Salut,
Voilà le log combo-fix
ComboFix 08-05-12.1 - Schmitt Thomas 2008-05-15 13:48:18.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2654 [GMT 2:00]
Endroit: C:\Users\Schmitt Thomas\Desktop\C-Fix.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-15 to 2008-05-15 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-15 11:56 --------- d-----w C:\Program Files\Steam
2008-05-14 23:10 --------- d-----w C:\Program Files\Windows Mail
2008-05-14 22:13 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-14 22:12 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\Malwarebytes
2008-05-14 22:12 --------- d-----w C:\PROGRA~2\Malwarebytes
2008-05-14 19:31 --------- d-----w C:\Program Files\Trend Micro
2008-05-14 18:24 --------- d-----w C:\Program Files\OD Fellowship
2008-05-14 18:21 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\LimeWire
2008-05-14 18:04 --------- d-----w C:\PROGRA~2\Google Updater
2008-05-14 06:33 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\Spyware Terminator
2008-05-14 06:33 --------- d-----w C:\PROGRA~2\Spyware Terminator
2008-05-12 15:04 --------- d-----w C:\Program Files\Google
2008-05-12 12:51 --------- d-----w C:\Program Files\Spyware Terminator
2008-05-11 19:42 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\Bitdefender
2008-05-11 19:42 --------- d-----w C:\Program Files\Common Files\BitDefender
2008-05-11 19:42 --------- d-----w C:\Program Files\BitDefender
2008-05-11 19:42 --------- d-----w C:\PROGRA~2\BitDefender
2008-05-11 18:31 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\BitTorrent
2008-05-11 10:01 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-05-10 23:16 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-10 20:18 --------- d-----w C:\Program Files\Navilog1
2008-05-10 11:45 141,312 ----a-w C:\Windows\system32\drivers\sp_rsdrv2.sys
2008-05-10 10:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 10:33 --------- d-----w C:\Program Files\CCleaner
2008-05-10 10:05 --------- d-----w C:\Program Files\VideoLAN
2008-05-09 20:47 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\vlc
2008-05-08 21:56 --------- d-----w C:\Program Files\Digital Image Recovery
2008-05-08 21:38 --------- d-----w C:\Program Files\Mozilla Firefox 3 Beta 2
2008-05-08 21:23 --------- d-----w C:\Program Files\PhotoRescue
2008-05-08 21:22 --------- d-----w C:\Program Files\R-Undelete
2008-05-08 21:01 --------- d-----w C:\Program Files\Dell
2008-05-08 20:47 --------- d-----w C:\Program Files\Common Files\Steam
2008-05-05 18:46 27,048 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
2008-05-05 18:46 15,864 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-05-03 11:23 --------- d-----w C:\Program Files\BitComet
2008-05-01 12:14 --------- d-----w C:\Program Files\DNA
2008-05-01 12:14 --------- d-----w C:\Program Files\BitTorrent
2008-04-14 10:50 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\TribalWeb
2008-04-13 23:33 --------- d-----w C:\Program Files\TribalWeb
2008-04-13 14:20 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\gtk-2.0
2008-04-13 13:57 --------- d-----w C:\Program Files\GIMP-2.0
2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-03-23 20:15 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\CDBurnerXP_Soft
2008-03-23 20:14 --------- d-----w C:\Program Files\CDBurnerXP
2008-03-23 18:24 --------- d-----w C:\Users\Schmitt Thomas\AppData\Roaming\InfraRecorder
2008-03-19 17:38 --------- d-----w C:\Program Files\GameShadow
2008-03-19 17:29 --------- d-----w C:\Program Files\Eidos
2008-03-18 20:17 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-03-18 20:17 103,736 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-02-23 12:35 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-01-28 21:04 130 ----a-w C:\Users\Schmitt Thomas\AppData\Roaming\wklnhst.dat
2008-01-23 13:47 174 --sha-w C:\Program Files\desktop.ini
2008-01-23 14:05 76 --sh--r C:\Windows\CT4CET.bin
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot@2008-05-15_13.40.16.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-15 11:35:39 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-15 11:54:57 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-15 10:52:13 2,031 ----a-w C:\Windows\bthservsdp.dat
+ 2008-05-15 11:44:47 2,031 ----a-w C:\Windows\bthservsdp.dat
- 2008-05-15 11:36:52 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-05-15 11:56:14 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-05-15 11:36:52 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-15 11:56:07 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-15 11:56:07 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-05-15 11:36:48 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-05-15 11:56:10 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-05-15 11:36:52 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-15 11:56:07 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-15 11:56:07 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-05-15 11:36:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-15 11:55:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-15 11:36:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-15 11:55:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-15 11:36:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-15 11:55:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-15 10:57:50 107,004 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-05-15 11:50:55 107,004 ----a-w C:\Windows\System32\perfc009.dat
