Outerinfo
Fermé
Vasariah
-
6 janv. 2008 à 03:48
Regis59 Messages postés 21123 Date d'inscription mardi 27 juin 2006 Statut Contributeur sécurité Dernière intervention 22 juin 2016 - 13 janv. 2008 à 11:35
Regis59 Messages postés 21123 Date d'inscription mardi 27 juin 2006 Statut Contributeur sécurité Dernière intervention 22 juin 2016 - 13 janv. 2008 à 11:35
6 réponses
Regis59
Messages postés
21123
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 346
6 janv. 2008 à 13:30
6 janv. 2008 à 13:30
Salut
Of course!
Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
A+
Of course!
Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
A+
et voila le rapport! Désolé du temps de réponse, je vis au québec.
ComboFix 08-01-04.1 - Florent 2008-01-06 10:41:09.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1301 [GMT -5:00]
Running from: C:\Users\Florent\Desktop\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Yazzle1848OinUninstaller.exe
C:\Windows\system32\x64
C:\Windows\system32\X86
C:\Windows\system32\X86\License.rtf
C:\Windows\system32\X86\Readme.txt
C:\Windows\system32\X86\setup.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-06 to 2008-01-06 ))))))))))))))))))))))))))))))))))))
.
2008-01-06 10:39 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2007-12-27 12:44 . 2007-12-27 12:47 <REP> d-------- C:\Program Files\HomeKeylogger
2007-12-27 12:37 . 2007-12-27 12:38 <REP> d-a------ C:\Users\All Users\rkfree
2007-12-27 12:37 . 2007-12-27 12:38 <REP> d-a------ C:\ProgramData\rkfree
2007-12-27 12:37 . 2007-12-27 13:57 <REP> d-------- C:\Program Files\RKFree
2007-12-17 15:42 . 2008-01-05 17:16 54,156 --ah----- C:\Windows\QTFont.qfn
2007-12-17 15:42 . 2007-12-17 15:42 1,409 --a------ C:\Windows\QTFont.for
2007-12-17 14:44 . 2007-12-27 12:50 <REP> d-------- C:\Program Files\Windows Live
2007-12-17 14:39 . 2007-12-17 14:46 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-17 14:38 . 2007-12-17 14:43 <REP> d-------- C:\Users\All Users\WLInstaller
2007-12-17 14:38 . 2007-12-17 14:43 <REP> d-------- C:\ProgramData\WLInstaller
2007-12-17 11:51 . 2007-12-17 11:51 <REP> d-------- C:\Program Files\Lionhead Studios
2007-12-15 13:12 . 2007-12-15 13:12 <REP> d-------- C:\Users\Florent\AppData\Roaming\InstallShield
2007-12-15 12:29 . 2007-04-04 18:53 81,768 --a------ C:\Windows\System32\xinput1_3.dll
2007-12-15 12:28 . 2007-03-12 16:42 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2007-12-15 12:28 . 2007-03-12 16:42 1,123,696 --a------ C:\Windows\System32\D3DCompiler_33.dll
2007-12-15 12:28 . 2007-03-15 16:57 443,752 --a------ C:\Windows\System32\d3dx10_33.dll
2007-12-14 21:56 . 2007-12-14 21:58 114 --a------ C:\Windows\SpaceForce-RU.cfg
2007-12-14 21:46 . 2007-12-14 21:46 <REP> d-------- C:\Windows\SpaceForce - Rogue Universe
2007-12-14 20:12 . 2007-12-14 20:53 <REP> d-------- C:\Users\Florent\AppData\Roaming\DAEMON Tools
2007-12-14 20:11 . 2007-12-14 20:11 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2007-12-14 14:02 . 2007-12-14 14:02 1 --a------ C:\Windows\System32\SI.bin
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Videos
2007-12-14 11:50 . 2006-11-02 05:23 <REP> d-------- C:\Users\Administrateur\Saved Games
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Pictures
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Music
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Links
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Downloads
2007-12-14 11:50 . 2007-12-14 11:50 <REP> dr------- C:\Users\Administrateur\Documents
2007-12-14 11:50 . 2006-11-02 06:18 <REP> d--h----- C:\Users\Administrateur\AppData
2007-12-13 10:04 . 2007-12-13 10:04 26 --a------ C:\Windows\System32\satsukidecodersettings.ini
2007-12-12 15:36 . 2007-12-12 15:36 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-12 15:36 . 2007-11-29 23:30 3,596,288 --a------ C:\Windows\System32\qt-dx331.dll
2007-12-12 15:36 . 2007-07-25 14:24 1,559,040 --a------ C:\Windows\System32\xvidcore.dll
2007-12-12 15:36 . 2007-12-04 02:33 682,496 --a------ C:\Windows\System32\divx.dll
2007-12-12 15:36 . 2006-09-24 16:11 389,120 --a------ C:\Windows\System32\lameACM.acm
2007-12-12 15:36 . 2007-03-10 12:51 282,624 --a------ C:\Windows\System32\xvidvfw.dll
2007-12-12 15:36 . 2004-01-25 17:18 217,088 --a------ C:\Windows\System32\yv12vfw.dll
2007-12-12 15:36 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll
