re. enfin terminé avec Comofix…
ComboFix 09-12-27.03 - Administrateur 28/12/2009 16:20:20.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1256.213.1036.18.2047.1523 [GMT 0:00]
Running from: c:\documents and settings\Administrateur\Bureau\coolman16.exe
AV: avast! antivirus 4.8.1368 [VPS 091227-1] On-access scanning disabled (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ADS - WINDOWS: deleted 48 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Application Data\inst.exe
C:\LOG.TXT
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\360x180° Mekan.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\SrchSTS.exe
c:\windows\Tasks\JkDefragCmd.exe
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-28 )))))))))))))))))))))))))))))))
.
2009-12-28 07:54 . 2009-12-28 14:10 -------- d-----w- C:\FindyKill
2009-12-27 11:53 . 2009-10-20 16:20 265728 -c----w- c:\windows\system32\dllcache\http.sys
2009-12-26 19:53 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-12-26 19:53 . 2009-06-10 09:21 2066432 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-12-26 19:52 . 2009-10-29 07:42 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-26 19:52 . 2009-10-29 07:42 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-26 19:52 . 2009-10-29 07:42 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-26 19:52 . 2009-10-29 07:42 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-12-26 19:52 . 2009-10-29 07:42 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-26 19:52 . 2009-10-29 07:42 11069952 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-12-26 19:52 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-26 19:52 . 2009-08-04 22:58 2191232 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-26 19:52 . 2009-08-04 17:28 2068096 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-26 19:52 . 2009-08-04 17:27 2147328 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-26 19:52 . 2009-08-04 17:27 2025984 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-26 10:53 . 2009-12-26 10:54 -------- d-----w- c:\program files\Navilog1
2009-12-25 23:38 . 2008-04-13 17:33 45056 -c–a-w- c:\windows\system32\dllcache\nsepm.dll
2009-12-25 23:37 . 2008-04-13 17:33 24064 -c–a-w- c:\windows\system32\dllcache\compfilt.dll
2009-12-25 23:31 . 2008-04-13 19:34 153088 ----a-w- c:\windows\system32\irftp.exe
2009-12-25 23:31 . 2008-04-13 19:33 29184 ----a-w- c:\windows\system32\irmon.dll
2009-12-25 23:31 . 2008-04-13 19:33 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-12-25 23:27 . 2001-08-28 12:00 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-12-25 23:27 . 2001-08-28 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-12-25 23:27 . 2001-08-28 12:00 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-12-25 23:27 . 2001-08-28 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-12-25 23:26 . 2009-12-25 23:56 -------- d-----w- c:\windows\NV15602404.TMP
2009-12-25 14:14 . 2008-08-12 03:34 446464 ----a-w- c:\windows\system32\nvudisp.exe
2009-12-25 14:13 . 2009-12-25 16:08 -------- d-----w- c:\windows\NV25282292.TMP
2009-12-25 13:02 . 2008-08-12 03:34 446464 ----a-r- c:\windows\system32\nvuninst.exe
2009-12-25 12:56 . 2009-12-25 13:00 -------- d-----w- c:\windows\NV11801144.TMP
2009-12-25 10:59 . 2009-12-25 10:59 -------- d-s—w- c:\documents and settings\Administrateur\UserData
2009-12-20 00:01 . 2009-12-25 12:47 -------- d-----w- c:\windows\ie8updates
2009-12-19 22:43 . 2009-12-19 22:43 -------- d-----w- c:\documents and settings\sarah\Application Data\vlc
2009-12-17 14:12 . 2009-12-17 14:12 -------- d-sh–w- c:\documents and settings\sarah\PrivacIE
2009-12-16 23:32 . 2009-12-26 19:49 -------- d-----w- c:\program files\COMODO
2009-12-16 23:30 . 2009-12-16 23:30 -------- d-sh–w- c:\documents and settings\Administrateur\IECompatCache
2009-12-16 23:29 . 2009-12-16 23:29 -------- d-sh–w- c:\documents and settings\Administrateur\PrivacIE
