ComboFix 09-04-25.A3 - Dimitri 25/04/2009 23:26.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.1790.745 [GMT 2:00]
Lancé depuis: c:\users\Dimitri\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\gxvxctuwcmocpsbtrptioabiknsxegoxjmpwr.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcveomorybsvtpsvuqeniteqtemdputbnt.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-25 au 2009-4-25 ))))))))))))))))))))))))))))))))))))
.
2009-04-25 10:55 . 2009-04-25 12:49 -------- d-----w c:\program files\a-squared Anti-Malware
2009-04-25 09:38 . 2009-02-13 09:31 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-25 09:38 . 2009-04-25 09:38 -------- d-----w c:\users\All Users\Avira
2009-04-25 09:38 . 2009-04-25 09:38 -------- d-----w c:\programdata\Avira
2009-04-25 09:38 . 2009-04-25 09:38 -------- d-----w c:\program files\Avira
2009-04-24 18:36 . 2009-04-24 18:36 691 ----a-w c:\users\Dimitri\AppData\Roaming\GetValue.vbs
2009-04-24 18:36 . 2009-04-24 18:36 35 ----a-w c:\users\Dimitri\AppData\Roaming\SetValue.bat
2009-04-24 17:27 . 2009-04-24 17:27 -------- d-----w c:\program files\trend micro
2009-04-24 17:27 . 2009-04-24 17:27 -------- d-----w C:\rsit
2009-04-19 21:35 . 2009-04-25 09:06 -------- d--h--w C:\$AVG8.VAULT$
2009-04-16 18:50 . 2009-04-25 09:32 -------- d-----w c:\users\All Users\avg8
2009-04-16 18:50 . 2009-04-25 09:32 -------- d-----w c:\programdata\avg8
2009-04-16 18:49 . 2009-04-16 18:49 -------- d-----w c:\program files\AVG
2009-04-10 13:25 . 2009-04-10 13:25 -------- d-----w c:\program files\Eidos
2009-04-10 13:09 . 2009-04-10 13:09 -------- d-----w c:\users\Dimitri\AppData\Roaming\DAEMON Tools Pro
2009-04-10 13:09 . 2009-04-10 13:09 -------- d-----w c:\users\Dimitri\AppData\Roaming\DAEMON Tools
2009-04-10 13:08 . 2009-04-10 13:08 -------- d-----w c:\users\All Users\DAEMON Tools Lite
2009-04-10 13:08 . 2009-04-10 13:08 -------- d-----w c:\programdata\DAEMON Tools Lite
2009-04-10 13:08 . 2009-04-10 13:08 -------- d-----w c:\program files\DAEMON Tools Lite
2009-04-10 13:01 . 2009-04-10 13:01 717296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-10 13:00 . 2009-04-10 13:22 -------- d-----w c:\users\Dimitri\AppData\Roaming\DAEMON Tools Lite
2009-04-08 20:46 . 2009-04-08 20:46 -------- d-----w c:\program files\FLV Player
2009-04-08 20:42 . 2009-04-08 20:42 -------- d-----w c:\users\Dimitri\AppData\Roaming\DivX
2009-04-08 18:59 . 2009-04-08 18:59 -------- d-----w c:\program files\Common Files\PX Storage Engine
2009-04-08 18:59 . 2009-04-08 18:59 -------- d-----w c:\program files\Common Files\DivX Shared
2009-04-08 18:59 . 2009-04-08 19:00 -------- d-----w c:\program files\DivX
2009-04-07 20:28 . 2009-04-07 20:28 -------- d-----w c:\windows\Sun
2009-04-07 20:10 . 2009-04-07 20:10 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-07 20:10 . 2009-04-07 20:10 -------- d-----w c:\program files\Java
2009-04-07 20:07 . 2009-04-07 20:07 -------- d-----w c:\windows\system32\Adobe
2009-04-07 17:42 . 2009-03-19 14:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-07 17:42 . 2008-04-17 10:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-04-07 17:41 . 2009-04-07 17:41 -------- d-----w c:\program files\iPod
2009-04-07 17:41 . 2009-04-07 17:42 -------- d-----w c:\users\All Users\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 17:41 . 2009-04-07 17:42 -------- d-----w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-07 17:41 . 2009-04-07 17:42 -------- d-----w c:\program files\iTunes
2009-04-05 21:00 . 2009-04-08 20:47 -------- d-----w c:\users\Dimitri\dwhelper
