ComboFix 08-05-15.3 - xp 2008-05-18 10:11:57.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1059 [GMT 2:00]
Endroit: C:\Documents and Settings\xp\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\563_button_1b_def.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\563_button_1b_over.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\572_button_1b_def.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\572_button_1b_over.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\573_button_1b_def.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\573_button_1b_over.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\FindIt.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\FindItHot.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\findithotxp.png
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\finditxp.png
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\logo.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\buttons\logoxp.bmp
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\contexts\error.xml
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\contexts\related.xml
C:\Documents and Settings\All Users.WINDOWS\Application Data\Starware370\contexts\travel.xml
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\jean-marc\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
C:\Documents and Settings\jean-marc\Application Data\SystemDoctor Free
C:\Documents and Settings\jean-marc\Application Data\SystemDoctor Free\Logs\update.log
C:\Documents and Settings\jean-marc\err.log
C:\Documents and Settings\jean-marc\Local Settings\Application Data\jfqmilhdok.dat
C:\Documents and Settings\jean-marc\Local Settings\Application Data\jfqmilhdok_nav.dat
C:\Documents and Settings\jean-marc\Local Settings\Application Data\jfqmilhdok_navps.dat
C:\Documents and Settings\jean-marc\Menu Démarrer\Programmes\InternetGameBox
C:\Documents and Settings\jean-marc\Menu Démarrer\Programmes\InternetGameBox\Conditions générales.lnk
C:\Documents and Settings\jean-marc\Menu Démarrer\Programmes\InternetGameBox\Confidentialité.lnk
C:\Documents and Settings\jean-marc\Menu Démarrer\Programmes\InternetGameBox\InternetGameBox.lnk
C:\Documents and Settings\jean-marc\Menu Démarrer\Programmes\InternetGameBox\Website.lnk
C:\Documents and Settings\jean-marc\ResErrors.log
C:\Program Files\Fichiers communs\SystemDoctor
C:\Program Files\Fichiers communs\SystemDoctor\err.log
C:\Redemption.ECF
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-18 to 2008-05-18 ))))))))))))))))))))))))))))))))))))
.
2008-05-17 21:40 . 2008-05-17 21:41 <REP> d-------- C:\WINDOWS\LastGood
2008-05-17 21:30 . 2008-02-28 13:26 1,414,440 --a------ C:\WINDOWS\system32\ShellManager310E2D762.dll
2008-05-17 21:30 . 2008-02-28 13:01 774,144 --a------ C:\WINDOWS\system32\NEROINSTAEC43759.DB
2008-05-17 21:28 . 2008-05-17 21:28 0 --a------ C:\WINDOWS\Irremote.ini
2008-05-17 21:15 . 2008-05-17 21:15 <REP> d-------- C:\9c1d9a4b358f0830c013348a0a
2008-05-17 21:09 . 2008-05-17 21:09 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-05-17 21:09 . 2008-05-17 21:10 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-05-16 22:14 . 2003-10-03 16:28 45,056 --a------ C:\WINDOWS\system32\vusetup.dll
2008-05-16 22:14 . 2005-06-06 17:51 11,264 --a------ C:\WINDOWS\system32\drivers\vulfntr.sys
2008-05-16 22:14 . 2005-01-05 18:02 6,912 --a------ C:\WINDOWS\system32\drivers\vulfnth.sys
2008-05-16 22:06 . 2005-03-23 16:56 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-05-16 21:58 . 2008-05-17 16:51 <REP> d--h----- C:\$AVG8.VAULT$
2008-05-16 16:17 . 2008-05-18 00:48 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-16 16:17 . 2008-05-16 16:17 <REP> d-------- C:\Program Files\AVG
2008-05-16 16:17 . 2008-05-16 16:17 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-05-16 16:17 . 2008-05-16 16:17 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-16 16:17 . 2008-05-16 16:17 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-16 16:17 . 2008-05-16 16:17 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-05-16 16:17 . 2008-05-16 16:17 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-15 09:56 . 2008-04-03 15:42 53,248 --a------ C:\WINDOWS\system32\drivers\ViPrt.sys
2008-05-15 09:56 . 2007-09-21 16:28 18,432 --a------ C:\WINDOWS\system32\vIdeInst.dll
2008-05-15 09:56 . 2008-04-03 15:42 16,896 --a------ C:\WINDOWS\system32\drivers\ViBus.sys
2008-05-15 09:56 . 2007-09-21 17:49 9,216 --a------ C:\WINDOWS\system32\drivers\videX32.sys
2008-05-15 09:27 . 2008-05-15 09:27 <REP> d-------- C:\Program Files\Realtek AC97
2008-05-15 09:25 . 2008-05-15 09:25 <REP> d-------- C:\WINDOWS\OPTIONS
2008-05-15 09:25 . 2008-02-25 20:54 105,088 --a------ C:\WINDOWS\system32\drivers\Rtnicxp.sys
2008-05-15 09:24 . 2008-05-15 09:24 <REP> d-------- C:\Program Files\S3
2008-05-15 09:19 . 2008-05-15 09:19 <REP> d-------- C:\Program Files\ma-config.com
2008-05-15 09:19 . 2008-05-16 22:03 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ma-config.com
