coucou Bzhatao,
Rapport ComboFix:
ComboFix 09-01-13.04 - Informatique 2009-01-16 22:44:03.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2038.1553 [GMT 1:00]
Lancé depuis: c:\documents and settings\informatique\Bureau\ComboFix.exe
AV: Symantec Endpoint Protection *On-access scanning disabled* (Outdated)
* Un nouveau point de restauration a été créé
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\iq.bat
c:\windows\msvrc20.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-16 au 2009-01-16 ))))))))))))))))))))))))))))))))))))
.
2009-01-16 22:09 . 2009-01-16 22:09 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-01-16 22:08 . 2009-01-16 22:08 <REP> d-------- c:\windows\ERUNT
2009-01-16 22:04 . 2009-01-16 22:22 <REP> d-------- C:\SDFix
2009-01-16 10:45 . 2009-01-16 10:45 <REP> d-------- C:\46ac15ef8e23caac26af13fb3c0fb7
2009-01-16 08:16 . 2009-01-16 22:12 110,003 -r-hs---- C:\x2csvg.exe
2009-01-15 17:08 . 2009-01-15 17:13 <REP> d-------- c:\program files\Symantec
2009-01-15 17:08 . 2009-01-15 17:13 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-15 17:08 . 2009-01-15 17:13 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-01-15 17:08 . 2009-01-15 17:13 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-15 17:08 . 2009-01-15 17:13 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-01-15 14:26 . 2009-01-16 14:14 <REP> d-------- c:\program files\Scan
2009-01-15 09:33 . 2009-01-15 09:31 110,883 -r-hs---- C:\ve.exe
2009-01-15 09:33 . 2009-01-16 22:12 110,003 -r-hs---- c:\windows\system32\olhrwef.exe
2009-01-15 09:33 . 2009-01-16 22:25 95,744 -r-hs---- c:\windows\system32\nmdfgds0.dll
2009-01-14 14:26 . 2009-01-14 16:59 <REP> d-------- c:\documents and settings\informatique\.housecall6.6
2009-01-14 13:23 . 2009-01-16 19:28 95,744 -r-hs---- c:\windows\system32\nmdfgds1.dll
2009-01-13 16:33 . 2009-01-13 16:33 0 --a------ c:\windows\system32\tport.tmp
2009-01-13 16:33 . 2009-01-13 16:33 0 --a------ c:\windows\system32\shport.tmp
2009-01-13 16:33 . 2009-01-13 16:33 0 --a------ c:\windows\system32\pport.tmp
2009-01-13 16:00 . 2009-01-13 16:00 <REP> d-------- c:\documents and settings\informatique\DoctorWeb
2009-01-13 14:00 . 2009-01-14 10:51 <REP> d-------- c:\program files\UsbFix
2009-01-13 12:49 . 2009-01-13 13:48 <REP> d-------- c:\program files\a-squared Free
2009-01-13 11:49 . 2009-01-13 11:49 <REP> d-------- c:\documents and settings\informatique\Application Data\skypePM
2009-01-13 11:49 . 2009-01-13 11:49 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-01-13 08:57 . 2009-01-13 08:57 <REP> d-------- c:\program files\CCleaner
2009-01-12 14:58 . 2009-01-12 14:58 <REP> d-------- c:\documents and settings\informatique\Application Data\GlarySoft
2009-01-12 14:51 . 2009-01-12 14:51 <REP> d-------- c:\program files\Glary Utilities
2009-01-12 11:41 . 2008-04-14 03:34 70,656 --a------ c:\windows\AhnRpta.exe
2009-01-09 21:32 . 2009-01-09 23:12 <REP> d-------- c:\program files\EsetOnlineScanner
2009-01-09 20:45 . 2009-01-09 21:29 <REP> d-------- c:\windows\BDOSCAN8
2009-01-07 15:53 . 2009-01-07 15:53 <REP> d-------- c:\documents and settings\informatique\Application Data\OpenOffice.org
2009-01-03 23:03 . 2009-01-16 16:08 <REP> d-------- c:\documents and settings\informatique\Application Data\dvdcss
2008-12-24 13:33 . 2008-12-24 13:33 <REP> d-------- c:\documents and settings\LocalService\Application Data\TeamViewer
2008-12-23 13:59 . 2008-12-23 14:00 <REP> d-------- c:\documents and settings\All Users\Application Data\EPSON
2008-12-23 13:59 . 2006-08-10 02:02 75,264 --a------ c:\windows\system32\E_FLBBGE.DLL
2008-12-23 13:59 . 2006-04-19 02:00 62,976 --a------ c:\windows\system32\E_FD4BBGE.DLL
2008-12-23 13:59 . 2004-09-10 20:12 49,152 --a------ c:\windows\system32\E_DCINST.DLL
2008-12-21 11:53 . 2008-12-21 11:54 <REP> d-------- c:\documents and settings\informatique\Application Data\Dr. DivX 2.0 OSS
2008-12-18 15:10 . 2008-12-18 15:10 <REP> d-------- c:\documents and settings\informatique\Application Data\gtk-2.0
