Voici pour combofix
ComboFix 09-02-17.02 - florent 2009-02-19 12:49:43.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2037.1259 [GMT 1:00]
Lancé depuis: c:\users\florent\Desktop\outils de réparation\ComboFix.exe
Commutateurs utilisés :: c:\users\florent\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning enabled* (Updated)
FW: Norton Internet Security *enabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BoontyGames
c:\program files\BoontyGames\Components\bureau.url
c:\program files\BoontyGames\Components\Joystick.ico
c:\program files\BoontyGames\Components\start.url
c:\program files\BoontyGames\Squadron\acenet_client_release.exe
c:\program files\BoontyGames\Squadron\acenet_server_release.exe
c:\program files\BoontyGames\Squadron\characters.ini
c:\program files\BoontyGames\Squadron\ecom.ini
c:\program files\BoontyGames\Squadron\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Squadron\joystick.ini
c:\program files\BoontyGames\Squadron\joystickkeys.ini
c:\program files\BoontyGames\Squadron\keyboard.ini
c:\program files\BoontyGames\Squadron\language\english\Menus\images\bt_mission_on.ini
c:\program files\BoontyGames\Squadron\language\english\Menus\images\bt_portrait_on.ini
c:\program files\BoontyGames\Squadron\language\english\Menus\images\classified_mission.ini
c:\program files\BoontyGames\Squadron\language\english\Menus\images\spacer.ini
c:\program files\BoontyGames\Squadron\language\english\strings.ini
c:\program files\BoontyGames\Squadron\maps\archipelago\map.ini
c:\program files\BoontyGames\Squadron\maps\desert2\map.ini
c:\program files\BoontyGames\Squadron\maps\island\map.ini
c:\program files\BoontyGames\Squadron\missions\1\mission.ini
c:\program files\BoontyGames\Squadron\missions\101\mission.ini
c:\program files\BoontyGames\Squadron\missions\102\mission.ini
c:\program files\BoontyGames\Squadron\missions\103\mission.ini
c:\program files\BoontyGames\Squadron\missions\11\mission.ini
c:\program files\BoontyGames\Squadron\missions\12\mission.ini
c:\program files\BoontyGames\Squadron\missions\13\mission.ini
c:\program files\BoontyGames\Squadron\missions\14\mission.ini
c:\program files\BoontyGames\Squadron\missions\15\mission.ini
c:\program files\BoontyGames\Squadron\missions\2\mission.ini
c:\program files\BoontyGames\Squadron\missions\21\mission.ini
c:\program files\BoontyGames\Squadron\missions\22\mission.ini
c:\program files\BoontyGames\Squadron\missions\23\mission.ini
c:\program files\BoontyGames\Squadron\missions\24\mission.ini
c:\program files\BoontyGames\Squadron\missions\25\mission.ini
c:\program files\BoontyGames\Squadron\missions\3\mission.ini
c:\program files\BoontyGames\Squadron\missions\31\mission.ini
c:\program files\BoontyGames\Squadron\missions\32\mission.ini
c:\program files\BoontyGames\Squadron\missions\33\mission.ini
c:\program files\BoontyGames\Squadron\missions\34\mission.ini
c:\program files\BoontyGames\Squadron\missions\35\mission.ini
c:\program files\BoontyGames\Squadron\missions\41\mission.ini
c:\program files\BoontyGames\Squadron\missions\42\mission.ini
c:\program files\BoontyGames\Squadron\missions\43\mission.ini
c:\program files\BoontyGames\Squadron\missions\44\mission.ini
c:\program files\BoontyGames\Squadron\missions\45\mission.ini
c:\program files\BoontyGames\Squadron\missions\51\mission.ini
c:\program files\BoontyGames\Squadron\missions\52\mission.ini
c:\program files\BoontyGames\Squadron\missions\61\mission.ini
c:\program files\BoontyGames\Squadron\modem.bat
c:\program files\BoontyGames\Squadron\mouse.ini
c:\program files\BoontyGames\Squadron\mousekeys.ini
c:\program files\BoontyGames\Squadron\music.ini
c:\program files\BoontyGames\Squadron\objects\ground\aagun\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\aagunruin\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Africanwell\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\ammodump\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Bighanger\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\bighangerburn\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\bridge\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\canyonaagun\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\cottage\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\cottage2\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Deserthouse1\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Deserthouse2\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Desertset1\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Desertset2\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Deserttent\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Factory\