ComboFix 10-08-10.03 - claudius 11/08/2010 5:48.1.2 - x86
Microsoft
Windows Vista
Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2038.1221 [GMT 2]
Lancé depuis: c:\users\claudius\Desktop\ComboFix.exe
SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\claudius\AppData\Roaming\.#
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-07-11 au 2010-08-11 ))))))))))))))))))))))))))))))))))))
.
2010-08-11 04:12 . 2010-08-11 04:12 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-09 12:43 . 2010-08-09 16:13 -------- d-----w- C:\Lop SD
2010-08-07 07:59 . 2010-08-07 09:40 -------- d-----w- c:\users\claudius\AppData\Roaming\TeamViewer
2010-08-07 07:58 . 2010-08-07 07:58 -------- d-----w- c:\program files\TeamViewer
2010-08-04 20:13 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-04 20:13 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-04 20:13 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-04 20:13 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-04 20:13 . 2010-06-28 20:32 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-04 20:11 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-04 20:11 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-04 20:10 . 2010-08-04 20:10 -------- d-----w- c:\programdata\Alwil Software
2010-08-04 20:10 . 2010-08-04 20:10 -------- d-----w- c:\program files\Alwil Software
2010-08-04 16:47 . 2010-08-07 08:52 -------- d-----w- c:\program files\ZHPDiag
2010-07-31 12:47 . 2008-08-26 15:49 110592 ----a-w- c:\users\claudius\AppData\Roaming\U3\temp\cleanup.exe
2010-07-30 20:00 . 2009-03-23 10:04 3547136 ---ha-w- c:\users\claudius\AppData\Roaming\U3\temp\Launchpad Removal.exe
2010-07-30 19:58 . 2010-07-31 12:57 -------- d-----w- c:\users\claudius\AppData\Roaming\U3
2010-07-30 15:27 . 2010-07-30 15:27 -------- d-----w- c:\program files\Artensoft Photo Mosaic Wizard
2010-07-28 16:12 . 2010-07-28 16:21 -------- d-----w- c:\programdata\ScreenVCR
2010-07-28 16:11 . 2010-07-28 16:11 -------- d-----w- c:\program files\TotalScreenRecorder_Gold
2010-07-28 15:46 . 2010-08-01 19:25 -------- d-----w- c:\program files\G Data
2010-07-28 15:43 . 2010-07-28 15:43 -------- d-----w- c:\users\claudius\AppData\Local\Downloaded Installations
2010-07-27 17:02 . 2010-07-17 03:00 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-27 12:28 . 2010-07-27 12:28 -------- d-----w- c:\programdata\F-Secure
2010-07-20 12:37 . 2010-07-20 12:37 -------- d-----w- c:\program files\Aneesoft
2010-07-12 13:07 . 2010-07-12 13:07 -------- d-----w- c:\program files\Inpaint
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-10 20:39 . 2009-10-04 00:12 -------- d-----w- c:\programdata\Spyware Terminator
2010-08-10 20:31 . 2009-10-04 00:12 -------- d-----w- c:\program files\Spyware Terminator
2010-08-10 20:31 . 2009-10-04 00:12 -------- d-----w- c:\users\claudius\AppData\Roaming\Spyware Terminator
2010-08-09 06:46 . 2009-02-13 13:01 -------- d-----w- c:\users\claudius\AppData\Roaming\MxBoost
2010-08-08 21:56 . 2009-07-28 19:14 -------- d-----w- c:\program files\JkDefrag
2010-08-05 17:03 . 2009-06-19 13:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-05 14:32 . 2009-06-19 13:26 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-05 13:54 . 2010-06-18 13:08 -------- d-----w- c:\program files\NXPowerLite
2010-08-05 07:24 . 2009-02-19 19:50 -------- d-----w- c:\program files\Common Files\Java
2010-08-05 07:24 . 2009-02-19 19:50 -------- d-----w- c:\program files\Java
2010-08-04 18:39 . 2009-02-14 14:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-04 06:44 . 2009-04-20 07:45 1356 ----a-w- c:\users\claudius\AppData\Local\d3d9caps.dat
2010-08-03 05:18 . 2010-01-07 19:04 1 ----a-w- c:\users\claudius\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-08-02 20:46 . 2006-11-02 15:48 679042 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-02 20:46 . 2006-11-02 15:48 126626 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-01 19:31 . 2010-06-24 13:13 -------- d-----w- c:\users\claudius\AppData\Roaming\Web Page Maker
2010-08-01 19:11 . 2009-02-14 14:23 -------- d-----w- c:\program files\CCleaner
2010-07-28 16:13 . 2010-07-09 19:24 -------- d-----w- c:\users\claudius\AppData\Roaming\DivX
2010-07-15 05:52 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-12 20:10 . 2009-02-13 14:41 -------- d-----w- c:\program files\Glary Utilities
2010-07-12 03:40 . 2010-07-12 03:40 673280 ----a-w- c:\windows\is-QJBQT.exe
2010-07-11 16:14 . 2009-02-13 12:29 -------- d-----w- c:\program files\Opera
2010-07-11 06:45 . 2010-06-19 16:58 -------- d-----w- c:\program files\Yahoo!
