Onglets de pubs qui s ouvrent tout seul !
dread99
Messages postés
28
Statut
Membre
-
Jules -
Jules -
Bonjour,
Depuis quelques temps j ai des onglets de pub qui s ouvre tout seul ... parfois je suis redirigé sur ebay alors que j essai d aller sur un site qui n a rien à voir ??
Je suis sur Windows 7 avec Firefox ... meme probleme avec les autres navigateurs .. j ai essayé IE et d autres ...
Le plus bizarre c est qui aucun anti virus le mien Mac afee ... ni ceux en ligne ... ni meme les Malwarebytes ou Spybot ... ou Trojan Hunter ... je crois avoir tout essayer ... je trouve rien ...
J aurais besoin d expert ... svp !
Voici un rapport Hijackthis que je viens de faire : si quelqu un peut m aider ?
Depuis quelques temps j ai des onglets de pub qui s ouvre tout seul ... parfois je suis redirigé sur ebay alors que j essai d aller sur un site qui n a rien à voir ??
Je suis sur Windows 7 avec Firefox ... meme probleme avec les autres navigateurs .. j ai essayé IE et d autres ...
Le plus bizarre c est qui aucun anti virus le mien Mac afee ... ni ceux en ligne ... ni meme les Malwarebytes ou Spybot ... ou Trojan Hunter ... je crois avoir tout essayer ... je trouve rien ...
J aurais besoin d expert ... svp !
Voici un rapport Hijackthis que je viens de faire : si quelqu un peut m aider ?
A voir également:
- Onglets de pubs qui s ouvrent tout seul !
- Bloquer les pubs youtube - Accueil - Streaming
- Box sfr un seul voyant allumé - Forum SFR / NeufBox / Numéricable
- Comment supprimer les pubs qui apparaissent sans arrêt - Guide
- Rouvrir les onglets fermés chrome - Guide
- Mon téléphone bip tout seul - Forum Mobile
11 réponses
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:11:56, on 14/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Windows\System32\hdsp32.exe
C:\Windows\System32\hdspmix.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Pando Networks\Pando\Pando.exe
C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4\Transfer Utility\CameraMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100307140833.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundTray] C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [HDSPTray1] hdsp32.exe
O4 - HKLM\..\Run: [HDSPTray2] hdspmix.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Pando] C:\Program Files\Pando Networks\Pando\Pando.exe /Minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: ImageMixer 3 SE Camera Monitor Ver.4.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{972DD6B2-8D52-4EEB-B7E2-D4E1DCEF618B}: NameServer = 213.36.80.1
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0177621267967321) (0177621267967321mcinstcleanup) - Unknown owner - C:\Users\dread\AppData\Local\Temp\017762~1.EXE (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
Scan saved at 20:11:56, on 14/03/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
C:\Program Files\Syncrosoft\POS\H2O\cledx.exe
C:\Windows\System32\hdsp32.exe
C:\Windows\System32\hdspmix.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Pando Networks\Pando\Pando.exe
C:\Program Files\PIXELA\ImageMixer 3 SE Ver.4\Transfer Utility\CameraMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100307140833.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundTray] C:\Program Files\Analog Devices\SoundMAX\SoundTray.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [HDSPTray1] hdsp32.exe
O4 - HKLM\..\Run: [HDSPTray2] hdspmix.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Pando] C:\Program Files\Pando Networks\Pando\Pando.exe /Minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: ImageMixer 3 SE Camera Monitor Ver.4.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{972DD6B2-8D52-4EEB-B7E2-D4E1DCEF618B}: NameServer = 213.36.80.1
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0177621267967321) (0177621267967321mcinstcleanup) - Unknown owner - C:\Users\dread\AppData\Local\Temp\017762~1.EXE (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Je viens de refaire tourner Combofix et voici le rapport :
ComboFix 10-03-14.06 - dread 15/03/2010 9:34.1.2 - x86
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.33.1033.18.3327.2542 [GMT 1:00]
Lancé depuis: c:\users\dread\Downloads\ComboFix.exe
SP: AVG Anti-Spyware *disabled* (Updated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
* Un antivirus résident est actif
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-15 au 2010-03-15 ))))))))))))))))))))))))))))))))))))
.