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Factory_burned\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Farmbarn\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Germantank\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Hanger\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\hangerburned\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\house1\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\house2\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\jetty\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Lookouttower\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\lshapedvilla\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\m_aagun\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\m_canyonaagun\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\m_pickuphealth\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\m_pickupnitro\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\m_pickuprockets\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Mosque\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Oildrum\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\oilrig\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\oilrigburn\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Palmtree\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Palmtree2\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\palmtree3\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\pickupbombs\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\pickuphealth\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\pickupnitro\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\pickuprepair\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\pickuprockets\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Prisonbuilding\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\Prisonbuildingburn\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\rowhouses\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\shrapnel\shrapnel.ini
c:\program files\BoontyGames\Squadron\objects\ground\takeoffpoint\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Tank\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\Tent\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\tree1\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\tree1_burned\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\TREE2\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\tree3\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\tree4\GROUND.INI
c:\program files\BoontyGames\Squadron\objects\ground\tree6\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\van\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\villachurch\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\villahouse\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\villaset\ground.ini
c:\program files\BoontyGames\Squadron\objects\ground\wheelgun\ground.ini
c:\program files\BoontyGames\Squadron\objects\ordinance\ordinance.ini
c:\program files\BoontyGames\Squadron\objects\particles\lensflare.ini
c:\program files\BoontyGames\Squadron\objects\planes\aircodh2\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\albertross\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\bristolscout\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\fokkertriplane\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\gothaGIV\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\halberstadt\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\handleypage\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\junkers\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multiaircodh2\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multifokkertriplane\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multigothaGIV\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multihalberstadt\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multihandleypage\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multijunkers\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multisopwithcamel\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\multispadx111\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\nieuport17\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\playernieuport17\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singleaircodh2\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlealbertross\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlebristolscout\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlefokkertriplane\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlegothaGIV\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlehalberstadt\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlehandleypage\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlejunkers\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlesopwithcamel\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\singlespadx111\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\sopwithcamel\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\spadx111\plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\traininghalberstadt\Plane.ini
