Voila!!
ComboFix 09-02-15.01 - gege 2009-02-17 1:02:05.1 - NTFSx86 MINIMAL
Lancé depuis: c:\documents and settings\gege\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\gege\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\gege\Application Data\inst.exe
c:\windows\system32\Pncrt.dll
f:\recycler\S-1-8-97-100014437-100011688-100019248-5298.com
f:\recycler\S-5-8-52-100000556-100024634-100019059-9874.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-17 au 2009-02-17 ))))))))))))))))))))))))))))))))))))
.
2009-02-17 13:01 . 2009-01-25 17:14 <REP> d--h----- c:\documents and settings\angelique\Voisinage réseau
2009-02-17 13:01 . 2009-01-25 17:14 <REP> d--h----- c:\documents and settings\angelique\Voisinage d'impression
2009-02-17 13:01 . 2009-01-25 10:18 <REP> d--h----- c:\documents and settings\angelique\Modèles
2009-02-17 13:01 . 2009-01-25 17:14 <REP> d-------- c:\documents and settings\angelique\Mes documents
2009-02-17 13:01 . 2009-01-25 17:14 <REP> dr------- c:\documents and settings\angelique\Menu Démarrer
2009-02-17 13:01 . 2009-01-25 17:14 <REP> d-------- c:\documents and settings\angelique\Favoris
2009-02-17 13:01 . 2009-02-08 22:03 <REP> d-------- c:\documents and settings\angelique\Bureau
2009-02-17 13:01 . 2009-02-17 13:01 <REP> d-------- c:\documents and settings\angelique
2009-02-17 12:30 . 2008-10-14 14:01 79,904 --a------ c:\windows\system32\drivers\fsdfw.sys
2009-02-17 12:29 . 2009-02-17 12:31 <REP> d-------- c:\program files\F-Secure Internet Security
2009-02-17 12:29 . 2009-02-17 12:29 <REP> d-------- c:\documents and settings\All Users\Application Data\fssg
2009-02-17 12:28 . 2009-02-17 12:28 <REP> d-------- c:\windows\LastGood.Tmp
2009-02-17 12:27 . 2009-02-17 12:30 <REP> d-------- c:\documents and settings\All Users\Application Data\f-secure
2009-02-17 11:09 . 2009-02-17 11:09 2,335,270 --a------ c:\windows\system32\[u]0/u604.mht
2009-02-17 11:09 . 2008-04-14 03:33 731,136 --a------ c:\windows\system32\6066.tmp
2009-02-17 11:09 . 2009-02-17 11:09 54,624 --a------ c:\windows\system32\8855.sys
2009-02-17 09:32 . 2009-02-17 09:39 <REP> d-------- c:\documents and settings\gege\Pavark
2009-02-16 21:13 . 2007-01-18 13:00 3,968 --a------ c:\windows\system32\drivers\AvgArCln.sys
2009-02-16 21:09 . 2009-02-16 22:39 <REP> d-------- c:\program files\Sophos
2009-02-16 18:41 . 2009-02-16 18:41 <REP> d-------- c:\windows\Sun
2009-02-16 18:36 . 2009-02-16 18:36 <REP> d-------- c:\program files\Alwil Software
2009-02-16 17:46 . 2009-02-16 17:46 75,264 --a------ c:\windows\system32\drivers\gaopdxxboejkdu.sy_
2009-02-16 17:01 . 2009-02-16 17:01 75,264 --a------ c:\windows\system32\drivers\gaopdxptusvurm.sy_
2009-02-16 17:01 . 2009-02-16 21:15 4 --a------ c:\windows\system32\gaopdxcounte_
2009-02-16 11:15 . 2009-02-17 12:05 <REP> d-------- c:\program files\eMule
2009-02-16 09:54 . 2009-02-16 10:42 <REP> d-------- c:\program files\Serious Sam 2
2009-02-15 21:39 . 2009-02-15 21:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Age of Empires 3
2009-02-15 21:33 . 2009-02-15 21:35 <REP> d-------- c:\program files\Hard Disk Sentinel
2009-02-15 12:16 . 2008-07-29 13:33 446,464 --a------ c:\windows\system32\nvunrm.exe
2009-02-15 12:16 . 2008-07-29 13:30 6,045 --a------ c:\windows\system32\nvnrm.nvu
2009-02-15 12:03 . 2008-08-27 13:58 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2009-02-15 12:03 . 2008-07-10 04:07 7,143 --a------ c:\windows\system32\nvide.nvu
