kikou mi revoilou
alors the rapport combofix
ComboFix 09-10-26.06 - Boss 27/10/2009 18:32.2.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3070.2583 [GMT 1:00]
Lancé depuis: c:\documents and settings\Boss\Bureau\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Exécution préalable -------
.
C:\Autorun.inf
c:\docume~1\Boss\LOCALS~1\Temp\cvasds0.dll
c:\docume~1\Boss\LOCALS~1\Temp\cvasds1.dll
C:\nds0q.exe
c:\windows\Installer\ecf3f.msi
c:\windows\kb913800.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf
D:\nds0q.exe
E:\Autorun.inf
E:\nds0q.exe
F:\Autorun.inf
F:\nds0q.exe
G:\autorun.inf
G:\nds0q.exe
H:\Autorun.inf
H:\nds0q.exe
Une copie infectée de c:\windows\system32\drivers\atapi.sys a été trouvée et désinfectée
Copie restaurée à partir de - Kitty ate it
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-27 au 2009-10-27 ))))))))))))))))))))))))))))))))))))
.
2009-10-22 22:14 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-22 22:14 . 2009-10-22 22:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-22 22:14 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-22 21:48 . 2009-10-22 21:48 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-10-22 21:45 . 2009-10-22 21:45 -------- d-----w- c:\windows\ERUNT
2009-10-22 21:40 . 2009-10-22 22:09 -------- d-----w- C:\SDFix
2009-10-22 20:44 . 2009-10-22 20:54 -------- d-----w- C:\ToolBar SD
2009-10-22 20:34 . 2009-10-22 21:06 -------- d-----w- C:\GenProc
2009-10-21 19:46 . 2009-10-21 19:46 -------- d-----w- c:\program files\CAPCOM
2009-10-21 19:05 . 2009-10-21 19:05 -------- d-----w- c:\program files\Micro Application
2009-10-21 17:41 . 2009-10-21 17:41 -------- d-----w- c:\windows\usgwmt
2009-10-20 20:39 . 2009-10-20 21:12 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-20 20:39 . 2009-10-20 21:12 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-20 20:39 . 2009-10-27 17:32 663584 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-10-20 20:39 . 2009-10-27 17:31 7117856 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-20 20:39 . 2009-10-27 17:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-20 20:39 . 2009-10-20 20:39 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-20 20:35 . 2009-10-20 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-17 21:46 . 2009-10-17 21:47 -------- d-----w- c:\program files\ShowTraf
2009-10-17 21:45 . 2009-10-17 21:45 -------- d-----w- c:\program files\WinPcap
2009-10-16 13:40 . 2009-10-16 13:42 -------- d-----w- c:\program files\Killing Floor
2009-10-13 21:06 . 2009-10-13 21:06 -------- d-----w- c:\windows\Sun
2009-10-13 21:05 . 2009-10-13 21:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-13 21:05 . 2009-10-13 21:05 -------- d-----w- c:\program files\Java
2009-10-01 09:39 . 2009-10-01 15:32 -------- d-----w- c:\documents and settings\Boss\Local Settings\Application Data\id Software
2009-09-30 09:27 . 2009-09-30 09:27 244192 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-30 08:19 . 2009-09-30 08:20 -------- d-----w- c:\documents and settings\Boss\Local Settings\Application Data\Rockstar Games
2009-09-30 08:14 . 2009-09-30 08:14 -------- d--h--r- c:\documents and settings\Boss\Application Data\SecuROM
2009-09-30 08:12 . 2009-09-30 08:12 -------- d-----w- c:\windows\system32\drivers\umdf
2009-09-29 20:45 . 2009-09-29 20:46 -------- d-----w- c:\program files\Rockstar Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-27 17:36 . 2006-03-24 12:00 93756 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-27 17:36 . 2006-03-24 12:00 533160 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-27 17:32 . 2009-10-20 20:39 8588 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-10-27 17:31 . 2009-10-20 20:39 61928 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-10-27 17:07 . 2009-08-28 18:58 -------- d-----w- c:\documents and settings\Boss\Application Data\uTorrent
