ComboFix 09-05-25.05 - Aurel 26/05/2009 3:23.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2044 [GMT 2:00]
Lancé depuis: c:\users\Aurel\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\Aurel\Desktop\CFScript.txt
AV: Antivirus BitDefender *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Pare-feu BitDefender *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: BitDefender AntiSpam *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
FILE ::
c:\program files\websrvx\websrvx.exe
c:\users\Aurel\AppData\Local\hpqjss.bat
c:\windows\sto453165.dat
c:\windows\sto453601.dat
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Aurel\AppData\Local\hpqjss.bat
c:\windows\sto453165.dat
c:\windows\sto453601.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_websrvx
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-26 au 2009-05-26 ))))))))))))))))))))))))))))))))))))
.
2009-05-26 01:25 . 2009-05-26 01:26 -------- d-----w c:\users\Aurel\AppData\Local\temp
2009-05-25 18:36 . 2009-05-25 18:36 -------- d-----w c:\program files\Microsoft
2009-05-25 18:35 . 2009-05-25 18:35 -------- d-----w c:\windows\PCHEALTH
2009-05-25 11:20 . 2009-05-25 11:20 -------- d-----w c:\program files\CCleaner
2009-05-22 08:51 . 2009-05-22 08:52 -------- d-----w C:\rsit
2009-05-19 17:16 . 2009-05-20 23:05 -------- d-----w c:\program files\Ad-remover
2009-05-18 10:19 . 2009-05-18 10:19 -------- d-----w c:\users\Aurel\AppData\Roaming\Malwarebytes
2009-05-18 10:19 . 2009-05-18 10:19 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-18 10:19 . 2009-05-18 10:19 -------- d-----w c:\programdata\Malwarebytes
2009-05-17 21:40 . 2009-05-17 21:40 -------- d-----w c:\program files\Trend Micro
2009-05-17 20:21 . 2009-05-21 23:51 -------- d-----w c:\program files\Common Files\PC Tools
2009-05-17 20:17 . 2009-05-21 23:52 -------- d-----w c:\program files\Spyware Doctor
2009-05-17 17:44 . 2009-05-25 18:44 -------- d-----w c:\programdata\Spybot - Search & Destroy
2009-05-17 17:44 . 2009-05-17 21:50 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-05-17 00:16 . 2009-05-17 18:14 81984 ----a-w c:\windows\system32\bdod.bin
2009-05-16 23:41 . 2009-05-17 18:16 -------- d-----w c:\program files\BitDefender
2009-05-16 23:39 . 2009-05-17 18:17 -------- d-----w c:\program files\Common Files\BitDefender
2009-05-16 23:16 . 2009-05-16 23:16 -------- d-----w c:\windows\BDOSCAN8
2009-05-15 00:01 . 2009-04-14 00:39 4656976 ----a-w c:\programdata\Microsoft\Windows Defender\Definition Updates\{83706AED-7792-420A-94F0-F3BE42A78695}\mpengine.dll
2009-05-13 05:36 . 2009-05-13 05:36 -------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-05-13 05:33 . 2009-05-13 17:02 -------- d-----w c:\program files\World of Warcraft
2009-05-10 23:25 . 2009-05-10 23:25 -------- d-----w c:\users\Aurel\WoW-BurningCrusade-frFR-Full-Installer
2009-05-10 23:25 . 2009-05-10 23:25 -------- d-----w c:\users\Aurel\WoW-2.0.0-frFR-Installer
2009-05-01 13:07 . 2009-05-13 16:04 -------- d-----w c:\users\Aurel\AppData\Roaming\teamspeak2
2009-05-01 13:07 . 2009-05-01 13:07 -------- d-----w c:\program files\Teamspeak2_RC2
2009-04-28 11:10 . 2009-04-28 11:10 -------- d-----w c:\users\Aurel\AppData\Roaming\Apple Computer
2009-04-28 11:10 . 2009-04-28 11:10 -------- d-----w c:\users\Aurel\AppData\Local\Apple Computer
2009-04-28 11:10 . 2009-03-19 14:32 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-28 11:10 . 2008-04-17 10:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-04-28 11:10 . 2009-04-28 11:10 -------- d-----w c:\program files\iPod
2009-04-28 11:10 . 2009-04-28 11:10 -------- d-----w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-28 11:10 . 2009-04-28 11:10 -------- d-----w c:\program files\iTunes
2009-04-28 11:02 . 2009-04-28 11:10 -------- d-----w c:\programdata\Apple Computer
2009-04-28 11:02 . 2009-04-28 11:02 -------- d-----w c:\program files\QuickTime
2009-04-28 11:01 . 2009-04-28 11:01 -------- d-----w c:\users\Aurel\AppData\Local\Apple
