ComboFix 09-01-21.04 - lucy 2009-01-24 17:30:27.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3000.2039 [GMT 1:00]
Lancé depuis: c:\users\lucy\Desktop\C-fix.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated)
FW: Bitdefender Firewall *enabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\lucy\AppData\Roaming\.#
c:\windows\Temp\log.txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-24 au 2009-01-24 ))))))))))))))))))))))))))))))))))))
.
2009-01-24 17:21 . 2009-01-24 17:32 121 --a------ c:\windows\bdagent.INI
2009-01-22 18:09 . 2007-12-10 14:53 81,288 --a------ c:\windows\System32\drivers\iksyssec.sys
2009-01-22 18:09 . 2007-12-10 14:53 66,952 --a------ c:\windows\System32\drivers\iksysflt.sys
2009-01-22 18:09 . 2009-01-22 18:11 42,376 --a------ c:\windows\System32\drivers\ikfilesec.sys
2009-01-22 18:09 . 2007-12-10 14:53 29,576 --a------ c:\windows\System32\drivers\kcom.sys
2009-01-22 18:08 . 2009-01-22 18:08 <REP> d-------- c:\users\lucy\AppData\Roaming\PC Tools
2009-01-21 13:03 . 2009-01-21 13:03 <REP> d-------- c:\program files\Microsoft
2009-01-21 13:02 . 2009-01-21 13:02 <REP> d-------- c:\program files\Microsoft Silverlight
2009-01-21 11:54 . 2009-01-24 17:32 81,984 --a------ c:\windows\System32\bdod.bin
2009-01-21 11:49 . 2009-01-21 11:49 <REP> d-------- c:\users\lucy\AppData\Roaming\Bitdefender
2009-01-21 11:49 . 2009-01-21 11:50 <REP> d-------- c:\users\All Users\BitDefender
2009-01-21 11:49 . 2009-01-21 11:50 <REP> d-------- c:\programdata\BitDefender
2009-01-21 11:49 . 2009-01-21 11:49 <REP> d-------- c:\program files\BitDefender
2009-01-21 11:46 . 2009-01-21 11:49 <REP> d-------- c:\program files\Common Files\BitDefender
2009-01-20 20:40 . 2009-01-20 20:40 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-20 20:40 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-20 20:40 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-20 20:09 . 2009-01-20 20:09 <REP> d-------- C:\rsit
2009-01-20 11:36 . 2009-01-20 11:36 2,608 --a------ c:\windows\System32\settings.aaw
2009-01-20 11:36 . 2009-01-20 11:36 976 --a------ c:\windows\System32\history.aaw
2009-01-18 21:04 . 2009-01-22 18:58 <REP> d-------- c:\program files\Spyware Doctor
2009-01-18 16:08 . 2009-01-18 16:08 <REP> d-------- c:\program files\Trend Micro
2009-01-14 19:51 . 2009-01-14 19:51 <REP> d-------- c:\users\lucy\AppData\Roaming\Malwarebytes
2009-01-14 19:51 . 2009-01-14 19:51 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-14 19:51 . 2009-01-14 19:51 <REP> d-------- c:\programdata\Malwarebytes
2009-01-14 19:06 . 2009-01-14 19:06 <REP> d-------- c:\users\All Users\1611339099
2009-01-14 19:06 . 2009-01-14 19:06 <REP> d-------- c:\programdata\1611339099
