voila le rapport mais j ai tout reactiver pour me connecter:
ComboFix 09-05-17.08 - moi 18/05/2009 18:35.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.2047.1090 [GMT 2:00]
Lancé depuis: c:\users\moi\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part01.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part02.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part03.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part04.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part05.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part06.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part07.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part08.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part09.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part10.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part11.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part12.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part13.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part14.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part15.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part16.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part17.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part18.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part19.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part20.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part21.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part22.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part23.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part24.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part25.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part26.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part27.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part28.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part29.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part30.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part31.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part32.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part33.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part34.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part35.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part36.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part37.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part38.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part39.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part40.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part41.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part42.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part43.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part44.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\B-13 - U.(PROPER).CAM.FRENCH.MD.XviD.KiNG.part45.rar
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RLBQ8YB.com]\info.htm
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RQANQNI.Samurai-Resurrection[2009]DvDrip-aXXo\Afro.Samurai-Resurrection[2009]DvDrip-aXXo.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RQANQNI.Samurai-Resurrection[2009]DvDrip-aXXo\afro.samurai.resurrection-aXXo.nfo
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x01.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x02.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x03.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x04.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x05.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x06.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x07.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x08.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x09.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x10.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x11.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\[u]0
/u4x12.avi
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RRRWKZ7\Thumbs.db
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RSX2R2M\Thumbs.db
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Cache\global_cache.bin
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Cache\login_cache.bin
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\configuration.lua
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\LogFiles\datacrc.2008-10-26.11-10-07.txt
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2100-2101_Patch.exe
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2100-2101_Patch.exe.resume
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2101_2201_Patch.exe
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2101_2201_Patch.exe.resume
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2201_2202_Patch.exe
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2201_2202_Patch.exe.resume
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2202_2300_Patch.exe
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2202_2300_Patch.exe.resume
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2300_2301_Patch.exe
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\Patch\EN_2300_2301_Patch.exe.resume
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\playback\temp.rec
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\playercfg.lua
c:\$recycle.bin\S-1-5-21-1423327921-1584481737-2649443580-1000\$RWK6YL3\warnings.log
c:\recycler\S-1-0-61-100014566-100007737-100032677-7036.com
c:\users\moi\AppData\Local\ceagy.dat
c:\users\moi\AppData\Local\ceagy_nav.dat
c:\users\moi\AppData\Local\ceagy_navps.dat
c:\windows\system32\drivers\gxvxctctmsqxeuwbsnxmrrnlgepdtiubdaxoj.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcecyxvqvxrscvhxfetekfqoadvbfvmtip.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-18 au 2009-05-18 ))))))))))))))))))))))))))))))))))))
.
2009-05-17 06:28 . 2009-05-17 06:28 -------- d-----w c:\program files\HDQuality
2009-05-08 10:39 . 2009-03-24 14:07 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-08 10:39 . 2009-05-08 10:39 -------- d-----w c:\program files\Avira
2009-05-02 14:23 . 2009-05-02 17:35 -------- d-----w c:\users\moi\AppData\Roaming\DivX
2009-05-02 14:21 . 2009-05-02 14:44 -------- d-----w c:\program files\Common Files\PX Storage Engine
2009-05-02 14:20 . 2009-05-02 14:21 -------- d-----w c:\program files\Common Files\DivX Shared
2009-05-02 14:20 . 2009-05-08 10:14 -------- d-----w c:\program files\DivX
2009-04-25 17:43 . 2009-04-28 15:34 -------- d-----w c:\program files\GameSpy Arcade
2009-04-25 13:21 . 2009-04-25 18:13 -------- d-----w c:\program files\Codemasters
2009-04-25 12:56 . 2009-04-25 12:56 -------- d-----w c:\program files\PlayLogic
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-18 16:31 . 2008-01-21 07:23 669328 ----a-w c:\windows\system32\perfh00C.dat
2009-05-18 16:31 . 2008-01-21 07:23 123350 ----a-w c:\windows\system32\perfc00C.dat
2009-05-17 14:30 . 2009-03-26 15:37 -------- d-----w c:\program files\Windows Live Safety Center
2009-05-13 04:54 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-05-02 17:38 . 2008-10-11 14:27 -------- d-----w c:\program files\Winamp
2009-04-25 14:07 . 2008-10-04 18:10 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-25 08:12 . 2008-12-27 15:50 -------- d-----w c:\program files\Vuze
2009-04-19 05:32 . 2008-11-05 17:26 -------- d-----w c:\program files\Free Video Converter
2009-04-15 20:25 . 2008-10-04 19:50 129784 ------w c:\windows\system32\pxafs.dll
