Voici les résultats :
ComboFix 08-12-31.01 - Mikael 2009-01-01 21:31:59.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2047.1544 [GMT 1:00]
Lancé depuis: c:\documents and settings\Mikael\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
D:\Autorun.inf
D:\resycled
d:\resycled\boot.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-01 au 2009-01-01 ))))))))))))))))))))))))))))))))))))
.
2009-01-01 19:28 . 2009-01-01 21:26 <REP> d-------- c:\program files\Wallpaper
2009-01-01 18:24 . 2009-01-01 18:24 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-01 18:24 . 2009-01-01 18:24 <REP> d-------- c:\documents and settings\Mikael\Application Data\Malwarebytes
2009-01-01 18:24 . 2009-01-01 18:24 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-01 18:24 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-01 18:24 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-01 18:02 . 2009-01-01 18:09 <REP> d-------- c:\program files\Navilog1
2009-01-01 16:47 . 2009-01-01 16:47 <REP> d-------- c:\program files\CCleaner
2009-01-01 12:14 . 2009-01-01 12:26 121 --a------ c:\windows\wininit.ini
2009-01-01 11:53 . 2009-01-01 21:26 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-01 11:53 . 2009-01-01 21:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-01 11:48 . 2009-01-01 11:48 <REP> d-------- c:\program files\Lavasoft
2009-01-01 11:48 . 2009-01-01 12:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-01 06:45 . 2009-01-01 19:30 <REP> d-------- c:\documents and settings\Mikael\Application Data\Wallpaper
2008-12-31 21:24 . 2005-02-08 12:12 2,670,592 --------- c:\windows\UNNMP.exe
2008-12-31 21:24 . 2005-06-07 09:40 49,655 --------- c:\windows\UNNMP.cfg
2008-12-31 21:23 . 2008-12-31 21:23 <REP> d-------- c:\program files\Fichiers communs\Ahead
2008-12-31 21:23 . 2005-04-20 11:32 2,916,352 --------- c:\windows\UNNeroVision.exe
2008-12-31 21:23 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2008-12-31 21:23 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
2008-12-31 21:23 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
2008-12-31 21:23 . 2004-07-09 09:43 364,544 --------- c:\windows\system32\TwnLib4.dll
2008-12-31 21:23 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
2008-12-31 21:23 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2008-12-31 21:23 . 2005-06-07 09:40 154,855 --------- c:\windows\UNNeroVision.cfg
2008-12-31 21:23 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-12-31 21:23 . 2001-06-26 08:15 38,912 --------- c:\windows\system32\picn20.dll
2008-12-31 15:48 . 2008-12-31 15:48 <REP> d-------- c:\program files\Hercules
2008-12-31 15:48 . 2006-09-26 14:16 347,648 --a------ c:\windows\system32\drivers\rt73.sys
2008-12-31 15:48 . 2006-04-14 12:05 162,560 --a------ c:\windows\system32\drivers\rt2500usb.sys
2008-12-31 15:48 . 2005-11-30 11:33 2,048 --a------ c:\windows\system32\drivers\rt73.bin
2008-12-30 15:40 . 2009-01-01 14:42 <REP> d-------- c:\program files\eMule
2008-12-30 00:08 . 2008-12-30 00:08 0 --a------ c:\windows\nsreg.dat
2008-12-29 09:24 . 2008-12-29 09:24 <REP> d-------- c:\documents and settings\Mikael\Application Data\.wyzo