2009-04-28 11:01 . 2009-04-28 11:01 -------- d-----w c:\program files\Apple Software Update
2009-04-28 11:00 . 2009-04-28 11:10 -------- d-----w c:\program files\Common Files\Apple
2009-04-28 11:00 . 2009-04-28 11:00 -------- d-----w c:\programdata\Apple
2009-04-26 17:28 . 2009-04-26 17:28 -------- d-----w c:\program files\Mumble
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 01:26 . 2008-10-04 15:20 -------- d-----w c:\program files\Norman
2009-05-25 23:48 . 2008-10-04 17:54 -------- d-----w c:\program files\Steam
2009-05-25 22:08 . 2009-04-15 13:00 -------- d-----w c:\programdata\Google Updater
2009-05-25 18:36 . 2008-10-04 17:14 -------- d-----w c:\program files\Windows Live
2009-05-25 18:22 . 2008-10-04 17:13 -------- d-----w c:\programdata\WLInstaller
2009-05-24 12:02 . 2008-01-21 08:40 669890 ----a-w c:\windows\system32\perfh00C.dat
2009-05-24 12:02 . 2008-01-21 08:40 123896 ----a-w c:\windows\system32\perfc00C.dat
2009-05-22 20:48 . 2008-10-04 17:54 -------- d-----w c:\program files\Common Files\Steam
2009-05-17 19:13 . 2009-04-15 13:36 -------- d-----w c:\program files\Disk Cleaner
2009-05-17 00:08 . 2008-10-11 11:18 -------- d-----w c:\users\Aurel\AppData\Roaming\OpenOffice.org2
2009-05-17 00:04 . 2008-10-11 11:19 1 ----a-w c:\users\Aurel\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-05-16 11:27 . 2008-06-24 02:00 -------- d-----w c:\program files\Common Files\Adobe
2009-05-13 09:11 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-28 10:38 . 2008-10-26 17:37 -------- d-----w c:\program files\Winamp
2009-04-27 17:59 . 2008-10-04 15:18 -------- d-----w c:\program files\Google
2009-04-15 13:36 . 2009-04-15 13:36 -------- d-----w c:\programdata\Disk Cleaner
2009-04-09 17:03 . 2009-04-09 17:02 -------- d-----w c:\program files\EPSON
2009-04-06 09:40 . 2008-12-26 00:31 -------- d-----w c:\program files\Image-Line
2009-04-06 09:39 . 2009-03-02 12:38 -------- d-----w c:\program files\BitTorrent
2009-04-04 10:45 . 2008-10-11 10:41 -------- d-----w c:\program files\Java
2009-04-02 14:29 . 2009-04-02 14:29 75048 ----a-w c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-19 14:32 . 2009-03-19 14:32 23400 ----a-w c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-17 03:38 . 2009-04-15 13:42 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 13:42 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-13 15:08 . 2009-03-13 15:08 684872 ----a-w c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-03-09 03:19 . 2008-11-26 15:12 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-05-10 17:23 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-05-10 17:23 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-10 17:23 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-10 17:23 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-10 17:23 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-10 17:23 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-10 17:23 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-10 17:23 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-10 17:23 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-10 17:23 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-10 17:23 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-10 17:23 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-10 17:23 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-10 17:23 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-10 17:23 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-10 17:23 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-10 17:23 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-10 17:23 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-15 13:42 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 13:42 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 13:42 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 13:42 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 13:42 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 13:42 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 13:42 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 13:42 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 13:42 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 13:42 17408 ----a-w c:\windows\system32\iashost.exe
