re,
qq problemes :
- Avira était coupé mais s'est réactivé et à trouvé un code heuristique placé dans quarantaine => donc combo a bossé avec Avira.
- j'ai aussi coupé le pare feu windows
- malwarebytes n'a jamais figuré dans la zone de notification => donc je ne sais pas s'il est coupé ou pas
rappart généré :
ComboFix 09-09-08.01 - Eric 08/09/2009 21:43.1.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.1022.436 [GMT 2:00]
Lancé depuis: c:\users\Eric\Desktop\Combo-Fix.exe.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-08 au 2009-09-08 ))))))))))))))))))))))))))))))))))))
.
2009-09-08 20:00 . 2009-09-08 20:00 -------- d-----w- c:\users\Eric\AppData\Local\temp
2009-09-08 20:00 . 2009-09-08 20:00 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2009-09-08 20:00 . 2009-09-08 20:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-08 20:00 . 2009-09-08 20:00 -------- d-----w- c:\users\c0c0tt£\AppData\Local\temp
2009-09-08 20:00 . 2009-09-08 20:00 -------- d-----w- c:\users\doune 4ever\AppData\Local\temp
2009-09-08 15:16 . 2009-09-08 15:16 -------- d-----w- c:\program files\Trend Micro
2009-09-06 12:30 . 2009-09-06 16:15 -------- d-----w- c:\users\doune 4ever\AppData\Roaming\vlc
2009-09-06 10:09 . 2009-09-06 10:09 -------- d-----w- C:\Sounds
2009-09-06 10:05 . 2008-09-04 04:28 19968 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys
2009-09-06 10:05 . 2008-09-04 04:27 24832 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2009-09-06 10:05 . 2008-09-04 04:27 13056 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2009-09-06 10:05 . 2009-09-06 10:05 -------- d-----w- c:\program files\LG Electronics
2009-09-06 10:01 . 2007-11-08 14:26 1164728 ----a-w- c:\windows\system32\NMSDVDXU.dll
2009-09-06 10:01 . 2009-09-06 10:01 -------- d-----w- c:\users\Eric\AppData\Roaming\LG Electronics
2009-09-06 10:01 . 2009-09-06 10:35 -------- d-----w- c:\program files\LG PC Suite II
2009-09-04 09:50 . 2009-08-25 15:04 75264 ----a-w- c:\windows\system32\uc_holybeast_launching.dll
2009-09-04 09:44 . 2009-09-04 09:44 680 ----a-w- c:\users\c0c0tt£\AppData\Local\d3d9caps.dat
2009-09-02 20:03 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 20:03 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 17:21 . 2009-09-02 17:47 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-02 17:21 . 2009-09-02 17:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-27 21:47 . 2009-09-06 16:19 -------- d-----w- c:\users\Eric\AppData\Roaming\vlc
2009-08-27 12:10 . 2009-08-27 12:10 1024896 ----a-w- c:\users\Public\MyWebTattoo.exe
2009-08-26 15:02 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-21 21:11 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-21 21:11 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-21 21:11 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-21 21:11 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-21 21:11 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-21 21:11 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-21 21:11 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-21 21:11 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-21 11:11 . 2009-08-21 11:11 -------- d-----w- C:\Temp
2009-08-21 11:11 . 2009-07-02 22:34 83376 ----a-w- c:\temp\npijjiautoinstallpluginff.dll
2009-08-21 11:11 . 2009-06-23 11:21 64000 ----a-w- c:\windows\system32\uc_sfighters_launching.dll
2009-08-21 11:11 . 2009-03-11 16:20 208384 ----a-w- c:\windows\system32\uc_rohan_launching.dll
2009-08-21 11:11 . 2009-07-02 22:34 58800 ----a-w- c:\windows\system32\ijjiProcessRestarter.exe
2009-08-21 11:11 . 2009-07-01 08:25 61440 ----a-w- c:\windows\system32\uc_atlantica_launching.dll
2009-08-21 11:11 . 2009-03-31 15:43 53248 ----a-w- c:\windows\system32\uc_luminary_launching.dll
2009-08-21 11:11 . 2009-08-21 11:11 -------- d-----w- c:\program files\ijji
2009-08-21 11:08 . 2009-01-29 09:53 87472 ----a-w- c:\windows\system32\ijjiChannelingPlugin.dll
2009-08-17 17:08 . 2009-08-17 17:08 -------- d-----w- c:\users\c0c0tt£\AppData\Roaming\Malwarebytes
2009-08-12 07:43 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 07:43 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 07:43 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 07:43 . 2009-06-10 11:38 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 07:43 . 2009-07-15 12:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 07:43 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 07:43 . 2009-07-15 12:40 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 07:43 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-11 20:32 . 2009-08-11 20:34 162131 ----a-w- c:\windows\hpqins00.dat
2009-08-11 20:28 . 2009-08-11 20:28 -------- d-----w- c:\programdata\HP Product Assistant