2008-12-29 00:04 . 2008-12-29 00:04 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-29 00:04 . 2008-12-29 00:04 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-28 23:22 . 2008-12-28 23:22 <REP> d-------- c:\program files\DAEMON Tools Lite
2008-12-28 23:22 . 2008-12-28 23:22 <REP> d-------- c:\documents and settings\Mikael\Application Data\DAEMON Tools Pro
2008-12-28 23:22 . 2008-12-28 23:22 <REP> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-28 23:21 . 2008-12-28 23:22 <REP> d-------- c:\documents and settings\Mikael\Application Data\DAEMON Tools Lite
2008-12-28 19:39 . 2008-12-28 19:39 <REP> d-------- c:\documents and settings\Mikael\Application Data\Ahead
2008-12-28 18:30 . 2008-12-28 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Ahead
2008-12-28 18:30 . 2001-03-08 19:30 24,064 --------- c:\windows\system32\msxml3a.dll
2008-12-28 15:19 . 2008-12-28 15:20 1,393 --a------ c:\windows\imsins.BAK
2008-12-28 13:12 . 2008-12-28 13:12 <REP> dr-h----- c:\documents and settings\Mikael\Application Data\SecuROM
2008-12-28 09:37 . 2008-12-28 09:37 21,419 --a------ c:\windows\system32\drivers\AegisP.sys
2008-12-27 22:35 . 2008-12-27 22:35 <REP> d-------- c:\windows\Logs
2008-12-25 22:42 . 2008-12-25 22:42 <REP> d-------- c:\program files\Audacity
2008-12-25 11:44 . 2008-12-25 11:44 <REP> d-------- c:\program files\Alcohol Soft
2008-12-25 11:33 . 2008-12-25 11:33 <REP> d-------- c:\program files\DATA BECKER
2008-12-21 21:50 . 2006-04-29 14:25 40,960 --a------ c:\windows\system32\psfind.dll
2008-12-21 21:48 . 2008-12-21 21:48 <REP> d-------- c:\program files\THQ
2008-12-21 18:51 . 2008-12-21 18:51 <REP> d-------- c:\program files\Sega
2008-12-20 18:52 . 2008-12-20 18:52 <REP> d-------- c:\program files\Activision
2008-12-20 14:55 . 2008-12-20 14:55 <REP> d-------- c:\documents and settings\Mikael\Application Data\IsolatedStorage
2008-12-20 14:54 . 2008-12-20 14:54 <REP> d-------- c:\windows\system32\URTTEMP
2008-12-20 14:50 . 2008-12-20 14:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Symantec
2008-12-19 16:38 . 2008-12-19 16:38 <REP> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-12-19 16:18 . 2008-12-19 16:18 0 --a------ c:\windows\ativpsrm.bin
2008-12-19 16:14 . 2008-12-19 16:14 <REP> d-------- C:\ATI
2008-12-19 16:09 . 2008-12-21 22:22 <REP> d-------- c:\program files\filehippo.com
2008-12-19 15:12 . 2008-12-29 23:46 <REP> d-------- c:\program files\ma-config.com
2008-12-19 11:53 . 2008-12-19 11:53 <REP> d-------- c:\windows\AU_Temp
2008-12-19 11:53 . 2008-12-19 11:53 <REP> d-------- c:\windows\AU_Log
2008-12-19 11:53 . 2008-12-19 11:53 170 --a------ c:\windows\GetServer.ini
2008-12-19 11:52 . 2008-12-19 11:52 507,904 --a------ c:\windows\TMUPDATE.DLL
2008-12-19 11:52 . 2008-12-19 11:52 286,720 --a------ c:\windows\PATCH.EXE
2008-12-19 11:52 . 2008-12-19 11:52 69,689 --a------ c:\windows\UNZIP.DLL
2008-12-19 09:14 . 2008-06-14 18:59 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-19 09:14 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-19 09:14 . 2006-12-28 20:01 19,569 --a------ c:\windows\
002788_.tmp
2008-12-19 08:00 . 2008-10-16 02:01 1,499,648 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2008-12-19 08:00 . 2008-10-16 21:18 1,160,192 -----c--- c:\windows\system32\dllcache\urlmon.dll