2009-01-14 19:02 . 2009-01-14 19:02 118 --a------ c:\windows\System32\MRT.INI
2009-01-14 09:26 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-02 19:48 . 2009-01-02 19:48 <REP> d-------- c:\users\lucy\AppData\Roaming\TomTom
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d----c--- c:\windows\System32\DRVSTORE
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d-------- c:\users\lucy\AppData\Roaming\Apple Computer
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d-------- c:\program files\iTunes
2009-01-02 16:24 . 2009-01-02 16:24 <REP> d-------- c:\program files\iPod
2009-01-02 16:24 . 2008-04-17 13:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2009-01-02 16:24 . 2008-04-17 13:12 15,464 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2009-01-02 16:23 . 2009-01-02 16:23 <REP> d-------- c:\program files\Bonjour
2009-01-02 16:22 . 2009-01-02 16:24 <REP> d-------- c:\users\All Users\Apple Computer
2009-01-02 16:22 . 2009-01-02 16:24 <REP> d-------- c:\programdata\Apple Computer
2009-01-02 16:22 . 2009-01-02 16:23 <REP> d-------- c:\program files\QuickTime
2009-01-02 16:22 . 2009-01-02 16:22 <REP> d-------- c:\program files\Apple Software Update
2009-01-02 16:21 . 2009-01-02 16:21 <REP> d-------- c:\users\All Users\Apple
2009-01-02 16:21 . 2009-01-02 16:21 <REP> d-------- c:\programdata\Apple
2009-01-02 16:21 . 2009-01-02 16:24 <REP> d-------- c:\program files\Common Files\Apple
2009-01-02 16:09 . 2009-01-02 16:09 <REP> d-------- c:\program files\VirginMega
2009-01-02 16:08 . 2009-01-02 16:08 <REP> d-------- c:\users\All Users\Downloaded Installations
2009-01-02 16:08 . 2009-01-02 16:08 <REP> d-------- c:\programdata\Downloaded Installations
2009-01-01 15:53 . 2009-01-01 15:53 <REP> dr------- c:\windows\System32\config\systemprofile\Music
2008-12-30 14:13 . 2008-12-30 14:13 <REP> d-------- c:\users\lucy\Option
2008-12-29 22:57 . 2008-12-29 22:57 952,832 --a------ c:\windows\System32\drivers\athr.sys
2008-12-29 18:36 . 2008-12-29 18:36 <REP> d-------- c:\program files\EA GAMES
2008-12-29 18:36 . 2005-02-26 06:34 442,368 -ra------ c:\windows\System32\vp6vfw.dll
2008-12-28 12:27 . 2008-12-28 12:29 <REP> d-------- c:\users\lucy\AppData\Roaming\eSobi
2008-12-27 23:24 . 2008-12-27 23:24 <REP> d-------- c:\program files\SiteAdvisor
2008-12-26 21:05 . 2008-12-26 21:05 <REP> d-------- c:\users\lucy\AppData\Roaming\Template
2008-12-26 20:52 . 2009-01-14 22:01 110 --a------ c:\users\lucy\AppData\Roaming\wklnhst.dat
2008-12-26 15:04 . 2008-12-26 15:04 <REP> d-------- c:\users\All Users\Messenger Plus!
2008-12-26 15:04 . 2008-12-26 15:04 <REP> d-------- c:\programdata\Messenger Plus!