2009-08-10 12:03 . 2009-08-10 12:03 230432 ----a-w- C:\PA207.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 16:16 . 2006-12-06 21:56 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-08 16:16 . 2006-12-06 21:56 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-08 14:57 . 2009-04-08 11:49 -------- d-----w- c:\programdata\Google Updater
2009-09-08 10:34 . 2009-04-03 10:10 -------- d--h--w- c:\users\Eric\AppData\Roaming\ijjigame
2009-09-07 20:13 . 2009-03-31 19:21 -------- d-----w- c:\users\Eric\AppData\Roaming\uTorrent
2009-09-06 10:05 . 2006-12-06 13:12 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-30 16:00 . 2009-06-21 10:33 -------- d-----w- c:\users\doune 4ever\AppData\Roaming\uTorrent
2009-08-30 14:40 . 2009-03-31 19:32 -------- d-----w- c:\users\Eric\AppData\Roaming\LimeWire
2009-08-23 16:59 . 2009-05-28 15:44 -------- d-----w- c:\users\Eric\AppData\Roaming\Spamihilator
2009-08-23 07:23 . 2009-06-01 08:32 -------- d-----w- c:\users\doune 4ever\AppData\Roaming\Spamihilator
2009-08-22 18:37 . 2009-04-04 17:13 -------- d-----w- c:\programdata\Roxio
2009-08-21 11:04 . 2009-05-29 10:14 -------- d-----w- c:\users\c0c0tt£\AppData\Roaming\Spamihilator
2009-08-19 14:49 . 2009-05-19 17:09 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-18 11:12 . 2009-03-31 19:22 -------- d-----w- c:\program files\uTorrent
2009-08-17 18:26 . 2009-05-15 11:24 680 ----a-w- c:\users\Eric\AppData\Local\d3d9caps.dat
2009-08-17 17:11 . 2009-06-19 14:28 -------- d-----w- c:\users\c0c0tt£\AppData\Roaming\uTorrent
2009-08-17 05:48 . 2009-04-02 09:16 158952 ----a-w- c:\windows\system32\PubPlugin.dll
2009-08-15 16:24 . 2009-04-02 09:14 92768 ----a-w- c:\users\c0c0tt£\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-13 14:50 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-10 16:27 . 2009-04-11 18:07 -------- d-----w- c:\users\doune 4ever\AppData\Roaming\LimeWire
2009-08-05 15:42 . 2009-03-31 19:31 -------- d-----w- c:\program files\Java
2009-08-05 15:22 . 2009-03-30 20:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-03 11:36 . 2009-03-30 20:10 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 11:36 . 2009-03-30 20:10 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 17:02 . 2009-08-01 17:02 -------- d-----w- c:\users\doune 4ever\AppData\Roaming\HP
2009-08-01 17:01 . 2009-05-15 11:52 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-27 18:45 . 2009-04-04 12:46 -------- d-----w- c:\users\Eric\AppData\Roaming\HP
2009-07-27 18:45 . 2009-04-04 07:45 146288 ----a-w- c:\windows\hpoins18.dat
2009-07-27 18:40 . 2009-04-04 07:43 -------- d-----w- c:\programdata\HP
2009-07-25 03:23 . 2009-03-31 19:31 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 18:20 . 2009-04-04 13:33 -------- d-----w- c:\users\Eric\AppData\Roaming\Image Zone Express
2009-07-24 17:09 . 2009-04-02 16:32 726 ----a-w- c:\users\Eric\AppData\Roaming\wklnhst.dat
2009-07-21 21:52 . 2009-07-28 17:28 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-28 17:28 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-28 17:28 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-28 17:28 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-16 16:12 . 2009-06-13 19:11 -------- d-----w- c:\users\Eric\AppData\Roaming\dvdcss
2009-07-14 20:07 . 2009-03-30 20:31 -------- d-----w- c:\program files\Windows Live
2009-07-14 20:06 . 2009-07-14 20:06 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-07-14 20:00 . 2009-07-14 20:00 -------- d-----w- c:\programdata\WLInstaller
2009-07-02 22:34 . 2009-04-02 09:16 710064 ----a-w- c:\windows\system32\ijjiSetup.exe
2009-07-02 22:34 . 2009-04-02 09:16 58800 ----a-w- c:\windows\system32\ijjiPlugin2.dll
2009-06-30 14:03 . 2009-03-31 12:39 92768 ----a-w- c:\users\doune 4ever\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-26 20:08 . 2009-03-30 15:36 92768 ----a-w- c:\users\Eric\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-15 17:27 . 2006-12-06 13:14 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-06-15 14:53 . 2009-07-15 10:55 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-15 10:55 23552 ----a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-15 10:55 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-15 10:55 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-15 10:55 289792 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-24 44136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Eric^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Notification de cadeaux MSN.lnk]
path=c:\users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notification de cadeaux MSN.lnk
