ComboFix 09-01-11.04 - Lucie 2009-01-13 1:49:09.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.3070.2289 [GMT 1:00]
Lancé depuis: c:\users\Lucie\Desktop\Antibagle.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\DAEMON Tools Lite\daemon.exe
c:\users\Lucie\AppData\Roaming\m
c:\users\Lucie\AppData\Roaming\m\flec006.exe
c:\users\Lucie\AppData\Roaming\m\list.oct
c:\windows\system32\drivers\downld
c:\windows\system32\drivers\downld\21873056.exe
c:\windows\system32\drivers\downld\3667099.exe
c:\windows\system32\drivers\downld\3670547.exe
c:\windows\system32\drivers\downld\3675820.exe
c:\windows\system32\drivers\downld\3677239.exe
c:\windows\system32\drivers\downld\3684306.exe
c:\windows\system32\drivers\downld\3744850.exe
c:\windows\system32\drivers\downld\3772556.exe
c:\windows\system32\drivers\downld\3788281.exe
c:\windows\system32\drivers\downld\3792977.exe
c:\windows\system32\drivers\downld\3843100.exe
c:\windows\system32\drivers\downld\3854535.exe
c:\windows\system32\drivers\downld\50154.exe
c:\windows\system32\drivers\srosa.sys
c:\windows\system32\drivers\srosa2.sys
c:\windows\system32\drivers\winfilse.exe
.
---- Previous Run -------
.
c:\program files\DAEMON Tools Lite\daemon.exe
c:\programdata\HotbarSA
c:\programdata\HotbarSA\HotbarSA.dat
c:\programdata\HotbarSA\HotbarSA_kyf.dat
c:\programdata\HotbarSA\HotbarSAAbout.mht
c:\programdata\HotbarSA\HotbarSAau.dat
c:\programdata\HotbarSA\HotbarSAEULA.mht
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Reset Cursor.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Uninstall Hotbar.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Weather.lnk
c:\users\Lucie\AppData\Roaming\hidires
c:\users\Lucie\AppData\Roaming\hidires\flec003.exe
c:\users\Lucie\AppData\Roaming\hidires\names.txt
c:\users\Lucie\AppData\Roaming\m
c:\users\Lucie\AppData\Roaming\m\data.oct
c:\users\Lucie\AppData\Roaming\m\flec006.exe
c:\users\Lucie\AppData\Roaming\m\list.oct
c:\users\Lucie\AppData\Roaming\m\shared\642-611 Practice Exam Testing Engine Software 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\70-223 Microsoft MCSE Windows 2000 Cluster 7.05.05.zip
c:\users\Lucie\AppData\Roaming\m\shared\a Motorola Siemens 128x128 128x160.zip
c:\users\Lucie\AppData\Roaming\m\shared\ABC Amber Word2Excel Converter 4.01.zip
c:\users\Lucie\AppData\Roaming\m\shared\Aberrater 3.0 beta.zip
c:\users\Lucie\AppData\Roaming\m\shared\Address Wizard Pro 4.23.zip
c:\users\Lucie\AppData\Roaming\m\shared\ADSS Charts Control 1.5.zip
c:\users\Lucie\AppData\Roaming\m\shared\Advanced Data Finder 1.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\Aplus Video to Xbox 8.68.zip
c:\users\Lucie\AppData\Roaming\m\shared\ASP.NET Maker 3.3.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\ASWSystems Toolbars Pack - Animals 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Athlon CPU SoftCooler XMas Edition 1.5 Build 101.zip
c:\users\Lucie\AppData\Roaming\m\shared\AUAU WMV MP4 ASF FLV to AVI Converter 4.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\Audio Editor 1.0.0.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\B&G Calculator 1.10.zip
c:\users\Lucie\AppData\Roaming\m\shared\Beach Clock Screensaver 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\BlankIE 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Bluetooth Framework ActiveX 5.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\BuddyVision 1.5.zip
c:\users\Lucie\AppData\Roaming\m\shared\CastlePaste PRO 2.01.1p.zip
c:\users\Lucie\AppData\Roaming\m\shared\Christmas Countdown 1.0.3.zip
c:\users\Lucie\AppData\Roaming\m\shared\clker.com openoffice.org addon 0.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\CONCEPT X7 5.21.zip
c:\users\Lucie\AppData\Roaming\m\shared\Countdown Redux 1.0.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\CurrProcess 1.13.zip
c:\users\Lucie\AppData\Roaming\m\shared\CZ-Xls2Csv 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Daniusoft Video Converter 2.0.1.8.zip
c:\users\Lucie\AppData\Roaming\m\shared\Database Software Icons 2008.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\DotNetScanner 1.6.zip
