je vous donne quand meme le log que vous voyez ce que j’ai mais c’est con que clubic ne soit pas agréé
–
ComboFix 08-11-22.02 - HOME 2008-11-23 19:42:12.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.2617 [GMT 1:00]
Lancé depuis: c:\documents and settings\HOME\Bureau\ComboFix.exe
- Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HOME\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\windows\system32\aliweyiz.ini
c:\windows\system32\aresayum.ini
c:\windows\system32\bevukeyo.dll
c:\windows\system32\bohotute.dll
c:\windows\system32\dejegima.dll
c:\windows\system32\efarobuj.ini
c:\windows\system32\ehiwemog.ini
c:\windows\system32\ekilokah.ini
c:\windows\system32\ekisibaf.ini
c:\windows\system32\fabisike.dll
c:\windows\system32\fawedevi.dll
c:\windows\system32\fefiyiri.dll
c:\windows\system32\gomewihe.dll
c:\windows\system32\hakolike.dll
c:\windows\system32\ijiroyaj.ini
c:\windows\system32\itubuzeh.ini
c:\windows\system32\ivedewaf.ini
c:\windows\system32\jayoriji.dll
c:\windows\system32\kurufihu.dll
c:\windows\system32\mokomaru.dll
c:\windows\system32\muyasera.dll
c:\windows\system32\ojimolil.ini
c:\windows\system32\pulowule.dll
c:\windows\system32\sajuyaya.dll
c:\windows\system32\uhifuruk.ini
c:\windows\system32\ukulizej.ini
c:\windows\system32\webomeru.dll
c:\windows\system32\wefeyubi.dll
c:\windows\system32\wemeyebi.dll
c:\windows\system32\yumaluso.dll
c:\windows\system32\ziyewila.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-23 au 2008-11-23 ))))))))))))))))))))))))))))))))))))
.
2008-11-23 18:33 . 2008-11-23 18:34 d-------- c:\program files\Azureus
2008-11-23 17:27 . 2007-09-12 18:19 d–h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-23 17:27 . 2007-09-12 18:19 d–h----- c:\documents and settings\Administrateur\Voisinage d’impression
2008-11-23 17:27 . 2007-09-12 16:36 d–h----- c:\documents and settings\Administrateur\Modèles
2008-11-23 17:27 . 2007-09-12 18:19 d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-23 17:27 . 2007-09-12 18:19 dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-23 17:27 . 2007-09-12 18:19 d-------- c:\documents and settings\Administrateur\Favoris
2008-11-23 17:27 . 2007-09-12 18:19 d-------- c:\documents and settings\Administrateur\Bureau
2008-11-23 17:27 . 2008-11-23 17:27 d-------- c:\documents and settings\Administrateur
2008-11-23 17:10 . 2008-11-23 17:10 d-------- c:\program files\Lavasoft
2008-11-23 17:09 . 2008-11-23 17:09 d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2008-11-23 17:09 . 2008-11-23 17:14 d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2008-11-23 17:06 . 2008-11-23 17:06 d-------- c:\program files\Trend Micro
2008-11-22 14:35 . 2008-11-22 14:35 d-------- c:\documents and settings\All Users.WINDOWS\Application Data\LightScribe
2008-11-22 14:25 . 2008-11-22 14:25 d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Nero
2008-11-12 22:46 . 2008-11-12 22:46 d-------- c:\documents and settings\HOME\Application Data\Avira
2008-11-12 21:59 . 2008-11-12 21:59 d-------- c:\windows\Drivers
2008-11-12 21:59 . 2002-12-24 13:52 54,016 --a------ c:\windows\system32\drivers\ousb2hub.sys
2008-11-12 21:59 . 2002-12-24 13:52 39,040 --a------ c:\windows\system32\drivers\ousbehci.sys
2008-11-12 21:59 . 2003-07-02 04:42 27,904 --a------ c:\windows\system32\drivers\VIAAGP1.SYS
2008-11-12 21:58 . 2008-11-12 21:58 d-------- c:\program files\Avira
2008-11-12 21:58 . 2008-05-07 14:20 71,592 --a------ c:\windows\system32\drivers\avfwot.sys
2008-11-12 21:58 . 2008-05-07 10:51 71,464 --a------ c:\windows\system32\drivers\avfwim.sys
2008-11-12 21:49 . 2008-11-12 21:49 d-------- c:\windows\PreInstall
2008-11-12 21:48 . 2004-08-03 23:31 20,992 --a------ c:\windows\system32\drivers\RTL8139.sys
2008-11-12 21:48 . 2004-08-03 23:31 20,992 --a–c— c:\windows\system32\dllcache\rtl8139.sys
2008-11-12 21:12 . 2008-11-12 21:16 d-------- c:\program files\Ray Adams
2008-11-12 21:12 . 2008-11-12 21:12 d-------- c:\documents and settings\HOME\Application Data\atitray
2008-11-12 21:06 . 2008-11-12 21:11 d-------- C:\d9b572b6b82853ae9604
2008-11-12 09:17 . 2008-10-24 12:21 455,296 -----c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 09:16 . 2008-09-04 18:16 1,106,944 -----c— c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:16 . 2008-11-12 21:16 d-------- c:\documents and settings\All Users.WINDOWS\Application Data\ATI
