ComboFix 08-02-23 - PG 2008-02-24 11:20:19.2 - NTFSx86
Endroit: C:\Documents and Settings\PG\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\kavo.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-24 to 2008-02-24 ))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:03 . 2008-02-22 18:03 <REP> d-------- C:\Program Files\Trend Micro
2008-02-18 15:33 . 2008-01-31 15:00 113,906 -r-hs---- C:\p3r1ud.exe
2008-01-24 14:26 . 2005-08-17 12:02 93,904 -ra------ C:\WINDOWS\system32\drivers\cmo_mdm.sys
2008-01-24 14:26 . 2005-08-17 12:04 73,696 -ra------ C:\WINDOWS\system32\drivers\cmo_serd.sys
2008-01-24 14:26 . 2005-08-17 11:59 58,352 -ra------ C:\WINDOWS\system32\drivers\cmo_bus.sys
2008-01-24 14:26 . 2005-08-17 12:02 8,304 -ra------ C:\WINDOWS\system32\drivers\cmo_mdfl.sys
2008-01-24 14:26 . 2005-08-17 12:03 6,176 -ra------ C:\WINDOWS\system32\drivers\cmo_cmnt.sys
2008-01-24 14:26 . 2005-08-17 12:03 6,176 -ra------ C:\WINDOWS\system32\drivers\cmo_cm.sys
2008-01-24 14:26 . 2005-08-17 11:59 5,840 -ra------ C:\WINDOWS\system32\drivers\cmo_whnt.sys
2008-01-24 14:26 . 2005-08-17 11:59 5,840 -ra------ C:\WINDOWS\system32\drivers\cmo_wh.sys
2008-01-24 14:20 . 2008-01-24 14:21 <REP> d-------- C:\Program Files\Interjet
2008-01-24 14:20 . 2006-03-09 16:40 196,608 -r------- C:\WINDOWS\PINSTALLPROCESS.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 15:23 --------- d-----w C:\Documents and Settings\PG\Application Data\Skype
2008-02-24 14:40 9,280 ----a-w C:\Documents and Settings\PG\Application Data\wklnhst.dat
2008-02-24 14:28 15,249,147 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-23 22:21 4,631,552 ----a-w C:\WINDOWS\Internet Logs\xDB7B.tmp
2008-02-23 22:21 218,112 ----a-w C:\WINDOWS\Internet Logs\xDB7A.tmp
2008-02-22 18:15 3,378,176 ----a-w C:\WINDOWS\Internet Logs\xDB78.tmp
2008-02-22 18:14 4,584,448 ----a-w C:\WINDOWS\Internet Logs\xDB79.tmp
2008-02-21 14:57 --------- d-----w C:\Program Files\Comptes Bancaires 5.6
2008-02-19 18:09 --------- d-----w C:\Documents and Settings\PG\Application Data\UseNeXT
2008-02-19 17:13 4,578,304 ----a-w C:\WINDOWS\Internet Logs\xDB7E.tmp
2008-02-19 17:13 151,040 ----a-w C:\WINDOWS\Internet Logs\xDB77.tmp
2008-02-18 18:13 96,256 ----a-w C:\WINDOWS\Internet Logs\xDB75.tmp
2008-02-18 18:13 4,574,208 ----a-w C:\WINDOWS\Internet Logs\xDB76.tmp
2008-02-15 22:58 128,000 ----a-w C:\WINDOWS\Internet Logs\xDB74.tmp
2008-02-14 21:35 206,336 ----a-w C:\WINDOWS\Internet Logs\xDB73.tmp
2008-02-11 22:48 4,564,480 ----a-w C:\WINDOWS\Internet Logs\xDB72.tmp
2008-02-11 22:48 192,512 ----a-w C:\WINDOWS\Internet Logs\xDB71.tmp
2008-02-11 00:49 492,544 ----a-w C:\WINDOWS\Internet Logs\xDB70.tmp
2008-02-07 00:29 4,540,928 ----a-w C:\WINDOWS\Internet Logs\xDB6F.tmp
2008-02-07 00:29 313,856 ----a-w C:\WINDOWS\Internet Logs\xDB6E.tmp
2008-02-04 20:14 307,712 ----a-w C:\WINDOWS\Internet Logs\xDB6D.tmp
2008-01-30 22:26 4,530,176 ----a-w C:\WINDOWS\Internet Logs\xDB6B.tmp
2008-01-30 22:26 111,104 ----a-w C:\WINDOWS\Internet Logs\xDB69.tmp
2008-01-30 08:33 337,408 ----a-w C:\WINDOWS\Internet Logs\xDB68.tmp
2008-01-27 17:33 470,528 ----a-w C:\WINDOWS\Internet Logs\xDB67.tmp
2008-01-27 17:33 4,434,944 ----a-w C:\WINDOWS\Internet Logs\xDB6C.tmp
2008-01-26 16:52 24,043,954 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_01_26_12_45_05_full.dmp.zip
2008-01-26 16:32 17,604,376 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_01_26_12_21_26_full.dmp.zip
2008-01-26 16:32 128,440 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_01_26_12_20_42_small.dmp.zip
2008-01-24 18:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 21:22 1,181,696 ----a-w C:\WINDOWS\Internet Logs\xDB65.tmp
2008-01-21 21:21 4,414,464 ----a-w C:\WINDOWS\Internet Logs\xDB66.tmp
2008-01-07 17:37 249,344 ----a-w C:\WINDOWS\Internet Logs\xDB64.tmp
2007-12-31 23:09 4,402,688 ----a-w C:\WINDOWS\Internet Logs\xDB63.tmp
2007-12-31 23:09 336,384 ----a-w C:\WINDOWS\Internet Logs\xDB62.tmp
2007-12-23 17:26 942,592 ----a-w C:\WINDOWS\Internet Logs\xDB61.tmp
2007-12-13 23:27 54,672 ----a-w C:\WINDOWS\system32\vsutil_loc040c.dll
2007-12-13 23:27 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-12-10 22:28 166,912 ----a-w C:\WINDOWS\Internet Logs\xDB60.tmp