2009-02-15 11:42 . 2009-02-15 11:57 <REP> d-------- c:\program files\Atheros
2009-02-15 10:38 . 2009-02-15 10:38 <REP> d-------- C:\Drivers
2009-02-14 22:15 . 2009-02-14 22:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Blizzard
2009-02-14 22:07 . 2009-02-16 11:19 <REP> d-------- c:\program files\Fichiers communs\Blizzard Entertainment
2009-02-14 19:09 . 2008-04-13 19:40 43,904 --a------ c:\windows\system32\drivers\sbp2port.sys
2009-02-14 19:09 . 2008-04-13 19:40 43,904 --a--c--- c:\windows\system32\dllcache\sbp2port.sys
2009-02-14 16:38 . 2009-02-14 16:38 <REP> d-------- c:\documents and settings\All Users\Application Data\ATI
2009-02-14 16:35 . 2009-02-14 16:36 <REP> d-------- c:\program files\ATI Technologies
2009-02-14 16:35 . 2009-01-13 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2009-02-14 16:33 . 2008-08-21 02:37 3,107,788 -ra------ c:\windows\system32\ativvaxx.dat
2009-02-14 16:33 . 2008-08-21 02:37 3,107,788 -ra------ c:\windows\system32\ativva5x.dat
2009-02-14 16:33 . 2008-08-21 02:37 887,724 -ra------ c:\windows\system32\ativva6x.dat
2009-02-14 16:33 . 2009-01-14 05:49 425,984 --a------ c:\windows\system32\ATIDEMGX.dll
2009-02-14 16:33 . 2009-01-14 04:37 307,200 --a------ c:\windows\system32\atiiiexx.dll
2009-02-14 16:33 . 2008-10-29 23:13 180,720 --a------ c:\windows\system32\atiicdxx.dat
2009-02-14 16:33 . 2008-11-21 04:26 15,362 --a------ c:\windows\atiogl.xml
2009-02-14 16:33 . 2007-08-31 14:20 7,167 -ra------ c:\windows\system32\atifglpf.xml
2009-02-14 16:25 . 2009-02-14 16:25 10 --a------ c:\windows\WININIT.INI
2009-02-14 12:42 . 2009-02-14 12:42 319 --a------ c:\windows\game.ini
2009-02-14 12:34 . 2009-02-14 12:34 <REP> d-------- c:\program files\Activision
2009-02-14 12:32 . 2009-02-14 12:32 <REP> d--hs---- c:\windows\ftpcache
2009-02-14 11:35 . 2006-05-20 16:16 1,184,984 --a------ c:\windows\system32\wvc1dmod.dll
2009-02-14 11:35 . 2006-05-11 19:21 626,688 --a------ c:\windows\system32\vp7vfw.dll
2009-02-14 10:23 . 2009-02-14 10:23 <REP> d-------- c:\documents and settings\gege\Application Data\ATI
2009-02-14 10:17 . 2009-02-14 15:35 <REP> d-------- C:\ATI
2009-02-14 10:06 . 2009-02-14 10:06 0 --a------ c:\windows\ativpsrm.bin
2009-02-14 10:05 . 2008-07-02 20:38 89,600 --a------ c:\windows\system32\drivers\AtiHdmi.sys
2009-02-13 17:04 . 2009-02-13 17:04 <REP> d--h----- c:\documents and settings\All Users\Application Data\~0
2009-02-13 15:01 . 2009-02-13 15:47 <REP> d-------- c:\documents and settings\gege\Application Data\LimeWire
2009-02-13 15:00 . 2009-02-13 15:00 <REP> d-------- c:\program files\Java
2009-02-13 15:00 . 2009-02-16 18:40 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-13 15:00 . 2009-02-16 18:40 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-13 12:40 . 2009-02-13 12:40 <REP> d-------- c:\program files\CCleaner
2009-02-13 12:07 . 2009-02-13 12:07 <REP> d-------- c:\documents and settings\gege\Application Data\Uniblue
2009-02-12 22:15 . 2002-12-10 02:20 102,439 --a------ c:\windows\system32\sipr3260.dll
2009-02-12 22:11 . 2009-02-14 11:35 <REP> d-------- c:\program files\VSO
2009-02-12 22:11 . 2009-02-15 15:37 <REP> d-------- c:\documents and settings\gege\Application Data\Vso
2009-02-12 22:11 . 2006-09-29 13:24 217,127 --a------ c:\windows\system32\drv43260.dll
2009-02-12 22:11 . 2006-09-29 13:25 208,935 --a------ c:\windows\system32\drv33260.dll
2009-02-12 22:11 . 2006-09-29 13:26 176,165 --a------ c:\windows\system32\drv23260.dll