2009-03-05 16:08 . 2009-05-16 23:59 49664 ----a-w c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-23_19.11.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-14 10:46 . 2009-05-25 17:54 39660 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2008-01-21 01:58 . 2009-05-25 17:57 57450 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-05-25 17:57 96128 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-10-04 15:24 . 2009-05-25 17:57 13572 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2906897876-258636576-2234130964-1000_UserData.bin
+ 2009-02-06 16:52 . 2009-02-06 16:52 49504 c:\windows\System32\sirenacm.dll
- 2008-10-04 14:14 . 2009-05-23 18:44 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-04 14:14 . 2009-05-25 22:08 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-10-04 14:14 . 2009-05-23 18:44 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-04 14:14 . 2009-05-25 22:08 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-04 14:14 . 2009-05-25 22:08 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-10-04 14:14 . 2009-05-23 18:44 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-05-25 18:36 . 2009-05-25 18:36 62304 c:\windows\Installer\{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}\IconWlc.exe
+ 2009-05-24 22:59 . 2009-05-24 22:59 58945 c:\windows\Installer\{63DC2DA0-2A6C-4C38-9249-B75395458657}\wlmail.exe
- 2009-01-02 15:36 . 2009-01-02 15:36 58945 c:\windows\Installer\{63DC2DA0-2A6C-4C38-9249-B75395458657}\wlmail.exe
- 2009-01-02 15:36 . 2009-01-02 15:36 80395 c:\windows\Installer\{059C042E-796A-4ACC-A81A-ECC2010BB78C}\MsblIco.Exe
+ 2009-05-25 18:36 . 2009-05-25 18:36 80395 c:\windows\Installer\{059C042E-796A-4ACC-A81A-ECC2010BB78C}\MsblIco.Exe
+ 2009-05-24 23:47 . 2009-05-24 23:47 47616 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\f0940934a3aa33b7671f416206a76c03\WindowsLiveWriter.ni.exe
+ 2009-05-24 23:48 . 2009-05-24 23:48 99840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1b63823a5b3ae8aa81cb94997db390ab\WindowsLive.Writer.Api.ni.dll
+ 2008-10-04 16:31 . 2009-05-25 00:35 252970 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
- 2006-11-02 10:33 . 2009-05-17 20:21 587484 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-05-24 12:02 587484 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-05-17 20:21 101556 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-05-24 12:02 101556 c:\windows\System32\perfc009.dat
+ 2009-05-10 17:28 . 2009-05-25 17:58 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-05-10 17:28 . 2009-05-23 18:44 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-05-24 23:48 . 2009-05-24 23:48 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\a362ea14c0fe23d4f2aea8ec021f0d3e\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\dff83a93cfce38247be2ac2e0a8785a9\WindowsLive.Writer.BrowserControl.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 334848 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\db7a09cf44aa9b0d0e57ddee3762ab1a\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 108544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b58392b9d39e8daf17f3bd78ab1147d0\WindowsLive.Writer.Passport.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 322048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\93193886e8077ef3c8de1ea5f0edd7f8\WindowsLive.Writer.SpellChecker.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 319488 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\84e8e405b3075006fb93c866af02c63c\WindowsLive.Writer.Interop.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 117760 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7db7da9911abb2aa8a4e94ef744e7586\WindowsLive.Writer.Instrumentation.