
rapport combofix
le pare feu m'a demandé de maintenir le blocage de flec006 , j'ai validé.
ComboFix 08-01-14.4 - Utilisateur 2008-01-17 17:32:26.8 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.139 [GMT 1:00]
Running from: H:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe
Command switches used :: H:\Documents and Settings\Utilisateur\Bureau\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\WINDOWS\system32\drivers\hldrrr.exe
H:\WINDOWS\system32\drivers\srosa.sys
H:\WINDOWS\system32\mdelk.exe
H:\WINDOWS\system32\wintems.exe
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\WINDOWS\system32\drivers\down\
H:\WINDOWS\system32\drivers\down\\100031.exe
H:\WINDOWS\system32\drivers\down\\100078.exe
H:\WINDOWS\system32\drivers\down\\100671.exe
H:\WINDOWS\system32\drivers\down\\100718.exe
H:\WINDOWS\system32\drivers\down\\101937.exe
H:\WINDOWS\system32\drivers\down\\102937.exe
H:\WINDOWS\system32\drivers\down\\103718.exe
H:\WINDOWS\system32\drivers\down\\105062.exe
H:\WINDOWS\system32\drivers\down\\105421.exe
H:\WINDOWS\system32\drivers\down\\111453.exe
H:\WINDOWS\system32\drivers\down\\113234.exe
H:\WINDOWS\system32\drivers\down\\113250.exe
H:\WINDOWS\system32\drivers\down\\115031.exe
H:\WINDOWS\system32\drivers\down\\115218.exe
H:\WINDOWS\system32\drivers\down\\116171.exe
H:\WINDOWS\system32\drivers\down\\116421.exe
H:\WINDOWS\system32\drivers\down\\117406.exe
H:\WINDOWS\system32\drivers\down\\117765.exe
H:\WINDOWS\system32\drivers\down\\118312.exe
H:\WINDOWS\system32\drivers\down\\118937.exe
H:\WINDOWS\system32\drivers\down\\118968.exe
H:\WINDOWS\system32\drivers\down\\119468.exe
H:\WINDOWS\system32\drivers\down\\120000.exe
H:\WINDOWS\system32\drivers\down\\120968.exe
H:\WINDOWS\system32\drivers\down\\124843.exe
H:\WINDOWS\system32\drivers\down\\124875.exe
H:\WINDOWS\system32\drivers\down\\126171.exe
H:\WINDOWS\system32\drivers\down\\126250.exe
H:\WINDOWS\system32\drivers\down\\126265.exe
H:\WINDOWS\system32\drivers\down\\127906.exe
H:\WINDOWS\system32\drivers\down\\128390.exe
H:\WINDOWS\system32\drivers\down\\128406.exe
H:\WINDOWS\system32\drivers\down\\128484.exe
H:\WINDOWS\system32\drivers\down\\129109.exe
H:\WINDOWS\system32\drivers\down\\129593.exe
H:\WINDOWS\system32\drivers\down\\130921.exe
H:\WINDOWS\system32\drivers\down\\131265.exe
H:\WINDOWS\system32\drivers\down\\131578.exe
H:\WINDOWS\system32\drivers\down\\132906.exe
H:\WINDOWS\system32\drivers\down\\134078.exe
H:\WINDOWS\system32\drivers\down\\134578.exe
H:\WINDOWS\system32\drivers\down\\135234.exe
H:\WINDOWS\system32\drivers\down\\14594406.exe
H:\WINDOWS\system32\drivers\down\\14619437.exe
H:\WINDOWS\system32\drivers\down\\14619687.exe
H:\WINDOWS\system32\drivers\down\\14620453.exe
H:\WINDOWS\system32\drivers\down\\14624593.exe
H:\WINDOWS\system32\drivers\down\\14635500.exe
H:\WINDOWS\system32\drivers\down\\14642296.exe
H:\WINDOWS\system32\drivers\down\\14646875.exe
H:\WINDOWS\system32\drivers\down\\14649218.exe
H:\WINDOWS\system32\drivers\down\\14649234.exe
H:\WINDOWS\system32\drivers\down\\14652406.exe
H:\WINDOWS\system32\drivers\down\\14653875.exe
H:\WINDOWS\system32\drivers\down\\14655375.exe
