Super le rename
ComboFix 09-02-12.03 - COD 2009-02-15 15:30:57.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1023.686 [GMT 1:00]
Lancé depuis: c:\documents and settings\COD\Bureau\dom.exe.exe
AV: avast! antivirus 4.8.1335 [VPS 090215-0] *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\GnuHashes.ini
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\UACquvjvjkx.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACeqtqmuha.dll
c:\windows\system32\UACpeicmylm.log
c:\windows\system32\UACrfagulgj.dat
c:\windows\system32\UACutatqrwn.log
c:\windows\system32\UACwhuukopm.dll
c:\windows\system32\UACwvohpieu.dll
c:\windows\system32\UACwyullcus.log
c:\windows\system32\UACxhvkuaid.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-15 au 2009-02-15 ))))))))))))))))))))))))))))))))))))
.
2009-02-15 15:28 . 2009-02-15 15:35 219,168 --ahs---- c:\windows\system32\drivers\fidbox.dat
2009-02-15 15:28 . 2009-02-15 15:28 32 --ahs---- c:\windows\system32\drivers\fidbox.idx
2009-02-14 22:10 . 2009-02-14 22:12 <REP> d-------- c:\program files\Navilog1
2009-02-14 20:59 . 2008-10-12 19:00 <REP> d--h----- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Voisinage réseau
2009-02-14 20:59 . 2008-10-12 19:00 <REP> d--h----- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Voisinage d'impression
2009-02-14 20:59 . 2008-10-12 18:08 <REP> d--h----- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Modèles
2009-02-14 20:59 . 2008-10-12 19:00 <REP> d-------- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Mes documents
2009-02-14 20:59 . 2008-10-12 19:00 <REP> dr------- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Menu Démarrer
2009-02-14 20:59 . 2008-10-12 19:00 <REP> d-------- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Favoris
2009-02-14 20:59 . 2008-10-12 19:00 <REP> d-------- c:\documents and settings\Administrateur.TATA-E6VFC47Q28\Bureau
2009-02-14 20:59 . 2009-02-14 20:59 <REP> d-------- c:\documents and settings\Administrateur.TATA-E6VFC47Q28
2009-02-14 18:33 . 2009-02-14 18:33 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-14 18:33 . 2009-02-14 18:33 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-02-14 18:33 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-14 18:33 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-14 15:43 . 2009-02-14 21:17 <REP> d-------- c:\program files\FindyKill
2009-02-14 15:38 . 2009-02-14 15:38 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-14 11:55 . 2009-02-14 11:54 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-14 11:52 . 2009-02-14 12:55 <REP> d-------- c:\program files\Lavasoft
2009-02-14 11:52 . 2009-02-14 12:55 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-02-14 11:25 . 2009-02-14 14:56 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-02-14 11:25 . 2009-02-14 14:55 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-02-14 10:56 . 2009-02-14 10:56 <REP> d-------- c:\program files\Goto Software
2009-02-14 10:56 . 2009-02-14 10:56 <REP> d-------- c:\documents and settings\COD\Application Data\VadeRetro
2009-02-14 10:56 . 2009-02-14 10:57 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\VadeRetro
2009-02-14 10:05 . 2009-02-14 10:05 <REP> d-------- c:\program files\Zone Labs
2009-02-14 10:05 . 2009-02-14 10:05 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\MailFrontier
2009-02-14 10:02 . 2009-02-15 15:02 <REP> d-------- c:\windows\Internet Logs
2009-02-14 09:53 . 2009-02-14 09:53 <REP> d-------- c:\program files\AxBx
2009-02-12 22:24 . 2009-02-12 22:24 0 --a------ c:\windows\iPlayer.INI
2009-02-12 20:54 . 2009-02-12 20:54 <REP> d-------- c:\program files\InterActual
2009-02-11 21:17 . 1998-06-24 00:00 137,000 --a------ c:\windows\system32\MSMAPI32.OCX
2009-02-11 21:17 . 1998-07-13 01:08 119,568 --a------ c:\windows\system32\VB6FR.DLL
2009-02-11 21:17 . 2001-10-28 16:42 116,224 --a------ c:\windows\system32\pdfcmnnt.dll
