Connection internet après combofix
Résolu/Fermé
A voir également:
- Connection internet après combofix
- Gmail connection - Guide
- Gps sans internet - Guide
- Connection internet - Guide
- 35 go internet équivalent en heure - Forum Mobile
- Facebook connection - Guide
3 réponses
Utilisateur anonyme
25 nov. 2011 à 23:58
25 nov. 2011 à 23:58
Bonsoir
Voila pourquoi il ne faut pas utiliser seul et sans conseils ComboFix...
Poste moi ce rapport ;merci
@+
Voila pourquoi il ne faut pas utiliser seul et sans conseils ComboFix...
Poste moi ce rapport ;merci
@+
Autre chose aussi : je n'arrive pas à reactiver mon pare feu windows!! Ca me met "desolé le centre de securité n'a pas pu activer le pare feu windoxs"
HELP!!!
HELP!!!
Bonjour
mille merci de me repondre!
Voici le rapport :
ComboFix 11-11-22.03 - delphine 23/11/2011 17:12:40.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.673 [GMT 1:00]
Lancé depuis: c:\documents and settings\delphine\Bureau\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\privacy.exe
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
c:\documents and settings\delphine\Application Data\Acgot
c:\documents and settings\delphine\Application Data\Acgot\ikoxvo.exe
c:\documents and settings\delphine\Application Data\OfferBox
c:\documents and settings\delphine\Application Data\OfferBox\config.xml
c:\documents and settings\delphine\WINDOWS
c:\windows\$NtUninstallKB23763$\2690453566
c:\windows\$NtUninstallKB23763$\3515911491\@
c:\windows\$NtUninstallKB23763$\3515911491\bckfg.tmp
c:\windows\$NtUninstallKB23763$\3515911491\cfg.ini
c:\windows\$NtUninstallKB23763$\3515911491\Desktop.ini
c:\windows\$NtUninstallKB23763$\3515911491\kwrd.dll
c:\windows\$NtUninstallKB23763$\3515911491\L\gmqeioro
c:\windows\$NtUninstallKB23763$\3515911491\U\00000001.@
c:\windows\$NtUninstallKB23763$\3515911491\U\00000002.@
c:\windows\$NtUninstallKB23763$\3515911491\U\00000004.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000000.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000004.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000032.@
c:\windows\system32\AutoRun.inf
c:\windows\$NtUninstallKB23763$ . . . . impossible à supprimer
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-23 au 2011-11-23 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-22 19:38 . 2011-11-23 15:38 -------- d-----w- c:\documents and settings\delphine\Application Data\Emichie
2011-10-25 20:46 . 2011-10-25 20:46 -------- d-----w- c:\program files\Microsoft.NET
2011-10-25 20:42 . 2011-10-26 21:25 -------- d-----w- c:\documents and settings\delphine\Application Data\Garmin
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:23 . 2009-08-07 13:44 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-05 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 18:59 614400 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-05 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-05 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10 . 2004-08-05 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-09-01 23:07 . 2011-09-01 23:07 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2009-10-30 14:30 . 2009-10-30 14:30 36873968 ----a-w- c:\program files\setup_av_free.exe
2009-08-17 14:49 . 2009-08-17 14:48 308160 ----a-w- c:\program files\avast_home_setup.exe
2011-10-01 17:14 . 2011-05-06 10:54 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-11 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-22 851968]
"XOSD"="c:\program files\XOSD\XOSD_ON.exe" [2007-01-03 476672]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
"SearchSettings"="c:\program files\Fichiers communs\Spigot\Search Settings\SearchSettings.exe" [2011-09-27 894304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\invited\Menu Démarrer\Programmes\Démarrage\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2005-9-23 61440]
.
c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2009-8-7 2101248]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\WYSIWYG\\Bin\\Wyg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
.
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [07/08/2009 15:06 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [07/08/2009 15:07 35712]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/10/2009 15:31 149328]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [27/09/2011 19:08 745880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/10/2009 15:31 19024]
R2 XRNBO;XRNBO;c:\windows\system32\drivers\XRNBO.sys [24/03/2011 00:09 177152]
S2 AMService;AMService;c:\windows\TEMP\usjeqr\setup.exe run --> c:\windows\TEMP\usjeqr\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S3 Dsaproto;NDIS Protocol Driver for DSA;c:\windows\system32\drivers\Dsaproto.sys [30/10/2009 02:48 88576]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13:49 227232]
S3 Ptndowent;Ptndowent; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
.
2011-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
.
2011-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-796845957-725345543-1004Core.job
- c:\documents and settings\delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-01 21:10]
.
2011-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-796845957-725345543-1004UA.job
- c:\documents and settings\delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-01 21:10]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mivolo.com
mStart Page = hxxp://mivolo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\delphine\Application Data\Mozilla\Firefox\Profiles\4om9lqzp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHELINS SUPPRIMES - - - -
.
HKCU-Run-{275D6D5D-BCF2-1F39-BD61-8AAAD8E6938B} - c:\documents and settings\delphine\Application Data\Acgot\ikoxvo.exe
HKCU-Run-Privacy Protection - c:\documents and settings\All Users.WINDOWS\Application Data\privacy.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-23 17:23
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(3268)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\XOSD\XOSD.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\O2Micro Oz128 Driver\o2flash.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Heure de fin: 2011-11-23 17:25:07 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-23 16:24
.