2007-12-12 15:36 . 2007-09-21 01:52 118,784 --a------ C:\Windows\System32\ac3acm.acm
2007-12-12 15:36 . 2007-11-29 23:28 81,920 --a------ C:\Windows\System32\dpl100.dll
2007-12-12 15:36 . 2007-10-03 16:03 414 --a------ C:\Windows\System32\lame_acm.xml
2007-12-12 14:59 . 2008-01-05 23:41 1,289 --a------ C:\Windows\mozver.dat
2007-12-12 13:33 . 2000-05-22 16:58 647,872 --a------ C:\Windows\System32\mscomct2.ocx
2007-12-12 13:33 . 1998-06-24 00:00 209,192 --a------ C:\Windows\System32\TABCTL32.OCX
2007-12-12 13:33 . 2003-01-26 15:48 147,456 --a------ C:\Windows\System32\vbzip11.dll
2007-12-12 13:33 . 1998-12-02 09:11 143,360 --a------ C:\Windows\System32\vbuzip10.dll
2007-12-12 13:33 . 1998-06-23 17:00 115,016 --a------ C:\Windows\System32\MSINET.OCX
2007-12-12 13:33 . 2005-06-30 09:53 45,056 --a------ C:\Windows\System32\wndRestrict.ocx
2007-12-12 13:33 . 1999-08-29 10:15 7,716 --a------ C:\Windows\System32\URLHIST.tlb
2007-12-12 13:14 . 2007-12-12 13:15 <REP> d-------- C:\Users\Florent\AppData\Roaming\Media Player Classic
2007-12-12 12:39 . 2007-12-12 12:39 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-12 12:39 . 2007-12-12 12:39 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-12 12:39 . 2007-12-12 12:39 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-12 12:39 . 2007-12-12 12:39 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-12 12:37 . 2007-12-12 12:37 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-12 12:37 . 2007-12-12 12:37 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-12 12:37 . 2007-12-12 12:37 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-12 12:37 . 2007-12-12 12:37 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-12 12:35 . 2007-12-12 12:35 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-12 12:35 . 2007-12-12 12:35 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-12 12:35 . 2007-12-12 12:35 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-11 20:55 . 2007-12-11 20:55 <REP> d-------- C:\Program Files\FLV Player
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 --a------ C:\Windows\System32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 --a------ C:\Windows\System32\ssldivx.dll
2007-12-09 17:11 . 2007-12-09 17:17 <REP> d-------- C:\Ares Tube
2007-12-08 20:30 . 2007-12-15 12:30 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2007-12-08 20:08 . 2006-11-29 13:06 3,426,072 --a------ C:\Windows\System32\d3dx9_32.dll
2007-12-08 20:08 . 2006-12-14 13:47 782,336 -ra------ C:\Windows\System32\tmp58C9.tmp
2007-12-08 20:08 . 2006-11-29 13:06 440,080 --a------ C:\Windows\System32\d3dx10.dll
2007-12-08 20:08 . 2007-12-08 20:08 409,600 --a------ C:\Windows\System32\wrap_oal.dll
2007-12-08 20:08 . 2006-12-08 12:02 251,672 --a------ C:\Windows\System32\xactengine2_5.dll
2007-12-08 20:08 . 2006-09-28 16:05 237,848 --a------ C:\Windows\System32\xactengine2_4.dll
2007-12-08 20:08 . 2007-12-08 20:08 114,688 --a------ C:\Windows\System32\OpenAL32.dll
2007-12-08 12:33 . 2007-03-04 07:55 1,936,528 --a------ C:\Windows\System32\ltmm15.dll
2007-12-08 12:33 . 2007-12-08 12:32 737,280 --a------ C:\Windows\iun6002.exe
2007-12-08 12:33 . 2007-03-04 07:55 135,168 --a------ C:\Windows\System32\DSKernel2.dll
2007-12-08 12:32 . 2007-12-08 12:32 <REP> d-------- C:\Windows\Replay Media Catcher
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Windows\Applian FLV Player
2007-12-08 00:32 . 2007-12-08 00:32 <REP> dr-h----- C:\MSOCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 15:37 --------- d-----w C:\Users\Florent\AppData\Roaming\AVG7
2008-01-04 23:33 --------- d-----w C:\Users\Florent\AppData\Roaming\BitTorrent
2008-01-04 23:07 --------- d-----w C:\Program Files\Grisbi
2008-01-04 06:01 --------- d-----w C:\Users\Florent\AppData\Roaming\Skype
2007-12-20 01:23 --------- d-----w C:\Users\Florent\AppData\Roaming\Grisbi
2007-12-17 16:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-16 21:44 --------- d-----w C:\Program Files\BitTorrent
2007-12-15 01:02 715,248 ----a-w C:\Windows\system32\drivers\sptd.sys
2007-12-12 19:32 --------- d-----w C:\Program Files\QuickTime
2007-12-12 19:26 --------- d-----w C:\Users\Florent\AppData\Roaming\DivX
2007-12-12 17:40 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 17:38 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 17:38 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 17:38 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 16:10 --------- d-----w C:\Program Files\DivX
