ComboFix 08-07-09.5 - RYCHIE 2008-07-10 12:43:19.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.369 [GMT 2:00]
Endroit: C:\Documents and Settings\RYCHIE\Bureau\claire\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMb760cbaf.txt
C:\WINDOWS\system32\aefmnewx.dll
C:\WINDOWS\system32\ajbgdjgk.ini
C:\WINDOWS\system32\alhuipxv.ini
C:\WINDOWS\system32\awtRkLFu.dll
C:\WINDOWS\system32\ayupca.dll
C:\WINDOWS\system32\bbwyeasx.dll
C:\WINDOWS\system32\bhvtfhkp.dll
C:\WINDOWS\system32\bkyylpnr.ini
C:\WINDOWS\system32\bnprqcyw.ini
C:\WINDOWS\system32\bnzxct.dll
C:\WINDOWS\system32\btuytagc.ini
C:\WINDOWS\system32\byoilrdg.ini
C:\WINDOWS\system32\cauhvtxf.ini
C:\WINDOWS\system32\cdzrht.dll
C:\WINDOWS\system32\cpmbuqix.dll
C:\WINDOWS\system32\dcdwhwgq.dll
C:\WINDOWS\system32\dfhnpsku.ini
C:\WINDOWS\system32\dgbblz.dll
C:\WINDOWS\system32\dstptrvy.ini
C:\WINDOWS\system32\dwojbw.dll
C:\WINDOWS\system32\dxphvxgi.ini
C:\WINDOWS\system32\eamxqfoc.dll
C:\WINDOWS\system32\eqjikbiy.ini
C:\WINDOWS\system32\eufixndj.dll
C:\WINDOWS\system32\faenehwx.ini
C:\WINDOWS\system32\fcepdrgs.ini
C:\WINDOWS\system32\ffntwpsf.dll
C:\WINDOWS\system32\fghqccdm.dll
C:\WINDOWS\system32\fgjccetq.dll
C:\WINDOWS\system32\fqivalnn.ini
C:\WINDOWS\system32\fueddkhq.dll
C:\WINDOWS\system32\gcsncfty.dll
C:\WINDOWS\system32\gvvpfiwt.dll
C:\WINDOWS\system32\gyvtmycj.ini
C:\WINDOWS\system32\hgGxUNeb.dll
C:\WINDOWS\system32\hikcqbui.dll
C:\WINDOWS\system32\hniggnbb.dll
C:\WINDOWS\system32\hrnmerwm.dll
C:\WINDOWS\system32\hshtyvne.dll
C:\WINDOWS\system32\htadxrfq.ini
C:\WINDOWS\system32\hvsouada.dll
C:\WINDOWS\system32\igegvfxo.dll
C:\WINDOWS\system32\ikywfn.dll
C:\WINDOWS\system32\imdokg.dll
C:\WINDOWS\system32\iojimpoh.dll
C:\WINDOWS\system32\isqogjrw.ini
C:\WINDOWS\system32\iwwvbx.dll
C:\WINDOWS\system32\jdpdxyvy.dll
C:\WINDOWS\system32\jdudysrs.ini
C:\WINDOWS\system32\jletxm.dll
C:\WINDOWS\system32\joymojbm.ini
C:\WINDOWS\system32\jvjqbluj.ini
C:\WINDOWS\system32\jwkcifqf.ini
C:\WINDOWS\system32\kdfrptiy.dll
C:\WINDOWS\system32\kerkoblt.dll
C:\WINDOWS\system32\knlfqswv.dll
C:\WINDOWS\system32\lcawgdbd.dll
C:\WINDOWS\system32\liwegggf.ini
C:\WINDOWS\system32\ljsfcbum.ini
