Ok Ok tiens voila le log combofix:
ComboFix 08-04-10.9 - juju 2008-04-11 14:31:42.1 - NTFSx86
Endroit: C:\Documents and Settings\juju\Bureau\ComboFix.exe
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\floriane\Application Data\DriveCleaner 2006 Free
C:\Documents and Settings\floriane\Application Data\DriveCleaner 2006 Free\Logs\update.log
C:\Documents and Settings\floriane\Application Data\HbTools
C:\Documents and Settings\floriane\Application Data\HbTools\HbTools.log
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\1.sdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\803618.sdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\ASPL1.dat
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\domains.txt
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\hstat\3530.dat
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\1000003674
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\1000025540
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\11208
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\12776
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\186757
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\26664
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\28437
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34123
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34237
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\42013
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\4382
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\705140
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\dynamic\ustat\3530.dat
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\ads.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\btntrans.idx
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\btntrans1.dat
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\business_promo.htm
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\buttondir.txt
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\components.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_buttons_other.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\d_icons_weather.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\default.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_511745-514279.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz1.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz10.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz11.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz12.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz13.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz14.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz15.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz16.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz17.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz18.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz19.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz2.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz20.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz3.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz4.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz5.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz6.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz7.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz8.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_bidz9.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_categorize.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_comparison.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_em_PROFL_CA_flow_b_IEB.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_explorer-people.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_favorites.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_Games.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hide.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_Hotmail.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_hsskin.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemster.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemsterie.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_jobsearch.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_Mails.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_new.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_premium.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_reun.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_ringtones.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchfor.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_searchgo.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_weather.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Default_yellowpages.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\email-t1-bg.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium-hotbar-premium.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\hotbar-premium.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\hotbar_promo.htm
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\icons2.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\keywords.idx
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\keywords1.dat
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\layout.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\linkpathlegal.txt
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\progress.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\s_icons_buttons.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\sales_buttons.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\t2_bg.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\theweb.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\top7.cdf
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\Top7_theweb.mnu
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\1\tsd_bg.res
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\ads.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\business_promo.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\buttondir.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\default.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\hotbar-premium.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\icons2.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\keywords.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\keywords1.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\layout.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\progress.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\samplegroups2.txt
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\samplegroups2.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\t2_bg.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\top7.xip
C:\Documents and Settings\floriane\Application Data\HbTools\v3.0\HbTools\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\floriane\Application Data\HbTools_Icons
C:\Documents and Settings\floriane\Application Data\HbTools_Icons\games2.ico
C:\Documents and Settings\floriane\Application Data\HbTools_Icons\Registryrepair.ico
C:\Documents and Settings\floriane\Application Data\HbTools_Icons\wallpapere1.ico
C:\Documents and Settings\floriane\Bureau\Free PC Wallpapers.lnk
C:\Documents and Settings\juju\Application Data\DriveCleaner 2006 Free
C:\Documents and Settings\juju\Application Data\DriveCleaner 2006 Free\Logs\update.log
C:\Documents and Settings\maman\Application Data\DriveCleaner 2006 Free
C:\Documents and Settings\maman\Application Data\DriveCleaner 2006 Free\Logs\update.log
C:\Documents and Settings\maman\err.log
