fichier effacé
combofix lancé, impossible d'arreter les anti-virus NOD32 et Norton, je ne sais pas comment faire!!
rapport combofix tout de meme :
ComboFix 09-01-21.04 - Arnaud 2009-01-29 18:46:54.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1023.512 [GMT 4:00]
Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)
AV: Norton 360 *On-access scanning enabled* (Updated)
FW: Norton 360 *enabled*
* Un nouveau point de restauration a été créé
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Arnaud\Application Data\drivers\downld
c:\program files\DAEMON Tools\daemon.exe
c:\windows\system32\antiwpa.dll
c:\windows\system32\Cache
c:\windows\system32\OGACheckControl.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-29 ))))))))))))))))))))))))))))))))))))
.
2009-01-29 17:29 . 2009-01-29 18:48 <REP> d--h----- c:\documents and settings\Arnaud\Application Data\drivers
2009-01-29 11:33 . 2009-01-29 11:33 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-29 11:33 . 2009-01-29 11:33 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-29 08:41 . 2009-01-29 17:40 <REP> d-------- c:\program files\FindyKill
2009-01-29 08:32 . 2009-01-29 08:32 <REP> d-------- c:\program files\CCleaner
2009-01-28 21:51 . 2009-01-28 21:51 <REP> d-------- c:\program files\Lavasoft
2009-01-28 21:46 . 2009-01-28 21:46 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-28 21:03 . 2009-01-28 21:03 1,079,808 --a------ c:\windows\system32\mfc80u.dll
2009-01-28 21:02 . 2009-01-28 21:02 1,093,632 --a------ c:\windows\system32\mfc80.dll
2009-01-28 18:14 . 2009-01-28 18:14 <REP> d-------- C:\N360_BACKUP
2009-01-28 17:57 . 2009-01-28 18:46 <REP> d-------- c:\program files\Norton 360
2009-01-28 17:56 . 2009-01-28 18:00 48,776 --a------ c:\windows\system32\S32EVNT1.DLL
2009-01-28 17:56 . 2009-01-28 18:00 8,014 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-28 17:56 . 2009-01-28 18:00 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-01-28 17:55 . 2009-01-28 18:00 <REP> d-------- c:\program files\Symantec
2009-01-28 17:54 . 2009-01-28 19:22 <REP> d-------- c:\program files\Fichiers communs\Symantec Shared
2009-01-19 10:52 . 2009-01-19 10:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Nokia
2009-01-19 10:52 . 2008-02-01 15:17 138,112 --a------ c:\windows\system32\drivers\nmwcdnsu.sys
2009-01-19 10:52 . 2008-02-01 15:17 8,320 --a------ c:\windows\system32\drivers\nmwcdnsuc.sys
2009-01-18 21:19 . 2009-01-18 21:26 664 --a------ c:\windows\system32\d3d9caps.dat
2009-01-18 18:06 . 2009-01-18 18:07 8 --a------ c:\windows\system32\nvModes.dat
2009-01-18 14:12 . 2009-01-18 14:12 <REP> d-------- c:\documents and settings\Arnaud\Application Data\REALVIZ
2009-01-18 14:12 . 2009-01-18 14:12 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-18 14:12 . 2009-01-18 14:12 1,409 --a------ c:\windows\QTFont.for
2009-01-18 14:11 . 2009-01-18 14:11 <REP> d-------- c:\program files\REALVIZ
2009-01-17 19:24 . 2009-01-17 19:24 <REP> d-------- c:\windows\ASTULogTemp
2009-01-17 19:24 . 2009-01-17 19:24 88,574 --a------ c:\windows\system32\ASTULog.cab
2009-01-17 19:24 . 2009-01-17 19:24 1,051 --a------ c:\windows\system32\setup.inf
2009-01-17 19:24 . 2009-01-17 19:24 283 --a------ c:\windows\system32\setup.rpt
2009-01-15 20:19 . 2009-01-15 20:19 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Apple Computer
2009-01-15 17:27 . 2009-01-27 21:27 <REP> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-01-11 14:19 . 2009-01-11 14:19 <REP> d-------- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate
2009-01-11 14:17 . 2009-01-11 14:17 <REP> d-------- c:\program files\Fichiers communs\Yahoo!
