Pc infecté : rapport Hijackthis
taurilius
-
green day -
green day -
Bonjour,
Je suis infecté par des popups comme bon nombre de personnes ce qui ralenti mon ordinateur.
Si vous pouviez m'aider sa serait vraiment Super.
Rapport Hijacthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:34, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\VIAudioi\SBADeck\ADeck.exe
F:\Program Files\Vtune\TBPanel.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Opera\opera.exe
F:\WINDOWS\system32\wpabaln.exe
F:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\Windows Live\Messenger\usnsvc.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [OSSelectorReinstall] F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe
O4 - HKLM\..\Run: [AudioDeck] F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [StartCCC] "F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Gainward] F:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OutpostMonitor] F:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "F:\Program Files\Agnitum\Outpost Security Suite Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Réglage rapide de Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: f:\progra~1\agnitum\outpos~1\wl_hook.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - F:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
Je suis infecté par des popups comme bon nombre de personnes ce qui ralenti mon ordinateur.
Si vous pouviez m'aider sa serait vraiment Super.
Rapport Hijacthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:34, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\VIAudioi\SBADeck\ADeck.exe
F:\Program Files\Vtune\TBPanel.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Opera\opera.exe
F:\WINDOWS\system32\wpabaln.exe
F:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\Windows Live\Messenger\usnsvc.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [OSSelectorReinstall] F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe
O4 - HKLM\..\Run: [AudioDeck] F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [StartCCC] "F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Gainward] F:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OutpostMonitor] F:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "F:\Program Files\Agnitum\Outpost Security Suite Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Réglage rapide de Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: f:\progra~1\agnitum\outpos~1\wl_hook.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - F:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
A voir également:
- Pc infecté : rapport Hijackthis
- Reinitialiser pc - Guide
- Pc lent - Guide
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Double ecran pc - Guide
- Forcer demarrage pc - Guide
21 réponses
ComboFix 08-06-20.4 - ludo 2008-06-24 12:20:31.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.677 [GMT 2:00]
Endroit: F:\Documents and Settings\ludo\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-24 to 2008-06-24 ))))))))))))))))))))))))))))))))))))
.
2008-06-23 18:22 . 2008-06-23 18:22 <REP> d-------- F:\Documents and Settings\ludo\Application Data\MailFrontier
2008-06-23 18:15 . 2008-06-24 11:27 4,212 ---h----- F:\WINDOWS\system32\zllictbl.dat
2008-06-23 18:14 . 2006-08-23 23:38 75,776 --a------ F:\WINDOWS\zllsputility.exe
2008-06-23 18:14 . 2006-08-23 23:39 42,920 --a------ F:\WINDOWS\system32\vsutil_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 26,536 --a------ F:\WINDOWS\zllsputility_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 18,344 --a------ F:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 18,344 --a------ F:\WINDOWS\system32\imsinstall_loc040c.dll
2008-06-23 18:14 . 2004-04-27 04:40 11,264 --a------ F:\WINDOWS\system32\SpOrder.dll
2008-06-23 18:13 . 2008-06-23 18:13 <REP> d-------- F:\Program Files\Zone Labs
2008-06-22 15:36 . 2008-06-22 15:36 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Media Player Classic
2008-06-22 15:34 . 2008-06-22 15:34 <REP> d-------- F:\Program Files\K-Lite Codec Pack
2008-06-22 15:34 . 2008-03-21 22:30 3,596,288 --a------ F:\WINDOWS\system32\qt-dx331.dll
2008-06-22 15:25 . 2008-06-24 11:18 <REP> d-------- F:\Program Files\Lopxp
2008-06-21 09:21 . 2008-06-21 09:21 <REP> d-------- F:\WINDOWS\nview
2008-06-20 17:59 . 2008-04-30 17:27 442,368 --a------ F:\WINDOWS\system32\NVUNINST.EXE
2008-06-19 23:05 . 2008-06-20 22:56 <REP> d-------- F:\WINDOWS\BDOSCAN8
2008-06-19 22:54 . 2008-06-19 22:54 <REP> d-------- F:\ATI
2008-06-19 18:09 . 2008-06-19 18:09 13,646 --a------ F:\WINDOWS\system32\wpa.bak
2008-06-19 13:59 . 2008-06-19 13:59 <REP> d-------- F:\WINDOWS\system32\LogFiles