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 152064 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\56771dc2fe172f871091c71ac3a561c2\WindowsLive.Writer.HtmlParser.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\423d86baaaa446228fc3205bd0671318\WindowsLive.Writer.FileDestinations.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 851968 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3c0571b569bad5e54a9932c8a898107e\WindowsLive.Writer.BlogClient.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 258048 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2e9d7206e575145912ce8aa61b211d77\WindowsLive.Writer.Mshtml.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 594944 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\20fb431e55c3f27ad51498fe55d37ae4\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 428032 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1c76889f6da313c75b11eaf60461c82e\WindowsLive.Writer.Localization.ni.dll
+ 2009-05-24 23:47 . 2009-05-24 23:47 843776 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\[u]0
/u521176f85dd52cee07fb05917197f4f\WindowsLive.Writer.Controls.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 118784 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\[u]0
/u1ac4b7ff5021dad8a2a4ca560e4b2d7\WindowsLive.Writer.Extensibility.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 145920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\b6c3541e8a9df4ddbd720eb4c4dfd5e8\WindowsLive.Client.ni.dll
+ 2006-11-02 10:22 . 2009-05-26 01:25 6262784 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-05-26 01:25 . 2009-05-26 01:25 6262784 c:\windows\ERDNT\subs\schema.dat
+ 2009-05-26 01:22 . 2009-05-26 01:22 6262784 c:\windows\ERDNT\Hiv-backup\schema.dat
+ 2009-05-24 23:48 . 2009-05-24 23:48 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ce1b4192a4cf7472f1755e3aaee3aef3\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2009-05-24 23:48 . 2009-05-24 23:48 2002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\99870d72535ce9a8c53ac80236c675c4\WindowsLive.Writer.CoreServices.ni.dll
+ 2009-05-24 23:47 . 2009-05-24 23:47 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2a806fa96e3330a853ef9834dffdebf4\WindowsLive.Writer.PostEditor.ni.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"recinfo"="c:\recinfo\recinfo.exe" [2008-02-13 52224]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 533264]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"Norman ZANDA"="c:\program files\Norman\Npm\Bin\ZLH.EXE" [2008-06-02 277616]
"Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"fsc-reg"="c:\programdata\fsc-reg\fscreg.exe" [2007-11-08 533264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9CED427E-AC35-4525-81B9-D296FB698991}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{6C766915-DE83-4A74-8E40-94B876A64731}"= TCP:c:\program files\DNA\btdna.exe:DNA
"TCP Query User{A145DBDE-E42F-436A-AFCB-B67FA0894778}c:\\users\\aurel\\program files\\dna\\btdna.exe"= UDP:c:\users\aurel\program files\dna\btdna.exe:btdna.exe
"UDP Query User{DD366BC5-8764-4789-B6C5-6EBC6C3E84AC}c:\\users\\aurel\\program files\\dna\\btdna.exe"= TCP:c:\users\aurel\program files\dna\btdna.exe:btdna.exe
"TCP Query User{651D20E9-4855-494D-B3D2-26576AF63435}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\counter-strike source\hl2.exe:hl2
"UDP Query User{67989C9B-C9DB-4A5F-9FC2-1D5767926201}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\counter-strike source\hl2.exe:hl2
"TCP Query User{E702F6E2-DEF0-4A70-A927-E0D0451F8138}c:\\users\\aurel\\program files\\dna\\btdna.exe"= UDP:c:\users\aurel\program files\dna\btdna.exe:btdna.exe
"UDP Query User{418DB7BA-9D36-441B-96D3-F756AB0913B3}c:\\users\\aurel\\program files\\dna\\btdna.exe"= TCP:c:\users\aurel\program files\dna\btdna.exe:btdna.exe
"TCP Query User{FBA9C4BA-524F-4A7C-A45D-1AFE36DED9C1}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\counter-strike source\hl2.exe:hl2
