ComboFix 08-12-16.03 - administrateur 2 2008-12-17 18:14:41.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.255.76 [GMT 1:00]
Lancé depuis: c:\documents and settings\administrateur 2\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\administrateur 2\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
- Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\administrateur 2\Application Data\gadcom
c:\documents and settings\administrateur 2\Application Data\SpeedRunner
c:\documents and settings\administrateur 2\Application Data\SpeedRunner\config.cfg
c:\documents and settings\administrateur 2\Local Settings\Application Data\oickqam.dat
c:\documents and settings\administrateur 2\Local Settings\Application Data\oickqam.exe
c:\documents and settings\administrateur 2\Local Settings\Application Data\oickqam_nav.dat
c:\documents and settings\administrateur 2\Local Settings\Application Data\oickqam_navps.dat
c:\documents and settings\All Users\Application Data\Starware354
c:\documents and settings\All Users\Application Data\Starware354\buttons\FindIt.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\FindItHot.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\findithotxp.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\finditxp.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\Highlight.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\HighlightHot.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\highlighthotxp.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\highlightxp.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\recipes.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\recipes.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\recipes_foreign_feed.bmp
c:\documents and settings\All Users\Application Data\Starware354\buttons\recipes_foreign_feed.png
c:\documents and settings\All Users\Application Data\Starware354\buttons\starware_toolbar_icon.bmp
c:\documents and settings\All Users\Application Data\Starware354\contexts\error.xml
c:\documents and settings\All Users\Application Data\Starware354\contexts\Related.xml
c:\documents and settings\All Users\Application Data\Starware354\contexts\Travel.xml
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\ProductMessagingConfig.xml
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\ProductMessagingConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\SimpleUpdateConfig.xml
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\SimpleUpdateConfig.xml.backup
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\TimerManagerConfig.xml
c:\documents and settings\All Users\Application Data\Starware354\SimpleUpdate\TimerManagerConfig.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354
c:\documents and settings\LocalService\Application Data\Starware354\BrowserSearch\BrowserSearch.xml
c:\documents and settings\LocalService\Application Data\Starware354\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Configurator\Configurator.xml
c:\documents and settings\LocalService\Application Data\Starware354\Configurator\Configurator.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Games\GamesOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\Games\GamesOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Games\images\active\Games0.bmp
c:\documents and settings\LocalService\Application Data\Starware354\Layouts\ToolbarLayout.xml
c:\documents and settings\LocalService\Application Data\Starware354\Layouts\ToolbarLayout.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Manager\ManagerOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\Manager\ManagerOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Movies\images\active\Movies0.bmp
c:\documents and settings\LocalService\Application Data\Starware354\Movies\MoviesOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\Movies\MoviesOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Recipes_Foreign\Recipes_ForeignOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\Recipes_Foreign\Recipes_ForeignOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
c:\documents and settings\LocalService\Application Data\Starware354\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\Toolbar\TBProductsOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\Toolbar\TBProductsOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\documents and settings\LocalService\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml
c:\documents and settings\LocalService\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354
c:\documents and settings\peggy\Application Data\Starware354\BrowserSearch\BrowserSearch.xml
c:\documents and settings\peggy\Application Data\Starware354\BrowserSearch\BrowserSearch.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Configurator\Configurator.xml
c:\documents and settings\peggy\Application Data\Starware354\Configurator\Configurator.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\ErrorSearch\ErrorSearchOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Games\GamesOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\Games\GamesOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Games\images\active\Games0.bmp
c:\documents and settings\peggy\Application Data\Starware354\Layouts\ToolbarLayout.xml
c:\documents and settings\peggy\Application Data\Starware354\Layouts\ToolbarLayout.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Manager\ManagerOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\Manager\ManagerOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Movies\images\active\Movies0.bmp
c:\documents and settings\peggy\Application Data\Starware354\Movies\MoviesOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\Movies\MoviesOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Recipes_Foreign\Recipes_ForeignOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\Recipes_Foreign\Recipes_ForeignOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\RecipeSearch_Foreign\RecipeSearch_ForeignOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\ScreensaversMarketingSitePager\images\active\ScreensaversMarketingSitePager0.bmp
c:\documents and settings\peggy\Application Data\Starware354\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\Toolbar\TBProductsOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\Toolbar\TBProductsOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml.backup
c:\documents and settings\peggy\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml
c:\documents and settings\peggy\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents
c:\program files\Mjcore
c:\windows\system32\ahtn.htm
c:\windows\system32\cgyddsex.dll
c:\windows\system32\coagrpdd.dll
c:\windows\system32\dqditwcx.dll
c:\windows\system32\eaqtosyr.dll
c:\windows\system32\eefNqtwa.ini
c:\windows\system32\eefNqtwa.ini2
c:\windows\system32\esrfxbsi.dll
c:\windows\system32\fccdcCUM.dll
c:\windows\system32\fnrtwe.dll
c:\windows\system32\frmwrk32.exe
c:\windows\system32\geBtRlml.dll
c:\windows\system32\ilgutwet.dll
c:\windows\system32\jipyfu.dll
c:\windows\system32\krjfys.dll
c:\windows\system32\lepaiaep.dll
c:\windows\system32\Llnqqqru.ini
c:\windows\system32\Llnqqqru.ini2
c:\windows\system32\lvehia.dll
c:\windows\system32\nntoxhcy.dll
c:\windows\system32\ntdll64.exe
c:\windows\system32\ocamcz.dll
c:\windows\system32\qtpzrd.dll
c:\windows\system32\siqfnfms.dll
c:\windows\system32\test.ttt
c:\windows\system32\ulzgxe.dll
c:\windows\system32\uniq.tll
c:\windows\system32\urqqqnlL.dll
c:\windows\system32\vfgqgqvh.dll
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\wwyfgksd.dll
c:\windows\system32\xyhdgm.dll
c:\windows\Tasks\bbrsspcr.job
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-17 au 2008-12-17 ))))))))))))))))))))))))))))))))))))
.
2008-12-16 20:55 . 2008-12-16 20:56 1,650,409 —hs---- c:\windows\system32\isbxfrse.ini
2008-12-13 12:19 . 2008-12-16 20:53 1,650,409 —hs---- c:\windows\system32\flgxlenn.ini
2008-12-12 20:40 . 2008-12-12 20:40 d-------- C:\VundoFix Backups
2008-12-12 12:19 . 2008-12-12 12:19 1,625,452 —hs---- c:\windows\system32\xesddygc.ini
2008-12-12 00:25 . 2008-12-12 00:26 1,630,702 —hs---- c:\windows\system32\dskgfyww.ini
2008-12-11 21:38 . 2008-12-11 21:38 1,627,952 —hs---- c:\windows\system32\eaeujbao.ini
2008-12-10 23:09 . 2008-12-11 19:18 d-------- c:\documents and settings\administrateur 2\DoctorWeb
2008-12-10 21:36 . 2008-12-11 21:37 1,627,952 —hs---- c:\windows\system32\ashnbnpg.ini
2008-12-10 20:18 . 2008-12-10 20:18 d-------- c:\program files\Trend Micro
2008-12-10 19:56 . 2008-12-10 19:57 d-------- c:\program files\CCleaner
2008-12-10 19:54 . 2008-12-10 19:54 d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-10 19:51 . 2008-12-10 19:51 d-------- c:\program files\Yahoo!