2007-12-07 17:58 457,728 ----a-w C:\WINDOWS\Internet Logs\xDB5F.tmp
2007-12-04 17:58 1,286,144 ----a-w C:\WINDOWS\Internet Logs\xDB5E.tmp
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-12 16:35 214,528 ----a-w C:\WINDOWS\Internet Logs\xDBDE.tmp
2007-11-08 20:56 498,176 ----a-w C:\WINDOWS\Internet Logs\xDBC0.tmp
2007-10-26 21:47 745,984 ----a-w C:\WINDOWS\Internet Logs\xDB5C.tmp
2007-10-26 21:47 4,317,696 ----a-w C:\WINDOWS\Internet Logs\xDB88.tmp
2007-10-22 23:25 517,632 ----a-w C:\WINDOWS\Internet Logs\xDB59.tmp
2007-10-21 23:24 81,920 ----a-w C:\WINDOWS\Internet Logs\xDB5A.tmp
2007-10-21 23:24 4,303,360 ----a-w C:\WINDOWS\Internet Logs\xDB5B.tmp
2007-10-20 00:12 4,303,360 ----a-w C:\WINDOWS\Internet Logs\xDB58.tmp
2007-10-20 00:12 111,616 ----a-w C:\WINDOWS\Internet Logs\xDB57.tmp
2007-10-19 03:18 4,302,336 ----a-w C:\WINDOWS\Internet Logs\xDB56.tmp
2007-10-19 03:18 288,768 ----a-w C:\WINDOWS\Internet Logs\xDB55.tmp
2007-10-17 21:42 548,352 ----a-w C:\WINDOWS\Internet Logs\xDB53.tmp
2007-10-17 21:42 4,298,752 ----a-w C:\WINDOWS\Internet Logs\xDB54.tmp
2007-10-16 02:26 401,920 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2007-10-16 02:26 4,297,216 ----a-w C:\WINDOWS\Internet Logs\xDB6A.tmp
2007-10-11 21:56 679,424 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2007-10-11 21:56 4,294,144 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2007-10-10 00:56 454,656 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2007-10-10 00:56 4,291,584 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2007-10-09 00:26 1,852,416 ----a-w C:\WINDOWS\Internet Logs\xDB8C.tmp
2007-10-02 02:50 515,584 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2007-10-01 02:38 567,296 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2007-10-01 02:38 4,273,664 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2007-09-27 02:40 633,856 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2007-09-27 02:40 4,271,104 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2007-09-20 23:16 4,265,984 ----a-w C:\WINDOWS\Internet Logs\xDB5D.tmp
2007-09-20 23:16 1,333,760 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2007-09-18 02:01 4,252,672 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2007-09-18 02:01 3,019,776 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2007-08-21 00:44 4,149,760 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2007-08-21 00:44 1,972,224 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2007-08-14 00:36 4,012,032 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2007-08-14 00:36 333,824 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2007-08-13 02:43 315,904 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2007-08-12 04:02 433,664 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2007-08-11 03:08 4,009,472 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2007-08-11 03:08 1,306,624 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2007-08-06 02:25 400,384 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2007-08-06 02:25 3,996,672 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2007-08-04 03:45 3,994,624 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2007-08-04 03:45 1,348,608 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2007-07-30 01:04 3,971,584 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2007-07-30 01:04 3,517,440 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2007-07-15 22:08 22,150,944 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_07_14_16_54_03_full.dmp.zip
