Win.exe combofix
Fermé
slash45
Messages postés
2
Date d'inscription
jeudi 31 août 2006
Statut
Membre
Dernière intervention
13 mars 2010
-
13 mars 2010 à 18:31
slash45 Messages postés 2 Date d'inscription jeudi 31 août 2006 Statut Membre Dernière intervention 13 mars 2010 - 13 mars 2010 à 18:32
slash45 Messages postés 2 Date d'inscription jeudi 31 août 2006 Statut Membre Dernière intervention 13 mars 2010 - 13 mars 2010 à 18:32
1 réponse
slash45
Messages postés
2
Date d'inscription
jeudi 31 août 2006
Statut
Membre
Dernière intervention
13 mars 2010
13 mars 2010 à 18:32
13 mars 2010 à 18:32
Et voici le rapport de ComboFix :
ComboFix 10-03-12.04 - H & N 13/03/2010 15:40:05.1.1 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.511.165 [GMT 1:00]
Lancé depuis: c:\documents and settings\H & N\Bureau\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-13 au 2010-03-13 ))))))))))))))))))))))))))))))))))))
.
2010-03-13 11:50 . 2010-03-13 11:50 -------- d-----w- c:\documents and settings\Najeh\Application Data\Yahoo!
2010-03-13 11:46 . 2010-03-13 11:46 -------- d-----w- c:\documents and settings\H & N\Application Data\Yahoo!
2010-03-13 01:16 . 2010-03-13 01:16 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Yahoo!
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\program files\Yahoo!
2010-03-13 00:42 . 2010-03-13 00:42 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Uniblue
2010-03-12 22:55 . 2010-03-12 22:55 -------- d-----w- c:\documents and settings\H & N\Application Data\Uniblue
2010-03-12 22:13 . 2010-03-12 22:13 -------- d-----w- c:\program files\Trend Micro
2010-03-12 04:35 . 2010-03-12 04:35 -------- d--h--w- c:\windows\PIF
2010-03-11 22:04 . 2010-03-11 22:05 64960 ----a-w- c:\documents and settings\H & N\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 02:48 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-07 18:29 . 2010-03-07 18:29 -------- d---a-w- C:\Navilog1
2010-02-21 21:24 . 2010-02-21 21:24 -------- d-----w- C:\FOUND.002
2010-02-20 00:21 . 2010-02-20 00:21 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-18 14:30 . 2001-08-17 20:56 7552 ----a-w- c:\windows\system32\drivers\SONYPVU1.SYS
2010-02-18 14:30 . 2001-08-17 20:56 7552 ----a-w- c:\windows\system32\dllcache\sonypvu1.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-11 21:08 . 2009-11-13 10:17 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-07 22:46 . 2004-09-20 17:47 84964 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-07 22:46 . 2004-09-20 17:47 510980 ----a-w- c:\windows\system32\perfh00C.dat
2010-02-11 09:43 . 2010-02-11 09:43 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-02-02 21:52 . 2010-02-02 21:52 -------- d-----w- c:\documents and settings\H & N\Application Data\dvdcss
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----w- c:\documents and settings\H & N\Application Data\Skype
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----w- c:\program files\Fichiers communs\Skype
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----r- c:\program files\Skype
2010-01-13 23:01 . 2010-01-13 23:01 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 15:07 . 2009-11-13 09:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-11-13 09:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2004-09-20 17:46 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:07 . 2004-09-20 17:46 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:41 . 2009-11-12 20:40 347648 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:09 . 2004-09-20 17:46 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2005-05-11 102400]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-20 2805248]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2005-06-16 86016]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-13 08:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Photags AutoDetect.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Photags AutoDetect.lnk
backup=c:\windows\pss\Photags AutoDetect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
2003-09-19 11:54 172032 ----a-w- c:\program files\ASUS\ASUS Live Update\ALU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Athan]
2009-08-23 00:14 1114112 ----a-w- c:\program files\Athan\Athan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-02-12 20:05 339968 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2009-12-12 08:01 2043160 ----a-w- c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-01-07 15:07 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-20 04:07 90112 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-12-21 06:23 688218 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-12-21 06:23 98394 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console]
2005-06-20 18:16 57344 ----a-w- c:\program files\ASUS\Wireless Console\wcourier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/11/2009 09:04 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/11/2009 09:04 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/11/2009 09:04 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [13/11/2009 09:11 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/11/2009 09:11 297752]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [13/11/2009 10:30 236368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [13/11/2009 10:30 19160]
.
Contenu du dossier 'Tâches planifiées'
2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{F01827B3-D5C8-47AB-B622-9E574C94A54E}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{EDC51865-C132-46FF-A893-9F491FC9BD38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
2010-03-12 c:\windows\Tasks\Malwarebytes' Scheduled Update for H & N.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-13 15:07]
2010-03-12 c:\windows\Tasks\Malwarebytes' Scheduled Scan for H & N.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-13 15:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.freewebtown.com/blackooh/BlaCk-TiMeind3x.html.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
AddRemove-CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966 - c:\program files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966\HXFSETUP.EXE -U -IHDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_10431966
AddRemove-{C5F1D23A-5282-467D-B0DA-B0D6F661D587} - c:\program files\InstallShield Installation Information\{C5F1D23A-5282-467D-B0DA-B0D6F661D587}\Setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-13 15:45
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Heure de fin: 2010-03-13 15:47:09
ComboFix-quarantined-files.txt 2010-03-13 14:47
Avant-CF: 24 238 948 352 octets libres
Après-CF: 25 744 900 096 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - A075D84F00BF26EAF79C9DE10EB11922
ComboFix 10-03-12.04 - H & N 13/03/2010 15:40:05.1.1 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.511.165 [GMT 1:00]
Lancé depuis: c:\documents and settings\H & N\Bureau\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-13 au 2010-03-13 ))))))))))))))))))))))))))))))))))))
.