2009-04-01 18:15 . 2009-04-25 21:15 -------- d-----w c:\users\Dimitri\Tracing
2009-04-01 17:49 . 2009-04-01 17:49 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-04-01 17:47 . 2009-04-01 17:47 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-01 17:34 . 2009-04-01 17:34 268 ---ha-w C:\sqmdata14.sqm
2009-04-01 17:34 . 2009-04-01 17:34 244 ---ha-w C:\sqmnoopt14.sqm
2009-04-01 17:29 . 2009-04-01 17:29 -------- d-----w c:\program files\Common Files\Windows Live
2009-04-01 12:26 . 2009-04-01 12:26 268 ---ha-w C:\sqmdata13.sqm
2009-04-01 12:26 . 2009-04-01 12:26 244 ---ha-w C:\sqmnoopt13.sqm
2009-03-29 17:20 . 2009-03-30 12:47 107888 ----a-w c:\windows\system32\CmdLineExt.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 21:17 . 2008-08-21 13:16 713304 ----a-w c:\windows\System32\perfh00C.dat
2009-04-25 21:17 . 2008-08-21 13:16 143336 ----a-w c:\windows\System32\perfc00C.dat
2009-04-25 10:16 . 2009-04-24 18:14 688 ----a-w C:\rapport.txt
2009-04-24 18:36 . 2008-08-21 03:58 -------- d-----w c:\program files\Google
2009-04-16 18:44 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-16 18:44 . 2008-08-21 04:01 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-16 18:41 . 2008-08-21 04:05 -------- d-----w c:\programdata\Microsoft Help
2009-04-16 18:33 . 2008-08-21 04:01 -------- d-----w c:\programdata\Symantec
2009-04-16 18:32 . 2006-11-02 10:25 86016 ----a-w c:\windows\Inf\infstrng.dat
2009-04-16 18:32 . 2006-11-02 10:25 86016 ----a-w c:\windows\Inf\infstor.dat
2009-04-16 18:32 . 2006-11-02 10:25 51200 ----a-w c:\windows\Inf\infpub.dat
2009-04-10 13:26 . 2008-08-21 03:51 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-07 17:41 . 2009-01-15 19:50 -------- d-----w c:\program files\Common Files\Apple
2009-04-01 17:50 . 2009-01-15 20:51 -------- d-----w c:\program files\Windows Live
2009-04-01 17:48 . 2009-01-23 16:19 -------- d-----w c:\program files\Microsoft
2009-03-30 16:34 . 2009-01-15 22:48 -------- d-----w c:\programdata\SimCity Societies
2009-03-17 18:29 . 2009-03-12 21:00 -------- d-----w c:\program files\tarot_eval 2.0
2009-03-17 03:38 . 2009-04-16 18:21 40960 ----a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-16 18:21 13824 ----a-w c:\windows\System32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 18:21 24064 ----a-w c:\windows\System32\amxread.dll
2009-03-15 22:21 . 2009-03-15 22:21 268 ---ha-w C:\sqmdata12.sqm
2009-03-15 22:21 . 2009-03-15 22:21 244 ---ha-w C:\sqmnoopt12.sqm
2009-03-12 21:06 . 2009-03-12 21:06 -------- d-----w c:\programdata\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-12 21:05 . 2009-03-12 21:04 -------- d-----w c:\program files\QuickTime
2009-03-12 21:00 . 2009-03-12 21:00 290816 ------w c:\windows\Setup1.exe
2009-03-12 21:00 . 2009-03-12 21:00 74752 ----a-w c:\windows\ST6UNST.EXE
2009-03-12 20:41 . 2009-03-12 20:41 -------- d-----w c:\program files\Jeux de cartes
2009-03-09 18:08 . 2009-03-03 17:10 7592 ----a-w c:\users\Dimitri\AppData\Local\d3d9caps.dat
2009-03-05 22:59 . 2009-03-05 22:59 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-05 22:59 . 2009-03-05 22:59 1900544 ----a-w c:\windows\System32\usbaaplrc.dll
2009-03-03 04:46 . 2009-04-16 18:21 3599328 ----a-w c:\windows\System32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 18:21 3547632 ----a-w c:\windows\System32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-16 18:21 827392 ----a-w c:\windows\System32\wininet.dll
2009-03-03 04:39 . 2009-04-16 18:21 183296 ----a-w c:\windows\System32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 18:21 551424 ----a-w c:\windows\System32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 18:21 26112 ----a-w c:\windows\System32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 18:21 78336 ----a-w c:\windows\System32\ieencode.dll
