Voila le résultat de Combofix :
ComboFix 08-12-23.01 - Utilisateur 2008-12-24 11:13:48.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.502.149 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
Les fichiers ci-dessous ont été désactivés pendant l'exécution:
c:\windows\system32\famujize.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\admintxt.txt
c:\windows\service.exe
c:\windows\system32\adasolug.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\iiffFWNg.dll
c:\windows\system32\NUFPYcdd.ini
c:\windows\system32\NUFPYcdd.ini2
c:\windows\system32\okariroz.ini
c:\windows\system32\rciaudlb.ini
c:\windows\system32\ritgwoyt.ini
c:\windows\system32\ugabugeh.ini
c:\windows\system32\wvUnKCrP.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-24 au 2008-12-24 ))))))))))))))))))))))))))))))))))))
.
2008-12-24 11:22 . 2008-12-24 11:22 120 ---hs---- c:\windows\system32\ugabugeh.ini
2008-12-24 11:05 . 2008-12-24 11:06 <REP> d-------- C:\32788R22FWJFW
2008-12-23 18:46 . 2008-12-23 18:46 <REP> d-------- C:\VundoFix Backups
2008-12-23 11:17 . 2008-12-23 11:17 <REP> d-------- c:\program files\Avira
2008-12-23 11:17 . 2008-12-23 11:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-22 22:46 . 2008-12-23 11:01 <REP> d-------- c:\documents and settings\Utilisateur\Tracing
2008-12-22 22:45 . 2008-12-22 22:45 <REP> d-------- c:\program files\Microsoft Silverlight
2008-12-22 22:44 . 2008-12-08 17:01 55,136 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys
2008-12-22 22:42 . 2008-12-22 22:42 <REP> d-------- c:\program files\Microsoft Sync Framework
2008-12-22 22:35 . 2008-12-22 22:44 <REP> d-------- c:\program files\Microsoft
2008-12-22 22:34 . 2008-12-22 22:34 <REP> d-------- c:\program files\Windows Live SkyDrive
2008-12-22 22:24 . 2008-12-22 22:24 <REP> d-------- c:\program files\Fichiers communs\Windows Live
2008-12-21 19:22 . 2008-12-21 19:22 69,654 --a------ c:\windows\webupdat.exe
2008-12-12 15:46 . 2008-12-12 15:46 0 --a------ c:\windows\TPTray.INI
2008-12-09 18:15 . 2008-12-09 18:15 385 --a------ c:\windows\ODBC.INI
2008-12-09 14:07 . 2008-12-10 08:44 <REP> d-------- c:\program files\DAEMON Tools Lite
2008-12-05 00:11 . 2008-12-05 00:11 308,584 --a------ c:\windows\WLXPGSS.SCR
2008-12-02 22:37 . 2008-12-02 22:37 49,480 --a------ c:\windows\system32\sirenacm.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 09:41 97,879 ----a-w c:\windows\system32\famujize.dll
2008-12-24 09:41 84,694 --sha-w c:\windows\system32\hegubagu.dll
2008-12-24 09:41 63,788 --sha-w c:\windows\system32\zizesabo.dll
2008-12-22 21:44 --------- d-----w c:\program files\Windows Live
2008-12-22 21:42 --------- d-----w c:\program files\Windows Live Toolbar
2008-12-14 01:15 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-12 17:53 --------- d-----w c:\documents and settings\Utilisateur\Application Data\gtk-2.0
2008-12-09 13:07 --------- d-----w c:\documents and settings\Utilisateur\Application Data\DAEMON Tools
2008-12-02 19:55 --------- d-----w c:\program files\BitComet
2008-11-23 11:47 410,976 ----a-w c:\windows\system32\deploytk.dll
2008-11-23 11:47 --------- d-----w c:\program files\Java
2008-11-13 18:37 1,603,955 ----a-w C:\mIRC.zip
2008-11-01 18:52 --------- d-----w c:\program files\CCleaner
2008-10-30 12:03 --------- d-----w c:\documents and settings\Utilisateur\Application Data\InfraRecorder
2008-10-30 11:42 --------- d-----w c:\program files\InfraRecorder
2008-10-30 11:41 3,431,285 ----a-w C:\ir045_unicode.exe
2008-10-28 12:38 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-24 09:42 63,788 --sha-w c:\windows\system32\sebodume.dll
2008-09-24 09:42 63,788 --sha-w c:\windows\system32\nobibipo.dll
2006-12-12 09:13 32,768 -c--a-w c:\documents and settings\All Users\Application Data\EBLib.dll
2006-07-28 14:25 19,456 -c--a-w c:\documents and settings\All Users\Application Data\LPCFilter.sys
