ComboFix 08-05-12.1 - geoffrey 2008-05-14 21:41:40.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2533 [GMT 2:00]
Endroit: C:\Documents and Settings\geoffrey\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bHklmnmp.ini
C:\WINDOWS\system32\bHklmnmp.ini2
C:\WINDOWS\system32\hook.dll
C:\WINDOWS\system32\pmnmlkHb.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-14 to 2008-05-14 ))))))))))))))))))))))))))))))))))))
.
2008-05-14 19:57 . 2008-04-13 19:34 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2008-05-14 19:57 . 2008-04-13 19:34 153,088 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2008-05-14 19:57 . 2008-04-13 19:33 29,184 --a------ C:\WINDOWS\system32\irmon.dll
2008-05-14 19:57 . 2008-04-13 19:33 29,184 --a--c--- C:\WINDOWS\system32\dllcache\irmon.dll
2008-05-14 19:57 . 2008-04-13 19:33 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-05-14 19:57 . 2008-04-13 19:33 8,192 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
2008-05-14 19:56 . 2008-05-14 19:56 <REP> d-------- C:\Documents and Settings\geoffrey\Bluetooth Software
2008-05-14 19:52 . 2008-05-14 19:52 <REP> d-------- C:\Program Files\WIDCOMM
2008-05-14 19:20 . 2008-05-14 19:20 <REP> d-------- C:\Program Files\Enigma Software Group
2008-05-13 21:44 . 2008-05-13 21:47 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-05-13 21:43 . 2008-03-01 14:58 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-13 21:43 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-13 21:43 . 2007-03-08 07:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-13 21:43 . 2008-03-01 14:58 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-13 21:43 . 2008-03-01 14:58 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-13 21:43 . 2008-03-01 14:58 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-13 21:43 . 2008-03-01 14:58 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-13 21:43 . 2008-03-01 14:58 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-13 21:43 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-12 11:18 . 2008-05-12 11:18 1,160 --a------ C:\WINDOWS\mozver.dat
2008-05-11 21:33 . 2008-05-11 21:33 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-11 20:19 . 2008-05-11 20:19 <REP> d-------- C:\Documents and Settings\geoffrey\Application Data\Grisoft
2008-05-11 20:19 . 2008-05-11 20:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-11 20:19 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-11 19:46 . 2008-05-11 19:46 0 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-11 18:54 . 2008-05-11 18:54 <REP> d-------- C:\VundoFix Backups
2008-05-11 18:37 . 2008-05-11 18:37 <REP> d-------- C:\Program Files\Trend Micro
2008-05-11 18:37 . 2008-05-11 18:37 <REP> d-------- C:\Deckard
2008-05-11 11:07 . 2008-05-14 19:39 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-05-10 21:24 . 2008-05-10 21:24 <REP> d-------- C:\Documents and Settings\geoffrey\Application Data\Ubisoft
2008-05-10 21:20 . 2008-05-10 21:20 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-05-10 21:12 . 2008-05-10 21:24 <REP> d-------- C:\Documents and Settings\geoffrey\Application Data\LimeWire
2008-05-10 21:01 . 2008-05-10 21:01 <REP> d-------- C:\WINDOWS\Sun
2008-05-10 20:55 . 2008-05-10 20:55 <REP> d-------- C:\Program Files\Java
2008-05-10 20:55 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-10 20:54 . 2008-05-10 20:54 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-05-10 19:34 . 2008-04-13 11:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-05-10 10:57 . 2008-05-10 19:32 <REP> d-------- C:\Program Files\Steam
2008-05-09 23:42 . 2008-05-09 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-05-09 23:41 . 2008-05-09 23:41 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-09 23:28 . 2008-05-09 23:28 <REP> d----c--- C:\ATI
2008-05-09 23:12 . 2008-05-09 23:12 <REP> d-------- C:\Program Files\MSBuild
2008-05-09 23:09 . 2008-05-09 23:13 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-09 23:08 . 2008-05-09 23:08 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-09 23:07 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-09 23:05 . 2008-05-09 23:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ubisoft
2008-05-09 23:03 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2008-05-09 22:55 . 2008-05-09 22:55 <REP> d-------- C:\Program Files\Ubisoft
2008-05-09 22:51 . 2008-05-09 22:51 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-05-09 22:23 . 2008-05-09 22:23 <REP> d-------- C:\Documents and Settings\geoffrey\Application Data\DAEMON Tools
2008-05-09 22:23 . 2008-05-09 22:23 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-09 22:22 . 2008-05-09 22:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-09 22:21 . 2008-05-09 22:21 <REP> d-------- C:\Program Files\Radical Games
2008-05-09 22:17 . 2008-05-09 22:17 <REP> d-------- C:\Program Files\Trust
2008-05-09 22:17 . 2006-12-26 17:53 2,637,824 --a------ C:\WINDOWS\system32\XWheel.dll
2008-05-09 22:17 . 2006-12-27 18:44 1,146,880 --a------ C:\WINDOWS\system32\MousePage.dll
2008-05-09 22:17 . 2006-12-26 17:53 679,936 --a------ C:\WINDOWS\system32\XIndicator.dll
2008-05-09 22:17 . 2006-12-29 16:49 27,648 --a------ C:\WINDOWS\system32\drivers\GMFilter.sys
2008-05-09 20:33 . 2008-05-12 20:13 <REP> d-------- C:\Documents and Settings\geoffrey\Contacts
2008-05-09 20:32 . 2008-05-09 20:32 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-05-09 20:32 . 2008-05-09 20:32 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-05-09 20:32 . 2008-05-09 20:32 268 --ah-c--- C:\sqmdata00.sqm
