ComboFix 08-06-12.2 - Louis-Nicolas 2008-06-14 9:47:28.1 - NTFSx86
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.1676 [GMT 2:00]
Endroit: C:\Users\Louis-Nicolas.HP\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\Louis-Nicolas.HP\AppData\Roaming\Microsoft\dtsc
C:\Users\Louis-Nicolas.HP\AppData\Roaming\Microsoft\dtsc\14515.exe
C:\Users\Louis-Nicolas.HP\AppData\Roaming\Microsoft\dtsc\s
C:\Windows\Fonts\CALIBRIB.TTF
C:\Windows\system32\aupmjaaf.dll
C:\Windows\system32\ddcDstSK.dll
C:\Windows\system32\ddcDuVnn.dll
C:\Windows\system32\faajmpua.ini
C:\Windows\system32\kyagpbnp.dll
C:\Windows\system32\lpbgvokp.dll
C:\Windows\system32\nxtpcqgr.ini
C:\Windows\system32\nxugskeg.dll
C:\Windows\system32\racfbvbs.dll
C:\Windows\system32\rnmjvalt.ini
C:\Windows\system32\tlavjmnr.dll
C:\Windows\system32\uenjgifv.ini
C:\Windows\System32\uFNUwyxx.ini
C:\WINDOWS\System32\uFNUwyxx.ini2
C:\Windows\system32\urqPfGWN.dll
C:\Windows\system32\vohfceua.dll
C:\Windows\system32\x64
D:\Autorun.inf
----- BITS: Possible sites infect‚s -----
hxxp://theinstalls.com
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-14 to 2008-06-14 ))))))))))))))))))))))))))))))))))))
.
2008-06-14 00:07 . 2008-06-14 00:07 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Infineon
2008-06-14 00:07 . 2008-06-14 00:07 <REP> d-------- C:\Users\All Users\Infineon
2008-06-14 00:07 . 2008-06-14 00:07 <REP> d-------- C:\ProgramData\Infineon
2008-06-14 00:00 . 2008-06-14 00:00 <REP> d-------- C:\Users\LOUIS-~1~HP\AppData
2008-06-14 00:00 . 2008-06-14 00:00 <REP> d-------- C:\Users\LOUIS-~1~HP
2008-06-13 23:59 . 2005-11-08 10:21 45,056 --a------ C:\WINDOWS\FPDRV_Ver.dll
2008-06-13 23:46 . 2008-06-13 23:46 <REP> d-------- C:\Program Files\OpenAL
2008-06-13 23:46 . 2008-06-13 23:46 413,696 --a------ C:\WINDOWS\System32\wrap_oal.dll
2008-06-13 23:46 . 2008-06-13 23:46 110,592 --a------ C:\WINDOWS\System32\OpenAL32.dll
2008-06-13 20:29 . 2008-06-13 20:29 95 --a------ C:\WINDOWS\wininit.ini
2008-06-13 20:09 . 2008-06-13 20:33 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-06-13 20:09 . 2008-06-13 20:33 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-06-13 20:09 . 2008-06-13 20:33 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-12 20:31 . 2008-06-14 08:48 <REP> d-------- C:\Program Files\uTorrent
2008-06-12 19:57 . 2008-06-12 19:57 <REP> d-------- C:\Program Files\CCleaner
2008-06-12 18:29 . 2008-06-13 23:00 <REP> d-------- C:\Users\Louis-Nicolas.HP\dwhelper
2008-06-12 07:34 . 2008-06-14 09:19 <REP> dr------- C:\Users\Louis-Nicolas.HP\T‚l‚chargements
2008-06-11 23:24 . 2008-06-11 23:24 <REP> d-------- C:\Program Files\Apple Software Update
2008-06-11 21:55 . 2008-06-11 22:22 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\LimeWire
2008-06-09 19:01 . 2008-06-09 19:01 0 --a------ C:\WINDOWS\QuickInstall.INI
2008-06-09 18:58 . 2008-06-09 18:58 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Leadertech
2008-06-09 18:56 . 2008-06-09 18:56 <REP> d-------- C:\Users\All Users\HotSync
