moi jai le meme pb de virus jai effectuer le combo fix voila le le rapport quelqu'un peut m'aider?
ComboFix 08-03-27.5 - fabien 2008-03-29 13:57:51.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1485 [GMT 1:00]
Endroit: C:\Documents and Settings\fabien\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\.protected
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\.protected
C:\Documents and Settings\fabien\Favoris\Error Cleaner.url
C:\Documents and Settings\fabien\Favoris\Privacy Protector.url
C:\Documents and Settings\fabien\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\fabien\Menu Démarrer\Programmes\Démarrage\.protected
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\WINDOWS\.protected
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdn.com
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\Installer\{5bd2d1b5-d756-4037-bf98-986e1905f5c3}
C:\WINDOWS\Installer\{5bd2d1b5-d756-4037-bf98-986e1905f5c3}\zip.dll
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\drivers\etc\.protected
C:\WINDOWS\system32akttzn.exe
C:\WINDOWS\system32anticipator.dll
C:\WINDOWS\system32awtoolb.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32bsva-egihsg52.exe
C:\WINDOWS\system32dpcproxy.exe
C:\WINDOWS\system32emesx.dll
C:\WINDOWS\system32h@tkeysh@@k.dll
C:\WINDOWS\system32hoproxy.dll
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32hxiwlgpm.exe
C:\WINDOWS\system32medup012.dll
C:\WINDOWS\system32medup020.dll
C:\WINDOWS\system32msgp.exe
C:\WINDOWS\system32msnbho.dll
C:\WINDOWS\system32mssecu.exe
C:\WINDOWS\system32msvchost.exe
C:\WINDOWS\system32mtr2.exe
C:\WINDOWS\system32mwin32.exe
C:\WINDOWS\system32netode.exe
C:\WINDOWS\system32newsd32.exe
C:\WINDOWS\system32ps1.exe
C:\WINDOWS\system32psof1.exe
C:\WINDOWS\system32psoft1.exe
C:\WINDOWS\system32regc64.dll
C:\WINDOWS\system32regm64.dll
C:\WINDOWS\system32Rundl1.exe
C:\WINDOWS\system32smp
C:\WINDOWS\system32smp\msrc.exe
C:\WINDOWS\system32sncntr.exe
C:\WINDOWS\system32ssurf022.dll
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32ssvchost.exe
C:\WINDOWS\system32sysreq.exe
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32taack.exe
C:\WINDOWS\system32temp#01.exe
C:\WINDOWS\system32thun.dll
C:\WINDOWS\system32thun32.dll
C:\WINDOWS\system32VBIEWER.OCX
C:\WINDOWS\system32vbsys2.dll
C:\WINDOWS\system32vcatchpi.dll
C:\WINDOWS\system32winlogonpc.exe
C:\WINDOWS\system32winsystem.exe
C:\WINDOWS\system32WINWGPX.EXE
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\Web\def.htm
C:\WINDOWS\winsystem.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_npf
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-29 ))))))))))))))))))))))))))))))))))))
.
2008-03-28 23:07 . 2008-03-28 23:07 <REP> d-------- C:\Program Files\Avira
2008-03-28 23:07 . 2008-03-28 23:07 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
2008-03-28 22:42 . 2008-03-28 22:59 <REP> d-------- C:\WINDOWS\AU_Temp
2008-03-28 22:42 . 2008-03-28 22:43 36,267,177 --a------ C:\WINDOWS\VPTNFILE.191
2008-03-28 22:42 . 2008-03-28 22:43 36,267,177 --a------ C:\WINDOWS\LPT$VPN.191
2008-03-28 22:35 . 2008-03-28 22:58 <REP> d-------- C:\fixwareout
2008-03-28 20:18 . 2008-03-28 22:58 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-03-26 23:23 . 2008-03-21 20:09 90,112 --a------ C:\WINDOWS\system32\uqzjcirr.exe
2008-03-26 17:31 . 2008-03-26 17:31 1,940,537 --a------ C:\WINDOWS\tsc.ptn
2008-03-26 17:31 . 2008-03-28 22:43 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2008-03-26 17:31 . 2008-03-26 17:31 333,576 --a------ C:\WINDOWS\TSC.exe
2008-03-26 17:31 . 2008-03-28 22:43 86,094 --a------ C:\WINDOWS\BPMNT.dll
2008-03-26 17:31 . 2008-03-26 17:31 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2008-03-26 17:31 . 2008-03-28 22:43 823 --a------ C:\WINDOWS\tsc.ini
2008-03-26 17:29 . 2008-03-26 17:29 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-03-26 17:29 . 2008-03-26 17:29 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-03-26 17:29 . 2008-03-26 17:29 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-03-26 17:29 . 2008-03-28 22:42 170 --a------ C:\WINDOWS\GetServer.ini
