voici le rapport ComboFix :
ComboFix 09-10-20.03 - crasse 21/10/2009 19:05.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.2047.1304 [GMT 2:00]
Lancé depuis: c:\documents and settings\crasse\Bureau\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\crasse\Application Data\Logs\scns.log
c:\documents and settings\crasse\Application Data\MSA\w2_0.exe
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\Installer\748713eb.msi
c:\windows\Installer\748713ec.msp
c:\windows\Installer\748713ed.msp
c:\windows\Installer\748713ee.msp
c:\windows\Installer\748713ef.msp
c:\windows\Installer\748713f0.msp
c:\windows\Installer\748713f1.msp
c:\windows\Installer\748713f2.msp
c:\windows\Installer\748713f3.msp
c:\windows\Installer\748713f4.msp
c:\windows\Installer\748713f5.msp
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SYSInfo.ocx
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICF
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-21 au 2009-10-21 ))))))))))))))))))))))))))))))))))))
.
2009-10-21 12:44 . 2009-10-21 12:50 -------- d--h--w- c:\windows\$hf_mig$
2009-10-21 10:20 . 2009-10-21 10:20 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-21 10:13 . 2009-10-21 10:13 -------- d-----w- C:\conficker
2009-10-20 16:18 . 2009-10-21 13:46 -------- d-----w- C:\UsbFix
2009-10-20 15:58 . 2009-10-20 15:58 -------- d-----w- c:\program files\AnVir Task Manager
2009-10-20 15:58 . 2009-10-21 16:59 -------- d-----w- c:\documents and settings\crasse\Local Settings\Application Data\AnVir
2009-10-20 15:16 . 2009-09-03 09:17 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-20 03:01 . 2009-10-20 03:01 -------- d-----w- c:\windows\ERUNT
2009-10-20 02:47 . 2009-10-20 02:47 -------- d-----w- C:\VundoFix Backups
2009-10-20 02:45 . 2009-10-20 12:46 -------- d-----w- C:\SDFix
2009-10-20 02:43 . 2009-10-20 02:43 -------- d-----w- c:\documents and settings\crasse\Local Settings\Application Data\Downloaded Installations
2009-10-20 02:34 . 2009-10-20 02:35 -------- d-----w- c:\program files\CCleaner
2009-10-20 01:57 . 2009-10-20 01:57 -------- d-----w- c:\documents and settings\crasse\Application Data\Malwarebytes
2009-10-20 01:57 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-20 01:57 . 2009-10-20 01:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-20 01:57 . 2009-10-20 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-20 01:57 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-20 01:53 . 2009-10-20 01:53 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-10-20 01:41 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-20 01:37 . 2009-10-20 01:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-10-20 01:36 . 2009-10-20 01:36 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-20 01:36 . 2009-10-20 01:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-20 01:36 . 2009-10-20 01:36 -------- d-----w- c:\program files\Lavasoft
2009-10-20 01:11 . 2009-10-21 10:39 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-20 01:11 . 2009-10-21 10:39 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-20 01:10 . 2009-10-21 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-20 01:10 . 2009-10-20 01:10 -------- d-----w- c:\program files\Kaspersky Lab
2009-10-20 01:04 . 2009-10-20 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-13 17:37 . 2009-10-13 17:37 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-13 17:37 . 2009-10-13 17:37 -------- d-----w- c:\windows\system32\AGEIA
2009-10-13 17:36 . 2009-10-13 17:36 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-10-13 17:36 . 2009-10-13 17:36 -------- d-----w- c:\program files\NVIDIA Corporation
2009-10-05 14:25 . 2009-10-05 14:25 -------- d-----w- c:\program files\FileZilla FTP Client
2009-10-01 20:35 . 2009-10-20 15:45 -------- d-----w- c:\program files\Free Download Manager
2009-09-27 16:19 . 2009-09-27 16:19 3674112 ----a-w- c:\windows\system32\nvwssr.dll
2009-09-27 14:43 . 2009-10-20 01:49 -------- d-----w- c:\program files\Google
2009-09-27 14:12 . 2009-09-27 14:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
2009-09-27 14:12 . 2009-09-27 14:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-09-27 14:12 . 2009-09-27 14:12 1604482 ----a-w- c:\windows\system32\nvdata.bin
2009-09-26 15:21 . 2009-10-20 15:49 -------- d-----w- c:\program files\tamasoftware
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-21 17:10 . 2009-09-01 01:28 -------- d-----w- c:\documents and settings\crasse\Application Data\MSA
2009-10-21 17:10 . 2009-08-29 09:39 -------- d-----w- c:\documents and settings\crasse\Application Data\Logs
2009-10-21 14:47 . 2008-06-22 20:43 -------- d-----w- c:\documents and settings\crasse\Application Data\OpenOffice.org2
2009-10-21 13:49 . 2008-04-01 01:04 -------- d-----w- c:\documents and settings\crasse\Application Data\dvdcss