2008-06-09 18:56 . 2008-06-09 18:56 <REP> d-------- C:\ProgramData\HotSync
2008-06-09 18:56 . 2008-06-09 18:53 53,248 --a------ C:\WINDOWS\PalmDevC.dll
2008-06-09 18:55 . 2008-06-12 10:25 <REP> d-------- C:\Program Files\palmOne
2008-06-09 18:54 . 2008-06-09 18:54 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\HotSync
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Videos
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Searches
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Saved Games
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Pictures
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Links
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Downloads
2008-06-09 18:53 . 2008-06-09 18:53 <REP> dr------- C:\WINDOWS\System32\config\systemprofile\Documents
2008-06-08 22:40 . 2008-06-14 09:18 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\uTorrent
2008-06-08 18:36 . 2008-06-08 18:36 <REP> d-------- C:\WINDOWS\System32\avsplugin
2008-06-08 18:36 . 2008-06-08 18:36 <REP> d-------- C:\Program Files\Smallvideosoft
2008-06-08 18:36 . 2007-03-12 17:49 7,277,568 --a------ C:\WINDOWS\System32\iPodmedia.dll
2008-06-08 18:36 . 2004-05-26 20:37 719,872 --a------ C:\WINDOWS\System32\devil.dll
2008-06-08 18:36 . 2006-10-17 22:29 487,479 --a------ C:\WINDOWS\System32\SkinMagic.dll
2008-06-08 18:36 . 2006-12-31 10:16 313,344 --a------ C:\WINDOWS\System32\avisynth.dll
2008-06-08 18:36 . 2007-02-16 07:10 60,273 --a------ C:\WINDOWS\System32\pthreadGC2.dll
2008-06-08 01:49 . 2008-06-08 01:34 29,480 --a------ C:\WINDOWS\System32\msxml3a.dll
2008-06-08 01:31 . 2008-06-08 01:31 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\InterVideo
2008-06-07 23:00 . 2008-06-08 01:52 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\CyberLink
2008-06-07 22:59 . 2008-06-08 01:53 <REP> d-------- C:\Users\All Users\CyberLink
2008-06-07 22:59 . 2008-06-08 01:53 <REP> d-------- C:\ProgramData\CyberLink
2008-06-07 22:59 . 2008-06-08 01:57 <REP> d-------- C:\Program Files\CyberLink
2008-06-06 19:18 . 2008-06-06 19:21 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Mobile Master
2008-06-04 18:36 . 2008-06-04 18:36 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Apple Computer
2008-06-04 18:36 . 2008-06-04 18:36 <REP> d-------- C:\Program Files\iTunes
2008-06-04 18:36 . 2008-06-12 19:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-04 18:36 . 2008-06-12 18:32 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-04 18:34 . 2008-06-04 18:36 <REP> d-------- C:\Users\All Users\Apple Computer
2008-06-04 18:34 . 2008-06-04 18:36 <REP> d-------- C:\ProgramData\Apple Computer
2008-06-04 18:34 . 2008-06-04 18:35 <REP> d-------- C:\Program Files\QuickTime
2008-06-04 18:32 . 2008-06-04 18:32 <REP> d-------- C:\Users\All Users\Apple
2008-06-04 18:32 . 2008-06-04 18:32 <REP> d-------- C:\ProgramData\Apple
2008-06-04 18:32 . 2008-06-04 18:32 <REP> d-------- C:\Program Files\Common Files\Apple
2008-05-30 17:54 . 2008-06-13 23:53 <REP> d-------- C:\Program Files\Warzone 2100
2008-05-28 22:20 . 2008-03-08 04:08 4,240,384 --a------ C:\WINDOWS\System32\GameUXLegacyGDFs.dll
