Salut merci de bien vouloir m'aider voila le rapport de combofix:
ComboFix 08-03-25.1 - yoann 2008-03-25 23:34:59.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1699 [GMT 1:00]
Endroit: C:\Users\yoann\Desktop\ComboFix.exe
.
-- Script messages for sUBs --
VFind -td "C:\Windows\system32\baiso*"
VFind.exe -ltf -s-1300000 -d+2007-12-25 C:\Windows\*
VFind.exe -ltf -s-1000000 -d+2007-12-25 "C:\Program Files\*"
pv -d10000 * -t -l
\SystemRoot\System32\smss.exe
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\services.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\helppane.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
winlogon.exe
explorer.exe
SED "/32\\[0-9]*\\insatll.~tmp/I!d"
VFind -tf "C:\Windows\system32\insatll.~tmp"
VFind.exe -ltf -s-1300000 -d+2007-12-25 C:\Windows\*
VFind.exe -ltf -s-1000000 -d+2007-12-25 "C:\Program Files\*"
pv -d10000 * -t -l
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-25 to 2008-03-25 ))))))))))))))))))))))))))))))))))))
.
2008-03-25 22:42 . 2008-03-25 22:42 <REP> d-------- C:\Program Files\Trend Micro
2008-03-24 21:37 . 2008-03-24 21:37 <REP> d-------- C:\Program Files\eMule
2008-03-22 17:42 . 2008-03-22 17:42 <REP> d-------- C:\Program Files\Common Files\Microsoft Games
2008-03-21 01:23 . 2007-03-12 16:42 3,495,784 --a------ C:\Windows\System32\d3dx9_33.dll
2008-03-21 01:22 . 2008-03-21 01:23 <REP> d--h----- C:\Windows\msdownld.tmp
2008-03-20 19:41 . 2008-03-21 13:43 <REP> d-------- C:\Program Files\Monte Cristo
2008-03-20 12:52 . 2008-03-21 00:05 <REP> d-------- C:\Program Files\Electronic Arts
2008-03-20 03:05 . 2008-03-03 15:05 1,086,952 --a------ C:\Windows\System32\zpeng24.dll
2008-03-20 03:05 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\vsdatant.sys
2008-03-20 01:27 . 2004-08-18 09:34 442,368 -ra------ C:\Windows\System32\vp6vfw.dll
2008-03-20 01:21 . 2008-03-20 01:23 <REP> d-------- C:\Users\yoann\AppData\Roaming\DAEMON Tools
2008-03-20 01:21 . 2008-03-20 01:21 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-03-20 01:11 . 2008-03-20 01:11 715,248 --a------ C:\Windows\System32\drivers\sptd.sys
2008-03-18 03:41 . 2008-03-03 15:05 54,672 --a------ C:\Windows\System32\vsutil_loc040c.dll
2008-03-18 03:41 . 2008-03-25 19:06 16,713 --a------ C:\Windows\System32\vsconfig.xml
2008-03-18 03:40 . 2008-03-25 19:08 <REP> d-------- C:\Windows\System32\ZoneLabs
2008-03-18 03:40 . 2008-03-25 23:38 352,616 --ah----- C:\Windows\System32\drivers\vsconfig.xml
2008-03-18 03:40 . 2008-01-23 10:38 276,368 --a------ C:\Windows\System32\drivers\~GLH0014.TMP
2008-03-18 01:09 . 2008-03-18 01:09 <REP> d-------- C:\Users\All Users\CheckPoint
2008-03-18 01:09 . 2008-03-18 01:09 <REP> d-------- C:\PROGRA~2\CheckPoint
2008-03-17 00:53 . 2008-03-17 00:53 <REP> d-------- C:\Program Files\Infogrames
2008-03-16 20:39 . 2008-03-18 18:35 <REP> d-------- C:\Program Files\GameSpy Arcade
2008-03-16 20:02 . 2008-03-16 20:02 <REP> d-------- C:\Program Files\2015
2008-03-16 19:51 . 2008-03-16 19:51 <REP> d-------- C:\Users\yoann\AppData\Roaming\tmp
2008-03-16 19:51 . 2008-03-16 19:51 <REP> d-------- C:\Users\yoann\AppData\Roaming\Reallusion
2008-03-16 14:00 . 2008-03-16 14:00 <REP> d-------- C:\Program Files\RSA
2008-03-16 13:57 . 2008-03-16 13:57 <REP> d-------- C:\Users\All Users\UIB
2008-03-16 13:57 . 2008-03-16 13:57 <REP> d-------- C:\PROGRA~2\UIB
2008-03-16 02:41 . 2008-03-16 02:41 98,304 --a------ C:\Windows\System32\CmdLineExt.dll
2008-03-16 02:27 . 2008-03-16 02:27 <REP> d-------- C:\Program Files\Ubisoft
