A voir également:
- Pc lent + Oneclick.exe + Msn & Itunes lent
- Pc lent - Guide
- Mon mac est lent comment le nettoyer - Guide
- Test performance pc - Guide
- Mon pc est trop lent et se bloque - Guide
- Reinitialiser pc - Guide
3 réponses
Utilisateur anonyme
2 juin 2009 à 20:22
2 juin 2009 à 20:22
C'est normal...
BitDefender est l'antivirus qui fait le + de beugs (ils fait beuger l'apparence, vous affiche pleins de messages d'erreurs, réduit la connexion Internet avec ses mises à jours...)
BitDefender est l'antivirus qui fait le + de beugs (ils fait beuger l'apparence, vous affiche pleins de messages d'erreurs, réduit la connexion Internet avec ses mises à jours...)
Utilisateur anonyme
2 juin 2009 à 20:23
2 juin 2009 à 20:23
Le débit 54 Mbits/s c'est la puissance de conexion WiFi mais pas la puissance de ta connexion elle même. Et pour ton ordi combien a t il de ram ?
Euh... Je dirais 512. Mais pas sur =s
Voila le log.txt en esperant que ca vous aide.
Dure j'ai un antivirus en carton --'
ComboFix 08-12-25.04 - Administrateur 2009-06-02 21:54:20.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.511.248 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\combo-fix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
.
- Mode FONCTIONNALITES REDUITES -
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\install\install.exe
c:\program files\OneStepSearch
c:\program files\OneStepSearch\home.js
c:\program files\OneStepSearch\readme.html
c:\program files\video access activex object
c:\windows\system32\Penx.dat
c:\windows\system32\Xpen.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-02 au 2009-06-02 ))))))))))))))))))))))))))))))))))))
.
2009-06-02 19:04 . 2009-06-02 19:39 91,648 --a------ C:\cp1041.nls
2009-05-29 19:32 . 2009-05-29 19:32 <REP> d-------- C:\Themes
2009-05-29 19:31 . 2009-05-29 19:31 <REP> d--hs---- C:\INCINERATE
2009-05-28 18:02 . 2009-06-01 20:08 54,156 --ah----- c:\windows\QTFont.qfn
2009-05-28 18:02 . 2009-05-28 18:02 1,409 --a------ c:\windows\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 17:32 --------- d-----w c:\program files\iolo
2009-05-29 17:32 --------- d-----w c:\program files\CursorXP
2009-05-29 17:28 --------- d-----w c:\program files\AviSynth 2.5
2009-05-29 08:09 --------- d-----w c:\program files\World of Warcraft
2009-05-27 20:56 81,984 ----a-w c:\windows\system32\bdod.bin
2009-05-08 12:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-05-02 17:52 --------- d-----w c:\program files\Azureus
2009-04-28 22:12 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-04-28 22:12 110,278 ----a-w c:\windows\BricoPackUninst.cmd
2009-04-28 17:00 --------- d-----w c:\program files\Ubisoft
2009-04-28 16:58 --------- d-----w c:\program files\BoontyGames
2009-04-28 16:57 --------- d-----w c:\program files\Symantec
2009-04-28 16:57 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-04-27 20:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-24 19:17 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2009-04-23 17:47 54,784 ----a-w c:\windows\system32\drivers\CDAC11BA.EXE
2009-04-23 17:47 12,464 ----a-w c:\windows\system32\drivers\CdaC15BA.SYS
2009-04-23 17:47 --------- d-----w c:\program files\Fichiers communs\Macrovision Shared
2009-04-23 17:47 --------- d-----w c:\documents and settings\All Users\Application Data\Macrovision
2009-04-23 17:27 --------- d-----w c:\program files\WildTangent
2009-04-12 11:50 --------- d-----w c:\program files\MSXML 4.0
2009-04-11 12:16 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-04-11 12:12 --------- d-----w c:\program files\Fichiers communs\BitDefender
2009-04-11 12:12 --------- d-----w c:\program files\BitDefender
2009-04-11 12:12 --------- d-----w c:\documents and settings\Administrateur\Application Data\BitDefender
2009-04-11 10:07 --------- d-----w c:\program files\Oberon Media
2009-04-10 05:31 81,920 ----a-w c:\windows\system32\W32N50.dll
2009-04-10 05:31 17,134 -c--a-w c:\windows\system32\PCANDIS5.sys
2009-04-09 20:53 --------- d-----w c:\program files\Wanadoo
2009-04-09 20:49 --------- d-----w c:\program files\RivaTuner v2.21
2009-04-09 20:49 --------- d-----w c:\program files\Fichiers communs\DivX Shared
2009-04-09 20:49 --------- d-----w c:\program files\DivX
2009-04-09 20:47 --------- d-----w c:\program files\GamesBar
