Voici le resultat
Merci
ComboFix 10-04-21.01 - 1 26/04/2010 13:28:17.1.4 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3326.2928 [GMT 2:00]
Lancé depuis: c:\documents and settings\1\Mes documents\Téléchargements\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\1\Application Data\avdrn.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-03-26 au 2010-04-26 ))))))))))))))))))))))))))))))))))))
.
2010-04-26 11:16 . 2010-04-26 11:18 -------- d-----w- c:\documents and settings\1\Application Data\QuickScan
2010-04-26 11:01 . 2010-04-26 11:01 -------- d-----w- c:\program files\Trend Micro
2010-04-26 09:46 . 2010-04-26 09:46 -------- d-----r- c:\documents and settings\LocalService\Favoris
2010-04-22 07:23 . 2010-04-22 07:23 71640 ----a-w- c:\documents and settings\2l\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-22 07:09 . 2010-04-22 07:09 -------- d-----w- c:\documents and settings\2\Local Settings\Application Data\PowerDVD DX
2010-04-22 07:09 . 2010-04-22 07:18 -------- d-----w- c:\documents and settings\2\Local Settings\Application Data\Microsoft
2010-04-20 09:50 . 2010-04-20 09:50 -------- d-----w- c:\documents and settings\3\Application Data\PTC
2010-04-20 09:49 . 2010-03-26 10:16 -------- d-----w- c:\documents and settings\3\Application Data\Bodet_Client
2010-04-20 09:44 . 2010-04-20 09:44 -------- d-----w- c:\documents and settings\4\Application Data\PTC
2010-04-20 09:43 . 2010-04-20 09:43 -------- d-sh--w- c:\documents and settings\4\IETldCache
2010-04-06 07:07 . 2010-04-06 07:07 685568 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\Wait.exe
2010-04-06 07:07 . 2010-04-06 07:07 13331456 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\TwinyExp.exe
2010-04-06 07:07 . 2010-04-06 07:07 8189440 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\Twinypar.exe
2010-04-06 07:07 . 2010-04-06 07:07 4082688 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\qtintf70.dll
2010-04-06 07:07 . 2010-04-06 07:07 3436032 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\resource.dll
2010-03-29 12:08 . 2010-03-29 14:25 720896 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\bodetDeploy.exe
2010-03-29 10:01 . 2010-03-29 10:01 -------- d-sh--w- c:\documents and settings\1\IECompatCache
2010-03-29 09:44 . 2010-03-29 09:44 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-03-29 09:42 . 2010-02-16 04:50 64000 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-03-29 09:42 . 2010-04-14 16:18 -------- d-----w- c:\windows\ie8updates
2010-03-29 09:42 . 2010-02-25 09:47 11070976 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-03-29 09:42 . 2010-02-25 06:17 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-03-29 09:42 . 2010-02-25 06:17 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2010-03-29 09:42 . 2010-02-25 06:17 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-29 09:42 . 2010-02-25 06:17 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2010-03-29 09:42 . 2010-02-25 06:17 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-03-29 09:41 . 2010-03-29 09:42 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-26 11:30 . 2010-03-16 10:45 802304 ----a-w- c:\windows\system32\drivers\szpgn.sys
2010-04-26 10:20 . 2008-10-12 13:26 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-04-14 16:19 . 2008-08-10 08:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-14 06:24 . 2009-11-13 07:21 79488 ----a-w- c:\documents and settings\1\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-04-06 07:07 . 2010-04-06 07:07 2502144 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\Exttwiv2.dll
2010-04-06 07:07 . 2010-04-06 07:07 1645320 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\gdiplus.dll
2010-04-06 07:07 . 2010-04-06 07:07 12864512 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\poste_2@8089\bin32\EditLib.dll
2010-04-06 07:07 . 2010-03-29 12:08 -------- d-----w- c:\documents and settings\1\Application Data\Bodet_Client
2010-04-06 07:05 . 2009-01-19 17:05 410976 ----a-w- c:\windows\system32\deploytk.dll
2010-04-06 07:05 . 2008-10-13 13:20 -------- d-----w- c:\documents and settings\1\Application Data\ntr
2010-03-29 12:08 . 2010-03-29 12:08 601600 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\Wait.exe
2010-03-29 12:08 . 2010-03-29 12:08 10691072 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\TwinyExp.exe
2010-03-29 12:08 . 2010-03-29 12:08 7898112 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\Twinypar.exe
2010-03-29 12:08 . 2010-03-29 12:08 3210752 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\resource.dll
2010-03-29 12:08 . 2010-03-29 12:08 2274816 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\Exttwiv2.dll
2010-03-29 12:08 . 2010-03-29 12:08 11782144 ----a-w- c:\documents and settings\1\Application Data\Bodet_Client\192.168.8.12@8089\bin32\EditLib.dll
2010-03-29 12:08 . 2009-02-23 14:33 4082688 ----a-w- c:\windows\system32\qtintf70.dll
2010-03-29 12:08 . 2009-02-23 14:33 1645320 ----a-w- c:\windows\system32\gdiplus.dll
2010-03-29 09:21 . 2004-08-19 12:03 85396 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-29 09:21 . 2004-08-19 12:03 511874 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-29 08:57 . 2008-08-10 08:26 -------- d-----w- c:\program files\Java
2010-03-26 10:17 . 2010-04-20 09:49 10691072 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\TwinyExp.exe
2010-03-26 10:17 . 2010-04-20 09:49 601600 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\Wait.exe
