Salut dedetraqué
je ne sais pas comment vous remercier.
le programme a marché sans probleme et à la fin du scan, j'ai redemaré la machine et le resultat
a ete impeccable ( le bouton rechercher fonctionne correctement) sauf que le bouton executer
apparait toujours pendant 2 secones mais ce n'est pas grave.
bonne journnée à toi et que le Seigneur vous benisse.
@++
voici le resultat de combofix:
ComboFix 08-11-01.01 - famille 2008-11-01 23:23:23.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.228 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\famille\Bureau\ComboFix.exe
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\famille\Local Settings\Temporary Internet Files\artmod_jewel_expand.GIF
C:\Documents and Settings\famille\Local Settings\Temporary Internet Files\t641945a.jpg
C:\Documents and Settings\famille\Menu Démarrer\VIP Casino.url
C:\WINDOWS\Cursors\Boom.vbs
C:\WINDOWS\Help\Microsoft.hlp
C:\WINDOWS\Media\rndll32.pif
C:\WINDOWS\pchealth\Global.exe
C:\WINDOWS\system\KEYBOARD.exe
C:\WINDOWS\system32\dllcache\Default.exe
C:\WINDOWS\system32\dllcache\Global.exe
C:\WINDOWS\system32\dllcache\rndll32.exe
C:\WINDOWS\system32\dllcache\tskmgr.exe
C:\WINDOWS\system32\drivers\drivers.cab.exe
C:\WINDOWS\system32\mdm.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-01 au 2008-11-01 ))))))))))))))))))))))))))))))))))))
.
2036-02-07 02:58 . 2008-07-29 22:24 <REP> dr------- C:\VIDEO_TS
2036-02-07 02:58 . 2036-02-07 02:58 <REP> dr------- C:\AUDIO_TS
2008-11-01 23:03 . 2008-11-01 23:26 <REP> d-------- C:\Documents and Settings\famille\Application Data\Free Download Manager
2008-11-01 23:03 . 2008-11-01 23:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2008-10-31 09:51 . 2008-10-31 09:51 <REP> d-------- C:\tmp
2008-10-31 09:49 . 2008-10-31 09:49 <REP> d-------- C:\YouTubeGet
2008-10-30 21:10 . 2008-10-30 21:10 <REP> d-------- C:\Eidos
2008-10-29 23:11 . 2008-10-29 23:11 <REP> d-------- C:\Program Files\RocketDock
2008-10-29 22:16 . 2008-10-29 22:25 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-29 22:16 . 2008-10-29 22:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-29 22:05 . 2008-10-29 22:05 <REP> d-------- C:\Program Files\P2P_Energy
2008-10-29 22:05 . 2008-10-29 22:05 <REP> d-------- C:\Program Files\Conduit
2008-10-29 22:04 . 2008-10-29 22:09 <REP> d-------- C:\Program Files\Morpheus Music
2008-10-29 19:46 . 2008-10-29 19:46 <REP> d-------- C:\Documents and Settings\famille\Application Data\Malwarebytes
2008-10-29 19:45 . 2008-10-29 19:46 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-29 19:45 . 2008-10-29 19:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-29 19:45 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-29 19:45 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-28 18:01 . 2008-10-28 18:01 <REP> d-------- C:\Program Files\Boonty
2008-10-28 17:50 . 2005-08-27 02:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-10-28 17:50 . 2004-03-08 23:00 131,856 --a------ C:\WINDOWS\system32\MSADODC.ocx
2008-10-28 17:50 . 2000-12-05 23:00 109,248 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-10-28 17:50 . 2000-07-15 05:00 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2008-10-27 06:32 . 2005-10-20 05:59 81,920 --a------ C:\WINDOWS\system32\ImageDrive.cpl
2008-10-24 22:43 . 2008-10-24 22:43 <REP> d-------- C:\Program Files\Alwil Software
2008-10-24 22:21 . 2008-10-29 21:49 <REP> d-------- C:\Program Files\trend micro
2008-10-24 21:08 . 2008-02-12 17:32 225,280 -rahsc--- C:\WINDOWS\system32\dllcache\svchost.exe
2008-10-22 21:49 . 2008-10-24 18:37 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-22 21:29 . 2008-10-22 21:29 <REP> d-------- C:\Program Files\AVG
2008-10-22 21:18 . 2008-10-22 21:18 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2008-10-22 21:00 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-10-22 21:00 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-10-22 21:00 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-10-22 21:00 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-10-22 21:00 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-10-22 21:00 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-10-22 21:00 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-10-22 06:54 . 2008-10-22 06:54 <REP> d-------- C:\Program Files\Microsoft Picture It! 7