H:\WINDOWS\system32\drivers\down\\14656234.exe
H:\WINDOWS\system32\drivers\down\\14657953.exe
H:\WINDOWS\system32\drivers\down\\14679203.exe
H:\WINDOWS\system32\drivers\down\\14681218.exe
H:\WINDOWS\system32\drivers\down\\14682046.exe
H:\WINDOWS\system32\drivers\down\\14682218.exe
H:\WINDOWS\system32\drivers\down\\14682421.exe
H:\WINDOWS\system32\drivers\down\\14682640.exe
H:\WINDOWS\system32\drivers\down\\14683890.exe
H:\WINDOWS\system32\drivers\down\\14686046.exe
H:\WINDOWS\system32\drivers\down\\14749843.exe
H:\WINDOWS\system32\drivers\down\\14753375.exe
H:\WINDOWS\system32\drivers\down\\163593.exe
H:\WINDOWS\system32\drivers\down\\163609.exe
H:\WINDOWS\system32\drivers\down\\168109.exe
H:\WINDOWS\system32\drivers\down\\168140.exe
H:\WINDOWS\system32\drivers\down\\183171.exe
H:\WINDOWS\system32\drivers\down\\186531.exe
H:\WINDOWS\system32\drivers\down\\29161140.exe
H:\WINDOWS\system32\drivers\down\\29166171.exe
H:\WINDOWS\system32\drivers\down\\29167343.exe
H:\WINDOWS\system32\drivers\down\\29170203.exe
H:\WINDOWS\system32\drivers\down\\29173437.exe
H:\WINDOWS\system32\drivers\down\\29182734.exe
H:\WINDOWS\system32\drivers\down\\29187062.exe
H:\WINDOWS\system32\drivers\down\\29189281.exe
H:\WINDOWS\system32\drivers\down\\29189312.exe
H:\WINDOWS\system32\drivers\down\\29192921.exe
H:\WINDOWS\system32\drivers\down\\29195093.exe
H:\WINDOWS\system32\drivers\down\\29196859.exe
H:\WINDOWS\system32\drivers\down\\29200843.exe
H:\WINDOWS\system32\drivers\down\\29202546.exe
H:\WINDOWS\system32\drivers\down\\29210765.exe
H:\WINDOWS\system32\drivers\down\\29212609.exe
H:\WINDOWS\system32\drivers\down\\29213484.exe
H:\WINDOWS\system32\drivers\down\\29213718.exe
H:\WINDOWS\system32\drivers\down\\29213875.exe
H:\WINDOWS\system32\drivers\down\\29217078.exe
H:\WINDOWS\system32\drivers\down\\29218359.exe
H:\WINDOWS\system32\drivers\down\\29220609.exe
H:\WINDOWS\system32\drivers\down\\29248937.exe
H:\WINDOWS\system32\drivers\down\\29252546.exe
H:\WINDOWS\system32\drivers\down\\323093.exe
H:\WINDOWS\system32\drivers\down\\343500.exe
H:\WINDOWS\system32\drivers\down\\343531.exe
H:\WINDOWS\system32\drivers\down\\366078.exe
H:\WINDOWS\system32\drivers\down\\384265.exe
H:\WINDOWS\system32\drivers\down\\43661640.exe
H:\WINDOWS\system32\drivers\down\\43665296.exe
H:\WINDOWS\system32\drivers\down\\43665828.exe
H:\WINDOWS\system32\drivers\down\\43668156.exe
H:\WINDOWS\system32\drivers\down\\43672109.exe
H:\WINDOWS\system32\drivers\down\\43695734.exe
H:\WINDOWS\system32\drivers\down\\43703031.exe
H:\WINDOWS\system32\drivers\down\\43708984.exe
H:\WINDOWS\system32\drivers\down\\43711234.exe
H:\WINDOWS\system32\drivers\down\\43711265.exe
H:\WINDOWS\system32\drivers\down\\43718078.exe
H:\WINDOWS\system32\drivers\down\\43721390.exe
H:\WINDOWS\system32\drivers\down\\43723312.exe
H:\WINDOWS\system32\drivers\down\\43724562.exe
H:\WINDOWS\system32\drivers\down\\43726468.exe
H:\WINDOWS\system32\drivers\down\\43732765.exe
H:\WINDOWS\system32\drivers\down\\43734125.exe
H:\WINDOWS\system32\drivers\down\\43735156.exe
H:\WINDOWS\system32\drivers\down\\43735328.exe
