Voilà le rapport :
ComboFix 08-07-04.3 - SANDRINE 2008-07-05 12:15:53.1 - NTFSx86
Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.1137 [GMT 2:00]
Endroit: C:\Users\SANDRINE\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-05 to 2008-07-05 ))))))))))))))))))))))))))))))))))))
.
2008-07-05 11:26 . 2008-07-05 11:31 <REP> d-------- C:\MSNCleaner
2008-07-03 08:27 . 2008-07-05 11:37 114,543,420 --a------ C:\Windows\MEMORY.DMP
2008-06-30 19:13 . 2008-06-30 19:13 <REP> d-------- C:\Users\SANDRINE\AppData\Roaming\vlc
2008-06-30 19:12 . 2008-06-30 19:12 <REP> d-------- C:\Program Files\VideoLAN
2008-06-29 19:56 . 2008-07-03 12:56 <REP> d-------- C:\Users\SANDRINE\amsn
2008-06-29 19:54 . 2008-06-29 19:55 <REP> d-------- C:\Program Files\aMSN
2008-06-29 18:56 . 2008-06-29 19:07 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-06-29 18:56 . 2008-06-29 18:56 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-28 14:48 . 2008-06-28 14:48 <REP> d-------- C:\Users\SANDRINE\AppData\Roaming\Malwarebytes
2008-06-28 14:48 . 2008-06-28 14:48 <REP> d-------- C:\ProgramData\Malwarebytes
2008-06-28 14:48 . 2008-06-28 14:48 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-28 14:48 . 2008-06-19 17:48 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-06-28 14:48 . 2008-06-19 17:47 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-06-27 22:07 . 2008-06-27 22:07 <REP> d-------- C:\Program Files\Trend Micro
2008-06-27 20:06 . 2008-04-13 22:25 <REP> d-------- C:\MSNFix
2008-06-27 19:57 . 2008-06-27 19:57 <REP> d-------- C:\Program Files\AxBx
2008-06-27 18:27 . 2008-06-27 18:36 96,966 --a------ C:\Windows\System32\drivers\klin.dat
2008-06-27 18:27 . 2008-06-27 18:36 88,774 --a------ C:\Windows\System32\drivers\klick.dat
2008-06-27 18:26 . 2008-07-05 11:38 <REP> d-------- C:\ProgramData\Kaspersky Lab
2008-06-27 18:26 . 2008-06-27 18:26 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-06-27 18:26 . 2008-07-05 12:02 3,186,208 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-06-27 18:26 . 2008-07-04 08:19 434,208 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
2008-06-27 18:26 . 2008-07-05 11:55 25,972 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-06-27 18:26 . 2008-07-05 12:19 2,564 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
2008-06-27 18:25 . 2008-06-27 18:25 <REP> d-------- C:\ProgramData\Kaspersky Lab Setup Files
2008-06-18 10:26 . 2008-06-18 10:26 <REP> d--h----- C:\ProgramData\CanonBJ
2008-06-11 17:56 . 2008-06-11 17:56 <REP> d-------- C:\Program Files\Common Files\PC SOFT
2008-06-11 17:56 . 2008-06-11 18:03 <REP> d-------- C:\Program Files\Ceres
2008-06-11 17:38 . 2008-06-21 18:47 <REP> d-------- C:\Users\SANDRINE\AppData\Roaming\FileZilla
2008-06-11 17:37 . 2008-06-11 17:37 <REP> d-------- C:\Program Files\FileZilla FTP Client
2008-06-11 14:01 . 2008-04-26 10:08 1,314,816 --a------ C:\Windows\System32\quartz.dll
2008-06-11 14:01 . 2008-05-10 03:33 113,664 --a------ C:\Windows\System32\drivers\rmcast.sys
2008-06-11 14:00 . 2008-04-25 04:12 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-06-11 14:00 . 2008-04-25 06:35 826,880 --a------ C:\Windows\System32\wininet.dll
2008-06-11 11:10 . 2006-08-10 02:02 75,264 --a------ C:\Windows\System32\E_FLBBEE.DLL
2008-06-11 11:10 . 2006-04-19 02:00 62,976 --a------ C:\Windows\System32\E_FD4BBEE.DLL
2008-06-11 11:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
2008-06-11 11:09 . 2008-06-11 11:13 <REP> d-------- C:\ProgramData\EPSON
2008-06-09 20:44 . 2008-06-09 20:44 <REP> d-------- C:\ProgramData\WindowsSearch
2008-06-09 10:13 . 2008-06-09 10:13 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2008-06-06 10:24 . 2008-07-01 17:50 <REP> d-------- C:\Users\SANDRINE\AppData\Roaming\uTorrent
2008-06-06 10:24 . 2008-06-06 10:24 <REP> d-------- C:\Program Files\uTorrent
2008-06-05 08:59 . 2008-06-05 08:59 <REP> d-------- C:\Program Files\SigmaTel