2009-02-11 21:16 . 1998-07-13 01:08 141,312 --a------ c:\windows\system32\MSCMCFR.DLL
2009-02-11 21:16 . 1998-07-13 01:08 59,904 --a------ c:\windows\system32\MSCC2FR.DLL
2009-02-11 21:16 . 1998-07-06 00:00 23,552 --a------ c:\windows\system32\MSMPIDE.DLL
2009-02-09 20:43 . 2006-08-21 10:14 128,896 -----c--- c:\windows\system32\dllcache\fltmgr.sys
2009-02-09 20:43 . 2006-08-21 10:14 23,040 -----c--- c:\windows\system32\dllcache\fltmc.exe
2009-02-09 20:43 . 2006-08-21 13:26 16,896 -----c--- c:\windows\system32\dllcache\fltlib.dll
2009-02-09 20:17 . 2007-07-09 14:11 584,192 -----c--- c:\windows\system32\dllcache\rpcrt4.dll
2009-02-09 20:16 . 2008-12-20 23:46 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-02-09 20:16 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-02-09 20:16 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-09 20:16 . 2008-12-20 23:46 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-02-09 20:16 . 2008-12-20 23:46 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-09 20:16 . 2008-12-20 23:46 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-02-09 20:16 . 2008-12-20 23:46 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-02-09 20:16 . 2008-12-20 23:46 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-09 20:16 . 2008-12-19 10:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-02-09 20:14 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-09 20:14 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-09 20:14 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-09 20:14 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-09 20:12 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-09 20:12 . 2008-12-11 12:57 333,184 -----c--- c:\windows\system32\dllcache\srv.sys
2009-02-09 20:12 . 2008-05-01 15:31 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-02-09 20:11 . 2008-04-11 19:51 683,520 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-02-09 19:57 . 2008-10-15 17:59 332,800 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-02-09 19:57 . 2008-10-03 11:17 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2009-02-09 19:56 . 2008-09-04 17:45 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-02-09 19:40 . 2001-08-28 13:00 68,608 --a------ c:\windows\system32\plugin.ocx
2009-02-09 19:40 . 2001-08-28 13:00 68,608 --a------ c:\windows\system32\dllcache\plugin.ocx
2009-02-09 19:36 . 2009-02-09 19:36 <REP> d-------- c:\windows\system32\LogFiles
2009-02-09 17:43 . 2009-02-09 20:02 1,544 --a------ c:\windows\system32\drivers\fwdrv.err
2009-02-09 10:13 . 2009-02-15 10:34 5,182 --a------ c:\windows\system32\uacinit.dll
2009-02-09 10:06 . 2009-02-09 11:05 717,856,768 --a------ c:\documents and settings\Le.Transporteur.3.TRUEFRENCH.XviD.MD.TS.KiNG.of.RLZ.avi
2009-02-07 23:28 . 2009-02-07 23:28 <REP> d-------- c:\documents and settings\COD\Application Data\Media Player Classic
2009-02-07 23:25 . 2009-02-07 23:25 <REP> d--h-c--- c:\documents and settings\All Users.WINDOWS\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-02-07 13:46 . 2009-02-07 13:46 <REP> d-------- c:\documents and settings\COD\Application Data\TuneUp Software
2009-02-07 13:46 . 2009-02-07 13:46 603,904 --a------ c:\windows\system32\TUProgSt.exe
2009-02-07 13:46 . 2009-02-07 13:46 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-02-07 13:46 . 2008-12-11 13:31 27,904 --a------ c:\windows\system32\uxtuneup.dll
2009-02-07 13:45 . 2009-02-07 13:50 <REP> d-------- c:\program files\TuneUp Utilities 2009
2009-02-07 13:45 . 2009-02-07 13:45 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\TuneUp Software
2009-02-07 12:44 . 2009-02-07 12:44 <REP> d--hs---- c:\documents and settings\All Users.WINDOWS\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-02-07 10:48 . 2009-02-07 10:48 <REP> d--h----- c:\windows\PIF
2009-02-07 10:40 . 2009-02-07 10:40 <REP> d-------- c:\program files\Lavalys
