Se connecter / S'enregistrer
Votre question
Fermé

Rapport Hijack - Mozilla Firefox

Tags :
  • Fenêtre intempestive
  • Sécurité
Dernière réponse : dans Sécurité et virus
14 Octobre 2008 15:01:42

Bonjours, j'ai des fenêtre intempestive dans mozilla firefox, voici le rapport Hijack :

Citation :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:01:16, on 14/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\qzoturmb\azinozyd.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\ManyCam 2.3\ManyCam.exe
C:\WINDOWS\system32\byjudwji.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program Files\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter\WLANUTL.exe
C:\Program Files\WinZip 8.1 Fr\WZQKPICK.EXE
C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Security Suite Pro\feedback.exe" /dump:o s_startup
O4 - HKLM\..\Run: [TrayServer] D:\Program Files\MAGIX\Video_deluxe_2008_PLUS\TrayServer.exe
O4 - HKLM\..\Run: [Fast SysTray] C:\Program Files\FastSysTray\FastsysTray.exe
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [e490a14e] rundll32.exe "C:\WINDOWS\system32\dkvnqjar.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [iaieq] c:\documents and settings\tanguy\local settings\application data\iaieq.exe iaieq
O4 - HKCU\..\Run: [Linkodotron] C:\PROGRA~1\LINKOD~1\LINKOD~1.EXE
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ManyCam] "C:\Program Files\ManyCam 2.3\ManyCam.exe"
O4 - HKCU\..\Run: [strapp] C:\WINDOWS\system32\byjudwji.exe
O4 - HKLM\..\Policies\Explorer\Run: [BofVZgrZx7] C:\Documents and Settings\All Users\Application Data\qzoturmb\azinozyd.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: SnagIt 8.lnk = C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip 8.1 Fr\WZQKPICK.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Réglage rapide de Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - http://messenger.zone.msn.com/binary/MJSS.cab69309.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown....
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Cont...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/fl...
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll yhdgty.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - D:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: olMntrService - Olivetti - C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe
O23 - Service: Pi3Web - Unknown owner - c:\Pi3Web\bin\Pi3Srv32.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O24 - Desktop Component 0: (no name) - http://www.fond-ecran.net/fonds/carmenelectra_002.jpg
O24 - Desktop Component 1: (no name) - http://www.wallpapers-zone.com/wallpapers/erotique/fond...

--
End of file - 11491 bytes

Autres pages sur : rapport hijack mozilla firefox

14 Octobre 2008 16:22:31

Et voici le rapport de ComboFix :

Citation :
ComboFix 08-10-12.01 - Tanguy 2008-10-14 15:59:47.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.418 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Tanguy\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\Tanguy\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
* Resident AV is active

