ComboFix 09-09-29.04 - LOUISIANE 30/09/2009 17:09.1.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.33.1036.18.1918.1424 [GMT -3:00]
Lancé depuis: c:\downloads\Software\ComboFix.exe
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
Overlay interrompu ... Veuillez exécuter ComboFix une nouvelle fois
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\utypipih.pif
c:\program files\Common Files\uwimo.pif
c:\program files\outlook
c:\program files\TS\tsc.exe
c:\programdata\agidezozy.sys
c:\programdata\nymuzeqyla.sys
c:\programdata\ofaj.vbs
c:\programdata\zyjybyxaty.dl
c:\users\Public\Documents\culeke.inf
c:\users\Public\Documents\siwaqyw.exe
c:\windows\abalihij.reg
c:\windows\awjtg2458.exe
c:\windows\gutif.exe
c:\windows\Installer\4bcfa24.msi
c:\windows\Installer\df2156.msi
c:\windows\ivihowivi.dll
c:\windows\ssrtm4133.exe
c:\windows\system32\bszip.dll
c:\windows\system32\cido.pif
c:\windows\system32\faqyw.inf
c:\windows\system32\mise.inf
c:\windows\system32\taskkill.com
c:\windows\system32\ucytiqo.dl
c:\windows\system32\wefocywud.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-28 au 2009-09-30 ))))))))))))))))))))))))))))))))))))
.
2009-09-30 23:01 . 2009-09-30 23:01 -------- d-sh--w- c:\windows\system32\%APPDATA%
2009-09-29 21:59 . 2009-09-30 20:28 -------- d-----w- c:\program files\TS
2009-09-29 21:41 . 2009-09-29 22:27 -------- d-----w- C:\UsbFix
2009-09-29 00:30 . 2009-09-29 00:30 24576 --sha-w- c:\users\LOUISIANE\ntuser.dll
2009-09-28 22:28 . 2009-09-28 22:28 16419 ----a-w- c:\windows\System32\config\SYSTEM~1\AppData\Local\karujajuku.com
2009-09-28 22:24 . 2009-09-29 00:28 24576 --sha-w- c:\windows\system32\calc.dll
2009-09-28 22:24 . 2009-09-28 22:24 24576 --sha-w- c:\windows\system32\config\systemprofile\ntuser.dll
2009-09-28 22:19 . 2009-09-28 22:19 16 ----a-w- c:\windows\pxysdb.dat
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\nwlnkfwd.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\nwlnkflt.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\ipinip.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\drivers\blbdrive.sys
2009-09-28 22:19 . 2009-09-28 22:19 8480 ----a-w- c:\windows\system32\sebdpx.sys
2009-09-28 22:19 . 2009-09-28 22:19 24659 ----a-w- c:\windows\system32\sebdpp.dll
2009-09-27 18:56 . 2009-08-27 14:09 1647984 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\NAVEX32A.DLL
2009-09-27 18:56 . 2009-09-26 08:00 259440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\ECMSVR32.DLL
2009-09-27 18:56 . 2009-08-27 14:09 84912 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\NAVENG.SYS
2009-09-27 18:56 . 2009-08-27 14:09 371248 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\EECTRL.SYS
2009-09-27 18:56 . 2009-08-27 14:09 177520 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\NAVENG32.DLL
2009-09-27 18:56 . 2009-08-27 14:09 1323568 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\NAVEX15.SYS
2009-09-27 18:56 . 2009-08-27 14:09 102448 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\ERASER.SYS
2009-09-27 18:56 . 2009-09-17 08:00 2747952 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\20090927.002\CCERASER.DLL
2009-09-27 17:45 . 2009-09-27 17:58 -------- d-----w- c:\program files\trend micro
2009-09-27 13:17 . 2009-09-30 00:05 -------- d-----w- c:\users\LOUISIANE\Incomplete
2009-09-27 13:17 . 2009-09-29 22:49 -------- d-----w- c:\users\LOUISIANE\Musique
2009-09-26 23:11 . 2009-09-26 23:25 -------- d-----w- C:\ToolBar SD
2009-09-26 19:54 . 2009-09-26 19:55 -------- d-----w- C:\GenProc
2009-09-26 19:13 . 2009-09-27 13:19 -------- d-----w- c:\windows\Downloaded Program Files
2009-09-26 17:47 . 2009-09-26 17:47 -------- d-----w- c:\program files\P2P_Max_France
2009-09-25 00:15 . 2009-09-30 19:55 -------- d-----w- c:\users\LOUISIANE\AppData\Roaming\Software Informer
2009-09-25 00:15 . 2009-09-25 00:15 -------- d-----w- c:\program files\Software Informer