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Music
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Links
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-06-05 08:53 . 2008-06-05 08:53 <REP> dr------- C:\Windows\System32\config\systemprofile\Documents
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-27 16:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-27 16:05 --------- d-----w C:\ProgramData\Symantec
2008-06-11 09:09 --------- d-----w C:\Program Files\EPSON
2008-06-06 10:07 --------- d-----w C:\Program Files\DivX
2008-06-05 06:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-05 06:58 --------- d-----w C:\Program Files\Sony
2008-05-30 23:22 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\Windows\System32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-05-29 13:02 --------- d-----w C:\Program Files\Ressources Windows Mobile
2008-05-28 07:49 --------- d-----w C:\Program Files\Windows Live
2008-05-28 07:47 --------- d-----w C:\ProgramData\WLInstaller
2008-05-28 07:34 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2008-05-22 22:22 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-05-22 22:22 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-05-22 22:20 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-05-22 22:19 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-05-22 22:19 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-05-22 22:19 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-05-21 07:46 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-05-20 09:40 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-25 16:22 206,088 ----a-w C:\Windows\System32\klogon.dll
2008-04-11 19:28 174 --sha-w C:\Program Files\desktop.ini
2008-04-11 14:15 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-04-11 14:14 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-04-11 13:41 47,560 ----a-w C:\Windows\System32\SPReview.exe
2008-04-11 13:41 152,576 ----a-w C:\Windows\System32\SPWizUI.dll
2007-04-23 13:39 92,064 ----a-w C:\Users\SANDRINE\mqdmmdm.sys
2007-04-23 13:39 9,232 ----a-w C:\Users\SANDRINE\mqdmmdfl.sys
2007-04-23 13:39 79,328 ----a-w C:\Users\SANDRINE\mqdmserd.sys
2007-04-23 13:39 66,656 ----a-w C:\Users\SANDRINE\mqdmbus.sys
2007-04-23 13:39 6,208 ----a-w C:\Users\SANDRINE\mqdmcmnt.sys
2007-04-23 13:39 5,936 ----a-w C:\Users\SANDRINE\mqdmwhnt.sys
2007-04-23 13:39 4,048 ----a-w C:\Users\SANDRINE\mqdmcr.sys
2007-04-23 13:39 25,600 ----a-w C:\Users\SANDRINE\usbsermptxp.sys
2007-04-23 13:39 22,768 ----a-w C:\Users\SANDRINE\usbsermpt.sys
2008-01-31 07:21 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-31 07:21 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-31 07:21 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
2008-04-25 18:22 62728 --a------ C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX4000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE" [2006-09-21 04:01 139264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2006-09-11 09:23 118784]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-22 11:32 223232]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-12-14 17:33 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-12-14 17:32 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-12-14 17:33 133656]
"CardDetector"="C:\Program Files\CardDetector\ICON225\CardDetector.exe" [2007-10-18 11:58 241664]
"BEWINTERNET-FR-DMESessionManager"="C:\Program Files\OrangeBS\BEWInternet\SessionManager\SessionManager.exe" [2007-10-30 18:54 102400]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-11-25 09:29:44 2134016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-11-24 11:36 73728 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"<NO NAME>"=