2009-02-12 22:11 . 2007-03-18 21:37 65,602 --a------ c:\windows\system32\cook3260.dll
2009-02-12 22:11 . 2009-02-14 11:35 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2009-02-12 22:11 . 2009-02-14 11:35 47,360 --a------ c:\documents and settings\gege\Application Data\pcouffin.sys
2009-02-12 20:08 . 2009-02-12 20:08 23,392 --a------ c:\windows\system32\nscompat.tlb
2009-02-12 20:08 . 2009-02-12 20:08 16,832 --a------ c:\windows\system32\amcompat.tlb
2009-02-10 12:28 . 2009-02-14 18:40 <REP> d-------- c:\program files\Microsoft Games
2009-02-10 12:28 . 1997-07-06 19:22 756,736 --------- c:\windows\system32\ir41_32.dll
2009-02-10 12:24 . 2009-02-10 12:24 <REP> d-------- c:\windows\Logs
2009-02-10 12:24 . 2009-02-14 12:25 138,464 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2009-02-10 12:24 . 2009-02-14 12:25 111,928 --a------ c:\windows\system32\PnkBstrB.exe
2009-02-10 12:24 . 2009-02-12 14:55 22,328 --a------ c:\documents and settings\gege\Application Data\PnkBstrK.sys
2009-02-10 12:23 . 2009-02-12 14:54 682,280 --a------ c:\windows\system32\pbsvc.exe
2009-02-10 12:23 . 2009-02-12 14:54 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2009-02-10 12:11 . 2009-02-10 12:30 <REP> d-------- c:\program files\Left 4 Dead
2009-02-08 22:06 . 2009-02-08 22:06 <REP> d-------- c:\documents and settings\gege\Application Data\CyberLink
2009-02-08 22:04 . 2009-02-08 22:04 <REP> d-------- c:\documents and settings\All Users\Application Data\CyberLink
2009-02-08 22:03 . 2001-03-08 18:30 24,064 --------- c:\windows\system32\msxml3a.dll
2009-02-08 22:02 . 2009-02-08 22:03 <REP> d-------- c:\program files\CyberLink
2009-02-08 21:49 . 2009-02-08 21:49 <REP> d-------- c:\program files\TeraCopy
2009-02-08 21:49 . 2009-02-17 00:49 <REP> d-------- c:\documents and settings\gege\Application Data\TeraCopy
2009-02-08 21:48 . 2009-02-08 23:52 <REP> d-------- c:\documents and settings\gege\Application Data\DAEMON Tools
2009-02-08 21:46 . 2009-02-10 12:08 <REP> d-------- c:\program files\DAEMON Tools Lite
2009-02-08 21:44 . 2009-02-08 21:44 715,248 --a------ c:\windows\system32\drivers\sptd.sys
2009-02-08 21:42 . 2009-02-08 21:42 <REP> d-------- c:\program files\Fichiers communs\Everstrike Software
2009-02-08 21:42 . 2009-02-08 21:42 <REP> d-------- c:\program files\Everstrike Software
2009-02-02 12:47 . 2009-02-02 12:47 <REP> dr-h----- c:\documents and settings\gege\Application Data\SecuROM
2009-02-02 12:47 . 2009-02-10 12:26 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-02-02 12:47 . 2009-02-14 15:44 7,912 --a------ c:\windows\system32\d3d9caps.dat
2009-02-02 12:45 . 2009-02-02 12:45 <REP> d-------- c:\program files\Fichiers communs\Adobe
2009-02-01 17:14 . 2009-02-01 17:14 <REP> d-------- c:\windows\system32\fr
2009-02-01 17:14 . 2009-02-01 17:14 <REP> d-------- c:\windows\l2schemas
2009-02-01 16:58 . 2009-02-01 16:58 <REP> d-------- c:\program files\Sierra
2009-02-01 16:01 . 2009-02-03 16:20 <REP> d-------- c:\documents and settings\gege\Application Data\vlc
2009-02-01 15:04 . 2009-02-01 15:04 244 --ah----- C:\sqmnoopt01.sqm
2009-02-01 15:04 . 2009-02-01 15:04 232 --ah----- C:\sqmdata01.sqm
2009-02-01 14:01 . 2009-02-17 11:12 69 --a------ c:\windows\NeroDigital.ini
2009-02-01 13:54 . 2009-02-01 13:54 <REP> d-------- c:\documents and settings\gege\Application Data\Nero
2009-02-01 13:53 . 2009-02-01 13:53 <REP> d-------- c:\program files\Nero
2009-02-01 13:53 . 2009-02-01 13:54 <REP> d-------- c:\program files\Fichiers communs\Nero
