voici le rapport que tu voulez
ComboFix 09-11-14.03 - 15 a la maison 14/11/2009 19:51..2 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1023.512 [GMT 1:00]
Lancé depuis: c:\documents and settings\15 a la maison\Bureau\bibite.exe
AV: avast! antivirus 4.8.1296 [VPS 091114-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents
c:\recycler\S-1-5-21-3666069656-9942426852-160582229-9780
c:\recycler\S-1-5-21-4337183070-5843590703-512275209-8281
c:\recycler\S-1-5-21-8290232482-6836887964-143895658-2613
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EPSON_EB_RPCV4_01
-------\Legacy_EPSON_PM_RPCV4_01
-------\Service_EPSON_EB_RPCV4_01
-------\Service_EPSON_PM_RPCV4_01
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-14 au 2009-11-14 ))))))))))))))))))))))))))))))))))))
.
2009-11-13 17:39 . 2009-11-13 17:39 -------- d-----w- c:\program files\Free Offers from Freeze.com
2009-11-13 17:34 . 2009-11-13 17:34 -------- d-----w- c:\program files\YouTUBE (TM) movie downloader
2009-11-05 17:35 . 2009-11-05 17:35 -------- d-----w- c:\windows\Performance
2009-11-05 17:35 . 2009-11-05 17:35 -------- d-----w- c:\documents and settings\15 a la maison\Local Settings\Application Data\Microsoft Corporation
2009-11-05 17:34 . 2009-11-05 17:34 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-05 17:25 . 2009-11-05 17:25 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-11-05 17:25 . 2009-11-05 17:27 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-05 13:07 . 2009-11-06 16:31 -------- d-----w- c:\documents and settings\15 a la maison\Local Settings\Application Data\WMTools Downloaded Files
2009-11-03 20:23 . 2009-11-05 05:56 -------- d-----w- C:\Temp
2009-11-01 16:18 . 2009-11-01 16:22 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\SoundSpectrum
2009-11-01 16:18 . 2009-11-01 16:18 -------- d-----w- c:\program files\SoundSpectrum
2009-11-01 14:14 . 2009-11-01 14:53 -------- d-----w- c:\windows\BDOSCAN8
2009-10-31 18:48 . 2009-10-31 18:50 -------- d-----w- C:\ToolBar SD
2009-10-30 11:10 . 2009-10-30 11:10 1183176 ----a-w- c:\documents and settings\15 a la maison\Application Data\Mozilla\Firefox\Profiles\q3vg7aks.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2009-10-29 16:51 . 2009-10-29 16:51 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\Malwarebytes
2009-10-29 16:50 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-29 16:50 . 2009-10-29 16:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-29 16:50 . 2009-10-29 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-29 16:50 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 23:35 . 2006-03-02 12:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-10-28 23:35 . 2009-10-28 23:35 40960 ----a-r- c:\documents and settings\15 a la maison\Application Data\Microsoft\Installer\{C179292C-735A-47EC-AD6D-AC6C6BE20017}\ARPPRODUCTICON.exe
2009-10-28 23:35 . 2009-10-28 23:35 327680 ----a-r- c:\documents and settings\15 a la maison\Application Data\Microsoft\Installer\{C179292C-735A-47EC-AD6D-AC6C6BE20017}\NewShortcut2_439CCEF89767436AB00754ACFDCFF417.exe
2009-10-28 23:35 . 2009-10-28 23:35 -------- d-----w- c:\program files\VirginMega
2009-10-28 23:35 . 2009-10-28 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-10-28 23:33 . 2009-10-28 23:33 -------- d-----w- c:\program files\Windows Media Connect 2
2009-10-28 23:32 . 2009-10-28 23:32 -------- d-----w- c:\windows\system32\LogFiles
2009-10-28 17:41 . 2009-10-28 17:50 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-10-28 09:29 . 2009-10-29 08:30 882 ----a-w- c:\windows\system32\wininit.dll
2009-10-27 22:51 . 2009-10-27 23:08 -------- d-----w- c:\program files\Pcsx2
2009-10-27 18:53 . 2009-11-03 15:58 -------- d-----w- c:\program files\Navilog1
2009-10-27 18:50 . 2009-10-27 18:50 -------- d-----w- c:\program files\Trend Micro
2009-10-27 17:58 . 2009-10-27 17:58 450560 ----a-w- c:\documents and settings\15 a la maison\Local Settings\Application Data\fmued.exe