2007-05-15 21:07 3,174,400 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2007-04-14 15:14 4,004,864 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2007-03-31 08:32 3,308,544 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2007-03-31 08:31 3,689,472 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2007-03-25 06:24 3,662,848 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2007-03-25 06:24 2,219,008 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2007-03-24 07:08 3,662,336 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2007-03-24 07:08 2,791,936 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2007-03-20 02:03 1,923,072 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2007-03-19 05:15 3,651,072 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-03-19 05:15 1,178,112 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2007-03-18 14:46 2,822,144 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2007-03-13 00:20 3,614,208 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 18:03 683520]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 05:10 536576]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-02-06 12:49 19490344]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2005-05-25 07:07 188459]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 11:46 192512]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 05:56 1077327]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-05 12:16 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 09:37 88363 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-01-21 16:48 675840]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 16:06 53248]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 16:24 24576]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 13:07 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 10:59 65536]
"Zooming"="ZoomingHook.exe" [2004-07-14 11:07 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-02-16 09:43 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-01-21 05:28 266240 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2004-11-15 05:49 118784]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 12:57 73728]
"NDSTray.exe"="NDSTray.exe" []
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-13 20:05 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 04:03 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 03:59 126976]
"TFncKy"="TFncKy.exe" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 09:00 79224]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-07-04 08:38 180269]
"CFSServ.exe"="CFSServ.exe" []
"eCarteBleue-LP-P1"="C:\Program Files\e-Carte Bleue\LA POSTE\CVD ADESIO\ECB.exe" [2002-12-20 03:49 188416]
"RIP PopUp"="C:\Program Files\RIP PopUp\nopopup.exe" [ ]
"CmUsbAudio"="cmcnfg2.cpl" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-08 00:42 176128]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"srePostpone"="c:\windows\system32\zonelabs\srescan.dll" [2008-01-28 12:28 1504736]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 07:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-13 22:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 17:20:56 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr;C:\WINDOWS\system32\drivers\EPIOMngr.sys [2004-07-30 10:05]
R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys [2005-02-25 14:08]
S1 StickyMesger;StickyMesger;C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys []
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\cmo_bus.sys [2005-08-17 11:59]
S3 cmo_mdfl;Data Modem @ CDMA Filter;C:\WINDOWS\system32\DRIVERS\cmo_mdfl.sys [2005-08-17 12:02]
S3 cmo_mdm;Data Modem @ CDMA Drivers;C:\WINDOWS\system32\DRIVERS\cmo_mdm.sys [2005-08-17 12:02]
S3 cmo_serd;Data Modem @ CDMA Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\cmo_serd.sys [2005-08-17 12:04]
S3 cmuda2;C-Media USB Audio Interface;C:\WINDOWS\system32\drivers\cmuda2.sys [2004-06-16 04:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e41bd128-db42-11dc-beb0-000fb084009f}]
\Shell\AutoRun\command - E:\p3r1ud.exe
\Shell\explore\Command - E:\p3r1ud.exe
\Shell\open\Command - E:\p3r1ud.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2005-03-18 08:54:28 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-24 11:23:49
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-24 11:25:03
ComboFix-quarantined-files.txt 2008-02-24 15:24:47
ComboFix2.txComboFix 08-02-23 - PG 2008-02-22 18:16:02.1 - NTFSx86
Endroit: C:\Documents and Settings\PG\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\a.exe
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\packet.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-23 to 2008-02-23 ))))))))))))))))))))))))))))))))))))
.