2008-03-24 19:45 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-03-24 19:45 . 2004-08-03 23:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-03-24 19:45 . 2004-08-04 00:55 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-03-24 19:45 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-03-24 19:45 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-03-24 19:45 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-03-24 19:45 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-03-24 19:44 . 2005-07-30 04:56 91,648 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-03-24 19:44 . 2004-08-04 00:55 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-03-24 19:44 . 2004-08-04 00:54 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-03-24 19:44 . 2004-08-04 00:55 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-03-24 19:44 . 2004-08-04 00:55 28,672 --a------ C:\WINDOWS\system32\vidcap.ax
2008-03-24 19:44 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2008-03-24 19:40 . 2004-12-18 09:58 245,820 --a------ C:\WINDOWS\system32\VM31bPrp.Ax
2008-03-24 19:40 . 2002-08-22 16:34 147,456 --a------ C:\WINDOWS\VMCap.exe
2008-03-24 19:40 . 2005-02-26 16:25 91,527 --a------ C:\WINDOWS\system32\drivers\usbVM31b.sys
2008-03-24 19:40 . 2003-05-15 17:17 61,440 --a------ C:\WINDOWS\system32\VM31bSTI.dll
2008-03-24 19:40 . 2004-04-26 15:48 53,248 --a------ C:\WINDOWS\amcap.exe
2008-03-24 19:40 . 2004-06-09 15:37 40,960 --a------ C:\WINDOWS\VM_STI.EXE
2008-03-23 18:32 . 2008-03-23 18:32 <REP> d-------- C:\Documents and Settings\fabien\Application Data\Grisoft
2008-03-23 18:32 . 2008-03-23 18:32 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-03-23 18:32 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-22 19:56 . 2008-03-22 19:56 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\NVIDIA
2008-03-22 17:22 . 2008-03-28 22:59 <REP> d-------- C:\Program Files\PC-Cleaner
2008-03-22 17:22 . 2008-03-22 17:23 <REP> d-------- C:\Documents and Settings\fabien\Application Data\PC-Cleaner
2008-03-22 14:30 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-22 14:30 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-22 14:30 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-22 14:30 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-22 14:30 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-22 14:30 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-22 14:30 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-22 14:30 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-22 10:56 . 2008-03-22 10:56 <REP> d-------- C:\Documents and Settings\fabien\Bureauvirii
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\BureauTrojan.Win32.BlackBird.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\BureauFWebdEditor.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\Bureaufwebd.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\Bureaufkwp2.0.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\Bureaufkwp1.5.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\Bureaufilemanagerclient.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\BureauEditorFKWP2.0.exe
2008-03-22 10:56 . 2008-03-22 10:56 4,096 --a------ C:\Documents and Settings\fabien\BureauEditorFKWP1.5.exe
2008-03-21 20:05 . 2008-03-21 18:16 245,760 --a------ C:\WINDOWS\altvxvm.dll
2008-03-21 20:05 . 2008-03-21 18:17 212,992 --a------ C:\WINDOWS\drnpfdxlwn.dll
2008-03-21 19:43 . 2008-03-21 19:43 <REP> d-------- C:\Documents and Settings\fabien\Application Data\Talkback
2008-03-21 19:42 . 2008-03-21 19:42 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-19 14:11 . 2008-03-19 14:11 <REP> d-------- C:\Documents and Settings\Murielle\Contacts
2008-03-19 14:09 . 2008-03-08 11:59 <REP> d-------- C:\Documents and Settings\Murielle\VS80-KB925674-X86
2008-03-19 14:09 . 2008-03-08 12:40 <REP> d--h----- C:\Documents and Settings\Murielle\Voisinage r‚seau
2008-03-19 14:09 . 2008-03-08 12:40 <REP> d--h----- C:\Documents and Settings\Murielle\Voisinage d'impression
2008-03-19 14:09 . 2008-03-08 11:53 <REP> d--h----- C:\Documents and Settings\Murielle\ModŠles
2008-03-19 14:09 . 2008-03-19 14:13 <REP> dr------- C:\Documents and Settings\Murielle\Mes documents
2008-03-19 14:09 . 2008-03-08 12:40 <REP> dr------- C:\Documents and Settings\Murielle\Menu D‚marrer
2008-03-19 14:09 . 2008-03-08 12:07 <REP> d-------- C:\Documents and Settings\Murielle\IXP000.TMP
2008-03-19 14:09 . 2008-03-19 14:09 <REP> dr------- C:\Documents and Settings\Murielle\Favoris
2008-03-19 14:09 . 2008-03-08 12:40 <REP> d-------- C:\Documents and Settings\Murielle\Bureau
2008-03-19 14:09 . 2008-03-19 14:09 <REP> d-------- C:\Documents and Settings\Murielle\Application Data\Styler
