Voila
ComboFix 08-02-25.3 - Bijan Moutschen 2008-02-26 19:07:54.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1213 [GMT 1:00]
Endroit: C:\Documents and Settings\Bijan Moutschen\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bijan Moutschen\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
.
2008-02-25 18:09 . 2008-02-25 18:09 <REP> d-------- C:\WINDOWS\ERUNT
2008-02-25 18:01 . 2008-02-25 15:14 <REP> d-------- C:\SDFix
2008-02-25 17:16 . 2008-02-25 17:49 <REP> d-------- C:\VundoFix Backups
2008-02-25 11:27 . 2008-02-25 11:27 514,806 --a------ C:\upload_moi_BIJAN.tar.gz
2008-02-25 11:08 . 2008-02-25 12:25 <REP> d-------- C:\MSNFix
2008-02-25 10:53 . 2008-02-25 10:53 <REP> d-------- C:\Program Files\CCleaner
2008-02-25 10:51 . 2008-02-25 10:51 <REP> d-------- C:\Documents and Settings\Bijan Moutschen\Application Data\Grisoft
2008-02-25 10:51 . 2008-02-25 10:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-25 10:51 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-25 10:46 . 2008-02-25 10:46 <REP> d-------- C:\Program Files\Trend Micro
2008-02-24 21:45 . 2008-02-24 21:45 <REP> d-------- C:\Documents and Settings\Bijan Moutschen\Application Data\McAfee
2008-02-24 20:17 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-02-24 19:01 . 2008-02-24 19:01 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Talkback
2008-02-24 19:01 . 2008-02-24 19:01 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SiteAdvisor
2008-02-24 18:28 . 2008-02-24 18:28 90 --a------ C:\WINDOWS\wininit.ini
2008-02-24 17:16 . 2008-02-24 17:16 <REP> d-------- C:\kav
2008-02-24 17:10 . 2008-02-24 17:10 <REP> d-------- C:\Program Files\Lavasoft
2008-02-24 17:10 . 2008-02-24 17:10 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-24 17:10 . 2008-02-24 17:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-24 16:54 . 2008-02-24 16:54 <REP> d-------- C:\Program Files\CleanUp!
2008-02-24 16:20 . 2008-02-24 14:15 78,848 --a------ C:\WINDOWS\system32\poolmc.MSNFix
2008-02-24 10:28 . 2008-02-24 10:28 <REP> d-------- C:\Program Files\iPod
2008-02-21 16:43 . 2008-02-21 16:43 71 --a------ C:\WINDOWS\fs_earth_link_9.ini
2008-02-16 18:52 . 2008-02-16 18:52 268 --ah----- C:\sqmdata03.sqm
2008-02-16 18:52 . 2008-02-16 18:52 244 --ah----- C:\sqmnoopt03.sqm
2008-02-12 17:37 . 2008-02-12 17:37 <REP> d-------- C:\Program Files\JoyToKey
2008-02-11 21:03 . 2008-02-11 21:03 57,623 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-02-11 21:02 . 2008-02-11 21:02 5,760,054 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-02-11 21:01 . 2008-02-11 21:03 6,120 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-02-11 21:00 . 2008-02-11 21:00 <REP> d-------- C:\WINDOWS\BricoPacks
2008-02-11 20:39 . 2008-02-11 20:39 <REP> d-------- C:\Program Files\SystemRequirementsLab
2008-02-10 20:22 . 2008-02-24 18:14 <REP> d-------- C:\Program Files\LiveKillCleanMessenger
2008-02-10 20:22 . 2008-02-10 20:22 <REP> d-------- C:\Documents and Settings\Bijan Moutschen\Application Data\Live-Prod
2008-02-10 16:31 . 2008-02-10 16:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-02-10 16:29 . 2008-02-26 17:23 1,080 --a------ C:\WINDOWS\system32\settingsbkup.sfm
2008-02-10 16:29 . 2008-02-26 17:23 1,080 --a------ C:\WINDOWS\system32\settings.sfm
2008-02-10 16:24 . 2008-02-11 20:49 <REP> d-------- C:\WINDOWS\nview
2008-02-10 16:24 . 2007-12-17 13:53 159,458 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-02-10 16:23 . 2008-02-10 16:23 <REP> d-------- C:\NVIDIA
2008-02-06 20:32 . 2008-02-06 20:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Dell
2008-02-05 17:38 . 2008-02-05 17:38 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-02-03 20:20 . 2008-02-03 20:20 62 --a------ C:\WINDOWS\my.ini
2008-02-02 19:18 . 2008-02-02 19:18 32 --a------ C:\WINDOWS\tdlp32.ini
2008-02-02 19:17 . 2008-02-02 19:17 <REP> d-------- C:\Program Files\Xara
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 18:12 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\Skype
2008-02-26 17:39 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\gtk-2.0
2008-02-26 16:25 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\skypePM
2008-02-26 16:24 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\OpenOffice.org2
2008-02-25 11:47 --------- d-----w C:\Program Files\McAfee
2008-02-24 20:48 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-02-24 20:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-24 19:27 --------- d-----w C:\Program Files\Fichiers communs\McAfee