2008-06-06 20:16 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-06-06 20:16 54,376 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-06-06 20:16 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-06-06 20:16 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-06-06 20:16 172,144 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-22 21:05 62,749 --sha-w c:\windows\system32\giwabamo.dll
2008-09-07 08:56 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090720080908\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7f2bae99-3e1d-4fe5-b560-de659f63dce1}]
2008-09-24 10:42 63788 --ahs---- c:\windows\system32\sebodume.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2007-10-08 6338872]
"SweetIM"="c:\program files\Macrogaming\SweetIM\SweetIM.exe" [2007-08-12 103712]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2007-12-15 482760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2006-04-12 638976]
"HWSetup"="c:\program files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-05-01 28672]
"SVPWUTIL"="c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2006-05-25 65536]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2007-06-01 53248]
"SmoothView"="c:\program files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2007-05-11 143360]
"DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-26 495616]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-05-22 413696]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-08-05 185896]
"Startup"="c:\windows\startup.vbs" [2006-08-01 1032]
"SgeEcView"="c:\program files\Utimaco\SafeGuard Easy\Ecview.exe" [2005-06-08 24576]
"EdWizard"="c:\program files\Utimaco\SafeGuard Easy\EdWizard.exe" [2005-06-08 245760]
"UERLKUP"="c:\program files\Utimaco\SafeGuard Easy\uerlkupn.exe" [2006-03-29 36864]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"SweetIM"="c:\program files\Macrogaming\SweetIM\SweetIM.exe" [2007-08-12 103712]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-23 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 271360]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"CPM27346dd9"="c:\windows\system32\famujize.dll" [2008-12-24 97879]
"24075e45"="c:\windows\system32\hegubagu.dll" [2008-12-24 84694]
"sujevamino"="c:\windows\system32\nobibipo.dll" [2008-09-24 63788]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2007-06-30 c:\windows\system32\TCtrlIOHook.exe]
"TDispVol"="TDispVol.exe" [2005-12-27 c:\windows\system32\TDispVol.exe]
"TPSMain"="TPSMain.exe" [2005-08-12 c:\windows\system32\TPSMain.exe]
"Zooming"="ZoomingHook.exe" [2005-06-06 c:\windows\system32\ZoomingHook.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
"CFSServ.exe"="CFSServ.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Utilisateur\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-22 143360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage rapide du logiciel HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\famujize.dll" [2008-12-24 97879]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\famujize.dll [2008-12-24 97879]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NotLog]
2002-01-22 14:28 110592 c:\windows\system32\SGLogEx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SGLogNotification]
2005-03-31 10:27 69632 c:\windows\system32\SGLogNotification.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uerclt]
2006-03-29 13:14 77824 c:\windows\system32\uercltn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\famujize.dll,c:\windows\system32\nunupofa.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\nunupofa.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Satsuki Decoder Pack\\filtres\\ac3config.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Mes documents\\eMule\\LinkCreator.exe"=
"e:\\Mes documents\\eMule\\emule.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Product Assistant\\bin\\hprbui.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe"=
"c:\\ComboFix\\fdsv.cfexe"=