c:\users\Lucie\AppData\Roaming\m\shared\Drink Prog 2.0.3.zip
c:\users\Lucie\AppData\Roaming\m\shared\Easy GIF Animator 4.81.zip
c:\users\Lucie\AppData\Roaming\m\shared\Easy HR Popup Calendar Lite 1.05.zip
c:\users\Lucie\AppData\Roaming\m\shared\ewido.anti-malware.3.5+.witamina.zip
c:\users\Lucie\AppData\Roaming\m\shared\Excel Export To XML Software 1.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\Expression Media Encoder 2.0.1406.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\FAAD 2 Binaries for Win32.zip
c:\users\Lucie\AppData\Roaming\m\shared\FastCap 1.4.7.zip
c:\users\Lucie\AppData\Roaming\m\shared\Flash MP3 Player 1.1.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\Floyd-Steinberg dithering 1.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\Gift Baskets Screensaver 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\HandyCrypto 3.10.298.zip
c:\users\Lucie\AppData\Roaming\m\shared\hashr 0.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\HP0-795 Downloadable Exam Simulator 2.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\HYMN 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\ImageWalker 2.31.zip
c:\users\Lucie\AppData\Roaming\m\shared\Induction Motor Data 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Instrumentation Widgets for Mobile Devices 1.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\InvoicePal for GoldMine Corporate Edition 1.3.zip
c:\users\Lucie\AppData\Roaming\m\shared\Jedi Console 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\JPdfBookmarks 1.2.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\Kaspersky.Antivirus.Personal.v5.0.388-Fr.Incl-Keys.Par.Emule-Paradise.zip
c:\users\Lucie\AppData\Roaming\m\shared\KeyEcho 2.3.zip
c:\users\Lucie\AppData\Roaming\m\shared\Kid's Abacus 2.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\KKFI 90.1FM RADIO 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Learn How To Play The Guitar 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\ler.zip
c:\users\Lucie\AppData\Roaming\m\shared\LingvoSoft Learning Voice 2007 French Romanian 2.3.86.zip
c:\users\Lucie\AppData\Roaming\m\shared\Logitech Mobile Video 7.04.zip
c:\users\Lucie\AppData\Roaming\m\shared\Magicbit MP4 Video Converter 4.5.20.0927.zip
c:\users\Lucie\AppData\Roaming\m\shared\makebootfat 1.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\Maximize Message Pane 0.9.100.zip
c:\users\Lucie\AppData\Roaming\m\shared\Memscope 1.10.zip
c:\users\Lucie\AppData\Roaming\m\shared\Mesh To Solid for AutoCAD 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\MLB News 2.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Mobile Music Polyphonic 2.63.zip
c:\users\Lucie\AppData\Roaming\m\shared\Mooma DVD Creator 2.00.zip
c:\users\Lucie\AppData\Roaming\m\shared\moreTunes 2.04.zip
c:\users\Lucie\AppData\Roaming\m\shared\Motion JPEG Camera 2.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\Movie411 1.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\MSTS-Dictionary Extension for Firefox 2.0.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\My Expose 2006 CTP.zip
c:\users\Lucie\AppData\Roaming\m\shared\ne.zip
c:\users\Lucie\AppData\Roaming\m\shared\NotesHolder 1.65 Build 114.zip
c:\users\Lucie\AppData\Roaming\m\shared\Opel Speedster Screensaver.zip
c:\users\Lucie\AppData\Roaming\m\shared\Override Compatibility 1.25.zip
c:\users\Lucie\AppData\Roaming\m\shared\Password Recovery Bar 1.2.5 build 35.zip
c:\users\Lucie\AppData\Roaming\m\shared\PasswordDock 5.0.50.zip
c:\users\Lucie\AppData\Roaming\m\shared\Polestar Virtual Printer 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\PPT2Flash SDK 3.2.8.zip
c:\users\Lucie\AppData\Roaming\m\shared\Print HTML 1.5.zip
c:\users\Lucie\AppData\Roaming\m\shared\Qlock Lite 1.86.zip
c:\users\Lucie\AppData\Roaming\m\shared\Read to Me Text to Speech 1.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\Reasy 0.0.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\RingtonEditor 1 build 20070320.zip
c:\users\Lucie\AppData\Roaming\m\shared\RM to FLV Converter 1.00.zip