C:\WINDOWS\system32\lpnnyo.dll
C:\WINDOWS\system32\lqzkol.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mohbayvy.dll
C:\WINDOWS\system32\mpxvixfb.ini
C:\WINDOWS\system32\neccbvik.ini
C:\WINDOWS\system32\nfbmbufj.ini
C:\WINDOWS\system32\nhrpvq.dll
C:\WINDOWS\system32\nmeoqsla.ini
C:\WINDOWS\system32\nnukkkfr.ini
C:\WINDOWS\system32\nrwbfa.dll
C:\WINDOWS\system32\ntasmkws.dll
C:\WINDOWS\system32\ntiyup.dll
C:\WINDOWS\system32\ntwajfmt.dll
C:\WINDOWS\system32\oenkrbos.ini
C:\WINDOWS\system32\ofcdbxvu.ini
C:\WINDOWS\system32\orgtiddw.dll
C:\WINDOWS\system32\panrkued.dll
C:\WINDOWS\system32\pcvcpoqo.ini
C:\WINDOWS\system32\pmnljJBq.dll
C:\WINDOWS\system32\poaxqmfr.dll
C:\WINDOWS\system32\qbiplfbr.ini
C:\WINDOWS\system32\qfxjylim.dll
C:\WINDOWS\system32\qhptngjh.ini
C:\WINDOWS\system32\qnpkcolv.ini
C:\WINDOWS\system32\qqmyqcnw.dll
C:\WINDOWS\system32\qrbdtkas.dll
C:\WINDOWS\system32\qsyqhdns.dll
C:\WINDOWS\system32\rldcyojm.dll
C:\WINDOWS\system32\rllugcxg.dll
C:\WINDOWS\system32\rqofhrxc.ini
C:\WINDOWS\system32\rvhpejva.dll
C:\WINDOWS\system32\sknnichm.dll
C:\WINDOWS\system32\snujvurx.dll
C:\WINDOWS\system32\swcaviuj.dll
C:\WINDOWS\system32\tduiddck.ini
C:\WINDOWS\system32\tikaulcm.ini
C:\WINDOWS\system32\toccsabk.ini
C:\WINDOWS\system32\tttuuutw.ini
C:\WINDOWS\system32\tylruy.dll
C:\WINDOWS\system32\ukqvejkk.dll
C:\WINDOWS\system32\uqrzdo.dll
C:\WINDOWS\system32\vkqgwmjr.dll
C:\WINDOWS\system32\vufqhoka.ini
C:\WINDOWS\system32\vuqmopsn.dll
C:\WINDOWS\system32\vzzapt.dll
C:\WINDOWS\system32\wfbwnqqu.ini
C:\WINDOWS\system32\whddmowa.dll
C:\WINDOWS\system32\wienum.dll
C:\WINDOWS\system32\WinSpooler.exe
C:\WINDOWS\system32\wqhtlucj.ini
C:\WINDOWS\system32\wqkwjakv.dll
C:\WINDOWS\system32\xexvetss.dll
C:\WINDOWS\system32\xhjuihpg.ini
C:\WINDOWS\system32\xijiypuv.dll
C:\WINDOWS\system32\xrtukt.dll
C:\WINDOWS\system32\xvwtuovf.dll
C:\WINDOWS\system32\xwudasgu.dll
C:\WINDOWS\system32\yacydfeg.ini
C:\WINDOWS\system32\yiupiqte.ini
C:\WINDOWS\system32\yqokekvx.dll
C:\WINDOWS\system32\YyIlkRqr.ini
C:\WINDOWS\system32\YyIlkRqr.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-10 to 2008-07-10 ))))))))))))))))))))))))))))))))))))
.