2009-10-27 17:03 . 2009-10-27 17:03 450560 ----a-w- c:\documents and settings\15 a la maison\Local Settings\Application Data\celhvrgd.exe
2009-10-27 14:08 . 2008-06-14 17:59 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-10-27 14:04 . 2009-08-04 17:05 2059776 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-27 14:04 . 2009-08-04 17:05 2182400 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-27 14:04 . 2009-08-04 17:05 2138112 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-27 14:04 . 2009-08-04 17:05 2017792 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-27 13:59 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-27 12:36 . 2006-03-02 12:00 15360 -c--a-w- c:\windows\system32\dllcache\register.exe
2009-10-27 12:35 . 2006-03-02 12:00 10096640 -c--a-w- c:\windows\system32\dllcache\hwxcht.dll
2009-10-27 12:34 . 2006-03-02 12:00 68608 -c--a-w- c:\windows\system32\dllcache\isatq.dll
2009-10-27 12:32 . 2006-03-02 12:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-10-27 12:25 . 2004-08-03 21:31 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2009-10-27 12:21 . 2006-03-02 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-27 12:21 . 2006-03-02 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-10-27 12:21 . 2006-03-02 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-27 12:21 . 2006-03-02 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-10-26 11:52 . 2008-04-14 02:33 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-10-26 11:33 . 2009-10-26 11:33 -------- d-----w- c:\windows\l2schemas
2009-10-26 11:33 . 2009-10-26 11:33 -------- d-----w- c:\windows\system32\fr
2009-10-26 11:33 . 2009-10-26 11:33 -------- d-----w- c:\windows\system32\bits
2009-10-22 16:06 . 2009-10-22 16:06 -------- d-----w- c:\windows\system32\cvirte
2009-10-22 16:05 . 2009-10-22 16:06 -------- d-----w- c:\program files\Fichiers communs\Merge Modules
2009-10-22 16:05 . 2009-10-22 16:07 -------- d-----w- c:\program files\National Instruments
2009-10-19 16:53 . 2009-10-19 16:53 -------- d-----w- c:\program files\GlobFX Technologies
2009-10-18 18:44 . 2009-10-18 18:46 -------- d-----w- C:\Lyrics
2009-10-18 18:44 . 2009-10-18 18:48 -------- d-----w- c:\program files\Minilyrics
2009-10-18 18:34 . 2009-10-18 18:41 -------- d-----w- c:\program files\KaraFun
2009-10-16 16:59 . 2009-10-16 16:59 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\Jasc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-14 18:46 . 2009-09-05 12:11 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\vlc
2009-11-14 17:52 . 2009-09-06 12:00 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\dvdcss
2009-11-12 21:59 . 2009-09-05 17:54 -------- d-----w- c:\program files\Steam
2009-11-11 12:24 . 2009-09-05 12:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-05 17:25 . 2009-09-22 19:34 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-05 17:25 . 2009-09-22 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-11-04 20:38 . 2009-09-05 14:51 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\EPSON
2009-10-31 01:26 . 2006-03-02 12:00 81352 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-31 01:26 . 2006-03-02 12:00 503386 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-27 12:48 . 2009-09-04 23:46 73552 ----a-w- c:\documents and settings\15 a la maison\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-27 12:31 . 2009-09-04 22:32 23016 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-26 11:36 . 2009-09-04 22:35 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-18 11:47 . 2009-09-05 20:14 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-10-14 19:26 . 2009-10-14 19:26 276846 ----a-w- c:\windows\PC Video Converter Studio Uninstaller.exe
2009-10-14 19:26 . 2009-10-14 19:26 -------- d-----w- c:\program files\PC Video Converter Studio
2009-10-13 17:00 . 2009-10-13 17:00 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-13 17:00 . 2009-09-05 21:03 152576 ----a-w- c:\documents and settings\15 a la maison\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-13 06:23 . 2009-09-05 12:21 -------- d-----w- c:\program files\Microsoft Works
