Problème Bad Pool Header et ouverture Firefox
Résolu/Fermé
tanguy76310
Messages postés
95
Date d'inscription
mercredi 7 janvier 2009
Statut
Membre
Dernière intervention
28 juillet 2014
-
12 janv. 2011 à 19:08
tanguy76310 Messages postés 95 Date d'inscription mercredi 7 janvier 2009 Statut Membre Dernière intervention 28 juillet 2014 - 14 janv. 2011 à 21:09
tanguy76310 Messages postés 95 Date d'inscription mercredi 7 janvier 2009 Statut Membre Dernière intervention 28 juillet 2014 - 14 janv. 2011 à 21:09
A voir également:
- Problème Bad Pool Header et ouverture Firefox
- Video downloadhelper firefox - Télécharger - Outils pour navigateurs
- Comment supprimer bing de firefox - Guide
- Page d'ouverture google - Guide
- Exporter favoris firefox - Guide
- Firefox download - Télécharger - Navigateurs
43 réponses
tanguy76310
Messages postés
95
Date d'inscription
mercredi 7 janvier 2009
Statut
Membre
Dernière intervention
28 juillet 2014
14 janv. 2011 à 13:11
14 janv. 2011 à 13:11
Voilà le rapport Combofix :
ComboFix 11-01-11.03 - Tanguy 14/01/2011 13:00:40.1.2 - x86
Microsoft Windows 7 Professionnel 6.1.7600.0.1252.33.1036.18.3067.2078 [GMT 1:00]
Lancé depuis: c:\users\Tanguy\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Tanguy\AppData\Roaming\dach100.dll
c:\users\Tanguy\AppData\Roaming\sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-12-14 au 2011-01-14 ))))))))))))))))))))))))))))))))))))
.
2011-01-14 12:06 . 2011-01-14 12:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-13 19:51 . 2011-01-13 19:51 -------- d-----w- C:\_OTM
2011-01-13 17:03 . 2011-01-13 17:23 -------- d-----w- C:\UsbFix
2011-01-13 10:33 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{087CFDCB-9FBD-4941-997D-73912A9ED1B9}\mpengine.dll
2011-01-12 21:55 . 2011-01-13 16:20 -------- d-----w- C:\tdsskiller
2011-01-12 19:03 . 2011-01-12 19:03 -------- d-----w- c:\programdata\ATI
2011-01-12 19:03 . 2011-01-12 19:03 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-01-12 19:03 . 2011-01-13 21:38 -------- d-----w- c:\program files\ZHPDiag
2011-01-12 18:57 . 2010-11-05 22:39 354840 ----a-w- c:\windows\system32\drivers\iaStor.sys
2011-01-12 18:09 . 2011-01-12 21:28 -------- d-----w- c:\users\Tanguy\AppData\Local\Google
2011-01-12 18:09 . 2011-01-12 20:23 -------- d-----w- c:\users\Tanguy\AppData\Local\Deployment
2011-01-12 18:09 . 2011-01-12 18:09 -------- d-----w- c:\users\Tanguy\AppData\Local\Apps
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\users\Tanguy\AppData\Roaming\Malwarebytes
2011-01-12 16:39 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\programdata\Malwarebytes
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-12 16:39 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 15:31 . 2011-01-12 15:31 -------- d-----w- c:\program files\Dachshund Software
2011-01-12 15:13 . 2011-01-12 15:14 -------- d--h--w- c:\windows\AxInstSV
2011-01-10 20:23 . 2011-01-10 20:23 -------- d-----w- c:\program files\Bonjour
2010-12-28 18:07 . 2010-12-28 18:07 -------- d-----w- c:\windows\Sun
2010-12-27 10:58 . 2010-12-27 10:58 -------- d-----w- c:\program files\VirtualDJ
2010-12-22 18:27 . 2011-01-04 11:28 -------- d-----w- c:\programdata\lx_Cats
2010-12-22 18:27 . 2009-08-13 11:02 147968 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdndrpp.dll
2010-12-22 09:59 . 2006-04-19 01:00 62976 ----a-w- c:\windows\system32\E_FD4BBVE.DLL
2010-12-20 09:49 . 2010-12-20 09:49 -------- d-----w- c:\program files\Infogrames
2010-12-19 21:45 . 2010-12-19 21:45 -------- d-----w- c:\program files\directx
2010-12-19 20:31 . 2010-12-19 20:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-12-19 18:17 . 2010-12-19 18:17 40960 ----a-r- c:\users\Tanguy\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2010-12-19 18:17 . 2010-12-19 18:17 40960 ----a-r- c:\users\Tanguy\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2010-12-19 18:17 . 2010-12-19 18:18 -------- d-----w- c:\program files\Project64 1.6