2009-02-05 22:00 . 2009-02-05 21:59 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-05 09:27 . 2009-02-05 09:27 268 --ah----- C:\sqmdata17.sqm
2009-02-05 09:27 . 2009-02-05 09:27 244 --ah----- C:\sqmnoopt19.sqm
2009-02-05 09:27 . 2009-02-05 09:27 244 --ah----- C:\sqmnoopt18.sqm
2009-02-05 09:27 . 2009-02-05 09:27 244 --ah----- C:\sqmnoopt17.sqm
2009-02-05 09:27 . 2009-02-05 09:27 232 --ah----- C:\sqmdata19.sqm
2009-02-05 09:27 . 2009-02-05 09:27 232 --ah----- C:\sqmdata18.sqm
2009-02-04 09:26 . 2009-02-04 09:26 <REP> d--hs---- c:\windows\system32\LocalService32
2009-02-04 09:26 . 2009-02-04 09:26 374,272 --ahs---- c:\windows\system32\26C.tmp
2009-01-23 22:46 . 2009-02-04 17:33 <REP> d-------- c:\documents and settings\COD\Application Data\LimeWire
2009-01-19 19:29 . 2009-01-26 17:46 <REP> d-------- c:\documents and settings\COD\Application Data\dvdcss
2009-01-19 07:06 . 2004-08-04 00:45 32,128 --a------ c:\windows\system32\drivers\wceusbsh.sys
2009-01-19 07:06 . 2004-08-04 00:45 32,128 --a--c--- c:\windows\system32\dllcache\wceusbsh.sys
2009-01-18 18:30 . 2009-02-10 17:55 <REP> d-------- C:\Data
2009-01-18 15:58 . 2009-02-11 19:05 50 --a------ c:\windows\MegaManager.INI
2009-01-18 12:38 . 2009-01-18 12:38 <REP> d-------- c:\program files\VideoLAN
2009-01-18 12:20 . 2009-02-01 13:41 <REP> d-------- c:\documents and settings\COD\Application Data\DivX
2009-01-18 12:09 . 2009-01-18 12:09 <REP> d-------- c:\program files\K-Lite Codec Pack
2009-01-18 12:09 . 2008-09-24 19:41 839,680 --a------ c:\windows\system32\lameACM.acm
2009-01-18 12:09 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2009-01-18 12:09 . 2008-09-16 20:23 168,448 --a------ c:\windows\system32\unrar.dll
2009-01-18 12:09 . 2008-12-08 12:53 57,344 --a------ c:\windows\system32\ff_vfw.dll
2009-01-18 12:09 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2009-01-18 12:09 . 2008-10-03 13:30 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-18 12:02 . 2009-01-18 12:02 <REP> d-------- c:\program files\Megaupload
2009-01-18 12:02 . 2009-01-18 12:02 <REP> d-------- c:\documents and settings\COD\Application Data\Megaupload
2009-01-18 12:02 . 2009-01-18 12:02 <REP> d-------- c:\documents and settings\COD\Application Data\InstallShield
2009-01-18 12:02 . 2009-01-18 12:02 <REP> d-------- c:\documents and settings\COD\Application Data\EmailNotifier
2009-01-18 12:02 . 2009-01-18 13:30 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Megaupload
2009-01-18 12:02 . 2009-01-18 12:02 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\EmailNotifier
2009-01-18 11:56 . 2008-11-06 17:37 129,784 --------- c:\windows\system32\pxafs.dll
2009-01-18 11:56 . 2008-11-06 17:37 120,056 --------- c:\windows\system32\pxcpyi64.exe
2009-01-18 11:56 . 2008-11-06 17:37 118,520 --------- c:\windows\system32\pxinsi64.exe
2009-01-18 11:13 . 2009-01-24 17:54 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Vsk5Online
2009-01-18 11:10 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-01-18 11:03 . 2009-01-18 11:10 <REP> d-------- c:\program files\Vsk5Online
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-15 09:32 13,440 ----a-w c:\windows\GPCIDrv.sys
2009-02-15 09:31 23,524 ----a-w c:\windows\system32\drivers\GVTDrv.sys
2009-02-14 17:27 25,088 ----a-w c:\windows\Internet Logs\xDB9.tmp
2009-02-14 17:27 1,374,208 ----a-w c:\windows\Internet Logs\xDBA.tmp
2009-02-14 15:44 --------- d-----w c:\program files\Google
2009-02-14 15:43 34,816 ----a-w c:\windows\Internet Logs\xDB7.tmp
2009-02-14 15:43 1,373,696 ----a-w c:\windows\Internet Logs\xDB8.tmp
2009-02-14 15:13 --------- d-----w c:\program files\MSN Messenger
2009-02-14 13:50 27,648 ----a-w c:\windows\Internet Logs\xDB6.tmp
2009-02-14 12:58 19,456 ----a-w c:\windows\Internet Logs\xDB5.tmp
2009-02-14 12:44 104,448 ----a-w c:\windows\Internet Logs\xDB3.tmp
2009-02-14 12:44 1,360,384 ----a-w c:\windows\Internet Logs\xDB4.tmp
2009-02-14 09:19 92,160 ----a-w c:\windows\Internet Logs\xDB1.tmp