2008-05-09 20:32 . 2008-05-09 20:32 244 --ah-c--- C:\sqmnoopt00.sqm
2008-05-09 14:15 . 2008-05-09 14:15 <REP> d-------- C:\Program Files\Avira
2008-05-09 14:15 . 2008-05-09 14:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-09 14:13 . 2008-04-13 19:33 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-05-09 14:13 . 2008-04-13 18:57 58,752 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-05-09 14:13 . 2008-04-13 11:45 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2008-05-09 14:13 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-05-09 14:12 . 2008-05-09 20:32 <REP> d-------- C:\Program Files\Windows Live
2008-05-09 14:12 . 2008-05-09 20:31 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage r‚seau
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage d'impression
2008-05-09 14:12 . 2008-05-09 13:15 <REP> d--h----- C:\Documents and Settings\Default User\ModŠles
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d-------- C:\Documents and Settings\Default User\Mes documents
2008-05-09 14:12 . 2008-05-09 14:12 <REP> dr------- C:\Documents and Settings\Default User\Menu D‚marrer
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d-------- C:\Documents and Settings\Default User\Favoris
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d-------- C:\Documents and Settings\Default User\Bureau
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d--h----- C:\Documents and Settings\All Users\ModŠles
2008-05-09 14:12 . 2008-05-14 19:56 <REP> dr------- C:\Documents and Settings\All Users\Menu D‚marrer
2008-05-09 14:12 . 2008-05-09 14:12 <REP> d-------- C:\Documents and Settings\All Users\Favoris
2008-05-09 14:12 . 2008-05-09 14:08 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-05-09 14:12 . 2008-05-14 19:32 <REP> d-------- C:\Documents and Settings\All Users\Bureau
2008-05-09 14:12 . 2008-05-09 14:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-09 14:11 . 2008-05-14 19:38 <REP> d-------- C:\WINDOWS\system32\CatRoot2
2008-05-09 14:11 . 2008-05-09 14:05 <REP> d-------- C:\WINDOWS\system32\CatRoot
2008-05-09 14:11 . 2008-05-09 13:18 <REP> d--h----- C:\Documents and Settings\Default User
2008-05-09 14:11 . 2008-05-09 13:17 <REP> d-------- C:\Documents and Settings\All Users
2008-05-09 14:11 . 2008-05-09 13:21 <REP> d-------- C:\Documents and Settings
2008-05-09 14:11 . 2002-08-29 16:35 1,086,182 -ra------ C:\WINDOWS\SET3.tmp
2008-05-09 14:11 . 2002-01-08 21:40 13,923 -ra------ C:\WINDOWS\SETA.tmp
2008-05-09 14:10 . 2008-05-09 14:11 <REP> d-------- C:\Program Files\LimeWire
2008-05-09 14:09 . 2008-05-09 14:11 <REP> d-------- C:\Program Files\BitComet
2008-05-09 14:09 . 2008-05-14 19:20 <REP> d-------- C:\Downloads
2008-05-09 14:09 . 2008-05-09 14:09 <REP> d--hs---- C:\Documents and Settings\geoffrey\UserData
2008-05-09 14:09 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-05-09 14:09 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-05-09 14:09 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-05-09 14:09 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-05-09 14:09 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-05-09 14:09 . 2008-05-09 14:09 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-05-09 14:08 . 2008-05-09 14:08 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2008-05-09 14:08 . 2008-05-09 14:08 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-05-09 14:08 . 2008-05-09 14:08 1,024 --ah----- C:\Documents and Settings\Default User\NTUSER.DAT.LOG
2008-05-09 14:01 . 2008-05-09 14:03 <REP> d-------- C:\WINDOWS\EHome
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 09:15 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-09 21:42 --------- d-----w C:\Documents and Settings\geoffrey\Application Data\ATI
2008-05-09 21:39 --------- d-----w C:\Program Files\ATI Technologies
2008-05-09 21:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-09 20:17 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-05-09 11:35 --------- d-----w C:\Program Files\C-Media
2008-05-09 11:25 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-05-09 11:24 --------- d-----w C:\Program Files\Hercules
2008-05-09 11:24 --------- d-----w C:\Documents and Settings\geoffrey\Application Data\InstallShield
2008-05-09 11:23 --------- d-----w C:\Documents and Settings\geoffrey\Application Data\InterTrust
2008-05-09 11:18 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-09 11:17 558,142 ----a-w C:\WINDOWS\java\Packages\SJBRNF1N.ZIP
2008-05-09 11:17 155,995 ----a-w C:\WINDOWS\java\Packages\G7XBTV1R.ZIP
2008-05-09 11:15 --------- d-----w C:\Program Files\Services en ligne
2008-04-13 17:50 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-13 17:37 332,800 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-13 17:33 98,816 ----a-w C:\WINDOWS\system32\psbase.dll
2008-04-13 17:32 764,416 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-04-13 17:32 61,471 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-13 17:32 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
2008-04-13 17:32 103,424 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 17:10 73,600 ----a-w C:\WINDOWS\system32\drivers\sr.sys
2008-04-13 17:09 80,384 ----a-w C:\WINDOWS\system32\drivers\parport.sys
2008-04-13 17:09 68,608 ----a-w C:\WINDOWS\system32\drivers\pci.sys
2008-04-13 17:09 46,848 ----a-w C:\WINDOWS\system32\drivers\p3.sys
2008-04-13 17:09 120,576 ----a-w C:\WINDOWS\system32\drivers\pcmcia.sys
2008-04-13 17:07 2,147,328 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 17:07 2,025,984 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-13 17:06 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-13 17:05 800,256 ----a-w C:\WINDOWS\system32\drivers\dmboot.sys