2008-06-19 13:59 . 2008-06-19 13:59 <REP> d-------- F:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-19 12:04 . 2008-06-19 12:04 <REP> d-------- F:\Program Files\Common Files
2008-06-19 12:04 . 2003-07-17 20:17 5,174 --a------ F:\WINDOWS\system32\nppt9x.vxd
2008-06-19 12:04 . 2005-01-01 11:43 4,682 --a------ F:\WINDOWS\system32\npptNT2.sys
2008-06-19 12:04 . 2008-06-22 23:29 31 --a------ F:\WINDOWS\GunzLauncher.INI
2008-06-19 12:00 . 2008-06-19 12:00 <REP> d---s---- F:\Program Files\Xfire
2008-06-19 12:00 . 2008-06-19 12:00 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Xfire
2008-06-19 11:47 . 2008-06-19 11:47 <REP> d-------- F:\Program Files\NHN USA
2008-06-19 11:47 . 2008-06-19 12:01 <REP> d--h----- F:\Documents and Settings\ludo\Application Data\ijjigame
2008-06-19 11:47 . 2008-06-17 19:28 710,064 --a------ F:\WINDOWS\system32\ijjiSetup.exe
2008-06-19 11:47 . 2008-06-11 23:01 58,800 --a------ F:\WINDOWS\system32\ijjiPlugin2.dll
2008-06-18 17:09 . 2008-06-18 17:09 <REP> d-------- F:\Program Files\Sunbelt Software
2008-06-18 17:01 . 2008-06-18 17:01 <REP> d-------- F:\Program Files\ESET
2008-06-18 17:01 . 2008-06-18 17:01 <REP> d-------- F:\Documents and Settings\All Users\Application Data\ESET
2008-06-18 16:38 . 2008-06-18 16:38 <REP> d-------- F:\Program Files\Anti-Leech
2008-06-18 16:05 . 2005-05-27 09:23 2,180,096 --a------ F:\WINDOWS\system32\drivers\lvsvf2.sys
2008-06-18 15:56 . 2005-07-19 17:31 53,248 -ra------ F:\WINDOWS\system32\InstMed.exe
2008-06-18 15:55 . 2005-05-27 09:36 372,736 --a------ F:\WINDOWS\system32\LVUI2RC.dll
2008-06-18 15:55 . 2005-01-31 11:20 211,712 --a------ F:\WINDOWS\system32\drivers\LV561AV.SYS
2008-06-18 15:55 . 2005-05-27 09:29 204,800 --a------ F:\WINDOWS\system32\LVUI2.dll
2008-06-18 15:55 . 2005-05-27 09:26 204,800 --a------ F:\WINDOWS\system32\LVCodec2.dll
2008-06-18 15:55 . 2005-01-31 11:00 106,496 --a------ F:\WINDOWS\system32\lvcoinst.dll
2008-06-18 15:55 . 2005-05-27 09:31 22,016 --a------ F:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-06-18 15:55 . 2005-01-31 09:38 9,255 --a------ F:\WINDOWS\system32\lvcoinst.ini
2008-06-18 11:27 . 2008-06-18 11:27 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-18 11:22 . 2004-08-19 16:10 91,648 --a------ F:\WINDOWS\system32\drivers\kswdmcap.ax
2008-06-18 11:22 . 2004-08-19 16:10 61,952 --a------ F:\WINDOWS\system32\drivers\kstvtune.ax
2008-06-18 11:22 . 2004-08-19 16:09 54,784 --a------ F:\WINDOWS\system32\drivers\vfwwdm32.dll
2008-06-18 11:22 . 2004-08-19 16:10 43,008 --a------ F:\WINDOWS\system32\drivers\ksxbar.ax
2008-06-18 11:22 . 2004-08-19 16:10 28,672 --a------ F:\WINDOWS\system32\drivers\vidcap.ax
2008-06-18 11:21 . 2008-06-18 11:21 <REP> d-------- F:\Program Files\IVT Corporation
2008-06-17 22:42 . 2008-06-17 22:42 <REP> d-------- F:\Program Files\Foxit Software
2008-06-17 22:01 . 2008-06-17 22:01 0 --a------ F:\WINDOWS\nsreg.dat
2008-06-17 19:43 . 2008-06-17 19:49 <REP> d-------- F:\Program Files\Navilog1
2008-06-16 19:52 . 2008-06-16 19:52 <REP> d-------- F:\WINDOWS\system32\Kaspersky Lab
2008-06-16 15:59 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\ludo\Application Data\FileZilla
2008-06-16 15:54 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\FileZilla FTP Client
2008-06-16 15:36 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\CCleaner
2008-06-16 15:34 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Spybot - Search & Destroy
2008-06-16 15:34 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 12:38 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2008-06-16 12:38 . 2007-07-30 19:19 207,736 --a------ F:\WINDOWS\system32\muweb.dll
2008-06-16 12:38 . 2007-07-30 19:18 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2008-06-15 20:49 . 2008-06-15 20:49 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-15 20:41 . 2008-06-15 20:41 <REP> d--h----- F:\WINDOWS\PIF
2008-06-15 20:09 . 2008-06-15 20:09 <REP> d-------- F:\Program Files\Trend Micro
2008-06-15 19:50 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Messenger Plus! Live
2008-06-15 19:26 . 2008-06-15 19:26 1,082,880 --a------ F:\WINDOWS\system32\AutoPartNt.exe
2008-06-15 19:26 . 2008-06-15 19:27 1,024 --a------ F:\WINDOWS\system32\AutoPartNt.let
2008-06-15 19:01 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\iTunes
2008-06-15 19:01 . 2008-06-15 19:01 <REP> d-------- F:\Program Files\iPod
2008-06-15 19:01 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Bonjour
2008-06-15 19:01 . 2008-06-15 19:01 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Apple Computer
2008-06-15 19:00 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\QuickTime