2009-02-14 09:19 1,328,128 ----a-w c:\windows\Internet Logs\xDB2.tmp
2009-02-11 20:17 --------- d-----w c:\program files\PDFCreator
2009-02-09 19:50 --------- d-----w c:\program files\Microsoft Works
2009-02-08 09:30 --------- d-----w c:\program files\eMule
2009-02-07 10:04 --------- d-----w c:\program files\CCleaner
2009-02-07 09:18 --------- d-----w c:\program files\Bonjour
2009-02-05 20:59 --------- d-----w c:\program files\Java
2009-01-18 11:02 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-18 10:56 --------- d-----w c:\program files\DivX
2009-01-17 21:43 --------- d-----w c:\documents and settings\COD\Application Data\Skype
2009-01-17 21:31 --------- d-----w c:\documents and settings\COD\Application Data\skypePM
2009-01-12 16:34 --------- d-----w c:\documents and settings\COD\Application Data\StopFlash
2008-12-30 11:03 --------- d-----w c:\program files\[MP3]Administrator
2008-12-30 10:58 --------- d-----w c:\program files\Electronic Arts
2008-12-21 13:01 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-12-21 13:01 --------- d--h--r c:\documents and settings\COD\Application Data\SecuROM
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\system32\dpu11.dll
2008-12-07 18:08 795,648 ----a-w c:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w c:\windows\system32\xvidvfw.dll
2007-09-26 16:31 2,532,922 ----a-w c:\windows\inf\SET6C.tmp
2007-09-22 19:37 5,000,000 ----a-w c:\documents and settings\toto\DIAM III002.zip
2007-09-22 19:37 22 ----a-w c:\documents and settings\toto\DIAM III001.zip
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2008-04-30 498176]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-07-20 7110656]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2005-07-20 86016]
"VGAUtil"="c:\program files\GigaByte\VGA Utility Manager\G-VGA.exe" [2005-08-16 544768]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"VadeRetro Outlook"="c:\program files\Goto Software\Vade Retro\VrMoRegister.exe" [2008-02-20 87552]
"VadeRetro Desktop"="c:\program files\Goto Software\Vade Retro\Vaderetro_Mgr.exe" [2008-04-10 1054208]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"nwiz"="nwiz.exe" [2005-07-20 c:\windows\system32\nwiz.exe]
"P17Helper"="P17.dll" [2005-05-03 c:\windows\system32\P17.dll]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
TrayMin300.exe.lnk - c:\program files\Philips\SPC 200NC PC Camera\TrayMin200.exe [2007-06-30 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\dnsapi32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-14 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-14 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-14 20560]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-02-07 603904]
S3 AVR309Prj;AVR309:USB to UART device driver;c:\windows\system32\drivers\AVR309.sys [2008-10-31 8652]
S3 GPCIDrv;GPCIDrv;c:\windows\GPCIDrv.sys [2008-10-12 13440]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2008-10-12 23524]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4cfbb7ea-c79b-11dd-a707-000272b0a53d}]
\Shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'
2009-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-15 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 15:04]
2009-02-15 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
Notify-305b49cf530 - c:\windows\System32\dnsapi32.dll
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\COD\Application Data\Mozilla\Firefox\Profiles\2sgx2420.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPJPI150_14.dll
FF - plugin: c:\program files\Java\jre1.5.0_14\bin\NPOJI610.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-15 15:35:00
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-02-15 15:37:05
ComboFix-quarantined-files.txt 2009-02-15 14:37:02
Avant-CF: 68,994,658,304 octets libres
Après-CF: 69,453,828,096 octets libres
301 --- E O F --- 2009-02-14 08:58:17