Voilà green day
ComboFix 08-07-08.7 - Clo 2008-07-09 14:58:02.1 - NTFSx86 MINIMAL
Endroit: C:\Documents and Settings\Clo\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-09 to 2008-07-09 ))))))))))))))))))))))))))))))))))))
.
2008-07-09 14:26 . 2008-07-09 14:26 <REP> d-------- C:\Program Files\Trend Micro
2008-07-09 11:27 . 2008-07-09 11:28 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-09 11:27 . 2008-07-09 12:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-09 10:06 . 2008-07-09 10:06 <REP> d-------- C:\Program Files\Lavasoft
2008-07-09 10:04 . 2008-07-09 10:04 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-06-30 19:39 . 2008-06-30 19:39 <REP> d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2008-06-30 19:37 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-06-30 19:37 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-06-30 19:35 . 2008-06-30 19:35 <REP> d-------- C:\Program Files\HP
2008-06-30 19:33 . 2008-06-30 19:41 103,535 --a------ C:\WINDOWS\hpoins04.dat
2008-06-30 19:33 . 2004-06-22 11:16 17,176 --------- C:\WINDOWS\hpomdl04.dat
2008-06-30 19:32 . 2008-06-30 19:32 <REP> d-------- C:\temp\HP_WebRelease
2008-06-30 19:32 . 2008-06-30 19:32 <REP> d-------- C:\temp
2008-06-30 19:00 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-06-30 19:00 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-06-30 18:57 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-30 18:57 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-29 13:37 . 2008-07-09 12:55 <REP> d-------- C:\Program Files\WinClamAVShield
2008-06-11 08:37 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:37 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-09 12:54 63,212 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-09 12:54 5,124,128 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-09 10:57 --------- d-----w C:\Documents and Settings\Clo\Application Data\OpenOffice.org2
2008-07-09 09:01 --------- d-----w C:\Program Files\Spyware Terminator
2008-07-09 09:01 --------- d-----w C:\Documents and Settings\Clo\Application Data\Spyware Terminator
2008-07-09 08:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-09 05:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-07-07 19:07 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-06-30 04:23 --------- d-----w C:\Program Files\LogMeIn
2008-05-28 19:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-28 19:39 --------- d-----w C:\Program Files\Synaptics
2008-05-28 19:27 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-05-28 19:27 --------- d-----w C:\Program Files\AvRack
2008-05-28 19:17 --------- d-----w C:\Program Files\ATI Technologies
2008-05-28 19:06 --------- d-----w C:\Program Files\Intel
2008-05-28 19:05 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-05-28 18:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\LogMeIn
2008-05-24 15:05 --------- d-----w C:\Program Files\Picasa2
2008-05-24 15:05 --------- d-----w C:\Program Files\Google
2008-05-23 07:30 --------- d-----w C:\Program Files\ExtraFilm PhotoAssistant
2008-05-19 13:24 83,288 ----a-w C:\WINDOWS\system32\LMIRfsClientNP.dll
2008-05-19 13:23 87,352 ----a-w C:\WINDOWS\system32\LMIinit.dll
2008-05-19 13:23 24,608 ----a-w C:\WINDOWS\system32\LMIport.dll
2008-05-19 13:23 23,736 ----a-w C:\WINDOWS\system32\lmimirr.dll
2008-05-19 13:23 10,040 ----a-w C:\WINDOWS\system32\lmimirr2.dll
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-09 16:50 68 ----a-w C:\scandata.dat
2008-05-09 16:48 --------- d-----w C:\Documents and Settings\Clo\Application Data\MCB
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-07 22:12 1817600]
"ExtraFilmHemmaAgent"="C:\Program Files\ExtraFilm PhotoAssistant\Agent.exe" [2007-11-05 17:59 323584]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 15:31 63048]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-22 21:10 335872]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-01-09 08:09 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-01-09 08:09 491520]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 11:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"SoundMan"="SOUNDMAN.EXE" [2003-12-19 11:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:54 15360]
C:\Documents and Settings\maman\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 16:41:28 393216]
C:\Documents and Settings\Clo\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 16:41:28 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-05-19 15:23 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
S1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-05-07 22:12]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2008-02-28 15:31]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-09 15:00:03
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-09 15:01:38
ComboFix-quarantined-files.txt 2008-07-09 13:01:33
Pre-Run: 19,438,686,208 octets libres
Post-Run: 19,575,078,912 octets libres
116 --- E O F --- 2008-06-20 18:37:32