2007-12-11 18:54 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-12-11 18:36 --------- d-----w C:\Program Files\RegCleaner
2007-12-06 01:58 --------- d-----w C:\Program Files\RADVideo
2007-12-06 01:54 --------- d-----w C:\ProgramData\Apple Computer
2007-12-05 23:43 --------- d-----w C:\Program Files\Veoh Networks
2007-12-01 19:44 --------- d-----w C:\Program Files\Google
2007-12-01 06:00 --------- d-----w C:\Program Files\Babo Violent 2
2007-11-30 12:44 4,870 ----a-w C:\Windows\System32\tmp.reg
2007-11-30 04:42 --------- d-----w C:\Program Files\AusLogics Disk Defrag
2007-11-29 22:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\Windows\System32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\Windows\System32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\Windows\System32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\Windows\System32\dpu10.dll
2007-11-21 23:58 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2007-11-21 23:58 --------- d-----w C:\Program Files\Synaptics
2007-11-17 04:33 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2007-11-17 02:41 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-14 12:44 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 12:44 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 12:44 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 12:44 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 12:44 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 12:44 299,008 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 12:44 289,280 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 12:44 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-11-14 12:44 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-14 12:44 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 12:44 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-11-14 12:44 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 12:44 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-14 12:44 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-11-14 08:01 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-14 08:01 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-14 08:01 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-14 08:01 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-14 08:01 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-14 08:01 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-11-14 08:01 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-14 08:01 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-14 08:00 --------- d-----w C:\Program Files\Windows Mail
2007-11-11 01:51 --------- d-----w C:\Program Files\Microsoft Games
2007-11-06 16:03 --------- d-----w C:\ProgramData\Avg7
2007-11-05 18:18 9,216 ----a-w C:\Windows\System32\avgwlntf.dll
2007-10-18 16:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-10-10 22:32 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-10 22:32 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-10 22:32 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-10 22:32 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 22:29 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-10 22:29 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 22:29 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-09-15 22:35 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Rasmpc]
@={9D1F87E7-4D72-41AB-9D57-D101A08F20E5}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="TOSCDSPD.EXE" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-11-30 20:35 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-15 15:14 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 00:07 4390912 C:\Windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" []
"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 07:06 413696]
"SVPWUTIL"="C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 20:42 438272]
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [2007-03-21 16:23 413696]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-09-10 22:21 180224]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-08 21:23 191552]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-22 09:37 579072]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 06:00 204800]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-08-24 19:54 141848]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-08-24 19:54 129560]