2008-06-15 19:00 . 2008-06-15 19:00 <REP> d-------- F:\Program Files\Fichiers communs\Apple
2008-06-15 19:00 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Apple Software Update
2008-06-15 19:00 . 2008-06-15 19:01 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-15 19:00 . 2008-06-15 19:00 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Apple
2008-06-15 18:51 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Opera
2008-06-15 18:47 . 2008-06-15 19:00 <REP> d----c--- F:\WINDOWS\system32\DRVSTORE
2008-06-15 18:47 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\ludo\Contacts
2008-06-15 18:44 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Google
2008-06-15 18:44 . 2008-06-24 10:19 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-15 18:43 . 2008-06-15 18:47 <REP> d-------- F:\Program Files\Windows Live
2008-06-15 18:43 . 2008-06-15 18:47 <REP> d--hsc--- F:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-06-15 18:42 . 2008-06-21 09:22 <REP> d-------- F:\WINDOWS\nvidia icons
2008-06-15 18:39 . 2008-06-18 15:54 <REP> d-------- F:\Program Files\Logitech
2008-06-15 18:39 . 2008-06-18 15:55 <REP> d-------- F:\Program Files\Fichiers communs\Logitech
2008-06-15 18:34 . 2004-08-03 23:10 85,376 --a------ F:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-06-15 18:32 . 2004-08-19 16:10 91,648 --a------ F:\WINDOWS\system32\kswdmcap.ax
2008-06-15 18:32 . 2004-08-19 16:10 91,648 --a--c--- F:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-06-15 18:32 . 2004-08-19 16:10 61,952 --a------ F:\WINDOWS\system32\kstvtune.ax
2008-06-15 18:32 . 2004-08-19 16:10 61,952 --a--c--- F:\WINDOWS\system32\dllcache\kstvtune.ax
2008-06-15 18:32 . 2004-08-19 16:09 54,784 --a------ F:\WINDOWS\system32\vfwwdm32.dll
2008-06-15 18:32 . 2004-08-19 16:09 54,784 --a--c--- F:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-06-15 18:32 . 2004-08-19 16:10 43,008 --a------ F:\WINDOWS\system32\ksxbar.ax
2008-06-15 18:32 . 2004-08-19 16:10 43,008 --a--c--- F:\WINDOWS\system32\dllcache\ksxbar.ax
2008-06-14 23:10 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Driver Cleaner Pro
2008-06-14 22:51 . 2008-06-14 22:51 <REP> d-------- F:\Documents and Settings\Administrateur\Application Data\ATI
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-14 22:50 . 2008-06-14 17:14 <REP> d--h----- F:\Documents and Settings\Administrateur\Modèles
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Mes documents
2008-06-14 22:50 . 2008-06-14 19:03 <REP> dr------- F:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Favoris
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Bureau
2008-06-14 22:50 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\Administrateur
2008-06-14 22:10 . 2008-06-14 22:10 <REP> d-------- F:\WINDOWS\ServicePackFiles
2008-06-14 22:08 . 2008-06-14 22:08 <REP> d-------- F:\WINDOWS\EHome
2008-06-14 22:08 . 2004-07-17 11:40 19,528 --a------ F:\WINDOWS\[u]0[/u]00001_.tmp
2008-06-14 21:50 . 2008-06-14 21:50 <REP> d-------- F:\WINDOWS\system32\config\systemprofile\Application Data\ATI
2008-06-14 21:47 . 2008-06-14 21:47 <REP> d-------- F:\Documents and Settings\All Users\Application Data\ATI
2008-06-14 21:47 . 2008-06-14 21:47 0 --a------ F:\WINDOWS\ativpsrm.bin
2008-06-14 21:03 . 2008-06-20 17:56 10 --a------ F:\WINDOWS\WININIT.INI
2008-06-14 21:00 . 2004-05-07 05:12 8,703 -r------- F:\WINDOWS\system32\drivers\EIO.sys
2008-06-14 20:46 . 2008-06-14 21:50 4,096 --a------ F:\WINDOWS\system32\crash
2008-06-14 20:38 . 2008-06-14 23:10 <REP> d-------- F:\Documents and Settings\ludo\Application Data\ATI
2008-06-14 20:30 . 2008-06-15 18:43 <REP> d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-14 19:05 . 2004-08-04 02:39 58,496 --a------ F:\WINDOWS\system32\drivers\redbook.sys
2008-06-14 19:05 . 2001-08-17 23:59 3,072 --a------ F:\WINDOWS\system32\drivers\audstub.sys
2008-06-14 19:04 . 2004-08-19 16:09 77,312 --a------ F:\WINDOWS\system32\usbui.dll
2008-06-14 19:04 . 2004-08-04 01:07 46,464 --a------ F:\WINDOWS\system32\drivers\GAGP30KX.SYS
2008-06-14 19:04 . 2001-08-17 22:13 27,165 --a------ F:\WINDOWS\system32\drivers\fetnd5.sys
2008-06-14 19:03 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Default User\Voisinage réseau
2008-06-14 19:03 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Default User\Voisinage d'impression
2008-06-14 19:03 . 2008-06-18 16:49 <REP> d--h----- F:\Documents and Settings\Default User\Modèles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-19 10:30 --------- d-----w F:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-19 09:47 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-06-18 14:49 --------- d-----w F:\Program Files\ma-config.com