"UDP Query User{4B3017A0-A0C2-44B4-BFF1-83315B449A15}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\counter-strike source\hl2.exe:hl2
"TCP Query User{6E58E269-EE17-4CA3-8FAD-3E5E006359F9}c:\\users\\aurel\\desktop\\installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe"= UDP:c:\users\aurel\desktop\installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe:installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe
"UDP Query User{7EB16D15-8CC5-43AA-A391-1F4AFA8E585E}c:\\users\\aurel\\desktop\\installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe"= TCP:c:\users\aurel\desktop\installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe:installer-5455-855fr-dragon-ball-z-mugen-edition-french.exe
"{F025745F-EF0A-4C88-9294-F756E7BDF2FA}"= UDP:c:\users\Aurel\Desktop\ryzom_setup_637.exe:ryzom_setup_637
"{B3E5327A-7211-4744-803C-5CE164076E36}"= TCP:c:\users\Aurel\Desktop\ryzom_setup_637.exe:ryzom_setup_637
"{32F95859-D470-434D-B20F-45AB33076565}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{DE76DE22-79DE-4421-9C5B-3DB9B004737C}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"TCP Query User{56EA9734-B3B8-427D-BAB4-50BE372EFD10}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{652EC79C-5ADE-401E-A188-80F4D865CA26}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
"{63DD92E2-E956-4723-A6EB-751724C0010D}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{47BF5687-7DA2-4E75-AEAC-65F1C3B04F92}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{0FDAB811-DD1C-43CD-8EDF-5DB3ED4E5016}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{EE0BB61A-EB4B-4743-BA51-174499F4FD1A}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{DEE70723-E45F-4C9E-B45C-02B75CC55EF3}"= UDP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{B997FE00-30C3-4EC7-8F3C-4478518161B3}"= TCP:c:\program files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{2AA49430-2327-4454-88D3-3EB1AFB68F5A}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{4F423FC3-AD5F-4393-970D-2B986CC76949}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{4B5AEE6A-72E3-4715-88A9-EBF0E46CB9D7}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{94A809C0-3340-4CA1-B39B-42B57A371B4A}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{C72FE8F5-822E-44CF-8482-CCB68A39E463}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{D8F4A150-3E63-4D01-89EF-43772D607CA2}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"TCP Query User{0103E31B-5358-4CB5-934B-78EDDD8BAB33}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{2EE93E8C-18C6-45D3-A914-86295F0D1AF6}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"TCP Query User{272C8B21-C146-49BA-B2FD-8BBED9F5516A}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\age of chivalry\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\age of chivalry\hl2.exe:hl2
"UDP Query User{5277FA2B-0BDD-459C-980E-07961F9665C8}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\age of chivalry\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\age of chivalry\hl2.exe:hl2
"TCP Query User{7533ED7C-A206-4F04-A051-820E67ABE272}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\source sdk base\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\source sdk base\hl2.exe:hl2
"UDP Query User{DC72CF3A-AE7B-4021-920F-CEACC11A5C1A}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\source sdk base\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\source sdk base\hl2.exe:hl2
"TCP Query User{A6502C23-5A18-4C53-B566-737C62F6D7FD}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\zombie panic! source\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\zombie panic! source\hl2.exe:hl2
"UDP Query User{5E3DD2BC-87C3-4DCF-8CDA-55CB1F5BAE26}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\zombie panic! source\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\zombie panic! source\hl2.exe:hl2
"TCP Query User{AE46CBA2-50B4-4C22-9D8D-F94B15AD8723}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\insurgency\\hl2.exe"= UDP:c:\program files\steam\steamapps\patafucka_noobkiller\insurgency\hl2.exe:hl2