2010-12-15 17:19 . 2010-10-12 04:25 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-15 17:19 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-15 17:19 . 2010-11-02 04:41 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-15 17:19 . 2010-11-02 04:40 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-12-15 17:19 . 2010-11-02 04:40 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-12-15 17:19 . 2010-11-02 04:39 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-12-15 17:19 . 2010-11-02 04:34 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-12-15 17:19 . 2010-11-02 04:34 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-12-15 17:18 . 2010-10-20 04:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-12-15 17:18 . 2010-10-20 02:58 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-12-15 17:18 . 2010-10-16 04:36 314368 ----a-w- c:\windows\system32\webio.dll
2010-12-15 17:18 . 2010-10-16 04:41 101760 ----a-w- c:\windows\system32\consent.exe
2010-12-15 17:17 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-13 17:23 . 2011-01-13 17:23 83702800 ----a-w- C:\UsbFix_Upload_Me_TANGUY-PC.zip
2010-12-15 21:49 . 2009-12-15 13:27 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-15 21:49 . 2009-12-15 12:33 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-26 04:19 . 2010-11-26 04:19 6650368 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-11-26 03:02 . 2010-11-26 03:02 16702976 ----a-w- c:\windows\system32\atioglxx.dll
2010-11-26 02:58 . 2010-11-26 02:58 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-11-26 02:58 . 2010-05-05 02:19 550400 ----a-w- c:\windows\system32\aticfx32.dll
2010-11-26 02:54 . 2010-11-26 02:54 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-11-26 02:54 . 2010-11-26 02:54 393216 ----a-w- c:\windows\system32\atieclxx.exe
2010-11-26 02:54 . 2010-11-26 02:54 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-11-26 02:52 . 2010-11-26 02:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-11-26 02:52 . 2010-11-26 02:52 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-11-26 02:52 . 2010-11-26 02:52 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-11-26 02:52 . 2010-11-26 02:52 15872 ----a-w- c:\windows\system32\atimuixx.dll
2010-11-26 02:52 . 2010-11-26 02:52 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-11-26 02:49 . 2009-07-13 22:09 4066816 ----a-w- c:\windows\system32\atidxx32.dll
2010-11-26 02:30 . 2010-11-26 02:30 4122624 ----a-w- c:\windows\system32\atiumdag.dll
2010-11-26 02:30 . 2010-11-26 02:30 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-11-26 02:30 . 2010-11-26 02:30 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-11-26 02:28 . 2010-11-26 02:28 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2010-11-26 02:24 . 2010-05-05 01:34 52736 ----a-w- c:\windows\system32\coinst.dll
2010-11-26 02:22 . 2010-11-26 02:22 3460096 ----a-w- c:\windows\system32\atiumdva.dll
2010-11-26 02:17 . 2010-11-26 02:17 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2010-11-26 02:17 . 2010-11-26 02:17 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-11-26 02:16 . 2010-11-26 02:16 27136 ----a-w- c:\windows\system32\atigktxx.dll
2010-11-26 02:16 . 2010-11-26 02:16 231936 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2010-11-26 02:15 . 2010-05-05 01:22 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2010-11-26 02:15 . 2010-11-26 02:15 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2010-11-26 02:15 . 2010-11-26 02:15 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-11-12 17:53 . 2010-05-15 21:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-01 23:03 . 2010-11-26 23:17 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-01 22:59 . 2010-11-26 23:17 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-10-19 09:41 . 2009-12-15 12:25 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Steam"="c:\program files\Steam\Steam.exe" [2010-11-17 1242448]
"Neuf Media Center"="c:\program files\SFR\Media Center\MediaCenter.exe" [2008-10-10 726336]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-08-05 7703072]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
c:\users\Tanguy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R0 mnnkhhs;mnnkhhs;c:\windows\System32\drivers\uitjhi.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gvohgndt;GEAR ASPI Filter Helper;c:\windows\System32\svchost.exe [2009-07-14 20992]
R3 IRS1600L;Voicetracerxp.Sys Voice Tracer Communication driver;c:\windows\system32\Drivers\VoiceTracerxp.sys [2002-11-11 16640]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2011-01-09 310640]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-08-17 135336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-11-28 589824]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