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Conditions générales.url
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Confidentialité.url
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Désinstaller.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\WebMediaPlayer.lnk
C:\Documents and Settings\Tanguy\Favoris\Cheap Pharmacy Online.url
C:\Documents and Settings\Tanguy\Favoris\Search Online.url
C:\Documents and Settings\Tanguy\Favoris\VIP Casino.url
C:\Documents and Settings\Tanguy\Local Settings\Application Data\iaieq.dat
C:\Documents and Settings\Tanguy\Local Settings\Application Data\iaieq.exe
C:\Documents and Settings\Tanguy\Local Settings\Application Data\iaieq_nav.dat
C:\Documents and Settings\Tanguy\Local Settings\Application Data\iaieq_navps.dat
C:\Documents and Settings\Tanguy\Menu Démarrer\Cheap Pharmacy Online.url
C:\Documents and Settings\Tanguy\Menu Démarrer\Search Online.url
C:\Documents and Settings\Tanguy\Menu Démarrer\VIP Casino.url
C:\resycled
C:\resycled\boot.com
C:\WINDOWS\BMe7a392d2.txt
C:\WINDOWS\k.txt
C:\WINDOWS\system32\abdvalao.dll
C:\WINDOWS\system32\aekhqmry.dll
C:\WINDOWS\system32\artelpor.ini
C:\WINDOWS\system32\bldkjx.dll
C:\WINDOWS\system32\brastk.exe
C:\WINDOWS\system32\c.ico
C:\WINDOWS\system32\cbXOFVlj.dll
C:\WINDOWS\system32\cgxxrruw.dll
C:\WINDOWS\system32\crnrhrks.dll
C:\WINDOWS\system32\dedNoqss.ini
C:\WINDOWS\system32\dedNoqss.ini2
C:\WINDOWS\system32\dftvfghf.dll
C:\WINDOWS\system32\dkvnqjar.dll
C:\WINDOWS\system32\docqrvrg.dll
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\ehjscvcg.dll
C:\WINDOWS\system32\ejqmqwlb.dll
C:\WINDOWS\system32\froutd.dll
C:\WINDOWS\system32\gdjnpf.dll
C:\WINDOWS\system32\iIBrrsPi.dll
C:\WINDOWS\system32\iifdebYp.dll
C:\WINDOWS\system32\ipciuq.dll
C:\WINDOWS\system32\iPsrrBIi.ini
C:\WINDOWS\system32\iPsrrBIi.ini2
C:\WINDOWS\system32\jrwqcmuj.ini
C:\WINDOWS\system32\m.ico
C:\WINDOWS\system32\movkivub.ini
C:\WINDOWS\system32\msysamd32.dll
C:\WINDOWS\system32\mumdtljk.ini
C:\WINDOWS\system32\ncebcf.dll
C:\WINDOWS\system32\ndtifypv.ini
C:\WINDOWS\system32\niboiy.dll
C:\WINDOWS\system32\oorcbyso.ini
C:\WINDOWS\system32\osbnkv.dll
C:\WINDOWS\system32\osybcroo.dll
C:\WINDOWS\system32\pmlhowqd.dll
C:\WINDOWS\system32\rajqnvkd.ini
C:\WINDOWS\system32\ropletra.dll
C:\WINDOWS\system32\s.ico
C:\WINDOWS\system32\sgsqwdmy.ini
C:\WINDOWS\system32\soiqhf.dll
C:\WINDOWS\system32\stkvvonk.dll
C:\WINDOWS\system32\tewwlevg.ini
C:\WINDOWS\system32\urftjxug.ini
C:\WINDOWS\system32\vmdnriwu.ini
C:\WINDOWS\system32\vpyfitdn.dll
C:\WINDOWS\system32\vupujs.dll
C:\WINDOWS\system32\winhoq32.dll
C:\WINDOWS\system32\winmbj32.dll
C:\WINDOWS\system32\wqkufxiq.dll
C:\WINDOWS\system32\wxstlasc.dll
C:\WINDOWS\system32\yhdgty.dll
C:\WINDOWS\system32\zhcrow.dll
D:\Autorun.inf
D:\install.exe
G:\autorun.inf

.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-14 au 2008-10-14 ))))))))))))))))))))))))))))))))))))
.