2008-05-28 22:20 . 2008-03-08 06:21 1,695,744 --a------ C:\WINDOWS\System32\gameux.dll
2008-05-27 20:34 . 2008-05-27 20:34 <REP> d-------- C:\Users\Louis-Nicolas.HP\Bluetooth Software
2008-05-27 19:36 . 2008-05-27 19:36 <REP> d-------- C:\Users\All Users\ESET
2008-05-27 19:36 . 2008-05-27 19:36 <REP> d-------- C:\ProgramData\ESET
2008-05-27 19:36 . 2008-05-27 19:36 <REP> d-------- C:\Program Files\ESET
2008-05-27 19:33 . 2008-05-27 19:33 <REP> d-------- C:\WINDOWS\System32\es-MX
2008-05-27 19:33 . 2008-05-27 19:33 <REP> d-------- C:\WINDOWS\System32\es-AR
2008-05-27 19:33 . 2008-05-27 19:33 <REP> d-------- C:\Program Files\WIDCOMM
2008-05-27 19:33 . 2007-12-12 13:12 233,472 --a------ C:\WINDOWS\System32\BtwRSupport.dll
2008-05-27 19:33 . 2007-12-12 13:12 80,936 --a------ C:\WINDOWS\System32\drivers\btwavdt.sys
2008-05-27 19:33 . 2007-12-12 13:12 80,424 --a------ C:\WINDOWS\System32\drivers\btwaudio.sys
2008-05-27 19:33 . 2007-12-12 13:12 16,168 --a------ C:\WINDOWS\System32\drivers\btwrchid.sys
2008-05-27 15:06 . 2008-05-27 15:06 13,478 --a------ C:\photo.jpg
2008-05-27 15:03 . 2008-06-08 22:34 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\FileZilla
2008-05-27 15:03 . 2008-05-27 15:03 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-05-26 21:14 . 2008-03-31 11:59 2,529,280 --a------ C:\WINDOWS\System32\Mechanical Clock 3D Screensaver.exe
2008-05-26 21:14 . 2008-03-28 18:39 848,896 --a------ C:\WINDOWS\System32\Mechanical_Clock_3D_Screensaver.scr
2008-05-26 19:43 . 2008-05-26 20:08 <REP> d-------- C:\Program Files\Project64 1.6
2008-05-24 12:10 . 2008-05-24 12:10 <REP> d-------- C:\WINDOWS\System32\3Planesoft
2008-05-24 12:10 . 2008-05-24 12:10 <REP> d-------- C:\Program Files\The Lost Watch 3D Screensaver
2008-05-24 12:10 . 2008-05-26 21:14 <REP> d-------- C:\Program Files\3Planesoft Screensaver Manager
2008-05-24 12:08 . 2008-06-12 20:00 <REP> d-------- C:\Program Files\Snowball
2008-05-20 19:09 . 2008-05-20 19:09 56 --ah----- C:\WINDOWS\System32\ezsidmv.dat
2008-05-19 19:02 . 2008-05-19 19:02 <REP> d-------- C:\Users\All Users\BVRP Software
2008-05-19 19:02 . 2008-05-19 22:10 <REP> d-------- C:\Users\All Users\Avanquest Bluetooth SDK
2008-05-19 19:02 . 2008-05-19 19:02 <REP> d-------- C:\ProgramData\BVRP Software
2008-05-19 19:02 . 2008-05-19 22:10 <REP> d-------- C:\ProgramData\Avanquest Bluetooth SDK
2008-05-19 18:48 . 2008-05-19 18:48 <REP> d-------- C:\Users\All Users\Sony Ericsson
2008-05-19 18:48 . 2008-05-19 18:48 <REP> d-------- C:\ProgramData\Sony Ericsson
2008-05-19 18:48 . 2008-05-19 18:48 <REP> d-------- C:\Program Files\Sony Ericsson
2008-05-18 11:47 . 2004-10-20 17:23 21,344 --a------ C:\WINDOWS\System32\drivers\fbxusb32.sys
2008-05-17 10:42 . 2008-05-17 10:42 <REP> d-------- C:\WINDOWS\Sun
2008-05-15 22:52 . 2008-05-15 22:52 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Thunderbird
2008-05-15 22:52 . 2008-05-15 22:52 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Talkback