2009-10-21 13:31 . 2009-06-29 00:25 -------- d-----w- c:\documents and settings\crasse\Application Data\.purple
2009-10-20 15:51 . 2009-04-08 20:47 -------- d-----w- c:\program files\Fichiers communs\Stardock
2009-10-20 15:50 . 2008-03-27 15:01 -------- d-----w- c:\program files\Real Alternative
2009-10-20 15:50 . 2008-02-10 20:09 -------- d-----w- c:\program files\QuickTime
2009-10-20 15:48 . 2009-04-15 13:12 -------- d-----w- c:\program files\MKVtoolnix
2009-10-20 15:46 . 2008-08-03 03:22 -------- d-----w- c:\program files\GameSpy Arcade
2009-10-20 15:45 . 2008-07-12 19:00 -------- d-----w- c:\program files\Free FLV Converter
2009-10-20 15:42 . 2008-11-25 14:03 -------- d-----w- c:\program files\AMVApp
2009-10-20 02:39 . 2008-11-29 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-19 22:54 . 2008-11-25 14:16 -------- d-----w- c:\documents and settings\crasse\Application Data\gtk-2.0
2009-10-19 20:31 . 2009-07-13 09:48 -------- d-----w- c:\program files\Avidemux 2.5
2009-10-17 14:41 . 2008-02-07 23:35 59296 ----a-w- c:\documents and settings\crasse\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-13 17:36 . 2008-04-09 15:37 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-10-05 15:30 . 2009-09-04 12:27 -------- d-----w- c:\documents and settings\crasse\Application Data\FileZilla
2009-10-03 11:51 . 2009-09-09 19:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-27 16:19 . 2009-09-27 16:19 3166208 ----a-w- c:\windows\system32\nvwss.dll
2009-09-27 14:12 . 2008-02-07 23:48 490088 ----a-w- c:\windows\system32\nvudisp.exe
2009-09-27 14:12 . 2007-12-05 00:41 888832 ----a-w- c:\windows\system32\nvapi.dll
2009-09-27 14:12 . 2007-12-05 00:41 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-09-27 14:12 . 2007-12-05 00:41 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
2009-09-27 14:12 . 2007-12-05 00:41 2007040 ----a-w- c:\windows\system32\nvcuda.dll
2009-09-27 14:12 . 2007-12-05 00:41 170600 ----a-w- c:\windows\system32\nvcodins.dll
2009-09-27 14:12 . 2007-12-05 00:41 170600 ----a-w- c:\windows\system32\nvcod.dll
2009-09-27 14:12 . 2007-12-05 00:41 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
2009-09-24 07:24 . 2008-02-07 23:48 490088 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-09-21 22:42 . 2009-06-22 13:42 -------- d-----w- c:\documents and settings\crasse\Application Data\Resolume
2009-09-17 13:04 . 2009-09-17 13:04 -------- d-----w- c:\program files\Resolume Avenue 3.1.1
2009-09-11 10:45 . 2009-09-11 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-11 00:58 . 2009-04-16 00:04 -------- d-----w- c:\documents and settings\All Users\Application Data\EmailNotifier
2009-09-09 13:10 . 2009-09-09 13:10 472576 ----a-w- c:\windows\Nvidia Omega Drivers v2.169.21 Uninstall.exe
2009-09-09 13:10 . 2009-09-09 13:10 -------- d-----w- c:\program files\Nvidia Omega Drivers
2009-09-08 14:59 . 2004-08-19 14:10 14336 ----a-w- c:\windows\system32\svchost.exe
2009-09-06 13:42 . 2009-09-06 13:25 -------- d-----w- c:\program files\Ableton
2009-09-06 13:42 . 2009-09-06 13:30 -------- d-----w- c:\documents and settings\crasse\Application Data\Ableton
2009-09-06 13:30 . 2009-09-06 13:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Ableton
2009-09-02 00:57 . 2008-07-21 16:50 290816 ------w- c:\windows\Setup1.exe
2009-09-02 00:57 . 2008-07-21 16:50 74752 ----a-w- c:\windows\ST6UNST.EXE
2009-09-01 10:14 . 2009-09-01 10:14 58520 ----a-w- c:\documents and settings\damien\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-31 11:42 . 2009-08-31 11:42 -------- d-----w- c:\program files\010 Editor v3
2009-08-31 11:35 . 2009-08-31 11:12 -------- d-----w- c:\program files\WinHex
2009-08-31 11:29 . 2009-08-31 11:29 123456 ----a-w- C:\abcdefgh.dat
2009-08-30 13:14 . 2008-08-02 18:30 -------- d-----w- c:\program files\thedraw
2009-08-30 11:31 . 2009-08-30 11:31 -------- d-----w- c:\documents and settings\damien\Application Data\EmailNotifier
2009-08-30 11:30 . 2009-08-30 11:30 -------- d-----w- c:\documents and settings\damien\Application Data\Nero
2009-08-30 11:30 . 2009-08-30 11:30 -------- d-----w- c:\documents and settings\damien\Application Data\EPSON
2009-08-14 11:36 . 2009-08-14 11:36 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-08-08 17:18 . 2009-04-13 11:32 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-08 17:18 . 2009-08-08 17:18 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-26 17:13 . 2009-07-26 17:13 1056 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-26 17:13 . 2009-07-26 17:13 88 --sh--r- c:\windows\system32\14F28D0EB6.sys
2006-05-03 09:06 . 2008-09-27 14:45 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2008-09-27 14:45 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2008-09-27 14:45 216064 --sh--r- c:\windows\system32\nbDX.dll
.