2010-03-15 08:40 . 2010-03-15 08:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-14 16:44 . 2010-03-14 16:44 -------- d-----w- c:\program files\Trend Micro
2010-03-14 09:50 . 2010-03-14 13:52 -------- d-----w- c:\program files\a-squared Free
2010-03-14 09:26 . 2010-03-14 09:26 -------- d-----w- C:\VundoFix Backups
2010-03-14 08:48 . 2010-03-14 13:40 -------- d-----w- c:\windows\BDOSCAN8
2010-03-13 10:28 . 2010-03-14 15:20 -------- d---a-w- C:\Navilog1
2010-03-13 10:28 . 2010-03-13 10:28 -------- d-----w- c:\program files\navilog1
2010-03-13 08:30 . 2010-03-13 08:30 -------- d-----w- c:\program files\RME
2010-03-13 08:21 . 2010-02-19 13:14 656384 ----a-w- c:\windows\system32\hdsp32.exe
2010-03-13 08:21 . 2010-02-19 13:10 22528 ----a-w- c:\windows\system32\hdspasio.dll
2010-03-13 08:21 . 2010-02-18 15:09 97280 ----a-w- c:\windows\system32\drivers\hdsp_64.sys
2010-03-13 08:21 . 2010-02-18 15:09 65536 ----a-w- c:\windows\system32\drivers\hdsp.sys
2010-03-13 08:21 . 2010-02-15 19:44 1250304 ----a-w- c:\windows\system32\hdspmix.exe
2010-03-13 07:10 . 2010-03-13 07:10 141352 ---ha-w- c:\windows\system32\mlfcache.dat
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Roaming\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Local\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\programdata\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Local\Apple
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\programdata\Apple
2010-03-13 06:40 . 2010-03-13 06:40 -------- d-----w- c:\users\dread\AppData\Local\Deployment
2010-03-13 06:40 . 2010-03-13 06:40 -------- d-----w- c:\users\dread\AppData\Local\Apps
2010-03-10 18:56 . 2006-08-01 10:31 3600384 ----a-w- c:\windows\ffmpeg.exe
2010-03-10 18:56 . 2010-03-10 18:56 -------- d-----w- c:\program files\Hercules
2010-03-10 18:56 . 2008-02-27 14:27 98432 ----a-w- c:\windows\system32\drivers\camfilt2.sys
2010-03-10 18:56 . 2007-09-10 07:50 457984 ----a-w- c:\windows\system32\drivers\PAC7302.SYS
2010-03-10 18:56 . 2010-03-10 18:56 -------- d-----w- c:\windows\system32\HWC HD
2010-03-08 21:38 . 2010-03-09 14:56 -------- d-----w- c:\programdata\Grisoft
2010-03-08 15:11 . 2010-03-08 15:11 -------- d-----w- c:\program files\TrojanHunter
2010-03-08 15:06 . 2010-03-08 15:06 -------- d-----w- c:\users\dread\AppData\Roaming\TrojanHunter
2010-03-08 15:05 . 2010-03-14 23:08 -------- d-----w- c:\program files\TrojanHunter 5.0
2010-03-07 19:12 . 2010-03-14 10:18 -------- dc----w- c:\windows\system32\DRVSTORE
2010-03-07 19:12 . 2010-03-07 19:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-07 19:08 . 2010-03-14 10:18 -------- d-----w- c:\programdata\Lavasoft
2010-03-07 13:08 . 2010-01-05 17:04 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-03-07 13:08 . 2010-01-05 17:04 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-03-07 13:08 . 2010-01-05 17:04 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-03-07 13:08 . 2010-01-05 17:04 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-03-07 13:08 . 2010-01-05 17:04 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-03-07 13:08 . 2010-01-05 17:04 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-03-07 13:08 . 2010-01-05 17:04 385536 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-03-07 13:08 . 2010-01-05 17:04 312584 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-03-07 13:08 . 2010-01-05 17:04 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-03-07 13:08 . 2010-01-05 17:04 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-03-07 13:07 . 2010-03-09 14:56 -------- d-----w- c:\program files\Common Files\Mcafee
2010-03-07 13:07 . 2010-03-09 14:55 -------- d-----w- c:\program files\McAfee.com
2010-03-07 13:07 . 2010-03-09 14:56 -------- d-----w- c:\program files\McAfee
2010-03-07 10:03 . 2010-03-09 14:56 -------- d-----w- c:\programdata\McAfee
2010-02-26 14:17 . 2010-02-26 14:17 -------- d-----w- c:\users\dread\AppData\Roaming\Nero
2010-02-26 14:15 . 2006-03-17 13:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2010-02-26 14:15 . 2006-03-17 10:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2010-02-26 14:15 . 2006-03-17 10:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2010-02-26 14:15 . 2006-03-17 10:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2010-02-26 14:15 . 2006-03-17 10:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2010-02-26 14:15 . 2010-03-09 14:56 -------- d-----w- c:\program files\Common Files\Nero
2010-02-26 14:15 . 2010-03-09 14:56 -------- d-----w- c:\program files\Nero
2010-02-26 14:15 . 2010-02-26 14:15 -------- d-----w- c:\programdata\Nero
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-17 11:36 . 2008-06-12 08:46 4608 ----a-w- c:\windows\system32\drivers\vncmirror.sys
2010-02-17 11:36 . 2008-06-12 08:46 20992 ----a-w- c:\windows\system32\vncmirror.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-15 08:29 . 2009-10-08 19:09 -------- d-----w- c:\users\dread\AppData\Roaming\uTorrent