2008-10-22 06:23 . 2008-10-22 06:23 3,072 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-10-17 15:43 . 2008-10-17 15:43 1,032 --a------ C:\WINDOWS\_profsect_0001.tmp
2008-10-17 15:25 . 2008-10-17 15:25 <REP> d-------- C:\Documents and Settings\famille\Application Data\IMSI
2008-10-17 15:22 . 2008-10-17 15:22 <REP> d-------- C:\Program Files\Common Files
2008-10-17 15:22 . 2008-10-17 15:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\IMSI
2008-10-17 15:20 . 2008-10-17 15:21 <REP> d-------- C:\Program Files\TurboCAD Professionnel v11.2 Setup
2008-10-12 21:38 . 2008-10-12 21:38 <REP> d-------- C:\EP6E
2008-10-11 15:22 . 2008-10-11 15:22 <REP> d-------- C:\Program Files\Component Factory Pty Ltd
2008-10-11 15:22 . 2008-10-11 15:22 <REP> d-------- C:\Documents and Settings\famille\Application Data\Component Factory
2008-10-04 06:55 . 2008-10-04 06:55 <REP> d--hs---- C:\Sites Favoris
2008-10-04 06:55 . 2008-10-06 18:38 <REP> d--hs---- C:\Downloads
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 22:21 --------- d-----w C:\Documents and Settings\famille\Application Data\TeraCopy
2008-11-01 22:03 --------- d-----w C:\Program Files\Free Download Manager
2008-11-01 06:49 --------- d-----w C:\Program Files\Total Video Converter
2008-10-29 21:05 --------- d-----w C:\Documents and Settings\famille\Application Data\Shareaza
2008-10-24 21:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-24 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-21 21:06 --------- d-----w C:\Program Files\Pool 'm Up
2008-10-20 08:45 --------- d-----w C:\Documents and Settings\famille\Application Data\KIMS
2008-10-19 16:37 --------- d-----w C:\Documents and Settings\famille\Application Data\Image Zone Express
2008-10-17 14:22 --------- d-----w C:\Program Files\IMSI
2008-10-16 18:52 --------- d-----w C:\Program Files\Zuma Deluxe
2008-10-14 20:56 545,280 ----a-w C:\WINDOWS\flashax.exe
2008-10-14 20:56 12,288 ----a-w C:\WINDOWS\impborl.dll
2008-10-11 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-29 21:31 998,873 ----a-w C:\WINDOWS\system32\Desperate Housewives.scr
2008-09-27 09:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avanquest Software
2008-09-24 22:58 107,132 ----a-w C:\WINDOWS\UninstallFirefox.exe
2008-09-20 19:16 1,017,801 ----a-w C:\WINDOWS\system32\LOST.scr
2008-09-20 19:09 1,014,754 ----a-w C:\WINDOWS\system32\Prison Break.scr
2008-09-18 16:22 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2008-09-10 20:27 --------- d-----w C:\Program Files\RSS Xpress
2008-09-10 18:56 --------- d-----w C:\Documents and Settings\famille\Application Data\Bull
2008-09-10 04:54 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-08 22:13 --------- d-----w C:\Program Files\BuildSoft
2008-09-08 14:06 --------- d-----w C:\Program Files\SPMP3050 Transcoding Tool
2008-09-08 14:05 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-04 22:56 --------- d-----w C:\Documents and Settings\famille\Application Data\dvdcss
2008-09-04 22:46 --------- d-----w C:\Documents and Settings\famille\Application Data\Ahead
2008-09-04 20:27 --------- d-----w C:\Program Files\Nero
2008-09-04 20:27 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-09-04 19:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-09-04 18:18 --------- d-----w C:\Documents and Settings\famille\Application Data\Autodesk
2008-09-04 18:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-09-04 10:07 --------- d-----w C:\Program Files\foXtaDemo
2008-09-01 05:53 --------- d-----w C:\Program Files\Dictionnaire
2008-08-25 18:16 516 ---ha-w C:\os847477.bin
2008-07-13 23:45 24,192 ----a-w C:\Documents and Settings\famille\usbsermptxp.sys
2008-07-13 23:45 22,768 ----a-w C:\Documents and Settings\famille\usbsermpt.sys
2008-02-12 09:06 445,952 ---h--r C:\WINDOWS\inf\chiCkie.exe