2009-02-01 13:53 . 2009-02-01 13:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Nero
2009-02-01 11:28 . 2009-02-01 11:28 244 --ah----- C:\sqmnoopt00.sqm
2009-02-01 11:28 . 2009-02-01 11:28 232 --ah----- C:\sqmdata00.sqm
2009-02-01 11:23 . 2009-02-01 11:23 <REP> d----c--- c:\windows\system32\DRVSTORE
2009-02-01 11:23 . 2009-02-01 19:50 <REP> d-------- c:\program files\MSN Messenger
2009-02-01 11:23 . 2009-02-01 11:34 <REP> d-------- c:\documents and settings\gege\Contacts
2009-02-01 10:58 . 2009-02-01 10:58 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2009-01-31 16:26 . 2009-01-31 16:26 <REP> d-------- c:\program files\Windows Live SkyDrive
2009-01-31 16:26 . 2009-01-31 16:26 <REP> d-------- c:\program files\Microsoft
2009-01-31 16:25 . 2009-01-31 16:26 <REP> d-------- c:\program files\Windows Live
2009-01-31 16:13 . 2009-01-31 16:13 <REP> d-------- c:\program files\Fichiers communs\Windows Live
2009-01-31 15:38 . 2009-01-31 15:38 <REP> d-------- c:\program files\Eidos
2009-01-31 15:24 . 2009-01-31 15:24 <REP> d-------- c:\windows\system32\LogFiles
2009-01-31 11:37 . 2009-01-31 11:39 <REP> d-------- c:\windows\system32\NtmsData
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-16 10:18 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-14 17:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-01-25 17:49 --------- d-----w c:\program files\Picasa2
2009-01-25 17:48 --------- d-----w c:\program files\Google
2009-01-25 14:03 --------- d-----w c:\program files\ASUS
2009-01-25 14:00 --------- d-----w c:\program files\InterVideo Information Service
2009-01-25 13:59 --------- d-----w c:\program files\InterVideo
2009-01-25 12:41 --------- d-----w c:\program files\NVIDIA Corporation
2009-01-25 12:34 --------- d-----w c:\program files\Analog Devices
2009-01-25 11:24 --------- d-----w c:\program files\VideoLAN
2009-01-25 09:55 --------- d-----w c:\program files\ma-config.com
2009-01-25 09:55 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-01-25 09:31 --------- d-----w c:\program files\Neuf
2009-01-25 09:20 --------- d-----w c:\program files\microsoft frontpage
2009-01-25 09:18 --------- d-----w c:\program files\Services en ligne
2009-01-15 07:19 6,301,248 ------w c:\windows\system32\drivers\nv4_mini.sys
2009-01-15 07:19 6,168,960 ------w c:\windows\system32\nv4_disp.dll
2009-01-15 07:19 290,816 ----a-w c:\windows\system32\nvwrsth.dll
2009-01-14 07:14 3,455,488 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-01-14 05:46 11,591,680 ----a-w c:\windows\system32\atioglxx.dll
2009-01-14 04:53 286,720 ----a-w c:\windows\system32\atiok3x2.dll
2009-01-14 04:47 323,584 ----a-w c:\windows\system32\ati2dvag.dll
2009-01-14 04:36 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-01-14 04:36 196,608 ----a-w c:\windows\system32\atipdlxx.dll
2009-01-14 04:36 151,552 ----a-w c:\windows\system32\Oemdspif.dll
2009-01-14 04:35 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2009-01-14 04:35 155,648 ----a-w c:\windows\system32\ati2evxx.dll
2009-01-14 04:34 598,016 ----a-w c:\windows\system32\ati2evxx.exe
2009-01-14 04:32 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-01-14 04:22 4,009,152 ----a-w c:\windows\system32\ati3duag.dll
2009-01-14 04:05 2,500,224 ----a-w c:\windows\system32\ativvaxx.dll
2009-01-14 03:50 48,640 ----a-w c:\windows\system32\amdpcom32.dll
2009-01-14 03:45 401,408 ----a-w c:\windows\system32\atikvmag.dll
2009-01-14 03:44 17,408 ----a-w c:\windows\system32\atitvo32.dll