2010-03-14 22:50 . 2009-10-08 22:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-03-14 19:57 . 2009-12-05 15:13 -------- d-----w- c:\users\dread\AppData\Roaming\OneSwarm
2010-03-14 17:11 . 2009-09-08 18:10 -------- d-----w- c:\programdata\Soulseek
2010-03-14 11:01 . 2009-10-14 22:04 -------- d-----w- c:\users\dread\AppData\Roaming\foobar2000
2010-03-14 10:20 . 2010-03-14 10:20 0 ----a-w- c:\program files\Lavasoft
2010-03-14 07:10 . 2009-11-21 17:17 -------- d-----w- c:\program files\DivX
2010-03-13 11:36 . 2009-11-21 17:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-13 06:33 . 2009-11-05 13:20 -------- d-----w- c:\program files\Google
2010-03-10 18:56 . 2009-09-06 16:32 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-10 13:59 . 2009-07-13 23:11 21584 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-03-09 14:56 . 2009-11-26 21:33 -------- d-----w- c:\users\dread\AppData\Roaming\dvdcss
2010-03-09 14:56 . 2009-11-16 18:40 -------- d-----w- c:\users\dread\AppData\Roaming\vlc
2010-03-09 14:56 . 2009-10-08 19:10 -------- d-----w- c:\program files\Ask.com
2010-03-03 16:13 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Defender
2010-03-01 14:46 . 2009-11-01 12:34 -------- d-----w- c:\users\dread\AppData\Roaming\DC++
2010-01-30 13:31 . 2009-10-08 22:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 11:39 . 2009-12-05 15:17 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-26 07:52 . 2010-01-26 07:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-08 03:18 . 2010-02-21 11:24 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-21 11:24 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-07 15:07 . 2009-11-11 18:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-11-11 18:03 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 14:50 . 2009-12-24 14:50 35132 ----a-w- c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2009-12-24 14:50 . 2009-12-24 14:50 130048 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-12-19 09:02 . 2010-02-21 11:24 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-21 11:24 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-21 11:24 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-21 11:24 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-21 11:24 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-21 11:24 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-21 11:24 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-21 11:24 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-21 11:24 91648 ----a-w- c:\windows\system32\avifil32.dll
2010-01-05 17:04 . 2010-03-07 13:08 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2008-06-19 09:16 . 2008-06-19 09:16 118784 ----a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
------- Sigcheck -------
[-] 2009-11-14 . A6E0C9720DE23A1C785788D549A3C7E0 . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-11-26 289584]
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" [2009-12-05 4058808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-04-02 1261568]
"SoundTray"="c:\program files\Analog Devices\SoundMAX\SoundTray.exe" [2007-04-01 49152]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-22 385024]
"HDSPTray1"="hdsp32.exe" [2010-02-19 656384]
"HDSPTray2"="hdspmix.exe" [2010-02-15 1250304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-26 149280]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-03 1179952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor Ver.4.lnk - c:\program files\PIXELA\ImageMixer 3 SE Ver.4\Transfer Utility\CameraMonitor.exe [2009-11-15 253952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-14 721904]
R2 0177621267967321mcinstcleanup;McAfee Application Installer Cleanup (0177621267967321);c:\users\dread\AppData\Local\Temp\017762~1.EXE [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-01-05 83496]
R3 SjyPkt;SjyPkt;c:\windows\System32\Drivers\SjyPkt.sys [x]
R3 UKS11LDR;M-Audio USB Keystation Loader;c:\windows\system32\drivers\uks11ldr.sys [2007-11-14 20168]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-01-05 160720]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-01-05 64304]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\DRIVERS\rtlprot.sys [2007-04-02 15360]
S2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2009-10-01 1858144]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-01-05 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-01-05 141792]
S3 camfilt2;camfilt2;c:\windows\system32\DRIVERS\camfilt2.sys [2008-02-27 98432]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-01-05 55456]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 hdsp;RME Hammerfall Audio Device;c:\windows\system32\drivers\hdsp.sys [2010-02-18 65536]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-01-05 312584]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-06-26 335872]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contenu du dossier 'Tâches planifiées'
2010-03-15 c:\windows\Tasks\RtlVistaStart.job
- c:\program files\ASUS WiFi-AP Solo\RtWLan.exe [2009-09-06 08:30]
.