"MMTray"="MMTray.exe" []
"HomeKeyLogger"="C:\Program Files\HomeKeylogger\KeyLogger.exe" [2007-08-04 02:36 28160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-08 21:23 191552]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-05 13:21 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-11-05 13:18 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\[u]0[/u]0TCrdMain]
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2007-12-14 08:18 482760 --a------ C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 --a------ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-08-24 19:54 154136 --a------ C:\Windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HSON]
C:\Program Files\TOSHIBA\TBS\HSON.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify]
2006-11-06 16:14 34352 --a------ C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2007-08-31 15:46 1460560 --a------ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-05-10 17:02 77824 --a------ C:\Program Files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe /VeohHide
R0 LPCFilter;LPC Lower Filter Driver;C:\Windows\system32\DRIVERS\LPCFilter.sys [2006-07-28 15:25]
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-04-27 19:13]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R2 TNaviSrv;TOSHIBA Navi Support Service;C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2007-04-27 19:15]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-08-24 19:39]
R3 NETw3v32;Pilote de carte réseau Intel(R) PRO/Wireless 3945ABG pour Windows Vista 32 bits;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 21:48]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-12-25 02:35]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 10:50]
R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-03-12 20:47]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\AutoRun.exe
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 10:43:18
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 10:44:10
ComboFix-quarantined-files.txt 2008-01-06 15:44:07
.
2008-01-04 16:19:24 --- E O F ---
ComboFix 08-01-04.1 - Florent 2008-01-06 10:41:09.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1301 [GMT -5:00]
Running from: C:\Users\Florent\Desktop\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Common Files\Yazzle1848OinUninstaller.exe
C:\Windows\system32\x64
C:\Windows\system32\X86
C:\Windows\system32\X86\License.rtf
C:\Windows\system32\X86\Readme.txt
C:\Windows\system32\X86\setup.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-06 to 2008-01-06 ))))))))))))))))))))))))))))))))))))
.
2008-01-06 10:39 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2007-12-27 12:44 . 2007-12-27 12:47 <REP> d-------- C:\Program Files\HomeKeylogger
2007-12-27 12:37 . 2007-12-27 12:38 <REP> d-a------ C:\Users\All Users\rkfree
2007-12-27 12:37 . 2007-12-27 12:38 <REP> d-a------ C:\ProgramData\rkfree
2007-12-27 12:37 . 2007-12-27 13:57 <REP> d-------- C:\Program Files\RKFree
2007-12-17 15:42 . 2008-01-05 17:16 54,156 --ah----- C:\Windows\QTFont.qfn
2007-12-17 15:42 . 2007-12-17 15:42 1,409 --a------ C:\Windows\QTFont.for
2007-12-17 14:44 . 2007-12-27 12:50 <REP> d-------- C:\Program Files\Windows Live
2007-12-17 14:39 . 2007-12-17 14:46 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-17 14:38 . 2007-12-17 14:43 <REP> d-------- C:\Users\All Users\WLInstaller
2007-12-17 14:38 . 2007-12-17 14:43 <REP> d-------- C:\ProgramData\WLInstaller
2007-12-17 11:51 . 2007-12-17 11:51 <REP> d-------- C:\Program Files\Lionhead Studios
2007-12-15 13:12 . 2007-12-15 13:12 <REP> d-------- C:\Users\Florent\AppData\Roaming\InstallShield
2007-12-15 12:29 . 2007-04-04 18:53 81,768 --a------ C:\Windows\System32\xinput1_3.dll
2007-12-15 12:28 . 2007-03-12 16:42 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2007-12-15 12:28 . 2007-03-12 16:42 1,123,696 --a------ C:\Windows\System32\D3DCompiler_33.dll
2007-12-15 12:28 . 2007-03-15 16:57 443,752 --a------ C:\Windows\System32\d3dx10_33.dll
2007-12-14 21:56 . 2007-12-14 21:58 114 --a------ C:\Windows\SpaceForce-RU.cfg
2007-12-14 21:46 . 2007-12-14 21:46 <REP> d-------- C:\Windows\SpaceForce - Rogue Universe
2007-12-14 20:12 . 2007-12-14 20:53 <REP> d-------- C:\Users\Florent\AppData\Roaming\DAEMON Tools
2007-12-14 20:11 . 2007-12-14 20:11 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2007-12-14 14:02 . 2007-12-14 14:02 1 --a------ C:\Windows\System32\SI.bin