2009-01-11 14:17 . 2009-01-11 14:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Studio 12
2009-01-11 14:17 . 2009-01-11 14:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2009-01-10 17:24 . 2009-01-20 21:11 98,304 --a------ c:\windows\DUMP4baf.tmp
2009-01-10 17:24 . 2009-01-20 21:21 98,304 --a------ c:\windows\DUMP4a76.tmp
2009-01-09 19:33 . 2009-01-11 14:17 <REP> d-------- c:\program files\Pinnacle
2009-01-09 19:08 . 2009-01-09 19:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\DivX
2009-01-08 16:22 . 2009-01-08 16:22 <REP> d-------- c:\windows\system32\QuickTime
2009-01-08 16:22 . 2009-01-09 19:05 <REP> d-------- c:\windows\system32\custom matrices
2009-01-08 16:22 . 2009-01-11 14:13 <REP> d-------- c:\windows\system32\C2MP
2009-01-08 16:22 . 2004-05-25 19:06 417,792 --a------ c:\windows\system32\ac3filter.cpl
2009-01-08 15:36 . 2009-01-08 15:36 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Ahead
2009-01-08 15:28 . 2009-01-28 16:53 116 --a------ c:\windows\NeroDigital.ini
2009-01-06 12:17 . 2009-01-22 15:18 <REP> d-------- c:\documents and settings\Arnaud\Application Data\AdobeUM
2009-01-05 19:51 . 2009-01-05 19:51 1,409 --a------ c:\windows\system32\tmpE2678.FOT
2009-01-05 19:51 . 2009-01-05 19:51 1,409 --a------ c:\windows\system32\tmpB0768.FOT
2009-01-05 19:30 . 2009-01-05 19:30 <REP> d-------- c:\program files\QuickTime
2009-01-05 19:30 . 2009-01-05 19:30 <REP> d-------- c:\program files\Apple Software Update
2009-01-05 19:30 . 2009-01-05 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-05 19:28 . 2009-01-05 19:28 <REP> d-------- c:\program files\Mindscape
2009-01-05 19:28 . 2009-01-05 19:38 49 --a------ c:\windows\tlc-fra.INI
2009-01-05 08:34 . 2004-03-02 17:37 125,184 --------- c:\windows\system32\drivers\imagesrv.sys
2009-01-05 08:34 . 2004-03-02 17:37 5,504 --------- c:\windows\system32\drivers\imagedrv.sys
2009-01-05 08:33 . 2009-01-05 08:33 <REP> d-------- c:\program files\Fichiers communs\Ahead
2009-01-05 08:33 . 2009-01-05 08:33 <REP> d-------- c:\program files\Ahead
2009-01-05 08:33 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2009-01-05 08:33 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
2009-01-05 08:33 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
2009-01-05 08:33 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
2009-01-05 08:33 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2009-01-05 08:33 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2009-01-05 08:27 . 2008-04-13 22:45 26,112 --a------ c:\windows\system32\drivers\usbser.sys
2009-01-05 08:27 . 2008-04-13 22:45 26,112 --a--c--- c:\windows\system32\dllcache\usbser.sys
2009-01-05 08:27 . 2008-03-21 14:57 14,640 --------- c:\windows\system32\spmsgXP_2k3.dll
2009-01-05 08:27 . 2009-01-05 08:27 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-01-05 08:27 . 2009-01-05 08:27 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-01-05 08:00 . 2009-01-18 12:46 <REP> d-------- c:\program files\Microsoft ActiveSync
2009-01-05 07:38 . 2009-01-05 07:38 <REP> d-------- c:\documents and settings\Arnaud\.java
2009-01-04 23:52 . 2009-01-05 06:31 <REP> d-------- c:\program files\NOS
2009-01-04 23:52 . 2009-01-05 06:41 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-01-04 23:27 . 2009-01-28 18:07 266 --a------ c:\windows\Predictor.ini
2009-01-04 23:27 . 2009-01-28 18:07 52 --a------ c:\windows\MaxSea¨ Param
2009-01-04 23:27 . 2009-01-28 18:07 40 --a------ c:\windows\CMapConfig.ini
2009-01-04 23:27 . 2009-01-28 18:07 33 --a------ c:\windows\SeaDriver.ini
2009-01-04 23:17 . 2009-01-04 23:17 <REP> d-------- c:\windows\MaxSea
2009-01-04 23:17 . 2009-01-28 18:07 29,600 --a------ c:\windows\SeaConfig
2009-01-04 23:17 . 2009-01-28 18:07 3,085 --a------ c:\windows\SeaConfig.rsr
2009-01-04 23:17 . 2009-01-04 23:17 2,487 --a------ c:\windows\SeaDriver2000.ini
2009-01-04 23:17 . 2009-01-28 18:07 1,612 --a------ c:\windows\SeaPref
2009-01-04 23:17 . 2009-01-04 23:27 827 --a------ c:\windows\SeaPref.rsr
2009-01-04 23:17 . 2009-01-15 19:51 544 --a------ c:\windows\SeaWay
2009-01-04 23:17 . 2009-01-04 23:24 512 --a------ c:\windows\SeaSimul
2009-01-04 23:17 . 2009-01-28 18:07 512 --a------ c:\windows\MaxSea¨_PosreportFile
2009-01-04 23:13 . 2009-01-04 23:13 1,680 --a------ c:\windows\system32\esnecil.nlp
2009-01-04 23:13 . 2009-01-04 23:15 1,680 --a------ c:\windows\system32\esnecil.ind