2008-03-11 22:05 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-11 22:05 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-11 22:05 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-11 07:21 . 2008-03-11 07:21 <REP> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-03-11 07:21 . 2008-03-11 07:21 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-03-10 23:30 . 2008-03-10 23:30 <REP> dr-h----- C:\Documents and Settings\fabien\Application Data\SecuROM
2008-03-10 23:30 . 2008-03-10 23:30 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-03-10 23:13 . 2008-03-10 23:13 <REP> d-------- C:\Program Files\KONAMI
2008-03-10 18:35 . 2008-03-10 18:35 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
2008-03-10 18:35 . 2006-12-08 03:04 76,800 --a------ C:\WINDOWS\system32\E_FLBCDE.DLL
2008-03-10 18:35 . 2006-04-19 03:00 62,976 --a------ C:\WINDOWS\system32\E_FD4BCDE.DLL
2008-03-10 18:35 . 2004-09-10 21:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-03-10 18:27 . 2008-03-10 18:27 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
2008-03-10 18:26 . 2007-03-11 20:07 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\UDL
2008-03-10 18:24 . 2008-03-10 18:24 <REP> d-------- C:\Documents and Settings\fabien\Application Data\InstallShield
2008-03-10 18:09 . 2007-03-27 00:00 67,072 --a------ C:\WINDOWS\system32\escwiad.dll
2008-03-10 18:09 . 2008-03-10 18:09 25 --a------ C:\WINDOWS\CDE DX7400DEFGIPS.ini
2008-03-09 23:17 . 2008-03-09 23:17 <REP> d-------- C:\Documents and Settings\fabien\Application Data\Media Player Classic
2008-03-09 16:15 . 2008-03-09 16:15 <REP> d-------- C:\Documents and Settings\fabien\Application Data\Ahead
2008-03-09 16:11 . 2008-03-09 16:11 <REP> d-------- C:\Documents and Settings\fabien\Application Data\DivX
2008-03-09 15:30 . 2008-03-09 15:30 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-03-08 18:41 . 2008-03-08 18:42 <REP> d-------- C:\Program Files\DivX
2008-03-08 18:40 . 2008-03-08 18:40 <REP> d-------- C:\Documents and Settings\fabien\Application Data\vlc
2008-03-08 18:34 . 2008-03-09 18:25 <REP> d-------- C:\Documents and Settings\fabien\Contacts
2008-03-08 18:28 . 2008-03-28 22:58 <REP> d-------- C:\Documents and Settings\fabien\Application Data\Azureus
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 11:31 --------- d-----w C:\Program Files\eMule
2008-03-26 16:23 --------- d-----w C:\Program Files\MioNet
2008-03-20 17:58 --------- d-----w C:\Program Files\Azureus
2008-03-12 06:50 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-03-11 21:09 --------- d-----w C:\Program Files\Windows Live
2008-03-08 12:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-07 18:11 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Azureus
2008-02-21 02:05 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-02-21 02:05 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-21 02:05 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-02-11 19:11 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-05 05:56 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\dvdcss
2008-01-09 17:09 1 ----a-w C:\Documents and Settings\Administrateur\SI.bin
2007-11-10 12:51 22,328 ----a-w C:\Documents and Settings\Administrateur\Application Data\PnkBstrK.sys
2007-06-12 05:51 92,064 ----a-w C:\Documents and Settings\Administrateur\mqdmmdm.sys
2007-06-12 05:51 9,232 ----a-w C:\Documents and Settings\Administrateur\mqdmmdfl.sys
2007-06-12 05:51 79,328 ----a-w C:\Documents and Settings\Administrateur\mqdmserd.sys
2007-06-12 05:51 66,656 ----a-w C:\Documents and Settings\Administrateur\mqdmbus.sys
2007-06-12 05:51 6,208 ----a-w C:\Documents and Settings\Administrateur\mqdmcmnt.sys
2007-06-12 05:51 5,936 ----a-w C:\Documents and Settings\Administrateur\mqdmwhnt.sys
2007-06-12 05:51 4,048 ----a-w C:\Documents and Settings\Administrateur\mqdmcr.sys
2007-06-12 05:51 25,600 ----a-w C:\Documents and Settings\Administrateur\usbsermptxp.sys
2007-06-12 05:51 22,768 ----a-w C:\Documents and Settings\Administrateur\usbsermpt.sys
2007-02-20 10:29 16,792 ----a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2004-08-28 14:00 579072 4d88aaf39adabfe45958ea1384e2c4ff C:\WINDOWS\system32\user32.dll
2007-12-07 02:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2004-08-28 14:00 876544 78188fb53c96e0636de67d6dd6ae4725 C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