2010-07-09 19:26 . 2010-07-09 19:26 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-09 19:26 . 2010-07-09 19:15 -------- d-----w- c:\programdata\DivX
2010-07-09 19:25 . 2010-07-09 19:25 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-09 19:25 . 2010-07-09 19:16 -------- d-----w- c:\program files\DivX
2010-07-09 19:25 . 2010-07-09 19:25 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-07-09 19:25 . 2010-07-09 19:25 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-07-09 19:25 . 2010-07-09 19:25 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 84054 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-07-09 19:23 . 2010-07-09 19:23 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-07-09 19:23 . 2010-07-09 19:23 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-07-09 19:22 . 2010-07-09 19:22 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-07-09 19:22 . 2010-07-09 19:22 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-07-09 19:22 . 2010-07-09 19:22 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-07-09 19:21 . 2010-07-09 19:21 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-07-09 19:21 . 2010-07-09 19:21 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-07-09 19:21 . 2010-07-09 19:21 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-07-09 19:21 . 2010-07-09 19:20 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-07-09 19:21 . 2010-07-09 19:21 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-07-09 19:20 . 2010-07-09 19:20 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-07-09 19:15 . 2010-07-09 19:25 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-07-09 19:14 . 2010-07-09 19:25 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-06-29 14:08 . 2010-06-29 14:07 -------- d-----w- c:\users\claudius\AppData\Roaming\DemoCreator
2010-06-29 14:04 . 2009-02-24 15:17 -------- d-----w- c:\program files\Wondershare
2010-06-26 06:15 . 2010-06-26 06:15 -------- d-----w- c:\program files\Microsoft.NET
2010-06-24 13:13 . 2010-06-24 13:13 -------- d-----w- c:\programdata\Web Page Maker
2010-06-19 17:22 . 2010-06-19 17:13 -------- d-----w- c:\users\claudius\AppData\Roaming\Yahoo!
2010-06-17 13:24 . 2010-06-17 13:23 -------- d-----w- c:\program files\DAEMON Tools Pro
2010-06-17 13:24 . 2010-02-02 17:39 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-06-17 13:22 . 2010-06-17 13:21 -------- d-----w- c:\programdata\DAEMON Tools Pro
2010-06-17 13:21 . 2010-06-17 13:21 -------- d-----w- c:\users\claudius\AppData\Roaming\DAEMON Tools Pro
2010-06-16 15:10 . 2009-05-30 12:55 -------- d-----w- c:\program files\EvJOSoft
2010-06-16 15:08 . 2009-12-17 14:14 -------- d-----w- c:\users\claudius\AppData\Roaming\FILEminimizerPictures
2010-06-16 15:04 . 2009-03-23 12:35 -------- d-----w- c:\program files\Common Files\SourceTec
2010-06-16 14:42 . 2010-03-31 12:17 -------- d-----w- c:\program files\SocuSoft Web Video Player
2010-06-16 14:15 . 2010-05-27 19:48 -------- d-----w- c:\users\claudius\AppData\Roaming\IrfanView
2010-06-13 09:57 . 2010-06-13 09:57 591 ----a-w- c:\users\claudius\AppData\Local\GLFFDE0.tmp
2010-06-12 19:07 . 2010-06-12 19:07 673280 ----a-w- c:\windows\is-FJSG9.exe
2010-06-11 14:51 . 2010-06-11 14:51 3055600 ----a-w- c:\users\claudius\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 14:36 . 2010-06-11 14:36 275952 ----a-w- c:\users\claudius\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2010-05-26 17:06 . 2010-06-09 08:29 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-09 08:29 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 12:14 . 2009-10-03 06:17 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-16 11:46 . 2010-05-16 11:46 673280 ----a-w- c:\windows\is-CU65G.exe
2007-02-24 04:28 . 2007-02-24 04:28 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DummyIconOverlay]
@="{B8A03725-03B9-485F-BB22-E848799D4C2A}"
[HKEY_CLASSES_ROOT\CLSID\{B8A03725-03B9-485F-BB22-E848799D4C2A}]
