ComboFix 10-10-05.01 - baptou 06/10/2010 1:54.1.2 - x86
Microsoft® Windows Vista(TM) Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.2046.790 [GMT 2:00]
Lancé depuis: d:\music\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: BitDefender Antispyware *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\directory\CyberGate
c:\users\baptou\AppData\Roaming\chrtmp
c:\users\baptou\AppData\Roaming\Microsoft\Windows\Recent\Tune_Brothers_-_I_Like_It_2010_feat_Anthony_-_Locks_%28Peter_Brown_Remix%29_%5Bhugeeeestuff.blogspot.com%5D.pif
c:\users\baptou\AppData\Roaming\SQLite3.dll
c:\windows\system32\Ijl11.dll
c:\windows\system32\tmp.reg
c:\windows\system32\zip32.dll
F:\Autorun.inf
F:\install.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-09-06 au 2010-10-06 ))))))))))))))))))))))))))))))))))))
.
2071-03-16 11:19 . 2007-02-12 08:51 675840 ----a-w- c:\windows\system32\DevExpress.XtraTreeList.v6.3.dll
2071-03-16 11:19 . 2007-02-12 08:51 434176 ----a-w- c:\windows\system32\DevExpress.XtraVerticalGrid.v6.3.dll
2071-03-16 11:19 . 2007-02-12 08:51 262144 ----a-w- c:\windows\system32\DevExpress.XtraPivotGrid.v6.3.dll
2071-03-16 11:19 . 2007-02-12 08:51 172032 ----a-w- c:\windows\system32\DevExpress.XtraPivotGrid.v6.3.Core.dll
2071-03-16 11:19 . 2007-02-12 08:51 1355776 ----a-w- c:\windows\system32\DevExpress.XtraGrid.v6.3.dll
2071-03-16 11:19 . 2007-02-12 08:51 1265664 ----a-w- c:\windows\system32\DevExpress.XtraEditors.v6.3.dll
2071-03-16 11:19 . 2007-02-12 08:51 102400 ----a-w- c:\windows\system32\DevExpress.XtraCharts.v6.3.UI.dll
2071-03-16 11:18 . 2007-02-12 08:51 962560 ----a-w- c:\windows\system32\DevExpress.BonusSkins.v6.3.dll
2071-03-16 11:18 . 2007-02-12 08:51 454656 ----a-w- c:\windows\system32\DevExpress.Data.v6.3.dll
2071-03-16 11:18 . 2007-02-12 08:51 2592768 ----a-w- c:\windows\system32\DevExpress.Utils.v6.3.dll
2010-10-05 23:46 . 2010-10-05 23:54 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2010-10-05 22:09 . 2010-10-05 22:09 -------- d-----w- c:\program files\List_Kill'em
2010-10-05 10:25 . 2010-10-05 10:25 -------- d-----w- c:\users\baptou\AppData\Roaming\InstallShield
2010-10-05 09:51 . 2010-10-05 09:58 -------- d-----w- c:\program files\ZHPDiag
2010-10-05 09:46 . 2010-10-05 09:48 -------- d-----w- c:\program files\Ad-Remover
2010-10-01 21:17 . 2010-10-01 21:17 -------- d-----w- C:\RaidTool
2010-10-01 21:17 . 2010-04-09 11:43 155648 ----a-w- c:\windows\system32\xRaidAPI.dll
2010-10-01 21:17 . 2010-04-09 11:37 1970176 ----a-w- c:\windows\system32\xRaidSetup.exe
2010-10-01 21:17 . 2006-11-02 12:21 319456 ----a-w- c:\windows\system32\DifxApi.dll
2010-10-01 21:17 . 2010-10-01 21:17 -------- d-----w- c:\windows\RaidTool
2010-10-01 21:17 . 2010-08-10 15:29 104024 ----a-w- c:\windows\system32\drivers\jraid.sys
2010-10-01 21:14 . 2010-10-01 21:14 -------- d-----w- c:\program files\Marvell
2010-10-01 11:24 . 2010-10-01 11:24 -------- d-----w- c:\programdata\ATI
2010-10-01 11:17 . 2010-10-01 11:17 -------- d-----w- c:\programdata\SonicFocus
2010-10-01 11:17 . 2010-10-01 11:17 -------- d-----w- c:\program files\Analog Devices
2010-10-01 11:13 . 2010-10-01 11:13 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-10-01 11:03 . 2010-10-01 11:03 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-09-29 09:56 . 2010-06-22 13:30 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-26 12:55 . 2010-09-26 12:55 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 10.0.1.22\SetupAdmin.exe