H:\WINDOWS\system32\drivers\down\\43736187.exe
H:\WINDOWS\system32\drivers\down\\43736421.exe
H:\WINDOWS\system32\drivers\down\\43738000.exe
H:\WINDOWS\system32\drivers\down\\43739984.exe
H:\WINDOWS\system32\drivers\down\\43768515.exe
H:\WINDOWS\system32\drivers\down\\43771968.exe
H:\WINDOWS\system32\drivers\down\\55421.exe
H:\WINDOWS\system32\drivers\down\\58181984.exe
H:\WINDOWS\system32\drivers\down\\58191703.exe
H:\WINDOWS\system32\drivers\down\\58192125.exe
H:\WINDOWS\system32\drivers\down\\58319812.exe
H:\WINDOWS\system32\drivers\down\\58323156.exe
H:\WINDOWS\system32\drivers\down\\58326609.exe
H:\WINDOWS\system32\drivers\down\\58333781.exe
H:\WINDOWS\system32\drivers\down\\58340671.exe
H:\WINDOWS\system32\drivers\down\\58343312.exe
H:\WINDOWS\system32\drivers\down\\58343328.exe
H:\WINDOWS\system32\drivers\down\\58348656.exe
H:\WINDOWS\system32\drivers\down\\58351046.exe
H:\WINDOWS\system32\drivers\down\\58353437.exe
H:\WINDOWS\system32\drivers\down\\58354500.exe
H:\WINDOWS\system32\drivers\down\\58356359.exe
H:\WINDOWS\system32\drivers\down\\58362671.exe
H:\WINDOWS\system32\drivers\down\\58364750.exe
H:\WINDOWS\system32\drivers\down\\58365609.exe
H:\WINDOWS\system32\drivers\down\\58365828.exe
H:\WINDOWS\system32\drivers\down\\58366312.exe
H:\WINDOWS\system32\drivers\down\\58366484.exe
H:\WINDOWS\system32\drivers\down\\58368125.exe
H:\WINDOWS\system32\drivers\down\\58373890.exe
H:\WINDOWS\system32\drivers\down\\58405296.exe
H:\WINDOWS\system32\drivers\down\\58409687.exe
H:\WINDOWS\system32\drivers\down\\61515.exe
H:\WINDOWS\system32\drivers\down\\61890.exe
H:\WINDOWS\system32\drivers\down\\62671.exe
H:\WINDOWS\system32\drivers\down\\64218.exe
H:\WINDOWS\system32\drivers\down\\64546.exe
H:\WINDOWS\system32\drivers\down\\64656.exe
H:\WINDOWS\system32\drivers\down\\66828.exe
H:\WINDOWS\system32\drivers\down\\68656.exe
H:\WINDOWS\system32\drivers\down\\69250.exe
H:\WINDOWS\system32\drivers\down\\70000.exe
H:\WINDOWS\system32\drivers\down\\70312.exe
H:\WINDOWS\system32\drivers\down\\71187.exe
H:\WINDOWS\system32\drivers\down\\72359.exe
H:\WINDOWS\system32\drivers\down\\74468.exe
H:\WINDOWS\system32\drivers\down\\75531.exe
H:\WINDOWS\system32\drivers\down\\75781.exe
H:\WINDOWS\system32\drivers\down\\77843.exe
H:\WINDOWS\system32\drivers\down\\81656.exe
H:\WINDOWS\system32\drivers\down\\82531.exe
H:\WINDOWS\system32\drivers\down\\82578.exe
H:\WINDOWS\system32\drivers\down\\88921.exe
H:\WINDOWS\system32\drivers\down\\88968.exe
H:\WINDOWS\system32\drivers\down\\89812.exe
H:\WINDOWS\system32\drivers\down\\92484.exe
H:\WINDOWS\system32\drivers\down\\92656.exe
H:\WINDOWS\system32\drivers\down\\93281.exe
H:\WINDOWS\system32\drivers\down\\93625.exe
H:\WINDOWS\system32\drivers\down\\97531.exe
H:\WINDOWS\system32\drivers\down\\97843.exe
H:\WINDOWS\system32\drivers\down\\98093.exe
H:\WINDOWS\system32\drivers\down\\98859.exe
H:\WINDOWS\system32\drivers\down\\99953.exe
H:\WINDOWS\system32\drivers\hldrrr.exe
H:\WINDOWS\system32\drivers\srosa.sys
H:\WINDOWS\system32\mdelk.exe
H:\WINDOWS\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-17 to 2008-01-17 ))))))))))))))))))))))))))))))))))))
.