2008-02-24 18:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-24 16:57 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-24 16:01 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-02-24 16:01 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-02-24 15:57 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-24 15:57 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\Download Manager
2008-02-24 09:28 --------- d-----w C:\Program Files\iTunes
2008-02-19 17:21 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\Apple Computer
2008-02-17 08:58 --------- d-----w C:\Program Files\QuickTime
2008-02-16 17:39 --------- d-----w C:\Program Files\DivX
2008-02-16 10:38 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\dvdcss
2008-02-12 16:36 --------- d-----w C:\Program Files\Fraps
2008-02-11 20:03 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-02-11 19:36 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\SystemRequirementsLab
2008-02-10 17:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 17:29 --------- d-----w C:\Program Files\Fichiers communs\Corel
2008-02-10 15:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-10 15:22 --------- d-----w C:\Program Files\Broadcom
2008-02-10 15:00 --------- d-----w C:\Program Files\Google
2008-02-10 13:03 --------- d-----w C:\Program Files\Microsoft Works
2008-02-10 12:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-10 12:01 --------- d-----w C:\Program Files\Free Easy Burner
2008-02-10 11:57 --------- d--h--w C:\Documents and Settings\Famille\Application Data\Gtek
2008-02-10 11:57 --------- d--h--w C:\Documents and Settings\Bijan Moutschen\Application Data\Gtek
2008-02-10 11:57 --------- d--h--w C:\Documents and Settings\Administrateur\Application Data\GTek
2008-02-10 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-02-05 21:20 --------- d-----w C:\Program Files\YAFSScreen
2008-02-03 19:24 --------- d-----w C:\Program Files\Common Files
2008-01-22 15:58 --------- d-----w C:\Program Files\DIFX
2008-01-22 14:55 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\DivX
2008-01-21 19:26 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\Smart Recorder
2008-01-21 15:50 --------- d-----w C:\Documents and Settings\Bijan Moutschen\Application Data\teamspeak2
2008-01-12 17:11 10,796 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-09 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-09 11:18 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-01-09 11:18 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-09 11:18 3,596,288 -c--a-w C:\WINDOWS\system32\qt-dx331.dll
2008-01-09 11:18 200,704 -c--a-w C:\WINDOWS\system32\ssldivx.dll
2008-01-09 11:18 129,784 -c----w C:\WINDOWS\system32\pxafs.dll
2008-01-09 11:18 120,056 -c----w C:\WINDOWS\system32\pxcpyi64.exe
2008-01-09 11:18 118,520 -c----w C:\WINDOWS\system32\pxinsi64.exe
2008-01-09 11:18 1,044,480 -c--a-w C:\WINDOWS\system32\libdivx.dll
2008-01-09 11:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-01-09 11:16 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-01-09 11:16 81,920 -c--a-w C:\WINDOWS\system32\dpl100.dll
2008-01-09 11:16 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-01-09 11:16 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-01-09 11:16 196,608 -c--a-w C:\WINDOWS\system32\dtu100.dll
2008-01-06 20:27 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-01-06 20:27 --------- d-----w C:\Program Files\Java
2008-01-04 14:03 --------- d-----w C:\Program Files\Saitek
2008-01-04 14:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Saitek
2008-01-02 21:53 --------- d-----w C:\Program Files\Fichiers communs\Apple
2007-12-26 15:31 --------- d-----w C:\Program Files\DVD Decrypter
2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-11 19:44 593,920 -c--a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-12-11 19:44 57,344 -c--a-w C:\WINDOWS\system32\dpv11.dll
2007-12-11 19:44 53,248 -c--a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-12-11 19:44 344,064 -c--a-w C:\WINDOWS\system32\dpus11.dll
2007-12-11 19:44 294,912 -c--a-w C:\WINDOWS\system32\dpu11.dll
2007-12-11 19:44 294,912 -c--a-w C:\WINDOWS\system32\dpu10.dll
2007-12-11 19:44 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-11 19:43 12,288 -c--a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-12-06 10:05 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-05 01:53 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:41 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-11-21 19:06 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-09-16 08:29 166 -c--a-w C:\Documents and Settings\Bijan Moutschen\Application Data\wklnhst.dat
2007-01-30 16:43 61 --sh--w C:\WINDOWS\cnerolf.bin
2007-02-18 10:04 61 --sh--w C:\WINDOWS\cnerolf.dat
2007-10-21 16:14 248 --sh--r C:\WINDOWS\system32\84BDB62C2A.sys
.