2010-09-26 12:55 . 2010-09-26 12:55 -------- d-----w- c:\program files\Safari
2010-09-26 12:55 . 2010-09-26 12:55 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.18.5\SetupAdmin.exe
2010-09-18 17:13 . 2010-09-18 17:13 -------- d-----w- c:\users\baptou\AppData\Roaming\FMZilla
2010-09-18 17:13 . 2010-09-18 19:13 -------- d-----w- c:\program files\Free Music Zilla
2010-09-18 11:53 . 2010-09-18 11:53 -------- d-----w- c:\users\baptou\AppData\Roaming\ProgSense
2010-09-18 11:53 . 2010-09-18 19:22 -------- d-----w- C:\downloads
2010-09-18 11:53 . 2010-09-18 11:53 -------- d-----w- c:\users\baptou\AppData\Roaming\GrabPro
2010-09-18 11:53 . 2010-09-18 11:53 -------- d-----w- c:\program files\Orbitdownloader
2010-09-18 11:53 . 2010-09-19 19:51 -------- d-----w- c:\users\baptou\AppData\Roaming\Orbit
2010-09-17 12:10 . 2010-09-17 12:10 -------- d-----w- c:\program files\QuickTime
2010-09-15 16:35 . 2010-04-05 17:02 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 16:35 . 2010-05-27 20:08 739328 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-15 16:35 . 2010-04-16 16:46 502272 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 16:35 . 2010-08-17 14:11 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-09 18:53 . 2010-09-09 18:58 -------- d-----w- c:\program files\The GodFather
2010-09-09 17:28 . 2010-09-09 17:28 -------- d-----w- c:\users\baptou\AppData\Roaming\IrfanView
2010-09-09 17:28 . 2010-09-09 17:28 -------- d-----w- c:\program files\IrfanView
2010-09-08 21:31 . 2010-09-08 21:31 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-09-08 21:30 . 2010-09-08 21:30 -------- d-----w- c:\program files\LSoft Technologies
2010-09-08 02:25 . 2010-09-08 02:25 6381056 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2010-09-08 01:55 . 2010-09-08 01:55 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-09-08 01:55 . 2010-09-08 01:55 528384 ----a-w- c:\windows\system32\aticfx32.dll
2010-09-08 01:52 . 2010-09-08 01:52 450560 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-09-08 01:51 . 2010-09-08 01:51 380928 ----a-w- c:\windows\system32\atieclxx.exe
2010-09-08 01:51 . 2010-09-08 01:51 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2010-09-08 01:50 . 2010-09-08 01:50 15830016 ----a-w- c:\windows\system32\atioglxx.dll
2010-09-08 01:49 . 2010-09-08 01:49 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2010-09-08 01:49 . 2010-09-08 01:49 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2010-09-08 01:49 . 2010-09-08 01:49 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2010-09-08 01:49 . 2010-09-08 01:49 11776 ----a-w- c:\windows\system32\atimuixx.dll
2010-09-08 01:49 . 2010-09-08 01:49 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-09-08 01:46 . 2010-09-08 01:46 3914240 ----a-w- c:\windows\system32\atidxx32.dll
2010-09-08 01:28 . 2010-09-08 01:28 46080 ----a-w- c:\windows\system32\aticalrt.dll
2010-09-08 01:28 . 2010-09-08 01:28 44032 ----a-w- c:\windows\system32\aticalcl.dll
2010-09-08 01:28 . 2010-09-08 01:28 4057088 ----a-w- c:\windows\system32\atiumdag.dll
2010-09-08 01:27 . 2010-09-08 01:27 4375552 ----a-w- c:\windows\system32\aticaldd.dll
2010-09-08 01:24 . 2010-09-08 01:24 65536 ----a-w- c:\windows\system32\coinst.dll
2010-09-08 01:21 . 2010-09-08 01:21 3392512 ----a-w- c:\windows\system32\atiumdva.dll
2010-09-08 01:15 . 2010-09-08 01:15 241664 ----a-w- c:\windows\system32\atiadlxx.dll