2008-05-15 22:52 . 2008-05-15 22:52 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-15 22:51 . 2008-05-15 22:51 <REP> d-------- C:\Program Files\Mozilla Thunderbird
2008-05-15 18:34 . 2008-05-15 18:34 <REP> d-------- C:\Program Files\Media Player Classic
2008-05-15 18:32 . 2008-05-15 18:32 <REP> d-------- C:\Users\Louis-Nicolas.HP\AppData\Roaming\Media Player Classic
2008-05-14 20:33 . 2008-05-14 20:33 <REP> d-------- C:\Program Files\PDFCreator
2008-05-14 20:33 . 2005-10-15 12:32 196,608 --a------ C:\WINDOWS\System32\pdfcmnnt.dll
2008-05-14 20:33 . 1998-07-13 01:08 141,312 --a------ C:\WINDOWS\System32\MSCMCFR.DLL
2008-05-14 20:33 . 1998-06-24 00:00 137,000 --a------ C:\WINDOWS\System32\MSMAPI32.OCX
2008-05-14 20:33 . 1998-07-06 00:00 23,552 --a------ C:\WINDOWS\System32\MSMPIDE.DLL
2008-05-14 18:46 . 2008-05-14 18:46 <REP> d-------- C:\WINDOWS\System32\Adobe
2008-05-14 18:30 . 2008-05-14 18:30 <REP> d-------- C:\Users\All Users\Office Genuine Advantage
2008-05-14 18:30 . 2008-05-14 18:30 <REP> d-------- C:\ProgramData\Office Genuine Advantage
2008-05-14 09:43 . 2008-05-14 09:43 <REP> d-------- C:\Users\Louis-Nicolas.HP\All Users
2008-05-14 09:40 . 2008-05-14 09:40 <REP> d-------- C:\Users\All Users\Adobe Systems
2008-05-14 09:40 . 2008-05-14 09:40 <REP> d-------- C:\ProgramData\Adobe Systems
2008-05-14 09:33 . 2008-05-14 09:33 <REP> d-------- C:\Program Files\Common Files\Adobe Systems Shared
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 22:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-06-13 12:42 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\TeraCopy
2008-06-12 17:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-12 07:01 --------- d-----w C:\Program Files\Windows Mail
2008-06-11 19:49 --------- d-----w C:\Program Files\adslTV
2008-06-09 16:54 16,694 ----a-w C:\Windows\system32\drivers\PalmUSBD.sys
2008-06-07 20:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-07 19:16 --------- d-----w C:\ProgramData\Roxio
2008-06-05 19:21 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\Skype
2008-06-05 19:09 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\skypePM
2008-06-04 11:26 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-20 16:36 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-19 20:08 --------- d-----w C:\Program Files\Analog Devices
2008-05-18 14:32 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\Roxio
2008-05-17 19:05 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-14 07:34 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-13 20:25 --------- d-----w C:\ProgramData\Sonic
2008-05-13 17:59 --------- d-----w C:\ProgramData\Skype
2008-05-13 17:59 --------- d-----w C:\Program Files\Skype
2008-05-13 17:59 --------- d-----w C:\Program Files\Common Files\Skype
2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-09 17:21 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\Winamp
2008-05-09 17:02 --------- d-----w C:\Program Files\Winamp
2008-05-09 16:15 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-05-08 18:08 --------- d-----w C:\ProgramData\Messenger Plus!
