voicii le rapport de combofix dites moi si tout est bon ?
ComboFix 08-05-21.2 - Ludovic 2008-05-22 19:26:42.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1217 [GMT 1:00]
Endroit: C:\Users\Ludovic\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\efcBrOiJ.dll
C:\Windows\system32\efcDTKcC.dll
C:\Windows\system32\geBtRLee.dll
C:\Windows\system32\jusched.exe
C:\Windows\system32\nnnKBSmK.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-22 to 2008-05-22 ))))))))))))))))))))))))))))))))))))
.
2008-05-22 18:33 . 2008-05-22 18:33 <REP> d-------- C:\WINDOWS\System32\Kaspersky Lab
2008-05-22 17:48 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\System32\d3dx9_26.dll
2008-05-22 16:57 . 2008-05-22 16:57 <REP> d-------- C:\WINDOWS\Sun
2008-05-22 16:38 . 2008-05-22 16:38 1,037 --a------ C:\WINDOWS\System32\sdbackup.reg
2008-05-22 16:24 . 2008-05-22 17:36 <REP> d-------- C:\Program Files\EA GAMES
2008-05-22 16:24 . 2004-08-18 09:34 442,368 -ra------ C:\WINDOWS\System32\vp6vfw.dll
2008-05-22 16:14 . 2008-05-22 16:14 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-05-22 16:09 . 2008-05-22 16:09 717,296 --a------ C:\WINDOWS\System32\drivers\sptd.sys
2008-05-22 16:08 . 2008-05-22 16:08 <REP> d-------- C:\Users\Ludovic\AppData\Roaming\DAEMON Tools
2008-05-22 15:37 . 2008-05-22 16:03 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-05-22 15:23 . 2008-05-22 15:38 <REP> d-------- C:\Users\All Users\Lavasoft
2008-05-22 15:23 . 2008-05-22 15:38 <REP> d-------- C:\ProgramData\Lavasoft
2008-05-22 15:10 . 2008-05-22 15:10 <REP> d-------- C:\Users\All Users\IncrediMail
2008-05-22 15:10 . 2008-05-22 15:11 <REP> d-------- C:\Users\All Users\IM
2008-05-22 15:10 . 2008-05-22 15:10 <REP> d-------- C:\ProgramData\IncrediMail
2008-05-22 15:10 . 2008-05-22 15:11 <REP> d-------- C:\ProgramData\IM
2008-05-22 15:10 . 2008-05-22 15:10 <REP> d-------- C:\Program Files\IncrediMail
2008-05-21 23:12 . 2008-05-21 23:12 <REP> d-------- C:\Users\Chantal\AppData\Roaming\Hewlett-Packard
2008-05-21 21:49 . 2008-05-21 21:49 268 --ah----- C:\sqmdata02.sqm
2008-05-21 21:49 . 2008-05-21 21:49 244 --ah----- C:\sqmnoopt02.sqm
2008-05-21 21:43 . 2008-05-22 16:27 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-05-21 21:43 . 2008-05-22 16:27 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-05-21 21:43 . 2008-05-22 16:18 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-21 21:40 . 2008-05-21 21:40 <REP> d-------- C:\Users\All Users\Messenger Plus!
2008-05-21 21:40 . 2008-05-21 21:40 <REP> d-------- C:\ProgramData\Messenger Plus!