2008-06-15 16:42 --------- d-----w F:\Program Files\Fichiers communs\InstallShield
2008-06-14 17:59 272,768 ------w F:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 16:53 --------- d-----w F:\Program Files\ASUS
2008-06-14 16:47 --------- d-----w F:\Program Files\Activision
2008-06-14 16:41 685,816 ----a-w F:\WINDOWS\system32\drivers\sptd.sys
2008-06-14 16:32 --------- d-----w F:\Program Files\VIAudioi
2008-06-14 16:21 --------- d-----w F:\Program Files\VIA
2008-06-14 15:36 --------- d-----w F:\Documents and Settings\All Users\Application Data\Acronis
2008-06-14 15:30 99,776 ----a-w F:\WINDOWS\system32\drivers\snapman.sys
2008-06-14 15:30 --------- d-----w F:\Program Files\Fichiers communs\Acronis
2008-06-14 15:29 --------- d-----w F:\Program Files\Acronis
2008-06-14 15:18 --------- d-----w F:\Program Files\microsoft frontpage
2008-06-14 15:16 --------- d-----w F:\Program Files\Services en ligne
2008-06-03 06:20 3,100,160 ----a-w F:\WINDOWS\system32\drivers\ati2mtag.sys
2008-06-03 03:21 306,688 ----a-w F:\WINDOWS\system32\ati2dvag.dll
2008-06-03 02:59 3,500,352 ----a-w F:\WINDOWS\system32\ati3duag.dll
2008-06-03 02:48 2,120,832 ----a-w F:\WINDOWS\system32\ativvaxx.dll
2008-06-03 02:21 557,056 ----a-w F:\WINDOWS\system32\ati2cqag.dll
2008-05-08 12:28 202,752 ----a-w F:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w F:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w F:\WINDOWS\system32\wininet.dll
2008-03-31 21:25 682,496 ----a-w F:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w F:\WINDOWS\system32\ff_vfw.dll
2008-03-25 04:51 621,344 ----a-w F:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w F:\WINDOWS\system32\msjint40.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-24_11.13.19,28 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 08:07:15 2,048 --s-a-w F:\WINDOWS\bootstat.dat
+ 2008-06-24 09:27:28 2,048 --s-a-w F:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"LogitechSoftwareUpdate"="F:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OSSelectorReinstall"="F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe" [2006-05-31 11:20 1281425]
"AudioDeck"="F:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-07-26 08:19 540672]
"StartCCC"="F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [ ]
"QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"LVCOMSX"="F:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="F:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="F:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
"egui"="F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-01-30 12:37 1443072]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Zone Labs Client"="F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-08-23 23:38 968696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=F:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=F:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ball mags]
F:\DOCUME~1\ludo\APPLIC~1\ONCEFR~1\city play math.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAMP SHIM EXIT HECK]
F:\Documents and Settings\All Users\Application Data\That Face Camp Shim\FLAG FLAW.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
--------- 2003-12-11 09:50 20992 F:\WINDOWS\LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 F:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\Messenger\\msmsgs.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"F:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=
"F:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"F:\\Program Files\\Anti-Leech\\ALIE_1.0.2.3\\alhlp.exe"=
"F:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"F:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"F:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
R0 videX32;videX32;F:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 05:38]
R1 epfwtdir;epfwtdir;F:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-01-30 12:38]
S3 maconfservice;Ma-Config Service;"F:\Program Files\ma-config.com\maconfservice.exe" [2008-06-14 10:13]
S3 USBSTOR;Pilote de stockage de masse USB;F:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-24 12:22:02
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1???\ ?|????E:\Sound\VIA\vin???|???|?????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-24 12:22:54
ComboFix-quarantined-files.txt 2008-06-24 10:22:50
ComboFix2.txt 2008-06-24 09:14:11
Pre-Run: 57,052,848,128 octets libres
Post-Run: 57,072,668,672 octets libres
244 --- E O F --- 2008-06-20 21:11:03
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.677 [GMT 2:00]
Endroit: F:\Documents and Settings\ludo\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-24 to 2008-06-24 ))))))))))))))))))))))))))))))))))))
.