2008-05-08 15:19 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-05-08 12:39 --------- d-----w C:\Program Files\MSBuild
2008-05-08 12:39 --------- d-----w C:\Program Files\Microsoft Works
2008-05-08 12:33 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-05-08 12:08 174 --sha-w C:\Program Files\desktop.ini
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Journal
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Defender
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Collaboration
2008-05-08 11:53 --------- d-----w C:\Program Files\Windows Calendar
2008-05-08 11:16 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-05-08 11:15 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-05-08 10:28 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-05-08 10:28 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2008-05-08 09:06 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\Todae
2008-05-08 07:12 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-07 22:20 --------- d-----w C:\Program Files\TeraCopy
2008-05-07 22:07 201,728 ----a-w C:\Windows\System32\PolarClock3.scr
2008-05-07 19:45 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-07 18:28 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\SampleView
2008-05-06 19:44 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-05-06 17:23 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-05-06 17:19 --------- d-----w C:\Program Files\Microsoft Small Business
2008-05-06 16:58 --------- d-----w C:\Program Files\Windows Live
2008-05-06 16:57 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-06 16:46 --------- d-----w C:\ProgramData\WLInstaller
2008-05-06 16:43 --------- d-----w C:\ProgramData\eMule
2008-05-06 16:41 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\eMule
2008-05-06 16:41 --------- d-----w C:\Program Files\eMule
2008-05-05 19:53 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\vlc
2008-05-05 19:07 --------- d-----w C:\ProgramData\Symantec
2008-05-05 19:06 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-05-05 19:06 8,014 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-05-05 19:06 109,744 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-05-05 19:06 --------- d-----w C:\Program Files\Symantec
2008-05-05 19:06 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-05 19:04 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-05-05 18:31 988,216 ----a-w C:\Windows\System32\winload.exe
2008-05-05 18:31 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-05-05 18:31 615,992 ----a-w C:\Windows\System32\ci.dll
2008-05-05 18:31 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-05-05 18:31 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-05-05 18:31 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-05-05 18:31 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-05-05 18:31 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-05-05 18:31 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-05-05 18:31 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-05-05 18:30 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-05-05 18:30 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-05-05 18:27 678,408 ----a-w C:\Windows\System32\gpprefcl.dll
2008-05-05 18:22 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-05 17:53 --------- d-----w C:\Program Files\Google
2008-05-05 17:41 --------- d-----w C:\Program Files\Java
2008-05-05 17:35 --------- d-----w C:\ProgramData\LightScribe
2008-05-05 17:29 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\Hewlett-Packard
2008-05-05 17:25 --------- d-----w C:\ProgramData\InstallShield
2008-05-05 17:21 0 --sha-r C:\Windows\system32\drivers\103C_HP_bNB_6710b (GR679ET#ABF)_Y5336AN_0U_QCNU8061925_E434581-053_4A_I30C0_SHP_V71.2E_68DDU F.10_T080111_WV6-0_L40C_M3063_J120_7Intel_86FD_92.00_#070705_N14E41693;80864222_(GR679ET#ABF)_XMOBILE_CN10_Z_2F.10.MRK
2008-05-05 17:21 --------- d-----w C:\Users\Louis-Nicolas.HP\AppData\Roaming\InstallShield
2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-04-29 01:42 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS
2008-04-29 01:42 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\divx.dll
2008-03-28 17:41 7,680 ----a-w C:\Windows\System32\ff_vfw.dll
2008-03-28 15:08 458,752 ----a-w C:\Windows\System32\3Planesoft_Screensaver_Manager.scr
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D39F49BB-7816-4024-BD6D-C4D37A49165B}]
C:\Windows\system32\xxywUNFu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 23:33 1233920]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 23:33 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [2007-01-09 15:52 145184]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 19:31 1033512]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-05-11 13:21 472632]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 16:12 317128]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-05-02 16:17 163840]
"CognizanceTS"="C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 19:12 17920]