2009-09-25 00:15 . 2009-09-30 20:02 -------- d-----w- c:\users\LOUISIANE\AppData\Roaming\Free Download Manager
2009-09-25 00:15 . 2009-09-25 00:15 -------- d-----w- c:\programdata\FreeDownloadManager.ORG
2009-09-25 00:15 . 2009-09-25 00:16 -------- d-----w- c:\program files\Free Download Manager
2009-09-17 08:00 . 2009-09-17 08:00 2747952 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\CCERASER.DLL
2009-09-14 21:32 . 2009-09-14 21:32 -------- d-----w- C:\dca04b2b8173fda18215871734
2009-09-14 21:31 . 2009-09-26 17:45 -------- d-----w- c:\program files\LimeWire
2009-09-12 03:13 . 2009-08-27 14:09 371248 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\eeCtrl.sys
2009-09-12 03:13 . 2009-08-27 14:09 102448 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\ERASER.sys
2009-09-12 03:13 . 2009-08-27 14:09 84912 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\naveng.sys
2009-09-12 03:13 . 2009-08-27 14:09 259440 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\ecmsvr32.dll
2009-09-12 03:13 . 2009-08-27 14:09 177520 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\naveng32.dll
2009-09-12 03:13 . 2009-08-27 14:09 1647984 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\navex32a.dll
2009-09-12 03:13 . 2009-08-27 14:09 1323568 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\navex15.sys
2009-09-12 02:55 . 2009-09-12 02:56 -------- d-----w- c:\programdata\Norton
2009-09-12 02:55 . 2009-09-12 02:55 -------- d-----w- c:\windows\system32\drivers\NSS
2009-09-12 02:55 . 2009-09-12 02:55 -------- d-----w- c:\programdata\NortonInstaller
2009-09-12 02:55 . 2009-09-12 02:55 -------- d-----w- c:\program files\NortonInstaller
2009-09-10 02:51 . 2009-06-10 12:07 2855424 ----a-w- c:\windows\system32\mf.dll
2009-09-10 02:51 . 2009-06-10 12:07 98816 ----a-w- c:\windows\system32\mfps.dll
2009-09-10 02:51 . 2009-06-10 10:15 24576 ----a-w- c:\windows\system32\mfpmp.exe
2009-09-10 02:51 . 2009-06-10 10:14 52736 ----a-w- c:\windows\system32\rrinstaller.exe
2009-09-10 02:51 . 2009-06-10 08:50 2048 ----a-w- c:\windows\system32\mferror.dll
2009-09-10 02:19 . 2009-07-11 19:32 297984 ----a-w- c:\windows\system32\wlansec.dll
2009-09-10 02:19 . 2009-07-11 19:32 290816 ----a-w- c:\windows\system32\wlanmsm.dll
2009-09-10 02:19 . 2009-07-11 19:26 123904 ----a-w- c:\windows\system32\L2SecHC.dll
2009-09-10 02:19 . 2009-07-11 19:32 502272 ----a-w- c:\windows\system32\wlansvc.dll
2009-09-10 02:19 . 2009-07-11 19:32 67584 ----a-w- c:\windows\system32\wlanhlp.dll
2009-09-10 02:19 . 2009-07-11 19:32 47104 ----a-w- c:\windows\system32\wlanapi.dll
2009-09-02 23:46 . 2009-08-29 03:41 1686528 ----a-w- c:\windows\system32\gameux.dll
2009-09-02 23:46 . 2009-08-29 03:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 23:46 . 2009-08-28 23:31 4247552 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-30 22:15 . 2008-12-13 22:44 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-30 19:06 . 2009-04-26 04:52 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-30 18:56 . 2009-03-04 19:55 -------- d-----w- c:\programdata\Google Updater
2009-09-30 00:24 . 2009-01-15 23:53 -------- d-----w- c:\users\LOUISIANE\AppData\Roaming\LimeWire
2009-09-29 21:45 . 2008-09-24 23:03 690832 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-29 21:45 . 2008-09-24 23:03 117572 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-28 22:28 . 2009-09-28 22:28 14051 ----a-w- c:\windows\System32\config\SYSTEM~1\AppData\Roaming\fylodi.sys
2009-09-28 22:24 . 2009-09-28 22:24 159344 ----a-w- c:\windows\System32\config\SYSTEM~1\AppData\Roaming\lizkavd.exe
2009-09-28 22:24 . 2009-09-28 22:24 23552 ----a-w- c:\windows\System32\config\SYSTEM~1\AppData\Roaming\svcst.exe
2009-09-28 22:24 . 2009-09-28 22:24 23552 ----a-w- c:\windows\System32\config\SYSTEM~1\AppData\Roaming\seres.exe