2008-03-16 01:34 . 2008-03-16 01:34 <REP> d-------- C:\perflogs
2008-03-15 16:20 . 2008-03-15 16:20 <REP> d-------- C:\Users\yoann\AppData\Roaming\Roxio
2008-03-15 16:20 . 2008-03-15 16:20 <REP> d-------- C:\Users\All Users\Roxio
2008-03-15 16:20 . 2008-03-15 16:20 <REP> d-------- C:\PROGRA~2\Roxio
2008-03-14 01:10 . 2008-03-14 01:09 691,545 --a------ C:\Windows\unins000.exe
2008-03-14 01:10 . 2008-03-14 01:10 2,543 --a------ C:\Windows\unins000.dat
2008-03-14 01:06 . 2008-03-18 02:07 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-03-14 01:06 . 2008-03-14 12:17 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-14 01:06 . 2008-03-18 02:07 <REP> d-------- C:\PROGRA~2\Spybot - Search & Destroy
2008-03-14 01:05 . 2008-03-25 23:40 <REP> d-------- C:\Windows\Internet Logs
2008-03-14 01:05 . 2008-03-14 01:05 <REP> d-------- C:\Program Files\Zone Labs
2008-03-13 21:15 . 2008-03-13 21:15 <REP> d-------- C:\Users\All Users\Avira
2008-03-13 21:15 . 2008-03-13 21:15 <REP> d-------- C:\Program Files\Avira
2008-03-13 21:15 . 2008-03-13 21:15 <REP> d-------- C:\PROGRA~2\Avira
2008-03-13 20:21 . 2008-03-13 20:21 <REP> d-------- C:\Program Files\CCleaner
2008-03-13 19:40 . 2008-03-13 19:42 1,905 --a------ C:\Windows\diagwrn.xml
2008-03-13 19:40 . 2008-03-13 19:42 1,905 --a------ C:\Windows\diagerr.xml
2008-03-12 12:39 . 2007-12-16 23:50 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-03-12 12:39 . 2007-12-16 10:56 41,984 --a------ C:\Windows\System32\drivers\monitor.sys
2008-03-12 03:01 . 2008-03-12 03:01 <REP> d-------- C:\Users\All Users\Age of Empires 3
2008-03-12 03:01 . 2008-03-12 03:01 <REP> d-------- C:\PROGRA~2\Age of Empires 3
2008-03-11 13:29 . 2008-03-11 13:29 <REP> d-------- C:\Program Files\Alwil Software
2008-03-10 19:16 . 2008-03-10 19:16 <REP> d-------- C:\Users\yoann\AppData\Roaming\eMule
2008-03-10 19:16 . 2008-03-24 21:37 <REP> d-------- C:\Users\All Users\eMule
2008-03-10 19:16 . 2008-03-24 21:37 <REP> d-------- C:\PROGRA~2\eMule
2008-03-08 20:33 . 2008-03-08 20:33 <REP> d-------- C:\Users\All Users\Trymedia
2008-03-08 20:33 . 2008-03-08 20:33 <REP> d-------- C:\PROGRA~2\Trymedia
2008-03-08 20:33 . 2008-03-08 20:33 218,929 --a------ C:\Windows\Prison Tycoon 2 Uninstaller.exe
2008-03-08 20:31 . 2008-03-08 20:31 <REP> d-------- C:\Windows\System32\URTTEMP
2008-03-08 20:21 . 2008-03-08 20:21 <REP> d-------- C:\Windows\System32\storage
2008-03-08 12:52 . 2005-05-26 15:34 2,297,552 --a------ C:\Windows\System32\d3dx9_26.dll
2008-03-08 04:48 . 2008-03-14 19:21 <REP> d-------- C:\Program Files\Dofus
2008-03-08 03:15 . 2008-03-08 03:15 5,917 --a------ C:\WirelessDiagLog.csv
2008-03-08 02:48 . 2008-03-12 02:32 <REP> d-------- C:\Downloads
2008-03-08 00:49 . 2008-03-23 18:42 573 --a------ C:\Windows\eReg.dat
2008-03-08 00:48 . 2008-03-08 00:48 <REP> d-------- C:\Program Files\AceGain
2008-03-08 00:48 . 2008-03-08 00:48 729,088 --a------ C:\Windows\iun6002.exe
2008-03-08 00:47 . 1998-06-17 17:07 57,344 --a------ C:\Windows\System32\Mfc42loc.dll
2008-03-08 00:28 . 2008-03-21 00:54 <REP> d-------- C:\Program Files\EA GAMES
2008-03-07 02:12 . 2008-03-07 02:12 <REP> d-------- C:\Users\yoann\AppData\Roaming\FlashGet
2008-03-07 02:11 . 2008-03-07 02:14 <REP> d-------- C:\Program Files\FlashGet
2008-03-06 01:40 . 2008-03-06 01:40 <REP> d-------- C:\Users\yoann\AppData\Roaming\Intel
2008-03-05 23:46 . 2008-03-05 23:46 <REP> d-------- C:\Users\All Users\Last.fm
2008-03-05 23:46 . 2008-03-05 23:46 <REP> d-------- C:\PROGRA~2\Last.fm
