Bonjour à tous,
Pourriez- vous s'il vous plait m'aider à me débarrasser de l’icône shredder sur mon bureau .
Je joins un rapport fait avec combofix.exe
ComboFix 09-09-13.05 - khaled 14/09/2009 13:48.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1232 [GMT 2]
Lancé depuis: c:\documents and settings\khaled\Bureau\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: avast! antivirus 4.8.1351 [VPS 090913-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\khaled\Local Settings\Application Data\hbuuwi.dat
c:\documents and settings\khaled\Local Settings\Application Data\hbuuwi_nav.dat
c:\documents and settings\khaled\Mes documents\cc_20090507_1245.reg
c:\documents and settings\khaled\Mes documents\copie_registre.reg
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-530119669-2916499505-1154690182-1003
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Installer\139d3b6c.msp
c:\windows\Installer\153b716f.msi
c:\windows\Installer\19a18.msp
c:\windows\Installer\1ac0a.msp
c:\windows\Installer\1f344.msp
c:\windows\Installer\1f38e.msp
c:\windows\Installer\31ca1.msp
c:\windows\Installer\3268488.msi
c:\windows\Installer\3bf1e15.msi
c:\windows\patch.exe
c:\windows\Readme.txt
c:\windows\system32\drivers\Sonyhcp.dll
c:\windows\system32\Ijl11.dll
c:\windows\system32\tmp28.tmp
c:\windows\system32\tmp29.tmp
c:\windows\system32\winspool.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-14 au 2009-09-14 ))))))))))))))))))))))))))))))))))))
.
2009-09-13 12:19 . 2009-09-13 14:49 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-13 12:19 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-13 12:19 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-13 12:19 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-13 12:19 . 2009-09-13 12:19 -------- d-----w- c:\program files\Avira
2009-09-13 12:11 . 2009-09-13 12:11 -------- d-----w- c:\program files\Trend Micro
2009-09-13 10:28 . 2009-09-13 10:28 -------- d-----w- c:\program files\Uniblue
2009-09-13 06:11 . 2009-09-13 10:11 -------- d-----w- c:\program files\a-squared Anti-Malware
2009-09-12 10:30 . 2009-09-12 10:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Winferno
2009-09-12 10:29 . 2009-09-12 10:29 -------- d-----w- c:\documents and settings\khaled\Application Data\Titanium Gears
2009-09-12 10:28 . 2009-09-12 10:29 -------- d-----w- c:\program files\Playalot Games
2009-09-12 10:25 . 2006-10-09 11:06 495616 ----a-w- c:\windows\system32\WINUTIL5.DLL
2009-09-12 10:25 . 2006-05-17 06:40 393216 ----a-w- c:\windows\system32\WINLCTL5.DLL
2009-09-12 10:24 . 2009-09-13 12:02 -------- d-----w- c:\program files\My.Freeze.com Toolbar
2009-09-11 09:21 . 2009-09-12 16:45 -------- d-----w- c:\documents and settings\khaled\Application Data\HouseCall 6.6
2009-09-11 09:21 . 2009-09-11 09:21 -------- d-----w- c:\windows\system32\HouseCall 6.6
2009-09-10 22:04 . 2009-09-10 22:04 -------- d-----w- c:\documents and settings\khaled\Application Data\COWON
2009-09-10 22:02 . 2009-09-10 22:02 -------- d-----w- c:\program files\Fichiers communs\COWON
2009-09-10 22:02 . 2009-09-10 22:03 -------- d-----w- c:\program files\JetAudio
2009-09-09 00:56 . 2009-06-21 21:47 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-09-06 07:04 . 2009-09-06 07:04 -------- d-----w- c:\documents and settings\khaled\Application Data\Snapfish
2009-09-06 07:04 . 2009-09-06 07:04 -------- d-----w- c:\documents and settings\khaled\Local Settings\Application Data\Snapfish
2009-09-03 17:51 . 2009-09-03 17:51 -------- d-----w- c:\program files\Novel Games
2009-08-30 22:48 . 2009-08-30 22:48 -------- d-sh--w- c:\documents and settings\saida\IETldCache
2009-08-27 01:07 . 2009-08-27 01:07 -------- d-sh--w- c:\documents and settings\Default User\IETldCache
2009-08-26 20:34 . 2009-07-03 16:57 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-08-26 20:34 . 2009-07-03 16:57 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-08-26 20:27 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-08-25 21:41 . 2009-08-25 21:41 -------- d-----w- c:\program files\TLKGAMES
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 18:08 . 2006-05-11 17:20 -------- d-----w- c:\program files\eMule
2009-09-13 12:19 . 2008-07-09 08:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-13 10:28 . 2007-05-29 19:46 -------- d-----w- c:\documents and settings\khaled\Application Data\Uniblue
2009-09-13 10:09 . 2008-06-16 18:55 -------- d-----w- c:\program files\Crux Calculator v5