------- Sigcheck -------
456f6f2eeaa0d975581e745c6ecfd140 C:\WINDOWS\system32\wininet.dll
-c----w 669,696 2007-06-26 14:36:02 C:\WINDOWS\$NtUninstallKB939653$\wininet.dll
-c----w 669,696 2007-08-22 12:57:30 C:\WINDOWS\$NtUninstallKB942615$\wininet.dll
-c----w 704,512 2007-10-11 05:59:29 C:\WINDOWS\$NtUninstallKB944533$\wininet.dll
----a-w 704,512 2007-12-07 00:47:21 C:\WINDOWS\system32\wininet.dll
----a-w 704,512 2007-12-07 00:47:21 C:\WINDOWS\system32\dllcache\wininet.dll
80a5400514eb32d393654768c4017e46 C:\WINDOWS\explorer.exe
----a-w 979,456 2007-06-13 13:22:28 C:\WINDOWS\explorer.exe
----a-w 979,456 2007-06-13 13:22:28 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2FA11ADF-3EF4-4B24-8558-02793F4A8E1E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3A2FF3C5-EDFF-46CE-BBA0-7A68B2499DBA}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89B9C4A6-7F4C-424A-931D-9DB76AD5C6B1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A27274FA-811F-4EFC-841F-2DFB333E93EB}]
C:\WINDOWS\system32\ddaby.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E256E6E5-CFBF-41CC-8281-D885A853CD93}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{f4686172-f5bb-4388-951c-80f52534566f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F512616D-2DD7-4A91-93E2-ADDEA26C1912}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-12 15:48 21760296]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"WindowsLivePhone"="C:\PROGRA~1\WI1F86~1\MESSEN~1\DEVICE~1\msgrdvmn.exe" [2007-03-29 11:21 722320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"CTHelper"="CTHELPER.EXE" [2005-11-08 20:30 16384 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 12:00 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 04:12 94208]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2007-05-15 16:25 137216]
"PMX Daemon"="ICO.EXE" [2006-11-08 16:01 49152 C:\WINDOWS\system32\ico.exe]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 02:00 45056]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 12:01 122880]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 19:07 49152]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 06:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 17:50 221184]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 17:50 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-29 11:16 1836544]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-03-05 20:10 36904]
"LifeChat"="C:\Program Files\Microsoft LifeChat\LifeChat.exe" [2007-01-26 13:31 259440]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-11-19 20:35 185896]
"ProfilerU"="C:\Program Files\Saitek\SD6\Software\ProfilerU.exe" [2007-10-02 10:10 233472]
"SaiMfd"="C:\Program Files\Saitek\SD6\Software\SaiMfd.exe" [2007-10-02 10:10 131072]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"789fc415"="C:\WINDOWS\system32\klwyokdl.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
C:\Documents and Settings\Bijan Moutschen\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 21:57:56 393216]
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 23:05:02 630784]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 20:41:18 65536]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 08:43:08 180224]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancer l'utilitaire d'enregistrement.lnk - C:\Program Files\WiFiConnector\NintendoWFCReg.exe [2007-09-17 18:31:29 1175552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\EA GAMES\\Medal of Honor Batailles du Pacifique(tm)\\mohpa.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\IVAO\\IvAp\\ivapnetint.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\Program Files\\adslTV\\adsltv.exe"=
"C:\\Program Files\\Microsoft Games\\Flight Simulator 9\\MADDOG2006\\MDCP.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"C:\\Program Files\\IVAO\\IvAp\\ivapconfig.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\kav\\kis7.0\\french\\setup.exe"=
"C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 SBKUPNT;SBKUPNT;C:\WINDOWS\system32\Drivers\SBKUPNT.SYS [2001-07-13 12:56]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2006-04-24 13:12]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S2 Apache2.2;Apache2.2;"K:\xampplite\apache\bin\apache.exe" []
S2 XAMPP;XAMPP Service;C:\Program Files\xampplite\xampplite\service.exe []
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-07-29 17:32]
S3 pmxmouse;PMXMOUSE;C:\WINDOWS\system32\DRIVERS\pmxmouse.sys [2006-04-24 11:57]
S3 pmxusblf;PMXUSBLF;C:\WINDOWS\system32\DRIVERS\pmxusblf.sys [2006-04-24 11:59]
S3 SaiH075C;SaiH075C;C:\WINDOWS\system32\DRIVERS\SaiH075C.sys [2007-05-01 16:11]
S3 SaiH0763;SaiH0763;C:\WINDOWS\system32\DRIVERS\SaiH0763.sys [2006-06-08 10:37]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4a1dfc68-741d-11dc-a552-000d0bffc227}]
\Shell\AutoRun\command - wd_windows_tools\setup.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-06 21:08:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-09 13:39:25 C:\WINDOWS\Tasks\LifeChatTask.job"
- C:\Program Files\Microsoft LifeChat\LifeChat.exe
"2008-02-25 08:00:01 C:\WINDOWS\Tasks\Rappel.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-26 19:12:26
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
.
Temps d'accomplissement: 2008-02-26 19:15:01
ComboFix-quarantined-files.txt 2008-02-26 18:14:58
ComboFix2.txt 2008-02-25 17:50:02
.
2008-02-13 20:36:18 --- E O F ---