2008-12-18 15:10 . 2008-12-18 15:10 <REP> d-------- c:\documents and settings\informatique\.zenmap
2008-12-18 15:09 . 2008-12-18 15:09 <REP> d-------- c:\program files\WinPcap
2008-12-18 14:32 . 2008-12-18 14:32 <REP> d-------- c:\program files\Fichiers communs\Skype
2008-12-18 14:32 . 2009-01-13 14:03 <REP> d-------- c:\documents and settings\informatique\Application Data\Skype
2008-12-18 14:27 . 2008-12-18 14:28 <REP> d-------- c:\documents and settings\informatique\Application Data\vlc
2008-12-18 14:19 . 2008-12-18 14:19 <REP> d-------- c:\documents and settings\informatique\.bitrock
2008-12-18 14:17 . 2008-12-18 14:17 <REP> d-------- c:\program files\Secunia
2008-12-18 13:59 . 2008-09-02 15:02 <REP> d-------- c:\program files\PDF-XchangeViewerPortable
2008-12-18 08:42 . 2008-12-18 08:42 <REP> d-------- c:\program files\TeamViewer
2008-12-18 08:34 . 2008-12-18 08:34 <REP> d-------- c:\documents and settings\informatique\temp
2008-12-18 08:34 . 2008-12-19 14:18 <REP> d-------- c:\documents and settings\informatique\Application Data\TeamViewer
2008-12-17 10:34 . 2008-12-17 10:34 <REP> d-------- c:\documents and settings\informatique\Application Data\Foxit
2008-12-16 12:39 . 2008-12-16 12:39 <REP> d-------- c:\program files\IObit
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 15:10 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-16 13:59 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-16 09:42 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-15 16:13 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-01-15 16:09 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 09:38 --------- d-----w c:\program files\Alwil Software
2009-01-12 14:53 --------- d-----w c:\program files\eMule
2009-01-12 14:52 --------- d-----w c:\program files\Toshiba
2009-01-09 20:05 --------- d-----w c:\program files\Spyware Doctor
2009-01-09 19:43 --------- d-----w c:\program files\UltraVNC
2008-12-21 12:49 --------- d-----w c:\program files\DivX
2008-12-19 17:14 --------- d-----w c:\program files\BitComet
2008-12-18 14:02 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-18 13:20 --------- d-----w c:\program files\Java
2008-12-18 13:19 --------- d-----w c:\program files\iWizz
2008-12-13 12:32 --------- d-----w c:\program files\DAEMON Tools Pro
2008-12-11 11:24 --------- d-----w c:\program files\KoxoLogin
2008-12-11 11:21 --------- d-----w c:\documents and settings\informatique\Application Data\U3
2008-12-11 11:16 --------- d-----w c:\program files\OpenOffice.org 3
2008-12-11 11:16 --------- d-----w c:\program files\JRE
2008-12-11 11:15 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-10 14:17 7,808 ----a-w c:\windows\system32\drivers\psi_mf.sys
2008-12-10 10:39 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-10 09:12 --------- d-----w c:\program files\NetMeter
2008-12-09 16:06 43,386,048 ----a-w c:\program files\vnc
2008-12-09 12:26 --------- d-----w c:\program files\DipiSoft
2008-12-03 11:50 --------- d-----w c:\documents and settings\informatique\Application Data\OpenOffice.org2
2008-11-30 13:44 --------- d-----w c:\documents and settings\NDF\Application Data\Apple Computer
2008-11-28 13:04 --------- d-----w c:\documents and settings\informatique\Application Data\Apple Computer
2008-11-27 09:36 --------- d-----w c:\program files\PhotoshopCS3Portable
2008-11-24 12:35 --------- d-----w c:\program files\Realtek
2008-11-24 11:55 --------- d-----w c:\program files\Driver-Soft
2008-11-24 07:06 --------- d-----w c:\documents and settings\informatique\Application Data\Canneverbe_Limited
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
2008-10-28 16:18 17,331,200 ----a-w c:\windows\RTHDCPL.EXE
2008-10-27 17:12 34,816 ----a-w c:\windows\system32\RtkCoInstXP.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-03-31 14:08 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-12-12 09:13 32,768 ----a-w c:\documents and settings\All Users\Application Data\EBLib.dll
2006-07-28 14:25 19,456 ----a-w c:\documents and settings\All Users\Application Data\LPCFilter.sys