2009-03-03 04:37 . 2009-04-16 18:21 98304 ----a-w c:\windows\System32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 18:21 54784 ----a-w c:\windows\System32\iasads.dll
2009-03-03 04:37 . 2009-04-16 18:21 44032 ----a-w c:\windows\System32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 18:21 666624 ----a-w c:\windows\System32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 18:21 17408 ----a-w c:\windows\System32\iashost.exe
2009-03-03 02:28 . 2009-04-16 18:21 26624 ----a-w c:\windows\System32\ieUnatt.exe
2009-02-27 19:21 . 2009-02-27 19:21 268 ---ha-w C:\sqmdata11.sqm
2009-02-27 19:21 . 2009-02-27 19:21 244 ---ha-w C:\sqmnoopt11.sqm
2009-02-27 16:05 . 2009-02-27 16:05 268 ---ha-w C:\sqmdata10.sqm
2009-02-27 16:05 . 2009-02-27 16:05 244 ---ha-w C:\sqmnoopt10.sqm
2009-02-27 13:44 . 2009-01-18 19:35 146 ----a-w c:\users\Dimitri\AppData\Roaming\wklnhst.dat
2009-02-27 13:44 . 2009-01-18 19:36 -------- d-----w c:\users\Dimitri\AppData\Roaming\Template
2009-02-27 13:27 . 2009-01-23 16:18 -------- d-----w c:\program files\Microsoft Silverlight
2009-02-26 17:01 . 2009-02-26 17:01 268 ---ha-w C:\sqmdata09.sqm
2009-02-26 17:01 . 2009-02-26 17:01 244 ---ha-w C:\sqmnoopt09.sqm
2009-02-24 19:35 . 2009-01-18 19:24 129784 ------w c:\windows\System32\pxafs.dll
2009-02-24 19:35 . 2009-01-18 19:24 120056 ------w c:\windows\System32\pxcpyi64.exe
2009-02-24 19:35 . 2009-01-18 19:24 118520 ------w c:\windows\System32\pxinsi64.exe
2009-02-24 19:34 . 2009-02-24 19:34 90112 ----a-w c:\windows\System32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\System32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 ----a-w c:\windows\System32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 ----a-w c:\windows\System32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 ----a-w c:\windows\System32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 ----a-w c:\windows\System32\DivX.dll
2009-02-21 13:34 . 2009-02-21 13:34 268 ---ha-w C:\sqmdata08.sqm
2009-02-21 13:34 . 2009-02-21 13:34 244 ---ha-w C:\sqmnoopt08.sqm
2009-02-19 21:30 . 2009-02-19 21:30 268 ---ha-w C:\sqmdata07.sqm
2009-02-19 21:30 . 2009-02-19 21:30 244 ---ha-w C:\sqmnoopt07.sqm
2009-02-18 21:43 . 2009-02-18 21:43 268 ---ha-w C:\sqmdata06.sqm
2009-02-18 21:43 . 2009-02-18 21:43 244 ---ha-w C:\sqmnoopt06.sqm
2009-02-17 22:15 . 2009-02-17 22:15 268 ---ha-w C:\sqmdata05.sqm
2009-02-17 22:15 . 2009-02-17 22:15 244 ---ha-w C:\sqmnoopt05.sqm
2009-02-16 21:49 . 2009-02-16 21:49 268 ---ha-w C:\sqmdata04.sqm
2009-02-16 21:49 . 2009-02-16 21:49 244 ---ha-w C:\sqmnoopt04.sqm
2009-02-15 21:47 . 2009-02-15 21:47 268 ---ha-w C:\sqmdata03.sqm
2009-02-15 21:47 . 2009-02-15 21:47 244 ---ha-w C:\sqmnoopt03.sqm
2009-02-15 18:51 . 2009-02-15 18:51 268 ---ha-w C:\sqmdata02.sqm
2009-02-15 18:51 . 2009-02-15 18:51 244 ---ha-w C:\sqmnoopt02.sqm
2009-02-13 08:49 . 2009-04-16 18:21 72704 ----a-w c:\windows\System32\secur32.dll
2009-02-13 08:49 . 2009-04-16 18:21 1255936 ----a-w c:\windows\System32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 18:54 2033152 ----a-w c:\windows\System32\win32k.sys
2009-02-06 17:39 . 2009-02-06 17:39 308600 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 16:52 . 2009-02-06 16:52 49504 ----a-w c:\windows\System32\sirenacm.dll
2009-01-30 16:02 . 2009-01-30 16:02 268 ---ha-w C:\sqmdata01.sqm
2009-01-30 16:02 . 2009-01-30 16:02 244 ---ha-w C:\sqmnoopt01.sqm