2009-10-08 21:24 . 2009-10-08 21:24 -------- d-----w- c:\program files\Alwil Software
2009-10-01 17:08 . 2009-09-06 11:00 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\BitTorrent
2009-10-01 16:40 . 2009-10-01 16:40 73728 ----a-w- c:\windows\ALCFDRTM.EXE
2009-09-29 20:58 . 2009-09-29 20:58 -------- d-----w- c:\program files\Bosch
2009-09-28 17:29 . 2009-09-28 17:29 -------- d-----w- c:\program files\Fichiers communs\EZB Systems
2009-09-28 17:29 . 2009-09-28 17:29 -------- d-----w- c:\program files\UltraISO
2009-09-28 16:20 . 2009-09-04 23:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-27 19:32 . 2009-09-16 21:15 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\OneSwarm
2009-09-27 18:17 . 2009-09-18 15:48 -------- d-----w- c:\program files\Notepad++
2009-09-25 05:54 . 2006-03-02 12:00 666112 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:54 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-24 20:49 . 2009-09-24 20:49 -------- d-----w- c:\program files\Fichiers communs\Macrovision Shared
2009-09-24 17:59 . 2009-09-13 08:35 -------- d-----w- c:\program files\Auralog
2009-09-23 22:35 . 2009-09-23 22:35 -------- d-----w- c:\program files\MSECache
2009-09-23 19:07 . 2009-09-23 19:07 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-09-23 19:07 . 2009-09-23 19:07 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-09-23 18:35 . 2009-09-23 18:27 -------- d-----w- c:\program files\Electronic Arts
2009-09-22 21:22 . 2009-09-13 20:38 -------- d-----w- c:\program files\SFRWidget
2009-09-22 21:03 . 2009-09-22 20:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-09-22 19:41 . 2009-09-22 19:41 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-22 19:40 . 2009-09-22 19:34 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\DAEMON Tools Lite
2009-09-19 09:58 . 2009-09-05 14:33 -------- d-----w- c:\program files\epson
2009-09-18 23:28 . 2009-09-18 23:28 14 ----a-w- c:\windows\popcinfo.dat
2009-09-18 22:35 . 2009-09-18 22:35 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\Zylom
2009-09-18 22:35 . 2009-09-18 22:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2009-09-18 15:48 . 2009-09-18 15:48 -------- d-----w- c:\documents and settings\15 a la maison\Application Data\Notepad++
2009-09-17 19:44 . 2009-09-08 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-09-16 21:29 . 2009-09-16 21:15 -------- d-----w- c:\program files\OneSwarm
2009-09-11 15:02 . 2009-09-11 15:01 24 --sha-w- c:\windows\S9A5F134A.tmp
2009-09-11 14:34 . 2006-03-02 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 14:43 . 2009-09-09 14:43 826856 ----a-w- c:\documents and settings\15 a la maison\Application Data\MSNInstaller\msnauins.exe
2009-09-06 12:13 . 2009-09-05 13:19 36864 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\PostBuild.exe
2009-09-05 21:50 . 2009-09-05 21:50 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-09-05 21:00 . 2009-09-05 20:59 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-09-05 19:51 . 2009-09-05 19:51 86576 ----a-w- c:\documents and settings\15 a la maison\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2009-09-05 19:51 . 2009-09-05 19:51 392728 ----a-w- c:\documents and settings\15 a la maison\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2009-09-05 19:51 . 2009-09-05 19:51 135680 ----a-w- c:\documents and settings\15 a la maison\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
2009-09-05 19:51 . 2009-09-05 19:51 132672 ----a-w- c:\documents and settings\15 a la maison\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2009-09-05 13:18 . 2009-09-05 13:18 53319 ----a-w- c:\documents and settings\All Users\Application Data\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}\PostBuild.exe
2009-09-04 23:25 . 2009-09-04 23:25 0 ----a-w- c:\windows\ativpsrm.bin
2009-09-04 22:52 . 2009-09-04 22:52 0 ----a-w- c:\windows\nsreg.dat