c:\users\Lucie\AppData\Roaming\m\shared\Russian Girls 3D additional pack 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Rusty Meeting 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Sanmaxi Access File Recovery 5.0.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\SaveCD 0.9 0.9 Beta.zip
c:\users\Lucie\AppData\Roaming\m\shared\SearchGun 1.3.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\Security23 1.8.zip
c:\users\Lucie\AppData\Roaming\m\shared\SelfImage 1.2.1.92.zip
c:\users\Lucie\AppData\Roaming\m\shared\Shaana Sidebar Calculator 1.14.zip
c:\users\Lucie\AppData\Roaming\m\shared\ShellBrowser Components for Delphi Win32 6.12.zip
c:\users\Lucie\AppData\Roaming\m\shared\Shuttle FTP Suite 3.7.zip
c:\users\Lucie\AppData\Roaming\m\shared\Skuld Video Converter 1.1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Smarky 0.9.6.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\SoftPepper DVD to PSP Video Suite 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Sothink DVD to iPod Converter 2.5 Build 70208.zip
c:\users\Lucie\AppData\Roaming\m\shared\Space Flight 3D Screensaver 1.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\Spam Crusher for Outlook 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\SpartacusFilter for Exchange Server 1.0.11.zip
c:\users\Lucie\AppData\Roaming\m\shared\Stormy Screen Savers 2 1.zip
c:\users\Lucie\AppData\Roaming\m\shared\SUN Java for SCJP 5.0 8.05.05.zip
c:\users\Lucie\AppData\Roaming\m\shared\Tavrida PERL Editor 3.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Tessela 0.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\The Free Awesome Dates Collection 2.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\Thumb Creator 1.0.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\TimeTracker 1.2.4.zip
c:\users\Lucie\AppData\Roaming\m\shared\Tiny Spy Agent 2.1.118.zip
c:\users\Lucie\AppData\Roaming\m\shared\TM Desktop Currency Converter 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\TTMaker 1.87c.zip
c:\users\Lucie\AppData\Roaming\m\shared\Turtle 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Ubercode 1.2.zip
c:\users\Lucie\AppData\Roaming\m\shared\University of Tampa Mail Checker 1.0.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\USA Geography Tutor 1.1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\UserTable 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Vcard Studio Express 1.0.0.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Video Ghost 1.0 Beta.zip
c:\users\Lucie\AppData\Roaming\m\shared\VOM - Venci Orders Manager 1.1.zip
c:\users\Lucie\AppData\Roaming\m\shared\VTExture 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Webation Active 1.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\Whizlabs RHCE (Red Hat Linux Certification) Exam Simulator 4.0.0.zip
c:\users\Lucie\AppData\Roaming\m\shared\WMS Log Storage Standard Edition 1.5 Build 0075.zip
c:\users\Lucie\AppData\Roaming\m\shared\XiaLaiKan 1.0.0.zip
c:\users\Lucie\AppData\Roaming\m\srvlist.oct
c:\users\Lucie\AppData\Roaming\WeatherDPA
c:\users\Lucie\AppData\Roaming\WeatherDPA\Weather\WeatherStartup.xml
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\ban_list.txt
c:\windows\system32\dcads-remove.exe
c:\windows\system32\drivers\downld
c:\windows\system32\drivers\downld\104099.exe
c:\windows\system32\drivers\downld\115861.exe
c:\windows\system32\drivers\downld\127406.exe
c:\windows\system32\drivers\downld\145236.exe
c:\windows\system32\drivers\downld\147280.exe
c:\windows\system32\drivers\downld\154643.exe
c:\windows\system32\drivers\downld\155501.exe
c:\windows\system32\drivers\downld\156625.exe
c:\windows\system32\drivers\downld\164752.exe
c:\windows\system32\drivers\downld\166874.exe
c:\windows\system32\drivers\downld\187232.exe
c:\windows\system32\drivers\downld\192645.exe
c:\windows\system32\drivers\downld\203035.exe
c:\windows\system32\drivers\downld\216685.exe
c:\windows\system32\drivers\downld\218073.exe
c:\windows\system32\drivers\downld\219618.exe
c:\windows\system32\drivers\downld\220460.exe
c:\windows\system32\drivers\downld\223923.exe
c:\windows\system32\drivers\downld\236091.exe
c:\windows\system32\drivers\downld\240678.exe
c:\windows\system32\drivers\downld\240943.exe