2008-07-10 12:30 . 2008-07-10 12:50 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-10 12:30 . 2008-07-10 12:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-09 17:26 . 2008-07-09 17:26 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-09 17:26 . 2008-07-09 17:26 <REP> d-------- C:\Documents and Settings\RYCHIE\Application Data\Malwarebytes
2008-07-09 17:26 . 2008-07-09 17:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-09 17:26 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-09 17:26 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-09 17:00 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-09 17:00 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-09 16:58 . 2008-07-09 17:02 <REP> d-------- C:\Toolbar SD
2008-07-09 16:22 . 2008-07-09 16:22 149 --a------ C:\WINDOWS\wininit.ini
2008-07-09 14:03 . 2008-06-21 04:54 269,736 -ra------ C:\WINDOWS\system32\drivers\SbFw.sys
2008-07-09 14:03 . 2008-06-21 04:54 65,576 --a------ C:\WINDOWS\system32\drivers\SbFwIm.sys
2008-07-09 14:02 . 2008-07-09 14:02 <REP> d-------- C:\Program Files\Sunbelt Software
2008-07-09 14:00 . 2008-07-09 14:00 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-09 14:00 . 2008-07-09 16:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-09 13:19 . 2008-07-09 13:19 <REP> d-------- C:\Program Files\Avira
2008-07-09 13:19 . 2008-07-09 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-09 10:36 . 2008-07-09 10:45 <REP> d-------- C:\fixwareout
2008-07-09 10:22 . 2008-07-09 10:22 <REP> d-------- C:\Program Files\Trend Micro
2008-07-01 19:23 . 2008-07-01 19:23 1,713,713 --ahs---- C:\WINDOWS\system32\pwjwqucf.tmp
2008-07-01 19:23 . 2008-07-01 19:23 294 --ahs---- C:\WINDOWS\system32\pwjwqucf.ini
2008-06-30 19:11 . 2008-06-30 19:11 1,733,619 --ahs---- C:\WINDOWS\system32\joymojbm.tmp
2008-06-28 10:18 . 2008-06-28 10:17 294 --ahs---- C:\WINDOWS\system32\jkfoolas.ini
2008-06-28 10:17 . 2008-06-28 10:17 1,733,640 --ahs---- C:\WINDOWS\system32\jkfoolas.tmp
2008-06-26 19:14 . 2008-06-26 19:14 1,706,852 ---hs---- C:\WINDOWS\system32\dxphvxgi.tmp
2008-06-24 20:56 . 2008-06-25 20:33 1,126 ---hs---- C:\WINDOWS\system32\pomenrob.ini
2008-06-21 04:54 . 2008-06-21 04:54 66,600 -ra------ C:\WINDOWS\system32\drivers\sbhips.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 14:24 --------- d-----w C:\Program Files\Safari
2008-07-09 12:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-05-18 07:42 --------- d-----w C:\Program Files\Apple Software Update
2008-05-17 17:29 6,712 ----a-w C:\Documents and Settings\RYCHIE\Application Data\wklnhst.dat
2008-05-17 09:14 --------- d-----w C:\Program Files\iTunes
2008-05-17 09:14 --------- d-----w C:\Program Files\iPod
2008-05-17 09:12 --------- d-----w C:\Program Files\QuickTime
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-15 18:09 81,920 ----a-w C:\Documents and Settings\RYCHIE\Application Data\ezpinst.exe
2007-12-15 18:09 47,360 ----a-w C:\Documents and Settings\RYCHIE\Application Data\pcouffin.sys
2006-07-11 20:04 1,155,076 ----a-w C:\Program Files\^^clip3_1.mpg
2006-07-11 20:04 1,155,076 ----a-w C:\Program Files\^^clip2_1.mpg
2006-07-11 20:04 1,155,076 ----a-w C:\Program Files\^^clip1_1.mpg
2006-06-15 18:00 2,193,412 ----a-w C:\Program Files\((dream2_1.mpg
2006-06-15 18:00 2,134,020 ----a-w C:\Program Files\((dream1_1.mpg
2006-06-15 17:58 1,984,516 ----a-w C:\Program Files\gonzo1.mpg
2006-06-15 17:58 1,959,940 ----a-w C:\Program Files\gonzo2.mpg