------- Sigcheck -------
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3qfe\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3gdr\tcpip.sys
[-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2gdr\tcpip.sys
[-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2qfe\tcpip.sys
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2004-08-03 . 7399D854596BFEFEED6B60879F28CE07 . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\tcpip.sys
c:\windows\system32\drivers\beep.sys ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2008-03-20 216520]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-04 486856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"AnVir Task Manager"="c:\program files\AnVir Task Manager\AnVir.exe" [2009-10-14 3107040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 144784]
"WinampAgent"="c:\program files\Winamp\Winampa.exe" [2008-01-15 37376]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-03-17 102400]
"NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-22 385024]
"Dell MFP Color Laser Printer 3115cn Launcher"="c:\program files\Dell Printers\Dell MFP Color Laser Printer 3115cn\Address Book Editor\Launcher.exe" [2006-08-10 389120]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\Dell Printers\paperport\pptd40nt.exe" [2006-06-30 36864]
"IndexSearch"="c:\program files\Dell Printers\paperport\IndexSearch.exe" [2006-06-30 40960]
"DLPSP"="c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE" [2006-02-22 192512]
"BootSkin Startup Jobs"="c:\program files\BootSkin\BootSkin.exe" [2004-04-26 270336]
"LogonStudio"="c:\program files\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"C0100Mon.exe"="c:\windows\C0100Mon.exe" [2007-04-30 32768]
"JulaPan"="JulaPan.Exe" - c:\windows\system32\JulaPan.exe [2006-09-05 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\crasse\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-4-8 576000]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
Psi.lnk - c:\program files\Psi\psi.exe [2008-7-26 9128960]
c:\documents and settings\All Users\Application Data\Microsoft\Shortcuts\
SnagIt 8.lnk - c:\program files\TechSmith\SnagIt 8\SnagIt32.exe [2007-5-16 6395464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=ma_cmidn.dll
"midi4"=ma_cmidn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
"c:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15232:TCP"= 15232:TCP:BitComet 15232 TCP
"15232:UDP"= 15232:UDP:BitComet 15232 UDP
"5891:TCP"= 5891:TCP:fauutmv
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15/12/2008 20:41 33808]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [20/10/2009 03:41 64288]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [17/11/2008 21:50 96016]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [17/11/2008 21:51 41744]
R2 DLSDB;Dell Printer Status Database;c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\dlsdbnt.exe [20/01/2009 18:06 135168]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [10/08/2008 01:25 33792]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\drivers\vrtaucbl.sys [22/05/2008 21:16 52864]
R3 JULA_01;Service for Juli@ 1;c:\windows\system32\drivers\JulaWdm.sys [05/09/2006 11:08 22912]
R3 JULA_AA;Service for Juli@ Audio Driver (EWDM);c:\windows\system32\drivers\Jula.sys [05/09/2006 11:08 29568]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/05/2009 17:46 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 20:59 19472]
S0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys --> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
S2 drpzrvb;Server Monitor;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 16:10 14336]
S2 gupdate1ca5125d7053344;Google Update Service (gupdate1ca5125d7053344);c:\program files\Google\Update\GoogleUpdate.exe [20/10/2009 03:37 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 13:17 1170768]
S2 vuaisqbx;Installer Manager;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 16:10 14336]
S2 yfmxpeg;Helper System;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 16:10 14336]
S3 C0100Afx;Provides a software interface to control audio effects of VC0100 camera.;c:\windows\system32\drivers\C0100Afx.sys [25/03/2008 18:21 141376]
S3 C0100Aud;Provides a software interface to control noise cancellation of VC0100 camera.;c:\windows\system32\drivers\C0100Aud.sys [25/03/2008 18:21 93440]
S3 C0100Aul;Provides a software interface to control audio formats of VC0100 camera.;c:\windows\system32\drivers\C0100Aul.sys [25/03/2008 18:21 5120]
S3 C0100Dev;Creative Camera VC0100 Driver;c:\windows\system32\drivers\C0100Dev.sys [25/03/2008 18:21 239936]
S3 C0100Vfx;Creative Camera VC0100 Video VFX Driver;c:\windows\system32\drivers\C0100Vfx.sys [25/03/2008 18:21 7168]
S3 sonydcam;Caméra de bureau 1394 générique;c:\windows\system32\drivers\sonydcam.sys [04/08/2004 01:09 25472]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [10/08/2008 03:01 16896]
S3 USB22LDR;M-Audio USB MIDISPORT 2x2 Loader;c:\windows\system32\drivers\usb22ldr.sys [26/05/2009 12:22 20936]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
drpzrvb
yfmxpeg
vuaisqbx
.