2010-02-19 18:10 72704 ----a-w- c:\users\claudius\AppData\Local\Votre Opinion\PanelApp\pahelper_1401.2010.0128.1601.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\users\claudius\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-02-13 133104]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-10-04 3055616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-10-04 2171904]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-11-26 6621384]
"snpstd"="c:\windows\vsnpstd.exe" [2004-06-10 286720]
"XtrCtrlExEmotion"="c:\program files\Hercules\Dualpix Emotion\XtrCtrlEx.exe" [2009-10-19 3261736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-11-26 923336]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^claudius^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^K-Meleon Loader.lnk]
backup=c:\windows\pss\K-Meleon Loader.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LowerCaseSwitcher
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 14:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PanelApp]
2009-12-30 10:03 31232 ----a-w- c:\users\claudius\AppData\Local\Votre Opinion\PanelApp\PanelApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeaMonkey Quick Launch]
2008-07-02 17:45 106496 ----a-w- c:\program files\mozilla.org\SeaMonkey\seamonkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2009-10-04 00:13 3055616 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Google Update"="c:\users\claudius\AppData\Local\Google\Update\GoogleUpdate.exe" /c
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
"VistaSp2"=hex(b):43,fb,82,07,2d,39,ca,01
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\DRIVERS\SCRCAMHRDRV.sys [2009-03-27 234304]
R3 DrmRAudio;DrmRAudio;c:\windows\system32\drivers\DrmRAudio.sys [2009-07-15 23096]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-02-23 14216]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-02-23 8456]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2009-06-18 42480]
R3 PanelSvc;PanelSvc;c:\program files\Votre Opinion\PanelApp\PanelSvc.exe [2009-12-30 91136]
R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-17 697328]
S1 aswSP;aswSP; [x]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-11-25 221264]
S1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-11-25 24656]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-10-04 142592]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-07-13 108289]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
S2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\OAcat.exe [2009-11-26 1282248]
S2 olMntrService;olMntrService;c:\program files\Olivetti\ANY_WAY\olMntrService.exe [2006-09-22 86016]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [2009-11-26 3291848]
S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-07-06 173352]
S3 hxctlflt;hxctlflt;c:\windows\system32\Drivers\hxctlflt.sys [2009-02-08 99968]
S3 OAnet;OnlineArmor Service;c:\windows\system32\DRIVERS\oanet.sys [2009-11-25 30800]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
getPlusHelper REG_MULTI_SZ getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-08-11 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-13 09:14]
2010-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1486186306-353780486-3863553046-1000Core.job
- c:\users\claudius\AppData\Local\Google\Update\GoogleUpdate.exe [2009-02-13 12:09]
2010-08-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1486186306-353780486-3863553046-1000UA.job
- c:\users\claudius\AppData\Local\Google\Update\GoogleUpdate.exe [2009-02-13 12:09]
2010-08-10 c:\windows\Tasks\User_Feed_Synchronization-{59A6C1EF-E44F-4ADC-AB2C-037AF3ED59A0}.job
- c:\windows\system32\msfeedssync.exe [2009-02-17 07:33]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\claudius\AppData\Roaming\Mozilla\Firefox\Profiles\5fqaot2o.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
[Vous devez être inscrit et connecté pour voir ce lien]FF - component: c:\users\claudius\AppData\Local\Votre Opinion\PanelApp\ff\components\FFoxAddinStub.dll