2008-11-11 19:51 . 2007-06-27 02:59 344,064 -ra------ c:\windows\system32\SET60.tmp
2008-11-11 19:39 . 2008-11-12 21:15 d-------- c:\documents and settings\All Users.WINDOWS\Application Data\ATI(2)
2008-11-09 20:35 . 2008-11-14 19:01 d-------- c:\program files\RamBoost XP
2008-10-27 20:07 . 2008-11-11 19:38 60,256 --a------ c:\windows\system32\ativvaxx.cap
2008-10-24 07:51 . 2008-10-15 17:35 337,408 -----c— c:\windows\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-23 18:39 --------- d-----w c:\program files\Lx_cats
2008-11-23 18:31 --------- d-----w c:\documents and settings\HOME\Application Data\Azureus
2008-11-23 17:07 --------- d-----w c:\program files\Microsoft ActiveSync
2008-11-23 17:07 --------- d-----w c:\program files\MediaCoder
2008-11-23 17:04 --------- d-----w c:\program files\Google
2008-11-23 17:03 --------- d-----w c:\program files\DivX
2008-11-23 17:02 --------- d-----w c:\program files\Fichiers communs\AVSMedia
2008-11-23 17:01 --------- d–h--w c:\program files\InstallShield Installation Information
2008-11-23 17:01 --------- d-----w c:\program files\Audacity
2008-11-23 17:00 --------- d-----w c:\program files\Apple Software Update
2008-11-23 14:49 --------- d-----w c:\program files\Mozilla Thunderbird
2008-11-22 13:35 --------- d-----w c:\program files\Fichiers communs\LightScribe
2008-11-22 13:34 --------- d-----w c:\program files\ma-config.com
2008-11-22 13:34 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ma-config.com
2008-11-22 13:28 --------- d-----w c:\program files\Fichiers communs\Ahead
2008-11-22 13:14 --------- d-----w c:\documents and settings\HOME\Application Data\Thunderbird
2008-11-22 08:53 --------- d-----w c:\documents and settings\HOME\Application Data\OpenOffice.org2
2008-11-12 20:58 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Avira
2008-11-12 20:16 --------- d-----w c:\program files\ATI Technologies
2008-11-12 20:12 --------- d-----w c:\program files\SpeedFan
2008-11-09 18:11 --------- d-----w c:\program files\Codemasters
2008-11-09 17:54 --------- d-----w c:\program files\GameSpy Arcade
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-04 12:51 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Azureus
2008-10-04 12:37 --------- d-----w c:\program files\Deluge
2008-10-02 19:32 --------- d-----w c:\documents and settings\HOME\Application Data\deluge
2008-10-02 19:07 --------- d-----w c:\documents and settings\HOME\Application Data\gtk-2.0
2008-09-27 11:57 --------- d-----w c:\documents and settings\HOME\Application Data\Leadertech
2008-09-25 16:58 21,656 ----a-w c:\windows\system32\drivers\xfilt.sys
2008-09-25 16:57 12,952 ----a-w c:\windows\system32\drivers\videX32.sys
2008-09-20 15:47 720,896 ----a-w c:\windows\iun6002.exe
2007-10-08 16:59 24,192 ----a-w c:\documents and settings\HOME\usbsermptxp.sys
2007-10-08 16:59 22,768 ----a-w c:\documents and settings\HOME\usbsermpt.sys
2008-03-19 20:49 56 --sh–r c:\windows\system32[u]0[/u]7DA44351B.sys
2006-05-03 09:06 163,328 --sh–r c:\windows\system32\flvDX.dll
2008-03-19 20:49 10,856 --sha-w c:\windows\system32\KGyGaAvL.sys
2007-02-21 10:47 31,232 --sh–r c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“LXDDCATS”=“c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll” [2007-01-22 102400]
“CAMP SHIM EXIT HECK”=“c:\documents and settings\All Users.WINDOWS\Application Data\That Face Camp Shim\Book View.exe” [2008-11-15 4927488]
“QuickTime Task”=“c:\program files\QuickTime\qttask.exe” [2007-06-29 286720]
“PCSuiteTrayApplication”=“c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe” [2007-06-18 271360]
“HydraVisionDesktopManager”=“c:\program files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe” [2003-09-15 270336]
“avgnt”=“c:\program files\Avira\Avira Premium Security Suite\avgnt.exe” [2008-06-12 266497]
“NeroFilterCheck”=“c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe” [2006-01-12 155648]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]
“Nokia.PCSync”=“c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2007-06-19 1241088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
“NoFavoritesMenu”= 0 (0x0)
“NoSMMyPictures”= 0 (0x0)