- 2008-05-15 10:57:50 121,436 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-05-15 11:50:55 121,436 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-05-15 10:57:50 617,860 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-05-15 11:50:55 617,860 ----a-w C:\Windows\System32\perfh009.dat
- 2008-05-15 10:57:50 699,236 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-05-15 11:50:55 699,236 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-05-15 10:47:23 5,372 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2969422473-2044396031-2590192733-1001_UserData.bin
+ 2008-05-15 11:38:32 5,492 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2969422473-2044396031-2590192733-1001_UserData.bin
- 2008-05-15 10:47:23 57,614 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-15 11:38:32 57,788 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-05-15 10:47:20 54,702 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-05-15 11:38:18 54,702 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 11:23 202544]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"Steam"="c:\program files\steam\steam.exe" [2008-04-08 07:33 1271032]
"EPSON Stylus DX4000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBEE.exe" [2006-09-21 05:01 139264]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 13:32 81920]
"i8kfangui"="C:\Program Files\I8kfanGUI\I8kfanGUI.exe" [2007-02-16 18:58 856064]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-12 17:00 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-23 23:31 1006264]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-08 01:50 9728 C:\Windows\System32\HCIMNTR.DLL]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-12 10:40 405504]
"Windows Mobile Device Center"="%windir%\WindowsMobile\wmdc.exe" [ ]
"PMX Daemon"="ICO.EXE" [2006-11-08 17:01 49152 C:\Windows\System32\ico.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 17:44 178712]
"NMSSupport"="C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2007-06-27 12:14 439512]
"CCUTRAYICON"="C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2007-06-27 12:18 215256]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 11:24 16384]
"OEM03Mon.exe"="C:\Windows\OEM03Mon.exe" [2007-06-18 07:44 36864]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-18 20:55 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-18 20:55 8530464]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-18 20:55 81920]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 21:21 57344]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-16 17:45 360448]
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-05-05 20:46 1179256]
C:\Users\Schmitt Thomas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TribalWeb.lnk - C:\Program Files\TribalWeb\tribalweb.exe [2008-04-14 01:33:53 1077248]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-13 13:43:38 715568]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-05-12 17:04:20 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_SZ msv1_0
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{66D325F7-13EE-4E09-BC6B-A3D7CC003DC1}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{E3303E85-3D53-4F82-8FBB-1E11EB268A76}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{46E47314-035C-486C-BA05-6B22398CB516}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{D4D57039-4E6C-45E4-8EEA-4B06D87E04C5}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{C59140C1-2A19-4F54-A3EC-245625CCE8C4}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{45A8B59E-B906-4AB4-8069-4A33EB29D73C}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{92CFFF70-D947-48F9-9520-BD6FFF4B8C8C}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{F937CF89-A058-4754-8002-070C32762697}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{238B8FCF-C5DB-4C92-B401-DE1553AC2E79}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{F7591647-D0F3-48DE-8A5A-AC71C8EF22BB}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{22A7872A-FC91-4552-A5E7-4C14CC35BED7}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{ED883DAA-B623-4E09-B3A2-0931069C1354}C:\\program files\\steam\\steamapps\\lavazza_12\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\lavazza_12\counter-strike source\hl2.exe:hl2
"UDP Query User{74C89AF8-6694-4DBE-9E58-728F4B11EA30}C:\\program files\\steam\\steamapps\\lavazza_12\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\lavazza_12\counter-strike source\hl2.exe:hl2