2009-04-15 20:25 . 2008-10-04 19:50 118520 ------w c:\windows\system32\pxinsi64.exe
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w c:\windows\system32\DivX.dll
2009-04-07 15:07 . 2008-10-04 18:14 -------- d-----w c:\program files\IDT
2009-04-06 16:23 . 2008-12-12 15:36 -------- d-----w c:\program files\Java
2009-04-04 22:19 . 2009-03-26 16:07 86 ----a-w c:\users\moi\AppData\Local\ceagy.bat
2009-04-04 05:27 . 2009-04-04 05:27 0 ----a-w c:\users\All Users\xmlF073.tmp
2009-04-04 05:27 . 2009-04-04 05:27 0 ----a-w c:\programdata\xmlF073.tmp
2009-04-04 05:27 . 2009-02-15 20:24 1801 ----a-w c:\users\All Users\xml1411.tmp
2009-04-04 05:27 . 2009-02-15 20:24 1801 ----a-w c:\programdata\xml1411.tmp
2009-04-04 05:27 . 2009-02-15 20:24 0 ----a-w c:\users\All Users\xml12E6.tmp
2009-04-04 05:27 . 2009-02-15 20:24 0 ----a-w c:\programdata\xml12E6.tmp
2009-04-04 05:27 . 2009-02-15 20:24 9017 ----a-w c:\users\All Users\xml1008.tmp
2009-04-04 05:27 . 2009-02-15 20:24 9017 ----a-w c:\programdata\xml1008.tmp
2009-03-27 06:14 . 2008-10-25 17:19 453152 ----a-w c:\windows\system32\NVUNINST.EXE
2009-03-26 17:48 . 2009-03-26 16:07 -------- d-----w c:\program files\Free Download Manager
2009-03-22 16:23 . 2009-03-22 16:23 -------- d-----w c:\program files\AMD
2009-03-22 16:23 . 2008-10-25 17:20 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-17 03:38 . 2009-04-16 16:09 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 16:09 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-09 03:19 . 2008-12-25 20:03 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-04-11 07:27 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-11 07:27 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-11 07:27 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-11 07:27 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-11 07:27 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-11 07:27 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-11 07:27 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-11 07:27 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-11 07:27 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-11 07:27 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-11 07:27 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-11 07:27 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-11 07:27 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-11 07:27 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-11 07:27 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-11 07:27 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-04-11 07:27 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-04-11 07:27 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-03 04:46 . 2009-04-16 16:10 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 16:10 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-16 16:10 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 16:10 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 16:10 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 16:10 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 16:10 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 16:10 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 16:10 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 16:10 17408 ----a-w c:\windows\system32\iashost.exe
2009-02-18 13:44 . 2009-02-18 13:44 135168 ----a-w c:\windows\system32\nvcod140.dll
2008-01-21 02:57 . 2006-11-02 12:48 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-12-09 17:40 333192 ----a-w c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-04-30 1562352]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-10-07 442480]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
c:\users\moi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
PowerStrip.lnk - c:\program files\PowerStrip\PStrip.exe [2008-11-19 737312]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{45ECBFE6-6BF1-42AE-AF46-A6696B19C6A0}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{F655FCEA-D58B-468E-9C1D-CB5ABBB0E970}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{13031793-A5F8-4083-9BAF-579BEB08EC53}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:Sid Meier's Civilization 4 Beyond the Sword
"{D25F5CDB-1649-4EE4-91FF-63478C502E45}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:Sid Meier's Civilization 4 Beyond the Sword
"{F865F22E-8E6F-4B56-8CD2-26ED0E269205}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:Sid Meier's Civilization 4 Beyond the Sword Pitboss
"{FFF82024-5ACD-4030-A6B0-343024A8384D}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:Sid Meier's Civilization 4 Beyond the Sword Pitboss
"TCP Query User{BE42308F-69A1-4243-8830-119A78643CFD}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{8CDA5FCA-D256-4E25-8A9C-AA7C2FE65681}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{50BCD2D4-B41F-40CA-B689-25E22941ADB1}"= UDP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{554A21D0-9555-4802-80C6-858BCB864723}"= TCP:c:\program files\Winamp Remote\bin\Orb.exe:Orb
"{00EE5E4C-B451-45FB-8C01-A118EB8250E9}"= UDP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{E3F6B1BC-D642-44CF-938E-9016B88AD16E}"= TCP:c:\program files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{42592081-0F29-4443-9318-D571D472045A}"= UDP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{13306D30-FBDB-4E96-9BCD-DA8B787EAB76}"= TCP:c:\program files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{5B88A2F5-0399-4D99-9B0B-DB6F439F2434}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{B6362D2F-BB7C-4B30-ACE0-D905D15B8884}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{1ED1C0C6-BBB4-4852-AEB2-08F5AB7E01DF}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{EB66C121-DD10-4992-B8AC-A64B546E02E3}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{156B245C-389A-4952-983D-75B570DE8889}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{267C7D1E-A536-43F0-ABEE-629DEFC3B630}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{BCAAA488-E830-44D6-9BFC-6D0C4046D858}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{4BD705C2-93D5-47F0-85E1-794C5803599A}"= UDP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{3695F5E3-1DC7-4B27-9708-FFC0BD1C4896}"= TCP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [08/05/2009 12:39 108289]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [27/12/2008 17:50 464264]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [27/12/2008 17:50 234888]
R2 PStrip;PStrip;c:\windows\System32\drivers\pstrip.sys [15/07/2007 04:37 27992]
R3 EthDriver;Dynex Gigabit PCI Driver;c:\windows\System32\drivers\dynex86.sys [20/05/2008 11:13 106496]
S3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\System32\drivers\l160x86.sys [12/11/2008 15:42 46592]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [21/01/2008 04:32 179712]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [24/01/2009 15:46 216232]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe [15/02/2009 22:23 98488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-05-17 c:\windows\Tasks\User_Feed_Synchronization-{DF998343-AB48-43DC-B702-2205B04A4CF7}.job
- c:\windows\system32\msfeedssync.exe [2009-04-11 11:31]
.
.
------- Examen supplémentaire -------
.
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-18 18:39
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-05-18 18:40
ComboFix-quarantined-files.txt 2009-05-18 16:40
Avant-CF: 223 723 180 032 octets libres
Après-CF: 232 086 069 248 octets libres
279 --- E O F --- 2009-05-18 15:45