"UDP Query User{B9AC7AFC-B28D-48AE-9E63-B9FD405FD26C}c:\\program files\\steam\\steamapps\\patafucka_noobkiller\\insurgency\\hl2.exe"= TCP:c:\program files\steam\steamapps\patafucka_noobkiller\insurgency\hl2.exe:hl2
"{0C10CBA2-C9D0-424F-ADD4-46FD64B66A73}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{625CC581-0221-4D77-BF3D-FF21D6B8E94E}"= TCP:c:\program files\Steam\Steam.exe:Steam
"TCP Query User{88629E3C-E8E4-4657-8EDF-135872AB95F2}c:\\program files\\ubisoft\\gearbox software\\brothersinarmseib\\system\\eib.exe"= UDP:c:\program files\ubisoft\gearbox software\brothersinarmseib\system\eib.exe:Brothers In Arms Earned In Blood
"UDP Query User{E35E1B1D-216D-4D06-8559-D73B88196359}c:\\program files\\ubisoft\\gearbox software\\brothersinarmseib\\system\\eib.exe"= TCP:c:\program files\ubisoft\gearbox software\brothersinarmseib\system\eib.exe:Brothers In Arms Earned In Blood
"TCP Query User{07BBF629-56E6-48F1-8E9A-EDB9F75C0470}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex00.489\\freezer v1.4 fr\\freezer.exe"= UDP:c:\users\aurel\appdata\local\temp\rar$ex00.489\freezer v1.4 fr\freezer.exe:freezer.exe
"UDP Query User{D8CA61C5-E346-4E00-9072-B383CFA203F7}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex00.489\\freezer v1.4 fr\\freezer.exe"= TCP:c:\users\aurel\appdata\local\temp\rar$ex00.489\freezer v1.4 fr\freezer.exe:freezer.exe
"TCP Query User{C91CC548-6A60-4B65-8124-604428BCE463}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex24.162\\freezer v1.4 fr\\freezer.exe"= UDP:c:\users\aurel\appdata\local\temp\rar$ex24.162\freezer v1.4 fr\freezer.exe:freezer.exe
"UDP Query User{84C3490C-8A84-4A07-A288-67DE99C08674}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex24.162\\freezer v1.4 fr\\freezer.exe"= TCP:c:\users\aurel\appdata\local\temp\rar$ex24.162\freezer v1.4 fr\freezer.exe:freezer.exe
"TCP Query User{3458DF03-B6F4-4C38-9285-C688A519C9B0}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex00.087\\freezer v1.4 fr\\freezer.exe"= UDP:c:\users\aurel\appdata\local\temp\rar$ex00.087\freezer v1.4 fr\freezer.exe:freezer.exe
"UDP Query User{E7BE3D21-4ED6-46B3-876D-3FB4F4344338}c:\\users\\aurel\\appdata\\local\\temp\\rar$ex00.087\\freezer v1.4 fr\\freezer.exe"= TCP:c:\users\aurel\appdata\local\temp\rar$ex00.087\freezer v1.4 fr\freezer.exe:freezer.exe
"TCP Query User{92239223-D863-4574-8737-36DC8E9E063F}c:\\users\\aurel\\desktop\\freezer.exe"= UDP:c:\users\aurel\desktop\freezer.exe:freezer.exe
"UDP Query User{486FB1A2-1695-40AD-AD5B-59DBDFA22DB9}c:\\users\\aurel\\desktop\\freezer.exe"= TCP:c:\users\aurel\desktop\freezer.exe:freezer.exe
"{01551691-66D3-4323-832C-B8F6487CE6CC}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{8B4E6D51-17A0-4B3E-A883-F776E2DECB88}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{6ECE563E-0CEF-48EE-89E8-EEA41519B616}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{A9BE94F7-C0AF-4A48-9275-C695C10F789E}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{76B30015-3D5B-42B3-918D-B106B2B7825E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{AFB85A9C-314C-4C1A-9285-89C3E32F58F4}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{D92A3B89-046F-4F25-B8A7-F63A720FA8FC}c:\\users\\aurel\\desktop\\wowq(2).exe"= UDP:c:\users\aurel\desktop\wowq(2).exe:wowq(2).exe
"UDP Query User{8BE3361B-CAFB-4DB6-B10B-15C68F681DAE}c:\\users\\aurel\\desktop\\wowq(2).exe"= TCP:c:\users\aurel\desktop\wowq(2).exe:wowq(2).exe
"TCP Query User{A3FD7E88-AB6B-4D7F-B607-E3CDD18BBA91}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{3A755155-BB7C-40C7-889C-5D51475E23FB}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{5FD13D13-25D8-442C-9A98-478FB30F328A}c:\\users\\aurel\\desktop\\wowbc.exe"= UDP:c:\users\aurel\desktop\wowbc.exe:wowbc.exe
"UDP Query User{EBD60558-6692-4E12-B4BA-409E1C26E77E}c:\\users\\aurel\\desktop\\wowbc.exe"= TCP:c:\users\aurel\desktop\wowbc.exe:wowbc.exe
"{5BDB9AE0-2179-456C-BC04-B8E9A623F094}"= UDP:3724:port 3724