.
------- Examen supplémentaire -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: {972DD6B2-8D52-4EEB-B7E2-D4E1DCEF618B} = 213.36.80.1
FF - ProfilePath - c:\users\dread\AppData\Roaming\Mozilla\Firefox\Profiles\qwjbkgmp.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(1320)
c:\progra~1\mcafee\sitead~1\saHook.dll
.
Heure de fin: 2010-03-15 09:42:24
ComboFix-quarantined-files.txt 2010-03-15 08:42
Avant-CF: 413 281 673 216 bytes free
Après-CF: 412 828 790 784 bytes free
- - End Of File - - 5D6614C5EDA533433803F02ECD7A7D6C
ComboFix 10-03-14.06 - dread 15/03/2010 9:34.1.2 - x86
Microsoft Windows 7 Home Basic 6.1.7600.0.1252.33.1033.18.3327.2542 [GMT 1:00]
Lancé depuis: c:\users\dread\Downloads\ComboFix.exe
SP: AVG Anti-Spyware *disabled* (Updated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
* Un antivirus résident est actif
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-15 au 2010-03-15 ))))))))))))))))))))))))))))))))))))
.
2010-03-15 08:40 . 2010-03-15 08:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-14 16:44 . 2010-03-14 16:44 -------- d-----w- c:\program files\Trend Micro
2010-03-14 09:50 . 2010-03-14 13:52 -------- d-----w- c:\program files\a-squared Free
2010-03-14 09:26 . 2010-03-14 09:26 -------- d-----w- C:\VundoFix Backups
2010-03-14 08:48 . 2010-03-14 13:40 -------- d-----w- c:\windows\BDOSCAN8
2010-03-13 10:28 . 2010-03-14 15:20 -------- d---a-w- C:\Navilog1
2010-03-13 10:28 . 2010-03-13 10:28 -------- d-----w- c:\program files\navilog1
2010-03-13 08:30 . 2010-03-13 08:30 -------- d-----w- c:\program files\RME
2010-03-13 08:21 . 2010-02-19 13:14 656384 ----a-w- c:\windows\system32\hdsp32.exe
2010-03-13 08:21 . 2010-02-19 13:10 22528 ----a-w- c:\windows\system32\hdspasio.dll
2010-03-13 08:21 . 2010-02-18 15:09 97280 ----a-w- c:\windows\system32\drivers\hdsp_64.sys
2010-03-13 08:21 . 2010-02-18 15:09 65536 ----a-w- c:\windows\system32\drivers\hdsp.sys
2010-03-13 08:21 . 2010-02-15 19:44 1250304 ----a-w- c:\windows\system32\hdspmix.exe
2010-03-13 07:10 . 2010-03-13 07:10 141352 ---ha-w- c:\windows\system32\mlfcache.dat
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Roaming\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Local\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\programdata\Apple Computer
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\users\dread\AppData\Local\Apple
2010-03-13 07:10 . 2010-03-13 07:10 -------- d-----w- c:\programdata\Apple
2010-03-13 06:40 . 2010-03-13 06:40 -------- d-----w- c:\users\dread\AppData\Local\Deployment
2010-03-13 06:40 . 2010-03-13 06:40 -------- d-----w- c:\users\dread\AppData\Local\Apps
2010-03-10 18:56 . 2006-08-01 10:31 3600384 ----a-w- c:\windows\ffmpeg.exe
2010-03-10 18:56 . 2010-03-10 18:56 -------- d-----w- c:\program files\Hercules
2010-03-10 18:56 . 2008-02-27 14:27 98432 ----a-w- c:\windows\system32\drivers\camfilt2.sys
2010-03-10 18:56 . 2007-09-10 07:50 457984 ----a-w- c:\windows\system32\drivers\PAC7302.SYS
2010-03-10 18:56 . 2010-03-10 18:56 -------- d-----w- c:\windows\system32\HWC HD
2010-03-08 21:38 . 2010-03-09 14:56 -------- d-----w- c:\programdata\Grisoft
2010-03-08 15:11 . 2010-03-08 15:11 -------- d-----w- c:\program files\TrojanHunter
2010-03-08 15:06 . 2010-03-08 15:06 -------- d-----w- c:\users\dread\AppData\Roaming\TrojanHunter
2010-03-08 15:05 . 2010-03-14 23:08 -------- d-----w- c:\program files\TrojanHunter 5.0
2010-03-07 19:12 . 2010-03-14 10:18 -------- dc----w- c:\windows\system32\DRVSTORE
2010-03-07 19:12 . 2010-03-07 19:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-03-07 19:08 . 2010-03-14 10:18 -------- d-----w- c:\programdata\Lavasoft
2010-03-07 13:08 . 2010-01-05 17:04 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-03-07 13:08 . 2010-01-05 17:04 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-03-07 13:08 . 2010-01-05 17:04 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-03-07 13:08 . 2010-01-05 17:04 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-03-07 13:08 . 2010-01-05 17:04 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-03-07 13:08 . 2010-01-05 17:04 51688 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-03-07 13:08 . 2010-01-05 17:04 385536 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2010-03-07 13:08 . 2010-01-05 17:04 312584 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2010-03-07 13:08 . 2010-01-05 17:04 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-03-07 13:08 . 2010-01-05 17:04 152320 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-03-07 13:07 . 2010-03-09 14:56 -------- d-----w- c:\program files\Common Files\Mcafee