Avant-CF: 15 357 513 728 octets libres
Après-CF: 19 015 335 936 octets libres
.
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
.
- - End Of File - - C2C61924D9CAC096DAED7527D3B8A207
mille merci de me repondre!
Voici le rapport :
ComboFix 11-11-22.03 - delphine 23/11/2011 17:12:40.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.673 [GMT 1:00]
Lancé depuis: c:\documents and settings\delphine\Bureau\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS\Application Data\privacy.exe
c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
c:\documents and settings\delphine\Application Data\Acgot
c:\documents and settings\delphine\Application Data\Acgot\ikoxvo.exe
c:\documents and settings\delphine\Application Data\OfferBox
c:\documents and settings\delphine\Application Data\OfferBox\config.xml
c:\documents and settings\delphine\WINDOWS
c:\windows\$NtUninstallKB23763$\2690453566
c:\windows\$NtUninstallKB23763$\3515911491\@
c:\windows\$NtUninstallKB23763$\3515911491\bckfg.tmp
c:\windows\$NtUninstallKB23763$\3515911491\cfg.ini
c:\windows\$NtUninstallKB23763$\3515911491\Desktop.ini
c:\windows\$NtUninstallKB23763$\3515911491\kwrd.dll
c:\windows\$NtUninstallKB23763$\3515911491\L\gmqeioro
c:\windows\$NtUninstallKB23763$\3515911491\U\00000001.@
c:\windows\$NtUninstallKB23763$\3515911491\U\00000002.@
c:\windows\$NtUninstallKB23763$\3515911491\U\00000004.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000000.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000004.@
c:\windows\$NtUninstallKB23763$\3515911491\U\80000032.@
c:\windows\system32\AutoRun.inf
c:\windows\$NtUninstallKB23763$ . . . . impossible à supprimer
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-23 au 2011-11-23 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-22 19:38 . 2011-11-23 15:38 -------- d-----w- c:\documents and settings\delphine\Application Data\Emichie
2011-10-25 20:46 . 2011-10-25 20:46 -------- d-----w- c:\program files\Microsoft.NET
2011-10-25 20:42 . 2011-10-26 21:25 -------- d-----w- c:\documents and settings\delphine\Application Data\Garmin
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:23 . 2009-08-07 13:44 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-05 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 09:41 . 2008-07-29 18:59 614400 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 2004-08-05 12:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 2004-08-05 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-06 14:10 . 2004-08-05 12:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-09-01 23:07 . 2011-09-01 23:07 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2009-10-30 14:30 . 2009-10-30 14:30 36873968 ----a-w- c:\program files\setup_av_free.exe
2009-08-17 14:49 . 2009-08-17 14:48 308160 ----a-w- c:\program files\avast_home_setup.exe
2011-10-01 17:14 . 2011-05-06 10:54 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-11 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-05 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-05 137752]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 16855552]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-22 851968]
"XOSD"="c:\program files\XOSD\XOSD_ON.exe" [2007-01-03 476672]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-25 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-06-09 254696]
"SearchSettings"="c:\program files\Fichiers communs\Spigot\Search Settings\SearchSettings.exe" [2011-09-27 894304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\invited\Menu Démarrer\Programmes\Démarrage\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2005-9-23 61440]
.
c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2009-8-7 2101248]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\WYSIWYG\\Bin\\Wyg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
.
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [07/08/2009 15:06 39680]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [07/08/2009 15:07 35712]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/10/2009 15:31 149328]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [27/09/2011 19:08 745880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/10/2009 15:31 19024]
R2 XRNBO;XRNBO;c:\windows\system32\drivers\XRNBO.sys [24/03/2011 00:09 177152]
S2 AMService;AMService;c:\windows\TEMP\usjeqr\setup.exe run --> c:\windows\TEMP\usjeqr\setup.exe run [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S3 Dsaproto;NDIS Protocol Driver for DSA;c:\windows\system32\drivers\Dsaproto.sys [30/10/2009 02:48 88576]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 13:49 227232]
S3 Ptndowent;Ptndowent; [x]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
.
2011-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
.
2011-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-796845957-725345543-1004Core.job
- c:\documents and settings\delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-01 21:10]
.
2011-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-796845957-725345543-1004UA.job
- c:\documents and settings\delphine\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-01 21:10]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mivolo.com
mStart Page = hxxp://mivolo.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\delphine\Application Data\Mozilla\Firefox\Profiles\4om9lqzp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHELINS SUPPRIMES - - - -
.
HKCU-Run-{275D6D5D-BCF2-1F39-BD61-8AAAD8E6938B} - c:\documents and settings\delphine\Application Data\Acgot\ikoxvo.exe
HKCU-Run-Privacy Protection - c:\documents and settings\All Users.WINDOWS\Application Data\privacy.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-23 17:23
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(3268)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\XOSD\XOSD.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\O2Micro Oz128 Driver\o2flash.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Heure de fin: 2011-11-23 17:25:07 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-23 16:24
.
Avant-CF: 15 357 513 728 octets libres
Après-CF: 19 015 335 936 octets libres
.
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
.
- - End Of File - - C2C61924D9CAC096DAED7527D3B8A207