gvohgndt
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: &Envoyer à OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Tanguy\AppData\Roaming\Mozilla\Firefox\Profiles\8dhsq5t6.default\
FF - prefs.js: browser.startup.homepage - hxxp://m.fr.yahoo.com/?fr=fptb-tyc8
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Interest Recognizer for Crazyloader: crazyloader@spointer.com - c:\program files\CrazyLoader\spointer\extensions\crazyloader@spointer.com
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{CA99B718-B718-CA99-18B7-99CA18B799CA} - c:\windows\system32\alk2d83.dll
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Run-DATAMNGR - c:\progra~1\WIA6EB~1\Datamngr\DATAMN~1.EXE
SafeBoot-klmdb.sys
AddRemove-Bandoo - c:\program files\Fun4IM\PreUninstall.exe
AddRemove-OfferBox Browser - c:\program files\OfferBox\uninst.exe
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-696869605-3829081844-908571491-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:b0,97,85,9a,f8,02,1a,d5,aa,ca,37,48,56,06,c1,71,69,b3,c6,c8,f2,75,fb,
27,2e,eb,ca,fa,7b,8d,3f,0c,2e,a0,7e,f3,dd,07,38,32,59,6b,b5,c8,60,3e,9a,9d,\
"??"=hex:f6,37,fa,cc,f5,ce,b5,5f,37,5d,51,f0,8d,78,df,e1
[HKEY_USERS\S-1-5-21-696869605-3829081844-908571491-1001\Software\SecuROM\License information*]
"datasecu"=hex:6b,60,61,c6,96,d8,8f,72,dd,e6,31,b0,73,01,e9,40,86,95,4a,16,51,
ee,ee,2c,f0,c9,e1,c7,bb,df,f8,05,a0,68,20,71,f5,86,9d,29,d3,fa,70,8b,54,12,\
"rkeysecu"=hex:62,6c,8d,a2,6a,ac,09,b2,e5,73,43,9a,b3,bb,9a,45
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2011-01-14 13:08:33
ComboFix-quarantined-files.txt 2011-01-14 12:08
Avant-CF: 190 321 364 992 octets libres
Après-CF: 190 213 574 656 octets libres
- - End Of File - - AB8D9B539C10E0CBD183F7A2BC501027
ComboFix 11-01-11.03 - Tanguy 14/01/2011 13:00:40.1.2 - x86
Microsoft Windows 7 Professionnel 6.1.7600.0.1252.33.1036.18.3067.2078 [GMT 1:00]
Lancé depuis: c:\users\Tanguy\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Tanguy\AppData\Roaming\dach100.dll
c:\users\Tanguy\AppData\Roaming\sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-12-14 au 2011-01-14 ))))))))))))))))))))))))))))))))))))
.
2011-01-14 12:06 . 2011-01-14 12:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-13 19:51 . 2011-01-13 19:51 -------- d-----w- C:\_OTM
2011-01-13 17:03 . 2011-01-13 17:23 -------- d-----w- C:\UsbFix
2011-01-13 10:33 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{087CFDCB-9FBD-4941-997D-73912A9ED1B9}\mpengine.dll
2011-01-12 21:55 . 2011-01-13 16:20 -------- d-----w- C:\tdsskiller
2011-01-12 19:03 . 2011-01-12 19:03 -------- d-----w- c:\programdata\ATI
2011-01-12 19:03 . 2011-01-12 19:03 -------- d-----w- c:\program files\Common Files\ATI Technologies
2011-01-12 19:03 . 2011-01-13 21:38 -------- d-----w- c:\program files\ZHPDiag
2011-01-12 18:57 . 2010-11-05 22:39 354840 ----a-w- c:\windows\system32\drivers\iaStor.sys
2011-01-12 18:09 . 2011-01-12 21:28 -------- d-----w- c:\users\Tanguy\AppData\Local\Google
2011-01-12 18:09 . 2011-01-12 20:23 -------- d-----w- c:\users\Tanguy\AppData\Local\Deployment
2011-01-12 18:09 . 2011-01-12 18:09 -------- d-----w- c:\users\Tanguy\AppData\Local\Apps
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\users\Tanguy\AppData\Roaming\Malwarebytes
2011-01-12 16:39 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\programdata\Malwarebytes
2011-01-12 16:39 . 2011-01-12 16:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-12 16:39 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-12 15:31 . 2011-01-12 15:31 -------- d-----w- c:\program files\Dachshund Software
2011-01-12 15:13 . 2011-01-12 15:14 -------- d--h--w- c:\windows\AxInstSV
2011-01-10 20:23 . 2011-01-10 20:23 -------- d-----w- c:\program files\Bonjour
2010-12-28 18:07 . 2010-12-28 18:07 -------- d-----w- c:\windows\Sun
2010-12-27 10:58 . 2010-12-27 10:58 -------- d-----w- c:\program files\VirtualDJ
2010-12-22 18:27 . 2011-01-04 11:28 -------- d-----w- c:\programdata\lx_Cats
2010-12-22 18:27 . 2009-08-13 11:02 147968 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lxdndrpp.dll
2010-12-22 09:59 . 2006-04-19 01:00 62976 ----a-w- c:\windows\system32\E_FD4BBVE.DLL
