ComboFix 09-06-14.02 - jano 15/06/2009 20:09.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.255.87 [GMT 2:00]
Lancé depuis: c:\documents and settings\jano\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
[i] ADS - WINDOWS: deleted 24 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers
c:\program files\QUAD Utilities
c:\recycler\S-1-5-21-0243336031-4052116379-881863308-0851
c:\temp\1cb
c:\windows\Fonts\'
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\c.cgm
c:\documents and settings\All Users\Application Data\Microsoft\Media Index\Drivers\hdddriver.dll
c:\documents and settings\jano\Local Settings\Application Data\qioseus.dat
c:\documents and settings\jano\Local Settings\Application Data\qioseus.exe
c:\documents and settings\jano\Local Settings\Application Data\qioseus_nav.dat
c:\documents and settings\jano\Local Settings\Application Data\qioseus_navps.dat
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
c:\recycler\S-1-5-21-0243336031-4052116379-881863308-0851\Desktop.ini
c:\temp\1cb\syscheck.log
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\agisisit.ini
c:\windows\system32\alewisub.ini
c:\windows\system32\irihukeg.ini
c:\windows\system32\iyuzoper.ini
c:\windows\system32\msssc.dll
c:\windows\vmreg.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-15 au 2009-06-15 ))))))))))))))))))))))))))))))))))))
.
2032-07-05 10:11 . 2032-07-05 10:11 -------- d-----w- c:\program files\Sony
2032-07-05 10:07 . 2007-04-04 10:43 23176 ----a-r- c:\windows\system32\drivers\s716nd5.sys
2032-07-05 10:07 . 2007-04-04 10:43 98952 ----a-r- c:\windows\system32\drivers\s716unic.sys
2032-07-05 10:07 . 2007-04-04 10:43 11016 ----a-r- c:\windows\system32\drivers\s716cr.sys
2032-07-05 10:07 . 2007-04-04 10:43 100360 ----a-r- c:\windows\system32\drivers\s716mgmt.sys
2032-07-05 10:07 . 2007-04-04 10:43 98568 ----a-r- c:\windows\system32\drivers\s716obex.sys
2032-07-05 10:07 . 2007-04-04 10:43 108552 ----a-r- c:\windows\system32\drivers\s716mdm.sys
2032-07-05 10:07 . 2007-04-04 10:43 15112 ----a-r- c:\windows\system32\drivers\s716mdfl.sys
2032-07-05 10:07 . 2007-04-04 10:43 12424 ----a-r- c:\windows\system32\drivers\s716cmnt.sys
2032-07-05 10:07 . 2007-04-04 10:43 12424 ----a-r- c:\windows\system32\drivers\s716cm.sys
2032-07-05 10:05 . 2007-04-04 10:43 12424 ----a-r- c:\windows\system32\drivers\s716whnt.sys
2032-07-05 10:05 . 2007-04-04 10:43 12424 ----a-r- c:\windows\system32\drivers\s716wh.sys
2032-07-05 10:05 . 2007-04-04 10:43 83208 ----a-r- c:\windows\system32\drivers\s716bus.sys
2032-07-05 09:58 . 2009-01-01 08:38 -------- d-----w- c:\documents and settings\jano\Application Data\Teleca
2032-07-05 09:54 . 2009-04-10 18:45 -------- dc----w- c:\windows\system32\DRVSTORE
2032-07-05 09:50 . 2032-07-05 09:50 -------- d-----w- c:\documents and settings\jano\Application Data\Sony Ericsson
2032-07-05 09:49 . 2009-01-01 08:37 -------- d-----w- c:\program files\Fichiers communs\Teleca Shared
2032-07-05 09:47 . 2009-06-09 11:37 -------- d-----w- c:\windows\Downloaded Installations
2009-06-15 17:39 . 2009-06-15 17:39 -------- d-----r- c:\documents and settings\LocalService\Favoris
2009-06-15 17:39 . 2009-06-15 17:39 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-15 17:15 . 2006-10-23 11:14 59264 -c----w- c:\windows\system32\dllcache\usbhub.sys
2009-06-15 17:15 . 2006-10-23 11:14 20608 -c----w- c:\windows\system32\dllcache\usbuhci.sys
2009-06-15 17:15 . 2006-10-23 11:14 30208 -c----w- c:\windows\system32\dllcache\usbehci.sys
2009-06-15 17:15 . 2006-10-23 11:14 17152 -c----w- c:\windows\system32\dllcache\usbohci.sys
2009-06-15 17:15 . 2006-10-23 11:14 143488 -c----w- c:\windows\system32\dllcache\usbport.sys
2009-06-15 15:36 . 2009-06-15 15:36 -------- d-----w- c:\program files\PIXELA