2009-04-04 07:03 --------- d-----w c:\documents and settings\All Users\Application Data\WotT
2009-03-25 19:14 21,840 -c--atw c:\windows\system32\SIntfNT.dll
2009-03-25 19:14 17,212 -c--atw c:\windows\system32\SIntf32.dll
2009-03-25 19:14 12,067 -c--atw c:\windows\system32\SIntf16.dll
2009-03-06 14:46 286,208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 10:18 37,864 ----a-w c:\documents and settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
2009-03-03 00:13 817,152 ----a-w c:\windows\system32\wininet.dll
2008-05-31 06:47 7,710,016 -c--a-w c:\program files\FLV PlayerRCATSetup.exe
2008-05-31 06:47 2,725,048 -c--a-w c:\program files\FLV PlayerFCSetup.exe
2008-05-31 06:44 411,248 -c--a-w c:\program files\FLV PlayerRCSetup.exe
2007-05-28 17:57 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2009-01-27 01:34 1,044,480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 200,704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-03-05 16:08 49,664 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTCheck"="c:\program files\Creative\ZEN Media Explorer\CTCheck.exe" [2007-10-25 380928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-05-26 257088]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-03-19 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-02-23 69632]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=qabapia.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rundll32.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\Explorer.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24784:TCP"= 24784:TCP:BitComet 24784 TCP
"24784:UDP"= 24784:UDP:BitComet 24784 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2009-02-12 104328]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
S2 QabapiDriver;Qabapi Driver;\??\c:\windows\system32\qabapi.sys []
S3 CCCP106;TRUST 120 SPACEC@M;c:\windows\system32\DRIVERS\cccp106.sys [2007-02-20 227200]
S3 qqd.sys;qqd.sys;\??\C:\qqd.sys []
S3 zlportio;zlportio;\??\c:\program files\UltraStar Deluxe\zlportio.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{280e196d-eec7-11dc-abb2-00032f417425}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f0c9ed3-bebd-11dc-ab5a-00032f417425}]
\Shell\AutoRun\command - F:\start.exe
\Shell\iledefrance\command - F:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdb9e506-18ef-11dd-ac19-00032f417425}]
\Shell\AutoRun\command - F:\
\Shell\explore\Command - RECYCLER\INFO.exe
\Shell\open\Command - RECYCLER\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e27001c1-728d-11dc-aa9b-00032f417425}]
\Shell\AutoRun\command - F:\AutoRun.exe
\Shell\Shell01\Command - F:\AutoRun.exe
\Shell\Shell02\Command - Allway Sync\Bin\syncappw.exe
\Shell\Shell03\Command - f:\datasafe\DataSafe.exe
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Tâches planifiées'
2009-06-02 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-04-22 14:17]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\Microsoft Office\Office10\EXCEL.EXE/3000
IE: Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CTSUEng.ocx - c:\windows\Downloaded Program Files\CTSUEngn.ocx
O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884}
hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
c:\windows\Downloaded Program Files\CTSUEng.inf
c:\windows\Downloaded Program Files\dream.1.0.0.9.dll - O16 -: {775879E2-7309-4619-BB02-AADE41F4B690}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
c:\windows\Downloaded Program Files\dream.1.0.0.9.inf
c:\windows\Downloaded Program Files\CONFLICT.1\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\CONFLICT.1\OberonGameHost_dbg.inf
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\default.pf8\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
[color=red]ATTENTION: FIREFOX POLICES IS IN FORCE /color
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.01.01
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 21:55:59
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-06-02 22:03:24
ComboFix-quarantined-files.txt 2009-06-02 20:03:19
Avant-CF: 6 121 627 648 octets libres
Après-CF: 6,341,046,272 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel (bootscreen)" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
221 --- E O F --- 2009-05-13 22:56:19
Voila le log.txt en esperant que ca vous aide.