2008-05-21 21:40 . 2008-05-21 21:40 268 --ah----- C:\sqmdata01.sqm
2008-05-21 21:40 . 2008-05-21 21:40 244 --ah----- C:\sqmnoopt01.sqm
2008-05-21 21:35 . 2008-05-21 21:35 1,060,920 --a------ C:\WINDOWS\System32\drivers\ntfs.sys
2008-05-21 21:35 . 2008-05-21 21:35 41,984 --a------ C:\WINDOWS\System32\drivers\monitor.sys
2008-05-21 21:32 . 2008-05-21 21:32 3,505,720 --a------ C:\WINDOWS\System32\ntkrnlpa.exe
2008-05-21 21:32 . 2008-05-21 21:32 3,471,928 --a------ C:\WINDOWS\System32\ntoskrnl.exe
2008-05-21 21:32 . 2008-05-21 21:32 211,000 --a------ C:\WINDOWS\System32\drivers\volsnap.sys
2008-05-21 21:32 . 2008-05-21 21:32 154,624 --a------ C:\WINDOWS\System32\drivers\nwifi.sys
2008-05-21 21:32 . 2008-05-21 21:32 109,624 --a------ C:\WINDOWS\System32\drivers\ataport.sys
2008-05-21 21:32 . 2008-05-21 21:32 45,112 --a------ C:\WINDOWS\System32\drivers\pciidex.sys
2008-05-21 21:32 . 2008-05-21 21:32 21,560 --a------ C:\WINDOWS\System32\drivers\atapi.sys
2008-05-21 21:32 . 2008-05-21 21:32 17,464 --a------ C:\WINDOWS\System32\drivers\intelide.sys
2008-05-21 21:31 . 2008-05-21 21:31 1,327,104 --a------ C:\WINDOWS\System32\quartz.dll
2008-05-21 21:31 . 2008-05-21 21:31 806,400 --a------ C:\WINDOWS\System32\drivers\tcpip.sys
2008-05-21 21:31 . 2008-05-21 21:31 217,144 --a------ C:\WINDOWS\System32\drivers\netio.sys
2008-05-21 21:31 . 2008-05-21 21:31 167,424 --a------ C:\WINDOWS\System32\tcpipcfg.dll
2008-05-21 21:31 . 2008-05-21 21:31 24,064 --a------ C:\WINDOWS\System32\netcfg.exe
2008-05-21 21:31 . 2008-05-21 21:31 22,016 --a------ C:\WINDOWS\System32\netiougc.exe
2008-05-21 21:30 . 2008-05-21 21:30 <REP> d-------- C:\Users\Sandra\AppData\Roaming\Hewlett-Packard
2008-05-21 21:25 . 2008-05-21 21:25 1,585,664 --a------ C:\WINDOWS\System32\setupapi.dll
2008-05-21 21:23 . 2008-05-21 21:23 2,027,008 --a------ C:\WINDOWS\System32\win32k.sys
2008-05-21 21:22 . 2008-05-21 21:22 4,247,552 --a------ C:\WINDOWS\System32\GameUXLegacyGDFs.dll
2008-05-21 21:22 . 2008-05-21 21:22 1,686,528 --a------ C:\WINDOWS\System32\gameux.dll
2008-05-21 21:22 . 2008-05-21 21:22 296,448 --a------ C:\WINDOWS\System32\gdi32.dll
2008-05-21 21:22 . 2008-05-21 21:22 223,232 --a------ C:\WINDOWS\System32\WMASF.DLL
2008-05-21 21:22 . 2008-05-21 21:22 9,728 --a------ C:\WINDOWS\System32\LAPRXY.DLL
2008-05-21 21:22 . 2008-05-21 21:22 2,048 --a------ C:\WINDOWS\System32\asferror.dll
2008-05-21 21:21 . 2008-05-21 21:21 11,776 --a------ C:\WINDOWS\System32\sbunattend.exe
2008-05-21 21:20 . 2008-05-21 21:20 84,480 --a------ C:\WINDOWS\System32\dnsrslvr.dll
2008-05-21 21:20 . 2008-05-21 21:20 24,576 --a------ C:\WINDOWS\System32\dnscacheugc.exe
2008-05-21 21:17 . 2008-05-22 19:09 <REP> d-------- C:\Users\Ludovic\AppData\Roaming\uTorrent
2008-05-21 21:17 . 2008-05-21 21:17 <REP> d-------- C:\Program Files\uTorrent
2008-05-21 21:16 . 2008-05-21 21:16 130,048 --a------ C:\WINDOWS\System32\drivers\srv2.sys
2008-05-21 21:16 . 2008-05-21 21:16 101,888 --a------ C:\WINDOWS\System32\drivers\mrxsmb.sys
2008-05-21 21:16 . 2008-05-21 21:16 84,992 --a------ C:\WINDOWS\System32\drivers\srvnet.sys
2008-05-21 21:16 . 2008-05-21 21:16 58,368 --a------ C:\WINDOWS\System32\drivers\mrxsmb20.sys
2008-05-21 21:15 . 2008-05-21 21:15 826,368 --a------ C:\WINDOWS\System32\wininet.dll
2008-05-21 21:13 . 2008-05-21 21:13 <REP> d-------- C:\Program Files\MSXML 4.0
2008-05-21 21:11 . 2008-05-21 21:11 2,048 --a------ C:\WINDOWS\System32\tzres.dll
2008-05-21 21:07 . 2008-05-21 21:07 1,244,672 --a------ C:\WINDOWS\System32\mcmde.dll
2008-05-21 20:24 . 2008-05-21 20:24 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-05-21 20:23 . 2008-05-21 20:23 268 --ah----- C:\sqmdata00.sqm
2008-05-21 20:23 . 2008-05-21 20:23 244 --ah----- C:\sqmnoopt00.sqm
2008-05-21 20:12 . 2008-05-21 20:21 <REP> d-------- C:\Program Files\Windows Live
2008-05-21 20:12 . 2008-05-21 20:21 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-21 20:11 . 2008-05-21 20:11 <REP> d-------- C:\Users\All Users\WLInstaller
2008-05-21 20:11 . 2008-05-21 20:11 <REP> d-------- C:\ProgramData\WLInstaller
2008-05-21 20:10 . 2008-05-21 20:10 <REP> d-------- C:\Users\All Users\Google
2008-05-21 20:09 . 2008-05-21 21:10 <REP> d-------- C:\Users\All Users\Google Updater