2010-12-20 09:49 . 2010-12-20 09:49 -------- d-----w- c:\program files\Infogrames
2010-12-19 21:45 . 2010-12-19 21:45 -------- d-----w- c:\program files\directx
2010-12-19 20:31 . 2010-12-19 20:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-12-19 18:17 . 2010-12-19 18:17 40960 ----a-r- c:\users\Tanguy\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2010-12-19 18:17 . 2010-12-19 18:17 40960 ----a-r- c:\users\Tanguy\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2010-12-19 18:17 . 2010-12-19 18:18 -------- d-----w- c:\program files\Project64 1.6
2010-12-15 17:19 . 2010-10-12 04:25 516096 ----a-w- c:\program files\Windows Mail\wab.exe
2010-12-15 17:19 . 2010-10-27 04:32 2048 ----a-w- c:\windows\system32\tzres.dll
2010-12-15 17:19 . 2010-11-02 04:41 351232 ----a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-15 17:19 . 2010-11-02 04:40 496128 ----a-w- c:\windows\system32\taskschd.dll
2010-12-15 17:19 . 2010-11-02 04:40 305152 ----a-w- c:\windows\system32\taskcomp.dll
2010-12-15 17:19 . 2010-11-02 04:39 749056 ----a-w- c:\windows\system32\schedsvc.dll
2010-12-15 17:19 . 2010-11-02 04:34 192000 ----a-w- c:\windows\system32\taskeng.exe
2010-12-15 17:19 . 2010-11-02 04:34 179712 ----a-w- c:\windows\system32\schtasks.exe
2010-12-15 17:18 . 2010-10-20 04:54 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-12-15 17:18 . 2010-10-20 02:58 294400 ----a-w- c:\windows\system32\atmfd.dll
2010-12-15 17:18 . 2010-10-16 04:36 314368 ----a-w- c:\windows\system32\webio.dll
2010-12-15 17:18 . 2010-10-16 04:41 101760 ----a-w- c:\windows\system32\consent.exe
2010-12-15 17:17 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-13 17:23 . 2011-01-13 17:23 83702800 ----a-w- C:\UsbFix_Upload_Me_TANGUY-PC.zip
2010-12-15 21:49 . 2009-12-15 13:27 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-15 21:49 . 2009-12-15 12:33 61960 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-26 04:19 . 2010-11-26 04:19 6650368 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-11-26 03:02 . 2010-11-26 03:02 16702976 ----a-w- c:\windows\system32\atioglxx.dll
2010-11-26 02:58 . 2010-11-26 02:58 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-11-26 02:58 . 2010-05-05 02:19 550400 ----a-w- c:\windows\system32\aticfx32.dll
2010-11-26 02:54 . 2010-11-26 02:54 462848 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-11-26 02:54 . 2010-11-26 02:54 393216 ----a-w- c:\windows\system32\atieclxx.exe
2010-11-26 02:54 . 2010-11-26 02:54 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-11-26 02:52 . 2010-11-26 02:52 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-11-26 02:52 . 2010-11-26 02:52 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-11-26 02:52 . 2010-11-26 02:52 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-11-26 02:52 . 2010-11-26 02:52 15872 ----a-w- c:\windows\system32\atimuixx.dll
2010-11-26 02:52 . 2010-11-26 02:52 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-11-26 02:49 . 2009-07-13 22:09 4066816 ----a-w- c:\windows\system32\atidxx32.dll
2010-11-26 02:30 . 2010-11-26 02:30 4122624 ----a-w- c:\windows\system32\atiumdag.dll
2010-11-26 02:30 . 2010-11-26 02:30 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-11-26 02:30 . 2010-11-26 02:30 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-11-26 02:28 . 2010-11-26 02:28 5441024 ----a-w- c:\windows\system32\aticaldd.dll
2010-11-26 02:24 . 2010-05-05 01:34 52736 ----a-w- c:\windows\system32\coinst.dll
2010-11-26 02:22 . 2010-11-26 02:22 3460096 ----a-w- c:\windows\system32\atiumdva.dll
2010-11-26 02:17 . 2010-11-26 02:17 249856 ----a-w- c:\windows\system32\atiadlxx.dll
2010-11-26 02:17 . 2010-11-26 02:17 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-11-26 02:16 . 2010-11-26 02:16 27136 ----a-w- c:\windows\system32\atigktxx.dll
2010-11-26 02:16 . 2010-11-26 02:16 231936 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2010-11-26 02:15 . 2010-05-05 01:22 30720 ----a-w- c:\windows\system32\atiuxpag.dll
2010-11-26 02:15 . 2010-11-26 02:15 28672 ----a-w- c:\windows\system32\atiu9pag.dll