2008-05-15 09:05 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-15 09:05 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-15 09:05 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-15 09:05 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-15 09:05 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-15 09:05 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-05-15 09:05 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-15 09:05 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-05-15 08:25 . 2008-05-15 10:47 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\TrackMania
2008-05-14 14:42 . 2008-05-14 14:42 <REP> d-------- C:\WINDOWS\wt
2008-05-14 12:46 . 2008-05-14 12:47 <REP> d-------- C:\Program Files\Panda Security
2008-05-14 11:42 . 2008-05-14 11:42 <REP> d-------- C:\Program Files\Trend Micro
2008-05-14 11:10 . 2008-05-14 11:10 <REP> d-------- C:\WINDOWS\Sun
2008-05-13 21:13 . 2008-05-13 21:13 <REP> d-------- C:\Program Files\Rockstar Games
2008-05-11 22:01 . 2008-05-11 22:01 <REP> d---s---- C:\WINDOWS\system32\Microsoft
2008-05-11 21:21 . 2008-05-11 21:22 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-11 21:09 . 2008-05-15 09:09 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-11 17:21 . 2008-05-11 17:21 <REP> d-------- C:\Program Files\Fichiers communs\BOONTY Shared
2008-05-11 17:20 . 2008-05-11 17:20 <REP> d-------- C:\Program Files\Boonty
2008-05-10 12:08 . 2008-05-11 17:21 <REP> d-------- C:\Program Files\Skyline
2008-05-09 19:46 . 2008-05-09 19:46 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
2008-05-09 19:40 . 2008-05-11 17:16 <REP> d-------- C:\Program Files\BoontyGames
2008-05-09 14:06 . 2004-08-04 00:54 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-08 17:58 . 2008-05-08 17:58 45 ---h----- C:\WINDOWS\dsez5937.dat
2008-05-07 10:48 . 2008-05-07 10:48 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-06 08:05 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-05-06 08:05 . 2004-08-03 23:08 25,600 --a--c--- C:\WINDOWS\system32\dllcache\usbser.sys
2008-05-06 08:04 . 2008-05-06 08:04 <REP> d--hs---- C:\Documents and Settings\xp\Phone Browser
2008-05-04 16:34 . 2008-05-07 14:09 <REP> d-------- C:\Program Files\Mystery Case Files - Madame Fate
2008-05-04 12:08 . 2008-05-04 12:08 <REP> d-------- C:\Program Files\ReflexiveArcade
2008-05-01 20:39 . 2008-05-01 20:39 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ViaMichelin
2008-05-01 10:29 . 2008-05-01 10:29 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-05-01 10:29 . 2008-05-01 10:29 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-04-28 16:27 . 2008-04-28 16:27 <REP> d-------- C:\QuickTime
2008-04-26 22:07 . 2007-07-30 19:19 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2008-04-26 22:07 . 2007-07-30 19:19 203,096 --a--c--- C:\WINDOWS\system32\dllcache\wuweb.dll
2008-04-25 09:38 . 2008-04-25 09:38 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\IM
2008-04-25 09:37 . 2008-04-25 09:37 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\IncrediMail
2008-04-24 17:23 . 2008-04-24 17:23 <REP> d-------- C:\Documents and Settings\xp\Application Data\Nokia Multimedia Player
2008-04-24 17:18 . 2008-04-24 17:18 <REP> d-------- C:\Program Files\Fichiers communs\PCSuite
2008-04-24 17:18 . 2008-04-24 17:18 <REP> d-------- C:\Program Files\Fichiers communs\Nokia
2008-04-24 17:17 . 2008-04-24 17:17 <REP> d-------- C:\Program Files\PC Connectivity Solution
2008-04-24 17:17 . 2007-11-29 10:33 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-04-24 17:17 . 2007-09-17 15:53 21,632 --a------ C:\WINDOWS\system32\drivers\pccsmcfd.sys
2008-04-24 17:17 . 2007-11-29 10:39 19,328 --a------ C:\WINDOWS\system32\drivers\ccdcmbo.sys
2008-04-24 17:17 . 2007-11-29 10:39 16,896 --a------ C:\WINDOWS\system32\drivers\ccdcmb.sys
2008-04-24 17:17 . 2007-11-29 10:39 8,064 --a------ C:\WINDOWS\system32\drivers\usbser_lowerflt.sys
2008-04-24 17:13 . 2008-04-24 17:13 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-04-24 17:12 . 2007-02-22 10:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-04-24 17:12 . 2007-11-29 10:39 95,744 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 08:05 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-05-18 08:03 --------- d-----w C:\Documents and Settings\xp\Application Data\Azureus
2008-05-17 19:31 --------- d-----w C:\Program Files\Nero
2008-05-17 19:31 --------- d-----w C:\Program Files\Fichiers communs\Nero
2008-05-17 19:31 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-05-15 08:46 --------- d-----w C:\Program Files\Steam
2008-05-15 07:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-14 11:37 1,626 ----a-w C:\WINDOWS\system32\tmp.reg
2008-05-14 10:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\EPSON
2008-05-11 19:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-05-11 18:39 --------- d-----w C:\Program Files\Google
2008-05-11 12:47 --------- d-----w C:\Program Files\Azada
2008-05-09 10:57 --------- d-----w C:\Program Files\CCleaner