2010-03-26 10:16 . 2010-04-20 09:49 7898112 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\Twinypar.exe
2010-03-26 10:16 . 2010-04-20 09:49 3210752 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\resource.dll
2010-03-26 10:16 . 2010-04-20 09:49 2274816 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\Exttwiv2.dll
2010-03-26 10:16 . 2010-04-20 09:49 11782144 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\localhost@8089\bin32\EditLib.dll
2010-03-26 10:16 . 2010-04-20 09:49 720896 ----a-w- c:\documents and settings\3\Application Data\Bodet_Client\bodetDeploy.exe
2010-03-18 10:49 . 2010-04-20 09:49 -------- d-----w- c:\documents and settings\3\Application Data\AVG7
2010-03-18 10:49 . 2010-04-20 09:49 -------- d-----w- c:\documents and settings\3\Application Data\ATI
2010-03-16 10:45 . 2010-03-16 10:45 12 ----a-w- c:\documents and settings\NetworkService\Application Data\zxcdyt.dat
2010-03-10 06:16 . 2004-08-19 12:03 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:17 . 2004-08-19 12:03 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-19 12:03 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:06 . 2004-08-19 12:03 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2004-08-03 23:48 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-12 07:07 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:34 . 2004-08-19 12:03 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-19 12:03 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2009-12-21 1803064]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-15 8523776]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-11-28 1036288]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-04-06 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\2\Menu D‚marrer\Programmes\D‚marrage\
all.bat [2007-7-27 441]
c:\documents and settings\1\Menu D‚marrer\Programmes\D‚marrage\
all.bat [2009-6-2 487]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 19:35 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1129\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1129\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1129\Scripts\Logon\2\0]
"Script"=all.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1140\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1140\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1140\Scripts\Logon\2\0]
"Script"=conditionnement.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1150\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1150\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1150\Scripts\Logon\2\0]
"Script"=etude.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1152\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1152\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1152\Scripts\Logon\2\0]
"Script"=all.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1171\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1171\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1171\Scripts\Logon\2\0]
"Script"=etude.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1172\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1172\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1172\Scripts\Logon\2\0]
"Script"=etude.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1179\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1179\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1179\Scripts\Logon\2\0]
"Script"=all.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1614\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1614\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1614\Scripts\Logon\2\0]
"Script"=etude.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1616\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1616\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1616\Scripts\Logon\2\0]
"Script"=secretariat.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1621\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1621\Scripts\Logon\1\0]
"Script"=connexion_imprimantes.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-1621\Scripts\Logon\2\0]
"Script"=stural.bat
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1504756772-668073842-1836148756-500\Scripts\Logon\0\0]
"Script"=horloge.bat
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [16/06/2009 12:39 108289]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [20/06/2007 15:30 79168]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [27/01/2009 18:45 717296]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys --> c:\program files\LogMeIn\x86\RaInfo.sys [?]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - szpgn
.
.
------- Examen supplémentaire -------
.
DPF: {1ED48504-8834-11D5-AC75-0008C73FD642} -
file://c:\program files\proeWildfire 2.0\i486_nt\obj\pvx_install.exe
DPF: {6DAE4E21-F4C2-4537-A697-1C9482D32E06} -
hxxp://192.168.8.193:8089/open/portail/ ... ortail.ocxFF - ProfilePath - c:\documents and settings\1\Application Data\Mozilla\Firefox\Profiles\wnqmzip3.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-Locked - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-26 13:30
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\szpgn]
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\LMIinit.dll
.
Heure de fin: 2010-04-26 13:31:20
ComboFix-quarantined-files.txt 2010-04-26 11:31
Avant-CF: 91 731 222 528 octets libres
Après-CF: 91 726 733 312 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 2E0EA82EC391D44F6676DF4C50A55C07