2008-04-13 17:05 25,216 ----a-w C:\WINDOWS\system32\drivers\kbdclass.sys
2008-04-13 17:05 154,496 ----a-w C:\WINDOWS\system32\drivers\dmio.sys
2008-04-13 17:04 93,184 ------w C:\WINDOWS\system32\msxml6r.dll
2008-04-13 17:04 37,632 ----a-w C:\WINDOWS\system32\drivers\isapnp.sys
2008-04-13 17:03 81,920 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-13 17:03 40,576 ------w C:\WINDOWS\system32\drivers\intelppm.sys
2008-04-13 17:02 50,688 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-13 17:02 40,960 ----a-w C:\WINDOWS\system32\drivers\crusoe.sys
2008-04-13 17:02 2,985,984 ----a-w C:\WINDOWS\system32\wmploc.dll
2008-04-13 17:01 572,416 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-13 17:00 66,048 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 17:00 54,144 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 16:59 25,856 ------w C:\WINDOWS\system32\drivers\hidbth.sys
2008-04-13 16:59 200,704 ------w C:\WINDOWS\system32\wmerror.dll
2008-04-13 16:59 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-13 16:58 273,664 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-04-13 16:58 1,845,760 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 16:58 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-13 16:57 70,144 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-13 16:57 44,672 ----a-w C:\WINDOWS\system32\drivers\fips.sys
2008-04-13 16:56 53,376 ----a-w C:\WINDOWS\system32\drivers\volsnap.sys
2008-04-13 16:55 8,704 ----a-w C:\WINDOWS\system32\asferror.dll
2008-04-13 16:55 40,064 ----a-w C:\WINDOWS\system32\drivers\processr.sys
2008-04-13 16:55 327,168 ------w C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-04-13 16:54 41,856 ----a-w C:\WINDOWS\system32\drivers\amdk7.sys
2008-04-13 16:54 41,472 ----a-w C:\WINDOWS\system32\drivers\amdk6.sys
2008-04-13 16:53 70,688 ----a-w C:\WINDOWS\system32\mmsystem.dll
2008-04-13 16:53 30,336 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 16:53 23,680 ----a-w C:\WINDOWS\system32\drivers\mouclass.sys
2008-04-13 16:52 188,672 ----a-w C:\WINDOWS\system32\drivers\acpi.sys
2008-04-13 10:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 10:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 10:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 10:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 10:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 10:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 10:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 10:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 10:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 10:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 10:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 10:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 10:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 10:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 10:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 10:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 10:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 10:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 10:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 10:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 10:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 10:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 09:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 09:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 09:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 09:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 09:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 09:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 09:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 09:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 09:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 09:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 09:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 09:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 09:56 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 09:56 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 09:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 09:56 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 09:56 12,288 ----a-w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 09:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:34 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 19:34 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-07-12 18:33 1581056 C:\WINDOWS\mixer.exe]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"Trust Gaming mouse"="C:\Program Files\Trust\GM-4200 Gamer Mouse Optical\Panel.exe" [2006-12-28 09:20 1232896]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 19:34 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-13 19:34 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10680:TCP"= 10680:TCP:BitComet 10680 TCP
"10680:UDP"= 10680:UDP:BitComet 10680 UDP
R3 GMFilter Filter;GMFilter Filter;C:\WINDOWS\system32\Drivers\GMFilter.sys [2006-12-29 16:49]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\autorun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-14 21:45:51
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\Hercules\WiFi Station\WiFiStation.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-14 21:47:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-14 19:47:23
Pre-Run: 145,321,586,688 octets libres
Post-Run: 145,297,735,680 octets libres
293