Application Data\Starware354\Configurator\Configurator.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Green_Card\Green_CardOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Green_Card\Green_CardOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Layouts\ToolbarLayout.xml
C:\Documents and Settings\clem\Application Data\Starware354\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Manager\ManagerOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Rechercher_de_recettes\Rechercher_de_recettesOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Rechercher_de_recettes\Rechercher_de_recettesOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Recipe_RSS\Recipe_RSSOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Recipe_RSS\Recipe_RSSOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Rencontres\RencontresOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Rencontres\RencontresOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Screensavers\ScreensaversOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Screensavers\ScreensaversOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\clem\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\clem\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml.backup
C:\Program Files\Starware354
C:\Program Files\Starware354\icons\star_16.ico
C:\Program Files\Starware354\Starware354Config.xml
C:\Program Files\Starware354\Starware354Uninstall.exe
D:\Autorun.inf
G:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-01 to 2008-01-01 ))))))))))))))))))))))))))))))))))))
.
2008-01-01 19:24 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-01 19:08 . 2008-01-01 19:08 <REP> d-------- C:\hijackthis
2008-01-01 18:57 . 2008-01-01 18:57 <REP> d-------- C:\Program Files\CCleaner
2008-01-01 18:14 . 2008-01-01 18:14 <REP> d-------- C:\WINDOWS\LastGood
2008-01-01 18:14 . 2008-01-01 18:14 <REP> d-------- C:\Program Files\Panda Security
2007-12-31 10:37 . 2007-12-31 10:37 <REP> d-------- C:\Program Files\Alwil Software
2007-12-30 21:44 . 2007-12-30 21:44 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intel
2007-12-30 21:43 . 2007-03-10 16:40 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-12-30 21:43 . 2007-03-10 16:22 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-12-30 21:43 . 2007-03-10 16:22 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-12-30 21:43 . 2007-03-10 16:22 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-12-30 21:43 . 2007-03-10 16:47 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-12-30 21:43 . 2007-03-10 16:22 <REP> d-------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-12-30 21:43 . 2007-03-10 16:47 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-12-30 21:43 . 2007-03-10 16:22 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-12-30 21:43 . 2007-03-10 16:52 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Ulead Systems
2007-12-30 17:56 . 2007-12-30 17:56 <REP> d-------- C:\WINDOWS\system32\NtmsData
2007-12-30 13:17 . 2007-12-30 13:17 <REP> d--hs---- C:\FOUND.006
2007-12-30 10:07 . 2007-12-30 10:07 <REP> d--hs---- C:\FOUND.005
2007-12-26 09:13 . 2007-12-26 09:13 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-26 09:13 . 2007-12-26 09:13 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-25 17:00 . 2007-12-25 17:00 <REP> d-------- C:\Documents and Settings\clem\Application Data\My Games
2007-12-25 16:45 . 2007-12-25 16:45 <REP> d-------- C:\Program Files\Firaxis Games
2007-12-25 16:44 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-12-10 19:45 . 2007-12-10 19:45 <REP> d--hs---- C:\FOUND.004
2007-12-05 13:55 . 2007-12-05 13:55 <REP> d--hs---- C:\FOUND.003
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 21:27 --------- d-----w C:\Documents and Settings\clem\Application Data\dvdcss
2007-11-28 20:47 --------- d-----w C:\Program Files\Western Digital Technologies
2007-11-24 16:29 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-24 16:29 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-24 16:29 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-24 16:29 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-24 16:04 3,861,320 ----a-w C:\Program Files\eMule0.48a-Installer2.exe
2007-11-24 16:04 --------- d-----w C:\Program Files\eMule
2007-11-24 15:48 --------- d-----w C:\Documents and Settings\clem\Application Data\vlc
2007-11-24 15:38 --------- d-----w C:\Program Files\VideoLAN
2007-11-24 15:31 9,679,815 ----a-w C:\Program Files\vlc-0.8.6c-win32.exe
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-02 10:24 13,411,824 ----a-w C:\Program Files\Google_Earth_BZXV.exe
2007-10-31 03:53 3,590,656 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-25 16:43 8,516,608 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-11 06:13 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 152,064 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 1,495,040 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,056,768 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,024,000 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 23:49 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:49 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:49 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-10 23:49 6,065,664 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-10-10 23:49 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-10-10 23:49 478,208 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:49 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-10-10 23:49 