c:\program files\BoontyGames\Squadron\objects\planes\trainingjunkers\Plane.ini
c:\program files\BoontyGames\Squadron\redace.ini
c:\program files\BoontyGames\Squadron\SHELL_DEFAULT_HTML\js\ShellScripts.js
c:\program files\BoontyGames\Squadron\sound\AircodMeta.ini
c:\program files\BoontyGames\Squadron\sound\AircodMetaAI.ini
c:\program files\BoontyGames\Squadron\sound\AlbertrossMeta.ini
c:\program files\BoontyGames\Squadron\sound\AlbertrossMetaAI.ini
c:\program files\BoontyGames\Squadron\sound\AmmoMeta.ini
c:\program files\BoontyGames\Squadron\sound\BoostMeta.ini
c:\program files\BoontyGames\Squadron\sound\BristolMeta.ini
c:\program files\BoontyGames\Squadron\sound\BuildExp.ini
c:\program files\BoontyGames\Squadron\sound\channels.ini
c:\program files\BoontyGames\Squadron\sound\EarthHit.ini
c:\program files\BoontyGames\Squadron\sound\EnemyPlaneHit.ini
c:\program files\BoontyGames\Squadron\sound\FarGrndExpl.ini
c:\program files\BoontyGames\Squadron\sound\FokkerMeta.ini
c:\program files\BoontyGames\Squadron\sound\GothaMeta.ini
c:\program files\BoontyGames\Squadron\sound\GothaMetaAI.ini
c:\program files\BoontyGames\Squadron\sound\HalberMeta.ini
c:\program files\BoontyGames\Squadron\sound\HandleyPageMeta.ini
c:\program files\BoontyGames\Squadron\sound\HandleyPageMetaAI.ini
c:\program files\BoontyGames\Squadron\sound\HealthMeta.ini
c:\program files\BoontyGames\Squadron\sound\JunkersMeta.ini
c:\program files\BoontyGames\Squadron\sound\MenuFocus.ini
c:\program files\BoontyGames\Squadron\sound\MenuMeta.ini
c:\program files\BoontyGames\Squadron\sound\MetalImpact.ini
c:\program files\BoontyGames\Squadron\sound\MetalImpactMeta.ini
c:\program files\BoontyGames\Squadron\sound\MetalRoofImpact.ini
c:\program files\BoontyGames\Squadron\sound\MetalRoofMeta.ini
c:\program files\BoontyGames\Squadron\sound\NieuportMeta.ini
c:\program files\BoontyGames\Squadron\sound\PlaneImpactMeta.ini
c:\program files\BoontyGames\Squadron\sound\Rico.ini
c:\program files\BoontyGames\Squadron\sound\SopwithMeta.ini
c:\program files\BoontyGames\Squadron\sound\sounds.ini
c:\program files\BoontyGames\Squadron\sound\SpadX111Meta.ini
c:\program files\BoontyGames\Squadron\sound\SpadX111MetaAI.ini
c:\program files\BoontyGames\Squadron\sound\StoneImpact.ini
c:\program files\BoontyGames\Squadron\sound\StoneImpactMeta.ini
c:\program files\BoontyGames\Squadron\sound\TreeExplode.ini
c:\program files\BoontyGames\Squadron\sound\TreeHit.ini
c:\program files\BoontyGames\Squadron\sound\WoodImpact.ini
c:\program files\BoontyGames\Squadron\SpMU.lnk
c:\program files\BoontyGames\Squadron\texden.ini
c:\program files\BoontyGames\Squadron\Ui\cursor.ini
c:\program files\BoontyGames\Squadron\unins000.exe
c:\program files\BoontyGames\Strategic Command\Campaign Editor.exe
c:\program files\BoontyGames\Strategic Command\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Strategic Command\Inf\combat.inf
c:\program files\BoontyGames\Strategic Command\Inf\terrain.inf
c:\program files\BoontyGames\Strategic Command\Inf\unit.inf
c:\program files\BoontyGames\Strategic Command\SC.exe
c:\program files\BoontyGames\Strategic Command\SC.ini
c:\program files\BoontyGames\Strategic Command\SC_g.exe
c:\program files\BoontyGames\Strategic Command\SHELL_DEFAULT_HTML\js\ShellScripts.js
c:\program files\BoontyGames\Strategic Command\SpMU.lnk
c:\program files\BoontyGames\Strategic Command\unins000.exe
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DIFxAPI.dll
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\DifXInstall64.exe
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\GEARAspiWDM.inf
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\gearaspiwdmx64.cat
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\x64\GEARAspi.dll
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\x64\GEARAspi64.dll
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x64\x64\GEARAspiWDM.sys
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\GEARAspiWDM.inf
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\gearaspiwdmx86.cat
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll
c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-19 au 2009-02-19 ))))))))))))))))))))))))))))))))))))
.