2008-05-21 20:09 . 2008-05-21 21:10 <REP> d-------- C:\ProgramData\Google Updater
2008-05-21 19:08 . 2008-05-21 19:08 <REP> d-------- C:\Users\All Users\CheckPoint
2008-05-21 19:08 . 2008-05-21 19:08 <REP> d-------- C:\ProgramData\CheckPoint
2008-05-21 19:08 . 2008-05-21 19:08 <REP> d-------- C:\Program Files\Zone Labs
2008-05-21 19:07 . 2008-05-21 19:08 <REP> d-------- C:\WINDOWS\System32\ZoneLabs
2008-05-21 19:07 . 2008-05-22 19:34 352,615 --ah----- C:\WINDOWS\System32\drivers\vsconfig.xml
2008-05-21 19:07 . 2008-03-03 15:06 279,440 --------- C:\WINDOWS\System32\drivers\vsdatant.sys
2008-05-21 19:07 . 2008-05-16 00:18 50,768 --a------ C:\WINDOWS\System32\drivers\aswMonFlt.sys
2008-05-21 19:06 . 2008-05-22 19:35 <REP> d-------- C:\WINDOWS\Internet Logs
2008-05-21 19:06 . 2008-05-21 19:06 1,712,984 --a------ C:\WINDOWS\System32\wuaueng.dll
2008-05-21 19:06 . 2008-05-21 19:06 1,524,224 --a------ C:\WINDOWS\System32\wucltux.dll
2008-05-21 19:06 . 2008-05-21 19:06 53,080 --a------ C:\WINDOWS\System32\wuauclt.exe
2008-05-21 19:06 . 2008-05-21 19:06 43,352 --a------ C:\WINDOWS\System32\wups2.dll
2008-05-21 18:55 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\System32\msonpmon.dll
2008-05-21 18:52 . 2008-05-21 18:52 <REP> d-------- C:\WINDOWS\PCHEALTH
2008-05-21 18:52 . 2008-05-21 18:52 <REP> d-------- C:\Program Files\Microsoft.NET
2008-05-21 18:50 . 2008-05-21 18:50 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-05-21 18:49 . 2008-05-21 21:38 <REP> d-------- C:\Users\All Users\Microsoft Help
2008-05-21 18:49 . 2008-05-21 21:38 <REP> d-------- C:\ProgramData\Microsoft Help
2008-05-21 18:46 . 2008-05-21 18:46 <REP> dr-h----- C:\MSOCache
2008-05-21 18:44 . 2008-05-21 18:44 <REP> d-------- C:\Program Files\CCleaner
2008-05-21 18:44 . 2008-05-21 18:44 <REP> d-------- C:\Program Files\Alwil Software
2008-05-21 18:43 . 2006-12-15 22:19 897,024 --a------ C:\WINDOWS\System32\hpotiop1.dll
2008-05-21 18:43 . 2006-12-15 22:19 675,840 --a------ C:\WINDOWS\System32\hpowiav1.dll
2008-05-21 18:43 . 2006-12-15 22:19 303,104 --a------ C:\WINDOWS\System32\hpovst01.dll
2008-05-21 18:42 . 2006-12-29 09:57 117,760 --a------ C:\WINDOWS\System32\hpz3l4v2.dll
2008-05-21 18:41 . 2008-05-21 18:41 <REP> d-------- C:\Users\All Users\Adobe Systems
2008-05-21 18:41 . 2008-05-21 18:41 <REP> d-------- C:\ProgramData\Adobe Systems
2008-05-21 18:40 . 2008-05-21 18:40 <REP> d-------- C:\Users\Ludovic\All Users
2008-05-21 18:38 . 2008-05-21 18:38 <REP> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-05-21 18:36 . 2008-05-21 18:36 <REP> d-------- C:\Users\All Users\Acronis
2008-05-21 18:36 . 2008-05-21 18:36 <REP> d-------- C:\ProgramData\Acronis
2008-05-21 18:36 . 2008-05-21 18:36 441,760 --a------ C:\WINDOWS\System32\drivers\timntr.sys
2008-05-21 18:36 . 2008-05-21 18:36 368,736 --a------ C:\WINDOWS\System32\drivers\tdrpman.sys
2008-05-21 18:36 . 2008-05-21 18:36 129,248 --a------ C:\WINDOWS\System32\drivers\snapman.sys
2008-05-21 18:36 . 2008-05-21 18:36 44,384 --a------ C:\WINDOWS\System32\drivers\tifsfilt.sys
2008-05-21 18:35 . 2008-05-21 18:36 <REP> d-------- C:\Program Files\Common Files\Acronis
2008-05-21 18:35 . 2008-05-21 18:35 <REP> d-------- C:\Program Files\Acronis
2008-05-21 18:33 . 2008-05-22 16:07 <REP> d-------- C:\Users\Ludovic\AppData\Roaming\Ahead
2008-05-21 18:33 . 2008-05-21 18:33 <REP> d-------- C:\Users\All Users\Ahead
2008-05-21 18:33 . 2008-05-21 18:33 <REP> d-------- C:\ProgramData\Ahead
2008-05-21 18:32 . 2008-05-21 18:32 <REP> d-------- C:\Program Files\Common Files\Ahead
2008-05-21 18:28 . 2008-05-21 18:28 <REP> d-------- C:\Program Files\VideoLAN
2008-05-21 18:28 . 2008-05-21 18:28 <REP> d-------- C:\Program Files\UltraDefrag
2008-05-21 18:28 . 2008-05-21 18:28 <REP> d-------- C:\Program Files\TubeMaster
2008-05-21 18:27 . 2008-05-21 18:27 <REP> d-------- C:\Program Files\MSN BackUp
2008-05-21 18:27 . 2008-05-21 18:27 <REP> d-------- C:\Program Files\Mozilla Thunderbird
2008-05-21 18:27 . 2008-05-22 19:21 <REP> d-------- C:\Program Files\Eraser
2008-05-21 18:27 . 2008-05-21 18:27 3,476 --a------ C:\WINDOWS\mozver.dat
2008-05-21 18:26 . 2008-05-21 18:26 <REP> d-------- C:\Program Files\Radio Fr Solo