"TCP Query User{7E09E2D3-61A2-4CA0-B418-4F4EFFEF8F42}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{82378C2A-3681-49F4-A20A-5E1797C10CF5}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{9FE20974-0545-46C1-8C01-B93A9BCD3544}C:\\program files\\tribalweb\\tribalweb.exe"= UDP:C:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{CFF254E7-1375-4A1A-B3C0-B4E25D75DDD1}C:\\program files\\tribalweb\\tribalweb.exe"= TCP:C:\program files\tribalweb\tribalweb.exe:tribalweb
"{196DA644-8F74-4744-B169-FAFF88230318}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{315FFAB2-A9B1-4CFC-931E-07B83A34FB26}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{E25BC13A-E33D-4D86-9187-415B53DD6594}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{8F88DD4B-6553-4FBE-BF1D-890D2D576621}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{24CF6482-152E-4D13-AC60-B840C59C2D82}C:\\users\\schmitt thomas\\program files\\dna\\btdna.exe"= UDP:C:\users\schmitt thomas\program files\dna\btdna.exe:btdna.exe
"UDP Query User{1FA35981-0803-4DE4-9B35-7D7483A87DD8}C:\\users\\schmitt thomas\\program files\\dna\\btdna.exe"= TCP:C:\users\schmitt thomas\program files\dna\btdna.exe:btdna.exe
"TCP Query User{0B894D4B-2CDE-45C4-8879-B8A2E3726618}C:\\users\\schmitt thomas\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\schmitt thomas\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{651962D3-A79F-49A4-BE3F-1D942B835F8F}C:\\users\\schmitt thomas\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\schmitt thomas\program files\bittorrent\bittorrent.exe:bittorrent.exe
"TCP Query User{9C03F2AA-3EED-4CED-9D72-820131C30055}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{5AAAADF2-31DA-48D6-B6C6-B21D2E45FE38}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\\Program Files\\Winsos\\winsos.exe"= C:\Program Files\Winsos\winsos.exe:*:Enabled:Winsos
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fanio;FanIO driver;C:\Windows\system32\drivers\fanio.sys [2007-02-16 11:05]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2008-05-10 13:45]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 02:45]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2007-02-12 13:46]
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-03-09 12:20]
R2 NMSCore;Intel(R) NMSCore;"C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe" [2007-06-27 12:14]
R2 nmsunidr;UniDriver for NMS;C:\Windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 22:34]
R2 QualityManager;Intel(R) Quality Manager;"C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe" [2007-06-27 12:17]
R2 RapiMgr;Windows Mobile-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 11:23]
R2 WcesComm;Windows Mobile-2003-based device connectivity;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
R3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 09:30]
R3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-04-02 06:42]
R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-04-02 06:42]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-04-02 06:42]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;C:\Windows\system32\drivers\HCW85BDA.sys [2007-11-20 09:20]
R3 IntelDH;IntelDH Driver;C:\Windows\system32\Drivers\IntelDH.sys [2008-01-23 16:10]
R3 LazerUsb;Lumanate Lazer USB;C:\Windows\system32\DRIVERS\LazerUsb.sys [2007-08-29 11:33]
R3 OEM03Afx;Provides a software interface to control audio effects of OEM003 camera.;C:\Windows\system32\Drivers\OEM03Afx.sys [2007-06-18 07:44]
R3 OEM03Vfx;Creative Camera OEM003 Video VFX Driver;C:\Windows\system32\DRIVERS\OEM03Vfx.sys [2007-06-18 07:44]
R3 OEM03Vid;Creative Camera OEM003 Driver;C:\Windows\system32\DRIVERS\OEM03Vid.sys [2007-06-18 07:44]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\system32\DRIVERS\livecamv.sys [2007-01-15 19:57]
S3 DHTRACE;Intel(R) DHTrace Controller;C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2007-06-27 12:15]
S3 pmxmouse;PMXMOUSE;C:\Windows\system32\DRIVERS\pmxmouse.sys [2007-06-01 15:41]
S3 pmxusblf;PMXUSBLF;C:\Windows\system32\DRIVERS\pmxusblf.sys [2007-05-24 18:44]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-05-08 12:11]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bdx REG_MULTI_SZ scan
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-15 13:56:25
Windows 6.0.6000 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\System32\PnkBstrA.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Windows\System32\stacsv.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\issm.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
C:\Program Files\Intel\NCS2\WMIProv\ncs2prov.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\System32\conime.exe
C:\Program Files\Windows Media Player\WMPSideShowGadget.exe
C:\Program Files\Windows Mail\WindowsMailGadget.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Dell\Xcelerator\bin\ehLumaQuarkD.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
C:\Windows\ehome\ehsched.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-15 14:01:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-15 11:59:53
ComboFix2.txt 2008-05-15 11:40:50
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associ‚ au num‚ro 0x2379 est introuvable dans le fichier de messages pour Application.
295 --- E O F --- 2008-05-14 23:10:33