2009-10-27 04:42 . 2009-09-17 23:51 -------- d-----w- c:\program files\PeerGuardian2
2009-10-21 19:05 . 2009-08-28 16:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-21 16:23 . 2009-08-28 16:56 -------- d-----w- c:\program files\ma-config.com
2009-10-20 21:12 . 2008-01-29 15:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys
2009-10-20 20:36 . 2009-09-08 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-20 19:31 . 2009-08-30 03:27 -------- d-----w- c:\program files\Lavasoft
2009-10-20 19:31 . 2009-08-30 03:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-20 19:29 . 2009-08-28 16:59 -------- d-----w- c:\program files\BitDefender
2009-10-20 19:29 . 2009-08-28 16:58 -------- d-----w- c:\program files\Fichiers communs\BitDefender
2009-10-20 19:29 . 2009-08-28 22:36 81984 ----a-w- c:\windows\system32\bdod.bin
2009-10-01 09:37 . 2009-08-29 21:37 139152 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-01 09:37 . 2009-08-29 21:37 139152 ----a-w- c:\documents and settings\Boss\Application Data\PnkBstrK.sys
2009-10-01 09:37 . 2009-08-29 21:37 111928 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-01 09:37 . 2009-08-29 21:37 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-10-01 09:37 . 2009-08-29 21:37 794408 ----a-w- c:\windows\system32\pbsvc.exe
2009-10-01 09:30 . 2009-09-06 14:53 -------- d-----w- c:\program files\Activision
2009-09-29 14:01 . 2009-08-29 20:16 -------- d-----w- c:\program files\Doom 3
2009-09-27 11:30 . 2009-09-27 11:30 -------- d-----w- c:\program files\SouthPeak Games
2009-09-26 09:27 . 2009-09-26 09:25 -------- d-----w- c:\documents and settings\Boss\Application Data\Juce VST Host
2009-09-22 23:00 . 2009-09-22 23:00 -------- d--h--w- c:\documents and settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2009-09-22 22:57 . 2009-09-22 22:57 -------- d-----w- c:\program files\Stardock Games
2009-09-22 19:24 . 2009-08-28 16:43 -------- d-----w- c:\program files\NVIDIA Corporation
2009-09-21 02:05 . 2009-09-21 02:01 -------- d-----w- c:\documents and settings\Boss\Application Data\Propellerhead Software
2009-09-21 02:01 . 2009-09-21 02:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Propellerhead Software
2009-09-21 02:01 . 2009-09-21 02:01 233472 ----a-w- c:\windows\system32\REX Shared Library.dll
2009-09-21 02:00 . 2009-09-21 02:00 -------- d-----w- c:\program files\Propellerhead
2009-09-20 23:04 . 2009-08-29 17:32 -------- d-----w- c:\program files\Image-Line
2009-09-20 23:04 . 2009-09-20 23:04 -------- d-----w- c:\program files\Outsim
2009-09-19 17:06 . 2009-09-16 18:09 -------- d-----w- c:\documents and settings\Boss\Application Data\DAEMON Tools Lite
2009-09-16 18:17 . 2009-09-16 18:12 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-09-16 18:15 . 2009-09-16 18:15 -------- d-----w- c:\documents and settings\Boss\Application Data\DAEMON Tools Pro
2009-09-16 18:13 . 2009-09-16 18:13 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-09-16 18:09 . 2009-09-16 18:09 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-16 17:58 . 2009-09-16 17:58 -------- d-----w- c:\program files\Microsoft WSE
2009-09-16 17:55 . 2009-08-30 02:45 -------- d-----w- c:\program files\Electronic Arts
2009-09-14 20:07 . 2009-09-14 19:46 -------- d-----w- c:\program files\eMule
2009-09-12 23:53 . 2009-09-12 23:53 -------- d-----w- c:\program files\Sierra
2009-09-11 14:18 . 2006-03-24 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 18:41 . 2009-09-09 18:41 -------- d-----w- c:\program files\AxBx
2009-09-08 22:48 . 2009-09-08 22:48 -------- d-----w- c:\documents and settings\Boss\Application Data\MSNInstaller