2008-12-19 08:00 . 2008-10-16 11:23 1,056,768 -----c--- c:\windows\system32\dllcache\danim.dll
2008-12-19 08:00 . 2008-10-16 21:18 826,368 -----c--- c:\windows\system32\dllcache\wininet.dll
2008-12-19 08:00 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-19 08:00 . 2008-10-16 11:23 152,064 -----c--- c:\windows\system32\dllcache\cdfview.dll
2008-12-19 08:00 . 2008-10-16 11:23 55,808 -----c--- c:\windows\system32\dllcache\extmgr.dll
2008-12-19 08:00 . 2008-10-15 15:18 18,432 -----c--- c:\windows\system32\dllcache\iedw.exe
2008-12-19 07:59 . 2008-12-13 07:37 3,593,216 -----c--- c:\windows\system32\dllcache\mshtml.dll
2008-12-19 07:59 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-19 07:59 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-19 07:59 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-19 07:59 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-19 07:59 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-19 07:59 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-19 07:59 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-19 07:59 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-19 07:59 . 2008-05-01 15:36 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-19 07:59 . 2008-05-08 13:28 202,752 --a--c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-19 07:58 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-18 21:43 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-18 21:43 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-14 20:23 . 2008-12-14 20:35 <REP> d-------- c:\documents and settings\Mikael\Contacts
2008-12-14 17:17 . 2008-12-14 20:22 <REP> d-------- c:\program files\Windows Live
2008-12-14 17:17 . 2008-12-14 17:32 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-12-14 17:17 . 2009-01-01 08:47 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-14 16:27 . 2008-10-03 11:03 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2008-12-14 16:05 . 2008-12-14 16:06 23,723 --a------ C:\TurokGame.dmp
2008-12-14 15:20 . 2008-12-20 18:56 319 --a------ c:\windows\game.ini
2008-12-14 15:08 . 2008-12-14 15:08 <REP> d-------- c:\documents and settings\Mikael\Application Data\Ubisoft
2008-12-14 14:37 . 2008-12-14 14:37 <REP> d-------- c:\documents and settings\All Users\Application Data\Ubisoft
2008-12-14 14:35 . 2007-10-12 15:14 3,734,536 --a------ c:\windows\system32\d3dx9_36.dll
2008-12-14 14:35 . 2007-10-12 15:14 1,374,232 --a------ c:\windows\system32\D3DCompiler_36.dll
2008-12-14 14:35 . 2007-10-02 09:56 444,776 --a------ c:\windows\system32\d3dx10_36.dll
2008-12-14 14:35 . 2007-10-22 03:39 267,272 --a------ c:\windows\system32\xactengine2_10.dll
2008-12-14 14:35 . 2007-07-20 00:57 267,112 --a------ c:\windows\system32\xactengine2_9.dll
2008-12-14 12:04 . 2008-12-14 12:04 <REP> d-------- c:\program files\DIFX
2008-12-14 12:04 . 2006-07-01 22:42 43,520 --a------ c:\windows\system32\drivers\AmdK8.sys
2008-12-14 11:39 . 2008-12-14 11:39 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-12-14 00:57 . 2008-10-16 14:09 43,544 --a------ c:\windows\system32\wups2.dll
2008-12-14 00:24 . 2008-12-29 23:42 <REP> d-------- c:\program files\VS Revo Group