2008-10-14 06:38 . 2008-06-30 17:16 234,640 --a------ C:\WINDOWS\system32\drivers\afwcore.sys
2008-10-12 16:34 . 2008-10-12 16:34 81,920 --a------ C:\WINDOWS\system32\byjudwji.exe
2008-10-12 16:02 . 2008-10-12 16:02 81,920 --a------ C:\WINDOWS\system32\gbijidyl.exe
2008-10-12 16:02 . 2008-10-12 16:36 152 --a------ C:\Documents and Settings\Tanguy\delself.bat
2008-10-12 00:43 . 2008-10-12 00:44 <REP> d-------- C:\Program Files\AutoIt3
2008-10-11 22:41 . 2008-10-11 22:41 81,920 --a------ C:\WINDOWS\system32\gvkxklkl.exe
2008-10-11 22:40 . 2008-10-11 22:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\qzoturmb
2008-10-11 22:17 . 2008-10-11 22:17 72 --a------ C:\WINDOWS\SCapPro.INI
2008-10-11 21:35 . 2008-10-11 21:35 <REP> d-------- C:\Documents and Settings\Tanguy\Application Data\ACASystems
2008-10-11 21:35 . 2008-10-11 21:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ACASystems
2008-10-11 14:31 . 2008-10-11 22:51 <REP> d-------- C:\Program Files\Game Cam V2
2008-10-11 14:05 . 2008-10-14 14:46 <REP> d-------- C:\Fraps
2008-10-10 21:57 . 2008-10-10 21:57 <REP> d-------- C:\Program Files\Trend Micro
2008-10-10 18:40 . 2004-08-04 00:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-10-10 18:40 . 2004-08-04 00:45 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-10-10 18:40 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-10-10 18:40 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-10-10 18:36 . 2008-10-10 18:36 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-10 18:36 . 2008-10-10 18:36 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-10-10 18:35 . 2004-08-04 00:54 21,504 --a------ C:\WINDOWS\system32\drivers\hidserv.dll
2008-10-10 18:28 . 2007-08-21 10:12 21,760 --a------ C:\WINDOWS\system32\drivers\point32.sys
2008-10-10 18:27 . 2008-10-10 18:27 <REP> d-------- C:\Program Files\Microsoft IntelliPoint
2008-10-10 18:24 . 2007-08-31 21:13 1,421,736 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-10-10 18:24 . 2007-08-31 21:15 18,856 --a------ C:\WINDOWS\system32\drivers\nuidfltr.sys
2008-10-10 18:23 . 2008-10-10 18:24 <REP> d-------- C:\Program Files\Microsoft IntelliType Pro
2008-10-10 16:32 . 2008-10-10 16:32 88,064 --a------ C:\WINDOWS\system32\kxjoayqn.dll
2008-10-05 07:36 . 2008-10-05 07:37 <REP> d---s---- C:\Documents and Settings\Benoit\Mes documents
2008-10-05 06:28 . 2008-10-05 06:28 <REP> d-------- C:\Program Files\iPod
2008-10-05 06:28 . 2008-10-05 06:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 05:58 . 2008-10-05 06:25 <REP> d-------- C:\Program Files\QuickTime
2008-10-05 05:03 . 2008-10-05 05:03 0 --a------ C:\WINDOWS\BMe7a392d2.xml
2008-10-05 03:14 . 2008-10-05 03:14 98 --a------ C:\WINDOWS\crocpix1.ini
2008-10-05 03:14 . 2008-10-05 03:14 0 --a------ C:\WINDOWS\windmcroc1.ini
2008-10-05 01:53 . 2008-10-05 01:53 <REP> d-------- C:\Documents and Settings\Tanguy\Application Data\TechSmith
2008-10-05 00:38 . 2008-10-05 00:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-10-05 00:37 . 2008-10-05 00:37 <REP> d-------- C:\Program Files\TechSmith
2008-10-04 18:45 . 2008-10-04 18:45 <REP> d-------- C:\Program Files\AMD
2008-10-04 18:45 . 2007-06-29 14:47 34,304 --a------ C:\WINDOWS\system32\drivers\AmdLLD.sys
2008-10-03 01:46 . 2008-10-03 01:46 81,920 --a------ C:\WINDOWS\system32\frapsvid.dll
2008-09-23 07:38 . 2008-09-23 07:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Video Converter Studio
2008-09-23 07:37 . 2008-09-23 07:37 <REP> d-------- C:\Program Files\Apowersoft
2008-09-23 07:37 . 2008-09-23 07:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Tiger Install