2008-02-12 16:32 225,280 -csha-r C:\WINDOWS\system32\dllcache\svchost.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "C:\Program Files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-09-15 06:47 1784856 --a------ C:\Program Files\P2P_Energy\tbP2P_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "C:\Program Files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "C:\Program Files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"L08FXLRD_1982546"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" [2007-06-12 351000]
"I just want to say I love Milko and I need a drink"="C:\Documents and Settings\famille\Local Settings\Application Data\svchost.exe" [2008-02-12 445952]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2005-04-08 512000]
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2005-07-26 184408]
"USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 65536]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"chiCkie"="C:\WINDOWS\inf\chiCkie.exe" [2008-02-12 445952]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"VTTimer"="VTTimer.exe" [2005-03-07 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-08-03 C:\WINDOWS\system32\VTTrayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogOff"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ProcessManager.exe]
"Debugger"=C:\WINDOWS\pchealth\helpctr\binaries\HelpHost.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"L08FXLRD_21443656"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" -m
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"chiCkie"=C:\WINDOWS\inf\chiCkie.exe
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"Horloge Parlante ZMSoft"=C:\ZMSoft\HParlant\HParlante.exe
"ImageDrive-{0CFE4D98-44D7-4542-9842-B924978C2A4F}"=C:\Program Files\Nero\Nero 7\Nero ImageDrive\ImageDrive.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
R0 sojubus;sojubus;C:\WINDOWS\system32\DRIVERS\sojubus.sys [2003-10-05 123520]
R0 sojuscsi;sojuscsi;C:\WINDOWS\system32\DRIVERS\sojuscsi.sys [2003-09-28 5504]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 eusk2par;EUTRON SmartKey Parallel Driver;C:\WINDOWS\system32\Drivers\eusk2par.sys [2005-11-21 25634]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys [2001-05-28 8864]
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys [2001-05-28 8864]
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys [2001-05-28 8864]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-05 14336]
S3 qccdcmdm0;Qualcomm USB CDC Driver (PID 3100);C:\WINDOWS\system32\DRIVERS\qcusbmdm.sys [2004-11-02 64384]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-13 306432]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{055e9659-8744-11dd-aaca-0013d3cc33c8}]
\Shell\AutoRun\command - 6.bat
\Shell\explore\Command - 6.bat
\Shell\open\Command - 6.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05fa9d92-5122-11dd-a9c6-0013d3cc33c8}]
\Shell\AutoRun\command - F:\o2g.exe
\Shell\explore\Command - F:\o2g.exe
\Shell\open\Command - F:\o2g.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ade98ea-512c-11dd-a9c7-0013d3cc33c8}]
\Shell\AutoRun\command - kg2v.com
\Shell\explore\Command - kg2v.com
\Shell\open\Command - kg2v.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{368c9f60-99ec-11dd-ab31-0013d3cc33c8}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
\Shell\Explore\command - F:\MS-DOS.com
\Shell\Open\command - F:\MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{373386e2-83d8-11dd-aab8-0013d3cc33c8}]
\Shell\AutoRun\command - F:\22xo.exe
\Shell\explore\Command - F:\22xo.exe
\Shell\open\Command - F:\22xo.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3888cd3d-a2b0-11dd-ab66-0013d3cc33c8}]
\Shell\AutoRun\command - F:\yew.bat
\Shell\explore\Command - F:\yew.bat
\Shell\open\Command - F:\yew.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{582a8497-59c5-11dd-a9e5-0013d3cc33c8}]
\Shell\AutoRun\command - F:\wak.cmd
\Shell\explore\Command - F:\wak.cmd
\Shell\open\Command - F:\wak.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{582a849c-59c5-11dd-a9e5-0013d3cc33c8}]