2008-12-10 16:57 . 2008-12-10 18:11 d-------- c:\program files\FindyKill
2008-12-09 21:32 . 2008-12-09 21:32 1,550,037 —hs---- c:\windows\system32\phdncbgy.ini
2008-12-08 21:29 . 2008-12-09 21:30 1,550,037 —hs---- c:\windows\system32\cqtdpnfs.ini
2008-12-07 21:36 . 2008-12-08 14:56 1,482,268 —hs---- c:\windows\system32\xdxpvdcb.ini
2008-12-07 21:31 . 2008-12-13 12:41 d-------- c:\windows\BDOSCAN8
2008-12-07 09:59 . 2008-12-07 09:59 552 --a------ c:\windows\system32\d3d8caps.dat
2008-12-06 22:08 . 2008-12-06 22:08 d-------- c:\windows\system32\Kaspersky Lab
2008-12-06 17:08 . 2008-12-06 17:09 d-------- c:\program files\The Cleaner Demo
2008-12-06 16:41 . 2008-12-06 16:41 d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-06 16:09 . 2008-12-08 19:54 d-------- c:\documents and settings\administrateur 2\Application Data\Twain
2008-12-06 16:04 . 2008-12-10 00:32 d-------- c:\program files\Webtools
2008-12-05 20:44 . 2008-12-05 20:44 d-------- c:\program files\Alwil Software
2008-12-05 20:44 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2008-12-05 20:44 . 2003-03-18 20:14 499,712 --a------ c:\windows\system32\MSVCP71.dll
2008-12-05 20:44 . 2003-02-21 04:42 348,160 --a------ c:\windows\system32\MSVCR71.dll
2008-12-05 19:40 . 2008-12-07 21:32 1,482,262 —hs---- c:\windows\system32\bgkytolq.ini
2008-12-05 12:37 . 2008-12-05 12:37 d-------- c:\program files\vghd
2008-12-05 12:37 . 2008-12-05 12:37 d-------- c:\documents and settings\administrateur 2\Application Data\vghd
2008-12-05 12:37 . 2008-12-05 12:37 152,904 --a------ c:\windows\system32\vghd.scr
2008-12-02 12:33 . 2008-12-02 12:34 d-------- c:\program files\Pastry Passion
2008-12-02 12:31 . 2008-12-02 12:35 d-------- c:\program files\Hidden Wonders
2008-12-02 12:30 . 2008-12-04 20:05 d-------- c:\program files\Delicious winter edition Deluxe English
2008-11-29 14:46 . 2008-11-29 14:46 d-------- c:\documents and settings\administrateur 2\Application Data\Jane s Hotel Family Hero
2008-11-29 14:43 . 2008-12-08 13:13 d-------- c:\program files\Jane’s Hotel 2 - Family Hero
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmpF631D.FOT
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmpE011D.FOT
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmpD590D.FOT
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmpCCE0D.FOT
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmpB4C0D.FOT
2008-11-28 20:30 . 2008-11-28 20:30 1,409 --a------ c:\windows\system32\tmp1231D.FOT
2008-11-26 20:34 . 2008-11-26 20:34 d-------- c:\documents and settings\All Users\Application Data\Gogii
2008-11-25 20:35 . 2008-11-25 20:47 d-------- c:\documents and settings\administrateur 2\Application Data\Pirateville
2008-11-25 13:07 . 2008-12-08 08:01 d-------- c:\program files\Delicious - Emily’s Tea Garden
2008-11-25 13:00 . 2008-11-25 13:00 d-------- c:\windows\The Hidden Object Show
2008-11-25 12:58 . 2008-11-25 12:59 d-------- c:\program files\Pirateville
2008-11-23 20:45 . 2008-11-23 20:45 d-------- c:\documents and settings\All Users\Application Data\Meridian93
2008-11-23 20:31 . 2008-11-23 20:31 d-------- c:\program files\LeeGTs Games
2008-11-23 19:17 . 2008-11-23 19:29 d-------- c:\program files\eToro
2008-11-23 18:12 . 2008-11-23 18:12 d-------- c:\program files\GamesBar
2008-11-23 18:11 . 2008-12-05 12:17 d-------- c:\program files\Oberon Media
2008-11-22 20:27 . 2008-11-22 20:30 d-------- c:\program files\Jane’s Hotel
2008-11-22 16:50 . 2008-11-22 16:50 d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-22 15:59 . 2008-11-22 15:57 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-22 15:03 . 2008-11-22 15:03 d-------- c:\program files\Fichiers communs\Adobe AIR
2008-11-19 16:55 . 2008-11-25 13:02 d-------- c:\program files\Delicious 2 Deluxe
2008-11-18 21:07 . 2008-11-18 21:07 d-------- c:\windows\Farm Frenzy 2
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 16:46 --------- d-----w c:\program files\Lx_cats
2008-12-06 15:02 --------- d-----w c:\program files\eMule
2008-11-29 13:10 --------- d-----w c:\program files\Zylom Games