2009-01-30 15:52 . 2009-01-30 15:52 268 ---ha-w C:\sqmdata00.sqm
2009-01-30 15:52 . 2009-01-30 15:52 244 ---ha-w C:\sqmnoopt00.sqm
2009-01-18 19:29 . 2009-01-15 17:46 71256 ----a-w c:\users\Dimitri\AppData\Local\GDIPFONTCACHEV1.DAT
2009-01-17 15:29 . 2009-01-17 15:29 95 ----a-w c:\users\Dimitri\AppData\Local\fusioncache.dat
2008-01-21 02:57 . 2006-11-02 12:48 174 --sha-w c:\program files\desktop.ini
2009-02-24 19:2009-02-24 19:34 34:32 . c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:2009-02-24 19:34 34:32 . c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-01-25 22:2009-01-25 22:19 19:03 . c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-08-21 13:34 . 2008-08-21 13:20 8192 --sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2008-02-04 1038136]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-04-28 1828136]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2009-01-15 91440]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2009-01-20 2523960]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-25 24064]
"PCMAgent"="c:\program files\CyberLink\PowerCinema\PCMAgent.exe" [2008-03-21 143360]
"CLMLServer"="c:\program files\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe" [2008-04-11 196608]
"PlayMovie"="c:\program files\CyberLink\PlayMovie\PMVService.exe" [2008-03-31 172032]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-10-02 67488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 92704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-07 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-07 6139904]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-01-23 101136]
c:\users\Dimitri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de notification Live Search.lnk - c:\users\Dimitri\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe [2009-1-15 143360]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Canon LBP5000 Fenˆtre d'‚tat.lnk - c:\windows\System32\spool\drivers\w32x86\3\CNAC4LAK.EXE [2009-1-30 50848]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-1-15 91440]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-15 688128]
R‚glages souris Labtec.lnk - c:\program files\Labtec Laser Mouse Software\MulMouse.exe [2009-1-25 266240]
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2007-4-29 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6EDE0952-34D7-4F6D-B2AB-87969C8372E6}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{97C3A485-8384-43B3-A39B-04A283EA2277}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EC007582-EBFF-4A96-92F5-27E27ADD5478}"= c:\program files\CyberLink\PowerCinema\PowerCinema.exe:CyberLink PowerCinema
"{00B2DB3D-1C03-4EDA-8142-8D23A358A3D6}"= c:\program files\CyberLink\PowerCinema\PCMService.exe:CyberLink PowerCinema Resident Program
"{168BBA7A-7B9F-48BD-A703-0C53FA77A3CF}"= c:\program files\CyberLink\PowerCinema\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{2249A77F-141C-4C88-B229-F96EEFB18520}"= c:\program files\CyberLink\PowerCinema\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{7F5081FB-6562-46E0-82A6-3A978B3C8116}"= c:\program files\CyberLink\PlayMovie\PlayMovie.exe:CyberLink PlayMovie
"{90E7DE21-DD1C-4BE8-A205-A7131E7BC260}"= c:\program files\CyberLink\PlayMovie\PMVService.exe:CyberLink PlayMovie Resident Program
