ComboFix 08-06-04.5 - autumn 2008-06-06 12:33:10.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.142 [GMT 2:00]
Endroit: C:\Documents and Settings\autumn\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\autumn\Bureau\CFScript.txt..txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE ::
C:\Documents and Settings\All Users\Application Data\third lies itch ford\Online deaf.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\SearchSettings.exe
C:\upload_moi_PAIX2007.tar.gz
C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\SearchSettings.exe
C:\WINDOWS\QTFont.for
C:\WINDOWS\QTFont.qfn
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-06 to 2008-06-06 ))))))))))))))))))))))))))))))))))))
.
2008-06-04 22:25 . 2008-06-04 22:25 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-04 22:25 . 2008-06-04 22:25 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Malwarebytes
2008-06-04 22:25 . 2008-06-04 22:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-04 22:25 . 2008-05-30 01:06 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-04 22:25 . 2008-05-30 01:06 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-04 21:14 . 2008-06-04 21:14 <REP> d-------- C:\Program Files\Trend Micro
2008-06-04 17:17 . 2008-06-04 17:17 <REP> d-------- C:\Program Files\Shareaza
2008-06-04 17:17 . 2008-06-04 17:17 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Shareaza
2008-06-03 16:48 . 2008-03-01 14:58 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-06-03 16:48 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-06-03 16:48 . 2007-03-08 07:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-06-03 16:48 . 2008-03-01 14:58 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-06-03 16:48 . 2008-03-01 14:58 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-06-03 16:48 . 2008-03-01 14:58 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-06-03 16:48 . 2008-03-01 14:58 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-06-03 16:48 . 2008-03-01 14:58 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-06-03 16:48 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-03 01:15 . 2008-06-03 01:15 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-02 20:19 . 2008-06-03 17:39 <REP> d-------- C:\Program Files\Fichiers communs\Softwin
2008-06-02 19:59 . 2008-06-04 10:01 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-06-02 19:55 . 2008-06-04 10:01 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-06-02 19:49 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-06-02 19:49 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-06-02 19:49 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-06-02 19:47 . 2008-06-02 19:47 <REP> d-------- C:\Program Files\AxBx
2008-06-02 15:21 . 2008-06-02 15:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-01 14:19 . 2008-06-01 14:19 <REP> d-------- C:\Program Files\Size The Acid
2008-05-31 19:46 . 2008-05-31 19:46 <REP> d-------- C:\Program Files\iTunes
2008-05-31 19:46 . 2008-05-31 19:46 <REP> d-------- C:\Program Files\iPod
2008-05-31 19:46 . 2008-05-31 19:46 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Apple Computer
2008-05-31 19:44 . 2008-05-31 19:45 <REP> d-------- C:\Program Files\QuickTime
2008-05-31 19:44 . 2008-05-31 19:44 <REP> d-------- C:\Program Files\Apple Software Update
2008-05-31 19:44 . 2008-05-31 19:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-05-31 19:43 . 2008-05-31 19:43 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-05-31 19:43 . 2008-05-31 19:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-05-28 12:16 . 2008-05-28 12:16 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Search Settings
2008-05-27 15:02 . 2008-05-27 15:10 <REP> d-------- C:\Program Files\Free FLV Converter
2008-05-27 15:02 . 2007-06-19 01:22 364,544 --a------ C:\WINDOWS\system32\PropertyGrid.ocx
2008-05-27 15:02 . 2008-05-15 11:30 208,896 --a------ C:\WINDOWS\system32\TubeFinder.exe
2008-05-27 15:02 . 2005-10-13 15:42 208,500 --a------ C:\WINDOWS\system32\ReyXpBasics.tlb
2008-05-27 15:02 . 1998-07-13 01:00 141,312 --a------ C:\WINDOWS\system32\MSCMCFR.DLL
2008-05-27 15:02 . 2000-07-15 07:00 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2008-05-27 15:02 . 2004-03-09 02:00 84,512 --a------ C:\WINDOWS\system32\PICCLP32.OCX
2008-05-27 15:02 . 1998-07-12 21:00 32,768 --a------ C:\WINDOWS\system32\CMDLGFR.DLL
2008-05-27 15:02 . 2005-09-28 03:31 24,576 --a------ C:\WINDOWS\system32\ControlSubX.ocx
2008-05-27 15:02 . 1998-07-13 02:00 9,728 --a------ C:\WINDOWS\system32\PCCLPFR.DLL
2008-05-27 14:25 . 2008-05-27 14:44 <REP> d-------- C:\Documents and Settings\autumn\dwhelper
