Re,
ci-joint rapport ComboFix , je n'ai pas désactivé l' antispyware qui doit être Spytbot
je peux le refaire si tu le souhaite mais dans l'immédiat je dois décrocher 2 ou 3 heures
encore merci pour votre aide
à tout à l'heure
jcld
ComboFix 08-12-13.03 - LE DU 2008-12-14 15:04:58.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.382.89 [GMT 1:00]
Running from: c:\documents and settings\LE DU\Bureau\ComboFix.exe
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!/B/COLOR
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\cfx32.ocx
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\regsvr32.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((( Files Created from 2008-11-14 to 2008-12-14 )))))))))))))))))))))))))))))))
.
2008-12-14 14:49 . 2008-12-14 14:49 <REP> d-------- C:\_OTMoveIt
2008-12-14 10:30 . 2008-04-13 18:33 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-13 09:29 . 2008-12-13 09:29 <REP> d-------- c:\windows\McAfee.com
2008-12-10 20:53 . 2008-12-10 20:53 <REP> d-------- c:\program files\Avira
2008-12-10 20:53 . 2008-12-10 20:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-10 18:37 . 2008-12-10 18:41 1,393 --a------ c:\windows\imsins.BAK
2008-12-10 18:16 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-10 18:16 . 2008-10-16 21:18 671,232 -----c--- c:\windows\system32\dllcache\mstime.dll
2008-12-10 18:16 . 2008-10-16 21:18 477,696 -----c--- c:\windows\system32\dllcache\mshtmled.dll
2008-12-10 18:16 . 2008-10-16 21:18 384,512 -----c--- c:\windows\system32\dllcache\iedkcs32.dll
2008-12-10 18:16 . 2008-10-16 21:18 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-10 18:16 . 2008-10-16 21:18 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-10 18:16 . 2008-10-16 21:18 230,400 -----c--- c:\windows\system32\dllcache\ieaksie.dll
2008-12-10 18:16 . 2008-10-16 21:18 193,024 -----c--- c:\windows\system32\dllcache\msrating.dll
2008-12-10 18:16 . 2008-10-15 08:04 161,792 -----c--- c:\windows\system32\dllcache\ieakui.dll
2008-12-10 18:16 . 2008-10-16 21:18 153,088 -----c--- c:\windows\system32\dllcache\ieakeng.dll
2008-12-10 18:16 . 2008-10-16 21:18 44,544 -----c--- c:\windows\system32\dllcache\iernonce.dll
2008-12-10 18:15 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-10 18:15 . 2008-10-16 21:18 1,160,192 -----c--- c:\windows\system32\dllcache\urlmon.dll
2008-12-10 18:15 . 2008-10-15 08:06 633,632 -----c--- c:\windows\system32\dllcache\iexplore.exe
2008-12-10 18:15 . 2008-10-16 21:18 124,928 -----c--- c:\windows\system32\dllcache\advpack.dll
2008-12-10 18:15 . 2008-10-16 21:18 102,912 -----c--- c:\windows\system32\dllcache\occache.dll
2008-12-10 18:15 . 2008-10-16 14:12 70,656 -----c--- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-10 18:15 . 2008-10-16 21:18 44,544 -----c--- c:\windows\system32\dllcache\pngfilt.dll
2008-12-10 18:15 . 2008-10-16 14:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-10 18:14 . 2008-10-16 21:18 826,368 -----c--- c:\windows\system32\dllcache\wininet.dll
2008-12-10 18:14 . 2008-10-16 21:18 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-10 18:14 . 2008-10-16 21:18 347,136 -----c--- c:\windows\system32\dllcache\dxtmsft.dll
2008-12-10 18:14 . 2008-10-16 21:18 233,472 -----c--- c:\windows\system32\dllcache\webcheck.dll
2008-12-10 18:14 . 2008-10-16 21:18 214,528 -----c--- c:\windows\system32\dllcache\dxtrans.dll
2008-12-10 18:14 . 2008-10-16 21:18 105,984 -----c--- c:\windows\system32\dllcache\url.dll