Dure j'ai un antivirus en carton --'
ComboFix 08-12-25.04 - Administrateur 2009-06-02 21:54:20.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.511.248 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\combo-fix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
.
- Mode FONCTIONNALITES REDUITES -
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\install\install.exe
c:\program files\OneStepSearch
c:\program files\OneStepSearch\home.js
c:\program files\OneStepSearch\readme.html
c:\program files\video access activex object
c:\windows\system32\Penx.dat
c:\windows\system32\Xpen.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-02 au 2009-06-02 ))))))))))))))))))))))))))))))))))))
.
2009-06-02 19:04 . 2009-06-02 19:39 91,648 --a------ C:\cp1041.nls
2009-05-29 19:32 . 2009-05-29 19:32 <REP> d-------- C:\Themes
2009-05-29 19:31 . 2009-05-29 19:31 <REP> d--hs---- C:\INCINERATE
2009-05-28 18:02 . 2009-06-01 20:08 54,156 --ah----- c:\windows\QTFont.qfn
2009-05-28 18:02 . 2009-05-28 18:02 1,409 --a------ c:\windows\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-29 17:32 --------- d-----w c:\program files\iolo
2009-05-29 17:32 --------- d-----w c:\program files\CursorXP
2009-05-29 17:28 --------- d-----w c:\program files\AviSynth 2.5
2009-05-29 08:09 --------- d-----w c:\program files\World of Warcraft
2009-05-27 20:56 81,984 ----a-w c:\windows\system32\bdod.bin
2009-05-08 12:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-05-02 17:52 --------- d-----w c:\program files\Azureus
2009-04-28 22:12 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-04-28 22:12 110,278 ----a-w c:\windows\BricoPackUninst.cmd
2009-04-28 17:00 --------- d-----w c:\program files\Ubisoft
2009-04-28 16:58 --------- d-----w c:\program files\BoontyGames
2009-04-28 16:57 --------- d-----w c:\program files\Symantec
2009-04-28 16:57 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-04-27 20:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-24 19:17 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2009-04-23 17:47 54,784 ----a-w c:\windows\system32\drivers\CDAC11BA.EXE
2009-04-23 17:47 12,464 ----a-w c:\windows\system32\drivers\CdaC15BA.SYS
2009-04-23 17:47 --------- d-----w c:\program files\Fichiers communs\Macrovision Shared
2009-04-23 17:47 --------- d-----w c:\documents and settings\All Users\Application Data\Macrovision
2009-04-23 17:27 --------- d-----w c:\program files\WildTangent
2009-04-12 11:50 --------- d-----w c:\program files\MSXML 4.0
2009-04-11 12:16 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-04-11 12:12 --------- d-----w c:\program files\Fichiers communs\BitDefender
2009-04-11 12:12 --------- d-----w c:\program files\BitDefender
2009-04-11 12:12 --------- d-----w c:\documents and settings\Administrateur\Application Data\BitDefender
2009-04-11 10:07 --------- d-----w c:\program files\Oberon Media
2009-04-10 05:31 81,920 ----a-w c:\windows\system32\W32N50.dll
2009-04-10 05:31 17,134 -c--a-w c:\windows\system32\PCANDIS5.sys
2009-04-09 20:53 --------- d-----w c:\program files\Wanadoo
2009-04-09 20:49 --------- d-----w c:\program files\RivaTuner v2.21
2009-04-09 20:49 --------- d-----w c:\program files\Fichiers communs\DivX Shared
2009-04-09 20:49 --------- d-----w c:\program files\DivX
2009-04-09 20:47 --------- d-----w c:\program files\GamesBar
2009-04-04 07:03 --------- d-----w c:\documents and settings\All Users\Application Data\WotT
2009-03-25 19:14 21,840 -c--atw c:\windows\system32\SIntfNT.dll
2009-03-25 19:14 17,212 -c--atw c:\windows\system32\SIntf32.dll
2009-03-25 19:14 12,067 -c--atw c:\windows\system32\SIntf16.dll
2009-03-06 14:46 286,208 ----a-w c:\windows\system32\pdh.dll
2009-03-03 10:18 37,864 ----a-w c:\documents and settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
2009-03-03 00:13 817,152 ----a-w c:\windows\system32\wininet.dll
2008-05-31 06:47 7,710,016 -c--a-w c:\program files\FLV PlayerRCATSetup.exe