2008-02-22 18:03 . 2008-02-22 18:03 <REP> d-------- C:\Program Files\Trend Micro
2008-02-18 15:33 . 2008-01-31 15:00 113,906 -r-hs---- C:\p3r1ud.exe
2008-01-24 14:26 . 2005-08-17 12:02 93,904 -ra------ C:\WINDOWS\system32\drivers\cmo_mdm.sys
2008-01-24 14:26 . 2005-08-17 12:04 73,696 -ra------ C:\WINDOWS\system32\drivers\cmo_serd.sys
2008-01-24 14:26 . 2005-08-17 11:59 58,352 -ra------ C:\WINDOWS\system32\drivers\cmo_bus.sys
2008-01-24 14:26 . 2005-08-17 12:02 8,304 -ra------ C:\WINDOWS\system32\drivers\cmo_mdfl.sys
2008-01-24 14:26 . 2005-08-17 12:03 6,176 -ra------ C:\WINDOWS\system32\drivers\cmo_cmnt.sys
2008-01-24 14:26 . 2005-08-17 12:03 6,176 -ra------ C:\WINDOWS\system32\drivers\cmo_cm.sys
2008-01-24 14:26 . 2005-08-17 11:59 5,840 -ra------ C:\WINDOWS\system32\drivers\cmo_whnt.sys
2008-01-24 14:26 . 2005-08-17 11:59 5,840 -ra------ C:\WINDOWS\system32\drivers\cmo_wh.sys
2008-01-24 14:20 . 2008-01-24 14:21 <REP> d-------- C:\Program Files\Interjet
2008-01-24 14:20 . 2006-03-09 16:40 196,608 -r------- C:\WINDOWS\PINSTALLPROCESS.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 22:21 4,631,552 ----a-w C:\WINDOWS\Internet Logs\xDB7B.tmp
2008-02-23 22:21 218,112 ----a-w C:\WINDOWS\Internet Logs\xDB7A.tmp
2008-02-23 22:16 --------- d-----w C:\Documents and Settings\PG\Application Data\Skype
2008-02-22 18:15 3,378,176 ----a-w C:\WINDOWS\Internet Logs\xDB78.tmp
2008-02-22 18:14 4,584,448 ----a-w C:\WINDOWS\Internet Logs\xDB79.tmp
2008-02-21 14:57 --------- d-----w C:\Program Files\Comptes Bancaires 5.6
2008-02-19 18:09 --------- d-----w C:\Documents and Settings\PG\Application Data\UseNeXT
2008-02-19 17:13 4,578,304 ----a-w C:\WINDOWS\Internet Logs\xDB7E.tmp
2008-02-19 17:13 151,040 ----a-w C:\WINDOWS\Internet Logs\xDB77.tmp
2008-02-18 18:13 96,256 ----a-w C:\WINDOWS\Internet Logs\xDB75.tmp
2008-02-18 18:13 4,574,208 ----a-w C:\WINDOWS\Internet Logs\xDB76.tmp
2008-02-15 22:58 128,000 ----a-w C:\WINDOWS\Internet Logs\xDB74.tmp
2008-02-14 21:35 206,336 ----a-w C:\WINDOWS\Internet Logs\xDB73.tmp
2008-02-11 22:48 4,564,480 ----a-w C:\WINDOWS\Internet Logs\xDB72.tmp
2008-02-11 22:48 192,512 ----a-w C:\WINDOWS\Internet Logs\xDB71.tmp
2008-02-11 00:49 492,544 ----a-w C:\WINDOWS\Internet Logs\xDB70.tmp
2008-02-07 00:29 4,540,928 ----a-w C:\WINDOWS\Internet Logs\xDB6F.tmp
2008-02-07 00:29 313,856 ----a-w C:\WINDOWS\Internet Logs\xDB6E.tmp
2008-02-04 20:14 307,712 ----a-w C:\WINDOWS\Internet Logs\xDB6D.tmp
2008-02-02 19:00 9,170 ----a-w C:\Documents and Settings\PG\Application Data\wklnhst.dat
2008-01-30 22:26 4,530,176 ----a-w C:\WINDOWS\Internet Logs\xDB6B.tmp
2008-01-30 22:26 111,104 ----a-w C:\WINDOWS\Internet Logs\xDB69.tmp
2008-01-30 08:33 337,408 ----a-w C:\WINDOWS\Internet Logs\xDB68.tmp
2008-01-27 17:33 470,528 ----a-w C:\WINDOWS\Internet Logs\xDB67.tmp
2008-01-27 17:33 4,434,944 ----a-w C:\WINDOWS\Internet Logs\xDB6C.tmp
2008-01-26 16:52 24,043,954 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_01_26_12_45_05_full.dmp.zip
2008-01-26 16:32 17,604,376 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2008_01_26_12_21_26_full.dmp.zip
2008-01-26 16:32 128,440 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_01_26_12_20_42_small.dmp.zip
2008-01-24 18:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 21:22 1,181,696 ----a-w C:\WINDOWS\Internet Logs\xDB65.tmp
2008-01-21 21:21 4,414,464 ----a-w C:\WINDOWS\Internet Logs\xDB66.tmp
2008-01-15 14:33 13,509,181 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-01-07 17:37 249,344 ----a-w C:\WINDOWS\Internet Logs\xDB64.tmp
2007-12-31 23:09 4,402,688 ----a-w C:\WINDOWS\Internet Logs\xDB63.tmp
2007-12-31 23:09 336,384 ----a-w C:\WINDOWS\Internet Logs\xDB62.tmp
2007-12-23 17:26 942,592 ----a-w C:\WINDOWS\Internet Logs\xDB61.tmp
2007-12-13 23:27 54,672 ----a-w C:\WINDOWS\system32\vsutil_loc040c.dll
2007-12-13 23:27 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
2007-12-10 22:28 166,912 ----a-w C:\WINDOWS\Internet Logs\xDB60.tmp
2007-12-07 17:58 457,728 ----a-w C:\WINDOWS\Internet Logs\xDB5F.tmp
2007-12-04 17:58 1,286,144 ----a-w C:\WINDOWS\Internet Logs\xDB5E.tmp