2008-12-26 15:01 . 2008-12-26 15:01 <REP> d-------- c:\program files\Messenger Plus! Live
2008-12-26 14:57 . 2008-12-26 14:57 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-12-26 14:57 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll
2008-12-25 20:19 . 2008-10-02 02:32 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2008-12-25 20:15 . 2008-10-22 02:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-25 20:11 . 2008-12-25 20:11 <REP> d-------- c:\program files\MSXML 4.0
2008-12-25 20:08 . 2008-11-01 02:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-25 20:08 . 2008-09-18 03:16 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-12-25 20:08 . 2008-08-28 04:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-12-25 20:08 . 2008-08-28 04:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-12-25 20:08 . 2008-06-19 04:31 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-12-25 20:08 . 2008-08-28 04:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-12-25 20:08 . 2008-04-18 06:48 269,312 --a------ c:\windows\System32\es.dll
2008-12-25 20:08 . 2008-10-22 04:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-12-25 20:08 . 2008-11-01 04:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-25 20:06 . 2008-09-18 06:09 3,601,464 --a------ c:\windows\System32\ntkrnlpa.exe
2008-12-25 20:06 . 2008-09-18 06:09 3,549,240 --a------ c:\windows\System32\ntoskrnl.exe
2008-12-25 20:06 . 2008-06-23 02:59 2,868,736 --a------ c:\windows\System32\mf.dll
2008-12-25 20:06 . 2008-10-21 06:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-12-25 20:06 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-12-25 20:06 . 2008-06-23 02:59 996,352 --a------ c:\windows\System32\WMNetMgr.dll
2008-12-25 20:06 . 2008-04-10 06:12 738,304 --a------ c:\windows\System32\inetcomm.dll
2008-12-25 20:06 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-12-25 20:06 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-12-25 20:06 . 2008-06-23 02:58 94,720 --a------ c:\windows\System32\logagent.exe
2008-12-25 19:58 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-12-25 19:58 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-12-25 19:58 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-12-25 19:58 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-12-25 19:58 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-12-25 19:58 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-12-25 19:58 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-12-25 19:57 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-12-25 19:57 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-12-25 19:49 . 2008-12-27 23:20 <REP> d-------- c:\program files\Windows Live
2008-12-25 19:49 . 2008-12-26 14:55 <REP> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-12-25 19:48 . 2008-12-26 14:53 <REP> d-------- c:\users\All Users\WLInstaller
2008-12-25 19:48 . 2008-12-26 14:53 <REP> d-------- c:\programdata\WLInstaller
2008-12-25 17:54 . 2009-01-23 20:08 <REP> d-a------ c:\users\All Users\TEMP
2008-12-25 17:54 . 2008-12-25 17:54 <REP> d-------- c:\users\All Users\SpinTop Games
2008-12-25 17:54 . 2009-01-23 20:08 <REP> d-a------ c:\programdata\TEMP
2008-12-25 17:54 . 2008-12-25 17:54 <REP> d-------- c:\programdata\SpinTop Games
2008-12-25 17:32 . 2009-01-22 10:45 <REP> d-------- c:\users\lucy\AppData\Roaming\CyberLink
2008-12-25 14:18 . 2009-01-14 21:56 <REP> d-------- c:\users\All Users\Partner
2008-12-25 14:18 . 2008-12-25 14:18 <REP> d-------- c:\users\All Users\Google
2008-12-25 14:18 . 2009-01-14 21:56 <REP> d-------- c:\programdata\Partner
2008-12-25 14:17 . 2008-12-25 14:17 <REP> dr------- c:\users\lucy\Videos
2008-12-25 14:17 . 2008-12-25 14:17 <REP> dr------- c:\users\lucy\Searches
2008-12-25 14:17 . 2009-01-01 18:00 <REP> dr------- c:\users\lucy\Pictures
2008-12-25 14:17 . 2009-01-01 18:14 <REP> dr------- c:\users\lucy\Music
2008-12-25 14:17 . 2009-01-01 16:15 <REP> dr------- c:\users\lucy\Contacts
2008-12-25 14:17 . 2008-12-25 14:18 <REP> d-------- c:\program files\Google
2008-12-25 14:16 . 2008-12-26 17:58 <REP> dr------- c:\users\lucy\Saved Games
2008-12-25 14:16 . 2008-12-25 14:17 <REP> dr------- c:\users\lucy\Links
2008-12-25 14:16 . 2009-01-02 19:48 <REP> dr------- c:\users\lucy\Downloads
2008-12-25 14:16 . 2009-01-22 10:45 <REP> dr------- c:\users\lucy\Documents
2008-12-25 14:16 . 2006-11-02 13:37 <REP> d-------- c:\users\lucy\AppData\Roaming\Media Center Programs
2008-12-25 14:16 . 2008-05-08 07:25 <REP> d-------- c:\users\lucy\AppData\Roaming\Acer GameZone Console
2008-12-25 14:16 . 2008-12-25 14:17 <REP> d--h----- c:\users\lucy\AppData
2008-12-25 14:16 . 2009-01-21 13:04 <REP> d-------- c:\users\lucy