2008-05-31 06:47 2,725,048 -c--a-w c:\program files\FLV PlayerFCSetup.exe
2008-05-31 06:44 411,248 -c--a-w c:\program files\FLV PlayerRCSetup.exe
2007-05-28 17:57 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2009-01-27 01:34 1,044,480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 200,704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-03-05 16:08 49,664 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTCheck"="c:\program files\Creative\ZEN Media Explorer\CTCheck.exe" [2007-10-25 380928]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-05-26 257088]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-03-19 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-02-23 69632]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=qabapia.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rundll32.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\Explorer.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24784:TCP"= 24784:TCP:BitComet 24784 TCP
"24784:UDP"= 24784:UDP:BitComet 24784 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R2 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2009-02-12 104328]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
S2 QabapiDriver;Qabapi Driver;\??\c:\windows\system32\qabapi.sys []
S3 CCCP106;TRUST 120 SPACEC@M;c:\windows\system32\DRIVERS\cccp106.sys [2007-02-20 227200]
S3 qqd.sys;qqd.sys;\??\C:\qqd.sys []
S3 zlportio;zlportio;\??\c:\program files\UltraStar Deluxe\zlportio.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{280e196d-eec7-11dc-abb2-00032f417425}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f0c9ed3-bebd-11dc-ab5a-00032f417425}]
\Shell\AutoRun\command - F:\start.exe
\Shell\iledefrance\command - F:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdb9e506-18ef-11dd-ac19-00032f417425}]
\Shell\AutoRun\command - F:\
\Shell\explore\Command - RECYCLER\INFO.exe
\Shell\open\Command - RECYCLER\INFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e27001c1-728d-11dc-aa9b-00032f417425}]
\Shell\AutoRun\command - F:\AutoRun.exe
\Shell\Shell01\Command - F:\AutoRun.exe
\Shell\Shell02\Command - Allway Sync\Bin\syncappw.exe
\Shell\Shell03\Command - f:\datasafe\DataSafe.exe
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Tâches planifiées'
2009-06-02 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-04-22 14:17]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\Microsoft Office\Office10\EXCEL.EXE/3000
IE: Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm
IE: Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CTSUEng.ocx - c:\windows\Downloaded Program Files\CTSUEngn.ocx
O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884}
hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
c:\windows\Downloaded Program Files\CTSUEng.inf
c:\windows\Downloaded Program Files\dream.1.0.0.9.dll - O16 -: {775879E2-7309-4619-BB02-AADE41F4B690}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--9b4e31a2-26b0-4209-92b6-ee687a2aabd4/online/dream_chronicles/fr/dreamweb.1.0.0.9.cab
c:\windows\Downloaded Program Files\dream.1.0.0.9.inf
c:\windows\Downloaded Program Files\CONFLICT.1\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\CONFLICT.1\OberonGameHost_dbg.inf
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\default.pf8\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPJPI150_03.dll
FF - plugin: c:\program files\Java\jre1.5.0_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
[color=red]ATTENTION: FIREFOX POLICES IS IN FORCE /color
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v2.01.01
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-02 21:55:59
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-06-02 22:03:24
ComboFix-quarantined-files.txt 2009-06-02 20:03:19
Avant-CF: 6 121 627 648 octets libres
Après-CF: 6,341,046,272 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel (bootscreen)" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
221 --- E O F --- 2009-05-13 22:56:19