c:\windows\system32\drivers\downld\252425.exe
c:\windows\system32\drivers\downld\277525.exe
c:\windows\system32\drivers\downld\278477.exe
c:\windows\system32\drivers\downld\291113.exe
c:\windows\system32\drivers\downld\314872.exe
c:\windows\system32\drivers\downld\346493.exe
c:\windows\system32\drivers\downld\356992.exe
c:\windows\system32\drivers\downld\46269.exe
c:\windows\system32\drivers\downld\57143.exe
c:\windows\system32\drivers\downld\57564.exe
c:\windows\system32\drivers\downld\62150.exe
c:\windows\system32\drivers\downld\64022.exe
c:\windows\system32\drivers\downld\66628.exe
c:\windows\system32\drivers\downld\66799.exe
c:\windows\system32\drivers\downld\69358.exe
c:\windows\system32\drivers\downld\69514.exe
c:\windows\system32\drivers\downld\70933.exe
c:\windows\system32\drivers\downld\72618.exe
c:\windows\system32\drivers\downld\78640.exe
c:\windows\system32\drivers\downld\89575.exe
c:\windows\system32\drivers\srosa.sys
c:\windows\system32\drivers\srosa2.sys
c:\windows\system32\drivers\winfilse.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\mdelk.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wintems.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SROSA
-------\Legacy_SROSA
-------\Legacy_SK9OU0S
-------\Legacy_SK9OU0S
-------\Legacy_SROSA
-------\Service_sK9Ou0s
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-13 au 2009-01-13 ))))))))))))))))))))))))))))))))))))
.
2009-01-13 01:53 . 2009-01-13 01:53 <REP> d-------- c:\windows\System32\drivers\downld
2009-01-12 17:57 . 2009-01-12 17:57 343,392,249 --a------ c:\windows\MEMORY.DMP
2009-01-12 17:12 . 2009-01-12 17:31 69 --a------ c:\windows\NeroDigital.ini
2009-01-12 12:29 . 2009-01-12 14:44 <REP> d-------- c:\program files\FindyKill
2009-01-11 19:05 . 2009-01-11 19:05 <REP> d-------- c:\users\Lucie\AppData\Roaming\Malwarebytes
2009-01-11 19:05 . 2009-01-11 19:05 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-11 19:05 . 2009-01-11 19:05 <REP> d-------- c:\programdata\Malwarebytes
2009-01-11 19:05 . 2009-01-11 19:10 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-11 19:05 . 2009-01-04 18:38 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-11 19:05 . 2009-01-04 18:38 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-12-30 18:17 . 2008-12-30 18:20 <REP> d--h----- c:\windows\msdownld.tmp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 00:54 --------- d-----w c:\program files\DAEMON Tools Lite
2008-12-30 17:38 --------- d-----w c:\program files\Common Files\BitDefender
2008-12-12 20:01 --------- d-----w c:\programdata\BitDefender
2008-12-12 20:01 --------- d-----w c:\program files\BitDefender
2008-11-30 16:24 --------- d---a-w c:\programdata\TEMP
2008-10-22 14:45 21,248 ----a-w c:\windows\Help\OEM\scripts\HPScript.exe
2008-10-22 03:43 95,232 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-10-22 03:43 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 03:43 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-10-21 05:16 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-16 21:13 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w c:\windows\System32\wuapi.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\System32\wups2.dll
2008-10-16 21:08 34,328 ----a-w c:\windows\System32\wups.dll
2008-10-16 20:56 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-10-16 20:55 83,456 ----a-w c:\windows\System32\wudriver.dll
2008-10-16 13:08 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-10-16 12:56 31,232 ----a-w c:\windows\System32\wuapp.exe
2008-07-10 01:08 174 --sha-w c:\program files\desktop.ini
2008-05-12 02:04 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-02-28 20:19 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-02-28 20:19 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-02-28 20:19 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-02-28 20:19 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-02-28 20:19 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-03-27 173368]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2008-04-03 09:52 265360 --a------ c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