2009-09-12 10:26 . 2007-05-29 18:29 -------- d-----w- c:\program files\Common Files
2009-09-12 10:19 . 2006-06-09 06:48 -------- d-----w- c:\documents and settings\khaled\Application Data\dvdcss
2009-09-11 08:24 . 2009-06-23 21:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-09-10 22:02 . 2006-05-11 16:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-10 01:29 . 2008-11-25 06:15 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-09-07 11:28 . 2007-09-08 17:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2009-09-07 11:27 . 2008-08-29 11:35 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-07 11:27 . 2008-08-29 11:35 22328 ----a-w- c:\documents and settings\khaled\Application Data\PnkBstrK.sys
2009-09-07 11:27 . 2008-08-29 11:34 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-09-07 11:27 . 2008-09-20 13:37 2337865 ----a-w- c:\windows\system32\pbsvc.exe
2009-09-07 11:27 . 2008-08-29 11:34 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-09-07 11:09 . 2007-06-23 16:55 -------- d-----w- c:\program files\Ubisoft
2009-09-03 17:51 . 2006-05-11 17:27 83688 ----a-w- c:\documents and settings\khaled\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-01 04:40 . 2008-06-04 10:57 59042 ----a-w- c:\windows\system32\perfc040.dat
2009-09-01 04:40 . 2008-06-04 10:57 435288 ----a-w- c:\windows\system32\perfh040.dat
2009-09-01 04:40 . 2004-08-16 15:41 94530 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-01 04:40 . 2004-08-16 15:41 532738 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-01 04:13 . 2009-06-09 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2009-08-31 22:52 . 2009-07-21 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-30 23:36 . 2009-07-21 20:54 -------- d-----w- c:\program files\Microsoft Works
2009-08-30 22:59 . 2007-04-09 23:04 30 ----a-w- c:\windows\mscpt.dat
2009-08-30 22:30 . 2009-03-12 18:02 -------- d-----w- c:\documents and settings\khaled\Application Data\XnView
2009-08-30 10:18 . 2008-10-25 14:07 -------- d-----w- c:\program files\Foxit Software
2009-08-29 10:10 . 2006-05-21 06:25 -------- d-----w- c:\documents and settings\khaled\Application Data\Canon
2009-08-28 15:08 . 2006-05-11 20:32 -------- d-----w- c:\program files\DivX
2009-08-28 15:07 . 2009-04-29 19:24 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-08-28 15:05 . 2006-08-26 18:13 -------- d-----w- c:\program files\Picasa2
2009-08-24 15:45 . 2008-12-14 18:13 -------- d-----w- c:\program files\Winamp Remote
2009-08-24 08:12 . 2006-10-23 11:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-24 03:13 . 2008-10-02 12:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-17 16:10 . 2008-12-29 09:21 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2008-12-29 09:21 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2008-12-29 09:21 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-12-29 09:21 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-12-29 09:21 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2008-12-29 09:21 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2008-12-29 09:21 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2008-12-29 09:21 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2008-12-29 09:21 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-05 09:00 . 2008-11-02 17:54 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:03 . 2008-11-02 17:54 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 21:07 . 2006-08-23 14:10 -------- d-----w- c:\documents and settings\khaled\Application Data\Skype
2009-07-13 21:43 . 2004-08-16 15:41 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:57 . 2008-11-02 17:54 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:26 . 2008-11-02 17:54 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:26 . 2008-11-02 17:54 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:26 . 2008-11-02 17:54 736768 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:26 . 2008-11-02 17:54 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:26 . 2008-11-02 17:54 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:26 . 2008-11-02 17:54 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2008-11-02 17:54 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:40 . 2008-11-02 17:54 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2008-11-02 17:54 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 20:33 . 2009-06-12 20:33 1286066 ----a-w- c:\program files\InstallMMTV_32.exe