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-14 14:05 4,479,008 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-14 14:05 163,534,368 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-14 14:04 424,064 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-14 14:04 2,194,376 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-14 12:47 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-14 06:04 --------- d-----w C:\Program Files\eMule
2008-10-14 04:36 --------- d--h--w C:\Program Files\Zero G Registry
2008-10-14 04:36 --------- d-----w C:\Program Files\WinZip 8.1 Fr
2008-10-14 04:36 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-10-14 04:36 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-10-14 04:36 --------- d-----w C:\Program Files\VirtualDJ
2008-10-14 04:36 --------- d-----w C:\Program Files\VDMSound
2008-10-14 04:36 --------- d-----w C:\Program Files\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter
2008-10-14 04:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-10-14 04:34 --------- d-----w C:\Documents and Settings\Tanguy\Application Data\VoipDiscount
2008-10-11 13:33 --------- d-----w C:\Program Files\Conjugaison
2008-10-05 04:29 --------- d-----w C:\Program Files\iTunes
2008-10-05 04:25 --------- d-----w C:\Program Files\Fichiers communs\Apple
2008-10-05 03:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-05 03:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-10-05 02:48 --------- d-----w C:\Program Files\ManyCam 2.3
2008-10-05 01:31 --------- d-----w C:\Program Files\ATI Technologies
2008-10-05 01:20 --------- d-----w C:\Program Files\Bonjour
2008-09-29 18:51 --------- d-----w C:\Program Files\Google
2008-09-22 16:18 360,320 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-09-22 16:18 360,320 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-09-10 18:31 --------- d-----w C:\Program Files\Apple Software Update
2008-09-03 04:38 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-02 00:28 64,801 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-09-02 00:28 6,116 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-08-31 13:32 --------- d-----w C:\Documents and Settings\Tanguy\Application Data\DeskSoft
2008-08-31 13:10 166,912 ----a-w C:\WINDOWS\novc.exe
2008-08-27 23:11 --------- d-----w C:\Documents and Settings\Tanguy\Application Data\vlc
2008-08-27 14:32 --------- d-----w C:\Documents and Settings\Tanguy\Application Data\com.uplayme.airclient.9B472EFF9A3BAE26509EDFEDD3D8214233BACDB1.1
2008-08-27 14:31 --------- d-----w C:\Program Files\Fichiers communs\Adobe AIR
2008-08-27 13:21 --------- d-----w C:\Program Files\Unlocker
2008-08-26 23:46 --------- d-----w C:\Program Files\RocketDock
2008-07-19 16:20 22,328 ----a-w C:\Documents and Settings\Tanguy\Application Data\PnkBstrK.sys
2007-12-09 03:13 88 --sh--r C:\WINDOWS\system32\C7314227B7.sys
.

------- Sigcheck -------

2007-06-27 16:14 824320 7201d19b81883b57d5ffe8ebb5a83e8b C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 11:49 825344 2dd1b0f579c80562edcb8848ff7ea9f6 C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-11 01:22 825344 871ae10d6ae8877e9636ae5017953d52 C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-07 03:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 14:34 827392 5a0093f59b505c008ed0cee615563c72 C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-23 09:19 827392 78d3d2b0be6ad3e6d82ccb115cf74310 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 17:40 827904 52589bae67dd9859724287372668690b C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2004-08-04 02:54 660480 58fe94ef42e074f4cad8bf02e70e6478 C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
2007-08-22 14:57 669696 4f6a45b54d26708e2c2bf2c43d83edea C:\WINDOWS\ie7\wininet.dll
2007-08-13 19:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
2007-08-20 11:59 824832 f6dfceed3a7aa4c9eeb966d3f1adc70a C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
2007-10-11 01:49 824832 bc5119c53bdd48dabc628d448a3bdccb C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
2007-12-07 04:08 824832 4fc90bece54fac81b0090b94e27bfb6b C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 14:58 826368 8e027981ddffa690d456fe18b37415a0 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
2008-04-23 06:16 826368 02d6aabd5f5a32c61478b5cdfe50e4a8 C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
2007-08-20 11:59 824832 f6dfceed3a7aa4c9eeb966d3f1adc70a C:\WINDOWS\SoftwareDistribution\Download\36e241a7c6880a9ebdbe78b98d36306d\SP2GDR\wininet.dll
2007-08-20 11:49 825344 2dd1b0f579c80562edcb8848ff7ea9f6 C:\WINDOWS\SoftwareDistribution\Download\36e241a7c6880a9ebdbe78b98d36306d\SP2QFE\wininet.dll
2008-06-23 18:28 817152 5f8a137bed66cb1150f139e4e6a6355c C:\WINDOWS\system32\wininet.dll
2008-06-23 18:28 817152 5f8a137bed66cb1150f139e4e6a6355c C:\WINDOWS\system32\dllcache\wininet.dll

2006-04-20 14:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 12:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 13:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 13:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2004-08-04 01:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2007-11-10 16:45 359808 b4e29943b4b04bd5e7381546848e6669 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 19:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2008-09-22 18:18 360320 073941d59ae065910064b728dee981ee C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-09-22 18:18 360320 073941d59ae065910064b728dee981ee C:\WINDOWS\system32\drivers\TCPIP.SYS