Contenu du dossier 'Tâches planifiées'
2009-10-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 01:41]
2009-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-20 01:36]
2009-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-20 01:36]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
FF - ProfilePath - c:\documents and settings\crasse\Application Data\Mozilla\Firefox\Profiles\40msg3rz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe
AddRemove-_{05D60953-9012-44DF-A1A6-9DD97AD6580A} - c:\program files\Corel\Corel Painter X\MSILauncher {05D60953-9012-44DF-A1A6-9DD97AD6580A}
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-21 19:14
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\docume~1\crasse\LOCALS~1\Temp\RGIB.tmp 7136 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\drpzrvb]
"ServiceDll"="c:\windows\system32\evmxi.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vuaisqbx]
"ServiceDll"="c:\windows\system32\evmxi.dll"
--
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\yfmxpeg]
"ServiceDll"="c:\windows\system32\evmxi.dll"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:f1,ce,b4,b3,7c,da,05,5f,db,83,75,a4,62,37,d1,1e,bf,1f,e0,75,0b,
49,26,a7,6f,66,66,51,e5,95,3e,f8,b8,7a,5b,81,8c,97,e0,2e,54,87,aa,52,d4,ff,\
[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2454940:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{7704DBB6-C611-0275-7566-26C6E73BA941}\Version 1.1]
@DACL=
"dat"="806585365:{A4F343CE-062D-1C6E-9BE9-0B5543BA1465}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2454961:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\{05B78A41-7B71-7355-3CC1-BB00BB7FC8DC}*\Install*Loc\xga-1\dat]
@DACL=
"default"="516231591:{7C3DE2CC-C448-5F9A-C45D-F4FF82E7DECE}"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{7704DBB6-C611-0275-7566-26C6E73BA941}\Version 3.x]
@DACL=
"dat"="1767914624:{77163B4A-3678-4C3F-D9BD-A0F72EABCE92}"
[HKEY_LOCAL_MACHINE\software\Microsoft\WinXGA*\Providers*\{D41D8CD9-8F00-B204-E980-0998ECF8427E}\Current*Set\xga-1\ver]
@DACL=
"KnownSvcs"="923715416:{6E1D0859-42E4-D0AA-9B64-13BD0A153B94}"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:f1,ce,b4,b3,7c,da,05,5f,db,83,75,a4,62,37,d1,1e,bf,1f,e0,75,0b,
49,26,a7,6f,66,66,51,e5,95,3e,f8,a2,22,fe,36,1a,ca,07,1c,54,87,aa,52,d4,ff,\
[HKEY_LOCAL_MACHINE\software\XBMga*\UUIDs\{A9D7D4CE-55BE-580F-81BE-24D727DCDD92}\xga-1\Install*Loc]
@DACL=
"{19620715-0001-1211-574574-30001}"="234522252:{14772076-26E2-FB24-3F5C-F66E20654106}"
[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="8:{19C42D30-D844-8A07-12A4-E783E7D228F7}"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1608)
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\system32\PSIService.exe
c:\program files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
c:\windows\system32\wdfmgr.exe
c:\program files\RealVNC\VNC4\WinVNC4.exe
c:\program files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
c:\windows\system32\CNAB4RPK.EXE
c:\combofix\CF14525.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.BIN
c:\program files\TechSmith\SnagIt 8\TSCHelp.exe
c:\program files\TechSmith\SnagIt 8\SnagPriv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Java\jre1.6.0_04\bin\jucheck.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Heure de fin: 2009-10-21 19:24 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-21 17:24
Avant-CF: 5 538 971 648 octets libres
Après-CF: 5 417 349 120 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 7B9B495F15B79E25C0E3A52337FBAEE4