"{73DE668B-D763-4B7F-8B4B-488F91C28D9D}"= UDP:6112:port 6112
"TCP Query User{E444299A-986A-4B21-9AB6-D207AF4EABD0}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{FD623031-047C-45CD-AB94-F24E41C00250}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"{520B5F26-5809-4CDD-BD51-D02BAEDD944B}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{A31B253A-D61C-4DC5-A5AC-0EB25EC76EDD}"= UDP:c:\program files\Windows Live\Messenger\wlcstart.exe:Windows Live Call
"{45E9E1C2-CF89-4B62-AF0E-1907319F69D1}"= TCP:c:\program files\Windows Live\Messenger\wlcstart.exe:Windows Live Call
"{7C9B8798-3B86-43D5-9BDC-471CE11CB613}"= UDP:c:\program files\Windows Live\Mail\wlmail.exe:Windows Live Mail
"{2FF968E8-F70D-4DB3-BA5B-81CF71E5C382}"= TCP:c:\program files\Windows Live\Mail\wlmail.exe:Windows Live Mail
"{61310982-FEF7-48F2-82F7-58BEC6072400}"= UDP:c:\program files\Windows Live\Photo Gallery\MovieMaker.Exe:Windows Live Movie Maker Bêta
"{749ADAD8-A7FA-4F7F-968C-E99B72080CA3}"= TCP:c:\program files\Windows Live\Photo Gallery\MovieMaker.Exe:Windows Live Movie Maker Bêta
"{ADB135AC-B9EA-49EF-9AE2-502D9854DC89}"= UDP:c:\program files\Windows Live\Writer\WindowsLiveWriter.exe:Windows Live Writer
"{98310D30-707F-400D-934C-DBD6CE0F8292}"= TCP:c:\program files\Windows Live\Writer\WindowsLiveWriter.exe:Windows Live Writer
"{7B8DE98A-91F5-4603-A71E-A45402B2ED5B}"= UDP:c:\program files\Windows Mail\WinMail.exe:Windows Mail
"{B0A5CD37-CF2F-4605-A805-821DFE214A5C}"= TCP:c:\program files\Windows Mail\WinMail.exe:Windows Mail
"{B724C66F-41EF-4499-996D-CE8AF7B3F519}"= UDP:c:\windows\ehome\ehshell.exe:Windows Media Center
"{EF3E7982-8CAD-482A-9A3C-514E13AEF2B7}"= TCP:c:\windows\ehome\ehshell.exe:Windows Media Center
"{42403714-7DFA-4AE5-9158-3E152FE74668}"= UDP:c:\program files\Movie Maker\MOVIEMK.exe:Windows Movie Maker
"{6258ECA2-FC1E-4E42-8B91-E8EAD807514D}"= TCP:c:\program files\Movie Maker\MOVIEMK.exe:Windows Movie Maker
"{94BFDD91-22E6-429B-AE78-78F8B73ACECC}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 NVOY;Norman's Very Own supplY of resources;c:\program files\Norman\Npm\Bin\nvoy.exe [04/10/2008 17:20 121912]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [17/05/2009 19:44 1153368]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [24/06/2008 03:54 46592]
R3 NVCScheduler;Norman Virus Control Scheduler;c:\program files\Norman\Npm\Bin\nvcsched.exe [04/10/2008 17:20 154680]
S3 RescueDrv;Inventel Access Point USB Rescue Driver;c:\windows\System32\drivers\resc_dwb.sys [05/01/2009 12:47 74828]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-05-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-15 13:00]
2009-05-25 c:\windows\Tasks\User_Feed_Synchronization-{0B95B891-2A7B-4F46-9D97-B92956F3159D}.job
- c:\windows\system32\msfeedssync.exe [2009-05-10 11:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=FUJD&bmod=FUJD
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\users\Aurel\AppData\Roaming\Mozilla\Firefox\Profiles\44g8omsl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-26 03:27
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2906897876-258636576-2234130964-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:be,52,ac,9e,38,76,fb,45,3b,86,8e,a6,65,e5,11,f9,02,49,7d,bb,bf,b2,2a,
5f,c9,f5,00,df,57,03,43,bf,d4,65,c0,a5,b3,a9,98,c8,a9,32,cc,e3,02,2d,c8,2d,\
"??"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0
/u000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Norman\Npm\Bin\elogsvc.exe
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Norman\Npm\Bin\Zanda.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe
c:\program files\Norman\Npm\Bin\Njeeves.exe
c:\windows\System32\conime.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Heure de fin: 2009-05-26 3:32 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-26 01:32
ComboFix2.txt 2009-05-23 19:14
Avant-CF: 16 876 048 384 octets libres
Après-CF: 16 490 967 040 octets libres
370 --- E O F --- 2009-05-14 10:46