"HP Software Update"="c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 02:29 102400]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 17:12 107112]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-11-28 06:34 134808]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-02-21 17:14 1183744]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-11 20:13 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-11 20:13 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-11 20:13 133656]
"IFXSPMGT"="C:\Windows\system32\ifxspmgt.exe" [2008-01-25 17:38 677144]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\Users\Louis-Nicolas.HP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-04 14:13:34 727592]
PDFCreator.lnk - C:\Program Files\PDFCreator\PDFCreator.exe [2008-05-14 20:33:26 2641920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APSHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 04:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1368809013-4150264858-3263198695-1006]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{CFD8B6E7-4F26-42F6-85FB-6F2BFC54609A}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{F38ACC61-2BC0-4D13-A0B8-D93534C2051C}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{9CBEF395-65E4-464D-933A-128846126CEF}"= UDP:C:\Program Files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{2764153E-F0CC-46F4-B533-BD1CBC6318B4}"= TCP:C:\Program Files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{4155C64B-910D-4D35-906C-04A1F9CF1672}"= UDP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{6D24CD59-36D8-45FE-8999-9243EA233BC8}"= TCP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{BACF10E0-2D07-4AB6-927A-178E6587482E}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{A92F063B-6B63-4EA8-B8CE-C851CD60A948}C:\\program files\\adsltv\\adsltv.exe"= UDP:C:\program files\adsltv\adsltv.exe:adsltv
"UDP Query User{75C29964-E191-4D34-9F15-8CD6A8C5CC44}C:\\program files\\adsltv\\adsltv.exe"= TCP:C:\program files\adsltv\adsltv.exe:adsltv
"{B88610D9-B671-41BA-8831-0CAF2ED4B7BF}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{9B588E09-2376-4A93-9789-C51B060A0168}"= UDP:C:\Program Files\Mozilla Thunderbird\thunderbird.exe:Mozilla Thunderbird
"{F4D1C0D7-6D62-439A-B086-10994C7A39C3}"= TCP:C:\Program Files\Mozilla Thunderbird\thunderbird.exe:Mozilla Thunderbird
"TCP Query User{6F4917C3-54F3-4042-B314-5CAEC28EDC3B}C:\\windows\\sminst\\scheduler.exe"= UDP:C:\windows\sminst\scheduler.exe:Scheduler
"UDP Query User{39987474-50E1-4D76-83D8-70CABC34EB21}C:\\windows\\sminst\\scheduler.exe"= TCP:C:\windows\sminst\scheduler.exe:Scheduler
"{12684A7E-5429-48A9-9C48-30AEA3C2AECA}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{4327E10A-8F4E-47CA-877D-FD1C0C32ADC6}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{467A74AD-8C77-429C-AF17-706958B97D3E}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{5C7FF9C6-B89C-4241-AFCB-5B8E2A87A885}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{2F6B0119-37C3-4216-ADD6-A5F51939ED9F}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{16AF401B-2CBA-44B2-8897-E4E7D40D1FF9}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{6876BBDA-9A9A-433C-8363-BC0313646D5E}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{08524DBD-C4B2-47BB-9343-6E7C81648473}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DisabledInterfaces"= {CE6C2780-2E77-4C87-AEF1-BDC78D03CCCF}
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]
R1 PersonalSecureDrive;PersonalSecureDrive;C:\Windows\system32\drivers\psd.sys [2007-07-24 08:21]
R2 AEADIFilters;Andrea ADI Filters Service;C:\Windows\system32\AEADISRV.EXE [2007-02-06 10:44]
R2 ASBroker;Courtier de session de connexion;C:\Windows\System32\svchost.exe [2008-01-18 23:33]
R2 ASChannel;Canal de communication local;C:\Windows\System32\svchost.exe [2008-01-18 23:33]
R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe [2007-01-05 03:00]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 19:36]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-02-26 16:52]
S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-12-12 13:12]
S3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-12-12 13:12]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-12-12 13:12]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 17:23]
S3 ovt530;Hercules Webcam Deluxe;C:\Windows\system32\Drivers\ov530vid.sys [2005-03-15 17:04]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
Cognizance REG_MULTI_SZ ASBroker ASChannel
GPSvcGroup REG_MULTI_SZ GPSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-14 09:54:25
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\audiodg.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\IFXTCS.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\WINDOWS\System32\IfxPsdSv.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe
C:\WINDOWS\SMINST\Scheduler.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Hewlett-Packard\Embedded Security Software\PSDrt.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-14 10:01:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-14 08:00:51
Pre-Run: 24,498,106,368 octets libres
Post-Run: 24,081,633,280 octets libres
396 --- E O F --- 2008-06-11 16:07:00
merci...
si tu regardes en-dessous de mon post... J'AI Firefox...
Merci...