Re,
désolé de ne pas avoir pu les poster plus tôt, mais je n'avais plus accès à l'ordi avec internet. :s
Il semble que presque tout refonctionne sauf internet et mon firewall... :s
Rapport InfoSat :
Tue Sep 23 22:13:18 2008
EliBagle v11.76 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 23 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Acción Directa):
Tue Sep 23 22:13:24 2008
EliBagle v11.76 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 23 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
__INCOMPLETE___(??????) [CIRCUS×CHERISH] D.C.S.G.?·??? ~?????????????~ ?01?66E34A02CA47A79FCC2DEBA808723A350235B2AE.ZIP -> Bagle__INCOMPLETE___(??????) [CIRCUS×CHERISH] D.C.S.G.?·??? ~?????????????~ ?02?E35428E33F4BFA797E91523C95675D510386BE94.ZIP -> Bagle__INCOMPLETE___(??????) [NAVEL×?? ?] SHUFFLE! -DAYS IN THE BLOOM- ?01?!F82FC300487D20F3230AC1FCE395D31C02B87893.ZIP -> Bagle__INCOMPLETE___(??????) [NAVEL×?? ?] SHUFFLE! -DAYS IN THE BLOOM- ?02?!32DB272EEFD1E8576114EF586B2EA5C902E401CF.ZIP -> Bagle__INCOMPLETE___(??????) [NAVEL×?? ?] SHUFFLE! -DAYS IN THE BLOOM- ?03?!BE8700416EB6E11FE49C09473623C1F202B0F30D.ZIP -> Bagle__INCOMPLETE___(??????) [NAVEL×?? ?] SHUFFLE! -DAYS IN THE BLOOM- ?04?!2E8CDE7E50BC876766FFD3671114B07A04F27FF9.ZIP -> Bagle__INCOMPLETE___(??????) [???????] D.C. ~?·???~ ?01?465BF2AEA0BE17DF2538BF8823BFC60602C737ED.ZIP -> Bagle__INCOMPLETE___(??????) [???????] D.C. ~?·???~ ?02?99B7A21F86AE2C65F6F7ACD87844A50201CDC949.ZIP -> Bagle__INCOMPLETE___(??????) [????×???] ????????? ?04?29D8E795265D7659CDE5675034756F9703B55216.ZIP -> BagleC:\Program Files\Analog Devices\SoundMAX\SMAX4PNP.EXE --> Eliminado Bagle.dldr
C:\Program Files\Google\GoogleToolbarNotifier\GOOGLETOOLBARNOTIFIER.EXE --> Eliminado Bagle.dldr
Nº Total de Directorios: 15774
Nº Total de Ficheros: 157594
Nº de Ficheros Analizados: 14604
Nº de Ficheros Infectados: 11
Nº de Ficheros Limpiados: 11
Tue Sep 23 22:36:01 2008
EliBagle v11.76 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 23 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad D:\
Nº Total de Directorios: 1268
Nº Total de Ficheros: 15565
Nº de Ficheros Analizados: 190
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Tue Sep 23 22:37:12 2008
EliBagle v11.76 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 23 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad F:\
(??????·??) [ASUKA] [2007-02] ?????? ???????? GEASS 05.ZIP -> Bagle[2006-10] FATE-STAY NIGHT 09 ?BOYS & GIRLS (?)?.ZIP -> Bagle(??????) [?????] ????? ?01?.ZIP -> Bagle(??????) [?????] ????? ?02?(4??).ZIP -> Bagle(??????) [?????] ????? ?03?(4??).ZIP -> Bagle(????) [????] ??????????! 1~8?·???1+2.ZIP -> Bagle(??????·??) [???????] [???] ??????? ?39? [2006-16].ZIP -> Bagle(??????·??) [???????] [???] ??????? ?40? [2006-17].ZIP -> Bagle(??????·??) [???????] [???] ??????? ?41? [2006-18].ZIP -> Bagle(??????·??) [???????] [???] ??????? ?42? [2006-19].ZIP -> Bagle(??????·??) [???????] [???] ??????? ?43? [2006-20].ZIP -> Bagle#TOUHOU(????29)(???)[GRAPHIC!!] FOLLOW MY STAR (?????).ZIP -> Bagle
Nº Total de Directorios: 2693
Nº Total de Ficheros: 40912
Nº de Ficheros Analizados: 2411
Nº de Ficheros Infectados: 12
Nº de Ficheros Limpiados: 12
Tue Sep 23 22:41:26 2008
EliBagle v11.76 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 23 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad G:\
Nº Total de Directorios: 12
Nº Total de Ficheros: 119
Nº de Ficheros Analizados: 6
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Rapport ComboFix :
ComboFix 08-09-22.05 - Ming 2008-09-23 22:50:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.515 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Ming\Bureau\TRISTAN.exe
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Ming\Cookies\ming@2o7[2].txt
C:\Documents and Settings\Ming\Cookies\ming@2o7[3].txt