2007-06-13 15:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\explorer.exe
2007-06-13 15:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 02:54 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 15:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1FEC19E-F893-4b56-9CC7-CFF71BB34693}]
2008-10-10 16:32 88064 --a------ C:\WINDOWS\system32\kxjoayqn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"DAEMON Tools Lite"="D:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-06-25 1209584]
"RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-19 630784]
"ManyCam"="C:\Program Files\ManyCam 2.3\ManyCam.exe" [2008-08-19 1725736]
"strapp"="C:\WINDOWS\system32\byjudwji.exe" [2008-10-12 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-05 185896]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"OutpostMonitor"="C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-07-15 1207128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"BofVZgrZx7"="C:\Documents and Settings\All Users\Application Data\qzoturmb\azinozyd.exe" [2008-10-11 53248]

C:\Documents and Settings\Tanguy\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 180224]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-05-21 155648]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-05-16 6395464]
Utilitaire r‚seau pour SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\Utilitaire r‚seau pour SAGEM Wi-Fi 11g USB adapter\WLANUTL.exe [2007-10-10 925696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip 8.1 Fr\WZQKPICK.EXE [2002-03-29 106561]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\Fichiers communs\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"=
"C:\\Program Files\\adslTV\\adsltv.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Documents and Settings\\Tanguy\\Application Data\\Weezo\\MySQL\\bin\\mysqld.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"D:\\Program Files\\Sierra Entertainment\\Empire Earth III\\EE3.exe"=
"D:\\Program Files\\Sierra\\Empire Earth II\\EE2.exe"=
"D:\\Sierra\\Empire Earth - The Art of Conquest\\EE-AOC.exe"=
"D:\\Sierra\\Empire Earth\\Empire Earth.exe"=
"D:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"C:\\Program Files\\DsNET Corp\\aTube Catcher 1.0\\smh.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1442:TCP"= 1442:TCP:Emule TCP
"2589:UDP"= 2589:UDP:Emule UPD

R1 SandBox;SandBox;C:\WINDOWS\system32\DRIVERS\SandBox.sys [2008-07-11 673920]
R2 ithsgt;ithsgt;C:\WINDOWS\system32\DRIVERS\ithsgt.sys [2008-05-07 162432]
R2 lilsgt;lilsgt;C:\WINDOWS\system32\DRIVERS\lilsgt.sys [2008-05-07 12032]
R2 litsgt;litsgt;C:\WINDOWS\system32\DRIVERS\litsgt.sys [2007-10-12 137344]
R2 olMntrService;olMntrService;C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe [2006-07-24 86016]
R2 tansgt;tansgt;C:\WINDOWS\system32\DRIVERS\tansgt.sys [2007-10-12 12032]
R3 afw;Agnitum firewall driver;C:\WINDOWS\system32\DRIVERS\afw.sys [2008-06-30 30864]
R3 afwcore;afwcore;C:\WINDOWS\system32\drivers\afwcore.sys [2008-06-30 234640]
R3 ASWFilt;ASWFilt;C:\WINDOWS\system32\Filt\ASWFilt.dll [2008-07-11 33408]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\WINDOWS\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 Tetri5;Tetri5 driver;C:\WINDOWS\system32\Drivers\Tetri5.sys [2008-05-14 53088]
R3 Tetris;Tetris driver;C:\WINDOWS\system32\Drivers\Tetris.sys [2008-05-14 48928]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
R3 VBEngNT;VBEngNT;C:\WINDOWS\system32\DRIVERS\VBEngNT.sys [2008-06-04 1072722]
R3 VBFilt;VBFilt;C:\WINDOWS\system32\Filt\VBFilt.dll [2008-07-11 158816]
S2 acssrv;Agnitum Client Security Service;C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2008-07-15 1570136]
S2 Pi3Web;Pi3Web;c:\Pi3Web\bin\Pi3Srv32.exe [ ]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;D:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [ ]
S3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [ ]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2006-01-18 402432]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS [ ]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96b8e3ae-cd03-11dc-9f3f-0001388d0024}]
\Shell\AutoRun\command - K:\start.exe
\Shell\iledefrance\command - K:\start.exe
.
Contenu du dossier 'Tâches planifiées'