2008-05-23 14:26 . 2007-04-24 11:33 108,680 -ra------ C:\WINDOWS\system32\drivers\s125mdm.sys
2008-05-23 14:26 . 2007-04-24 11:33 100,488 -ra------ C:\WINDOWS\system32\drivers\s125mgmt.sys
2008-05-23 14:26 . 2007-04-24 11:33 98,696 -ra------ C:\WINDOWS\system32\drivers\s125obex.sys
2008-05-23 14:26 . 2007-04-24 11:33 83,336 -ra------ C:\WINDOWS\system32\drivers\s125bus.sys
2008-05-23 14:26 . 2007-04-24 11:33 15,112 -ra------ C:\WINDOWS\system32\drivers\s125mdfl.sys
2008-05-23 14:26 . 2007-04-24 11:33 12,424 -ra------ C:\WINDOWS\system32\drivers\s125whnt.sys
2008-05-23 14:26 . 2007-04-24 11:33 12,424 -ra------ C:\WINDOWS\system32\drivers\s125wh.sys
2008-05-23 14:26 . 2007-04-24 11:33 12,424 -ra------ C:\WINDOWS\system32\drivers\s125cmnt.sys
2008-05-23 14:26 . 2007-04-24 11:33 12,424 -ra------ C:\WINDOWS\system32\drivers\s125cm.sys
2008-05-22 23:27 . 2008-05-22 23:28 <REP> d-------- C:\Program Files\Lexmark 1200 Series
2008-05-22 23:27 . 2006-01-12 12:32 983,107 --a------ C:\WINDOWS\system32\LXCZGF.DLL
2008-05-22 23:27 . 2006-07-13 13:24 458,752 --a------ C:\WINDOWS\system32\LXCZJSWR.DLL
2008-05-22 23:27 . 2006-07-13 13:17 356,352 --a------ C:\WINDOWS\system32\LXCZUTIL.DLL
2008-05-22 23:27 . 2006-07-13 13:45 69,632 --a------ C:\WINDOWS\system32\lxczscin.dll
2008-05-22 23:27 . 2006-07-13 13:45 57,344 --a------ C:\WINDOWS\system32\lxczcinf.dll
2008-05-22 23:27 . 2006-07-13 13:45 49,152 --a------ C:\WINDOWS\system32\lxczcoin.dll
2008-05-22 23:27 . 2006-01-30 20:42 270 --a------ C:\WINDOWS\system32\lxczcoin.ini
2008-05-22 23:15 . 2008-05-22 23:15 <REP> d-------- C:\Lexmark
2008-05-22 21:04 . 2008-05-22 21:04 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Teleca
2008-05-22 21:02 . 2008-05-22 21:02 <REP> d-------- C:\Documents and Settings\autumn\Application Data\Sony Ericsson
2008-05-20 18:03 . 2008-05-20 18:03 <REP> d-------- C:\Program Files\Sony Ericsson
2008-05-20 18:03 . 2008-05-20 18:07 <REP> d-------- C:\Program Files\Fichiers communs\Teleca Shared
2008-05-20 18:03 . 2008-05-20 18:03 <REP> d-------- C:\Program Files\Fichiers communs\Sony Ericsson Shared
2008-05-20 18:02 . 2008-05-20 18:02 <REP> d-------- C:\WINDOWS\Downloaded Installations
2008-05-20 18:00 . 2008-05-20 18:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Teleca
2008-05-20 18:00 . 2008-05-20 18:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-05-16 13:31 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-05-16 13:31 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-13 03:53 . 2008-05-13 03:53 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-05-13 03:53 . 2008-05-13 03:53 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-05-13 03:53 . 2008-05-13 03:53 9,878 --a------ C:\WINDOWS\system32\dsm_fr.qm
2008-05-13 03:53 . 2008-05-13 03:53 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-05-13 03:51 . 2008-05-13 03:51 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-05-13 03:51 . 2008-05-13 03:51 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-05-13 03:49 . 2008-05-13 03:49 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-05-13 03:49 . 2008-05-13 03:49 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
2008-05-13 03:49 . 2008-05-13 03:49 161,096 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-13 03:49 . 2008-05-13 03:49 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-13 03:48 . 2008-05-13 03:48 8,835 --a------ C:\WINDOWS\system32\dpufr.qm
2008-05-12 12:37 . 2008-05-12 12:39 <REP> d-------- C:\Program Files\Startup Manager
2008-05-12 12:37 . 2008-05-12 12:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Startup Manager
2008-05-12 12:33 . 2008-05-12 12:33 <REP> d-------- C:\Program Files\SystemRequirementsLab
2008-05-12 12:33 . 2008-05-12 12:33 <REP> d-------- C:\Documents and Settings\autumn\Application Data\SystemRequirementsLab
2008-05-12 12:07 . 2008-05-12 12:10 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-11 18:11 . 2008-05-11 18:11 <REP> d-------- C:\WINDOWS\Profiles
2008-05-06 17:11 . 2008-05-06 17:12 <REP> d-------- C:\Program Files\SecondLife
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 09:57 --------- d-----w C:\Program Files\eMule
2008-06-05 16:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-02 23:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-02 15:06 --------- d-----w C:\Program Files\MSN Messenger
2008-06-02 13:21 --------- d-----w C:\Program Files\Lavasoft
2008-06-02 13:20 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-06-01 12:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\third lies itch ford
2008-06-01 12:04 --------- d-----w C:\Program Files\DivX
2008-05-30 16:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-05-28 15:46 --------- d-----w C:\Program Files\Yahoo!