2008-11-29 13:06 --------- d-----w c:\documents and settings\administrateur 2\Application Data\Zylom
2008-11-22 17:33 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-22 17:00 --------- d-----w c:\program files\Java
2008-11-22 13:58 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-19 14:59 --------- d-----w c:\program files\Windows Live
2008-11-19 14:59 --------- d-----w c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2008-11-18 20:20 --------- d-----w c:\documents and settings\All Users\Application Data\FarmFrenzy2
2008-11-13 13:06 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-12 15:10 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-11-12 14:18 --------- d-----w c:\documents and settings\administrateur 2\Application Data\F-Secure
2008-11-10 20:16 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-11-10 20:16 --------- d-----w c:\documents and settings\administrateur 2\Application Data\PlayFirst
2008-11-10 19:12 --------- d-----w c:\documents and settings\administrateur 2\Application Data\KC Softwares
2008-11-10 18:07 --------- d-----w c:\program files\KC Softwares
2008-11-07 19:39 --------- d-----w c:\program files\Cooking Dash
2008-10-31 21:35 --------- d—a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-31 20:24 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-10-31 19:31 --------- d-----w c:\documents and settings\administrateur 2\Application Data\Home Sweet Home 2
2008-10-25 21:17 --------- d-----w c:\documents and settings\administrateur 2\Application Data\cerasus.media
2008-10-25 19:25 --------- d-----w c:\documents and settings\administrateur 2\Application Data\PetShowCraze
2008-10-25 16:44 --------- d-----w c:\documents and settings\administrateur 2\Application Data\Friday’s games
2008-10-24 13:24 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-11-22 136600]
“phc700”=“c:\windows\vphc700.exe” [2005-07-20 339968]
“News Service”=“c:\program files\AntivirusFirewall\FSGUI\ispnews.exe” [2008-12-10 356352]
“Lexmark 5200 series”=“c:\program files\Lexmark 5200 series\lxbtbmgr.exe” [2004-06-04 57344]
“F-Secure TNB”=“c:\program files\AntivirusFirewall\TNB\TNBUtil.exe” [2008-12-10 700416]
“F-Secure Startup Wizard”=“c:\program files\AntivirusFirewall\FSGUI\FSSW.EXE” [2008-12-10 372736]
“F-Secure Manager”=“c:\program files\AntivirusFirewall\Common\FSM32.EXE” [2008-12-10 122929]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“LXBTCATS”=“c:\windows\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll” [2004-03-17 65536]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE” [2004-08-20 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{56F9679E-7826-4C84-81F3-532071A8BCC5}”= “c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll” [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\webhits32]
2004-10-16 11:15 7680 c:\windows\system32\webhits32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=ocamcz.dll jipyfu.dll
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“c:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe”= c:\Program Files\AntivirusFirewall\backweb\6588780\program\fspex.exe
“%windir%\system32\sessmgr.exe”=
“c:\Program Files\Messenger\msmsgs.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\Program Files\eMule\emule.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“58808:TCP”= 58808:TCP:emule:tcp entrant
“64202:UDP”= 64202:UDP:emule:udp entrant
“1700:TCP”= 1700:TCP:MioNet Remote Drive Access
“1641:TCP”= 1641:TCP:MioNet Remote Drive Verification
“4462:TCP”= 4462:TCP:127.0.0.1
“4672:UDP”= 4672:UDP:127.0.0.1
“1661:TCP”= 1661:TCP:messenger
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
“AllowInboundEchoRequest”= 1 (0x1)
“AllowInboundTimestampRequest”= 1 (0x1)
“AllowInboundMaskRequest”= 1 (0x1)
“AllowInboundRouterRequest”= 1 (0x1)
“AllowOutboundDestinationUnreachable”= 1 (0x1)
“AllowOutboundSourceQuench”= 1 (0x1)
“AllowOutboundParameterProblem”= 1 (0x1)
“AllowOutboundTimeExceeded”= 1 (0x1)
“AllowRedirect”= 1 (0x1)
“AllowOutboundPacketTooBig”= 1 (0x1)
.