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-11 to 2008-04-11 ))))))))))))))))))))))))))))))))))))
.
2008-04-11 00:05 . 2008-04-11 00:07 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-04-10 23:42 . 2008-04-10 23:42 <REP> d-------- C:\Program Files\RamBoost XP
2008-04-10 16:10 . 2008-04-10 16:10 <REP> d-------- C:\Documents and Settings\maman\Application Data\Grisoft
2008-04-10 15:57 . 2008-04-10 15:58 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-10 15:57 . 2008-04-10 16:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-10 15:10 . 2008-04-11 12:03 <REP> d-------- C:\Documents and Settings\juju\Application Data\LimeWire
2008-04-10 14:47 . 2008-04-10 14:47 <REP> d-------- C:\Documents and Settings\juju\Application Data\Grisoft
2008-04-10 14:47 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-10 14:46 . 2008-04-10 14:46 <REP> d-------- C:\Program Files\LimeWire
2008-04-09 20:14 . 2008-04-09 20:14 <REP> d-------- C:\Documents and Settings\juju\Application Data\TuneUp Software
2008-04-09 18:08 . 2008-04-10 17:59 <REP> d-------- C:\Program Files\Navilog1
2008-04-09 18:02 . 2008-04-09 18:02 <REP> d-------- C:\Program Files\Executive Software
2008-04-09 15:12 . 2008-04-09 15:13 <REP> d-------- C:\Program Files\RegCleaner
2008-03-27 10:20 . 2008-03-27 10:20 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-03-26 13:44 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-26 13:44 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-03-26 13:44 . 2007-07-30 20:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-25 17:21 . 2006-11-29 14:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-03-25 17:20 . 2008-03-25 17:20 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-25 17:16 . 2008-03-25 17:19 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-03-25 17:15 . 2008-03-25 17:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-11 10:02 --------- d-----w C:\Program Files\Lx_cats
2008-04-10 15:06 --------- d-----w C:\Documents and Settings\maman\Application Data\OpenOffice.org2
2008-04-10 13:56 --------- d-----w C:\Documents and Settings\floriane\Application Data\Obj chin
2008-04-09 18:09 --------- d-----w C:\Documents and Settings\juju\Application Data\OpenOffice.org2
2008-04-09 13:12 --------- d-----w C:\Program Files\Zylom Games
2008-04-09 12:26 --------- d-----w C:\Program Files\VideoLAN
2008-04-09 12:16 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-08 13:57 --------- d-----w C:\Program Files\MSN Messenger
2008-04-07 19:06 2,090 ----a-w C:\Documents and Settings\juju\Application Data\wklnhst.dat
2008-04-07 09:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\GamesBar
2008-03-28 10:00 --------- d-----w C:\Documents and Settings\maman\Application Data\Obj chin
2008-03-28 09:59 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-28 09:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Proxy Long Chin Ping
2008-03-27 08:19 --------- d-----w C:\Program Files\Windows Live
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-10 08:23 --------- d-----w C:\Documents and Settings\maman\Application Data\TribalWeb
2008-02-28 15:28 --------- d-----w C:\Program Files\Java
2008-02-28 14:39 --------- d-----w C:\Program Files\TribalWeb
2008-02-28 14:04 83,208 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-28 14:04 73,496 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-28 14:04 --------- d-----w C:\Program Files\Symantec
2008-02-28 14:04 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-24 19:24 --------- d-----w C:\Program Files\TLC-Edusoft
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:32 670,208 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"NCLaunch"="C:\WINDOWS\NCLAUNCH.EXe" [2005-12-29 01:30 40960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"vptray"="C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe" [2003-04-29 15:48 90112]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-12-14 19:19 221184]
"F-Secure Manager"="C:\Program Files\Pack Sécurité\Common\FSM32.exe" [2006-04-02 03:19 184369]
"F-Secure Startup Wizard"="C:\Program Files\Pack Sécurité\FSGUI\FSSW.exe" [2006-09-01 15:11 724992]
"F-Secure TNB"="C:\Program Files\Pack Sécurité\FSGUI\TNBUtil.exe" [2006-09-01 15:11 671744]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-04-27 16:21 69632]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-05 14:00 160768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 23:18 443968]
C:\Documents and Settings\maman\Menu D‚marrer\Programmes\D‚marrage\
TribalWeb.lnk - C:\Program Files\TribalWeb\tribalweb.exe [2008-02-28 16:39:50 1077248]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Pack S‚curit‚.lnk - C:\Program Files\Pack S‚curit‚\backweb\361343\Program\fspex.exe [2007-01-12 11:09:32 32807]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoDesktop"= 0 (0x0)
"NoClose"= 0 (0x0)
"StartMenuLogOff"= 0 (0x0)
"HideClock"= 0 (0x0)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Pack Sécurité.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Pack Sécurité.lnk
backup=C:\WINDOWS\pss\Pack Sécurité.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^juju^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\juju\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^maman^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\maman\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 11:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2005-06-23 21:33 57344 C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 20:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DataLayer]
--a------ 2005-06-07 11:31 819712 C:\Program Files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2007-08-21 11:44 208946 C:\Program Files\IncrediMail\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2004-12-14 19:57 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2004-12-14 19:51 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic]
--a------ 2007-10-09 14:42 475180 C:\PROGRA~1\Magentic\bin\Magentic.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\messengerskinner]
C:\Program Files\MessengerSkinner\MessengerSkinner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2005-06-29 15:29 176128 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PcSync]
--a------ 2005-06-24 14:08 860160 C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware-Secure]
C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\lxcgcoms.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Pack Sécurité\\backweb\\361343\\Program\\fspex.exe"=
"C:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"C:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"C:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\TribalWeb\\tribalweb.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R2 BackWeb Plug-in - 361343;Pack Sécurité;C:\PROGRA~1\PACKSC~1\backweb\361343\Program\SERVIC~1.EXE [2007-01-12 11:09]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 14:00]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f353ae5-dd54-11dc-99ee-0013d4f65719}]
\Shell\AutoRun\command - J:\h.cmd
\Shell\explore\Command - J:\h.cmd
\Shell\open\Command - J:\h.cmd
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-04-11 12:00:10 C:\WINDOWS\Tasks\A0E5AC389126231C.job"
- c:\docume~1\maman\applic~1\objchi~1\2 extra open.exe
"2008-04-09 18:14:24 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-11 14:35:22
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\NavLogon.dll
.
Temps d'accomplissement: 2008-04-11 14:35:57
ComboFix-quarantined-files.txt 2008-04-11 12:35:51
Pre-Run: 178,560,081,920 octets libres
Post-Run: 178,747,068,416 octets libres
.
2008-04-11 09:53:55 --- E O F ---