backup=c:\windows\pss\Notification de cadeaux MSN.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e5,1f,bf,93,21,e2,c9,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{476CB903-C18C-4B59-AF0D-2A8D5758B342}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{49F56069-E6A2-414E-AB90-6DC1F8057A3D}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{39E4179A-A3B1-4BBB-924C-06D296DA5D16}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{AE1F472A-81F8-41AE-9929-EA8AE3A17607}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{E230A820-65E3-429D-8EFE-EED0CAC2A01E}"= UDP:c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{CA7AAC92-AB5D-4F04-B648-39EB36A62150}"= TCP:c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{85AC98B0-DBA3-45AC-B301-F6F72B3A5B07}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{81D2422E-034E-4D88-8194-3C10B46E2E42}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{EC01CB8B-6465-4DA2-AC2E-92E65E052176}"= UDP:c:\users\Eric\AppData\Local\Temp\7zSFAB3.tmp\SymNRT.exe:Norton Removal Tool
"{6CD4A42B-1352-4451-B116-A68488BB5E54}"= TCP:c:\users\Eric\AppData\Local\Temp\7zSFAB3.tmp\SymNRT.exe:Norton Removal Tool
"{0832280B-0E52-47CF-B22F-D2D5F9015629}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C94D2907-9BC5-4EFB-8165-0ABF11A4D6B6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8D8A7A62-C85B-4533-AE02-6FB462CD08DE}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{6E8C10D7-F1D1-4574-A9E2-9918E2448C86}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{88884B29-A537-4F07-ADF0-BDAA31F39A72}c:\\users\\c0c0tt£\\appdata\\local\\temp\\low\\plauncher.exe"= UDP:c:\users\c0c0tt£\appdata\local\temp\low\plauncher.exe:plauncher.exe
"UDP Query User{E09F4D82-3CF9-45F9-849E-CCF70A4EAB14}c:\\users\\c0c0tt£\\appdata\\local\\temp\\low\\plauncher.exe"= TCP:c:\users\c0c0tt£\appdata\local\temp\low\plauncher.exe:plauncher.exe
"{480B613D-D758-4B56-ACE3-097D7309B097}"= UDP:c:\users\Eric\AppData\Local\Temp\PurpleBean.exe:PurpleBean.exe
"{111E0BDD-13B5-4B7E-B32B-6DF62CCAC903}"= TCP:c:\users\Eric\AppData\Local\Temp\PurpleBean.exe:PurpleBean.exe
"TCP Query User{56D7B96F-C8CE-456A-AE01-1B3E53F3811B}c:\\ijji\\english\\u_sf\\soldierfront.exe"= UDP:c:\ijji\english\u_sf\soldierfront.exe:soldierfront
"UDP Query User{2CA0E115-217A-422D-95A2-68086A707DBE}c:\\ijji\\english\\u_sf\\soldierfront.exe"= TCP:c:\ijji\english\u_sf\soldierfront.exe:soldierfront
"{4C783668-7C28-49DD-A91E-D75B57AC9A33}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{908FC404-7466-449A-B10A-40362D677BAC}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{6F09F397-F015-409A-9169-EE92B9CAE9AC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6CFF1371-05D6-4DA0-9D1C-B85056F39BBB}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{5F0D5285-4CD7-4989-A628-D13C4436A6E9}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{6FCD3CA2-B206-4122-9B42-2399DC2817FA}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{0ABEEC61-3F9E-44AE-B0D7-834C45D8FB8E}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{B8AF817B-92DA-495B-B46A-A306B8C0348D}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{510378C0-87FF-4161-AF1F-346A39600682}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{801CD148-E448-408F-8BBE-A48305C80957}c:\\users\\public\\downloads\\utorrent\\utorrent.exe"= UDP:c:\users\public\downloads\utorrent\utorrent.exe:µTorrent
"UDP Query User{6BEE9C28-16A1-4E65-8011-15CDEAF1E08D}c:\\users\\public\\downloads\\utorrent\\utorrent.exe"= TCP:c:\users\public\downloads\utorrent\utorrent.exe:µTorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [19/05/2009 19:09 108289]
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [03/09/2006 11:32 208896]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [02/09/2009 19:21 1153368]
R3 PAC207;SoC PC-Camera;c:\windows\System32\drivers\PFC027.SYS [05/12/2006 11:34 507136]
S2 gupdate1c9b8409faafa10;Service Google Update (gupdate1c9b8409faafa10);c:\program files\Google\Update\GoogleUpdate.exe [08/04/2009 13:53 133104]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [10/05/2006 10:13 29696]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 17:13 234864]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-09-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-08 11:49]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 11:53]
2009-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-08 11:53]
2009-09-08 c:\windows\Tasks\User_Feed_Synchronization-{F58C3BD9-D22E-4361-89BA-BBA533EF6899}.job
- c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
.
.
------- Examen supplémentaire -------
.
uStart Page =
www.ijji.com
uDefault_Search_URL =
hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} -
hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27(...)
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-08 22:00
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-09-08 22:04
ComboFix-quarantined-files.txt 2009-09-08 20:04
Avant-CF: 131 994 865 664 octets libres
Après-CF: 132 757 225 472 octets libres
248 --- E O F --- 2009-09-08 09:51
-------
ben...
on sais pas tout !!