2009-06-15 15:30 . 2001-11-25 11:11 81924 ------w- c:\windows\system32\drivers\VC4CB104.SYS
2009-06-15 15:30 . 2009-06-15 15:30 -------- d-----w- c:\program files\REGSHAVE
2009-06-15 15:30 . 2002-06-25 08:06 45056 ------w- c:\windows\system32\FINFCOPY.dll
2009-06-15 15:30 . 2002-02-27 11:27 65536 ------w- c:\windows\system32\FINFCHECK.dll
2009-06-15 15:30 . 2002-02-13 10:00 45056 ------w- c:\windows\system32\FCLKBTN.DLL
2009-06-15 15:30 . 2002-02-05 16:33 69632 ------w- c:\windows\system32\FREGSHEX.DLL
2009-06-15 15:25 . 2009-06-15 15:25 -------- d-----w- c:\documents and settings\jano\Application Data\InstallShield
2009-06-15 09:24 . 2009-06-15 09:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-13 11:29 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-13 11:29 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-13 11:29 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-13 11:29 . 2009-06-13 11:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-13 10:58 . 2009-06-13 10:58 -------- d-sh--w- c:\documents and settings\babeth 2\PrivacIE
2009-06-13 10:09 . 2009-06-13 10:10 -------- d-----w- C:\Downloads
2009-06-12 14:34 . 2009-06-12 14:34 -------- d-sh--w- c:\documents and settings\jano\IECompatCache
2009-06-12 14:33 . 2009-06-12 14:33 -------- d-sh--w- c:\documents and settings\jano\PrivacIE
2009-06-12 14:31 . 2009-06-12 14:31 -------- d-sh--w- c:\documents and settings\jano\IETldCache
2009-06-12 14:02 . 2009-06-12 14:02 -------- d-sh--w- c:\documents and settings\babeth 2\IETldCache
2009-06-12 10:19 . 2009-06-12 10:19 -------- d--h--w- c:\windows\msdownld.tmp
2009-06-12 10:16 . 2009-06-12 10:19 -------- dc-h--w- c:\windows\ie8
2009-06-10 08:51 . 2009-03-24 14:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-09 16:40 . 2009-06-10 08:42 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-09 14:16 . 2009-06-10 08:08 526848 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Network\install.exe
2009-06-09 11:59 . 2009-06-09 11:59 198064 ----a-w- c:\documents and settings\jano\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-06-09 11:52 . 2009-06-15 18:05 -------- d-----w- c:\documents and settings\jano\Application Data\DMCache
2009-06-09 11:52 . 2009-06-09 13:39 -------- d-----w- c:\documents and settings\jano\Application Data\IDM
2009-06-09 11:52 . 2009-06-14 19:26 -------- d-----w- c:\program files\Internet Download Manager
2009-06-09 11:38 . 2009-06-09 11:59 -------- d-----w- c:\documents and settings\All Users\Application Data\SymplisIT
2009-06-09 11:38 . 2009-06-09 11:38 -------- d-----w- c:\program files\SymplisIT
2009-06-08 17:08 . 2009-06-08 17:08 -------- d-----w- c:\program files\SFR
2009-06-06 15:41 . 2009-06-06 15:49 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-06 08:15 . 2009-06-06 08:15 -------- d-----w- c:\documents and settings\babeth 2\Local Settings\Application Data\Thunderbird
2009-06-06 08:15 . 2009-06-06 08:15 -------- d-----w- c:\documents and settings\babeth 2\Application Data\Thunderbird
2009-05-27 10:22 . 2009-03-26 15:35 210352 ----a-w- c:\windows\system32\idmmbc.dll
2009-05-26 12:18 . 2009-06-13 12:19 -------- d-----w- c:\documents and settings\babeth 2\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2032-07-06 10:10 . 2007-09-05 17:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-06-15 16:52 . 2008-02-16 19:55 -------- d-----w- c:\documents and settings\jano\Application Data\uTorrent
2009-06-15 16:15 . 2008-08-20 08:29 -------- d-----w- c:\program files\FinePixViewer
2009-06-15 15:36 . 2007-08-15 14:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-15 15:32 . 2008-08-20 08:30 -------- d-----w- c:\documents and settings\jano\Application Data\FUJIFILM
2009-06-15 09:24 . 2009-03-23 10:19 -------- d-----w- c:\program files\Yahoo!