2008-01-16 21:46 . 2008-01-16 21:46 <REP> d-------- H:\Program Files\Avira
2008-01-16 21:46 . 2008-01-16 21:46 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Avira
2008-01-16 15:38 . 2008-01-16 15:38 4,608 --ahs---- H:\WINDOWS\system32\Thumbs.db
2008-01-16 14:51 . 2000-08-31 08:00 51,200 --a------ H:\WINDOWS\NirCmd.exe
2008-01-13 20:28 . 2008-01-13 20:28 <REP> d-------- H:\WINDOWS\system32\Kaspersky Lab
2008-01-13 16:41 . 2008-01-13 16:41 <REP> d-------- H:\Program Files\Chocolatier
2008-01-13 15:28 . 2008-01-16 22:54 <REP> d--h----- H:\Documents and Settings\Utilisateur\Application Data\m
2008-01-13 00:16 . 2008-01-13 00:16 <REP> d-------- H:\Deckard
2008-01-12 21:58 . 2008-01-12 22:06 <REP> d-------- H:\Program Files\Navilog1
2008-01-12 20:22 . 2008-01-12 20:22 <REP> d-------- H:\Program Files\Trend Micro
2008-01-12 17:58 . 2008-01-12 23:01 <REP> d-------- H:\WINDOWS\BDOSCAN8
2008-01-12 11:56 . 2008-01-12 11:56 <REP> d-------- H:\Documents and Settings\Utilisateur\Application Data\Valusoft
2008-01-12 11:56 . 2008-01-12 11:56 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Valusoft
2008-01-12 02:50 . 2008-01-12 02:50 <REP> d-------- H:\Program Files\Hot Dish
2008-01-11 12:34 . 2008-01-11 12:34 53,500 --a------ H:\adventure.dat
2008-01-10 12:45 . 2008-01-10 13:16 <REP> d-------- H:\Program Files\Super Granny 3
2008-01-05 17:33 . 2008-01-12 16:57 <REP> d-------- H:\Program Files\WildWestWendy
2008-01-05 13:37 . 2008-01-12 13:43 2,157 --a------ H:\WINDOWS\wwwconfig.dat
2008-01-02 16:17 . 2008-01-02 16:17 <REP> d-------- H:\Program Files\LightScribe
2008-01-02 16:15 . 2008-01-02 16:15 <REP> d-------- H:\Program Files\Fichiers communs\LightScribe
2007-12-23 09:53 . 2007-12-23 09:53 <REP> d-------- H:\Program Files\Dnote Software
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 22:29 --------- d-----w H:\Documents and Settings\Utilisateur\Application Data\SolidDocuments
2008-01-13 15:41 --------- d-----w H:\Documents and Settings\Utilisateur\Application Data\PlayFirst
2008-01-13 15:41 --------- d-----w H:\Documents and Settings\All Users\Application Data\PlayFirst
2008-01-12 17:34 --------- d-----w H:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-01-12 17:26 --------- d-----w H:\Documents and Settings\Utilisateur\Application Data\ViquaSoft
2008-01-12 17:24 --------- d-----w H:\Documents and Settings\Utilisateur\Application Data\Sandlot Games
2008-01-12 15:57 --------- d-----w H:\Program Files\TribalWeb.net
2008-01-12 15:57 --------- d-----w H:\Program Files\Traffic Jam Extreme
2008-01-12 15:57 --------- d-----w H:\Program Files\Slingo Quest
2008-01-12 15:57 --------- d-----w H:\Program Files\creation sonnerieMP3
2008-01-12 15:57 --------- d-----w H:\Program Files\Alien Shooter
2008-01-12 15:57 --------- d-----w H:\Program Files\Air Strike 2
2008-01-12 13:42 --------- d-----w H:\Program Files\Mulet
2008-01-12 12:01 --------- d---a-w H:\Documents and Settings\All Users\Application Data\TEMP
2008-01-10 11:48 --------- d-----w H:\Program Files\Fichiers communs\Sandlot Shared
2008-01-05 16:33 --------- d-----w H:\Program Files\Fichiers communs\Oberon Media
2007-12-21 10:19 --------- d-----w H:\Program Files\Virtual Villagers 2
2007-12-21 10:16 --------- d-----w H:\Program Files\Diner Dash Hometown Hero
2007-12-13 10:21 --------- d-----w H:\Program Files\DivX
2007-12-13 08:26 --------- d-----w H:\Program Files\Virtual Villagers
2007-12-11 09:03 --------- d-----w H:\Program Files\DestinatorApps
2007-12-11 07:15 --------- d-----w H:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-10 18:49 --------- d-----w H:\Program Files\Microsoft ActiveSync
2007-12-07 17:47 --------- d-----w H:\Program Files\Windows Live
2007-12-07 17:47 --------- d-----w H:\Program Files\MSN Messenger
2007-12-07 17:47 --------- d-----w H:\Program Files\Messenger Plus! Live
2007-12-01 00:32 --------- d-----w H:\Documents and Settings\All Users\Application Data\Fugazo
2007-11-29 22:30 43,528 ------w H:\WINDOWS\system32\drivers\PxHelp20.sys
2007-11-27 22:10 --------- d-----w H:\Program Files\Ricochet Infinity
2007-11-25 18:51 --------- d-----w H:\Documents and Settings\All Users\Application Data\Reflexive
.