2008-05-21 18:26 . 2008-05-21 21:10 <REP> d-------- C:\Program Files\Picasa2
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-22 16:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-22 16:42 --------- d-----w C:\Program Files\Microsoft Games
2008-05-22 15:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-21 21:08 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-21 21:08 --------- d-----w C:\Program Files\Windows Mail
2008-05-21 20:37 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-05-21 20:37 2,923,520 ----a-w C:\Windows\explorer.exe
2008-05-21 20:37 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-05-21 20:24 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-05-21 20:24 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-05-21 20:24 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-05-21 20:24 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-05-21 20:24 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-05-21 20:24 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-05-21 20:24 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-05-21 20:24 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
2008-05-21 20:22 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-05-21 20:22 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-05-21 20:22 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-05-21 20:22 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-05-21 20:22 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-05-21 20:15 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-05-21 17:54 --------- d-----w C:\ProgramData\WildTangent
2008-05-21 17:53 --------- d-----w C:\Program Files\MSBuild
2008-05-21 17:53 --------- d-----w C:\Program Files\Microsoft Works
2008-05-21 17:48 --------- d-----w C:\ProgramData\Hewlett-Packard
2008-05-21 17:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-21 17:13 --------- d-----w C:\ProgramData\Symantec
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Modèles
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Favoris
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Documents
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Bureau
2008-05-21 16:59 --------- d-sh--w C:\ProgramData\Application Data
2008-05-21 16:59 --------- d-sh--w C:\Program Files\Fichiers communs
2007-12-07 21:57 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-05-21 21:21 1232896]
"Eraser"="C:\Program Files\Eraser\eraser.exe" [2003-07-25 11:15 536576]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-21 20:09 68856]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-05-18 19:44 243072]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 10:39 486856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-08 07:26 1006264]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 17:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 12:59 118784]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-25 14:52 4702208 C:\WINDOWS\RtHDVCpl.exe]
"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2007-04-07 02:56 54936]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-07 17:01 2620336]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-07 17:36 904880]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-07 17:08 140568]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 15:05 959976]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
C:\Users\Ludovic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 16:24 54840 c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
--a------ 2007-04-18 16:01 65536 c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1160770533-2116503048-2882012982-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F8D4CCCB-1626-45AE-8D7E-7581943CC359}"= c:\Program