2009-09-26 19:14 . 2008-09-24 13:19 56712 ----a-w- c:\users\LOUISIANE\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-26 17:15 . 2008-09-24 14:39 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-25 00:21 . 2009-08-17 17:35 -------- d-----w- c:\programdata\Kaspersky Lab
2009-09-12 02:55 . 2008-12-13 22:44 -------- d-----w- c:\program files\Norton Security Scan
2009-09-12 02:55 . 2008-12-14 16:55 -------- d-----w- c:\programdata\Symantec
2009-09-10 03:07 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-09-10 03:07 . 2008-12-17 01:51 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-02 21:18 . 2008-09-25 08:18 -------- d-----w- c:\program files\Java
2009-08-27 02:37 . 2009-08-27 02:31 -------- d-----w- c:\program files\PhotoFiltre
2009-08-24 06:17 . 2009-04-08 02:02 -------- d-----w- c:\program files\iPod
2009-08-24 06:17 . 2009-04-08 02:02 -------- d-----w- c:\program files\iTunes
2009-08-24 01:55 . 2009-08-24 01:47 -------- d-----w- c:\program files\QuickTime
2009-08-17 17:32 . 2008-09-24 13:36 -------- d-----w- c:\programdata\avg8
2009-08-14 17:16 . 2009-09-10 02:47 213592 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 16:42 . 2009-09-10 02:47 167424 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-08-14 16:40 . 2009-09-10 02:47 103936 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:40 . 2009-09-10 02:47 15360 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 14:25 . 2009-09-10 02:47 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:25 . 2009-09-10 02:47 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:25 . 2009-09-10 02:47 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:25 . 2009-09-10 02:47 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:25 . 2009-09-10 02:47 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:25 . 2009-09-10 02:47 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:25 . 2009-09-10 02:47 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 14:24 . 2009-09-10 02:47 813568 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 14:23 . 2009-09-10 02:47 22016 ----a-w- c:\windows\system32\netiougc.exe
2009-07-25 08:23 . 2008-11-29 02:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-21 21:52 . 2009-08-30 22:24 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-30 22:24 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-30 22:24 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-30 22:24 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 14:52 . 2009-08-23 22:06 71680 ----a-w- c:\windows\system32\atl.dll
2009-07-14 13:02 . 2009-08-18 17:42 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 13:01 . 2009-08-18 17:41 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-07-14 13:00 . 2009-08-18 17:42 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-07-14 11:11 . 2009-08-18 17:41 8147968 ----a-w- c:\windows\system32\wmploc.DLL
2009-07-12 11:46 . 2009-07-12 11:48 3403032 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-03-04 20:04 . 2009-03-04 20:04 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-05-30 17:12 . 2007-05-30 17:12 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"calc"="c:\windows\system32\config\SYSTEM~1\ntuser.dll" [2009-09-28 24576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
"calc"="c:\windows\system32\calc.dll" [2009-09-29 24576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"calc"="c:\windows\system32\config\SYSTEM~1\ntuser.dll" [2009-09-28 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sebdpp]
2009-09-28 22:19 24659 ----a-w- c:\windows\System32\sebdpp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{7B3562B5-808C-4B9F-BEB2-157EFFAF5FBD}c:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:c:\program files\intervideo\dvd8\windvd.exe:WinDVD
"UDP Query User{0675AA89-24A9-4D07-B178-B486D0EEC554}c:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:c:\program files\intervideo\dvd8\windvd.exe:WinDVD