2010-11-26 02:15 . 2010-11-26 02:15 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-11-26 02:09 . 2010-11-26 02:09 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-11-12 17:53 . 2010-05-15 21:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-01 23:03 . 2010-11-26 23:17 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-01 22:59 . 2010-11-26 23:17 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-10-19 09:41 . 2009-12-15 12:25 222080 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Steam"="c:\program files\Steam\Steam.exe" [2010-11-17 1242448]
"Neuf Media Center"="c:\program files\SFR\Media Center\MediaCenter.exe" [2008-10-10 726336]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-11-25 98304]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-05 283160]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-08-05 7703072]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 1164584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
c:\users\Tanguy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
AntiCrash.lnk - c:\program files\Dachshund Software\AntiCrash\AntiCrash.exe [2002-12-17 2301798]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R0 mnnkhhs;mnnkhhs;c:\windows\System32\drivers\uitjhi.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gvohgndt;GEAR ASPI Filter Helper;c:\windows\System32\svchost.exe [2009-07-14 20992]
R3 IRS1600L;Voicetracerxp.Sys Voice Tracer Communication driver;c:\windows\system32\Drivers\VoiceTracerxp.sys [2002-11-11 16640]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2011-01-09 310640]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [2009-07-13 207360]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [2009-07-13 661504]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-08 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-11-26 176128]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-08-17 135336]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-05 13336]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-11-28 589824]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-11-26 6650368]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-11-26 231936]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
gvohgndt
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: &Envoyer à OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Tanguy\AppData\Roaming\Mozilla\Firefox\Profiles\8dhsq5t6.default\
FF - prefs.js: browser.startup.homepage - hxxp://m.fr.yahoo.com/?fr=fptb-tyc8
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Interest Recognizer for Crazyloader: crazyloader@spointer.com - c:\program files\CrazyLoader\spointer\extensions\crazyloader@spointer.com
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{CA99B718-B718-CA99-18B7-99CA18B799CA} - c:\windows\system32\alk2d83.dll
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
HKLM-Run-DATAMNGR - c:\progra~1\WIA6EB~1\Datamngr\DATAMN~1.EXE
SafeBoot-klmdb.sys
AddRemove-Bandoo - c:\program files\Fun4IM\PreUninstall.exe
AddRemove-OfferBox Browser - c:\program files\OfferBox\uninst.exe
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-696869605-3829081844-908571491-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:b0,97,85,9a,f8,02,1a,d5,aa,ca,37,48,56,06,c1,71,69,b3,c6,c8,f2,75,fb,
27,2e,eb,ca,fa,7b,8d,3f,0c,2e,a0,7e,f3,dd,07,38,32,59,6b,b5,c8,60,3e,9a,9d,\
"??"=hex:f6,37,fa,cc,f5,ce,b5,5f,37,5d,51,f0,8d,78,df,e1
[HKEY_USERS\S-1-5-21-696869605-3829081844-908571491-1001\Software\SecuROM\License information*]
"datasecu"=hex:6b,60,61,c6,96,d8,8f,72,dd,e6,31,b0,73,01,e9,40,86,95,4a,16,51,
ee,ee,2c,f0,c9,e1,c7,bb,df,f8,05,a0,68,20,71,f5,86,9d,29,d3,fa,70,8b,54,12,\
"rkeysecu"=hex:62,6c,8d,a2,6a,ac,09,b2,e5,73,43,9a,b3,bb,9a,45
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2011-01-14 13:08:33
ComboFix-quarantined-files.txt 2011-01-14 12:08
Avant-CF: 190 321 364 992 octets libres
Après-CF: 190 213 574 656 octets libres
- - End Of File - - AB8D9B539C10E0CBD183F7A2BC501027
jfkpresident
Messages postés
13404
Date d'inscription
lundi 3 septembre 2007
Statut
Contributeur sécurité
Dernière intervention
5 janvier 2015
1 175
14 janv. 2011 à 20:16
14 janv. 2011 à 20:16
Rien d'infectieux ...
Quels sont les problemes qui persistent ?
Quels sont les problemes qui persistent ?
tanguy76310
Messages postés
95
Date d'inscription
mercredi 7 janvier 2009
Statut
Membre
Dernière intervention
28 juillet 2014
14 janv. 2011 à 21:09
14 janv. 2011 à 21:09
Aucun problèmes apparement !