2009-05-18 08:21 . 2009-05-18 08:21 45778 ----a-w- c:\program files\fax-0413330158-0466767000-20090518095252-000645980.pdf
2009-04-28 06:58 . 2009-04-28 06:57 19250285 ----a-w- c:\program files\Seven_Remix_XP_2_0_by_Niwradsoft.exe
2009-03-07 05:51 . 2009-03-07 05:51 7858876 ----a-w- c:\program files\ripper setup_ocr.exe
2009-03-06 11:42 . 2009-03-06 11:42 1385540 ----a-w- c:\program files\DSpeech.exe
2009-03-02 16:02 . 2009-03-02 16:02 823283 ----a-w- c:\program files\DVDRegionFreeLite59.exe
2008-12-27 12:20 . 2008-12-27 12:20 16319896 ----a-w- c:\program files\jre-6u11-windows-i586-p-s.exe
2008-12-27 11:38 . 2008-12-27 11:36 661775 ----a-w- c:\program files\Java_Platform__Enterprise_Edition_5_SDK_uninstall.B12271236
2008-12-27 11:38 . 2008-12-27 11:36 192 ----a-w- c:\program files\Java_Platform__Enterprise_Edition_5_SDK_uninstall.A12271236
2008-12-27 08:37 . 2008-12-27 08:33 582130 ----a-w- c:\program files\Java_Platform__Enterprise_Edition_5_SDK_install.B12270933
2008-12-27 08:37 . 2008-12-27 08:33 184 ----a-w- c:\program files\Java_Platform__Enterprise_Edition_5_SDK_install.A12270933
2008-12-27 08:37 . 2008-12-27 08:34 2057 ----a-w- c:\program files\Install_Application_Server_9PE_200812270932.log
2008-12-27 08:34 . 2008-12-27 08:34 152067 ----a-w- c:\program files\uninstall.exe
2008-12-27 08:34 . 2008-12-27 08:34 139263 ----a-w- c:\program files\uninstall.dos.exe
2008-12-19 05:58 . 2008-12-17 06:06 3323 ----a-w- c:\program files\screamer.xml
2008-12-17 06:01 . 2008-12-17 06:01 1875912 ----a-w- c:\program files\screamer043.zip
2008-10-28 06:10 . 2008-10-28 06:10 1418588 ----a-w- c:\program files\eba.pdf
2008-10-25 14:06 . 2008-10-25 14:06 2690304 ----a-w- c:\program files\FoxitReader23_enu_Setup.exe
2008-10-25 13:37 . 2008-10-25 13:37 26596640 ----a-w- c:\program files\AdbeRdr90_fr_FR.exe
2008-10-11 18:08 . 2008-12-17 06:03 520192 ----a-w- c:\program files\sc.exe
2008-10-11 18:07 . 2008-12-17 06:03 659456 ----a-w- c:\program files\screamer.exe
2008-10-07 23:39 . 2008-12-17 06:03 173663 ----a-w- c:\program files\presets.xml.gz
2008-09-18 13:38 . 2008-12-17 06:03 98360 ----a-w- c:\program files\bass.dll
2008-07-28 10:40 . 2008-12-17 06:03 15424 ----a-w- c:\program files\basswma.dll
2008-05-26 10:51 . 2008-05-26 10:51 9345410 ----a-w- c:\program files\iWizz.zip
2008-04-17 11:17 . 2008-12-17 06:03 150904 ----a-w- c:\program files\bass_aac.dll
2007-05-27 07:44 . 2007-05-27 07:44 152576 ----a-w- c:\program files\7-zip.dll
2007-01-17 23:52 . 2008-12-17 06:03 892928 ----a-w- c:\program files\iconv.dll
2007-01-17 23:52 . 2008-12-17 06:03 161792 ----a-w- c:\program files\lame_enc.dll
2006-05-11 17:07 . 2006-05-11 17:07 278528 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2003-07-12 18:45 . 2007-02-06 17:36 274432 ----a-w- c:\program files\ClonyXXL.exe
2008-12-16 08:33 . 2008-12-16 08:33 23 --sha-w- c:\windows\system32\abccaebdcc_g.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-16 1266992]
"{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}"= "c:\program files\My.Freeze.com Toolbar\NetAssistant.dll" [2008-11-26 253048]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CLASSES_ROOT\clsid\{e38fa08e-f56a-4169-abf5-5c71e3c153a1}]
[HKEY_CLASSES_ROOT\NetAssistant.NetAssistantBHO.1]
[HKEY_CLASSES_ROOT\TypeLib\{1E8FC16F-4C51-49C4-BC9B-4FC24BDDCEE7}]
[HKEY_CLASSES_ROOT\NetAssistant.NetAssistantBHO]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DB35C569-5624-4CFC-8043-E5139F55A073}]
2008-09-24 04:02 796672 ----a-w- c:\progra~1\Crawler\Shared\CShared.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
2008-11-26 17:40 253048 ----a-w- c:\program files\My.Freeze.com Toolbar\NetAssistant.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Acronis Scheduler2 Service"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2008-10-17 165144]
"ATIPTA"="c:\ati technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-01-28 110740]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"Cloneur Expert Monitor"="c:\program files\Micro Application\Cloneur Expert\TrueImageMonitor.exe" [2006-05-12 443100]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"OPSE reminder"="c:\program files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" [2003-07-07 729088]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"VersionCheck"="c:\program files\Onlineeye Pro\vcheck.exe" [2005-08-26 167936]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-06-30 520024]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-03-23 198160]