2010-09-08 01:15 . 2010-09-08 01:15 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2010-09-08 01:15 . 2010-09-08 01:15 19968 ----a-w- c:\windows\system32\atigktxx.dll
2010-09-08 01:14 . 2010-09-08 01:14 221696 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2010-09-08 01:14 . 2010-09-08 01:14 30208 ----a-w- c:\windows\system32\atiuxpag.dll
2010-09-08 01:14 . 2010-09-08 01:14 28160 ----a-w- c:\windows\system32\atiu9pag.dll
2010-09-08 01:13 . 2010-09-08 01:13 23040 ----a-w- c:\windows\system32\atitmpxx.dll
2010-09-08 01:13 . 2010-09-08 01:13 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-09-08 01:08 . 2010-09-08 01:08 52736 ----a-w- c:\windows\system32\atimpc32.dll
2010-09-08 01:08 . 2010-09-08 01:08 52736 ----a-w- c:\windows\system32\amdpcom32.dll
2010-09-06 18:11 . 2010-09-06 18:18 -------- d-----w- c:\users\baptou\AppData\Roaming\GNU Solfege
2010-09-06 17:50 . 2010-09-06 17:50 -------- d-----w- c:\program files\GNU Solfege
2010-09-06 16:13 . 2010-09-06 16:13 -------- d-----w- c:\program files\ASIO4ALL v2
2010-09-06 15:20 . 2010-09-06 15:20 -------- d-----w- c:\users\baptou\AppData\Roaming\Cycling '74
2010-09-06 15:20 . 2010-09-06 15:20 -------- d-----w- c:\program files\AkaiPro
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-05 23:18 . 2009-06-28 02:01 -------- d-----w- c:\users\baptou\AppData\Roaming\uTorrent
2010-10-05 22:39 . 2009-08-28 14:54 -------- d-----w- c:\users\baptou\AppData\Roaming\Winamp
2010-10-05 13:51 . 2010-05-06 20:53 -------- d-----w- c:\users\baptou\AppData\Roaming\Mipony
2010-10-05 10:26 . 2010-05-10 19:51 -------- d-----w- c:\users\baptou\AppData\Roaming\Celemony Software GmbH
2010-10-05 10:26 . 2009-06-26 11:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-10-05 10:26 . 2009-11-23 18:05 -------- d-----w- c:\program files\Common Files\VST3
2010-10-05 10:22 . 2009-06-26 18:06 -------- d-----w- c:\programdata\eMule
2010-10-05 10:18 . 2009-09-15 15:18 -------- d-----w- c:\users\baptou\AppData\Roaming\RayV
2010-10-05 09:31 . 2009-06-26 06:43 1356 ----a-w- c:\users\baptou\AppData\Local\d3d9caps.dat
2010-10-01 21:19 . 2006-11-02 15:45 678804 ----a-w- c:\windows\system32\perfh00C.dat
2010-10-01 21:19 . 2006-11-02 15:45 126420 ----a-w- c:\windows\system32\perfc00C.dat
2010-10-01 21:17 . 2006-11-02 10:25 51200 ----a-w- c:\windows\Inf\infpub.dat
2010-10-01 21:17 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstrng.dat
2010-10-01 21:17 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstor.dat
2010-10-01 11:23 . 2009-06-26 06:44 101984 ----a-w- c:\users\baptou\AppData\Local\GDIPFONTCACHEV1.DAT
2010-10-01 11:15 . 2009-06-26 08:42 -------- d-----w- c:\program files\ATI Technologies
2010-10-01 11:05 . 2010-10-01 11:05 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_point32_01009.Wdf
2010-10-01 10:57 . 2010-07-28 20:55 -------- d-----w- c:\programdata\ma-config.com
2010-10-01 10:57 . 2010-07-28 20:55 -------- d-----w- c:\program files\ma-config.com
2010-09-29 23:03 . 2010-09-03 22:40 -------- d-----w- c:\users\baptou\AppData\Roaming\vlc
2010-09-29 21:12 . 2009-06-28 02:02 -------- d-----w- c:\program files\uTorrent
2010-09-26 12:59 . 2010-06-17 09:35 -------- d-----w- c:\program files\iTunes
2010-09-26 12:58 . 2010-06-17 09:35 -------- d-----w- c:\program files\iPod
2010-09-26 12:58 . 2009-06-28 14:38 -------- d-----w- c:\program files\Common Files\Apple