2008-06-23 18:22 . 2008-06-23 18:22 <REP> d-------- F:\Documents and Settings\ludo\Application Data\MailFrontier
2008-06-23 18:15 . 2008-06-24 11:27 4,212 ---h----- F:\WINDOWS\system32\zllictbl.dat
2008-06-23 18:14 . 2006-08-23 23:38 75,776 --a------ F:\WINDOWS\zllsputility.exe
2008-06-23 18:14 . 2006-08-23 23:39 42,920 --a------ F:\WINDOWS\system32\vsutil_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 26,536 --a------ F:\WINDOWS\zllsputility_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 18,344 --a------ F:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-06-23 18:14 . 2006-08-23 23:39 18,344 --a------ F:\WINDOWS\system32\imsinstall_loc040c.dll
2008-06-23 18:14 . 2004-04-27 04:40 11,264 --a------ F:\WINDOWS\system32\SpOrder.dll
2008-06-23 18:13 . 2008-06-23 18:13 <REP> d-------- F:\Program Files\Zone Labs
2008-06-22 15:36 . 2008-06-22 15:36 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Media Player Classic
2008-06-22 15:34 . 2008-06-22 15:34 <REP> d-------- F:\Program Files\K-Lite Codec Pack
2008-06-22 15:34 . 2008-03-21 22:30 3,596,288 --a------ F:\WINDOWS\system32\qt-dx331.dll
2008-06-22 15:25 . 2008-06-24 11:18 <REP> d-------- F:\Program Files\Lopxp
2008-06-21 09:21 . 2008-06-21 09:21 <REP> d-------- F:\WINDOWS\nview
2008-06-20 17:59 . 2008-04-30 17:27 442,368 --a------ F:\WINDOWS\system32\NVUNINST.EXE
2008-06-19 23:05 . 2008-06-20 22:56 <REP> d-------- F:\WINDOWS\BDOSCAN8
2008-06-19 22:54 . 2008-06-19 22:54 <REP> d-------- F:\ATI
2008-06-19 18:09 . 2008-06-19 18:09 13,646 --a------ F:\WINDOWS\system32\wpa.bak
2008-06-19 13:59 . 2008-06-19 13:59 <REP> d-------- F:\WINDOWS\system32\LogFiles
2008-06-19 13:59 . 2008-06-19 13:59 <REP> d-------- F:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-19 12:04 . 2008-06-19 12:04 <REP> d-------- F:\Program Files\Common Files
2008-06-19 12:04 . 2003-07-17 20:17 5,174 --a------ F:\WINDOWS\system32\nppt9x.vxd
2008-06-19 12:04 . 2005-01-01 11:43 4,682 --a------ F:\WINDOWS\system32\npptNT2.sys
2008-06-19 12:04 . 2008-06-22 23:29 31 --a------ F:\WINDOWS\GunzLauncher.INI
2008-06-19 12:00 . 2008-06-19 12:00 <REP> d---s---- F:\Program Files\Xfire
2008-06-19 12:00 . 2008-06-19 12:00 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Xfire
2008-06-19 11:47 . 2008-06-19 11:47 <REP> d-------- F:\Program Files\NHN USA
2008-06-19 11:47 . 2008-06-19 12:01 <REP> d--h----- F:\Documents and Settings\ludo\Application Data\ijjigame
2008-06-19 11:47 . 2008-06-17 19:28 710,064 --a------ F:\WINDOWS\system32\ijjiSetup.exe
2008-06-19 11:47 . 2008-06-11 23:01 58,800 --a------ F:\WINDOWS\system32\ijjiPlugin2.dll
2008-06-18 17:09 . 2008-06-18 17:09 <REP> d-------- F:\Program Files\Sunbelt Software
2008-06-18 17:01 . 2008-06-18 17:01 <REP> d-------- F:\Program Files\ESET
2008-06-18 17:01 . 2008-06-18 17:01 <REP> d-------- F:\Documents and Settings\All Users\Application Data\ESET
2008-06-18 16:38 . 2008-06-18 16:38 <REP> d-------- F:\Program Files\Anti-Leech
2008-06-18 16:05 . 2005-05-27 09:23 2,180,096 --a------ F:\WINDOWS\system32\drivers\lvsvf2.sys
2008-06-18 15:56 . 2005-07-19 17:31 53,248 -ra------ F:\WINDOWS\system32\InstMed.exe
2008-06-18 15:55 . 2005-05-27 09:36 372,736 --a------ F:\WINDOWS\system32\LVUI2RC.dll
2008-06-18 15:55 . 2005-01-31 11:20 211,712 --a------ F:\WINDOWS\system32\drivers\LV561AV.SYS
2008-06-18 15:55 . 2005-05-27 09:29 204,800 --a------ F:\WINDOWS\system32\LVUI2.dll
2008-06-18 15:55 . 2005-05-27 09:26 204,800 --a------ F:\WINDOWS\system32\LVCodec2.dll
2008-06-18 15:55 . 2005-01-31 11:00 106,496 --a------ F:\WINDOWS\system32\lvcoinst.dll
2008-06-18 15:55 . 2005-05-27 09:31 22,016 --a------ F:\WINDOWS\system32\drivers\LVUSBSta.sys
2008-06-18 15:55 . 2005-01-31 09:38 9,255 --a------ F:\WINDOWS\system32\lvcoinst.ini
2008-06-18 11:27 . 2008-06-18 11:27 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Bluetooth
2008-06-18 11:22 . 2004-08-19 16:10 91,648 --a------ F:\WINDOWS\system32\drivers\kswdmcap.ax