2009-02-18 19:42 . 2009-02-18 19:42 <REP> d-------- C:\rsit
2009-02-18 14:59 . 2009-02-18 14:59 <REP> d----c--- c:\windows\System32\DRVSTORE
2009-02-18 14:59 . 2008-04-17 13:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2009-02-18 14:59 . 2008-04-17 13:12 15,464 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2009-02-18 14:35 . 2009-02-18 16:29 <REP> d-------- c:\program files\Norton 360
2009-02-18 14:32 . 2009-02-18 14:37 123,952 --a------ c:\windows\System32\drivers\SYMEVENT.SYS
2009-02-18 14:32 . 2009-02-18 14:37 10,563 --a------ c:\windows\System32\drivers\SYMEVENT.CAT
2009-02-18 14:32 . 2009-02-18 14:37 805 --a------ c:\windows\System32\drivers\SYMEVENT.INF
2009-02-18 14:16 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-18 14:16 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-18 14:16 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-18 14:16 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-18 14:16 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-18 14:07 . 2009-02-18 14:53 <REP> d-------- c:\users\florent\AppData\Roaming\Symantec
2009-02-17 19:46 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-17 19:46 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-17 19:24 . 2009-02-17 19:31 <REP> d-a------ c:\users\All Users\TEMP
2009-02-17 19:24 . 2009-02-17 19:31 <REP> d-a------ c:\programdata\TEMP
2009-02-17 19:01 . 2009-02-18 19:42 <REP> d-------- c:\program files\Trend Micro
2009-02-09 20:35 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-09 20:35 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-09 20:35 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-09 20:35 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-09 20:35 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-09 20:35 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-09 20:34 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-09 20:34 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-09 20:09 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-09 20:09 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-09 20:09 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-09 20:09 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-09 20:09 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-09 19:08 . 2007-12-11 20:22 65,536 --a------ c:\windows\System32\Autodial2000.dll
2009-02-09 19:07 . 2009-02-09 19:57 <REP> d-------- c:\program files\OrangeHSS
2009-02-07 14:43 . 2009-02-07 14:43 <REP> d-------- c:\program files\Common Files\xing shared
2009-01-31 12:13 . 2006-11-28 20:24 167,936 --a------ c:\windows\System32\igfxres.dll
2009-01-28 15:08 . 2009-01-28 15:08 <REP> d-------- c:\windows\Sun
2009-01-20 23:03 . 2009-02-18 23:20 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-20 23:03 . 2009-01-20 23:03 1,409 --a------ c:\windows\QTFont.for
2009-01-19 19:04 . 2009-01-19 19:04 <REP> d-------- c:\users\florent\AppData\Roaming\vlc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-19 11:37 --------- d-----w c:\users\florent\AppData\Roaming\OpenOffice.org2
2009-02-18 14:00 --------- d-----w c:\programdata\Symantec
2009-02-18 13:40 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-18 13:37 --------- d-----w c:\program files\Symantec
2009-02-18 13:17 --------- d-----w c:\program files\Windows Mail
2009-02-17 18:08 --------- d-----w c:\program files\Windows Live Toolbar
2009-02-17 18:08 --------- d-----w c:\program files\Google
2009-02-09 20:49 --------- d-----w c:\users\florent\AppData\Roaming\LimeWire
2009-02-07 13:43 --------- d-----w c:\program files\Common Files\Real
2009-02-03 16:15 --------- d-----w c:\users\florent\AppData\Roaming\dvdcss
2009-01-18 12:49 --------- d-----w c:\programdata\UniversalisV10
2009-01-18 12:49 --------- d-----w c:\programdata\HP Product Assistant
2009-01-11 11:00 --------- d-----w c:\users\florent\AppData\Roaming\Image Zone Express
2009-01-06 17:48 --------- d-----w c:\programdata\WindowsSearch
2009-01-03 17:52 --------- d-----w c:\program files\Microsoft Silverlight
2009-01-02 13:37 --------- d-----w c:\program files\VideoLAN
2008-12-05 18:23 326,656 ----a-w c:\windows\System32\actxprxy.dll
2008-07-26 12:09 174 --sha-w c:\program files\desktop.ini
2008-08-01 12:25 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-08-01 12:25 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-08-01 12:25 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-02-18_22.26.19.80 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-18 21:13:25 167,696 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-02-19 11:38:00 167,696 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-02-18 21:14:37 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-19 11:39:33 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-18 21:14:37 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-19 11:39:33 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-18 21:17:37 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-19 11:41:06 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-02-18 21:17:46 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-19 11:41:53 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-19 11:41:53 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-18 20:42:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-19 11:45:13 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-18 20:42:42 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-19 11:45:13 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-18 20:42:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-19 11:45:13 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-18 21:20:37 11,884 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-925658876-164935754-3953589676-1000_UserData.bin
+ 2009-02-19 11:42:12 11,884 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-925658876-164935754-3953589676-1000_UserData.bin