2008-09-02 06:41 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090220080903\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"cdoosoft"="c:\windows\system32\olhrwef.exe" [2009-01-16 110003]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-13 115560]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\informatique\Menu D‚marrer\Programmes\D‚marrage\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2008-12-17 748840]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4C402F-882A-4526-8C08-51278EA437C1}"= "c:\windows\system32\afmain1.dll" [2008-04-14 78848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^informatique^Menu Démarrer^Programmes^Démarrage^Ekiga.lnk]
backup=c:\windows\pss\Ekiga.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^informatique^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^informatique^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^informatique^Menu Démarrer^Programmes^Démarrage^Secunia PSI.lnk]
path=c:\documents and settings\informatique\Menu Démarrer\Programmes\Démarrage\Secunia PSI.lnk
backup=c:\windows\pss\Secunia PSI.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^NDF^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RayV
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2004-03-24 13:40 196608 c:\program files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
--a------ 2007-05-22 10:50 413696 c:\program files\Camera Assistant Software for Toshiba\traybar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarryLaunch]
--a------ 2008-04-16 16:54 45056 c:\documents and settings\informatique\Application Data\CoSoSys\CarryItEasy\CarryLaunch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CeEKEY]
--a------ 2007-07-06 05:49 651264 c:\program files\Toshiba\E-KEY\CeEKey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
--a------ 2008-10-09 13:53 200136 c:\program files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDWMon]
--a------ 2007-04-26 10:49 495616 c:\program files\Toshiba\TOSHIBA Direct Disc Writer\DDWMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus D78 Series]
--a------ 2006-09-22 04:01 139264 c:\windows\system32\spool\drivers\w32x86\3\E_FATIBGE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2009-01-12 16:33 119280 c:\documents and settings\informatique\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2007-06-01 23:13 162584 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup]
--a------ 2004-05-01 12:45 28672 c:\program files\Toshiba\TOSHIBA Applet\HWSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2007-06-01 23:13 142104 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2007-06-01 23:13 138008 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
--a------ 2008-06-12 11:54 1058304 c:\program files\Spyware Doctor\SDTrayApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2007-05-11 10:59 143360 c:\program files\Toshiba\Utilitaire de zoom TOSHIBA\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-12-10 11:39 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL]
--a------ 2006-05-25 10:17 65536 c:\program files\Toshiba\Windows Utilities\SVPWUTIL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-03 09:24 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
--a------ 2008-04-14 03:34 143872 c:\windows\system32\mobsync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\topi]
--a------ 2007-07-10 08:24 581632 c:\program files\Toshiba\Toshiba Online Product Information\TOPI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2005-04-11 15:08 65536 c:\program files\Toshiba\TOSCDSPD\TOSCDSPD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPNF]
--a------ 2007-06-01 04:40 53248 c:\program files\Toshiba\TouchPad\TPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2008-06-19 16:20 57344 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2008-10-28 17:18 17331200 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TCtryIOHook]
--a------ 2007-06-30 07:18 28672 c:\windows\system32\TCtrlIOHook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TDispVol]
--a------ 2005-12-27 12:06 73728 c:\windows\system32\TDispVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