2008-10-08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-10-14 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
- - - - ORPHELINS SUPPRIMES - - - -

BHO-{024B2482-4F48-471A-9A2F-2633D4CC1968} - (no file)
BHO-{0870315C-20F4-48EC-B9B3-C9AE99C3BBAC} - (no file)
BHO-{1F88A6F5-908C-4C28-9A81-829953C5F5C5} - (no file)
BHO-{20c98689-c73b-4a23-ab27-e3c455980eaa} - (no file)
BHO-{2BC764F6-F1D5-402E-93CC-57AFB11E8682} - (no file)
BHO-{36CE344C-88AD-445C-8C33-14BBB4EA561A} - (no file)
BHO-{389A058E-FBD5-4336-ACF9-172CFFF0FB8F} - C:\WINDOWS\system32\ssqoNded.dll
BHO-{3CC538F1-5724-4A3D-91F7-6878E490E765} - (no file)
BHO-{4781DBCA-E59D-48A3-96F0-99729263E2A6} - (no file)
BHO-{4B0FAF5A-67C4-4625-AE07-B0DBADA16EBF} - (no file)
BHO-{53915D25-500E-4785-A2CC-7FB3FD4059F4} - C:\WINDOWS\system32\iIBrrsPi.dll
BHO-{5CBD4DAB-C80E-4FE2-A926-71F604BA6606} - (no file)
BHO-{624A02DB-6498-463E-951F-AE5C1A724507} - (no file)
BHO-{698EFD28-BC86-4EAF-8736-FFD3C335C331} - (no file)
BHO-{8EF7E888-280D-418C-AD68-0C4F4AD1C971} - (no file)
BHO-{903C377B-E501-4A35-A6B2-1E3994711EA1} - C:\WINDOWS\system32\iifdebYp.dll
BHO-{908F6967-958F-4384-949E-2A3C4EBEE804} - (no file)
BHO-{DD553424-366F-41EE-8FD4-80A71913F6E7} - (no file)
BHO-{E025BA7F-839F-44B9-A9E2-7C4E9A06AB0F} - (no file)
BHO-{e86b5984-ceef-418b-8b99-95a4535e39f3} - C:\WINDOWS\system32\yhdgty.dll
BHO-{f3aae4aa-8100-4970-9016-c3935f946a21} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-Linkodotron - C:\PROGRA~1\LINKOD~1\LINKOD~1.EXE
HKLM-Run-TrayServer - D:\Program Files\MAGIX\Video_deluxe_2008_PLUS\TrayServer.exe
HKLM-Run-Fast SysTray - C:\Program Files\FastSysTray\FastsysTray.exe
HKLM-Run-e490a14e - C:\WINDOWS\system32\dkvnqjar.dll
HKLM-Run-Kupdate - (no file)
ShellExecuteHooks-{903C377B-E501-4A35-A6B2-1E3994711EA1} - C:\WINDOWS\system32\iifdebYp.dll
Notify-iifdebYp - (no file)
Notify-winhoq32 - (no file)


.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Tanguy\Application Data\Mozilla\Firefox\Profiles\4jvf9uk2.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Anti-Leech\ALNN\npalnn.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-14 16:06:23
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...


C:\Documents and Settings\Tanguy\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 855 bytes hidden from API

Scan terminé avec succès
Fichiers cachés: 1

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

PROCESSUS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter\WLANUTL.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-10-14 16:11:38 - La machine a redémarré [Tanguy]
ComboFix-quarantined-files.txt 2008-10-14 14:11:32

Avant-CF: 13 858 942 976 octets libres
Après-CF: 13,812,580,352 octets libres

392 --- E O F --- 2008-09-11 05:18:17
a b 8 Sécurité
14 Octobre 2008 17:56:56

Double topic : je lock
Tom's guide dans le monde
  • Allemagne
  • Italie
  • Irlande
  • Royaume Uni
  • Etats Unis
Suivre Tom's Guide
Inscrivez-vous à la Newsletter
  • ajouter à twitter
  • ajouter à facebook
  • ajouter un flux RSS