2009-01-14 03:44 110,592 ----a-w c:\windows\system32\atiadlxx.dll
2009-01-14 03:43 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-01-14 03:37 577,536 ----a-w c:\windows\system32\ati2cqag.dll
2009-01-14 02:36 45,056 ----a-w c:\windows\system32\amdcalrt.dll
2009-01-14 02:36 45,056 ----a-w c:\windows\system32\amdcalcl.dll
2009-01-14 02:34 3,227,648 ----a-w c:\windows\system32\Amdcaldd.dll
2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
.
------- Sigcheck -------
2004-08-20 00:10 14336 2979b03d5382a602623c0535b16ab9c0 c:\windows\$NtServicePackUninstall$\svchost.exe
2008-04-14 03:34 14336 e4bdf223cd75478bf44567b4d5c2634d c:\windows\ServicePackFiles\i386\svchost.exe
2008-04-14 03:34 14336 e4bdf223cd75478bf44567b4d5c2634d c:\windows\system32\svchost.exe
2005-03-02 19:20 578048 c34920eb988ce98910bd6b0417f334eb c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2005-03-02 19:10 578048 0df75fb73f705b011630159a43d7c354 c:\windows\$NtServicePackUninstall$\user32.dll
2004-08-20 00:09 578048 61c8c283ad063bb697ae61a155c64a5a c:\windows\$NtUninstallKB890859$\user32.dll
2008-04-14 03:33 579584 e853f84d3ce2faa2a802e33cf89ac023 c:\windows\ServicePackFiles\i386\user32.dll
2008-04-14 03:33 579584 e853f84d3ce2faa2a802e33cf89ac023 c:\windows\system32\user32.dll
2004-08-20 00:09 82944 eed74b969b2ca1acc558ff60fb420e28 c:\windows\$NtServicePackUninstall$\ws2_32.dll
2008-04-14 03:33 82432 fb836f9e62d82904c983ad21296a5d9c c:\windows\ServicePackFiles\i386\ws2_32.dll
2008-04-14 03:33 82432 fb836f9e62d82904c983ad21296a5d9c c:\windows\system32\ws2_32.dll
2008-10-16 11:23 671744 f9ae6dbb4ec5b4d1a82bf2f0cb7ee200 c:\windows\$hf_mig$\KB958215\SP2QFE\wininet.dll
2008-10-16 02:01 670208 05033943ff61abd13b93c00337d04e92 c:\windows\$hf_mig$\KB958215\SP3GDR\wininet.dll
2008-10-16 02:04 671232 1c6e9fdab1f4cb983a39efba6f131acc c:\windows\$hf_mig$\KB958215\SP3QFE\wininet.dll
2008-10-16 20:33 827904 37d1a1bfe3d9904f2c3d11592456f9c0 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2004-08-20 00:09 660480 4e958b97efc3d801f49283d1820f48b7 c:\windows\$NtServicePackUninstall$\wininet.dll
2004-08-20 00:09 660480 4e958b97efc3d801f49283d1820f48b7 c:\windows\$NtUninstallKB958215$\wininet.dll
2008-10-16 11:38 663552 4bad064ed3fb5008af94d427dd77fddd c:\windows\ie7\wininet.dll
2007-08-13 18:54 818688 a4a0fc92358f39538a6494c42ef99fe9 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-04-14 03:33 670208 4a6e04ea20f48d750d9bfed8600d516b c:\windows\ServicePackFiles\i386\wininet.dll
2006-06-23 13:28 581120 1f063bdbd1afef9ac0abd02384d40376 c:\windows\SoftwareDistribution\Download\73231fc5e2f4907698b91ecd0c870ff8\rtmgdr\wininet.dll
2006-06-23 20:46 593408 38a54870eced4c83f227a5c4be236709 c:\windows\SoftwareDistribution\Download\73231fc5e2f4907698b91ecd0c870ff8\RTMQFE\wininet.dll
2008-10-16 21:18 826368 cfbfa47415e85018e2cdc509e5e3d011 c:\windows\system32\wininet.dll
2008-10-16 21:18 826368 cfbfa47415e85018e2cdc509e5e3d011 c:\windows\system32\dllcache\wininet.dll
2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2008-06-20 11:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\$NtServicePackUninstall$\tcpip.sys
2004-08-04 07:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB917953$\tcpip.sys
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\dllcache\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\drivers\tcpip.sys
2004-08-20 00:10 506368 123eea158f74d0f67a51dcdf065d1091 c:\windows\$NtServicePackUninstall$\winlogon.exe