"MailNotifierSessionManager"="c:\program files\Orange\Notification Mail\SessionManager\SessionManager.exe" [2008-11-03 131824]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-07-26 3209360]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-28 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-28 16248320]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2004-08-19 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-30 68856]
c:\documents and settings\khaled\Menu D‚marrer\Programmes\D‚marrage\
BJ Status Monitor Canon MP110 Series Printer.lnk - c:\documents and settings\khaled\cnmss Canon MP110 Series Printer (Local).exe [2008-8-6 13824]
BJ Status Monitor Canon MP110 Series Printer.lnk.disabled [2008-11-11 1006]
PowerReg Scheduler.exe [2007-4-3 256000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Lancement rapide d'Adobe Reader.lnk.disabled [2008-5-15 1760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 19:35 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\program files\FeedReader30
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CSmileys
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qsuxhkmpad
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SalatTimes
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"comHost"=3 (0x3)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Freebie Notes"="i:\freebie notes\FreebieNotes.exe"
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\Inventime\\my.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\APPS\\Powercinema\\PowerCinema.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Electronic Arts\\Medal of Honor Airborne\\UnrealEngine3\\Binaries\\MOHA.exe"=
"c:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter 2 Demo SP\\graw2.exe"=
"c:\\Program Files\\Podmailing\\podmailing.exe"=
"c:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Micro Application\\Super Jeux de cartes 4\\Jeu de Belote\\belote365i.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"c:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"c:\\Program Files\\Eidos\\Conflict Denied Ops\\ConflictDeniedOps.exe"=
"c:\\Program Files\\Empire Interactive\\Strangelite\\Starship Troopers\\STGame.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:Port DCOM (135)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [21/01/2008 19:28 21512]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [31/03/2009 14:38 64160]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [11/07/2006 09:30 42392]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [29/12/2008 11:21 114768]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [13/09/2009 14:19 108289]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [29/12/2008 11:21 20560]
R2 BCMNTIO;BCMNTIO;c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [28/12/2006 09:39 3744]
R2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [23/10/2008 15:50 188416]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1029456]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [24/07/2008 19:46 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [26/11/2008 08:23 47640]
R2 MAPMEM;MAPMEM;c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [28/12/2006 09:39 3904]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [02/11/2008 19:54 14336]
R2 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [15/07/2007 03:37 27992]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [11/05/2006 18:33 709760]
S3 BvrpKrnl;BvrpKrnl;c:\program files\WinPhone Ultimate Edition\BVRPKrnl.exe --> c:\program files\WinPhone Ultimate Edition\BVRPKrnl.exe [?]
S3 ewdmaudn;ewdmaudn;\??\c:\docume~1\khaled\LOCALS~1\Temp\ewdmaudn.sys --> c:\docume~1\khaled\LOCALS~1\Temp\ewdmaudn.sys [?]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [21/01/2008 19:28 26248]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [19/06/2008 15:24 576680]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe --> c:\program files\Spyware Doctor\pctsAuxs.exe [?]
S3 sh3bus;SHARP 3G GSM USB Control driver (WDM);c:\windows\system32\DRIVERS\sh3bus.sys --> c:\windows\system32\DRIVERS\sh3bus.sys [?]
S3 sh3mdfl;SHARP 3G GSM USB Modem Filter;c:\windows\system32\DRIVERS\sh3mdfl.sys --> c:\windows\system32\DRIVERS\sh3mdfl.sys [?]
S3 sh3mdm;SHARP 3G GSM USB Modem Driver;c:\windows\system32\DRIVERS\sh3mdm.sys --> c:\windows\system32\DRIVERS\sh3mdm.sys [?]
S3 sh3mgmt;SHARP 3G GSM USB AT Command Drivers (WDM);c:\windows\system32\DRIVERS\sh3mgmt.sys --> c:\windows\system32\DRIVERS\sh3mgmt.sys [?]
