ComboFix 08-08-21.01 - benziane 2008-08-21 23:30:12.2 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.179 [GMT 1:00]
Endroit: C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\ComboFix.exe
Command switches used :: C:\Documents and Settings\benziane\Mes documents\Downloads\Programs\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE ::
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
F:\compresse\wsp_0.9.6_lakionline
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\! FIRST READ THIS !.txt
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\English.lng
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\ReadMe.txt
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp.exe
F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_emu.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-21 to 2008-08-21 ))))))))))))))))))))))))))))))))))))
.
2008-08-21 22:23 . 2008-08-21 22:23 <REP> d-------- C:\Program Files\Trend Micro
2008-08-21 17:52 . 2008-08-21 17:52 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-21 17:52 . 2008-08-21 17:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-21 17:17 . 2008-08-21 17:17 <REP> d-------- C:\Program Files\Lavasoft
2008-08-21 14:55 . 2008-08-21 14:55 15,648 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2008-08-21 14:55 . 2008-08-21 14:55 15,648 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2008-08-21 14:55 . 2008-08-21 14:54 12,960 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2008-08-21 14:54 . 2008-08-21 14:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-21 14:49 . 2008-08-21 14:49 860 --a------ C:\c0a80100.pac
2008-08-19 11:10 . 2008-08-19 11:10 14,615 --a------ C:\fond.bin
2008-08-18 04:10 . 2008-08-18 04:10 <REP> d-------- C:\Documents and Settings\benziane\Application Data\PingTesterDataBas
2008-08-18 03:48 . 2008-08-18 03:48 <REP> d-------- C:\Program Files\SatcoDX
2008-08-18 02:12 . 2008-08-18 02:12 <REP> d-------- C:\Documents and Settings\benziane\Application Data\Micro Application
2008-08-18 00:47 . 2008-08-18 00:47 <REP> d-------- C:\Program Files\Micro Application
2008-08-16 11:20 . 2008-08-16 11:20 <REP> d-------- C:\Program Files\BreakPoint Software
2008-08-16 00:13 . 2008-08-16 00:13 <REP> d-------- C:\Program Files\CorvoBoys GBTool
2008-08-16 00:13 . 2008-08-16 00:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}
2008-08-15 21:53 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-08-15 19:06 . 2008-08-15 19:06 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-08-15 19:06 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-08-15 19:05 . 2008-08-15 19:05 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-08-15 19:05 . 2008-08-15 19:05 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-15 19:05 . 2008-08-15 19:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-08-14 16:35 . 2008-08-14 16:35 <REP> d-------- C:\Program Files\MacBoX_v.4
2008-08-13 17:01 . 2008-08-13 17:01 <REP> d-------- C:\Program Files\MSN Games
2008-08-13 17:01 . 2008-08-13 17:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-12 23:18 . 2008-07-19 12:28 2,038,069 --------- C:\WINDOWS\Receiver Firmwareinfo.CAB
2008-08-12 23:18 . 2008-08-12 23:18 74,752 --a------ C:\WINDOWS\ST6UNST.EXE
2008-08-12 23:18 . 2008-08-12 23:18 364 --a------ C:\WINDOWS\ST6UNST.000
2008-08-08 01:49 . 2008-08-08 01:49 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-08-07 18:52 . 2008-08-07 18:52 <REP> d-------- C:\WINDOWS\Sun
2008-08-06 22:17 . 2008-08-06 22:17 <REP> d-------- C:\Program Files\Apple Software Update
2008-08-06 22:13 . 2008-08-06 22:13 <REP> d-------- C:\Program Files\Safari
2008-08-05 11:33 . 2008-08-05 11:33 <REP> d-------- C:\Documents and Settings\benziane\Application Data\TuneUp Software
2008-08-04 23:33 . 2008-08-04 23:33 <REP> d-------- C:\Program Files\Sun
2008-08-04 23:33 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-04 23:32 . 2008-08-04 23:32 <REP> d-------- C:\Program Files\Java
2008-08-04 23:26 . 2008-08-04 23:26 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-08-04 18:14 . 2008-08-04 18:14 <REP> d-------- C:\Program Files\ma-config.com
2008-08-04 18:14 . 2008-08-04 18:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-08-04 13:18 . 2008-08-04 13:18 <REP> d-------- C:\Program Files\eMule
2008-08-04 12:57 . 2008-08-04 12:57 <REP> d-------- C:\Documents and Settings\benziane\Application Data\skypePM
2008-08-04 12:57 . 2008-08-04 12:57 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-08-04 00:59 . 2008-08-04 14:33 230,424 --a------ C:\img2-001.raw
2008-08-03 23:35 . 2008-08-03 23:35 <REP> d-------- C:\Documents and Settings\benziane\Application Data\Apple Computer
2008-08-03 23:34 . 2008-08-03 23:34 <REP> d-------- C:\Program Files\Bonjour
2008-08-03 23:33 . 2008-08-03 23:33 <REP> d-------- C:\Program Files\QuickTime
2008-08-03 23:33 . 2008-08-03 23:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-03 23:32 . 2008-08-03 23:32 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-08-03 23:32 . 2008-08-03 23:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-08-03 19:47 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-03 16:39 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-08-03 16:39 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-08-03 16:39 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-08-03 11:39 . 2008-08-03 11:39 <REP> d-------- C:\Program Files\Real
2008-08-03 11:39 . 2008-08-03 11:39 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-08-03 11:39 . 2008-08-03 11:39 <REP> d-------- C:\Program Files\Fichiers communs\Real
2008-08-03 11:39 . 2008-08-03 11:39 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-08-03 11:39 . 2008-08-03 11:39 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-08-03 03:15 . 2008-08-03 03:15 <REP> d-------- C:\Documents and Settings\benziane\Application Data\MSNInstaller
2008-08-03 02:41 . 2008-08-03 02:41 <REP> d-------- C:\Documents and Settings\benziane\Application Data\Yahoo!