2009-09-04 20:46 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:15 . 2006-03-02 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 21:33 . 2009-08-17 21:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2005-10-12 14:04 . 2005-10-12 14:04 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-25 61440]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-05-07 591696]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-13 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-17 61952]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-10-13 77824]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\ALCWZRD.EXE [2004-10-13 2742272]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\15 a la maison\Menu D‚marrer\Programmes\D‚marrage\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
[HKLM\~\startupfolder\C:^Documents and Settings^15 a la maison^Menu Démarrer^Programmes^Démarrage^Widget SFR.lnk]
path=c:\documents and settings\15 a la maison\Menu Démarrer\Programmes\Démarrage\Widget SFR.lnk
backup=c:\windows\pss\Widget SFR.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Hyperappel du Petit Larousse 2010.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Hyperappel du Petit Larousse 2010.lnk
backup=c:\windows\pss\Hyperappel du Petit Larousse 2010.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\EpsonNet\\EpsonNet Config V3\\ENConfig.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\cslegnacs\\condition zero\\hl.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Larousse\\Petit Larousse 2010\\bin\\Hyperappel.exe"=
"c:\\Program Files\\SFRWidget\\WidgetSFR.exe"=
"c:\\Program Files\\OneSwarm\\OneSwarm.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Steam\\steamapps\\cslegnacs\\day of defeat\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [08/10/2009 22:24 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [08/10/2009 22:24 20560]
R2 EpsonCustomerResearchParticipation;EpsonCustomerResearchParticipation;c:\program files\epson\EpsonCustomerResearchParticipation\EPCP.exe [29/10/2008 10:00 92048]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Fichiers communs\Microsoft Shared\Windows Live\WLIDSVC.EXE [30/03/2009 16:28 1533808]
R3 PhTVTune;Philips WDM TV Tuner;c:\windows\system32\drivers\PhTVTune.sys [05/09/2009 14:00 14624]
S3 getPlusHelper;getPlus(R) Helper;c:\windows\System32\svchost.exe -k getPlusHelper [02/03/2006 13:00 14336]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenu du dossier 'Tâches planifiées'
2009-10-25 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.1.0.3\DriverRobot.exe [2009-09-04 11:30]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search/?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\15 a la maison\Application Data\Mozilla\Firefox\Profiles\q3vg7aks.default\
FF - prefs.js: browser.startup.homepage - google.fr
FF - prefs.js: keyword.URL -
hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&(...)
FF - component: c:\documents and settings\15 a la maison\Application Data\Mozilla\Firefox\Profiles\q3vg7aks.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - component: c:\documents and settings\15 a la maison\Application Data\Mozilla\Firefox\Profiles\q3vg7aks.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 50
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-14 20:04
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x867D71F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x867d71f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(588)
c:\windows\system32\Ati2evxx.dll
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(3296)
c:\program files\Windows Media Player\wmpband.dll
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Fichiers communs\Microsoft Shared\Windows Live\WLIDSvcM.exe
.
**************************************************************************
.
Heure de fin: 2009-11-14 20:09 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-14 19:09
Avant-CF: 99 590 529 024 octets libres
Après-CF: 99 527 811 072 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 37D5CB70FC0501D8A12B9D396348D7B3