C:\Documents and Settings\Ming\Cookies\ming@atom[1].txt
C:\Documents and Settings\Ming\Cookies\ming@belnet.dl.sourceforge[1].txt
C:\Documents and Settings\Ming\Cookies\ming@metrics.adobe[2].txt
C:\WINDOWS\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-23 au 2008-09-23 ))))))))))))))))))))))))))))))))))))
.
2008-09-23 20:29 . 2008-09-23 21:20 <REP> d-------- C:\Program Files\FindyKill
2008-09-17 18:48 . 2008-09-17 18:48 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-17 06:39 . 2008-09-17 06:39 <REP> d-------- C:\Program Files\Haali
2008-09-16 05:28 . 2008-09-16 05:28 <REP> d-------- C:\Documents and Settings\Ming\Application Data\Media Player Classic
2008-09-15 10:49 . 2008-09-15 10:59 <REP> d-------- C:\Program Files\QuickTime Alternative
2008-09-15 10:49 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-15 10:49 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-15 10:15 . 2008-09-15 10:15 <REP> d-------- C:\Program Files\iPod
2008-09-15 10:15 . 2008-09-15 10:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-15 10:11 . 2008-09-15 10:11 <REP> d-------- C:\Program Files\Bonjour
2008-09-07 14:08 . 2008-09-07 14:18 <REP> d-------- C:\Program Files\EasyPicture2Icon
2008-09-02 18:53 . 2004-08-04 00:55 91,648 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-09-02 18:02 . 2008-09-02 18:02 <REP> d-------- C:\Program Files\Blue Onion Software
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\WINDOWS\system32\dnssd.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 15:46 --------- d-----w C:\Program Files\lolifox
2008-09-23 15:43 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-09-23 14:24 --------- d-----w C:\Documents and Settings\Ming\Application Data\uTorrent
2008-09-23 01:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-09-19 15:21 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-09-18 20:25 --------- d-----w C:\Program Files\MAL Updater
2008-09-17 04:34 --------- d-----w C:\Program Files\Combined Community Codec Pack
2008-09-15 19:31 --------- d-----w C:\Documents and Settings\Ming\Application Data\vlc
2008-09-15 09:26 --------- d-----w C:\Program Files\Mp3tag
2008-09-15 09:08 --------- d-----w C:\Program Files\Winamp
2008-09-15 09:00 --------- d-----w C:\Program Files\QuickTime
2008-09-15 08:59 --------- d-----w C:\Program Files\Fichiers communs\Apple
2008-09-15 08:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-15 08:15 --------- d-----w C:\Program Files\iTunes
2008-09-15 08:07 --------- d-----w C:\Program Files\Apple Software Update
2008-09-14 13:42 --------- d-----w C:\Documents and Settings\Ming\Application Data\Aegisub
2008-09-10 14:45 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-09-07 12:12 --------- d-----w C:\Program Files\Minilyrics
2008-09-07 10:41 --------- d-----w C:\Documents and Settings\Ming\Application Data\foobar2000
2008-09-06 05:24 --------- d-----w C:\Documents and Settings\Ming\Application Data\Vso
2008-09-02 16:48 --------- d-----w C:\Program Files\MSN Messenger
2008-09-02 16:48 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-02 07:41 --------- d-----w C:\Program Files\Opera
2008-09-01 15:05 --------- d-----w C:\Documents and Settings\Ming\Application Data\MiniLyrics
2008-08-28 13:56 --------- d-----w C:\Program Files\MediaCoder
2008-08-27 09:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-27 08:52 --------- d-----w C:\Program Files\UberIcon
2008-08-10 18:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-10 18:34 --------- d-----w C:\Documents and Settings\Ming\Application Data\InstallShield
2008-08-10 10:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-10 10:01 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-10 09:47 --------- d-----w C:\Program Files\Stardock
2008-08-09 20:55 --------- d-----w C:\Program Files\WIDCOMM
2008-08-06 21:26 --------- d-----w C:\Program Files\Cheat Engine