2010-03-07 13:07 . 2010-03-09 14:55 -------- d-----w- c:\program files\McAfee.com
2010-03-07 13:07 . 2010-03-09 14:56 -------- d-----w- c:\program files\McAfee
2010-03-07 10:03 . 2010-03-09 14:56 -------- d-----w- c:\programdata\McAfee
2010-02-26 14:17 . 2010-02-26 14:17 -------- d-----w- c:\users\dread\AppData\Roaming\Nero
2010-02-26 14:15 . 2006-03-17 13:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2010-02-26 14:15 . 2006-03-17 10:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2010-02-26 14:15 . 2006-03-17 10:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2010-02-26 14:15 . 2006-03-17 10:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2010-02-26 14:15 . 2006-03-17 10:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2010-02-26 14:15 . 2010-03-09 14:56 -------- d-----w- c:\program files\Common Files\Nero
2010-02-26 14:15 . 2010-03-09 14:56 -------- d-----w- c:\program files\Nero
2010-02-26 14:15 . 2010-02-26 14:15 -------- d-----w- c:\programdata\Nero
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-17 11:36 . 2008-06-12 08:46 4608 ----a-w- c:\windows\system32\drivers\vncmirror.sys
2010-02-17 11:36 . 2008-06-12 08:46 20992 ----a-w- c:\windows\system32\vncmirror.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-15 08:29 . 2009-10-08 19:09 -------- d-----w- c:\users\dread\AppData\Roaming\uTorrent
2010-03-14 22:50 . 2009-10-08 22:33 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-03-14 19:57 . 2009-12-05 15:13 -------- d-----w- c:\users\dread\AppData\Roaming\OneSwarm
2010-03-14 17:11 . 2009-09-08 18:10 -------- d-----w- c:\programdata\Soulseek
2010-03-14 11:01 . 2009-10-14 22:04 -------- d-----w- c:\users\dread\AppData\Roaming\foobar2000
2010-03-14 10:20 . 2010-03-14 10:20 0 ----a-w- c:\program files\Lavasoft
2010-03-14 07:10 . 2009-11-21 17:17 -------- d-----w- c:\program files\DivX
2010-03-13 11:36 . 2009-11-21 17:17 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-13 06:33 . 2009-11-05 13:20 -------- d-----w- c:\program files\Google
2010-03-10 18:56 . 2009-09-06 16:32 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-10 13:59 . 2009-07-13 23:11 21584 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-03-09 14:56 . 2009-11-26 21:33 -------- d-----w- c:\users\dread\AppData\Roaming\dvdcss
2010-03-09 14:56 . 2009-11-16 18:40 -------- d-----w- c:\users\dread\AppData\Roaming\vlc
2010-03-09 14:56 . 2009-10-08 19:10 -------- d-----w- c:\program files\Ask.com
2010-03-03 16:13 . 2009-07-14 04:52 -------- d-----w- c:\program files\Windows Defender
2010-03-01 14:46 . 2009-11-01 12:34 -------- d-----w- c:\users\dread\AppData\Roaming\DC++
2010-01-30 13:31 . 2009-10-08 22:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 11:39 . 2009-12-05 15:17 5115824 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-26 07:52 . 2010-01-26 07:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-08 03:18 . 2010-02-21 11:24 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-21 11:24 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-01-07 15:07 . 2009-11-11 18:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07 . 2009-11-11 18:03 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 14:50 . 2009-12-24 14:50 35132 ----a-w- c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2009-12-24 14:50 . 2009-12-24 14:50 130048 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-12-19 09:02 . 2010-02-21 11:24 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-21 11:24 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-21 11:24 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-21 11:24 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-21 11:24 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-21 11:24 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-21 11:24 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-21 11:24 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-21 11:24 91648 ----a-w- c:\windows\system32\avifil32.dll