2009-06-13 11:29 . 2009-03-15 16:23 -------- d-----w- c:\program files\Avira
2009-06-06 15:43 . 2009-04-04 17:30 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-06-06 11:45 . 2009-04-04 17:28 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-05-16 10:53 . 2006-03-02 12:00 2864 ----a-w- c:\windows\system32\winsock.dll
2009-05-15 17:52 . 2007-08-19 09:31 -------- d-----w- c:\program files\Google
2009-05-15 17:51 . 2009-03-13 19:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-05-09 10:06 . 2009-03-28 16:24 -------- d-----w- c:\documents and settings\babeth 2\Application Data\Apple Computer
2009-05-09 08:28 . 2009-05-09 08:27 -------- d-----w- c:\documents and settings\jano\Application Data\FileZilla
2009-04-28 16:45 . 2009-04-26 10:26 -------- d-----w- c:\program files\SlySoft
2009-04-20 07:25 . 2009-03-27 18:18 -------- d-----w- c:\program files\ZZZZZZ
2009-04-20 07:19 . 2009-04-20 07:19 -------- d-----w- c:\documents and settings\babeth 2\Application Data\TuneUp Software
2009-04-10 17:59 . 2008-05-04 13:44 72040 ----a-w- c:\documents and settings\babeth 2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-04 17:08 . 2009-04-04 17:07 290816 ------w- c:\windows\Setup1.exe
2009-04-04 17:08 . 2009-04-04 17:07 74752 ----a-w- c:\windows\ST6UNST.EXE
2009-04-02 14:29 . 2009-04-02 14:29 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-29 09:39 . 2006-03-02 12:00 90152 ----a-w- c:\windows\system32\perfc00C.dat
2009-03-29 09:39 . 2006-03-02 12:00 521066 ----a-w- c:\windows\system32\perfh00C.dat
2009-03-23 14:08 . 2007-09-14 16:59 556 ----a-w- C:\pnpID.dat
2009-03-22 14:43 . 2007-09-14 17:00 251 ----a-w- C:\drvpnp.dat
2009-03-22 14:43 . 2009-03-22 14:43 807 ----a-w- C:\tmpFile.dat
2009-03-21 20:50 . 2009-03-14 12:06 51760 ---ha-w- c:\windows\system32\mlfcache.dat
2009-03-19 14:32 . 2009-04-10 18:45 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 14:32 . 2009-03-19 14:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
2009-04-05 12:12 1883672 ----a-w- c:\program files\Eazel-FR\tbEaz1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f-secure manager"="c:\program files\Pack Securite\Common\FSM32.EXE" [2008-09-23 182936]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2009-6-15 303104]
GA511 Smart Wizard Utility.lnk - c:\windows\Installer\{52CAD7C7-1E41-43FE-8613-AB9D79B2DBBC}\NewShortcut1.exe [2007-8-16 40960]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/uaswBoot.exe /A:* /L:French /KBD:2
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^ExifLauncher2.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\ExifLauncher2.lnk
backup=c:\windows\pss\ExifLauncher2.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CPM035bdf17"=Rundll32.exe "c:\windows\system32\tejonubo.dll",a
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [01/06/2004 11:02 6016]
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [05/07/2006 14:46 63352]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [06/12/2005 17:11 35328]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [13/06/2009 13:29 108289]
S2 Fluxmyrioz;Fluxmyrioz;c:\windows\System32\svchost.exe -k netsvcs [02/03/2006 14:00 14336]
S2 fsihs;F-Secure Installer restarter;"c:\docume~1\jano\LOCALS~1\Temp\Installer\[u]0/u0000001\bootstrap\fsihs.exe" --> c:\docume~1\jano\LOCALS~1\Temp\Installer\[u]0/u0000001\bootstrap\fsihs.exe [?]