2006-06-15 17:48 1,700,047 ----a-w C:\Program Files\$$003.mpg
2006-06-15 17:48 1,699,852 ----a-w C:\Program Files\$$002_3.mpg
2006-06-15 17:48 1,698,143 ----a-w C:\Program Files\$$001.mpg
2006-05-21 09:20 1,030,213 ----a-w C:\Program Files\3.mpg
2006-05-16 21:46 2,234,372 ----a-w C:\Program Files\magic1.mpg
2006-05-16 21:46 2,146,308 ----a-w C:\Program Files\magic2.mpg
2006-05-13 12:36 2,379,780 ----a-w C:\Program Files\dream2.mpg
2006-05-13 12:36 2,373,636 ----a-w C:\Program Files\dream1.mpg
2006-05-07 19:04 700,420 ----a-w C:\Program Files\2.mpg
2006-05-06 09:27 736,206 ----a-w C:\Program Files\4_9.wmv
2006-05-06 09:27 705,882 ----a-w C:\Program Files\3_10.wmv
2006-05-06 09:26 731,874 ----a-w C:\Program Files\2_11.wmv
2006-05-06 09:26 702,994 ----a-w C:\Program Files\1_11.wmv
2006-05-06 08:59 1,395,843 ----a-w C:\Program Files\3_12.mpg
2006-05-06 08:59 1,395,759 ----a-w C:\Program Files\4_2.mpg
2006-05-06 08:57 1,394,424 ----a-w C:\Program Files\1_16.mpg
2006-05-06 08:57 1,393,645 ----a-w C:\Program Files\2_17.mpg
2006-05-06 08:55 933,892 ----a-w C:\Program Files\3_11.mpg
2006-05-06 08:55 860,164 ----a-w C:\Program Files\2_16.mpg
2006-05-06 08:55 860,164 ----a-w C:\Program Files\1_15.mpg
2006-04-30 12:43 782,340 ----a-w C:\Program Files\2_15.mpg
2006-04-29 08:23 1,687,845 ----a-w C:\Program Files\[u]0/u003.mpg
2006-04-24 19:14 1,437,700 ----a-w C:\Program Files\2_14.mpg
2006-04-24 19:14 1,368,068 ----a-w C:\Program Files\3_10.mpg
2006-04-24 19:08 1,290,894 ----a-w C:\Program Files\1_14.mpg
2006-04-24 19:03 735,236 ----a-w C:\Program Files\1_13.mpg
2006-04-24 19:03 700,420 ----a-w C:\Program Files\2_13.mpg
2006-04-19 05:42 1,395,843 ----a-w C:\Program Files\3_9.mpg
2006-04-19 05:42 1,395,759 ----a-w C:\Program Files\4_1.mpg
2006-04-19 05:41 1,394,424 ----a-w C:\Program Files\1_12.mpg
2006-04-19 05:41 1,393,645 ----a-w C:\Program Files\2_12.mpg
2006-04-15 09:07 1,291,124 ----a-w C:\Program Files\3_8.mpg
2006-04-15 09:07 1,284,546 ----a-w C:\Program Files\2_11.mpg
2006-04-15 09:07 1,279,776 ----a-w C:\Program Files\1_11.mpg
2006-04-15 08:54 1,599,492 ----a-w C:\Program Files\2_10.mpg
2006-04-15 08:54 1,597,444 ----a-w C:\Program Files\1_10.mpg
2006-04-12 18:24 2,256,900 ----a-w C:\Program Files\[u]0/u3_9.mpg
2006-04-12 18:24 2,129,924 ----a-w C:\Program Files\[u]0/u1_10.mpg
2006-04-12 18:24 2,109,444 ----a-w C:\Program Files\[u]0/u2_10.mpg
2006-04-11 21:07 521,350 ----a-w C:\Program Files\2_10.wmv
2006-04-11 21:07 493,920 ----a-w C:\Program Files\3_9.wmv
2006-04-11 21:07 492,470 ----a-w C:\Program Files\1_10.wmv
2006-04-11 21:07 460,702 ----a-w C:\Program Files\4_8.wmv
2006-04-11 21:05 1,269,637 ----a-w C:\Program Files\3_7.mpg
2006-04-11 18:46 1,260,693 ----a-w C:\Program Files\1_9.mpg
2006-04-11 18:46 1,252,854 ----a-w C:\Program Files\2_9.mpg
2006-04-11 18:12 1,751,044 ----a-w C:\Program Files\2_8.mpg
2006-04-11 18:12 1,751,044 ----a-w C:\Program Files\1_8.mpg
2006-04-11 18:03 1,343,492 ----a-w C:\Program Files\[u]0/u2_9.mpg
2006-04-11 18:03 1,232,900 ----a-w C:\Program Files\[u]0/u3_8.mpg
2006-04-11 17:59 1,220,612 ----a-w C:\Program Files\[u]0/u2_8.mpg
2006-04-09 12:10 1,629,124 ----a-w C:\Program Files\[u]0/u001_2.mpg
2006-04-09 12:10 1,561,728 ----a-w C:\Program Files\[u]0/u002_2.mpg
2006-04-09 11:58 804,868 ----a-w C:\Program Files\2_7.mpg
2006-04-09 11:58 802,820 ----a-w C:\Program Files\1_7.mpg
2006-04-08 12:23 1,255,428 ----a-w C:\Program Files\[u]0/u3_6.mpg