2008-04-14 03:34 512000 dd73d6b9f6b4cb630cf35b438b540174 c:\windows\ServicePackFiles\i386\winlogon.exe
2008-04-14 03:34 512000 dd73d6b9f6b4cb630cf35b438b540174 c:\windows\system32\winlogon.exe
2004-08-04 07:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\$NtServicePackUninstall$\ndis.sys
2008-04-13 20:20 182656 1df7f42665c94b825322fae71721130d c:\windows\ServicePackFiles\i386\ndis.sys
2008-04-13 20:20 182656 1df7f42665c94b825322fae71721130d c:\windows\system32\drivers\ndis.sys
2004-08-04 07:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\$NtServicePackUninstall$\ip6fw.sys
2008-04-13 19:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\ServicePackFiles\i386\ip6fw.sys
2008-04-13 19:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\system32\drivers\ip6fw.sys
2005-03-02 19:13 2059008 5311776074b6c13f983dc75baeac9c0c c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2008-08-14 14:39 2065024 dcbc1a6d150b5ee1bd6257186157b0f3 c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 14:23 2068096 8da71f1900721e1e4fcb5b02d55fb771 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 19:26 2068096 755b50949d0dbc0f0136b0db58765331 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2008-08-14 14:44 2017792 7d0242cd4b2242bc766435dc1a1d49fa c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-20 00:04 2017280 35567c8c50986c2bc5c3efd79cb045e4 c:\windows\$NtUninstallKB890859$\ntkrnlpa.exe
2008-04-14 03:07 2025984 92e82482cdb39929cf7b541a9648afae c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 14:23 2068096 8da71f1900721e1e4fcb5b02d55fb771 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-04-14 03:07 2067968 b71a8f101cefaf82fc5ec16130a54a3f c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
2008-08-14 14:23 2025984 f2dec52ed964ad57220b1f5aa32b5c61 c:\windows\system32\ntkrnlpa.exe
2008-08-14 14:23 2068096 8da71f1900721e1e4fcb5b02d55fb771 c:\windows\system32\dllcache\ntkrnlpa.exe
2005-03-02 19:13 2181632 3e2a0a4a0c0b19fc113618a9562a3b2a c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2008-08-14 14:39 2188032 c6649255e51f145b6e15c505ab68e459 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 14:23 2191232 c8d4d5974f9671da0a37175650912960 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 19:26 2191232 d79210549bbf09b7638e860440504299 c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2008-08-14 14:44 2138112 f54f9151170d876d9540cb8021cc83d5 c:\windows\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-20 00:04 2150400 36f32a5a83df734e022734d93860a9a4 c:\windows\$NtUninstallKB890859$\ntoskrnl.exe
2008-04-14 03:07 2147328 b10c36956eb7a8b1586dbe3b43875280 c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 14:23 2191232 c8d4d5974f9671da0a37175650912960 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-04-14 03:08 2191104 099d639da1ef6968d4e41795bb507e6b c:\windows\ServicePackFiles\i386\ntoskrnl.exe
2008-08-14 14:23 2147328 e422f0930804a5d6e697e5d7dbfd9863 c:\windows\system32\ntoskrnl.exe
2008-08-14 14:23 2191232 c8d4d5974f9671da0a37175650912960 c:\windows\system32\dllcache\ntoskrnl.exe
2008-04-14 03:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd c:\windows\explorer.exe
2004-08-20 00:09 1036288 2a7bd330924252a2fd80344fc949bb72 c:\windows\$NtServicePackUninstall$\explorer.exe
2008-04-14 03:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd c:\windows\ServicePackFiles\i386\explorer.exe