Contenu du dossier ‘Tâches planifiées’
2008-12-11 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\ANTIVI~1\ANTI-V~1\fsav.exe [2008-12-10 10:25]
2008-12-17 c:\windows\Tasks\User_Feed_Synchronization-{553AC877-6901-4CE7-9D74-50FF0C863196}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
2008-12-17 c:\windows\Tasks\User_Feed_Synchronization-{6C444134-CF94-4657-8984-B004A74D0414}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 02:05]
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
BHO-{1A7CD708-11C5-480A-A4AF-5F28EFE69C02} - c:\windows\system32\urqqqnlL.dll
BHO-{7c0cd5d8-c308-4555-b0f9-877479848362} - c:\windows\system32\ocamcz.dll
BHO-{9c131af3-2705-4bc3-82e6-bab34c51733d} - c:\windows\system32\ulzgxe.dll
BHO-{C81BAB98-02D9-4CCD-BC3B-9A0C4609706F} - c:\windows\system32\fccdcCUM.dll
ShellExecuteHooks-{C81BAB98-02D9-4CCD-BC3B-9A0C4609706F} - c:\windows\system32\fccdcCUM.dll
.
------- Examen supplémentaire -------
.
uStart Page = google.fr…
IE: &Bloquer cette fenêtre publicitaire - c:\program files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Tout télécharger avec Free Download Manager - [c:\program…](file://c:\program) files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - [c:\program…](file://c:\program) files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - [c:\program…](file://c:\program) files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - [c:\program…](file://c:\program) files\Free Download Manager\dlfvideo.htm
O16 -: DirectAnimation Java Classes - [c:\windows\Java\classes\dajava.cab…](file://c:\windows\Java\classes\dajava.cab)
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - [c:\windows\Java\classes\xmldso.cab…](file://c:\windows\Java\classes\xmldso.cab)
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\program files\Wanadoo\msvcp60.dll - c:\windows\system32\atl.dll
c:\windows\Downloaded Program Files\AdVerifierADP.dll
c:\windows\Downloaded Program Files\AdSignerADP.dll
O16 -: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF}
static.impots.gouv.fr…
c:\windows\Downloaded Program Files\AdSignerADP.inf
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
jeuxmultijoueurs.orange.fr…
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-17 18:29:06
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16???
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
--------------------- DLLs chargées dans les processus actifs ---------------------
-
-
-
-
-
-
-
‘winlogon.exe’(620)
c:\windows\system32\webhits32.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\slserv.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\Lexmark 5200 Series\lxbtbmon.exe
c:\program files\Windows Desktop Search\WindowsSearch.exe
c:\windows\system32\searchfilterhost.exe
.
.
Heure de fin: 2008-12-17 18:46:09 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-17 17:45:55
Avant-CF: 6ÿ213ÿ169ÿ152 octets libres
AprÞs-CF: 6,272,204,800 octets libres
356 — E O F — 2008-11-13 13:07:16