2004-08-28 14:00 876544 78188fb53c96e0636de67d6dd6ae4725 C:\WINDOWS\system32\wininet.dll
2007-12-07 03:08 824832 4fc90bece54fac81b0090b94e27bfb6b C:\WINDOWS\system32\DllCache\wininet.dll
2004-08-28 14:00 507904 fb66744d525ea5df9a719f1db9b2dff4 C:\WINDOWS\system32\winlogon.exe
2004-08-28 14:00 182656 bc84c4f67d0e880b0c46dc0ce2b8cbaa C:\WINDOWS\system32\drivers\ndis.sys
2004-08-28 14:00 2437632 61381c1b4c0374569fbbf20ff9be199c C:\WINDOWS\system32\ntkrnlpa.exe
2004-08-28 14:00 2302976 eb0349334ecad45736daf747222b0f0d C:\WINDOWS\system32\ntoskrnl.exe
2004-08-28 14:00 1789952 addc47dfd517f2143d71e9310e414b50 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10F0C2A9-8E38-43e3-204D-45524C494E20}]
C:\Program Files\PC-Antispyware\IeExtension.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{837A022B-C2C0-4EE3-B2AC-6B896C38B030}]
2008-03-21 18:17 212992 --a------ C:\WINDOWS\drnpfdxlwn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-28 14:00 25088]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 11:29 220544]
"EPSON Stylus DX7400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.exe" [2007-04-12 07:00 182272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-10 21:59 1235456]
"UberIcon"="C:\Program Files\UberIcon\UberIcon Manager.exe" [2006-07-17 23:16 122880]
"VisualTaskTips"="C:\Windows\System32\VisualTaskTips.exe" [2004-08-28 14:00 36864]
"Vistadrv"="C:\WINDOWS\system32\Vistadrive\vsdrv.exe" [2006-07-30 03:37 121089]
"TransBar"="C:\WINDOWS\system32\transbar.exe" [2004-08-28 14:00 139264]
"Styler"="C:\Program Files\styler\Styler.exe" [2006-05-03 11:48 307200]
"Look 'n' Stop"="C:\Program Files\Soft4Ever\looknstop\looknstop.exe" [2008-03-08 12:06 516164]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-11-17 17:29 7700480]
"nwiz"="nwiz.exe" [2006-11-17 17:29 1622016 C:\WINDOWS\system32\nwiz.exe]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19 729088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 10:07 843776]
"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 16:31 1122304]
"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 16:14 497152]
"antiviirus"="C:\Program Files\antiviirus.exe" [ ]
"uqzjcirr"="C:\WINDOWS\system32\uqzjcirr.exe" [2008-03-21 20:09 90112]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-11-17 17:29 86016]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 15:37 40960]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25 249896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="C:\WINDOWS\system32\sti_ci.dll" [2004-08-28 14:00 678912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="cmd.exe" [2004-08-28 14:00 403968 C:\WINDOWS\system32\cmd.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-28 14:00 44544]
"nltide3"="cmd.exe" [2004-08-28 14:00 403968 C:\WINDOWS\system32\cmd.exe]
"nltide2"="cmd.exe" [2004-08-28 14:00 403968 C:\WINDOWS\system32\cmd.exe]
"nltide_2"="regsvr32 /s /n /i:U shell32" []
"nltide_3"="advpack.dll" [2004-08-28 14:00 124928 C:\WINDOWS\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"altvxvm"= {A04C6768-5B0B-47E3-89E0-0E2CFE2EE6B7} - C:\WINDOWS\altvxvm.dll [2008-03-21 18:16 245760]
"bokpkov"= {1BF20490-74B7-4871-BB3D-9F84D8C5F952} - C:\WINDOWS\bokpkov.dll [ ]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7561:TCP"= 7561:TCP:EMULE
"7571:UDP"= 7571:UDP:EMUle
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
R0 Si3112;Si3112;C:\WINDOWS\system32\drivers\Si3112.sys [2004-08-28 14:00]
R0 Si3124;Si3124;C:\WINDOWS\system32\drivers\Si3124.sys [2004-08-28 14:00]
R0 Si3132r5;Si3132r5;C:\WINDOWS\system32\drivers\Si3132r5.sys [2004-08-28 14:00]
R0 Si3531;Si3531;C:\WINDOWS\system32\drivers\Si3531.sys [2004-08-28 14:00]
R1 lnsfw1;lnsfw1;C:\WINDOWS\system32\drivers\lnsfw1.sys [2008-03-08 12:06]
R2 MioNet;MioNet Service;"C:\Program Files\MioNet\MioNetManager.exe" -s "C:\Program Files\MioNet\wrapper.conf" []
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-12-29 01:58]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-03-29 13:05:22 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-29 14:02:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Windows\System32\VttHooks.dll
-> C:\WINDOWS\altvxvm.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\MioNet\MioNetManager.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-29 14:06:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 13:06:48
Pre-Run: 87,538,257,920 octets libres
Post-Run: 87,445,188,608 octets libres