2008-05-26 11:12 --------- d-----w C:\Program Files\Zylom Games
2008-05-13 01:53 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-05-13 01:53 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-05-13 01:53 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-05-13 01:53 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-05-13 01:53 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-05-13 01:53 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-05-12 12:16 --------- d-----w C:\Program Files\EA GAMES
2008-05-11 17:57 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-05-11 16:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-11 16:06 --------- d-----w C:\Documents and Settings\autumn\Application Data\Microsoft Games
2008-05-11 16:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-05-11 16:00 --------- d-----w C:\Program Files\Fichiers communs\Logitech
2008-05-11 15:58 --------- d-----w C:\Program Files\Google
2008-05-06 15:45 --------- d-----w C:\Documents and Settings\autumn\Application Data\SecondLife
2008-05-01 20:23 --------- d-----w C:\Documents and Settings\autumn\Application Data\Skype
2008-04-30 22:30 --------- d-----w C:\Program Files\Common Files
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-28 20:45 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-28 07:23 --------- d-----w C:\Program Files\GOA
2008-04-25 10:57 --------- d-----w C:\Documents and Settings\autumn\Application Data\IMVU
2008-04-21 13:41 --------- d-----w C:\Program Files\Atari
2008-04-21 12:34 --------- d-----w C:\Program Files\Sims2Pack Clean Installer
2008-04-21 12:34 --------- d-----w C:\Program Files\MySpace
2008-04-21 12:34 --------- d-----w C:\Program Files\GIMP-2.0
2008-04-21 12:34 --------- d-----w C:\Program Files\Beneton Movie GIF
2008-04-19 21:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-04-19 21:41 --------- d-----w C:\Program Files\Windows Live
2008-04-19 21:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-19 15:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-30 14:53 47,360 ----a-w C:\Documents and Settings\autumn\Application Data\pcouffin.sys
2006-03-02 12:00 73,728 -csh--w C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-05_14.46.17.45 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-05 12:29:29 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-06 07:16:13 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA9A5E2B-606B-49CE-A429-FF6E66367B70}]
C:\WINDOWS\system32\pmnoPfeb.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"Splash screen for Avast!"="C:\Program Files\Alwil Software\Avast4\ashAvast.exe" [2008-05-16 01:10 271736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-24 04:08 16050688 C:\WINDOWS\RTHDCPL.exe]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-06-13 08:16 528384]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"Itch ford four knob"="C:\Documents and Settings\All Users\Application Data\third lies itch ford\LOCKS ACTIVE.exe" [2008-06-06 12:17 2157568]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-04 02:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 01:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-04-25 13:34 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Windows Registry Repair Pro"=C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"E07FXLRD_5793000"="C:\Program Files\Microsoft Encarta\Microsoft Encarta 2007 - Collection DVD\EDICT.EXE" -m
"E07FXLRD_9880078"="C:\Program Files\Microsoft Encarta\Microsoft Encarta 2007 - Collection DVD\EDICT.EXE" -m
"E07FXLRD_5371953"="C:\Program Files\Microsoft Encarta\Microsoft Encarta 2007 - Collection DVD\EDICT.EXE" -m
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
"PCMService"="c:\APPS\Powercinema\PCMService.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"WinampAgent"="C:\Program Files\Winamp\Winampa.exe"
"LVCOMSX"="C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
"SeekmoOE"=C:\Program Files\Seekmo\bin\10.0.370.0\OEAddOn.exe
"SeekmoSA"="C:\Program Files\Seekmo\bin\10.0.370.0\SeekmoSA.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Powercinema\\PowerCinema.exe"=
"C:\\APPS\\Powercinema\\PCMService.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\eMule\\eMule.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
"C:\\WINDOWS\\system32\\mcoinstall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 UxTuneUp;Extension de conception TuneUp;C:\WINDOWS\System32\svchost.exe [2006-03-02 14:00]
S3 s125bus;Sony Ericsson Device 125 driver (WDM);C:\WINDOWS\system32\DRIVERS\s125bus.sys [2007-04-24 11:33]
S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s125mdfl.sys [2007-04-24 11:33]
S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s125mdm.sys [2007-04-24 11:33]
S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s125mgmt.sys [2007-04-24 11:33]
S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s125obex.sys [2007-04-24 11:33]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2006-03-02 14:00]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-06 10:00:01 C:\WINDOWS\Tasks\A61B837B91E434A7.job"
- c:\docume~1\alex\applic~1\sizeth~1\MfcdSeekDefault.exe
"2008-06-05 13:15:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-04 16:00:03 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-06 12:36:08
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
C:\Documents and Settings\autumn\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1087 bytes hidden from API
Scan terminé avec succès
Les fichiers cachés: 1
**************************************************************************
.
Temps d'accomplissement: 2008-06-06 12:49:02
ComboFix-quarantined-files.txt 2008-06-06 10:48:57
ComboFix2.txt 2008-06-05 12:47:12
Pre-Run: 49,135,628,288 octets libres
Post-Run: 49,146,945,536 octets libres
289 --- E O F --- 2008-06-04 08:01:43