Files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{051F7D88-3D8F-4F83-833D-B9496D70F680}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{BAA57561-F094-4939-9E5C-05699F02FC7C}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{76AEFEAB-5413-4431-BA18-BF2A686DB56C}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{195BAC5B-A2E4-46DD-BF07-CD44EC99A88C}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B66C0FB8-444D-4FF3-AA5E-09C96088C437}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4DA716B4-A811-431A-9EC2-89520C266D89}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B47529E4-C1A3-41A2-9A3E-01ABD7B8173D}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{ECE29975-3334-4BB3-8EDD-B1622FD8468C}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{F79478BF-777E-4B72-A328-6EEFD1A3F9C5}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{B4945324-29D9-42CC-83DE-861259445F21}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{59D20CA1-A756-4560-8CFC-8F005D7FE7B2}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{50D6BB02-CE81-4C32-BF00-8CBEC1E15025}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{66F7BA51-8387-4F63-990F-AF8549DA1365}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{2EC9DB9C-D3B2-446D-9DE9-573748A004FD}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{5B251F92-CE5E-4DBD-A675-21B48D3F18A9}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{6EB0809D-EB4D-45B0-AF3C-8956CC468B8F}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{A1744227-94EF-459F-B489-D4D5F3C7A6FA}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{5873A7D6-C31D-439C-A5A0-E8D14EFA876C}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-05-21 18:36]
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-16 00:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 00:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-16 00:18]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-09-14 23:16]
S3 ultradfg;ultradfg;C:\Windows\system32\DRIVERS\ultradfg.sys [2007-10-08 10:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{45bd088f-2811-11dd-ae11-001e907216c5}]
\shell\AutoRun\command - J:\Autorun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-22 19:36:03
Windows 6.0.6000 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\Users\Ludovic\AppData\Local\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1201 bytes hidden from API
Scan termin‚ avec succŠs
Les fichiers cach‚s: 1
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\Windows\Explorer.exe
-> ?:\Windows\system32\urlmon.dll
-> ?:\Program Files\IncrediMail\bin\B4ImApp.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\audiodg.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\System32\schtasks.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\WUDFHost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\IncrediMail\bin\ImApp.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\hp\KBD\kbd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-22 19:43:59 - machine was rebooted [Ludovic]
ComboFix-quarantined-files.txt 2008-05-22 18:43:48
Pre-Run: 262,198,046,720 octets libres
Post-Run: 263,205,097,472 octets libres
321 --- E O F --- 2008-05-22 15:50:52
[05/22/2008, 19:21:20] - VirtumundoBeGone v1.5 ( "C:\Users\Ludovic\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ECD7WPAM\VirtumundoBeGone[1].exe" )
[05/22/2008, 19:21:35] - Detected System Information:
[05/22/2008, 19:21:35] - Windows Version: 6.0.6000,
[05/22/2008, 19:21:35] - Current Username: Ludovic (Admin)
[05/22/2008, 19:21:35] - Windows is in NORMAL mode.
[05/22/2008, 19:21:35] - Searching for Browser Helper Objects:
[05/22/2008, 19:21:35] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[05/22/2008, 19:21:35] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/22/2008, 19:21:35] - BHO 3: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} ()
[05/22/2008, 19:21:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/22/2008, 19:21:35] - No filename found. Continuing.
[05/22/2008, 19:21:35] - BHO 4: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (Groove GFS Browser Helper)
[05/22/2008, 19:21:35] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[05/22/2008, 19:21:35] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[05/22/2008, 19:21:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/22/2008, 19:21:35] - No filename found. Continuing.
[05/22/2008, 19:21:35] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/22/2008, 19:21:35] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[05/22/2008, 19:21:35] - Finished Searching Browser Helper Objects
[05/22/2008, 19:21:35] - Finishing up...
[05/22/2008, 19:21:35] - Nothing found! Exiting...