2008-08-03 02:41 . 2008-08-03 02:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-03 02:39 . 2008-08-03 02:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-03 02:35 . 2008-08-03 02:35 <REP> d-------- C:\Program Files\Yahoo!
2008-08-03 01:00 . 2008-08-03 01:00 <REP> d-------- C:\Documents and Settings\benziane\Contacts
2008-08-03 00:50 . 2008-06-23 17:28 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-03 00:50 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-03 00:50 . 2007-03-08 07:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-03 00:50 . 2008-06-23 17:28 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-03 00:50 . 2008-06-23 17:28 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-03 00:50 . 2008-06-23 17:28 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-03 00:50 . 2008-06-23 17:28 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-03 00:50 . 2008-06-23 17:28 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-03 00:50 . 2008-06-23 10:20 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-02 23:58 . 2008-08-02 23:58 <REP> d-------- C:\Program Files\Windows Live Toolbar
2008-08-02 23:58 . 2008-08-02 23:58 <REP> d-------- C:\Program Files\Windows Live Favorites
2008-08-02 23:49 . 2008-08-02 23:49 <REP> d-------- C:\WINDOWS\system32\DRVSTORE
2008-08-02 23:35 . 2008-08-02 23:35 <REP> d--hs---- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-08-02 23:34 . 2008-08-02 23:34 <REP> d-------- C:\Program Files\Windows Live
2008-08-02 23:34 . 2008-08-02 23:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-02 23:30 . 2008-08-02 23:30 <REP> d--hs---- C:\Recycled
2008-08-02 23:10 . 2008-08-02 23:10 385 --a------ C:\WINDOWS\ODBC.INI
2008-08-02 23:09 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-08-02 23:06 . 2008-08-02 23:06 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-08-02 23:06 . 2008-08-02 23:06 <REP> d-------- C:\Program Files\Microsoft.NET
2008-08-02 22:34 . 2008-08-02 22:34 0 --a------ C:\WINDOWS\nsreg.dat
2008-08-02 22:30 . 2008-08-02 22:30 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-08-02 22:24 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-08-02 22:24 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-02 22:20 . 2008-08-02 22:20 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-08-02 22:11 . 2008-08-02 22:11 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-08-02 22:08 . 2008-08-02 22:09 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-08-02 22:08 . 2008-08-02 22:09 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-02 21:00 . 2008-08-02 21:00 <REP> d-------- C:\Program Files\Internet Download Manager
2008-08-02 21:00 . 2008-08-02 21:00 <REP> d-------- C:\Documents and Settings\benziane\Application Data\IDM
2008-08-02 21:00 . 2008-08-02 21:00 <REP> d-------- C:\Documents and Settings\benziane\Application Data\DMCache
2008-07-29 15:03 . 2008-07-09 15:34 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 21:55 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-21 21:55 32 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-21 21:55 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-21 21:55 32 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-06 17:19 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-08-02 21:13 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-08-02 21:13 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-08-02 19:59 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-08-02 19:56 --------- d-----w C:\Program Files\Kaspersky Lab
2008-08-02 19:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-02 19:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-02 19:50 --------- d-----w C:\Program Files\Skype
2008-08-02 19:50 --------- d-----w C:\Program Files\Google
2008-08-02 19:50 --------- d-----w C:\Program Files\Fichiers communs\Skype
2008-08-02 19:50 --------- d-----w C:\Documents and Settings\benziane\Application Data\Skype
2008-08-02 19:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-08-02 19:49 --------- d-----w C:\Program Files\VideoLAN
2008-08-02 19:49 --------- d-----w C:\Documents and Settings\benziane\Application Data\vlc
2008-08-02 19:46 --------- d-----w C:\Program Files\Fichiers communs\snp325
2008-08-02 19:46 --------- d-----w C:\Documents and Settings\benziane\Application Data\InstallShield
2008-08-02 19:42 --------- d-----w C:\Program Files\Realtek
2008-08-02 19:41 --------- d-----w C:\Program Files\S3
2008-08-02 19:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 19:38 --------- d-----w C:\Program Files\VIA
2008-08-02 19:37 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-08-02 19:34 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-08-02 19:34 --------- d-----w C:\Program Files\Athan
2008-08-02 19:31 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-02 19:30 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-02 19:15 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-02 19:14 --------- d-----w C:\Program Files\Services en ligne
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 09:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:21 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:21 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 18:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 18:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 18:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 10:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\c0a80100.pac -- Not a PE file.