2010-03-13 11:50 . 2010-03-13 11:50 -------- d-----w- c:\documents and settings\Najeh\Application Data\Yahoo!
2010-03-13 11:46 . 2010-03-13 11:46 -------- d-----w- c:\documents and settings\H & N\Application Data\Yahoo!
2010-03-13 01:16 . 2010-03-13 01:16 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Yahoo!
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-03-13 00:57 . 2010-03-13 00:57 -------- d-----w- c:\program files\Yahoo!
2010-03-13 00:42 . 2010-03-13 00:42 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Uniblue
2010-03-12 22:55 . 2010-03-12 22:55 -------- d-----w- c:\documents and settings\H & N\Application Data\Uniblue
2010-03-12 22:13 . 2010-03-12 22:13 -------- d-----w- c:\program files\Trend Micro
2010-03-12 04:35 . 2010-03-12 04:35 -------- d--h--w- c:\windows\PIF
2010-03-11 22:04 . 2010-03-11 22:05 64960 ----a-w- c:\documents and settings\H & N\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 02:48 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-07 18:29 . 2010-03-07 18:29 -------- d---a-w- C:\Navilog1
2010-02-21 21:24 . 2010-02-21 21:24 -------- d-----w- C:\FOUND.002
2010-02-20 00:21 . 2010-02-20 00:21 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-18 14:30 . 2001-08-17 20:56 7552 ----a-w- c:\windows\system32\drivers\SONYPVU1.SYS
2010-02-18 14:30 . 2001-08-17 20:56 7552 ----a-w- c:\windows\system32\dllcache\sonypvu1.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-11 21:08 . 2009-11-13 10:17 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-07 22:46 . 2004-09-20 17:47 84964 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-07 22:46 . 2004-09-20 17:47 510980 ----a-w- c:\windows\system32\perfh00C.dat
2010-02-11 09:43 . 2010-02-11 09:43 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-02-02 21:52 . 2010-02-02 21:52 -------- d-----w- c:\documents and settings\H & N\Application Data\dvdcss
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----w- c:\documents and settings\H & N\Application Data\Skype
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----w- c:\program files\Fichiers communs\Skype
2010-01-21 18:50 . 2010-01-21 18:50 -------- d-----r- c:\program files\Skype
2010-01-13 23:01 . 2010-01-13 23:01 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-07 15:07 . 2009-11-13 09:30 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-11-13 09:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:50 . 2004-09-20 17:46 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:07 . 2004-09-20 17:46 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 07:41 . 2009-11-12 20:40 347648 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:09 . 2004-09-20 17:46 33280 ----a-w- c:\windows\system32\csrsrv.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="c:\windows\ATK0100\HControl.exe" [2005-05-11 102400]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 61952]
"AlcWzrd"="ALCWZRD.EXE" [2005-04-20 2805248]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2005-06-16 86016]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-13 08:11 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 10:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Bluetooth Manager.lnk
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Photags AutoDetect.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Photags AutoDetect.lnk
backup=c:\windows\pss\Photags AutoDetect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Live Update]
2003-09-19 11:54 172032 ----a-w- c:\program files\ASUS\ASUS Live Update\ALU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Athan]
2009-08-23 00:14 1114112 ----a-w- c:\program files\Athan\Athan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-02-12 20:05 339968 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2009-12-12 08:01 2043160 ----a-w- c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2010-01-07 15:07 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-04-20 04:07 90112 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-12-21 06:23 688218 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-12-21 06:23 98394 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console]
2005-06-20 18:16 57344 ----a-w- c:\program files\ASUS\Wireless Console\wcourier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [13/11/2009 09:04 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [13/11/2009 09:04 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [13/11/2009 09:04 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [13/11/2009 09:11 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [13/11/2009 09:11 297752]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [13/11/2009 10:30 236368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [13/11/2009 10:30 19160]
.
Contenu du dossier 'Tâches planifiées'
2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{F01827B3-D5C8-47AB-B622-9E574C94A54E}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
2010-03-13 c:\windows\Tasks\User_Feed_Synchronization-{EDC51865-C132-46FF-A893-9F491FC9BD38}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
2010-03-12 c:\windows\Tasks\Malwarebytes' Scheduled Update for H & N.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-13 15:07]
2010-03-12 c:\windows\Tasks\Malwarebytes' Scheduled Scan for H & N.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-11-13 15:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.freewebtown.com/blackooh/BlaCk-TiMeind3x.html.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
AddRemove-CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966 - c:\program files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_10431966\HXFSETUP.EXE -U -IHDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_10431966
AddRemove-{C5F1D23A-5282-467D-B0DA-B0D6F661D587} - c:\program files\InstallShield Installation Information\{C5F1D23A-5282-467D-B0DA-B0D6F661D587}\Setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-13 15:45
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Heure de fin: 2010-03-13 15:47:09
ComboFix-quarantined-files.txt 2010-03-13 14:47
Avant-CF: 24 238 948 352 octets libres
Après-CF: 25 744 900 096 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - A075D84F00BF26EAF79C9DE10EB11922