2009-09-08 19:16 . 2009-09-08 01:03 91 ----a-w- c:\windows\system32\tempBatFile.bat
2009-09-08 18:58 . 2009-09-08 18:58 -------- d-----w- c:\documents and settings\Boss\Application Data\Malwarebytes
2009-09-08 18:58 . 2009-09-08 18:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-08 18:51 . 2009-09-06 16:24 -------- d-----w- c:\program files\ZebHelpProcess
2009-09-06 16:24 . 2009-09-06 16:24 -------- d-----w- c:\program files\Fichiers communs\Borland Shared
2009-09-06 15:17 . 2009-09-06 15:17 0 ----a-w- c:\windows\nsreg.dat
2009-09-06 14:46 . 2009-09-06 14:46 -------- d-----w- c:\program files\CCleaner
2009-09-05 23:52 . 2009-09-05 23:16 -------- d-----w- c:\documents and settings\Boss\Application Data\Red Alert 3
2009-09-04 21:04 . 2006-03-24 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 11:39 . 2009-08-28 16:54 15248 ----a-w- c:\documents and settings\Boss\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-30 11:38 . 2009-08-30 11:36 -------- d-----w- c:\program files\Windows Live
2009-08-30 11:37 . 2009-08-30 11:37 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-08-30 11:36 . 2009-08-30 11:36 -------- d-----w- c:\program files\Microsoft
2009-08-30 11:36 . 2009-08-30 11:36 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-08-30 11:27 . 2009-08-30 11:27 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-08-30 10:52 . 2009-08-30 02:45 1722 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-08-30 02:54 . 2009-08-30 02:54 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-08-30 02:53 . 2009-08-30 02:53 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2009-08-30 02:19 . 2009-08-28 17:39 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-08-30 02:18 . 2009-08-30 02:18 -------- d-----w- c:\documents and settings\All Users\Application Data\THQ
2009-08-30 02:11 . 2009-08-30 02:11 -------- d-----w- c:\program files\THQ
2009-08-30 01:34 . 2009-08-29 10:29 -------- d-----w- c:\program files\Windows Desktop Search
2009-08-30 00:15 . 2009-08-30 00:14 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-08-29 21:38 . 2009-08-29 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2009-08-29 21:30 . 2009-08-29 21:30 -------- d-----w- c:\program files\Ubisoft
2009-08-29 17:42 . 2009-08-29 17:42 -------- d-----w- c:\documents and settings\Boss\Application Data\Windows Search
2009-08-29 17:36 . 2009-08-29 17:36 -------- d-----w- c:\program files\Trend Micro
2009-08-29 17:35 . 2009-08-29 17:35 -------- d-----w- c:\program files\Alcohol Soft
2009-08-29 17:33 . 2009-08-29 17:32 -------- d-----w- c:\program files\VstPlugins
2009-08-29 17:33 . 2009-08-29 17:33 -------- d-----w- c:\program files\ASIO4ALL v2
2009-08-29 10:29 . 2009-08-29 10:29 -------- d-----w- c:\documents and settings\Boss\Application Data\Windows Desktop Search
2009-08-29 10:18 . 2009-08-29 10:18 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-08-29 09:50 . 2009-08-29 09:50 -------- d-----w- c:\program files\NFO viewer
2009-08-29 09:18 . 2009-08-28 17:18 -------- d-----w- c:\program files\uTorrent
2009-08-29 07:56 . 2006-03-24 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-28 22:38 . 2009-08-28 17:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Creative
2009-08-28 22:38 . 2009-08-28 17:53 -------- d-----w- c:\documents and settings\Boss\Application Data\Creative
2009-08-28 19:32 . 2009-08-28 19:32 -------- d-----w- c:\documents and settings\Boss\Application Data\Media Player Classic
2009-08-28 19:32 . 2009-08-28 19:31 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-08-28 19:23 . 2009-08-28 19:23 -------- d-----w- c:\program files\MSBuild
2009-08-28 19:23 . 2009-08-28 19:23 -------- d-----w- c:\program files\Reference Assemblies