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Videos
2007-12-14 11:50 . 2006-11-02 05:23 <REP> d-------- C:\Users\Administrateur\Saved Games
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Pictures
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Music
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Links
2007-12-14 11:50 . 2006-11-02 05:23 <REP> dr------- C:\Users\Administrateur\Downloads
2007-12-14 11:50 . 2007-12-14 11:50 <REP> dr------- C:\Users\Administrateur\Documents
2007-12-14 11:50 . 2006-11-02 06:18 <REP> d--h----- C:\Users\Administrateur\AppData
2007-12-13 10:04 . 2007-12-13 10:04 26 --a------ C:\Windows\System32\satsukidecodersettings.ini
2007-12-12 15:36 . 2007-12-12 15:36 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-12-12 15:36 . 2007-11-29 23:30 3,596,288 --a------ C:\Windows\System32\qt-dx331.dll
2007-12-12 15:36 . 2007-07-25 14:24 1,559,040 --a------ C:\Windows\System32\xvidcore.dll
2007-12-12 15:36 . 2007-12-04 02:33 682,496 --a------ C:\Windows\System32\divx.dll
2007-12-12 15:36 . 2006-09-24 16:11 389,120 --a------ C:\Windows\System32\lameACM.acm
2007-12-12 15:36 . 2007-03-10 12:51 282,624 --a------ C:\Windows\System32\xvidvfw.dll
2007-12-12 15:36 . 2004-01-25 17:18 217,088 --a------ C:\Windows\System32\yv12vfw.dll
2007-12-12 15:36 . 2007-09-04 17:56 164,352 --a------ C:\Windows\System32\unrar.dll
2007-12-12 15:36 . 2007-09-21 01:52 118,784 --a------ C:\Windows\System32\ac3acm.acm
2007-12-12 15:36 . 2007-11-29 23:28 81,920 --a------ C:\Windows\System32\dpl100.dll
2007-12-12 15:36 . 2007-10-03 16:03 414 --a------ C:\Windows\System32\lame_acm.xml
2007-12-12 14:59 . 2008-01-05 23:41 1,289 --a------ C:\Windows\mozver.dat
2007-12-12 13:33 . 2000-05-22 16:58 647,872 --a------ C:\Windows\System32\mscomct2.ocx
2007-12-12 13:33 . 1998-06-24 00:00 209,192 --a------ C:\Windows\System32\TABCTL32.OCX
2007-12-12 13:33 . 2003-01-26 15:48 147,456 --a------ C:\Windows\System32\vbzip11.dll
2007-12-12 13:33 . 1998-12-02 09:11 143,360 --a------ C:\Windows\System32\vbuzip10.dll
2007-12-12 13:33 . 1998-06-23 17:00 115,016 --a------ C:\Windows\System32\MSINET.OCX
2007-12-12 13:33 . 2005-06-30 09:53 45,056 --a------ C:\Windows\System32\wndRestrict.ocx
2007-12-12 13:33 . 1999-08-29 10:15 7,716 --a------ C:\Windows\System32\URLHIST.tlb
2007-12-12 13:14 . 2007-12-12 13:15 <REP> d-------- C:\Users\Florent\AppData\Roaming\Media Player Classic
2007-12-12 12:39 . 2007-12-12 12:39 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-12 12:39 . 2007-12-12 12:39 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-12 12:39 . 2007-12-12 12:39 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-12 12:39 . 2007-12-12 12:39 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-12 12:37 . 2007-12-12 12:37 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-12 12:37 . 2007-12-12 12:37 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-12 12:37 . 2007-12-12 12:37 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-12 12:37 . 2007-12-12 12:37 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-12 12:35 . 2007-12-12 12:35 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-12 12:35 . 2007-12-12 12:35 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-12 12:35 . 2007-12-12 12:35 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-11 20:55 . 2007-12-11 20:55 <REP> d-------- C:\Program Files\FLV Player
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 --a------ C:\Windows\System32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 --a------ C:\Windows\System32\ssldivx.dll
2007-12-09 17:11 . 2007-12-09 17:17 <REP> d-------- C:\Ares Tube
2007-12-08 20:30 . 2007-12-15 12:30 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2007-12-08 20:08 . 2006-11-29 13:06 3,426,072 --a------ C:\Windows\System32\d3dx9_32.dll
2007-12-08 20:08 . 2006-12-14 13:47 782,336 -ra------ C:\Windows\System32\tmp58C9.tmp
2007-12-08 20:08 . 2006-11-29 13:06 440,080 --a------ C:\Windows\System32\d3dx10.dll
2007-12-08 20:08 . 2007-12-08 20:08 409,600 --a------ C:\Windows\System32\wrap_oal.dll
2007-12-08 20:08 . 2006-12-08 12:02 251,672 --a------ C:\Windows\System32\xactengine2_5.dll
2007-12-08 20:08 . 2006-09-28 16:05 237,848 --a------ C:\Windows\System32\xactengine2_4.dll
2007-12-08 20:08 . 2007-12-08 20:08 114,688 --a------ C:\Windows\System32\OpenAL32.dll