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:49 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:49 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-10-10 23:49 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:49 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-10-10 23:49 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:49 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:49 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:49 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:49 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:49 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:49 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:49 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:49 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 23:49 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 11:01 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 11:00 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-10-10 05:46 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-10-01 13:49 542,088 ----a-w C:\WINDOWS\system32\SymNeti.dll
2007-10-01 13:49 161,160 ----a-w C:\WINDOWS\system32\SymRedir.dll
2007-08-27 11:57 3,853,117 ----a-w C:\Program Files\setup_oC305PE2.exe
2007-03-23 22:36 1,708,697 ----a-w C:\Program Files\jidelna-v.mov
2007-03-23 11:39 20,928,336 ----a-w C:\Program Files\SkypeSetup.exe
2007-03-14 16:15 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
1999-07-07 01:00 6 --sh--r C:\WINDOWS\@desktop@.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 12:54 172032]
"Wireless Console"="C:\Program Files\ASUS\Wireless Console\wcourier.exe" [2005-07-22 14:36 57344]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-11 06:03 708697]
"Matchlock Scheduling"="C:\Program Files\Ulead Systems\Ulead InstaMedia 3.0\Monitor.exe" [2005-07-05 23:22 45056]
"Ulead Remote Control Center"="C:\Program Files\Ulead Systems\Ulead InstaMedia 3.0\RMC.exe" [2005-05-27 08:09 49152]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-22 12:08 52840]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-05-31 22:46 401408]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-06-03 01:31 385024]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2005-05-31 22:50 356352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"RTHDCPL"="RTHDCPL.EXE" [2005-07-13 03:37 14679552 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
C:\Documents and Settings\clem\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-24 14:41:25]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
ASUS ChkMail.lnk - C:\Program Files\ASUS\Asus ChkMail\ChkMail.exe [2007-03-10 16:40:08]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 13:42:30]
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-24 14:41:25]
Acc‚l‚rateur de d‚marrage AutoCAD.lnk - C:\Program Files\Fichiers communs\Autodesk Shared\acstart17.exe [2006-03-05 14:43:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2005-05-31 22:46 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-05 14:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControl]
2005-07-06 20:26 102400 --a------ C:\WINDOWS\ATK0100\HControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
System
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 11:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
2003-05-08 11:00 49152 --a------ C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zshutdown]
c:\sysprep\patch\sysprep.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"SPBBCSvc"=2 (0x2)
"LxrSII1s"=2 (0x2)
"ITECIRService"=2 (0x2)
R2 LxrSII1d;Secure II Driver;C:\WINDOWS\system32\Drivers\LxrSII1d.sys [2006-01-10 10:52]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-08-03 17:29]
R3 AVerE506;AVerE506 service;C:\WINDOWS\system32\DRIVERS\AVerE506.sys [2005-06-14 11:12]
R3 ITECIR;ITE CIR Driver;C:\WINDOWS\system32\DRIVERS\ITECIR.sys [2004-04-22 15:03]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
S3 Asushwio;Asushwio;C:\WINDOWS\system32\drivers\Asushwio.sys [2000-03-29 14:17]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 12:10]
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys []
S4 ITECIRService;ITE Remote Control Service;C:\WINDOWS\system32\RemoteControlService.exe [2005-05-16 14:09]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a25b81e-6c6e-11dc-8991-0013ce6fb3e6}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL antihost.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4473d0e6-da1f-11db-a6ae-0013ce6fb3e6}]
\Shell\AutoRun\command - F:\Autorun.exe /run
\Shell\Shell00\Command - F:\Autorun.exe /run
\Shell\Shell01\Command - F:\Autorun.exe /action
\Shell\Shell02\Command - F:\Autorun.exe /uninstall
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81ba20a2-5947-11dc-8953-806d6172696f}]
\Shell\AutoRun\command - D:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad8b8040-cf22-11db-a687-806d6172696f}]
\Shell\AutoRun\command - C:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd4731b4-9b71-11dc-8a10-0013ce6fb3e6}]
\Shell\AutoRun\command - G:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
*Newly Created Service* - PROCEXP90
*Newly Created Service* - RKPAVPROC
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-12-14 19:24:56 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - clem.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-01 19:27:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-01 19:27:43
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-01 18:27:42
.
2007-12-31 08:31:34 --- E O F ---
A+
JPAV