2010-09-17 12:10 . 2009-06-28 14:39 -------- d-----w- c:\programdata\Apple Computer
2010-09-15 17:24 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-15 17:21 . 2009-10-08 13:01 -------- d-----w- c:\programdata\Microsoft Help
2010-09-06 20:34 . 2009-08-04 12:40 -------- d-----w- c:\program files\Mp3tag
2010-09-05 19:04 . 2009-06-26 20:01 -------- d-----w- c:\program files\Common Files\LightScribe
2010-09-05 18:00 . 2010-09-05 18:00 691 ----a-w- c:\users\baptou\AppData\Roaming\GetValue.vbs
2010-09-05 18:00 . 2010-09-05 18:00 35 ----a-w- c:\users\baptou\AppData\Roaming\SetValue.bat
2010-09-05 18:00 . 2010-09-05 18:00 35 ----a-w- c:\users\baptou\AppData\Roaming\SetValue.bat
2010-09-04 20:12 . 2010-09-04 20:12 -------- d-----w- c:\program files\Bonjour
2010-08-29 14:57 . 2010-08-29 14:57 -------- d-----w- c:\programdata\KONAMI
2010-08-21 17:17 . 2009-06-29 10:35 -------- d-----w- c:\programdata\Ubisoft
2010-08-21 09:58 . 2010-04-26 12:23 164345 ----a-w- c:\windows\hpoins19.dat
2010-08-19 22:27 . 2010-08-19 22:27 -------- d-----w- c:\program files\Apple Software Update
2010-08-18 15:09 . 2010-08-19 14:28 52224 ----a-w- c:\users\baptou\AppData\Roaming\Mozilla\Firefox\Profiles\vqjmfi8b.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\FFExternalAlert.dll
2010-08-18 15:09 . 2010-08-19 14:28 101376 ----a-w- c:\users\baptou\AppData\Roaming\Mozilla\Firefox\Profiles\vqjmfi8b.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\RadioWMPCore.dll
2010-08-16 10:41 . 2010-08-16 10:41 100368 ----a-w- c:\windows\system32\drivers\AtihdLH3.sys
2010-08-15 22:12 . 2009-08-02 22:36 -------- d-----w- c:\users\baptou\AppData\Roaming\Media Player Classic
2010-08-14 22:35 . 2010-07-20 01:30 -------- d-----w- c:\users\baptou\AppData\Roaming\WebCam Recorder
2010-07-27 16:44 . 2010-07-27 16:44 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 16:44 . 2010-07-27 16:44 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 16:44 . 2010-07-27 16:44 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 16:44 . 2010-07-27 16:44 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-07-21 14:53 . 2010-07-21 14:53 505232 ----a-w- c:\windows\system32\ipcoin80.dll
2010-07-21 14:53 . 2010-07-21 14:53 40848 ----a-w- c:\windows\system32\drivers\point32.sys
2010-07-21 14:30 . 2010-07-21 14:30 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-16 23:02 . 2010-07-16 18:05 0 ----a-w- c:\users\baptou\errorlog.tmp
2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2009-05-06 1262888]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files\mipony-plugin\tbmip1.dll" [2010-06-10 2515552]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
2010-06-10 10:57 2515552 ----a-w- c:\program files\mipony-plugin\tbmip1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{90d46c30-9f25-4104-aea9-35c3f84477ff}"= "c:\program files\mipony-plugin\tbmip1.dll" [2010-06-10 2515552]
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{90D46C30-9F25-4104-AEA9-35C3F84477FF}"= "c:\program files\mipony-plugin\tbmip1.dll" [2010-06-10 2515552]
[HKEY_CLASSES_ROOT\clsid\{90d46c30-9f25-4104-aea9-35c3f84477ff}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-09-29 328056]
"RayV"="c:\program files\RayV\RayV\RayV.exe" [2009-08-19 2487592]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-01-29 198160]
"HP Software Update"="d:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-06-15 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"ProfilerU"="c:\program files\Saitek\SD6\Software\ProfilerU.exe" [2009-06-03 237568]