2008-12-13 23:51 . 2008-12-19 11:31 <REP> d-------- c:\windows\system32\fr-fr
2008-12-13 23:51 . 2008-12-19 09:27 <REP> d-------- c:\windows\system32\fr
2008-12-13 23:51 . 2008-12-19 19:03 <REP> d-------- c:\windows\system32\bits
2008-12-13 23:51 . 2008-12-19 19:03 <REP> d-------- c:\windows\l2schemas
2008-12-13 23:47 . 2006-12-28 12:01 19,569 --a------ c:\windows\
002784_.tmp
2008-12-01 21:46 . 2008-12-01 21:46 11,304,960 --a------ c:\windows\system32\atioglxx.dll
2008-12-01 21:11 . 2008-12-01 21:11 69,112 --a------ c:\windows\system32\ativvaxx.cap
2008-12-01 20:57 . 2008-12-01 20:57 48,640 --a------ c:\windows\system32\amdpcom32.dll
2008-12-01 20:53 . 2008-12-01 20:53 45,056 --a------ c:\windows\system32\amdcalrt.dll
2008-12-01 20:53 . 2008-12-01 20:53 45,056 --a------ c:\windows\system32\amdcalcl.dll
2008-12-01 20:52 . 2008-12-01 20:52 86,016 --a------ c:\windows\system32\atiadlxx.dll
2008-12-01 20:50 . 2008-12-01 20:50 3,252,224 --a------ c:\windows\system32\Amdcaldd.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 19:44 138,696 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-01-01 11:03 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-31 20:24 --------- d-----w c:\program files\Ahead
2008-12-31 14:48 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 23:05 --------- d-----w c:\documents and settings\Mikael\Application Data\LimeWire
2008-12-28 23:04 --------- d-----w c:\program files\Java
2008-12-28 22:22 --------- d-----w c:\program files\DAEMON Tools Toolbar
2008-12-28 22:22 --------- d-----w c:\documents and settings\Mikael\Application Data\DAEMON Tools
2008-12-28 17:32 --------- d-----w c:\program files\EA GAMES
2008-12-28 16:53 --------- d-----w c:\program files\AGEIA Technologies
2008-12-27 22:01 22,328 ----a-w c:\documents and settings\Mikael\Application Data\PnkBstrK.sys
2008-12-27 21:50 --------- d-----w c:\program files\Ubisoft
2008-12-21 21:36 --------- d-----w c:\program files\VirtualDJ
2008-12-20 18:19 --------- d-----w c:\program files\Electronic Arts
2008-12-19 15:35 --------- d-----w c:\program files\ATI Technologies
2008-12-18 20:53 14,656 ----a-w c:\windows\gdrv.sys
2008-12-01 22:13 3,452,928 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 19:51 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-01-01 13:45 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-01 13:45 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-01 13:45 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-01 13:45 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-01 13:45 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
"Wallpaper"="c:\program files\Wallpaper\Wallpaper.exe" [2007-08-21 233472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Control Center"="c:\program files\ASUS\WLAN Card Utilities\Center.exe" [2004-05-05 1459200]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-29 136600]
"WiFiCtrl"="c:\program files\Hercules\Hercules WiFi Controller Software\WiFiCtrl.exe" [2006-10-05 11755520]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-30 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"d:\\Jeux\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avcenter.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\UT2004\\System\\UT2004.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 ASNDIS5;ASNDIS5 Protocol Driver;\??\c:\windows\system32\ASNDIS5.SYS [2008-09-07 16269]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c:
\Shell\Open\command - c:\resycled\boot.com c:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d:
\Shell\Open\command - d:\resycled\boot.com d:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09817bab-d2cc-11dd-8013-001a4d9212ef}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com i:
\Shell\Open\command - i:\resycled\boot.com i:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09817bac-d2cc-11dd-8013-001a4d9212ef}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com j:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bbfd94c-80b2-11dd-bfbe-001a4d9212ef}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com i:
\Shell\Open\command - i:\resycled\boot.com i:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7bbfd94d-80b2-11dd-bfbe-001a4d9212ef}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com j:
\Shell\Open\command - j:\resycled\boot.com j:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{844b1aa8-a39f-11dd-bfc4-001a4d9212ef}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com k:
*Newly Created Service* - ASNDIS5
.
Contenu du dossier 'Tâches planifiées'
2008-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
.
- - - - ORPHELINS SUPPRIMES - - - -
Notify-dimsntfy - (no file)
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: {4E0943C7-00D8-4804-A04A-C72768138D69} = 192.168.1.1,213.203.124.146
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetecti(...)
c:\windows\Downloaded Program Files\hardwaredetection.inf
FF - ProfilePath - c:\documents and settings\Mikael\Application Data\Mozilla\Firefox\Profiles\aiz3ycxh.default\
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - component: c:\program files\Mozilla Firefox\components\iamfamous.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-01 21:34:57
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-1177238915-796845957-725345543-1004
"*"=dword:00000004
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-1177238915-796845957-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-1177238915-796845957-725345543-1004
@Allowed: (Full) (S-1-5-21-1177238915-796845957-725345543-1004)
@Allowed: (Full) (S-1-5-21-1177238915-796845957-725345543-1004)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-1177238915-796845957-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_USERS\S-1-5-21-1177238915-796845957-725345543-1004\Software\SecuROM\License information*NULL*]
@Security="Inherited"
"datasecu"=hex:1e,f7,03,25,33,25,65,d7,b0,23,ce,d0,e4,29,a5,60,6e,49,a0,d3,de,\
17,5f,e3,36,29,77,4a,15,26,82,fd,ac,a2,b3,aa,2e,79,44,64,ca,9c,12,fe,0f,07,\
d9,c5,e5,77,98,fa,ef,e4,b8,e6,b4,2f,87,b0,a3,72,08,9a,68,3f,b1,e4,c0,37,66,\
56,d8,c2,5d,d1,30,f3,25,86,b2,39,3c,7e,d8,18,89,80,e6,ae,95,48,0a,2b,1d,10,\
3d,71,d6,67,86,32,f4,85,18,f3,a8,ec,7d,b7,60,2b,9c,b5,5c,3a,d5,88,60,0b,f9,\
f3,d1,04,74,21,57,34,ee,b2,52,ca,1c,4f,95,82,56,58,63,d2,c8,ea,32,83,9d,bb,\
f1,8e,6f,5a,6f,02,d9,16,3f,c2,bf,d0,45,16,68,63,42,ea,3d,0d,44,cb,b4,cc,f2,\