2008-12-25 14:13 . 2008-12-25 14:13 <REP> dr------- c:\windows\System32\config\systemprofile\Contacts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 10:39 --------- d-----w c:\programdata\McAfee
2009-01-14 18:03 --------- d-----w c:\program files\Windows Mail
2009-01-10 18:46 --------- d-----w c:\program files\Common Files\Adobe
2008-12-28 11:33 --------- d-----w c:\programdata\eSobi
2008-12-26 14:52 --------- d-----w c:\programdata\CyberLink
2008-12-26 13:44 --------- d-----w c:\programdata\SiteAdvisor
2008-12-25 19:24 --------- d-----w c:\programdata\Microsoft Help
2008-12-25 19:11 --------- d-----w c:\program files\Microsoft Works
2008-12-25 13:17 --------- d-----w c:\program files\Acer
2008-12-25 13:13 --------- d-sh--w c:\programdata\Modèles
2008-12-25 13:13 --------- d-sh--w c:\programdata\Menu Démarrer
2008-12-25 13:13 --------- d-sh--w c:\programdata\Favoris
2008-12-25 13:13 --------- d-sh--w c:\programdata\Bureau
2008-12-25 13:13 --------- d-sh--w c:\program files\Fichiers communs
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-05-14 16:05 121392 --a------ c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1049896]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-04-10 147456]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-04-10 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-04-18 167936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-17 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-17 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-17 145944]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-09-10 809480]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-05-14 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-06-11 409600]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-25 24064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-04 368640]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=G
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{094339B4-DC9A-4360-BD84-3F092D663E07}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{630EE3C1-2814-48EE-A950-11CD55D32643}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7B7DEEEB-D07C-4D91-9E38-F857C78E87AD}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{85FDDE5B-8CBC-4798-B06D-8EC8E0C59F70}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{700982FC-837F-4B5A-9A78-2CBD0B8EB989}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{1EC0BE30-C5C4-4D30-8DDA-FDFEE6BEFF0F}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{89DA007C-73BF-4DD5-92F4-A6479FA63BA8}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{54955791-5D79-4470-BEFE-6EECB7BB4EF4}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{E0025EC9-154E-4225-AD81-E6274D2A9539}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{40E69045-CA01-447A-83E4-B1783A083C27}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{BC1FF906-2695-4CE7-9E0B-8921A138BF38}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe:Acer Play Movie
"{8406E2DF-9398-479A-9ADE-72D2DC6E56B9}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe:Acer Play Movie Resident Program
"{47CD24C2-2AE6-49B8-943F-6642F4F24FC8}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:Acer HomeMedia
"{ABC3DC77-FA05-4633-AC70-4AA663768CB3}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{26C652E1-BECF-4DE5-9C4E-8BDB89D8840E}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{03E49A29-215B-4393-BDB5-EF5D3D90817E}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6F51DBC0-FC24-438C-B340-F471A7772BB8}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{0DF8E135-B6FF-4579-AE18-9201525C3CE2}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\System32\drivers\bdfndisf.sys [2008-06-02 86792]
R4 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\[u]0/u00.fcl [2008-05-08 07:32:42 61424]
R4 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R4 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-05-08 81504]
R4 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-05-08 24576]
R4 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424]
R4 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-05-08 122368]
R4 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2008-01-21 179712]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-12-25 24064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-22 337800]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
HKLM-Run-eRecoveryService - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0908&m=aspire_5735
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=2&o=vp32&d=0908&m=aspire_5735
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 17:32:06
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-24 17:33:55
ComboFix-quarantined-files.txt 2009-01-24 16:33:53
Avant-CF: 34 900 566 016 octets libres
Après-CF: 34,897,440,768 octets libres
265 --- E O F --- 2009-01-21 12:04:21