--a------ 2005-08-12 10:14 266240 c:\windows\system32\TPSMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zooming]
--a------ 2005-06-06 08:58 24576 c:\windows\system32\ZoomingHook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\DipiSoft\\IPScan32\\IPScan32.exe"=
"c:\\Program Files\\DipiSoft\\WakeOnLan\\WakeOnLan.exe"=
"c:\\Documents and Settings\\informatique\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Documents and Settings\\informatique\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\informatique\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11091:TCP"= 11091:TCP:BitComet 11091 TCP
"11091:UDP"= 11091:UDP:BitComet 11091 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-01-15 112688]
R4 acedrv10;acedrv10;c:\windows\system32\drivers\ACEDRV10.sys [2007-07-27 330144]
R4 acehlp10;acehlp10;c:\windows\system32\drivers\acehlp10.sys [2007-07-27 251680]
R4 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R4 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2007-03-26 105856]
R4 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2007-02-19 134016]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-04-17 1527900]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
S3 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-06-01 34064]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-12-10 7808]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [2008-06-12 742216]
S3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys --> c:\windows\system32\DRIVERS\TpChoice.sys [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30a9a8f4-8a00-11dd-9eba-001cbfb90d95}]
\Shell\AutoRun\command - F:\x2csvg.exe
\Shell\open\Command - F:\x2csvg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{55fb46fa-014c-11dd-9e06-001cbfb90d95}]
\Shell\AutoRun\command - G:\x2csvg.exe
\Shell\open\Command - G:\x2csvg.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-16 c:\windows\Tasks\User_Feed_Synchronization-{5CC33BBA-EED8-437E-99B4-44AD2732FCCE}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-Symantec Antvirus
MSConfigStartUp-vamsoft - c:\windows\system32\vamsoft.exe
MSConfigStartUp-CFSServ - CFSServ.exe
MSConfigStartUp-NDSTray - NDSTray.exe
MSConfigStartUp-TFncKy - TFncKy.exe
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {CAEEBB25-834B-496F-8A19-B23474ADB2B4} = 194.206.126.253,208.67.222.222
c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe
c:\windows\Downloaded Program Files\live.ini
c:\windows\Downloaded Program Files\scanoptions.tsi
c:\windows\Downloaded Program Files\lang.ini
c:\windows\Downloaded Program Files\ipsupd.dll
c:\windows\Downloaded Program Files\bdupd.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\oscan8.ocx
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
c:\windows\Downloaded Program Files\oscan8.inf
FF - ProfilePath - c:\documents and settings\informatique\Application Data\Mozilla\Firefox\Profiles\6ze83rr2.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - component: c:\documents and settings\informatique\Application Data\Mozilla\Firefox\Profiles\6ze83rr2.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\documents and settings\informatique\Application Data\Mozilla\Firefox\Profiles\6ze83rr2.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\documents and settings\informatique\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\informatique\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-connections-per-server - 6
FF - user.js: network.http.max-persistent-connections-per-server - 3
FF - user.js: content.max.tokenizing.time - 1500000
FF - user.js: content.notify.interval - 750000
FF - user.js: nglayout.initialpaint.delay - 100
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-16 22:45:12
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
Heure de fin: 2009-01-16 22:46:21
ComboFix-quarantined-files.txt 2009-01-16 21:46:19
Avant-CF: 121 336 975 360 octets libres
Après-CF: 121,350,582,272 octets libres
335 --- E O F --- 2009-01-15 07:06:43
merci !