e0,72,6a,49,a4,05,44,69,98,b5,97,66,19,6d,26,89,38,10,36,da,f7,18,52,9b,15,\
f1,0c,0e,ed,6c,a5,22,4b,8f,0a,1b,ca,b1,6d,2b,d5,78,27,26,02,02,90,e8,60,ad,\
c3,aa,93,ed,c7,32,8b,da,ad,cd,8f,7a,af,97,b1,7a,c3,f4,b3,6a,c4,b6,6f,8d,bb,\
a4,6b,b6,e2,26,b5,0b,60,2e,bd,9a,61,39,4c,58,c5,f4,ed,1a,c7,74,93,01,ab,ba,\
74,57,ea,8a,f5,aa,6b,99,b4,37,a1,a4,60,6f,20,ef,7b,eb,65,22,37,0c,5b,bd,66,\
44,ec,13,fe,33,be,0b,ba,5c,ec,e8,9a,fa,30,4c,70,5d,9a,70,35,e0,21,0e,e8,18,\
db,c2,be,8a,39,80,6c,3d,ca,27,8d,aa,93,b7,08,dc,fa,4e,00,29,b2,62,44,76,81,\
4f,49,e0,75,a9,06,67,c9,2b,d4,3b,23,e7,8f,b7,8f,35,ba,45,81,7a,11,c0,c6,58,\
60,f5,15,28,bc,cb,81,6a,36,f0,a2,58,13,97,a8,e8,6b,b1,de,7d,6c,61,36,42,4c,\
c0,56,69,c4,29,3f,57,0b,10,7d,aa,93,ec,74,50,4e,aa,b8,4e,49,85,a3,80,af,7e,\
bd,e4,36,61,0c,a9,b0,b0,65,37,c2,39,f3,37,f0,04,99,b4,8c,e7,f8,c2,a7,9d,ba,\
5f,7d,c8,e2,9a,9b,40,33,25,57,ea,f5,7e,ed,1b,d4,21,0c,7f,58,87,42,d9,ad,99,\
be,a6,e9,b0,3b,d9,e0,4c,c8,d0,4f,4d,6b,f4,f3,d5,f1,4e,7e,e9,77,3f,18,6d,0b,\
47,98,d7,58,15,0a,b0,c4,7a,cc,a9,fc,9a,d4,bd,12,85,54,cb,15,6a,38,79,31,13,\
ec,ef,9b,6d,3d,9d,5c,53,ef,b2,82,f1,f8,64,81,ee,5c,15,b8,7d,90,2c,86,29,91,\
25,a7,a3,f1,72,01,23,8e,60,8f,a1,da,d3,8b,f1,8b,99,d2,0a,47,28,f7,91,0c,57,\
49,4e,9a,18,c1,6d,cc,13,0b,ab,cd,8b,a6,41,e3,9b,28,29,9d,73,8d,45,5c,40,d2,\
78,7c,b2,c6,7a,51,33,96,e3,fb,97,16,15,14,c2,32,07,1f,56,16,7a,17,13,fd,d5,\
cd,a1,03,b2,70,a3,66,21,f7,82,18,9f,75,bb,d5,ed,ae,fe,57,cf,f2,40,d4,0f,cf,\
73,22,20,e2,56,37,56,52,87,be,b7,b9,03,85,1d,4e,b6,f3,5e,7c,0f,ee,70,e7,b0,\
53,70,33,20,c3,9e,bd,36,04,53,02,c4,5f,3c,4b,0e,7c,46,41,a4,b6,9a,ab,69,66,\
18,a8,e6,f9,1a,4e,5e,0a,d9,64,2d,1c,f5,93,8d,47,48,85,a1,1a,0a,f0,74,04,2f,\
15,0c,04,2d,b8,fa,0b,ca,82,33,e0,a7,f5,77,2e,7b,4b,e8,b4,df,d2,c5,10,6d,07,\
3b,fd,3b,04,b2,c0,7e,1d,eb,e4,f1,69,4d,2a,ac,f9,6d,94,25,d1,94,6d,fc,2a,7a,\
bc,38,59,ab,e7,58,81,34,1d,3b,e0,27,dd,e3,31,a4,e4,8e,d2,37,db,b1,49,64,e4,\
2d,04,e0,db,9b,81,d0,ee,25,59,8d,23,ed,d1,80,d6,09,5a,78,b5,d1,e0,09,a3,aa,\
ae,e9,e3,4f,40,c2,7a,63,81,b1,d0,b0,db,11,a8,d7,13,4f,53,bd,b8,79,18,a0,92,\
03,72,8b,9f,cc,0a,6f,a8,14,39,a0,94,59,88,3b,47,c1,17,9b,3e,ca,1c,bf,f5,25,\
c8,f8,d6,16,0a,e7,d0,38,9b,3b,a9,21,66,09,65,c5,c8,c3,4a,1b,e4,a3,dd,89,52,\
25,b7,02,a9,e2,08,37,de,b3,4b,68,e8,67,f2,65,22,f2,8c,5c,2a,87,cf,40,f5,40,\
64,19,79,8a,b7,3c,0e,0b,60,a5,a0,d7,e0,c8,39,ec,18,e4,36,f1,72,d1,14,85,9b,\
bf,2f,94,15,84,cb,c4,a0,78,81,2d,10,30,bc,dc,0f,b3,26,4b,8e,59,fe,12,82,d2,\
16,20,20,1c,c0,82,25,01,a6,35,a9,e9,99,18,4c,dc,b9,50,7a,78,9e,ba,b2,0b,46,\
ba,cf,68,53,0c,ce,23,1e,eb,bb,9c,3b,c2,49,dc,62,9e,a2,33,eb,57,19,2f,7e,1e,\
64,3c,62,42,0e,a8,db,6f,47,6d,48,7a,1a,e6,f3,63,d2,fa,9a,c8,3f,0b,af,20,a3,\
21,d4,72,bc,4e,37,c7,f6,c4,27,73,6c,b8,2d,05,1e,60,0b,a9,e0,dc,22,53,98,40,\
31,af,4e,0a,13,16,e8,3c,0e,3e,0d,36,c3,2e,17,14,26,14,35,69,d8,02,fe,ad,28,\
3d,57,b4,83,73,d7,9e,77,a2,82,49,73,57,cd,ef,f9,97,fa,de,de,48,79,c3,7d,8f,\
ec,a3,c5,2c,e3,ed,dc,11,92,97,82,d2,bd,18,45,24,d9,fc,0f,96,fd,ee,01,d1,3b,\
d3,47,3b,44,f0,75,b5,d6,a1,34,d5,17,1a,45,56,c3,49,c7,cb,27,63,43,04,d0,f5,\
a1,c3,11,62,36,b0,93,69,10,a1,87,f9,5d,33,42,33,6c,1f,66,56,5e,40,95,a5,10,\
4b,f4,90,66,1b,3a,09,25,fe,06,db,23,f2,b7,49,3a,6a,20,bd,b2,05,35,15,62,e3,\