2010-01-05 17:04 . 2010-03-07 13:08 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2008-06-19 09:16 . 2008-06-19 09:16 118784 ----a-w- c:\program files\mozilla firefox\plugins\MyCamera.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
------- Sigcheck -------
[-] 2009-11-14 . A6E0C9720DE23A1C785788D549A3C7E0 . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-11-26 289584]
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" [2009-12-05 4058808]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-04-02 1261568]
"SoundTray"="c:\program files\Analog Devices\SoundMAX\SoundTray.exe" [2007-04-01 49152]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-22 385024]
"HDSPTray1"="hdsp32.exe" [2010-02-19 656384]
"HDSPTray2"="hdspmix.exe" [2010-02-15 1250304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-26 149280]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-03 1179952]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor Ver.4.lnk - c:\program files\PIXELA\ImageMixer 3 SE Ver.4\Transfer Utility\CameraMonitor.exe [2009-11-15 253952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-14 721904]
R2 0177621267967321mcinstcleanup;McAfee Application Installer Cleanup (0177621267967321);c:\users\dread\AppData\Local\Temp\017762~1.EXE [x]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-01-05 83496]
R3 SjyPkt;SjyPkt;c:\windows\System32\Drivers\SjyPkt.sys [x]
R3 UKS11LDR;M-Audio USB Keystation Loader;c:\windows\system32\drivers\uks11ldr.sys [2007-11-14 20168]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-01-05 160720]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-01-05 64304]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\DRIVERS\rtlprot.sys [2007-04-02 15360]
S2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2009-10-01 1858144]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-01-05 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-01-05 141792]
S3 camfilt2;camfilt2;c:\windows\system32\DRIVERS\camfilt2.sys [2008-02-27 98432]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-01-05 55456]
S3 CLEDX;Team H2O CLEDX service;c:\windows\system32\DRIVERS\cledx.sys [2005-05-09 33792]
S3 hdsp;RME Hammerfall Audio Device;c:\windows\system32\drivers\hdsp.sys [2010-02-18 65536]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-01-05 312584]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
S3 RTL8187;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187.sys [2008-06-26 335872]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-09-28 315392]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contenu du dossier 'Tâches planifiées'
2010-03-15 c:\windows\Tasks\RtlVistaStart.job
- c:\program files\ASUS WiFi-AP Solo\RtWLan.exe [2009-09-06 08:30]
.
.
------- Examen supplémentaire -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: {972DD6B2-8D52-4EEB-B7E2-D4E1DCEF618B} = 213.36.80.1
FF - ProfilePath - c:\users\dread\AppData\Roaming\Mozilla\Firefox\Profiles\qwjbkgmp.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPCIG.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(1320)
c:\progra~1\mcafee\sitead~1\saHook.dll
.
Heure de fin: 2010-03-15 09:42:24
ComboFix-quarantined-files.txt 2010-03-15 08:42
Avant-CF: 413 281 673 216 bytes free
Après-CF: 412 828 790 784 bytes free
- - End Of File - - 5D6614C5EDA533433803F02ECD7A7D6C
Essaie du supprimer : c:\users\dread\AppData\Local\Temp\017762~1.EXE
C'est la seul chose que je vois. (Je ne suis pas non plus un professionnel)
C'est la seul chose que je vois. (Je ne suis pas non plus un professionnel)
j ai toujours le meme probleme malgre des millions de manips .... je desespere vraiment ... c est quoi ce truc ?
voici le genre de page qui s ouvre ...
ca ferme carrement la page sur laquelle je suis ....
http://go-protect-my-system.xorg.pl/...
ca ferme carrement la page sur laquelle je suis ....
http://go-protect-my-system.xorg.pl/...