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-12 16:35 214,528 ----a-w C:\WINDOWS\Internet Logs\xDBDE.tmp
2007-11-08 20:56 498,176 ----a-w C:\WINDOWS\Internet Logs\xDBC0.tmp
2007-10-26 21:47 745,984 ----a-w C:\WINDOWS\Internet Logs\xDB5C.tmp
2007-10-26 21:47 4,317,696 ----a-w C:\WINDOWS\Internet Logs\xDB88.tmp
2007-10-22 23:25 517,632 ----a-w C:\WINDOWS\Internet Logs\xDB59.tmp
2007-10-21 23:24 81,920 ----a-w C:\WINDOWS\Internet Logs\xDB5A.tmp
2007-10-21 23:24 4,303,360 ----a-w C:\WINDOWS\Internet Logs\xDB5B.tmp
2007-10-20 00:12 4,303,360 ----a-w C:\WINDOWS\Internet Logs\xDB58.tmp
2007-10-20 00:12 111,616 ----a-w C:\WINDOWS\Internet Logs\xDB57.tmp
2007-10-19 03:18 4,302,336 ----a-w C:\WINDOWS\Internet Logs\xDB56.tmp
2007-10-19 03:18 288,768 ----a-w C:\WINDOWS\Internet Logs\xDB55.tmp
2007-10-17 21:42 548,352 ----a-w C:\WINDOWS\Internet Logs\xDB53.tmp
2007-10-17 21:42 4,298,752 ----a-w C:\WINDOWS\Internet Logs\xDB54.tmp
2007-10-16 02:26 401,920 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2007-10-16 02:26 4,297,216 ----a-w C:\WINDOWS\Internet Logs\xDB6A.tmp
2007-10-11 21:56 679,424 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2007-10-11 21:56 4,294,144 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2007-10-10 00:56 454,656 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2007-10-10 00:56 4,291,584 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2007-10-09 00:26 1,852,416 ----a-w C:\WINDOWS\Internet Logs\xDB8C.tmp
2007-10-02 02:50 515,584 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2007-10-01 02:38 567,296 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2007-10-01 02:38 4,273,664 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2007-09-27 02:40 633,856 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2007-09-27 02:40 4,271,104 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2007-09-20 23:16 4,265,984 ----a-w C:\WINDOWS\Internet Logs\xDB5D.tmp
2007-09-20 23:16 1,333,760 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2007-09-18 02:01 4,252,672 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2007-09-18 02:01 3,019,776 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2007-08-21 00:44 4,149,760 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2007-08-21 00:44 1,972,224 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2007-08-14 00:36 4,012,032 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2007-08-14 00:36 333,824 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2007-08-13 02:43 315,904 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2007-08-12 04:02 433,664 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2007-08-11 03:08 4,009,472 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2007-08-11 03:08 1,306,624 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2007-08-06 02:25 400,384 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2007-08-06 02:25 3,996,672 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2007-08-04 03:45 3,994,624 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2007-08-04 03:45 1,348,608 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2007-07-30 01:04 3,971,584 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2007-07-30 01:04 3,517,440 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2007-07-15 22:08 22,150,944 ----a-w C:\WINDOWS\Internet Logs\vsmon_on_demand_2007_07_14_16_54_03_full.dmp.zip
2007-05-15 21:07 3,174,400 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2007-04-14 15:14 4,004,864 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2007-03-31 08:32 3,308,544 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2007-03-31 08:31 3,689,472 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2007-03-25 06:24 3,662,848 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2007-03-25 06:24 2,219,008 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2007-03-24 07:08 3,662,336 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2007-03-24 07:08 2,791,936 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2007-03-20 02:03 1,923,072 