2004-08-20 00:10 108544 63dcde1a0d86eeb8924d6738ff616ead c:\windows\$NtServicePackUninstall$\services.exe
2008-04-14 03:34 109056 54cb50058851d95e56ec70d09f70857f c:\windows\ServicePackFiles\i386\services.exe
2008-04-14 03:34 109056 54cb50058851d95e56ec70d09f70857f c:\windows\system32\services.exe
2004-08-20 00:09 13312 259af82a0932eea4f316f92db94707b6 c:\windows\$NtServicePackUninstall$\lsass.exe
2008-04-14 03:34 13312 91e6024d6d4dcdecdb36c43ecf9bbecb c:\windows\ServicePackFiles\i386\lsass.exe
2008-04-14 03:34 13312 91e6024d6d4dcdecdb36c43ecf9bbecb c:\windows\system32\lsass.exe
2004-08-20 00:09 15360 64e41e8fee655b03e3f19ded21ba5118 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2008-04-14 03:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 c:\windows\ServicePackFiles\i386\ctfmon.exe
2008-04-14 03:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 c:\windows\system32\ctfmon.exe
2005-06-11 01:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2005-06-11 00:53 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\$NtServicePackUninstall$\spoolsv.exe
2004-08-20 00:10 57856 df9fc62ad51cb082b0ae371919a232cb c:\windows\$NtUninstallKB896423$\spoolsv.exe
2008-04-14 03:34 57856 460e4ce148bd07218da0b6a3d31885a9 c:\windows\ServicePackFiles\i386\spoolsv.exe
2008-04-14 03:34 57856 460e4ce148bd07218da0b6a3d31885a9 c:\windows\system32\spoolsv.exe
2004-08-20 00:10 25088 84717891f0734c611721f56c60b5fbc3 c:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-14 03:34 26624 e74ddb12188c2ff57a78624dbf7332fc c:\windows\ServicePackFiles\i386\userinit.exe
2008-04-14 03:34 26624 e74ddb12188c2ff57a78624dbf7332fc c:\windows\system32\userinit.exe
2004-08-20 00:09 297984 78f90c3e230ad122bcb116abad5fefe9 c:\windows\$NtServicePackUninstall$\termsrv.dll
2008-04-14 03:33 297984 710bc85a8c22626ee094439e3ea0d38c c:\windows\ServicePackFiles\i386\termsrv.dll
2008-04-14 03:33 297984 710bc85a8c22626ee094439e3ea0d38c c:\windows\system32\termsrv.dll
2006-07-05 11:58 1050112 fb85ef2a6713e3a58a497e093626b93c c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2006-07-05 11:56 1049088 ce4af1fa47a29adf97cb107775ce395c c:\windows\$NtServicePackUninstall$\kernel32.dll
2004-08-20 00:09 1048576 c88f74591579dbde273c61312b2d3886 c:\windows\$NtUninstallKB917422$\kernel32.dll
2008-04-14 03:33 1054720 3ac8886dfa5ab641417df4d3b7f5512e c:\windows\ServicePackFiles\i386\kernel32.dll
2008-04-14 03:33 1054720 3ac8886dfa5ab641417df4d3b7f5512e c:\windows\system32\kernel32.dll
2004-08-20 00:09 17408 29d5e58fb089c41898a81bd4c8970f22 c:\windows\$NtServicePackUninstall$\powrprof.dll
2008-04-14 03:33 17408 9f2c862e39bf8e8fc51c3f6a6bceb415 c:\windows\ServicePackFiles\i386\powrprof.dll
2008-04-14 03:33 17408 9f2c862e39bf8e8fc51c3f6a6bceb415 c:\windows\system32\powrprof.dll
2004-08-20 00:09 110080 e55dafa1a354bd5cb69151563dc9748a c:\windows\$NtServicePackUninstall$\imm32.dll
2008-04-14 03:33 110080 0469b73db32e5520f342c5e163aa3cca c:\windows\ServicePackFiles\i386\imm32.dll
2008-04-14 03:33 110080 0469b73db32e5520f342c5e163aa3cca c:\windows\system32\imm32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Autoconfigurateur WiFi Neuf"="c:\program files\Neuf\Kit\WiFi\9wifi.exe" [2006-12-15 139264]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Hard Disk Sentinel"="c:\program files\Hard Disk Sentinel\HDSentinel.exe" [2009-02-15 3055104]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-16 148888]
"F-Secure Manager"="c:\program files\F-Secure Internet Security\Common\FSM32.EXE" [2008-10-14 182936]