S3 sh3obex;SHARP 3G GSM USB OBEX Drivers (WDM);c:\windows\system32\DRIVERS\sh3obex.sys --> c:\windows\system32\DRIVERS\sh3obex.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{f60e3ad9-5525-418c-8225-2c5ebd483e88}]
c:\program files\Nosibay\Bubble Shopping\Deploy.exe /L=1036 /O=NOS001 /I=7495 /X=GBZ-5RH-C6F /M=1 /W=1 /A=1
[HKEY_CURRENT_USER\software\microsoft\active setup\installed components\{f60e3ad9-5525-418c-8225-2c5ebd483e88}]
c:\program files\Nosibay\Bubble Shopping\Deploy.exe /L=1036 /O=NOS001 /I=7495 /X=GBZ-5RH-C6F /M=1 /W=0 /A=1
.
Contenu du dossier 'Tâches planifiées'
2009-09-08 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 12:38]
2009-09-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-09-14 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2009-03-29 13:31]
2009-09-14 c:\windows\Tasks\User_Feed_Synchronization-{7501EF8A-18B3-4A4F-8503-585F59AB7D2A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://google.fr/mStart Page =
hxxp://fr.yahoo.comuInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://fr.search.yahoo.comIE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Télécharger tout avec FlashGet - c:\program files\FlashGet\jc_all.htm
IE: {{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} -
res://c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
TCP: {76DF9A35-25C1-49B5-8D2B-117086602367} = 192.168.1.1
TCP: {ADD2E850-FACF-4F62-9061-49142D6B65E0} = 193.252.19.3,193.252.19.4
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} -
hxxp://www.pixaco.fr/static/download/pixacodndupload.cabDPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cabDPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} -
hxxp://www3.snapfish.fr/SnapfishActivia2.cabDPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} -
hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyB1.dll
BHO-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyB1.dll
Toolbar-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\myBabylon_English\tbmyB1.dll
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - c:\program files\myBabylon_English\tbmyB1.dll
HKCU-Run-Freebie Notes - i:\freebie notes\FreebieNotes.exe
HKLM-Run-NiwradSoft Welcome - c:\windows\NiwradSoft Shell Pack\Tools\NS Welcome.exe
HKLM-Run-Raccourci vers la page des propriétés de High Definition Audio - HDAudPropShortcut.exe
ShellExecuteHooks-{93994DE8-8239-4655-B1D1-5F4E91300429} - (no file)
Notify-AtiExtEvent - (no file)
Notify-dimsntfy - (no file)
MSConfigStartUp-feedreader - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-14 14:03
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MysqlInventime]
"ImagePath"="c:\apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=c:\apps\Inventime\mysql\my.ini MysqlInventime"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1882948580-4280743379-658375066-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1882948580-4280743379-658375066-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f7,ca,27,e7,37,ef,c5,26,00,a9,27,d1,79,59,ee,59,a6,8d,50,0e,2f,dd,fc,
9d,32,60,9c,0e,d5,7a,85,c5,ef,af,21,27,38,85,d1,61,0c,af,03,fa,e5,11,e4,7d,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
[HKEY_USERS\S-1-5-21-1882948580-4280743379-658375066-1006\Software\SecuROM\License information*]
"datasecu"=hex:56,9d,fc,94,b3,48,d9,9c,61,6c,4a,d5,6e,5e,da,fc,9a,b0,00,0b,91,
ff,cc,f7,9d,03,b2,01,e9,79,52,09,cc,d1,86,71,b6,dd,12,b5,fe,7a,2e,46,c8,4d,\
"rkeysecu"=hex:aa,9e,77,7e,a2,b8,62,55,9a,a2,76,e4,c9,c1,53,de
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3D736D2F-74C2-165E-C9EA-622B2C672454}\InProcServer32*]
"oajklcakochbfkjcdeeggiofckammm"=hex:6a,61,69,66,69,69,64,6a,67,66,6b,6a,62,63,
6b,6d,66,66,6e,6b,00,07
"najkncnmcbhinkfndkncccdlfmag"=hex:6a,61,66,66,68,6a,66,68,6a,68,61,6c,66,68,
6b,62,6b,6d,67,6e,00,07
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(856)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(2444)
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\a-squared Anti-Malware\a2service.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\windows\system32\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\fxssvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\apps\ABOARD\AOSD.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\Video\FxSvr2.exe
.
**************************************************************************
.
Heure de fin: 2009-09-14 14:14 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-09-14 12:14
Avant-CF: 2 088 374 272 octets libres
Après-CF: 3 103 940 608 octets libres
Current=2 Default=2 Failed=1 LastKnownGood=6 Sets=1,2,3,4,5,6
473 --- E O F --- 2009-09-14 07:01
Merci pour votre gentillesse .