FF - component: c:\users\claudius\AppData\Roaming\Mozilla\Firefox\Profiles\5fqaot2o.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\Opera\program\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\users\claudius\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\claudius\AppData\Roaming\Mozilla\Firefox\Profiles\5fqaot2o.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\users\claudius\AppData\Roaming\Mozilla\Firefox\Profiles\5fqaot2o.default\extensions\npfax@microgaming.co.uk\platform\WINNT_x86-msvc\plugins\npfax.dll
FF - plugin: c:\users\claudius\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - plugin: c:\users\claudius\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\claudius\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 600000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-MsMpSvc
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
[Vous devez être inscrit et connecté pour voir ce lien]Rootkit scan 2010-08-11 06:12
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1486186306-353780486-3863553046-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3152939E-0ECE-DA3A-28DD-D1470560508C}*]
"nabehlakkpkgpfjoclekgploibpo"=hex:6a,61,6f,64,69,67,6a,6d,64,6b,6f,6a,6b,68,
6e,65,67,66,62,65,00,00
"mapjbndfaaghnmebdnpcelnfkp"=hex:6a,61,68,64,6c,66,64,61,65,69,6e,67,70,61,65,
61,62,6d,65,6a,00,00
"hanjhomcdcdjmeoa"=hex:61,62,63,6b,67,63,6c,61,69,63,6e,63,69,6c,67,67,64,6c,
6b,68,66,6b,6d,6f,65,6b,6d,69,65,66,6a,6c,6d,6a,00,77
"hanjhomcgcimoedh"=hex:6f,61,6c,65,65,6e,6a,6d,6e,63,64,61,6e,65,6f,6d,6e,64,
67,6f,62,6c,64,65,6b,6c,6f,6c,69,61,00,6c
[HKEY_USERS\S-1-5-21-1486186306-353780486-3863553046-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B374082C-497D-F92D-6069-6A0558B44258}*]
"fbakfjekglpjfadopomedfdbkhagckhoapiakhjeffef"=hex:64,62,6b,62,63,6e,6e,6b,69,
70,6e,62,69,6c,63,61,61,67,6e,68,6c,6c,67,6b,69,65,64,65,63,6f,61,62,66,67,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(3248)
c:\program files\Tall Emu\Online Armor\OAwatch.dll
.
Heure de fin: 2010-08-11 06:22:31
ComboFix-quarantined-files.txt 2010-08-11 04:22
Avant-CF: 48 471 154 688 octets libres
Après-CF: 48 556 851 200 octets libres
- - End Of File - - B0B626E3FCD3AE78DA4860E229D07FF1
Sam 14 Jan 2023, 07:16 par arkanax
» oui madame !
Sam 14 Jan 2023, 07:11 par arkanax
» ça pique !!!
Sam 14 Jan 2023, 07:09 par arkanax
» C’est mathématiquement, philosophiquement idiot !
Sam 14 Jan 2023, 07:04 par arkanax
» Le saviez-vous?Au 19ème siècle, la cocaïne était utilisée pour traiter la dépression et les maux de dents !
Sam 14 Jan 2023, 06:57 par arkanax
» gentil toutou
Ven 13 Jan 2023, 07:21 par arkanax
» oh oui !
Ven 13 Jan 2023, 07:14 par arkanax
» bon appétit
Ven 13 Jan 2023, 07:10 par arkanax
» Le saviez-vous?La reconnaissance de soi chez les animaux
Ven 13 Jan 2023, 07:03 par arkanax
» la méprise
Jeu 12 Jan 2023, 07:16 par arkanax
» oh oui !
Jeu 12 Jan 2023, 07:12 par arkanax
» la dictée
Jeu 12 Jan 2023, 07:06 par arkanax
» Le saviez-vous?Le détenteur du record du monde de tir à l’arc n’a pas de bras !
Jeu 12 Jan 2023, 07:03 par arkanax
» heureusement qu'elle est la !
Mer 11 Jan 2023, 07:24 par arkanax
» dessous de table !
Mer 11 Jan 2023, 07:13 par arkanax
» c'est très bien
Mer 11 Jan 2023, 07:09 par arkanax
» Le saviez-vous? La plus petite guitare du monde a la taille d’un globule rouge !
Mer 11 Jan 2023, 07:05 par arkanax
» affreux !!!
Mar 10 Jan 2023, 07:18 par arkanax
» le marque-pages
Mar 10 Jan 2023, 07:15 par arkanax
» merci du conseil
Mar 10 Jan 2023, 07:09 par arkanax
» Le saviez-vous?En 2008, une plage a été volée en Jamaïque, tout le sable a été dérobé !
Mar 10 Jan 2023, 07:04 par arkanax
» coooooool
Lun 09 Jan 2023, 07:14 par arkanax
» bonne question !
Lun 09 Jan 2023, 07:10 par arkanax
» chère Dr
Lun 09 Jan 2023, 07:04 par arkanax
» Le saviez-vous?Au 19ème siècle, en Grande-Bretagne, une tentative de suicide était punie par pendaison
Lun 09 Jan 2023, 07:00 par arkanax