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-15 21:42 1,655 ----a-w C:\WINDOWS\Fonts\LR______.PFM
2008-07-15 21:30 2,560 ----a-w C:\WINDOWS\system32\bitcometres.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-23 09:53 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"UberIcon"="C:\Program Files\UberIcon\UberIcon Manager.exe" [2006-02-05 180224]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-30 1829712]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-08 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-08 126976]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-03-29 233534]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2002-06-23 1148928]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 2629632]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\\vptray.exe" [2005-04-17 85184]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-11-01 995328]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-11-01 1101824]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
C:\Documents and Settings\Ming\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Rainlendar.lnk - C:\Program Files\Rainlendar\Rainlendar.exe [2005-10-23 118784]
Rainmeter.lnk - C:\Program Files\Rainmeter\Rainmeter.exe [2006-01-21 118784]
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2006-08-03 1976056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 00:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= C:\WINDOWS\system32\l3codecp.acm
"VIDC.ACDV"= ACDV.dll
"msacm.l3codec"= l3codecp.acm
"vidc.yv12"= yv12vfw.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2005-04-13 12:12 88209 C:\WINDOWS\AGRSMMSG.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LightScribe Control Panel"=C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"TopDesk"=C:\Program Files\TopDesk\topdesk.exe
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MAL Updater\\MalUpdater.exe"=
"C:6\\[GAME]\\PortableDark-Oberon\\dark-oberon\\doberon.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"777:TCP"= 777:TCP:BitComet 777 TCP
"777:UDP"= 777:UDP:BitComet 777 UDP
"7777:TCP"= 7777:TCP:BitComet 7777 TCP
"7777:UDP"= 7777:UDP:BitComet 7777 UDP
"80:TCP"= 80:TCP:BitComet 80 TCP
"80:UDP"= 80:UDP:BitComet 80 UDP
"8888:TCP"= 8888:TCP:BitComet 8888 TCP
"8888:UDP"= 8888:UDP:BitComet 8888 UDP
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2006-04-16 33920]
R2 Prvflder;Prvflder;C:\WINDOWS\system32\DRIVERS\prvflder.sys [2006-04-21 70912]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 CyUsbNT;Cypress Manufacturing Driver;C:\WINDOWS\system32\Drivers\CyUsbNT.sys [2005-02-16 28800]
S3 ebookman;FEP_USB Driver;C:\WINDOWS\system32\Drivers\ebookman.sys [2001-05-11 19677]
S3 el575nd5;Pilote de carte réseau PC Card 3Com Megahertz 10/100 CardBus;C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 69692]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-02 354560]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - (no file)
MSConfigStartUp-Startup Manager Scanner - C:\Program Files\Startup Mechanic\StartupMonitor.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Ming\Application Data\Mozilla\Firefox\Profiles\7nh4ar6o.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.be/
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1111.1511\npCIDetect11.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npvlc.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npdivx32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-23 22:54:41
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????3?6?7?6??????? ???B?????????????hLC? ??????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-23 23:00:39
ComboFix-quarantined-files.txt 2008-09-23 20:59:45
Avant-CF: 1.191.022.592 octets libres
Après-CF: 1,190,248,448 octets libres
236 --- E O F --- 2008-09-15 09:22:13