2007-12-08 12:33 . 2007-03-04 07:55 1,936,528 --a------ C:\Windows\System32\ltmm15.dll
2007-12-08 12:33 . 2007-12-08 12:32 737,280 --a------ C:\Windows\iun6002.exe
2007-12-08 12:33 . 2007-03-04 07:55 135,168 --a------ C:\Windows\System32\DSKernel2.dll
2007-12-08 12:32 . 2007-12-08 12:32 <REP> d-------- C:\Windows\Replay Media Catcher
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Windows\Applian FLV Player
2007-12-08 00:32 . 2007-12-08 00:32 <REP> dr-h----- C:\MSOCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 15:37 --------- d-----w C:\Users\Florent\AppData\Roaming\AVG7
2008-01-04 23:33 --------- d-----w C:\Users\Florent\AppData\Roaming\BitTorrent
2008-01-04 23:07 --------- d-----w C:\Program Files\Grisbi
2008-01-04 06:01 --------- d-----w C:\Users\Florent\AppData\Roaming\Skype
2007-12-20 01:23 --------- d-----w C:\Users\Florent\AppData\Roaming\Grisbi
2007-12-17 16:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-16 21:44 --------- d-----w C:\Program Files\BitTorrent
2007-12-15 01:02 715,248 ----a-w C:\Windows\system32\drivers\sptd.sys
2007-12-12 19:32 --------- d-----w C:\Program Files\QuickTime
2007-12-12 19:26 --------- d-----w C:\Users\Florent\AppData\Roaming\DivX
2007-12-12 17:40 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-12 17:38 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 17:38 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 17:38 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 16:10 --------- d-----w C:\Program Files\DivX
2007-12-11 18:54 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2007-12-11 18:36 --------- d-----w C:\Program Files\RegCleaner
2007-12-06 01:58 --------- d-----w C:\Program Files\RADVideo
2007-12-06 01:54 --------- d-----w C:\ProgramData\Apple Computer
2007-12-05 23:43 --------- d-----w C:\Program Files\Veoh Networks
2007-12-01 19:44 --------- d-----w C:\Program Files\Google
2007-12-01 06:00 --------- d-----w C:\Program Files\Babo Violent 2
2007-11-30 12:44 4,870 ----a-w C:\Windows\System32\tmp.reg
2007-11-30 04:42 --------- d-----w C:\Program Files\AusLogics Disk Defrag
2007-11-29 22:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\Windows\System32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\Windows\System32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\Windows\System32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\Windows\System32\dpu10.dll
2007-11-21 23:58 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2007-11-21 23:58 --------- d-----w C:\Program Files\Synaptics
2007-11-17 04:33 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2007-11-17 02:41 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-14 12:44 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-14 12:44 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-14 12:44 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-14 12:44 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-14 12:44 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-14 12:44 299,008 ----a-w C:\Windows\System32\wlansec.dll
2007-11-14 12:44 289,280 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-14 12:44 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2007-11-14 12:44 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-14 12:44 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-14 12:44 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2007-11-14 12:44 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-14 12:44 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-14 12:44 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2007-11-14 08:01 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-14 08:01 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-14 08:01 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-14 08:01 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-14 08:01 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-14 08:01 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-11-14 08:01 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-14 08:01 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-14 08:00 --------- d-----w C:\Program Files\Windows Mail
2007-11-11 01:51 --------- d-----w C:\Program Files\Microsoft Games
2007-11-06 16:03 --------- d-----w C:\ProgramData\Avg7
2007-11-05 18:18 9,216 ----a-w C:\Windows\System32\avgwlntf.dll