"{1426B37A-3675-43D4-820F-66BDA4E3BF79}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{057DB74C-3F61-4730-8EF2-EE0503F11EF2}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{B7CBD772-24C6-48F6-AE02-315C63FEF1F9}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{2CE81030-2D93-4CD8-9A24-50AEB5940514}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{8379941A-63E8-4AE4-9908-F941DE011747}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{9A9E17AD-FA8C-4A18-9C5C-D14BDBA26363}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{461C5C96-DCD8-4C5C-A813-D93DB196C64D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{7CCBEB34-58E7-4AB6-943A-B4B0C05C5A41}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{E244532B-5060-4352-95BA-37C69EC4B6CB}"= UDP:16943:BitComet 16943 TCP
"{AF23B2AD-8AD5-4B7E-9151-352BDF86630C}"= TCP:16943:BitComet 16943 UDP
"{6338F603-17E7-43A2-8152-42E6C9E03AD3}"= UDP:c:\windows\System32\CNAC4RPK.EXE:Canon LBP5000 RPC Server Process
"{6B671326-00C9-47CD-8CE1-46D689F37E50}"= TCP:c:\windows\System32\CNAC4RPK.EXE:Canon LBP5000 RPC Server Process
"{7886637A-0176-4A99-AF51-BA601E02D850}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{EFF04463-FBAB-41E5-A1C0-118439B8D08A}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{664D1E0A-F140-46EB-A40D-9F547303EA77}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
R3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-01-25 24064]
R3 PsSdk31;PsSdk31;c:\windows\system32\Drivers\pssdk31.drv [2009-01-21 30272]
R3 PsSdkLBF;PsSdkLBF;c:\windows\system32\Drivers\pssdklbf.drv [2009-01-21 37440]
S1 MUsbFltr;WayTechUSBFilterDrive; [x]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\CyberLink\PlayMovie\[u]0
/u00.fcl [2008-03-31 08:52 41456]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-10-02 124832]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\system32\DRIVERS\RTL8187B.sys [2007-07-18 281088]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e09c1337-e329-11dd-a95a-806e6f6e6963}]
\shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e795c71a-25cf-11de-b352-0021971dd4f0}]
\shell\AutoRun\command - E:\autorun.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-25 c:\windows\Tasks\Extension de garantie-Dimitri.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-08-21 10:13]
2009-04-25 c:\windows\Tasks\Recovery DVD Creator-Dimitri.job
- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-08-21 10:13]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-SmartFlip - c:\users\Dimitri\Downloads\smartflip_smartflip_0.8_beta_2_anglais_33580\SmartFlip.exe
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Tout télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Télécharger avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Télécharger toutes les vidéos avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Dimitri\AppData\Roaming\Mozilla\Firefox\Profiles\8bmxa36f.default\
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-25 23:29
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\Dimitri\AppData\Local\Temp\gxvxc000 0 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gxvxcserv.sys]
"imagepath"="\systemroot\system32\drivers\gxvxchknrbeejsdnwmxiroibhfqpxdrrsipxl.sys"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk31]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdk31.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdkLBF]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdklbf.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\CyberLink\PlayMovie\[u]0
/u00.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gxvxcserv.sys]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\gxvxchknrbeejsdnwmxiroibhfqpxdrrsipxl.sys"
.
Heure de fin: 2009-04-25 23:31
ComboFix-quarantined-files.txt 2009-04-25 21:31
Avant-CF: 158 435 975 168 octets libres
Après-CF: 158 606 176 256 octets libres
319 --- E O F --- 2009-04-24 18:53