2008-12-10 18:14 . 2008-10-16 21:18 27,648 -----c--- c:\windows\system32\dllcache\jsproxy.dll
2008-12-10 18:13 . 2008-10-16 21:18 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-10 18:13 . 2008-10-16 21:18 1,831,424 -----c--- c:\windows\system32\dllcache\inetcpl.cpl
2008-12-10 18:13 . 2008-10-16 21:18 133,120 -----c--- c:\windows\system32\dllcache\extmgr.dll
2008-12-10 18:13 . 2008-10-16 21:18 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-10 18:13 . 2008-10-16 21:18 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-10 17:56 . 2008-10-03 11:03 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2008-12-10 12:39 . 2008-12-10 12:39 82 --a------ c:\windows\wininit.ini
2008-12-09 18:37 . 2008-12-09 18:35 21,353,001 --a------ c:\windows\LPT$VPN.697
2008-12-09 18:34 . 2008-12-09 18:35 21,353,001 --a------ c:\windows\VPTNFILE.697
2008-12-09 18:27 . 2008-12-09 18:36 <REP> d-------- c:\windows\AU_Temp
2008-11-30 20:02 . 2008-12-02 09:39 <REP> d-------- c:\program files\OUIDIRE LookHere
2008-11-30 12:58 . 2008-04-13 18:33 219,648 --a------ c:\windows\system32\uxtheme.backup
2008-11-30 12:38 . 2008-11-30 12:38 <REP> d-------- c:\program files\ZNsoft Corporation
2008-11-28 21:22 . 2008-11-29 21:59 <REP> d-------- c:\program files\EsetOnlineScanner
2008-11-27 14:10 . 2008-11-27 14:09 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-26 20:04 . 2008-11-26 20:04 <REP> d-------- c:\documents and settings\LE DU\Application Data\Yahoo!
2008-11-25 16:49 . 2008-11-25 16:51 <REP> d-------- c:\program files\Recuva
2008-11-25 11:40 . 2008-11-29 02:32 <REP> d-------- c:\documents and settings\All Users\Application Data\DriverScanner
2008-11-25 10:53 . 2008-11-25 10:53 <REP> d----c--- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2008-11-25 10:32 . 2008-11-25 10:32 <REP> dr-h----- C:\AHCache
2008-11-22 13:38 . 2008-12-11 13:57 <REP> d-------- c:\program files\RogueRemover FREE
2008-11-22 12:54 . 2008-11-22 12:54 <REP> d-------- c:\documents and settings\LE DU\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 13:33 --------- d-----w c:\program files\Mozilla Thunderbird
2008-12-12 23:18 --------- d-----w c:\program files\JkDefrag
2008-12-12 23:07 --------- d-----w c:\program files\Freecorder
2008-12-12 22:56 --------- d-----w c:\documents and settings\LE DU\Application Data\Dexpot
2008-12-12 22:53 --------- d-----w c:\program files\Java
2008-12-12 22:23 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-12 21:43 --------- d-----w c:\program files\NCH Swift Sound
2008-12-12 20:43 --------- d-----w c:\program files\Dexpot
2008-12-11 17:26 --------- d-----w c:\program files\Uniblue
2008-12-09 17:35 91,744 ----a-w c:\windows\BPMNT.dll
2008-12-09 17:35 71,749 ----a-w c:\windows\hcextoutput.dll
2008-12-09 17:35 345,157 ----a-w c:\windows\tsc.exe
2008-12-09 17:35 1,213,784 ----a-w c:\windows\vsapi32.dll
2008-12-09 17:21 69,689 ----a-w c:\windows\UNZIP.DLL
2008-12-09 17:21 507,904 ----a-w c:\windows\TMUPDATE.DLL
2008-12-09 17:21 286,720 ----a-w c:\windows\PATCH.EXE
2008-12-09 08:53 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-04 10:25 --------- d-----w c:\program files\jv16 PowerTools
2008-12-04 09:14 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-02 08:39 --------- d-----w c:\documents and settings\LE DU\Application Data\Uniblue
2008-11-28 19:44 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-27 18:23 --------- d-----w c:\program files\Registry Expert
2008-11-25 15:46 --------- d-----w c:\program files\Yahoo!