"SaiMfd"="c:\program files\Saitek\SD6\Software\SaiMfd.exe" [2009-06-03 131072]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-08 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 1797008]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-07 98304]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-08-28 1282048]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2010-01-19 43632]
c:\users\baptou\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-7-14 576000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - d:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-05 36608]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2010-09-12 251248]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 utezmzq2;AVZ Kernel Driver;c:\windows\system32\Drivers\utezmzq2.sys [2010-06-15 7168]
R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [2008-11-19 16640]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-09-08 691696]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-09-08 176128]
S2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [2010-06-15 194817]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-06-15 108289]
S2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2010-06-15 434945]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-09-08 6381056]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-09-08 221696]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2010-08-16 100368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.freemusiczilla.com
uInternet Settings,ProxyOverride = *.local
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Recherche avec cherche.us - c:\users\baptou\scriptjava.html
IE: Télécharger avec Mipony - file://d:\program files\MiPony\Browser\IEContext.htm
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: chat-land.org
FF - ProfilePath - c:\users\baptou\AppData\Roaming\Mozilla\Firefox\Profiles\vqjmfi8b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://fmz.qiwa.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2465030&q=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\baptou\AppData\Roaming\Mozilla\Firefox\Profiles\vqjmfi8b.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\FFExternalAlert.dll
FF - component: c:\users\baptou\AppData\Roaming\Mozilla\Firefox\Profiles\vqjmfi8b.default\extensions\{90d46c30-9f25-4104-aea9-35c3f84477ff}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\RayV\RayV\plugins\nprayvplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "
http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "
http://www.xeoo.com/?p=h&a=firefox");
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2871028216-1793917854-55297659-1000_Classes\CLSID\{1ac8f0bc-abb6-48e9-be06-850085314f6a}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000098
"Therad"=dword:00000010
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_USERS\S-1-5-21-2871028216-1793917854-55297659-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):f3,72,f4,55,42,86,9c,fb,56,e6,a5,5f,56,02,d3,92,61,65,7f,56,12,
33,3f,c6,8f,75,f0,90,8d,87,4a,18,87,d6,34,56,f6,7b,d4,6f,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Heure de fin: 2010-10-06 02:01:04
ComboFix-quarantined-files.txt 2010-10-06 00:01
Avant-CF: 4 746 985 472 octets libres
Après-CF: 4 606 976 000 octets libres
- - End Of File - - 18561C24FE9C81E86AB95DAF468E1BD8