2009-12-16 23:17 . 2009-12-16 23:17 -------- d-sh–w- c:\documents and settings\Administrateur\IETldCache
2009-12-16 23:05 . 2009-12-25 23:54 -------- dc-h–w- c:\windows\ie8
2009-12-16 22:59 . 2009-12-16 22:59 -------- d-----w- c:\windows\3FDF4C9CBFA043AEB7D454BC33B1B0DA.TMP
2009-12-16 22:58 . 2009-12-16 23:17 -------- d-----w- c:\windows\NV34803876.TMP
2009-12-16 22:56 . 2009-12-25 23:29 -------- d-----w- c:\windows\nvidia icons
2009-12-16 20:23 . 2009-12-25 23:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-16 19:24 . 2009-12-16 19:24 -------- d-----w- c:\windows\system32\xircom
2009-12-16 19:24 . 2009-12-16 19:24 -------- d-----w- c:\windows\system32\wbem\snmp
2009-12-16 19:24 . 2009-12-16 19:24 -------- d-----w- c:\program files\microsoft frontpage
2009-12-16 19:23 . 2009-12-16 19:23 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft
2009-12-16 19:22 . 2001-08-28 12:00 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-12-16 16:00 . 2009-12-16 19:20 -------- d–h--w- c:\documents and settings\Default User\Modèles
2009-12-16 16:00 . 2009-12-16 16:00 -------- d–h--w- c:\documents and settings\Default User\Voisinage réseau
2009-12-16 16:00 . 2009-12-16 16:00 -------- d–h--w- c:\documents and settings\Default User\Voisinage d’impression
2009-12-16 16:00 . 2009-12-16 16:00 -------- d-----w- c:\documents and settings\Default User\Mes documents
2009-12-16 16:00 . 2009-12-16 16:00 -------- d-----w- c:\documents and settings\Default User\Favoris
2009-12-16 16:00 . 2009-12-16 16:00 -------- d-----w- c:\documents and settings\Default User\Bureau
2009-12-16 16:00 . 2009-12-16 16:00 -------- d-----r- c:\documents and settings\Default User\Menu Démarrer
2009-12-15 22:50 . 2009-12-15 22:50 -------- d-----w- c:\program files\ma-config.com
2009-12-15 22:50 . 2009-12-15 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2009-12-11 23:43 . 2009-12-11 23:43 152576 ----a-w- c:\documents and settings\Administrateur\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-11 23:33 . 2009-12-11 23:33 79488 ----a-w- c:\documents and settings\Administrateur\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-11 19:54 . 2009-12-11 19:54 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes’ Anti-Malware\mbam-setup.exe
2009-12-09 19:07 . 2009-12-09 19:10 249856 ------w- c:\windows\Setup1.exe
2009-12-09 19:07 . 2009-12-09 19:10 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-12-04 20:36 . 2009-12-04 20:36 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Mchid
2009-12-04 20:36 . 2009-12-04 20:36 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Livestation
2009-12-04 17:16 . 2009-12-16 08:09 302624 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-12-04 17:16 . 2009-12-16 08:09 18868256 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-12-04 16:46 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-04 16:46 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-04 16:46 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-04 16:46 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-04 16:46 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-04 16:46 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-04 16:46 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-04 16:46 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-12-04 16:46 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-04 16:46 . 2009-12-04 16:46 -------- d-----w- c:\program files\Alwil Software
2009-12-04 15:53 . 2009-12-28 11:34 -------- d-----w- c:\documents and settings\Administrateur\Tracing
2009-12-04 15:40 . 2009-12-04 15:40 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-12-04 15:40 . 2009-08-05 22:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-12-04 15:39 . 2009-12-04 15:39 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-12-04 15:37 . 2009-12-04 15:37 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-12-04 15:33 . 2009-12-04 15:33 -------- d-----w- c:\program files\Microsoft