2008-11-25 10:49 --------- d-----w c:\documents and settings\LE DU\Application Data\SolSuite
2008-11-23 19:05 --------- d-----w c:\documents and settings\LE DU\Application Data\FireShot
2008-11-23 10:46 --------- d-----w c:\program files\Navilog1
2008-11-22 12:01 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-11-18 13:13 --------- d-----w c:\program files\ACT
2008-11-17 17:15 --------- d-----w c:\program files\adslTV
2008-11-14 08:03 --------- d-----w c:\program files\CCleaner
2008-11-09 11:50 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-05 17:07 --------- d-----w c:\program files\IcoFX 1.6
2008-11-05 17:01 --------- d-----w c:\program files\Webshots
2008-10-31 10:21 --------- d-----w c:\program files\eMule
2008-10-27 13:23 --------- d-----w c:\program files\Siber Systems
2008-10-27 10:11 --------- d-----w c:\program files\Microsoft Baseline Security Analyzer 2
2008-10-25 04:34 --------- d-----w c:\documents and settings\All Users\Application Data\BOC425
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 11:20 --------- d-----w c:\program files\Windows Live Safety Center
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-22 15:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-18 09:33 --------- d-sh--w c:\documents and settings\All Users\Application Data\System Restore
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-15 17:37 --------- d-----w c:\documents and settings\LE DU\Application Data\Malwarebytes
2008-10-15 17:36 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-20 10:29 2,788,800 ----a-w c:\program files\FLV PlayerFCSetup.exe
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2006-01-16 19:14 774,144 ----a-w c:\program files\RngInterstitial.dll
2005-04-09 18:48 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2004-03-11 11:27 40,960 ----a-w c:\program files\Uninstall_CDS.exe
2006-02-27 12:49 32 --sha-w c:\windows\{1760F6D2-270B-4EA5-B842-41AFD2C4A4F7}.dat
2006-02-27 13:12 32 --sha-w c:\windows\{26253970-64A8-404F-B541-C25DEBAC33DF}.dat
2006-02-27 12:35 32 --sha-w c:\windows\{329A798E-A90A-4822-A106-76DFBBACF00A}.dat
2006-02-27 12:35 32 --sha-w c:\windows\{3505FDD5-5767-4FAA-94B2-479D11AA501F}.dat
2006-02-27 13:10 32 --sha-w c:\windows\{361FB0D9-0157-4584-AD1D-46A8CCA1EA7C}.dat
2006-02-27 12:35 32 --sha-w c:\windows\{4A2BDF17-B472-4DD4-B85F-510593335386}.dat
2006-02-27 12:37 32 --sha-w c:\windows\{956E86B6-A4D3-4690-8CB1-FD997AF7C376}.dat
2006-02-27 12:06 32 --sha-w c:\windows\{AAE1FE52-8AEF-4164-8E14-241801849D53}.dat
2007-11-25 15:57 23 --sha-w c:\windows\system32\acb1_r.dll
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2007-12-17 13:43 27,648 --sh--w c:\windows\system32\Smab0.dll
2006-02-27 12:49 32 --sha-w c:\windows\system32\{1DF35C2D-8C75-4865-B7AD-17BAA9A1EF84}.dat
2006-02-27 12:37 32 --sha-w c:\windows\system32\{26DFE11E-0D7D-430B-BAE1-C4F738FC9570}.dat
2006-02-27 12:35 32 --sha-w c:\windows\system32\{3BA5F819-CFFB-4780-8039-1689AC057784}.dat
2006-02-27 13:10 32 --sha-w c:\windows\system32\{55A5E8DD-46EA-4BEB-A8AC-ECCF688E0EEC}.dat
2006-02-27 12:06 32 --sha-w c:\windows\system32\{8DF40D66-42E1-480D-A4FB-D3F2C9C321D6}.dat
2006-02-27 12:35 32 --sha-w c:\windows\system32\{BE2CC24B-AEDE-4AB7-81D0-B676F6B41656}.dat
2006-02-27 13:12 32 --sha-w c:\windows\system32\{D990B6F7-95E6-499C-9E9C-208716504839}.dat
2006-02-27 12:35 32 --sha-w c:\windows\system32\{E7AE4D3D-7282-4102-839C-EDFC0AA4B9DF}.dat
2008-07-11 18:22 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008071120080712\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-10-27 160592]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-24 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-27 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"PromptOnSecureDesktop"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.enc"= ITIG726.acm
"wave2"= orbvcumd.dll
"mixer2"= orbvcumd.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Manager.lnk]
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDAS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Piratrax
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 16:05 81920 c:\program files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gigaget]