MD5: c55ea316656d22b5b2a3aa18c6797d98
C:\img2-001.raw -- Not a PE file.
MD5: af49fd09fa42d532c9090b7400a47dee
---- Directory of C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794} ----
2008-08-16 00:13 98 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\instance.dat
2008-08-16 00:13 188 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\Setup.dat
2008-08-16 00:13 1005 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\Setup.par
2008-03-03 12:51 575060 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\mia.dll
2008-03-03 12:51 360960 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\Setup.msi
2008-03-03 12:51 2205532 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\Setup.exe
2008-03-03 12:51 1472355 --a------ C:\Documents and Settings\All Users\Application Data\{31AF25DF-EFEB-4C20-8C2A-0ED5C4C1C794}\Setup.res
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-08-02 20:50 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:54 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-07-29 15:18 2610608]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"SpeedConnectStartUp"="E:\Program Files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe" [2008-08-03 21:31 565760]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"tsnp325"="C:\WINDOWS\tsnp325.exe" [2007-04-21 09:36 270336]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-03 11:39 185896]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-12-19 05:12 16062464 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 04:54 15360]
C:\Documents and Settings\benziane\Menu D‚marrer\Programmes\D‚marrage\
No-IP DUC.lnk - E:\Program Files\No-IP\DUC20.exe [2008-07-20 18:44:24 1172992]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38 1134592]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
"SpeedConnectStartUp"=E:\Program Files\CBS Software\SpeedConnect Internet Accelerator\SpeedConnectStartUp.exe -run
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"IDMan"=C:\Program Files\Internet Download Manager\IDMan.exe /onboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AppleSyncNotifier"=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"VTTrayp"=VTtrayp.exe
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"Athan"=C:\Program Files\Athan\Athan.exe
"FixCamera"=C:\WINDOWS\FixCamera.exe
"snp325"=C:\WINDOWS\vsnp325.exe
"VTTimer"=VTTimer.exe
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 7.0\\AVP.EXE"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MacBoX_v.4\\OpenCom.exe"=
"C:\\Program Files\\MacBoX_v.4\\gboxx86.exe"=
"C:\\Program Files\\MacBoX_v.4\\MacBoX_v.4.exe"=
"C:\\Program Files\\MacBoX_v.4\\GboxSC.exe"=
"C:\\Program Files\\Google\\Web Accelerator\\GoogleWebAccWarden.exe"=
"D:\\Program Files\\eMule\\emule.exe"=
"F:\\wsp_0.9.6_lakionline\\wsp_0.9.6_lakionline\\wsp_0.9.6_lakionline\\wsp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5656:UDP"= 5656:UDP:MacBoX_v.4
"7561:TCP"= 7561:TCP:eMule
"7571:UDP"= 7571:UDP:eMule
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 14:22]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-10-18 11:39]
R2 ioperm;ioperm support for Cygwin driver;F:\gbox control\gbox control\ioperm.sys [2005-11-23 00:03]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-04 04:55]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 20:57]
S3 SNP325;USB PC Camera (SNPSTD325);C:\WINDOWS\system32\DRIVERS\snp325.sys [2007-10-29 16:57]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-08-15 19:06]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-21 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-08-21 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:23]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 23:32:01
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-21 23:32:49
ComboFix-quarantined-files.txt 2008-08-21 22:32:48
ComboFix2.txt 2008-08-21 21:58:30
Pre-Run: 12,139,134,976 octets libres
Post-Run: 12,139,790,336 octets libres
296 --- E O F --- 2008-08-15 13:07:08
merci de ton aide si le dossier F:\compresse\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp_0.9.6_lakionline\wsp.exe
Folder::
F:\compresse\wsp_0.9.6_lakionline
a quelque chose de louche je peut me m'en passer - je le desinstalle et je le supprime
merci de ton aide