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{66D20D0E-EF06-4CDF-9168-DBB969AB67C8}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{C8A6E6B1-D4B7-4B99-A394-0817774D35FF}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{69B8FD12-7775-4B17-B5B3-A0EC01DF7BE8}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{58F2EA48-45A7-4993-AEDC-FD86871B89C4}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{50CCBBD9-DC4A-4472-AF0F-B9522B8CAFB8}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{E8E57D23-82D0-41A3-83F1-680D22290BE3}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 2009\\french\\setup.exe"= UDP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009
"UDP Query User{AEF7D47E-5797-410C-960D-4B12E43293BC}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 2009\\french\\setup.exe"= TCP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009
"TCP Query User{832B59B2-9F28-4ED7-BA2F-C02D4D085CC1}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{FD928F85-299C-4F4C-8481-80B2327AF8C2}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{60B2BC9F-331E-4710-8AD6-975EA4097F29}C:\\program files\\amsn\\bin\\wish.exe"= UDP:C:\program files\amsn\bin\wish.exe:Wish Application
"UDP Query User{363376A6-6A41-423A-8258-55122EA86A5C}C:\\program files\\amsn\\bin\\wish.exe"= TCP:C:\program files\amsn\bin\wish.exe:Wish Application
"TCP Query User{BC92B14E-1153-4829-BE38-6AF0729E9BDA}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{26302E53-5E73-46A1-A453-39FDD5A9862D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\OrangeBS\\BEWInternet\\Connectivity\\ConnectivityManager.exe"= C:\Program Files\OrangeBS\BEWInternet\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R0 shpf;Sony HDD Protection Filter Driver;C:\Windows\system32\DRIVERS\shpf.sys [2006-12-01 10:20]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sVAIO_VEDB []
R2 RapiMgr;Windows Mobile-based device connectivity;C:\Windows\system32\svchost.exe [2008-01-18 23:33]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 WcesComm;Windows Mobile-2003-based device connectivity;C:\Windows\system32\svchost.exe [2008-01-18 23:33]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-11-30 14:29]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2006-11-09 03:09]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2006-11-09 03:09]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\Windows\system32\DRIVERS\SonyImgF.sys [2006-09-06 11:44]
R3 SPI;Sony Programmable I/O Control Device;C:\Windows\system32\DRIVERS\SonyPI.sys [2006-10-05 10:19]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2006-11-06 15:56]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-15 02:12]
S3 GT72NDISIPXP;GT 72 IP NDIS;C:\Windows\system32\DRIVERS\Gt51Ip.sys [2007-07-09 17:17]
S3 GT72UBUS;GT 72 U BUS;C:\Windows\system32\DRIVERS\gt72ubus.sys [2007-06-26 16:38]
S3 GTPTSER;GT PT SER;C:\Windows\system32\DRIVERS\gtptser.sys [2007-03-30 16:38]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys [2007-10-30 18:31]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2007-10-30 18:31]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 17:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" []
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-01-16 15:05]
S3 WSDPrintDevice;Prise en charge de l’impression WSD via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys [2008-01-18 22:15]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
GPSvcGroup REG_MULTI_SZ GPSvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d726504f-0d4a-11dd-89fe-0016fef61d98}]
\shell\AutoRun\command - G:\AutoRunCardDetector.exe
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-07-05 09:48:37 C:\Windows\Tasks\User_Feed_Synchronization-{BB6E1DFE-5C8B-4CFF-A380-1C04D549CFBB}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 12:19:40
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-05 12:22:01
ComboFix-quarantined-files.txt 2008-07-05 10:20:58
Pre-Run: 39,977,435,136 octets libres
Post-Run: 40,438,403,072 octets libres
228 --- E O F --- 2008-07-04 06:19:00