2008-03-05 23:30 . 2008-03-05 23:30 <REP> d-------- C:\Program Files\Last.fm
2008-03-04 23:33 . 2008-03-04 23:33 <REP> d-------- C:\Users\yoann\AppData\Roaming\vlc
2008-03-04 23:15 . 2008-03-18 02:07 <REP> d-------- C:\Users\yoann\AppData\Roaming\Winamp
2008-03-04 23:15 . 2008-03-05 20:11 <REP> d-------- C:\Program Files\Winamp
2008-03-04 23:08 . 2008-03-04 23:08 <REP> d-------- C:\Users\yoann\AppData\Roaming\InstallShield
2008-03-04 20:26 . 2008-03-04 20:26 <REP> d-------- C:\Program Files\VideoLAN
2008-03-04 20:02 . 2008-03-04 20:02 <REP> d-------- C:\Windows\PCHEALTH
2008-03-04 20:00 . 2008-03-04 20:00 0 --a------ C:\Windows\nsreg.dat
2008-03-04 19:58 . 2008-03-04 20:02 <REP> d-------- C:\Program Files\Windows Live
2008-03-04 19:58 . 2008-03-04 20:01 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-04 19:57 . 2008-03-04 19:57 <REP> d-------- C:\Users\All Users\WLInstaller
2008-03-04 19:57 . 2008-03-04 19:57 <REP> d-------- C:\PROGRA~2\WLInstaller
2008-03-04 19:20 . 2008-03-04 19:20 <REP> d-------- C:\Users\yoann\AppData\Roaming\Creative
2008-03-04 19:20 . 2006-04-29 14:25 40,960 --a------ C:\Windows\System32\psfind.dll
2008-03-04 19:18 . 2008-03-04 19:18 <REP> d-------- C:\Users\yoann\AppData\Roaming\CyberLink
2008-03-04 19:12 . 2008-03-04 19:12 <REP> d-------- C:\Program Files\THQ
2008-03-04 18:44 . 2008-03-24 23:35 95,219 --a------ C:\Users\yoann\AppData\Roaming\nvModes.dat
2008-03-04 13:14 . 2008-03-04 13:14 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-03-04 13:14 . 2008-03-04 13:14 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-03-04 13:11 . 2008-03-04 13:11 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-03-04 13:11 . 2008-03-04 13:11 3,470,392 --a------ C:\Windows\System32\ntoskrnl.exe
2008-03-04 13:11 . 2008-03-04 13:11 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-03-04 13:11 . 2008-03-04 13:11 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-03-04 13:11 . 2008-03-04 13:11 110,136 --a------ C:\Windows\System32\drivers\ataport.sys
2008-03-04 13:11 . 2008-03-04 13:11 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-03-04 13:11 . 2008-03-04 13:11 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 00:09 2,157,568 ----a-w C:\Windows\Internet Logs\xDBBF29.tmp
2008-03-18 22:17 547,840 ----a-w C:\Windows\Internet Logs\xDB904D.tmp
2008-03-13 23:27 --------- d-----w C:\Program Files\Microsoft Games
2008-03-13 11:24 --------- d-----w C:\Program Files\Windows Mail
2008-03-05 15:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll
2008-03-05 15:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll
2008-03-05 15:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll
2008-03-05 14:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll
2008-03-05 14:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll
2008-03-04 17:45 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-04 12:10 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-04 12:10 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-04 12:10 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-04 12:10 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-04 12:07 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-03-04 12:07 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-03-04 12:07 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-03-04 12:07 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-03-04 11:43 --------- d-sh--w C:\Program Files\Fichiers communs