2009-01-04 23:09 . 2009-01-04 23:09 <REP> d-------- c:\program files\SentEmul
2009-01-04 23:09 . 2003-03-24 19:06 11,812 --a------ c:\windows\system32\drivers\SentEmul.sys
2009-01-04 23:08 . 2009-01-04 23:08 <REP> d-------- c:\program files\JavaSoft
2009-01-04 23:08 . 2001-11-26 23:24 45,148 --a------ c:\windows\system32\plugincpl131_02.cpl
2009-01-04 23:07 . 2009-01-04 23:07 <REP> d-------- c:\program files\C-Map
2009-01-04 23:07 . 2002-04-16 22:29 192,512 --a------ c:\windows\system32\CMGBase.dll
2009-01-04 23:07 . 1999-06-19 00:49 165,888 --a------ c:\windows\Ckconfig.exe
2009-01-04 23:07 . 2000-06-29 12:45 52,224 --a------ c:\windows\system32\Crypserv.exe
2009-01-04 23:07 . 2000-02-03 23:53 24,608 --a------ c:\windows\system32\Ckldrv.sys
2009-01-04 23:07 . 2002-07-26 17:07 20,000 --------- c:\windows\system32\drivers\cmapusb.sys
2009-01-04 23:07 . 2002-07-29 11:44 18,013 --------- c:\windows\system32\drivers\cmap_pc2.sys
2009-01-04 23:07 . 2002-07-26 13:59 16,088 --------- c:\windows\system32\drivers\cmapldr.sys
2009-01-04 23:07 . 2009-01-28 18:09 2,807 --a------ c:\windows\Maxsea.ini
2009-01-04 23:07 . 2009-01-04 23:07 44 --a------ c:\windows\Crypkey.ini
2009-01-04 23:06 . 2009-01-04 23:06 <REP> d-------- c:\windows\system32\RNBOSENT
2009-01-04 23:06 . 2009-01-04 23:06 <REP> d-------- c:\windows\Drivers
2009-01-04 23:06 . 2009-01-04 23:06 <REP> d-------- c:\program files\I&M
2009-01-04 23:06 . 2005-05-31 06:30 76,288 --------- c:\windows\system32\drivers\SENTINEL.SYS
2009-01-04 23:06 . 2005-05-31 06:30 50,176 --a------ c:\windows\system32\SNTI386.DLL
2009-01-04 23:06 . 1996-05-03 20:21 27,648 -ra------ c:\windows\Setup_ck.exe
2009-01-04 23:06 . 2005-05-31 06:30 26,120 --a------ c:\windows\system32\drivers\SNTNLUSB.SYS
2009-01-04 23:06 . 2005-05-31 06:30 18,432 --a------ c:\windows\system32\RNBOVDD.DLL
2009-01-04 23:06 . 1996-05-03 18:36 18,432 --a------ c:\windows\Setup_ck.dll
2009-01-04 23:06 . 1995-07-04 21:33 11,776 --a------ c:\windows\Ckrfresh.exe
2009-01-04 23:06 . 2005-05-31 06:30 9,949 --------- c:\windows\system32\SENTINEL.HLP
2009-01-04 22:51 . 2005-06-28 23:24 <REP> d-------- C:\CM93
2009-01-04 21:36 . 2009-01-06 10:24 351 --a------ c:\windows\system\cmicnfg.ini
2009-01-04 21:35 . 2009-01-04 21:35 1,188 --a------ c:\windows\ImpTableL.bin
2009-01-04 18:40 . 2008-04-13 22:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-01-04 18:40 . 2008-04-13 22:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2009-01-04 15:58 . 2009-01-04 15:58 <REP> d-------- c:\program files\Fichiers communs\Adobe Systems Shared
2009-01-04 15:58 . 2009-01-04 15:58 <REP> d-------- c:\documents and settings\All Users\Application Data\Adobe Systems
2009-01-04 15:57 . 2009-01-06 12:14 <REP> d-------- c:\program files\Fichiers communs\Adobe
2009-01-04 15:39 . 2009-01-04 15:39 <REP> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-04 15:18 . 2009-01-04 15:18 <REP> d-------- c:\windows\system32\fr
2009-01-04 15:18 . 2009-01-04 15:18 <REP> d-------- c:\windows\system32\bits
2009-01-04 15:18 . 2009-01-04 15:18 <REP> d-------- c:\windows\l2schemas
2009-01-04 14:41 . 2009-01-04 19:07 <REP> d-------- c:\windows\system32\XPSViewer
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 19:08 685,816 ----a-w c:\windows\system32\drivers\sptd.sys
2009-01-03 18:05 512,096 ----a-w c:\windows\system32\drivers\amon.sys
2009-01-03 18:05 15,424 ----a-w c:\windows\system32\drivers\nod32drv.sys
2009-01-03 17:54 --------- d-----w c:\program files\microsoft frontpage
2009-01-03 17:51 --------- d-----w c:\program files\Services en ligne
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"PMCRemote"="c:\program files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2007-04-24 253000]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
"PMCLoader"="c:\program files\Pinnacle\TVCenter Pro\PMCLoader.exe" [2007-05-30 105544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-01-29 950664]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2009-01-29 115816]
"nwiz"="nwiz.exe" [2008-09-18 c:\windows\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Arnaud\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe [2009-01-06 25214]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-04 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 c:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv32"= ir32.dll
"SENTINEL"= snti386.dll