2009-12-04 15:33 . 2009-12-04 15:33 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-12-04 11:53 . 2009-12-04 11:53 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-11-30 22:46 . 2009-12-25 11:16 -------- d-----w- c:\program files\uTorrent
2009-11-30 22:46 . 2009-12-28 16:22 -------- d-----w- c:\documents and settings\Administrateur\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-28 16:02 . 2009-04-05 20:26 -------- d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-28 14:54 . 2009-04-05 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-12-28 14:10 . 2008-04-14 12:00 81804 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-28 14:10 . 2008-04-14 12:00 503590 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-28 07:46 . 2009-04-16 17:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-28 00:01 . 2009-04-16 17:34 -------- d-----w- c:\program files\Google
2009-12-27 22:36 . 2009-03-20 19:23 89488 -c–a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-27 13:20 . 2009-10-25 14:32 -------- d-----w- c:\program files\Free Video Converter
2009-12-26 20:28 . 2009-03-19 18:42 -------- d-----w- c:\program files\Microsoft Encarta
2009-12-26 00:20 . 2009-04-08 07:27 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
2009-12-25 23:34 . 2009-03-19 17:44 23096 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-12-25 15:58 . 2009-04-09 08:20 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2009-12-17 00:08 . 2009-03-19 18:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-16 22:59 . 2009-03-19 18:17 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-12-16 20:48 . 2009-03-19 17:47 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-16 20:01 . 2009-03-19 18:08 -------- d-----w- c:\program files\XnView
2009-12-16 08:09 . 2009-12-04 17:16 28988 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-12-16 08:09 . 2009-12-04 17:16 218900 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-12-16 00:38 . 2009-11-27 19:26 -------- d-----w- c:\program files\trend micro
2009-12-12 23:22 . 2009-05-04 18:30 -------- d-----w- c:\program files\Viewpoint
2009-12-12 14:29 . 2009-11-27 20:19 -------- d-----w- c:\program files\Malwarebytes’ Anti-Malware
2009-12-11 23:44 . 2009-08-10 18:00 -------- d-----w- c:\program files\Java
2009-12-10 00:03 . 2009-03-19 17:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-04 15:40 . 2009-03-19 17:52 -------- d-----w- c:\program files\Windows Live
2009-12-04 10:25 . 2009-03-19 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-12-03 16:14 . 2009-11-27 20:19 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 16:13 . 2009-11-27 20:19 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-27 20:19 . 2009-11-27 20:19 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-11-27 20:19 . 2009-11-27 20:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-27 19:27 . 2009-11-27 19:27 -------- d-----w- c:\program files\CCleaner
2009-11-26 21:11 . 2009-11-02 21:49 -------- d-----w- c:\program files\Spyware Doctor
2009-11-26 21:11 . 2009-11-02 21:49 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-11-26 21:11 . 2009-10-25 16:29 -------- d-----w- c:\program files\Videos To DVD
2009-11-26 21:11 . 2009-03-19 18:09 -------- d-----w- c:\program files\Real Alternative
2009-11-26 21:11 . 2009-03-19 18:09 -------- d-----w- c:\program files\QT Lite
2009-11-26 21:11 . 2009-11-21 09:26 -------- d-----w- c:\program files\DivX
2009-11-26 21:11 . 2009-03-19 18:10 -------- d-----w- c:\program files\Elaborate Bytes
2009-11-26 21:11 . 2009-03-19 18:08 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-11-26 21:11 . 2009-05-20 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\LightScribe