2008-06-18 11:22 . 2004-08-19 16:10 61,952 --a------ F:\WINDOWS\system32\drivers\kstvtune.ax
2008-06-18 11:22 . 2004-08-19 16:09 54,784 --a------ F:\WINDOWS\system32\drivers\vfwwdm32.dll
2008-06-18 11:22 . 2004-08-19 16:10 43,008 --a------ F:\WINDOWS\system32\drivers\ksxbar.ax
2008-06-18 11:22 . 2004-08-19 16:10 28,672 --a------ F:\WINDOWS\system32\drivers\vidcap.ax
2008-06-18 11:21 . 2008-06-18 11:21 <REP> d-------- F:\Program Files\IVT Corporation
2008-06-17 22:42 . 2008-06-17 22:42 <REP> d-------- F:\Program Files\Foxit Software
2008-06-17 22:01 . 2008-06-17 22:01 0 --a------ F:\WINDOWS\nsreg.dat
2008-06-17 19:43 . 2008-06-17 19:49 <REP> d-------- F:\Program Files\Navilog1
2008-06-16 19:52 . 2008-06-16 19:52 <REP> d-------- F:\WINDOWS\system32\Kaspersky Lab
2008-06-16 15:59 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\ludo\Application Data\FileZilla
2008-06-16 15:54 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\FileZilla FTP Client
2008-06-16 15:36 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\CCleaner
2008-06-16 15:34 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Spybot - Search & Destroy
2008-06-16 15:34 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-16 12:38 . 2007-07-30 19:19 271,224 --a------ F:\WINDOWS\system32\mucltui.dll
2008-06-16 12:38 . 2007-07-30 19:19 207,736 --a------ F:\WINDOWS\system32\muweb.dll
2008-06-16 12:38 . 2007-07-30 19:18 30,072 --a------ F:\WINDOWS\system32\mucltui.dll.mui
2008-06-15 20:49 . 2008-06-15 20:49 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-15 20:41 . 2008-06-15 20:41 <REP> d--h----- F:\WINDOWS\PIF
2008-06-15 20:09 . 2008-06-15 20:09 <REP> d-------- F:\Program Files\Trend Micro
2008-06-15 19:50 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Messenger Plus! Live
2008-06-15 19:26 . 2008-06-15 19:26 1,082,880 --a------ F:\WINDOWS\system32\AutoPartNt.exe
2008-06-15 19:26 . 2008-06-15 19:27 1,024 --a------ F:\WINDOWS\system32\AutoPartNt.let
2008-06-15 19:01 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\iTunes
2008-06-15 19:01 . 2008-06-15 19:01 <REP> d-------- F:\Program Files\iPod
2008-06-15 19:01 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Bonjour
2008-06-15 19:01 . 2008-06-15 19:01 <REP> d-------- F:\Documents and Settings\ludo\Application Data\Apple Computer
2008-06-15 19:00 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\QuickTime
2008-06-15 19:00 . 2008-06-15 19:00 <REP> d-------- F:\Program Files\Fichiers communs\Apple
2008-06-15 19:00 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Apple Software Update
2008-06-15 19:00 . 2008-06-15 19:01 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-15 19:00 . 2008-06-15 19:00 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Apple
2008-06-15 18:51 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Opera
2008-06-15 18:47 . 2008-06-15 19:00 <REP> d----c--- F:\WINDOWS\system32\DRVSTORE
2008-06-15 18:47 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\ludo\Contacts
2008-06-15 18:44 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Google
2008-06-15 18:44 . 2008-06-24 10:19 <REP> d-------- F:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-15 18:43 . 2008-06-15 18:47 <REP> d-------- F:\Program Files\Windows Live
2008-06-15 18:43 . 2008-06-15 18:47 <REP> d--hsc--- F:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-06-15 18:42 . 2008-06-21 09:22 <REP> d-------- F:\WINDOWS\nvidia icons
2008-06-15 18:39 . 2008-06-18 15:54 <REP> d-------- F:\Program Files\Logitech
2008-06-15 18:39 . 2008-06-18 15:55 <REP> d-------- F:\Program Files\Fichiers communs\Logitech
2008-06-15 18:34 . 2004-08-03 23:10 85,376 --a------ F:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-06-15 18:32 . 2004-08-19 16:10 91,648 --a------ F:\WINDOWS\system32\kswdmcap.ax
2008-06-15 18:32 . 2004-08-19 16:10 91,648 --a--c--- F:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-06-15 18:32 . 2004-08-19 16:10 61,952 --a------ F:\WINDOWS\system32\kstvtune.ax