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Modèles
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Menu Démarrer
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Favoris
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Documents
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Bureau
2008-03-04 11:43 --------- d-sh--w C:\PROGRA~2\Application Data
2008-02-29 09:08 25,784 ------w C:\Windows\system32\drivers\msahci.sys
2008-02-29 09:08 20,152 ------w C:\Windows\system32\drivers\viaide.sys
2008-02-29 09:08 19,128 ------w C:\Windows\system32\drivers\cmdide.sys
2008-02-29 09:08 18,104 ------w C:\Windows\system32\drivers\amdide.sys
2008-02-29 09:08 17,592 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-02-29 09:08 17,592 ------w C:\Windows\system32\drivers\aliide.sys
2008-02-29 09:04 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-02-29 09:03 --------- d-----w C:\Program Files\Windows Calendar
2008-02-29 09:01 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys
2008-02-29 09:01 13,312 ----a-w C:\Windows\system32\drivers\sffdisk.sys
2008-02-29 09:01 12,800 ----a-w C:\Windows\system32\drivers\sffp_sd.sys
2008-02-29 09:01 12,800 ------w C:\Windows\system32\drivers\sffp_mmc.sys
2008-02-29 08:59 --------- d-----w C:\Program Files\Windows Defender
2008-02-29 08:56 72,192 ----a-w C:\Windows\System32\dot3msm.dll
2008-02-29 08:55 98,304 ----a-w C:\Windows\System32\mssitlb.dll
2008-02-29 01:16 174 --sha-w C:\Program Files\desktop.ini
2008-02-05 22:07 462,864 ----a-w C:\Windows\System32\d3dx10_37.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@={F2F31467-B1AC-4df0-AE79-FD5FA085E22B}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@={A3E208F7-0E3A-4182-A7A6-B169D5D691AA}
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-11-14 12:22 3186440 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-11-14 12:22 3186440 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-04 13:10 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-02-20 15:15 816368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-02-29 09:59 1006264]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-07 09:50 159744]
"OEM02Mon.exe"="C:\Windows\OEM02Mon.exe" [2007-08-28 06:51 36864]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-12-03 05:28 405504]
"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-02-29 02:24 77824]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 17:43 118784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 14:00 174872]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-12-21 10:58 184320]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-13 21:16 249896]
"Windows Mobile-based device management"="%windir%\WindowsMobile\wmdSync.exe" [ ]
"PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [2007-11-14 11:38 49416]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-10-04 21:24 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-10-04 21:24 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-10-04 21:24 81920]
"NVHotkey"="C:\Windows\system32\nvHotkey.dll" [2007-10-04 21:24 86016]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 15:05 959976]