- 2009-02-18 21:20:37 80,258 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-19 11:42:12 80,338 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-18 20:46:22 63,128 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-19 11:42:10 63,580 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-10-31 12:24 576352 --a------ c:\program files\Common Files\Symantec Shared\Backup\buShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-11-24 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-19 411768]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-02-06 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-01-17 534648]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-11-01 438272]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-01-13 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-01-13 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-01-13 81920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-28 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-28 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-28 81920]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-02-13 405504]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-19 227840]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-02-18 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 c:\windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
Hyperappel de l'Encyclop‚die Universelle Larousse.lnk - c:\program files\Larousse\Encyclop‚die Universelle Larousse\bin\hyperappel.exe [2007-11-25 53248]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.l3codec"= l3codecp.acm
[HKLM\~\startupfolder\C:^Users^florent^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.2.lnk]
path=c:\users\florent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.2.lnk
backup=c:\windows\pss\OpenOffice.org 2.2.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Desktop SMS]
--a------ 2007-01-19 13:25 1507328 c:\program files\IDM\Desktop SMS\DesktopSMS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-09-19 21:12 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-11-24 22:03 171448 c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2009-02-07 14:43 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\topi]
--a------ 2007-03-02 14:10 577536 c:\program files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
--a------ 2007-02-19 15:00 571024 c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{34879E72-745D-43BB-8363-D081463AFE08}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{63A0A4CD-8506-4BAF-B55C-4CA7B3EF9490}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{E1D93FBE-A68B-4070-B90B-A9019B1B37B1}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{9ED187BB-DF81-48C6-BB9B-01929C529407}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"TCP Query User{24FE297F-E492-4237-9316-63E4F3C4379E}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= UDP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"UDP Query User{C5861700-B366-4F65-BE7C-738AAA71151C}c:\\program files\\webmediaplayer\\webmediaplayer.exe"= TCP:c:\program files\webmediaplayer\webmediaplayer.exe:WebMediaPlayer
"{0922065C-97BC-48C4-ABD1-9DC7A32656F0}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{B32CC631-615E-4145-9571-9C663DC22DA2}c:\\users\\florent\\appdata\\locallow\\powerchallenge\\powersoccer\\powersoccer.exe"= UDP:c:\users\florent\appdata\locallow\powerchallenge\powersoccer\powersoccer.exe:powersoccer.exe
"UDP Query User{DB6D2DCB-72CE-462A-800B-388585714D32}c:\\users\\florent\\appdata\\locallow\\powerchallenge\\powersoccer\\powersoccer.exe"= TCP:c:\users\florent\appdata\locallow\powerchallenge\powersoccer\powersoccer.exe:powersoccer.exe
"TCP Query User{75CB0CE6-97A2-47E0-AAD6-26C851BE907C}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{3F72FC74-2D11-4670-9A7B-FC040393FAE7}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090129.001\IDSvix86.sys [2009-02-18 270384]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-18 99376]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2008-02-05 41008]
S2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\System32\drivers\adildr.sys [2007-09-22 56088]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [2008-01-12 23888]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-08-30 28224]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Une-cle-pour-demarrer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{283763a5-2183-11dd-9721-001b381c0900}]
\shell\AutoRun\command - G:\Euphytose.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{570f6058-c7aa-11dd-be73-001b381c0900}]
\shell\AutoRun\command - G:\Une-cle-pour-demarrer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{788d2d96-a045-11dc-a49b-001b381c0900}]
\shell\Auto\command - wscript "esta ig.vbs"
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "esta ig.vbs"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ddc544b-669f-11dc-94f7-001b381c0900}]
\shell\AutoRun\command - D:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94eb7b94-b14f-11dd-9107-806e6f6e6963}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dce6236e-7ab2-11dd-94e4-001b381c0900}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs
.
Contenu du dossier 'Tâches planifiées'
2009-02-18 c:\windows\Tasks\User_Feed_Synchronization-{11B8D3A8-5017-47E3-B055-1BD1B37E79A5}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
.
------- Examen supplémentaire -------
.
uStart Page = www.orange.fr
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-19 12:54:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-02-19 12:56:25
ComboFix-quarantined-files.txt 2009-02-19 11:55:46
ComboFix2.txt 2009-02-18 21:27:20
Avant-CF: 28 193 665 024 octets libres
Après-CF: 28,060,532,736 octets libres
471 --- E O F --- 2009-02-19 00:23:02