2008-06-15 18:32 . 2004-08-19 16:10 61,952 --a--c--- F:\WINDOWS\system32\dllcache\kstvtune.ax
2008-06-15 18:32 . 2004-08-19 16:09 54,784 --a------ F:\WINDOWS\system32\vfwwdm32.dll
2008-06-15 18:32 . 2004-08-19 16:09 54,784 --a--c--- F:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-06-15 18:32 . 2004-08-19 16:10 43,008 --a------ F:\WINDOWS\system32\ksxbar.ax
2008-06-15 18:32 . 2004-08-19 16:10 43,008 --a--c--- F:\WINDOWS\system32\dllcache\ksxbar.ax
2008-06-14 23:10 . 2008-06-18 16:49 <REP> d-------- F:\Program Files\Driver Cleaner Pro
2008-06-14 22:51 . 2008-06-14 22:51 <REP> d-------- F:\Documents and Settings\Administrateur\Application Data\ATI
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-14 22:50 . 2008-06-14 17:14 <REP> d--h----- F:\Documents and Settings\Administrateur\Modèles
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Mes documents
2008-06-14 22:50 . 2008-06-14 19:03 <REP> dr------- F:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Favoris
2008-06-14 22:50 . 2008-06-14 19:03 <REP> d-------- F:\Documents and Settings\Administrateur\Bureau
2008-06-14 22:50 . 2008-06-18 16:49 <REP> d-------- F:\Documents and Settings\Administrateur
2008-06-14 22:10 . 2008-06-14 22:10 <REP> d-------- F:\WINDOWS\ServicePackFiles
2008-06-14 22:08 . 2008-06-14 22:08 <REP> d-------- F:\WINDOWS\EHome
2008-06-14 22:08 . 2004-07-17 11:40 19,528 --a------ F:\WINDOWS\[u]0[/u]00001_.tmp
2008-06-14 21:50 . 2008-06-14 21:50 <REP> d-------- F:\WINDOWS\system32\config\systemprofile\Application Data\ATI
2008-06-14 21:47 . 2008-06-14 21:47 <REP> d-------- F:\Documents and Settings\All Users\Application Data\ATI
2008-06-14 21:47 . 2008-06-14 21:47 0 --a------ F:\WINDOWS\ativpsrm.bin
2008-06-14 21:03 . 2008-06-20 17:56 10 --a------ F:\WINDOWS\WININIT.INI
2008-06-14 21:00 . 2004-05-07 05:12 8,703 -r------- F:\WINDOWS\system32\drivers\EIO.sys
2008-06-14 20:46 . 2008-06-14 21:50 4,096 --a------ F:\WINDOWS\system32\crash
2008-06-14 20:38 . 2008-06-14 23:10 <REP> d-------- F:\Documents and Settings\ludo\Application Data\ATI
2008-06-14 20:30 . 2008-06-15 18:43 <REP> d-------- F:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-14 19:05 . 2004-08-04 02:39 58,496 --a------ F:\WINDOWS\system32\drivers\redbook.sys
2008-06-14 19:05 . 2001-08-17 23:59 3,072 --a------ F:\WINDOWS\system32\drivers\audstub.sys
2008-06-14 19:04 . 2004-08-19 16:09 77,312 --a------ F:\WINDOWS\system32\usbui.dll
2008-06-14 19:04 . 2004-08-04 01:07 46,464 --a------ F:\WINDOWS\system32\drivers\GAGP30KX.SYS
2008-06-14 19:04 . 2001-08-17 22:13 27,165 --a------ F:\WINDOWS\system32\drivers\fetnd5.sys
2008-06-14 19:03 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Default User\Voisinage réseau
2008-06-14 19:03 . 2008-06-14 19:03 <REP> d--h----- F:\Documents and Settings\Default User\Voisinage d'impression
2008-06-14 19:03 . 2008-06-18 16:49 <REP> d--h----- F:\Documents and Settings\Default User\Modèles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-19 10:30 --------- d-----w F:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-19 09:47 --------- d--h--w F:\Program Files\InstallShield Installation Information
2008-06-18 14:49 --------- d-----w F:\Program Files\ma-config.com
2008-06-15 16:42 --------- d-----w F:\Program Files\Fichiers communs\InstallShield
2008-06-14 17:59 272,768 ------w F:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 16:53 --------- d-----w F:\Program Files\ASUS
2008-06-14 16:47 --------- d-----w F:\Program Files\Activision
2008-06-14 16:41 685,816 ----a-w F:\WINDOWS\system32\drivers\sptd.sys
2008-06-14 16:32 --------- d-----w F:\Program Files\VIAudioi
2008-06-14 16:21 --------- d-----w F:\Program Files\VIA
2008-06-14 15:36 --------- d-----w F:\Documents and Settings\All Users\Application Data\Acronis
2008-06-14 15:30 99,776 ----a-w F:\WINDOWS\system32\drivers\snapman.sys
2008-06-14 15:30 --------- d-----w F:\Program Files\Fichiers communs\Acronis