C:\Users\yoann\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Last.fm Helper.lnk - C:\Program Files\Last.fm\LastFMHelper.exe [2008-03-05 23:30:14 106496]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 18:55:50 703280]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [2007-09-07 17:27:08 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Windows\system32\psqlpwd.dll 2007-11-14 12:07 96008 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BA820E37-9489-4680-836D-66492FF491A6}"= C:\Program Files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{F6357A9D-5EE0-4270-9093-B50D7123967C}"= C:\Program Files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{751BA52B-3CF4-4B1C-9756-9623DF19FDEA}"= C:\Program Files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{E247EB81-A34D-4090-A05C-515DBAD90079}"= C:\Program Files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{1B7AB382-CBB7-42C2-B16E-3663FC0A2E1A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{AE167D44-E648-4D5D-A365-455723597886}C:\\program files\\ea games\\battlefield vietnam\\bfvietnam.exe"= UDP:C:\program files\ea games\battlefield vietnam\bfvietnam.exe:BfVietnam
"UDP Query User{20734507-EC8F-4A6C-ADAC-0C6046395DA8}C:\\program files\\ea games\\battlefield vietnam\\bfvietnam.exe"= TCP:C:\program files\ea games\battlefield vietnam\bfvietnam.exe:BfVietnam
"TCP Query User{3FF16852-0BED-4E93-8240-8220961B7501}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{4C2EE5C2-FD8D-45F6-BC58-92D9B4A145C7}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{8FFBC942-FD61-4B84-881A-EAB5EAEA94DE}C:\\program files\\ea games\\battlefield vietnam\\bfvietnam.exe"= UDP:C:\program files\ea games\battlefield vietnam\bfvietnam.exe:BfVietnam
"UDP Query User{E63571FB-B458-4305-BDEC-CA016009FBB8}C:\\program files\\ea games\\battlefield vietnam\\bfvietnam.exe"= TCP:C:\program files\ea games\battlefield vietnam\bfvietnam.exe:BfVietnam
"{ED1C95D0-991C-4320-80E8-4F9D40561D9E}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{A02B7A6F-12BB-44CA-B7EB-FB2E53A50BC3}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{96F5E24E-CE9A-4BC0-9D62-B332DD9288C7}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:Age of Empires III - The Asian Dynasties
"{DCEFBDAB-7619-4170-A697-CDDD625B9781}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3y.exe:Age of Empires III - The Asian Dynasties
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\system32\aestsrv.exe [2007-12-03 05:27]
R2 RapiMgr;Connectivité de l'appareil Windows Mobile;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
R2 WcesComm;Connectivité de l'appareil Windows Mobile 2003;C:\Windows\system32\svchost.exe [2006-11-02 10:45]
R3 OEM02Dev;Creative Camera OEM002 Driver;C:\Windows\system32\DRIVERS\OEM02Dev.sys [2007-08-28 06:51]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM02Vfx.sys [2007-08-28 06:51]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-28 07:40]
S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2006-11-07 02:37]
S3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2006-11-07 00:13]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2006-11-07 00:13]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 08:36]
S3 TcUsb;TC USB Kernel Driver;C:\Windows\system32\Drivers\tcusb.sys [2007-11-14 11:29]
S4 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\drivers\ianvstor.sys [2007-09-07 10:27]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{adf69c5e-f612-11dc-b472-0015c5869235}]
\shell\AutoRun\command - F:\autorun.exe
\shell\setup\command - F:\install.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-25 23:42:49
Windows 6.0.6000 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-25 23:46:54 - machine was rebooted [yoann]
ComboFix-quarantined-files.txt 2008-03-25 22:46:47
.
2008-03-16 08:05:39 --- E O F ---