2008-05-09 10:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Skyline
2008-05-09 10:32 --------- d-----w C:\Documents and Settings\xp\Application Data\EoRezo
2008-05-09 05:21 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-05-08 16:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\GamesBar
2008-05-05 10:34 --------- d-----w C:\Program Files\Ahead
2008-05-05 10:31 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-04-28 14:29 --------- d-----w C:\Program Files\iTunes
2008-04-26 19:30 --------- d-----w C:\Program Files\Wanadoo
2008-04-24 15:16 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-04-24 15:14 --------- d-----w C:\Documents and Settings\xp\Application Data\PC Suite
2008-04-24 15:13 --------- d-----w C:\Program Files\DIFX
2008-04-24 15:13 --------- d-----w C:\Documents and Settings\xp\Application Data\Nokia
2008-04-16 21:44 --------- d-----w C:\Program Files\Fichiers communs\Oberon Media
2008-04-16 05:11 --------- d-----w C:\Program Files\Azureus
2008-04-11 16:11 --------- d-----w C:\Program Files\MSN Messenger
2008-04-11 16:09 --------- d-----w C:\Program Files\Windows Live
2008-04-11 16:08 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-04-11 16:06 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WLInstaller
2008-04-09 20:59 --------- d-----w C:\Program Files\CamStudio
2008-04-08 13:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Zylom
2008-04-07 09:08 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-05 14:30 97,288 ------w C:\DSETUP.dll
2008-03-05 14:30 527,880 ------w C:\DXSETUP.exe
2008-03-05 14:30 1,694,728 ------w C:\dsetup32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
.
[code]<pre>
----a-w 1,397,760 2007-12-26 12:04:21 C:\Documents and Settings\jean-marc\Bureau\gravage\InCD\InCD .exe
----a-w 57,344 2007-12-26 11:46:44 C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy .exe
----a-w 5,207,368 2007-12-26 12:05:46 C:\Program Files\Pando Networks\Pando\pando .exe
</pre>
/code
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{413B556F-9483-4319-9DCA-5378529986E2}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando"="C:\Program Files\Pando Networks\Pando\Pando.exe" [2008-02-09 15:02 6051144]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 22:45 1211176]
"EPSON Stylus DX7400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.exe" [2007-04-12 08:00 182272]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-19 22:32 262401]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"EoWeather"="" []
"EoEngine"="" []
"CreativeTaskScheduler"="C:\Program Files\Creative\Shared Files\CTSched.exe" [2006-01-09 04:43 53340]
"VTTimer"="VTTimer.exe" [2006-09-21 16:36 53248 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2007-06-11 11:15 176128 C:\WINDOWS\system32\S3Trayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-16 16:17 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Documents and Settings\xp\Bureau\nokia pc suite\Nokia PC Suite 6\PcSync2.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.XVID"= xvid.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"OPTENET_FILTER"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Steam\\steamapps\\elesan2\\counter-strike source\\hl2.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1577:UDP"= 1577:UDP:Windows Media Format SDK (firefox.exe)
"1576:UDP"= 1576:UDP:Windows Media Format SDK (firefox.exe)
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-05-16 16:17]
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2008-04-03 15:42]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-09-21 17:49]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2008-04-03 15:42]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-16 16:17]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-16 16:17]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-16 16:17]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:55]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2007-07-23 14:54]
R3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-11-04 00:45]
S3 maconfservice;maconfservice;"C:\Program Files\ma-config.com\maconfservice.exe" [2008-05-14 16:40]
S3 pccsmcfd;PCCS Mode Change Filter Driver;C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 15:53]
S3 StMp3Rec;Pilote de périphérique de la restauration de lecteur;C:\WINDOWS\system32\Drivers\StMp3Rec.sys [2006-06-02 14:14]
S3 upperdev;upperdev;C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2007-11-29 10:39]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2008-05-09 19:46]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-05 12:12:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-09 15:18:44 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-18 10:17:45
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-18 10:23:47
ComboFix-quarantined-files.txt 2008-05-18 08:23:43
Pre-Run: 34,778,558,464 octets libres
Post-Run: 36,553,318,400 octets libres
273 --- E O F --- 2008-04-26 21:01:57
Voilà, voilà!!