“NoStartMenuMyMusic”= 0 (0x0)
“NoRecentDocsNetHood”= 0 (0x0)
“NoSimpleStartMenu”= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
“NoFavoritesMenu”= 0 (0x0)
“NoSMMyPictures”= 0 (0x0)
“NoStartMenuMyMusic”= 1 (0x1)
“NoRecentDocsNetHood”= 0 (0x0)
“ForceStartMenuLogoff”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\windows\system32\sajuyaya.dll c:\windows\system32\wemeyebi.dll
“LoadAppInit_DLLs”=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.mjpg”= pvmjpg30.dll
“msacm.dvacm”= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
“msacm.ulmp3acm”= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
“msacm.mpegacm”= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
[HKLM~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^ImageMixer HDD Camera Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\ImageMixer HDD Camera Monitor.lnk
backup=c:\windows\pss\ImageMixer HDD Camera Monitor.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^HOME^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=c:\documents and settings\HOME\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=c:\windows\pss\MSN Pictures Displayer.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^HOME^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.2.lnk]
path=c:\documents and settings\HOME\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.2.lnk
backup=c:\windows\pss\OpenOffice.org 2.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a------ 2005-06-23 19:33 57344 c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
–a------ 2006-12-23 18:05 143360 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
–a------ 2007-02-13 01:00 312240 c:\program files\Lexmark Fax Solutions\fm3032.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
–a------ 2005-06-08 13:44 196608 c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
–a------ 2005-06-08 14:24 458752 c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
–a------ 2005-06-08 14:14 217088 c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
–a------ 2005-07-19 16:32 221184 c:\windows\system32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
–a------ 2007-02-06 00:32 20480 c:\program files\Lexmark 2500 Series\lxddamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
–a------ 2007-02-13 00:58 291760 c:\program files\Lexmark 2500 Series\lxddmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a------ 2006-01-12 15:40 155648 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a------ 2007-06-18 14:10 271360 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a------ 2007-06-29 05:24 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
–a------ 2008-01-21 11:17 61440 c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 2005-05-03 11:43 69632 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2007-04-12 10:33 16132608 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
-ra------ 2007-02-06 00:30 176128 c:\windows\system32\S3Trayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
-ra------ 2006-09-21 09:36 53248 c:\windows\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“WMPNetworkSvc”=3 (0x3)
“WLSetupSvc”=3 (0x3)
“gusvc”=3 (0x3)
“Apple Mobile Device”=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“UpdatesDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
“FirewallOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“c:\Program Files\Lexmark 2500 Series\lxddamon.exe”=
“c:\Program Files\Lexmark 2500 Series\App4R.exe”=
“c:\WINDOWS\system32\lxddcoms.exe”=
“c:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe”=
“c:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe”=
“c:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe”=
“c:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“d:\GRID.exe”=
“c:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe”=
“c:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
“c:\WINDOWS\system32\services.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“135:TCP”= 135:TCP:TCP Port 135
“5000:TCP”= 5000:TCP:TCP Port 5000
“5001:TCP”= 5001:TCP:TCP Port 5001
“5002:TCP”= 5002:TCP:TCP Port 5002
“5003:TCP”= 5003:TCP:TCP Port 5003
“5004:TCP”= 5004:TCP:TCP Port 5004
“5005:TCP”= 5005:TCP:TCP Port 5005
“5006:TCP”= 5006:TCP:TCP Port 5006
“5007:TCP”= 5007:TCP:TCP Port 5007