2007-10-18 16:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-10-10 22:32 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-10 22:32 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-10 22:32 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-10 22:32 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 22:29 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-10 22:29 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 22:29 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-09-15 22:35 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Rasmpc]
@={9D1F87E7-4D72-41AB-9D57-D101A08F20E5}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="TOSCDSPD.EXE" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-11-30 20:35 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-15 15:14 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-02-15 00:07 4390912 C:\Windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" []
"HWSetup"="C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 07:06 413696]
"SVPWUTIL"="C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 20:42 438272]
"Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [2007-03-21 16:23 413696]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-09-10 22:21 180224]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-08 21:23 191552]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-22 09:37 579072]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 06:00 204800]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-08-24 19:54 141848]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-08-24 19:54 129560]
"MMTray"="MMTray.exe" []
"HomeKeyLogger"="C:\Program Files\HomeKeylogger\KeyLogger.exe" [2007-08-04 02:36 28160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-08 21:23 191552]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-05 13:21 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-11-05 13:18 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\[u]0[/u]0TCrdMain]
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2007-12-14 08:18 482760 --a------ C:\Program Files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 23:47 31016 --a------ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2007-08-24 19:54 154136 --a------ C:\Windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HSON]
C:\Program Files\TOSHIBA\TBS\HSON.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify]
2006-11-06 16:14 34352 --a------ C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2007-08-31 15:46 1460560 --a------ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-05-10 17:02 77824 --a------ C:\Program Files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe /VeohHide
R0 LPCFilter;LPC Lower Filter Driver;C:\Windows\system32\DRIVERS\LPCFilter.sys [2006-07-28 15:25]
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-04-27 19:13]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R2 TNaviSrv;TOSHIBA Navi Support Service;C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2007-04-27 19:15]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-08-24 19:39]
R3 NETw3v32;Pilote de carte réseau Intel(R) PRO/Wireless 3945ABG pour Windows Vista 32 bits;C:\Windows\system32\DRIVERS\NETw3v32.sys [2007-02-07 21:48]
R3 RTL8169;Realtek 8169 NT Driver;C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-12-25 02:35]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 10:50]
R3 UVCFTR;UVCFTR;C:\Windows\system32\DRIVERS\UVCFTR_S.SYS [2007-03-12 20:47]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\AutoRun.exe
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 10:43:18
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 10:44:10
ComboFix-quarantined-files.txt 2008-01-06 15:44:07
.
2008-01-04 16:19:24 --- E O F ---
wouhouuu et je précise que outerinfo a disparu de ma liste de programmes installés, mais est il vraiment delete?
Regis59
Messages postés
21123
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 346
6 janv. 2008 à 21:44
6 janv. 2008 à 21:44
Oui :-)
Ou en sont tes soucis?
A+
Ou en sont tes soucis?
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
excusez moi je pensais que ma réponse avait été posét mais visiblement non.
Mes problemes ont bien disparus, tout va bien, merci beaucoup! :)
Mes problemes ont bien disparus, tout va bien, merci beaucoup! :)
Regis59
Messages postés
21123
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 346
13 janv. 2008 à 11:35
13 janv. 2008 à 11:35
DE RIEN :)
Bon dimanche !
A+
Bon dimanche !
A+