2006-04-08 12:15 983,075 ----a-w C:\Program Files\4_7.wmv
2006-04-08 12:15 983,075 ----a-w C:\Program Files\3_8.wmv
2006-04-08 12:15 977,275 ----a-w C:\Program Files\1_9.wmv
2006-04-08 12:15 1,029,475 ----a-w C:\Program Files\2_9.wmv
2006-04-08 12:14 2,034,885 ----a-w C:\Program Files\1_8.wmv
2006-04-08 12:14 1,986,885 ----a-w C:\Program Files\2_8.wmv
2006-04-08 12:14 1,978,885 ----a-w C:\Program Files\4_6.wmv
2006-04-08 12:14 1,930,885 ----a-w C:\Program Files\3_7.wmv
2006-04-06 18:41 1,583,108 ----a-w C:\Program Files\[u]0/u3_5.mpg
2006-04-06 18:41 1,583,108 ----a-w C:\Program Files\[u]0/u2_6.mpg
2006-04-06 18:41 1,583,108 ----a-w C:\Program Files\[u]0/u1_6.mpg
2006-04-06 18:39 1,710,564 ----a-w C:\Program Files\3_6.mpg
2006-04-06 18:38 1,637,533 ----a-w C:\Program Files\2_6.mpg
2006-04-06 18:38 1,637,407 ----a-w C:\Program Files\1_6.mpg
2006-04-06 18:14 2,236,420 ----a-w C:\Program Files\[u]0/u3_4.mpg
2006-04-06 18:14 2,207,748 ----a-w C:\Program Files\[u]0/u4_2.mpg
2006-04-06 18:11 2,166,788 ----a-w C:\Program Files\3_5.mpg
2006-04-06 18:10 2,222,084 ----a-w C:\Program Files\2_5.mpg
2006-04-06 18:10 2,166,788 ----a-w C:\Program Files\1_5.mpg
2006-04-04 18:34 1,220,612 ----a-w C:\Program Files\[u]0/u3_3.mpg
2006-04-04 18:34 1,157,124 ----a-w C:\Program Files\[u]0/u2_4.mpg
2006-04-04 18:33 1,042,436 ----a-w C:\Program Files\[u]0/u1_4.mpg
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 13:55 5674352]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 18:49 4739072]
"EPSON Stylus DX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 08:01 180736]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [2007-08-03 13:51 202024]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 22:10 344064]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [2006-10-14 09:55 3335944]
"SpeedOptimizer"="C:\PROGRA~1\SPEEDO~1\SPO.EXE" [2003-09-29 16:53 607232]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 10:25 1828136]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 12:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=pxxkiixs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
R0 xmasbus;xmasbus;C:\WINDOWS\system32\DRIVERS\xmasbus.sys [2003-12-21 18:24]
R0 xmasscsi;xmasscsi;C:\WINDOWS\system32\Drivers\xmasscsi.sys [2003-12-20 21:03]
R1 SbFw;SbFw;C:\WINDOWS\system32\drivers\SbFw.sys [2008-06-21 04:54]
R1 sbhips;Sunbelt HIPS Driver;C:\WINDOWS\system32\drivers\sbhips.sys [2008-06-21 04:54]
R2 SbPF.Launcher;SbPF.Launcher;C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [2008-07-01 10:51]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [2008-07-01 10:51]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\sbfwim.sys [2008-06-21 04:54]
S3 PRISM_USB;Prism Mini USB Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\PRISMUSB.sys [2002-02-24 22:39]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-09 12:38:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{0BE5AF5D-776D-4E4D-84FC-E90658C580A1} - C:\WINDOWS\system32\rqRklIyY.dll
BHO-{487C9905-26A8-42C8-8033-C58AD3D2AEC3} - (no file)
BHO-{eb905a0b-e591-4920-8d38-6f02f795941d} - C:\WINDOWS\system32\xqqctw.dll
HKLM-Run-PRISMSTA.EXE - PRISMSTA.EXE
Notify-awtRkLFu - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 12:50:54
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-10 12:57:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-10 10:56:03
Pre-Run: 5,848,817,664 octets libres
Post-Run: 5,878,308,864 octets libres
361 --- E O F --- 2008-07-10 10:25:56