--a------ 2006-02-07 09:28 495616 c:\program files\Giganology\Gigaget\GigagetShell.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-03-23 16:06 1398272 c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 13:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 14:24 458752 c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 14:14 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
--a------ 2004-05-21 19:11 221184 c:\windows\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2008-04-13 18:34 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 14:40 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 00:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
--a------ 2007-05-23 13:03 8631840 c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
--a------ 2008-04-02 08:50 1424648 c:\program files\Uniblue\SpyEraser\SpyEraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 18:20 866584 c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
--------- 2003-12-11 09:50 20992 c:\windows\LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"vspdfprsrv.exe"=c:\program files\Visagesoft\eXPert PDF\vspdfprsrv.exe --background
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Downloads\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XIIc\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XIIc\\RpcSandraSrv.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 OrbVirtualCable;Orb Virtual Cable;c:\windows\system32\drivers\orbvckmd.sys [2006-03-17 14336]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2006-10-10 5632]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2007-02-27 51440]
R2 Machnm32;Machnm32 Driver;\??\c:\windows\System32\Machnm32.sys [2007-11-19 2304]
R3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);c:\windows\system32\DRIVERS\CamDrL20.sys [2005-10-30 245760]
R3 SbieDrv;SbieDrv;\??\c:\program files\Sandboxie\SbieDrv.sys [2008-11-15 102912]
S1 GhPciScan;GhostPciScanner; []
S3 cpuz129;cpuz129; []
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2006-02-16 4096]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-12-12 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 23:10]
2008-12-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2008-12-11 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-05-23 13:03]
2008-04-05 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2007-05-23 13:03]
2008-04-10 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-04-02 08:50]
2008-12-14 c:\windows\Tasks\User_Feed_Synchronization-{E4B01ED1-77C2-4AB9-AD58-DCD8F343F367}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:58]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
MSConfigStartUp-Uniblue RegistryBooster2 - c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.webshots.com/r/internal/start/client/RAND
mStart Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_dp_id=18&x_format=redirect
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local;*.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
- c:\program files\Yahoo!\Common\yinsthelper.dll
c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe
c:\windows\BDOSCAN8\bdcore.dll
c:\windows\BDOSCAN8\libfn.dll
c:\windows\BDOSCAN8\bdupd.dll
c:\windows\BDOSCAN8\ipsupd.dll
c:\windows\BDOSCAN8\lang.ini
c:\windows\BDOSCAN8\scanoptions.tsi
c:\windows\BDOSCAN8\live.ini
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
c:\windows\Downloaded Program Files\oscan8.inf
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://charon777.free.fr/plugins/hardwaredetection_2_0_4_12.cab
FF - ProfilePath - c:\documents and settings\LE DU\Application Data\Mozilla\Firefox\Profiles\x0qp5rvb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.leboncoin.fr
FF - plugin: c:\documents and settings\LE DU\Application Data\Mozilla\Firefox\Profiles\x0qp5rvb.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-14 15:12:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\orbvcumd.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WRLogonNTF.dll
- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\orbvcumd.dll
.
Completion time: 2008-12-14 15:17:41
ComboFix-quarantined-files.txt 2008-12-14 14:17:08
Pre-Run: 5ÿ889ÿ228ÿ800 octets libres
Post-Run: 5,877,788,672 octets libres
332 --- E O F --- 2008-12-11 10:40:26