"F-Secure TNB"="c:\program files\F-Secure Internet Security\FSGUI\TNBUtil.exe" [2008-10-14 957024]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.IV41"= ir41_32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 15:35 202024 c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2007-12-15 11:02 482760 c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-04-13 11:09 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 09:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARXP\\FEARXP.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\F-Secure Internet Security\HIPS\drivers\fshs.sys [2008-10-14 66720]
R2 LF30FS;LF30FS;c:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [2004-11-19 101488]
R3 8855;8855;c:\windows\system32\8855.sys [2009-02-17 54624]
R3 ALSysIO;ALSysIO; [x]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-07-02 89600]
R3 cpuz131;cpuz131; [x]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure Internet Security\Anti-Virus\minifilter\fsgk.sys [2008-10-14 72288]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure Internet Security\ORSP Client\fsorsp.exe [2008-10-14 55904]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-01-24 216232]
R3 MEMSWEEP2;MEMSWEEP2; [x]
R4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSfilter.sys [2008-10-14 39776]
R4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure Internet Security\Anti-Virus\Win2K\FSrec.sys [2008-10-14 25184]
S0 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [2008-10-14 79904]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - AVG Anti-Rootkit
*Deregistered* - AvgArCln
*Deregistered* - Beep
*Deregistered* - Cdfs
*Deregistered* - DcomLaunch
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - Fastfat
*Deregistered* - FltMgr
*Deregistered* - FSFW
*Deregistered* - Ftdisk
*Deregistered* - KSecDD
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - rdpdr
*Deregistered* - RpcSs
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - swenum
*Deregistered* - TermDD
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39c03947-eb02-11dd-8078-806d6172696f}]
\Shell\AutoRun\command - E:\Setup.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-LFAgent - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
LSP: c:\program files\F-Secure Internet Security\FSPS\program\FSLSP.DLL
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-17 01:06:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\89.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1454471165-1957994488-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:53,63,b1,9c,0e,fb,d7,82,9e,83,25,51,eb,8c,fb,df,60,37,28,93,4b,ce,c5,
0b,82,5e,93,f3,12,fd,1b,76,16,31,2d,7e,a2,7b,84,6a,e5,b6,fe,fa,6f,fe,b2,52,\
"??"=hex:10,9d,4a,73,d9,b7,d9,6c,3a,f1,5b,9a,d6,ec,3a,cf
[HKEY_USERS\S-1-5-21-1454471165-1957994488-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:c6,7f,3b,a5,41,b3,8c,55,91,4a,6e,e9,8a,a3,34,3a,2a,db,bd,05,18,
2b,06,29,9a,5e,b7,d9,29,5b,c6,05,fd,cc,f7,6e,a9,9d,a7,ec,65,88,7b,c5,2e,2e,\
"rkeysecu"=hex:ce,cb,b9,b2,2d,7c,7d,22,e6,6f,86,9c,f7,fb,e3,c4
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ñw*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(240)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-02-17 2:00:24
ComboFix-quarantined-files.txt 2009-02-17 01:00:23
Avant-CF: 27,638,370,304 octets libres
Après-CF: 28,554,141,696 octets libres
436 --- E O F --- 2009-02-13 22:00:01
merci beaucoup pour ton aide!