S2 gupdate1c9d585fb97a69a;Service Google Update (gupdate1c9d585fb97a69a);c:\program files\Google\Update\GoogleUpdate.exe [15/05/2009 19:52 133104]
S2 hpdj3500;hpdj3500;c:\docume~1\jano\LOCALS~1\Temp\hpdj3500.exe -servicerunning=true -uninstall=hp deskjet 3500 series -product=3500 --> c:\docume~1\jano\LOCALS~1\Temp\hpdj3500.exe -servicerunning=true -uninstall=hp deskjet 3500 series -product=3500 [?]
S2 LANPkt;Realtek LANPkt Protocol;c:\windows\system32\drivers\LANPkt.sys [28/11/2006 11:48 8440]
S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [16/08/2007 08:50 26144]
S3 bfastfao;bfastfao;\??\c:\docume~1\jano\LOCALS~1\Temp\bfastfao.sys --> c:\docume~1\jano\LOCALS~1\Temp\bfastfao.sys [?]
S3 Diag69xp;Diag69xp;c:\windows\system32\drivers\diag69xp.sys [28/11/2006 11:48 11237]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [05/07/2032 12:05 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [05/07/2032 12:07 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [05/07/2032 12:07 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [05/07/2032 12:07 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [05/07/2032 12:07 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [05/07/2032 12:07 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [05/07/2032 12:07 98952]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Fluxmyrioz
.
Contenu du dossier 'Tâches planifiées'
2009-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-06-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-13 17:49]
2009-06-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-15 17:52]
2009-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1078081533-1801674531-1007.job
- c:\documents and settings\jano\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-15 17:43]
2009-06-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-1078081533-1801674531-1009.job
- c:\documents and settings\babeth 2\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-13 18:02]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{cae5226a-2553-47da-8aac-8bc05d2e9c73} - (no file)
HKCU-Run-RemoveIT Pro v7Ent - c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
HKCU-Run-qioseus - c:\documents and settings\jano\local settings\application data\qioseus.exe
HKLM-Run-CPM035bdf17 - c:\windows\system32\ronuruso.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
LSP: c:\windows\system32\idmmbc.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 20:16
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1466fa53-ebc3-4ecd-a95d-5a03aa5df0d5}]
@Denied: (Full) (Everyone)
"Model"=dword:000000a5
"Therad"=dword:00000007
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):19,4f,1f,9a,98,98,d1,0e,23,70,1b,1e,88,75,18,a8,53,3b,d7,a1,bc,
8b,88,a7,c5,f4,3c,1e,54,03,da,f7,d9,98,05,67,8a,5b,a3,99,00,00,00,00,00,00,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(460)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1768)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bgsvcgen.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\system32\CF18613.exe
c:\program files\NETGEAR GA511 Adapter\GA511.exe
c:\windows\SoftwareDistribution\Download\b36c7ee8fdde6b71de76c51647bccbb6\update\update.exe
.
**************************************************************************
.
Heure de fin: 2009-06-15 20:23 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-15 18:23
Avant-CF: 59 816 161 280 octets libres
Après-CF: 61 693 472 768 octets libres
Current=1 Default=1 Failed=4 LastKnownGood=5 Sets=1,2,3,4,5,6
268 --- E O F --- 2009-03-13 19:03