2009-08-28 19:20 . 2009-08-28 19:20 -------- d-----w- c:\program files\MSXML 6.0
2009-08-28 19:19 . 2009-08-28 19:19 127 ----a-w- c:\documents and settings\Boss\Local Settings\Application Data\fusioncache.dat
2009-08-28 19:19 . 2009-08-28 19:19 -------- d-----w- c:\program files\MSXML 4.0
2009-08-28 18:04 . 2009-08-28 17:51 -------- d-----w- c:\program files\Creative
2009-08-28 18:00 . 2009-08-28 16:42 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-08-28 18:00 . 2009-08-28 18:00 81920 ----a-w- c:\windows\system32\OpenAL32.dll
2009-08-28 18:00 . 2009-08-28 18:00 233472 ----a-w- c:\windows\system32\wrap_oal.dll
2009-08-28 16:14 . 2009-08-28 16:14 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-26 08:01 . 2006-03-24 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 01:03 . 2009-08-17 01:03 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-08-17 01:02 . 2009-08-17 01:02 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-08-16 22:57 . 2009-08-28 17:39 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-08-16 22:57 . 2009-08-16 22:57 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-08-16 22:57 . 2009-08-16 22:57 7729568 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-17 45056]
"RCSystem"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 49152]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-10 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-13 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-10-20 208616]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2005-08-07 16384]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2005-08-07 18944]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Doom 3\\DOOM3.exe"=
"c:\\Documents and Settings\\Boss\\Bureau\\Tactical Ops\\System\\TacticalOps.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"c:\\Warhammer_Dawn_of_War_2-WiCKED\\WiCKED-DOW2\\DOW2.exe"=
"c:\\Program Files\\THQ\\Frontlines-Fuel of War\\Binaries\\FFOW.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.8.game"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW-lanfix 1.5.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MP.exe"=
"c:\\Program Files\\Activision\\Wolfenstein\\MP\\Wolf2MPLite.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Killing Floor\\System\\KillingFloor.exe"=
"c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX9.EXE"=
"c:\\Program Files\\CAPCOM\\RESIDENT EVIL 5\\RE5DX10.EXE"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 16:29 33808]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [30/08/2009 12:38 54752]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [13/03/2008 17:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 16:06 24592]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 16:13 234864]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [02/08/2005 22:10 32512]
.
Contenu du dossier 'Tâches planifiées'
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
mWindow Title =
IE: Add to Anti-Banner
FF - ProfilePath - c:\documents and settings\Boss\Application Data\Mozilla\Firefox\Profiles\by4qfb3l.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-27 18:41
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1085031214-1123561945-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:a1,9b,6f,f2,be,da,a1,b4,4f,6f,cb,a9,e9,06,4e,1e,2b,94,22,4f,dd,
f8,b9,3a,45,09,02,52,70,85,58,91,7d,02,f6,14,4e,0e,78,aa,c4,bf,e6,cf,32,5a,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
Heure de fin: 2009-10-27 18:42
ComboFix-quarantined-files.txt 2009-10-27 17:42
Avant-CF: 249 065 988 096 octets libres
Après-CF: 249 049 518 080 octets libres
- - End Of File - - CA9B4EDEE597D16570973362D99B2952
voila merci 'ncor boocoop
@ toute