2009-11-26 21:11 . 2009-03-19 18:08 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-11-21 11:53 . 2009-11-21 09:27 -------- d-----w- c:\documents and settings\Administrateur\Application Data\DivX
2009-11-21 10:14 . 2009-11-21 10:14 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-11-17 13:42 . 2009-11-17 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\WLInstaller
2009-11-17 13:39 . 2009-11-17 13:24 -------- dcsh–w- c:\program files\Fichiers communs\WindowsLiveInstaller
2009-11-14 00:47 . 2009-11-14 00:47 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-11-10 20:56 . 2009-08-21 15:59 -------- d-----w- c:\program files\Mobile Partner
2009-11-07 10:26 . 2009-11-07 10:20 -------- d-----w- c:\program files\CaTrain
2009-11-06 15:04 . 2009-11-06 15:04 -------- d-----w- c:\documents and settings\Administrateur\Application Data\GlarySoft
2009-10-29 07:42 . 2008-04-13 17:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:39 . 2008-04-13 17:33 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2008-04-13 17:33 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-13 09:53 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-15 18:05 . 2009-10-11 05:34 36864 -c–a-w- c:\documents and settings\All Users\Application Data\TEMP{01FB4998-33C4-4431-85ED-079E3EEFE75D}\PostBuild.exe
2009-10-14 18:58 . 2009-03-19 18:27 95259 -c–a-w- c:\windows\system32\drivers\klick.dat
2009-10-14 18:58 . 2009-03-19 18:27 108059 -c–a-w- c:\windows\system32\drivers\klin.dat
2009-10-13 10:33 . 2008-04-13 17:33 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2008-04-13 17:33 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2008-04-13 17:33 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 04:17 . 2009-08-10 18:00 411368 -c–a-w- c:\windows\system32\deploytk.dll
2009-10-09 21:13 . 2009-04-22 19:24 47360 -c–a-w- c:\documents and settings\Administrateur\Application Data\pcouffin.sys
2009-10-09 21:13 . 2009-04-22 19:24 47360 -c–a-w- c:\documents and settings\Administrateur\Application Data\pcouffin.sys
2009-10-08 11:31 . 2009-11-02 21:50 149456 -c–a-w- c:\windows\SGDetectionTool.dll
2009-10-08 11:31 . 2009-11-02 21:50 165840 -c–a-w- c:\windows\PCTBDRes.dll
2009-10-08 11:31 . 2009-11-02 21:50 1636304 -c–a-w- c:\windows\PCTBDCore.dll
2009-10-08 11:31 . 2009-11-02 21:50 767952 -c–a-w- c:\windows\BDTSupport.dll
2009-10-06 16:31 . 2009-11-02 21:50 87784 -c–a-w- c:\windows\system32\drivers\PCTAppEvent.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“WinMover”=“c:\program files\WinMover\WinMover.exe” [2005-12-02 10240]
“E09FXLRD_550265”=“c:\program files\Microsoft Encarta\Microsoft Encarta 2009 - Collection DVD\EDICT.EXE” [2008-05-28 351000]
“Yahoo! Pager”=“c:\program files\Yahoo!\Messenger\YahooMessenger.exe” [2007-11-06 3810544]
“LightScribe Control Panel”=“c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe” [2008-06-09 2363392]
“Mobile Partner”=“c:\program files\Mobile Partner\Mobile Partner.exe” [2009-11-10 114688]
“ccleaner”=“c:\program files\CCleaner\CCleaner.exe” [2009-11-24 1738040]
“uTorrent”=“c:\program files\uTorrent\uTorrent.exe” [2009-12-25 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2009-11-24 81000]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-08-12 13570048]
“BluetoothAuthenticationAgent”=“bthprops.cpl” [2008-04-13 110592]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-08-12 86016]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
“SweetRegistry”=“advpack.dll” [2009-03-08 128512]
c:\documents and settings\Administrateur\Menu D?marrer\Programmes\D?marrage
OneNote 2007 - Capture d’?cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“HideRunAsVerb”= 0 (0x0)
“NoNetConnectDisconnect”= 1 (0x1)
“NoResolveTrack”= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoResolveTrack”= 1 (0x1)
“NoSMBalloonTip”= 1 (0x1)
“NoSMConfigurePrograms”= 1 (0x1)
“NoStrCmpLogical”= 0 (0x0)
“NoWelcomeScreen”= 1 (0x1)
“HonorAutoRunSetting”= 0 (0x0)