"vidc.DIV3"= divxc32.dll
"vidc.DIV4"= divxc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"vidc.davc"= davcvfw.dll
"vidc.hfyu"= huffyuv.dll
"vidc.IV45"= Ir41_qc.dll
"msacm.divxa32"= DivXa32.acm
"msacm.l3codec"= l3codecp.acm
"msacm.ac3filter"= ac3filter.acm
"vidc.mjpg"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\I&M\\MaxSea\\MaxSea.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2008-12-29 17064]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-01-03 15424]
R3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;c:\windows\system32\drivers\3xHybrid.sys [2009-01-03 1121536]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2005-05-12 1287296]
R4 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-01-04 10384]
R4 sentemul;sentemul;c:\windows\system32\drivers\SentEmul.sys [2009-01-04 11812]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
.
Contenu du dossier 'Tâches planifiées'
2009-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 16:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.kartoo.com/
IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\System32\imon.dll
FF - ProfilePath - c:\documents and settings\Arnaud\Application Data\Mozilla\Firefox\Profiles\yz6hih0d.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.kartoo.com/
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1439.6872\npCIDetect13.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_02\bin\NPJava11.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_02\bin\NPJava12.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_02\bin\NPJava131_02.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_02\bin\NPJava32.dll
FF - plugin: c:\program files\JavaSoft\JRE\1.3.1_02\bin\NPOJI600.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava11.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava12.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava131_02.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJava32.dll
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-29 18:50:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,32,49,97,a7,be,
f6,e8,24,c8,28,51,af,b0,29,a3,98,e0,24,42,61,ef,6a,5d,57,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,61,a1,1d,52,05,
80,22,04,71,3b,04,66,8b,46,0d,96,3b,b5,32,3c,51,33,12,02,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,80,3a,15,75,9a,
01,2b,4e,25,da,ec,7e,55,20,c9,26,46,71,1d,f3,69,57,c9,03,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,ca,6b,cd,1a,e6,
e4,26,05,3e,1e,9e,e0,57,5a,93,61,2a,4c,47,6c,5a,57,a8,7a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,13,30,92,d6,6b,
12,8a,10,cd,44,cd,b9,a6,33,6c,cd,8a,b2,dd,3c,ea,29,53,03,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,c8,87,2f,2b,01,
ee,aa,42,b0,18,ed,a7,3f,8d,37,a4,51,20,08,48,e2,bb,ed,1f,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,cf,77,10,fc,a6,
a7,27,86,31,77,e1,ba,b1,f8,68,02,83,4f,9e,b8,53,61,92,b0,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,3b,10,2c,ec,84,
8b,8e,73,83,6c,56,8b,a0,85,96,ab,55,00,a9,88,32,58,b1,4c,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,e4,2c,d7,1b,34,
53,0d,3b,51,fa,6e,91,28,9e,14,cc,25,48,bb,33,04,27,e4,1a,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,75,72,9d,de,cc,
a7,14,75,b1,cd,45,5a,a8,c4,f8,b9,e1,83,b7,4e,e8,dd,f2,8a,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,6c,d9,0c,32,6f,
1c,7f,18,e3,0e,66,d5,eb,bc,2f,6b,bd,51,d2,8c,01,89,8c,89,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,5d,b3,df,9e,9d,
8d,66,e3,fa,ea,66,7f,d4,3b,6b,70,c7,ce,2c,32,da,67,ee,fb,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
"OOBETimer"="reset"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(716)
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'lsass.exe'(772)
c:\windows\System32\imon.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\ATKKBService.exe
c:\windows\system32\Crypserv.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\tcpsvcs.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Heure de fin: 2009-01-29 18:53:46 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-29 14:53:43
Avant-CF: 343 740 305 408 octets libres
Après-CF: 343,622,098,944 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[Boot Loader]
Timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
Current=9 Default=9 Failed=8 LastKnownGood=10 Sets=1,2,3,4,5,6,7,8,9,10
387 --- E O F --- 2009-01-14 15:45:16