(((((((((((((((((((((((((((((
snapshot@2008-01-16_20.04.58.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 13:52:02 1,425,408 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-17 16:31:05 1,425,408 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-16 13:52:02 8,192 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-17 16:31:05 8,192 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-16 13:52:02 1,425,408 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-17 16:31:06 1,425,408 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-16 13:52:02 8,192 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-17 16:31:06 8,192 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-16 13:52:03 10,256,384 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000005\NTUSER.DAT
+ 2008-01-17 16:31:06 10,280,960 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000005\NTUSER.DAT
- 2008-01-16 13:52:03 217,088 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-17 16:31:06 217,088 ----a-w H:\WINDOWS\ERDNT\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2007-08-09 12:04:11 40,768 ----a-w H:\WINDOWS\system32\drivers\avgntdd.sys
+ 2007-07-18 13:22:19 21,312 ----a-w H:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2007-09-07 11:05:19 62,016 ----a-w H:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 09:34:36 28,352 ----a-w H:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"swg"="H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"Philips Intelligent Agent"="H:\Program Files\Philips Intelligent Agent\Philips Intelligent Agent.exe" [2007-03-06 10:58 579760]
"LightScribe Control Panel"="H:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-12-05 12:30 2295072]
"H/PC Connection Agent"="H:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 14:07 1289000]
"SpybotSD TeaTimer"="H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"mule_st_key"="H:\Documents and Settings\Utilisateur\Application Data\m\flec006.exe" [2008-01-16 15:45 96772]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"LogitechCommunicationsManager"="H:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02 563984]
"LogitechQuickCamRibbon"="H:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06 2027792]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"SpybotSnD"="H:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [ ]
"avgnt"="H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoScreenShot.lnk]
path=H:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\AutoScreenShot.lnk
backup=H:\WINDOWS\pss\AutoScreenShot.lnkCommon Startup
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=H:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=H:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=H:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=H:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\H:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^BoontyBox 01net.lnk]
path=H:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\BoontyBox 01net.lnk
backup=H:\WINDOWS\pss\BoontyBox 01net.lnkStartup
[HKLM\~\startupfolder\H:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^TribalWeb.lnk]
path=H:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\TribalWeb.lnk
backup=H:\WINDOWS\pss\TribalWeb.lnkStartup
[HKLM\~\startupfolder\H:^Documents and Settings^Utilisateur^Menu Démarrer^Programmes^Démarrage^TribalWeb.net.lnk]
path=H:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage\TribalWeb.net.lnk
backup=H:\WINDOWS\pss\TribalWeb.net.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-09 10:09 63712 H:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 19:51 39792 H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2007-09-10 13:33 6338360 H:\Program Files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--------- 2004-08-19 16:10 110592 H:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ItLauncherAutoStart]
--a------ 2006-06-09 21:57 81983 H:\PROGRA~1\JEUXCL~1\bin\ITLAUN~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\L07FXLRD_157176703]
H:\Program Files\Microsoft Etudes\Microsoft Encarta 2007 - Études DVD\EDICT.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
H:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
--a------ 2007-07-25 15:02 563984 H:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideo[inspector]]
H:\Program Files\Logitech\Video\InstallHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
h:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
H:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 H:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-22 12:22 1622016 H:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
-r------- 2005-09-22 09:42 90112 H:\WINDOWS\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 2006-12-27 16:53 73840 H:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
H:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
H:\Program Files\Windows Defender\MSASCui.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Yahoo! Pager"="H:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
S3 Boonty Games;Boonty Games;"H:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" []
S3 LVPrcMon;Logitech LVPrcMon Driver;H:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-12-09 14:37]
S3 NPF;NetGroup Packet Filter Driver;H:\WINDOWS\system32\drivers\npf.sys [2005-08-02 22:10]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"H:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-10-18 12:24:49 H:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- H:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 18:56:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-17 19:00:40 - machine was rebooted [Utilisateur]
ComboFix-quarantined-files.txt 2008-01-17 18:00:37
ComboFix2.txt 2008-01-16 19:05:17
.
2007-12-11 07:15:18 --- E O F ---