“5008:TCP”= 5008:TCP:TCP Port 5008
“5009:TCP”= 5009:TCP:TCP Port 5009
“5010:TCP”= 5010:TCP:TCP Port 5010
“5011:TCP”= 5011:TCP:TCP Port 5011
“5012:TCP”= 5012:TCP:TCP Port 5012
“5013:TCP”= 5013:TCP:TCP Port 5013
“5014:TCP”= 5014:TCP:TCP Port 5014
“5015:TCP”= 5015:TCP:TCP Port 5015
“5016:TCP”= 5016:TCP:TCP Port 5016
“5017:TCP”= 5017:TCP:TCP Port 5017
“5018:TCP”= 5018:TCP:TCP Port 5018
“5019:TCP”= 5019:TCP:TCP Port 5019
“5020:TCP”= 5020:TCP:TCP Port 5020
“4668:TCP”= 4668:TCP:emuleTCP
“4669:UDP”= 4669:UDP:emuleUDP
R0 videX32;videX32;c:\windows\system32\DRIVERS\videX32.sys [2007-09-12 12952]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2007-09-12 21656]
R1 avfwot;avfwot;c:\windows\system32\DRIVERS\avfwot.sys [2008-11-12 71592]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;“c:\program files\Avira\Avira Premium Security Suite\avfwsvc.exe” [2008-11-12 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;“c:\program files\Avira\Avira Premium Security Suite\avmailc.exe” [2008-11-12 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;“c:\program files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE” [2008-11-12 258305]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;“c:\program files\Avira\Avira Premium Security Suite\avesvc.exe” [2008-11-12 41217]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service []
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys [2008-11-12 71464]
S3 DCamUSBIntel;KONICA_MINOLTA DiMAGE PC camera driver;c:\windows\system32\DRIVERS\mltcap.sys [2007-09-30 150240]
S3 ids00026;ids00026;??\c:\documents and settings\All Users.WINDOWS\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys []
S3 maconfservice;Ma-Config Service;“c:\program files\ma-config.com\maconfservice.exe” [2008-11-17 195752]
S3 S3GIGP;S3GIGP;c:\windows\system32\DRIVERS\S3gIGPm.sys [2007-09-12 709632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\setup.exe
.
Contenu du dossier ‘Tâches planifiées’
2008-11-23 c:\windows\Tasks\AD4E8B0691853E82.job
- c:\docume~1\home\applic~1\gramti~1\Mixhelpteam.exe []
2008-10-11 c:\windows\Tasks\At1.job
2008-03-11 c:\windows\Tasks\At2.job
2008-11-11 c:\windows\Tasks\At3.job
2008-03-11 c:\windows\Tasks\At4.job
2008-11-11 c:\windows\Tasks\At5.job
2008-10-11 c:\windows\Tasks\At6.job
- C:\Documents []
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
BHO-{04611f59-e061-4ac2-9c7d-245437cbcd83} - c:\windows\system32\mokomaru.dll
HKCU-Run-1great - c:\docume~1\HOME\APPLIC~1\GRAMTI~1\binlistabout.exe
MSConfigStartUp-eMuleAutoStart - c:\program files\eMule\emule.exe
MSConfigStartUp-PC Connection Agent - c:\program files\Microsoft ActiveSync\wcescomm.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
MSConfigStartUp-WINSOS VERIFY - c:\program files\Winsos\WINSOS.EXE
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\HOME\Application Data\Mozilla\Firefox\Profiles\ftm0ujbq.default
FireFox -: prefs.js - SEARCH.DEFAULTURL - www.google.com…
FF -: plugin - c:\documents and settings\HOME\Application Data\Mozilla\Firefox\Profiles\ftm0ujbq.default\extensions{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF -: plugin - c:\program files\ma-config.com\nphardwaredetection.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npigl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npitunes.dll
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-11-23 19:48:19
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
.
--------------------- DLLs chargées dans les processus actifs ---------------------
-
-
-
-
-
-
-
‘winlogon.exe’(708)
c:\windows\system32\Ati2evxx.dll
-
-
-
-
-
-
-
‘lsass.exe’(768)
c:\windows\system32\avsda.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Avira\Avira Premium Security Suite\sched.exe
c:\program files\Avira\Avira Premium Security Suite\avguard.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\windows\system32\lxddcoms.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Mozilla Firefox\firefox.exe
.
.
Heure de fin: 2008-11-23 19:54:18 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-23 18:52:58
Avant-CF: 38 994 419 712 octets libres
Après-CF: 39,195,611,136 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP dition familiale” /fastdetect /NoExecute=OptIn /noguiboot
350 — E O F — 2008-11-12 20:58:37