cd,d1,f2,0f,6d,ff,72,ad,de,fd,72,a6,2a,c8,d6,34,3a,9a,85,18,97,78,2a,17,f8,\
40,2c,89,8b,49,8e,4c,2c,7b,c3,db,73,3c,c5,9f,2b,7b,e3,31,39,b8,ea,6c,00,80,\
3b,09,55,a3,95,1d,d0,d9,31,4e,40,f0,9f,49,3f,2d,ac,61,20,81,c0,78,d8,c2,a6,\
1d,bd,8e,0a,7a,05,12,65,2a,68,03,36,20,f4,7c,24,d1,47,22,2f,56,6c,5a,dd,2a,\
82,a9,ae,a5,e7,63,77,8e,1e,d1,b7,a4,a5,e4,18,6b,fd,41,a8,68,c2,8b,74,16,f8,\
f3,dc,45,fa,8a,30,05,e5,14,df,10,38,f2,6b,0b,6a,9e,9c,36,f7,17,ae,6e,76,cc,\
e1,24,c6,35,36,06,f8,1c,49,83,3f,29,3d,f7,91,c1,e9,22,58,99,cf,35,08,1a,c3,\
e3,02,c8,15,7c,cc,03,a9,18,72,23,54,27,c7,9c,3d,fb,cd,4e,6b,ea,6c,66,80,97,\
be,1a,86,3d,02,5a,09,6f,7a,a8,ac,6f,05,61,f7,83,e0,e3,11,b1,ae,59,f7,c6,dc,\
a5,01,be,db,aa,e4,88,12,a6,9e,35,95,bd,d5,81,68,75,9e,fe,60,23,8f,69,cd,c7,\
cb,e3,3e,96,8b,e4,a6,ae,62,1d,06,8e,cd,e1,19,51,45,bb,58,48,e9,dc,89,a4,f1,\
06,72,3c,18,fe,e8,c1,9a,6e,85,23,0f,01,1c,c2,f4,ed,2b,88,9b,1a,72,b8,db,77,\
89,d9,cc,59,99,7f,c9,4c,0a,22,b5,1d,75,1b,f0,b9,f1,da,c0,c5,d4,a8,79,e3,38,\
07,c3,ef,46,5e,35,30,62,31,eb,3b,f5,5d,70,91,79,f9,98,c9,80,16,0f,14,af,16,\
50,7a,b6,bf,5f,42,47,7b,10,29,66,2c,1b,79,de,66,fd,4e,c4,88,5a,15,94,11,8a,\
d6,7e,0e,c8,40,fe,0c,d3,b5,02,5f,bb,50,08,be,82,76,a6,6c,c9,af,f0,c1,dc,7d,\
89,f5,cf,9d,da,b7,06,d9,69,46,a3,eb,6d,2e,f1,59,8e,f8,23,01,a0,23,a2,ba,ce,\
d0,27,a7,e9,14,c9,44,ac,da,1c,06,58,32,56,c4,a5,ee,1f,59,68,fb,1f,dd,92,bc,\
94,83,33,92,58,90,d6,0b,5c,2c,8a,ab,ee,ea,3d,e5,ab,50,0e,93,32,f1,66,33,50,\
25,09,4b,fa,ac,22,ab,3b,20,fb,bc,36,3c,82,6d,b7,9c,0c,50,b5,fe,16,db,e8,45,\
93,02,b0,19,84,08,dc,3a,a2,80,bb,a8,61,f1,5c,51,cd,8a,c6,2d,53,a7,33,85,ca,\
81,b6,1f,c7,13,b8,50,61,eb,af,60,68,7c,cb,93,04,59,79,78,50,71,07,58,fb,1a,\
e9,ea,2d,a3,dd,43,dc,a0,ca,74,d5,0f,8b,52,b9,b7,f8,dd,9f,2b,92,8c,75,6a,bc,\
4d,fb,75,03,ab,99,e8,4f,3d,21,b8,ef,7a,be,df,61,ab,ba,51,0c,25,8e,65,b9,d0,\
3c,49,3a,74,f4,e1,17,8e,08,18,9d,e0,09,da,aa,c2,aa,8d,0f,23,7a,4c,b2,10,4d,\
eb,a9,42,88,2f,ff,d5,5d,21,0a,ed,17,1a,d6,27,7b,48,92,71,a2,a6,9a,c0,a1,f3,\
a4,f8,c1,11,38,48,a6,e6,2a,99,2c,01,7c,f6,c8,57,41,27,d5,6f,2c,37,ad,7f,64,\
0e,3c,d7,28,e7,47,0b,1f,e0,a0,18,28,44,9f,da,75,0a,ca,bc,82,b8,bc,ce,51,82,\
e6,6f,65,51,22,01,c2,bf,09,8f,7e,fc,07,33,23,41,d1,32,3f,a4,4f,61,12,5d,59,\
cd,2c,77,4a,b0,61,d6,18,d7,cd,fa,45,02,6f,85,3e,58,26,ec,4d,52,f7,d3,0f,08,\
19,d3,f7,38,09,d3
"rkeysecu"=hex:05,be,49,30,d3,14,44,8f,0c,a8,0c,e9,26,26,6d,6d
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*NULL*]
@Security="Inherited"
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-1177238915-796845957-725345543-1004
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*â*NULL*¬ r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\*NULL*u|·*NULL*]
@Security="Inherited"
"DisplayName"="?\11"
"DeviceDesc"="?\11"
"ProviderName"="?\11???\11\
08"
"MFG"="??\
09"
"ReinstallString"="8.432.0.0000"
"DeviceInstanceIds"=multi:"e:\\drivers\\xp\\driver\\xp_inf\\cx_54437.inf\
00"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Heure de fin: 2009-01-01 21:38:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-01 20:38:06
Avant-CF: 44 234 985 472 octets libres
Après-CF: 44,181,291,008 octets libres
412 --- E O F --- 2008-12-29 09:16:45