[HKEY_USERS.default\software\microsoft\windows\currentversion\policies\explorer]
“ForceClassicControlPanel”= 1 (0x1)
“NoResolveTrack”= 1 (0x1)
“NoSMBalloonTip”= 1 (0x1)
“NoSMConfigurePrograms”= 1 (0x1)
“NoSMHelp”= 1 (0x1)
“NoStrCmpLogical”= 0 (0x0)
“NoWelcomeScreen”= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
“QuickTime Task”=“c:\program files\QT Lite\qttask.exe” -atboottime
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\Program Files\uTorrent\uTorrent.exe”=
“c:\Program Files\Skype\Phone\Skype.exe”=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [02/11/2009 21:50 207280]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [04/12/2009 16:46 114768]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [15/05/2008 11:07 61424]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/12/2009 16:46 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [04/12/2009 15:40 54752]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/12/2007 12:28 24592]
S2 gupdate1c9eaba729b6cd8;Service Google Update (gupdate1c9eaba729b6cd8);c:\program files\Google\Update\GoogleUpdate.exe [11/06/2009 17:31 133104]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 GPU-Z;GPU-Z; [x]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [11/12/2009 15:43 238960]
S3 ZD1211BU(Atheros);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(Atheros);c:\windows\system32\drivers\ZD1211BU.sys [19/03/2009 18:28 500736]
S4 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [02/11/2009 21:50 112592]
S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [04/05/2009 18:30 24652]
— Other Services/Drivers In Memory —
NewlyCreated - EAPHOST
NewlyCreated - IP6FW
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 451872 -c–a-w- c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
2009-03-08 04:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
------- Supplementary Scan -------
.
uStart Page = google.fr…
TCP: {A15A9F33-A60E-40A7-BA87-615387CE9568} = 172.25.1.53 172.25.1.54
.
Toolbar-Locked - (no file)
HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe
AddRemove-Download Accelerator Plus (DAP) - c:\progra~1\DAP\DAPREMOVE.EXE
AddRemove-MP4 Video Converter_is1 - c:\program files\WinAVI MP4 Converter\unins000.exe
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-12-28 16:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
“ImagePath”="??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1275210071-1202660629-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
“88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,01,dd,37,ed,0d,f6,43,a8,ca,13,
“2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,01,dd,37,ed,0d,f6,43,a8,ca,13,
“6256FFB019F8FDFBD36745B06F4540E9AEAF222A25”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,01,dd,37,ed,0d,f6,43,a8,ca,13,\
[HKEY_USERS\S-1-5-21-1275210071-1202660629-1177238915-500\Software\SecuROM\License information*]
“datasecu”=hex:15,4c,1e,5b,22,6b,84,c3,65,9d,fe,15,ce,30,01,50,28,b5,37,41,0e,
85,d6,29,65,aa,a7,9e,d9,2d,2f,d3,c8,e5,90,8c,9f,0e,21,80,44,07,4a,d4,2c,94,
“rkeysecu”=hex:81,13,7c,56,38,30,a3,a7,31,c6,9a,d2,bd,34,58,c3
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
“88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,01,dd,37,ed,0d,f6,43,a8,ca,13,
“6256FFB019F8FDFBD36745B06F4540E9AEAF222A25”=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,4b,01,dd,37,ed,0d,f6,43,a8,ca,13,
.
--------------------- DLLs Loaded Under Running Processes ---------------------
-
-
-
-
-
-
-
‘winlogon.exe’(1440)
c:\windows\system32\klogon.dll
.
Completion time: 2009-12-28 16:24:27
ComboFix-quarantined-files.txt 2009-12-28 16:24
Pre-Run: 33 125 101 568 octets libres
Post-Run: 33 093 738 496 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Professionnel” /noexecute=optin /fastdetect
Current=2 Default=2 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
-
- End Of File - - E4193E0C25371E5D66F81828A5C0BDA1