"c:\\WINDOWS\\system32\\TPSMain.exe"=
"c:\\WINDOWS\\explorer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11254:TCP"= 11254:TCP:BitComet 11254 TCP
"11254:UDP"= 11254:UDP:BitComet 11254 UDP
"127:TCP"= 127:TCP:eMule : TCP Entrant
R0 AES-256;AES-256;c:\windows\system32\DRIVERS\AES256.SYS [2005-06-08 17952]
R0 SgeFlt;SgeFlt;c:\windows\system32\DRIVERS\SGEFLT.SYS [2005-06-08 54880]
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2008-12-22 55136]
R2 SeaPort;SeaPort;"c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" [2008-12-04 226640]
R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\DRIVERS\tdudf.sys [2007-03-26 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\DRIVERS\trudf.sys [2007-02-19 134016]
R3 uscbs109;uscbs109;c:\windows\system32\DRIVERS\uscbs109.sys [2005-03-22 8672]
R3 uscsc109;uscsc109;c:\windows\system32\DRIVERS\uscsc109.sys [2005-03-22 102336]
S3 fsssvc;Windows Live Contrôle parental;"c:\program files\Windows Live\Family Safety\fsssvc.exe" [2008-12-08 533344]
S3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{684f94ee-c60b-11dd-b200-001b383e82a6}]
\Shell\Auto\command - G:\bittorrent.exe e
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd7748ac-2f1b-11dd-b0ec-001b383e82a6}]
\Shell\AutoRun\command - g:\wd_windows_tools\WDSetup.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-24 c:\windows\Tasks\pbokrkxb.job
- c:\windows\system32\rundll32.exe [2008-04-14 03:34]
2007-08-03 c:\windows\Tasks\Rappel d'enregistrement 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-04-14 03:34]
2007-08-17 c:\windows\Tasks\Rappel d'enregistrement 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-04-14 03:34]
2007-08-03 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-04-14 03:34]
2008-12-23 c:\windows\Tasks\WebReg Photosmart C4380 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-03-11 20:27]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{15030399-1b95-4ca0-9b4b-05f8ed7da41a} - c:\windows\system32\xsufjt.dll
BHO-{4959F1EC-3A19-45AD-9495-76DA91A025BE} - c:\windows\system32\ddcYPFUN.dll
ShellIconOverlayIdentifiers-{ba930330-a721-11d3-a7b9-00500464ee16} - Sgedrse.Dll
ShellIconOverlayIdentifiers-{2030D939-54A7-4fea-9B06-49EA77EFC87F} - Sgedrse.Dll
HKCU-Run-TVAgent WiFi - c:\program files\Kit ADSL\Wizard\Agent_WiFi.exe
MSConfigStartUp-TFncKy - TFncKy.exe
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) =
hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Utilisateur\Application Data\Mozilla\Firefox\Profiles\73eieb4s.default\
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage -
hxxp://fr.msn.com/
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA2&q=
FF - prefs.js: browser.startup.homepage -
hxxp://fr.msn.com/
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA2&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-24 11:21:51
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\windows\system32\ugabugeh.ini 120 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(960)
c:\windows\system32\SGLogEx.dll
c:\windows\system32\SGLogNotification.dll
c:\windows\system32\uercltn.dll
c:\windows\system32\USWERRLN.dll
c:\windows\system32\uerlibws.dll
c:\windows\system32\GetUserSid.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Utimaco\SafeGuard Easy\SgeCtl.exe
c:\windows\system32\SgLogPlayer.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
c:\program files\Toshiba\ConfigFree\NDSTray.exe
c:\windows\system32\TPSBattM.exe
c:\program files\Toshiba\TOSHIBA Direct Disc Writer\DDWMon.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\Toshiba\ConfigFree\CFSServ.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\documents and settings\Utilisateur\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2008-12-24 11:29:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-24 10:29:50
Avant-CF: 6 527 737 856 octets libres
Après-CF: 6,613,835,776 octets libres
313 --- E O F --- 2008-12-18 22:17:00