\Shell\AutoRun\command - H:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{582a849d-59c5-11dd-a9e5-0013d3cc33c8}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5eef747b-9c48-11dd-ab3e-0013d3cc33c8}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
\Shell\Explore\command - H:\MS-DOS.com
\Shell\Open\command - H:\MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77b026bc-57dc-11dd-a9df-0013d3cc33c8}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
\Shell\Explore\command - MS-DOS.com
\Shell\Open\command - MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f9cb45b-8ef3-11dd-aaff-0013d3cc33c8}]
\Shell\AutoRun\command - F:\2fiji.com
\Shell\explore\Command - F:\2fiji.com
\Shell\open\Command - F:\2fiji.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82934c80-68fe-11dd-aa33-0013d3cc33c8}]
\Shell\AutoRun\command - I:\9mf.exe
\Shell\explore\Command - I:\9mf.exe
\Shell\open\Command - I:\9mf.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{841d10b8-6196-11dd-aa0b-0013d3cc33c8}]
\Shell\AutoRun\command - F:\xih9.cmd
\Shell\explore\Command - F:\xih9.cmd
\Shell\open\Command - F:\xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9339518f-7c0f-11dd-aa8c-0013d3cc33c8}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
\Shell\Explore\command - H:\MS-DOS.com
\Shell\Open\command - H:\MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96392500-63fc-11dd-aa17-0013d3cc33c8}]
\Shell\AutoRun\command - 1weicxa.com
\Shell\explore\Command - 1weicxa.com
\Shell\open\Command - 1weicxa.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b64612e0-815e-11dd-aaab-0013d3cc33c8}]
\Shell\AutoRun\command - F:\1t6yxlxx.cmd
\Shell\explore\Command - F:\1t6yxlxx.cmd
\Shell\open\Command - F:\1t6yxlxx.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0243286-9af2-11dd-ab35-0013d3cc33c8}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c579038c-67d6-11dd-aa2d-0013d3cc33c8}]
\Shell\AutoRun\command - F:\wak.cmd
\Shell\explore\Command - F:\wak.cmd
\Shell\open\Command - F:\wak.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd8576da-5371-11dd-a9ce-0013d3cc33c8}]
\Shell\AutoRun\command - F:\1weicxa.com
\Shell\explore\Command - F:\1weicxa.com
\Shell\open\Command - F:\1weicxa.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce63304d-5117-11dd-a9c5-0013d3cc33c8}]
\Shell\AutoRun\command - 0u.cmd
\Shell\explore\Command - 0u.cmd
\Shell\open\Command - 0u.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d0881c44-535f-11dd-a9cc-0013d3cc33c8}]
\Shell\AutoRun\command - F:\1t6yxlxx.cmd
\Shell\explore\Command - F:\1t6yxlxx.cmd
\Shell\open\Command - F:\1t6yxlxx.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1dd43dd-87f7-11dd-aacb-0013d3cc33c8}]
\Shell\AutoRun\command - H:\1t6yxlxx.cmd
\Shell\explore\Command - H:\1t6yxlxx.cmd
\Shell\open\Command - H:\1t6yxlxx.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d649f72d-9ec1-11dd-ab4a-0013d3cc33c8}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MS-DOS.com
\Shell\Explore\command - MS-DOS.com
\Shell\Open\command - MS-DOS.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de89c91b-979a-11dd-ab23-0013d3cc33c8}]
\Shell\AutoRun\command - F:\2ifetri.cmd
\Shell\explore\Command - F:\2ifetri.cmd
\Shell\open\Command - F:\2ifetri.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfa3d92c-646f-11dd-aa1a-0013d3cc33c8}]
\Shell\AutoRun\command - I:\xmnm2.cmd
\Shell\explore\Command - I:\xmnm2.cmd
\Shell\open\Command - I:\xmnm2.cmd
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-10-31 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 14:39]
2008-11-01 C:\WINDOWS\Tasks\User_Feed_Synchronization-{58525551-538D-404B-B429-1DFAFF1A737D}.job
- C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\famille\Application Data\Mozilla\Firefox\Profiles\g39ugfmp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://fr.msn.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-01 23:27:54
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
**************************************************************************
.
Heure de fin: 2008-11-01 23:31:15
ComboFix-quarantined-files.txt 2008-11-01 22:30:13
Avant-CF: 11 160 559 616 octets libres
Après-CF: 11,351,285,760 octets libres
317 --- E O F --- 2008-10-04 23:40:38