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2007-03-19 05:15 3,651,072 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-03-19 05:15 1,178,112 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2007-03-18 14:46 2,822,144 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2007-03-13 00:20 3,614,208 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 18:03 683520]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 05:10 536576]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-02-06 12:49 19490344]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2005-05-25 07:07 188459]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2003-10-30 11:46 192512]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 05:56 1077327]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-05 12:16 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 09:37 88363 C:\WINDOWS\agrsmmsg.exe]
"CeEKEY"="C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe" [2005-01-21 16:48 675840]
"TPNF"="C:\Program Files\TOSHIBA\TouchPad\TPTray.exe" [2004-11-29 16:06 53248]
"TOSHIBA Accessibility"="C:\Program Files\TOSHIBA\Accessibility\FnKeyHook.exe" [2004-12-07 16:24 24576]
"HWSetup"="C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe" [2004-12-23 13:07 28672]
"SVPWUTIL"="C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe" [2005-02-25 10:59 65536]
"Zooming"="ZoomingHook.exe" [2004-07-14 11:07 24576 C:\WINDOWS\system32\ZoomingHook.exe]
"TCtryIOHook"="TCtrlIOHook.exe" [2005-02-16 09:43 28672 C:\WINDOWS\system32\TCtrlIOHook.exe]
"TPSMain"="TPSMain.exe" [2005-01-21 05:28 266240 C:\WINDOWS\system32\TPSMain.exe]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2004-11-15 05:49 118784]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2004-11-12 12:57 73728]
"NDSTray.exe"="NDSTray.exe" []
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-01-13 20:05 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-11-02 04:03 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 03:59 126976]
"TFncKy"="TFncKy.exe" []
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 09:00 79224]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-07-04 08:38 180269]
"CFSServ.exe"="CFSServ.exe" []
"eCarteBleue-LP-P1"="C:\Program Files\e-Carte Bleue\LA POSTE\CVD ADESIO\ECB.exe" [2002-12-20 03:49 188416]
"RIP PopUp"="C:\Program Files\RIP PopUp\nopopup.exe" [ ]
"CmUsbAudio"="cmcnfg2.cpl" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2005-03-08 00:42 176128]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 07:00 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 SerTVOutCtlr;TOSHIBA Controls Driver -EPIOMngr;C:\WINDOWS\system32\drivers\EPIOMngr.sys [2004-07-30 10:05]
R1 TPwSav;Common Driver;C:\WINDOWS\system32\Drivers\TPwSav.sys [2005-02-25 14:08]
S1 StickyMesger;StickyMesger;C:\Program Files\TOSHIBA\Accessibility\StickyMesger.sys []
S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\cmo_bus.sys [2005-08-17 11:59]
S3 cmo_mdfl;Data Modem @ CDMA Filter;C:\WINDOWS\system32\DRIVERS\cmo_mdfl.sys [2005-08-17 12:02]
S3 cmo_mdm;Data Modem @ CDMA Drivers;C:\WINDOWS\system32\DRIVERS\cmo_mdm.sys [2005-08-17 12:02]
S3 cmo_serd;Data Modem @ CDMA Diagnostic Serial Port (WDM);C:\WINDOWS\system32\DRIVERS\cmo_serd.sys [2005-08-17 12:04]
S3 cmuda2;C-Media USB Audio Interface;C:\WINDOWS\system32\drivers\cmuda2.sys [2004-06-16 04:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f166cfe-a59f-11dc-be5d-000fb084009f}]
\Shell\AutoRun\command - E:\p3r1ud.exe
\Shell\explore\Command - E:\p3r1ud.exe
\Shell\open\Command - E:\p3r1ud.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e41bd128-db42-11dc-beb0-000fb084009f}]
\Shell\AutoRun\command - E:\p3r1ud.exe
\Shell\explore\Command - E:\p3r1ud.exe
\Shell\open\Command - E:\p3r1ud.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2005-03-18 08:54:28 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-23 18:26:47
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ACS.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-23 18:31:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-23 22:30:59
t 2008-02-23 22:31:23