2008-06-14 15:29 --------- d-----w F:\Program Files\Acronis
2008-06-14 15:18 --------- d-----w F:\Program Files\microsoft frontpage
2008-06-14 15:16 --------- d-----w F:\Program Files\Services en ligne
2008-06-03 06:20 3,100,160 ----a-w F:\WINDOWS\system32\drivers\ati2mtag.sys
2008-06-03 03:21 306,688 ----a-w F:\WINDOWS\system32\ati2dvag.dll
2008-06-03 02:59 3,500,352 ----a-w F:\WINDOWS\system32\ati3duag.dll
2008-06-03 02:48 2,120,832 ----a-w F:\WINDOWS\system32\ativvaxx.dll
2008-06-03 02:21 557,056 ----a-w F:\WINDOWS\system32\ati2cqag.dll
2008-05-08 12:28 202,752 ----a-w F:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w F:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w F:\WINDOWS\system32\wininet.dll
2008-03-31 21:25 682,496 ----a-w F:\WINDOWS\system32\divx.dll
2008-03-28 17:41 7,680 ----a-w F:\WINDOWS\system32\ff_vfw.dll
2008-03-25 04:51 621,344 ----a-w F:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w F:\WINDOWS\system32\msjint40.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-24_11.13.19,28 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-24 08:07:15 2,048 --s-a-w F:\WINDOWS\bootstat.dat
+ 2008-06-24 09:27:28 2,048 --s-a-w F:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"LogitechSoftwareUpdate"="F:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OSSelectorReinstall"="F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe" [2006-05-31 11:20 1281425]
"AudioDeck"="F:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-07-26 08:19 540672]
"StartCCC"="F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [ ]
"QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"LVCOMSX"="F:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="F:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="F:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
"egui"="F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-01-30 12:37 1443072]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Zone Labs Client"="F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-08-23 23:38 968696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=F:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=F:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ball mags]
F:\DOCUME~1\ludo\APPLIC~1\ONCEFR~1\city play math.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAMP SHIM EXIT HECK]
F:\Documents and Settings\All Users\Application Data\That Face Camp Shim\FLAG FLAW.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Utility]
--------- 2003-12-11 09:50 20992 F:\WINDOWS\LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 F:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"F:\\Program Files\\Messenger\\msmsgs.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"F:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"F:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"F:\\Program Files\\iTunes\\iTunes.exe"=
"F:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"F:\\Program Files\\Anti-Leech\\ALIE_1.0.2.3\\alhlp.exe"=
"F:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"F:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"F:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
R0 videX32;videX32;F:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 05:38]
R1 epfwtdir;epfwtdir;F:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-01-30 12:38]
S3 maconfservice;Ma-Config Service;"F:\Program Files\ma-config.com\maconfservice.exe" [2008-06-14 10:13]
S3 USBSTOR;Pilote de stockage de masse USB;F:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-24 12:22:02
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1???\ ?|????E:\Sound\VIA\vin???|???|?????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-24 12:22:54
ComboFix-quarantined-files.txt 2008-06-24 10:22:50
ComboFix2.txt 2008-06-24 09:14:11
Pre-Run: 57,052,848,128 octets libres
Post-Run: 57,072,668,672 octets libres
244 --- E O F --- 2008-06-20 21:11:03