2007-12-06 11:58 1198432 --a------ c:\program files\Search Settings\kb125\SearchSettings.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-03-27 13:12 1164600 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-03-27 1164600]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-03-27 1164600]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 2321600]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-08-09 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-09 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-08-09 81920]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
"SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2007-12-06 1069920]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX3000"="c:\windows\vVX3000.exe" [2007-04-10 709992]
"KiweeHook"="c:\program files\Kiwee Toolbar2\1.5.131\kwtbaim.exe" [2008-04-03 56456]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-03-27 111928]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-12 29744]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-04-03 44168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-491465651-3313389990-2482465319-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D4224847-3077-4636-9FD7-3264BB6C592A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{ADF2D612-AF53-4F5E-B13F-5D1FB5F4898A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0CA19D1F-BB8F-4D06-A799-B2D5AD0AC3E6}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DDA9613B-FC64-4976-BFF8-C05C797A897E}"= UDP:c:\program files\eMule\emule.exe:eMule
"{CDEE7F01-B820-4154-B7FF-7043FFDA9843}"= TCP:c:\program files\eMule\emule.exe:eMule
"TCP Query User{52DFF08D-0849-4DED-871C-415B411A420D}c:\\program files\\goa\\gunbound\\gunbound.gme"= UDP:c:\program files\goa\gunbound\gunbound.gme:GunBound
"UDP Query User{F80A09A9-D554-4F5B-93DC-8FA0A4B51806}c:\\program files\\goa\\gunbound\\gunbound.gme"= TCP:c:\program files\goa\gunbound\gunbound.gme:GunBound
"TCP Query User{936525A4-F801-431A-A4A5-E43A80FB5F19}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{D33181E0-C1DB-48FB-A906-8041DA010081}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"TCP Query User{39301DF4-EB0A-4F35-B430-3E65D3A27300}c:\\program files\\freeplayer\\vlc\\vlc.exe"= UDP:c:\program files\freeplayer\vlc\vlc.exe:VLC media player
"UDP Query User{874D5571-A30E-42D0-9254-6DD671FCDAE6}c:\\program files\\freeplayer\\vlc\\vlc.exe"= TCP:c:\program files\freeplayer\vlc\vlc.exe:VLC media player
"{72F6E230-D73B-45D3-9801-3F7FBCE6B6BC}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{74E1B2D0-6F44-4535-BDFA-0FFF81D4C40E}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{4ED259DC-E8F2-477A-AB88-B345441BA7E5}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{3E2DEFBA-B4F2-4AAE-94AD-67F881BFD5BF}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-05-12 29744]
--- Other Services/Drivers In Memory ---
*Deregistered* - sptd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{196ca5c4-af03-11dc-9b07-001bb9d83f67}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3e1a2d3-b45d-11dc-a65f-001bb9d83f67}]
\shell\AutoRun\command - J:\AUTOTMM.EXE Ver40
.
Contenu du dossier 'Tâches planifiées'
2009-01-12 c:\windows\Tasks\User_Feed_Synchronization-{A348B083-754D-4FEC-8FA5-0744A7E6643B}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 10:45]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-MsnMsgr - ~c:\program files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
FF - ProfilePath -
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/...{moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 01:54:00
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\System32\rundll32.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\schtasks.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
c:\hp\KBD\kbd.exe
c:\windows\System32\conime.exe
.
**************************************************************************
.
Heure de fin: 2009-01-13 1:57:38 - La machine a redémarré [Lucie]
ComboFix-quarantined-files.txt 2009-01-13 00:57:34
Avant-CF: 74,044,755,968 octets libres
Après-CF: 74,022,322,176 octets libres
471 --- E O F --- 2009-01-12 13:28:53