"TCP Query User{FD7EB83D-667A-4610-95C0-7A2816CFA4AA}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{577737FE-DD2D-43A8-A2E7-68FE7A9CB29A}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{31D18F2B-0D18-4788-9B3D-4AE04DE288CF}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8C22D123-C045-4A1D-9FD0-9645780A027C}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{70DCFCA7-BD4B-400E-8BCC-3B4B03A6D423}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{193CE781-7A08-47C3-8D47-6BBBF2B2ADF0}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{EC33B62D-DDD1-4EB0-A0B6-91892DEACC1F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{40D8DF30-8645-4F72-BEEE-700ADB6D3171}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E66CF8BE-918E-4EC3-9926-1F313187B85D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A744824D-C54F-4730-800D-3F6FC199F941}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D069D6C4-81F6-4F5F-946B-89F7F5A34356}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{56095E1E-A711-4E33-BB41-09E41EAA5E34}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CB43E2F4-53FD-451A-A261-8EF38BA8572E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{873427E1-ABC0-4DDE-8A87-127A38F599B7}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{84D80DFB-DA13-4122-AA74-EEAA9D1F26E0}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{85A19E8D-2CDC-4544-B33F-F727E7EEA762}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{4CCADCCC-8EE6-4C80-81F2-A988BE22742C}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{71E48131-31ED-4584-A2A7-EDC07D349B85}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{504BB996-7C7E-40B3-B448-50B7C5A879E9}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{6B55EE22-F49B-4122-94D1-C634D83A272E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{0619C31E-DA64-44D2-B3E6-6FBB49CD0944}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
S1 sebdpx;SEB Controller;c:\windows\System32\sebdpx.sys [28/09/2009 19:19 8480]
S2 AeLookupSvcALG;Expérience d’application AeLookupSvcALG;c:\windows\TEMP\qbiffnrkla.exe service --> c:\windows\TEMP\qbiffnrkla.exe service [?]
S2 gupdate1c99d075f8153ac;Service Google Update (gupdate1c99d075f8153ac);c:\program files\Google\Update\GoogleUpdate.exe [04/03/2009 17:25 133104]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [26/04/2009 01:53 1153368]
S3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\System32\drivers\fetnd6v.sys [22/09/2008 03:20 43520]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [27/04/2009 19:43 55280]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [04/03/2009 17:03 30192]
S3 S3GIGP;S3GIGP;c:\windows\System32\drivers\VTGKModeDX32.sys [24/09/2008 09:09 780288]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;c:\windows\System32\drivers\sis163u.sys [24/09/2008 09:09 218624]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-09-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-11 23:03]
2009-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-04 20:24]
2009-09-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-04 20:24]
2009-09-30 c:\windows\Tasks\Norton Security Scan for LOUISIANE.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-09-12 19:45]
.
.
------- Examen supplémentaire -------
.
mWindow Title =
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: Crawler Search - tbr:iemenu
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
WebBrowser-{1C491116-C175-45E1-A570-6FB14FEA8B7B} - (no file)
**************************************************************************
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\HelpPane.exe
.
**************************************************************************
.
Heure de fin: 2009-09-30 20:05 - La machine a redémarré [SYSTEM]
ComboFix-quarantined-files.txt 2009-09-30 23:05
Avant-CF: 64 036 515 840 octets libres
Après-CF: 63 944 609 792 octets libres
287 --- E O F --- 2009-09-28 22:42