Voila le rapport D:\Documents and Settings\fred.114067890310\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\RelatedSearch\RelatedSearchOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Rencontres\RencontresOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Rencontres\RencontresOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Screensavers\ScreensaversOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Screensavers\ScreensaversOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Toolbar\TBProductsOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\Toolbar\TBProductsOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\ToolbarLogo\ToolbarLogoOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\ToolbarSearch\ToolbarSearchOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml
D:\Documents and Settings\fred.114067890310\Application Data\Starware354\TravelSearch\TravelSearchOptions.xml.backup
D:\Documents and Settings\fred.114067890310\Bureau\Error Cleaner.url
D:\Documents and Settings\fred.114067890310\Bureau\Privacy Protector.url
D:\Documents and Settings\fred.114067890310\Bureau\Spyware&Malware Protection.url
D:\Documents and Settings\fred.114067890310\Favoris\Error Cleaner.url
D:\Documents and Settings\fred.114067890310\Favoris\Privacy Protector.url
D:\Documents and Settings\fred.114067890310\Favoris\Spyware&Malware Protection.url
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-17 to 2008-07-17 ))))))))))))))))))))))))))))))))))))
.
2008-07-17 14:27 . 2008-07-17 12:58 <REP> d-------- C:\SDFix
2008-07-16 20:52 . 2008-07-16 20:52 1,917 --a------ C:\WINDOWS\imsins.BAK
2008-07-16 20:48 . 2008-07-16 20:48 <REP> d-------- C:\Program Files\Trend Micro
2008-07-16 20:30 . 2008-07-16 20:30 <REP> d-------- C:\Program Files\CCleaner
2008-07-16 20:25 . 2008-07-16 20:25 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-07-16 14:36 . 2008-07-16 08:31 155,648 --a------ C:\WINDOWS\agpqlrfm.exe
2008-07-15 18:15 . 2008-07-15 18:15 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-07-15 18:15 . 2008-07-15 18:15 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2008-07-15 18:15 . 2008-07-15 18:15 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2008-07-15 18:10 . 2008-07-15 18:10 <REP> d-------- D:\Documents and Settings\fred.114067890310\Application Data\CyberLink
2008-07-15 16:02 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-07-15 16:02 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\drivers\usbser.sys
2008-07-15 16:02 . 2004-08-03 23:08 25,600 --a------ C:\WINDOWS\system32\dllcache\usbser.sys
2008-07-15 16:02 . 2007-11-02 14:36 18,176 --a------ C:\WINDOWS\system32\drivers\motccgp.sys
2008-07-15 16:02 . 2007-01-22 18:33 7,680 --a------ C:\WINDOWS\system32\drivers\motccgpfl.sys
2008-07-15 16:02 . 2007-11-02 14:51 6,400 --a------ C:\WINDOWS\system32\drivers\motswch.sys
2008-07-15 16:01 . 2008-07-15 16:01 <REP> d-------- C:\Program Files\Common Files
2008-07-15 15:40 . 2008-07-15 15:50 <REP> d-------- C:\Program Files\Avanquest update
2008-07-15 15:37 . 2008-07-15 15:40 <REP> d-------- D:\Documents and Settings\All Users\Application Data\BVRP Software
2008-07-15 15:37 . 2008-07-15 16:03 <REP> d-------- C:\Program Files\Motorola Phone Tools
2008-07-15 15:37 . 2008-07-15 15:37 <REP> d-------- C:\Program Files\Fichiers communs\Motorola Shared
2008-07-15 15:36 . 2008-07-15 15:36 <REP> d-------- D:\Documents and Settings\fred.114067890310\Application Data\InstallShield
2008-06-20 19:41 . 2008-06-20 19:41 247,808 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:44 . 2008-06-20 12:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 15:23 139,229,472 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-17 15:23 1,151,776 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-17 12:53 --------- d-----w D:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-17 12:53 --------- d-----w C:\Program Files\eMule
2008-07-17 12:46 110,300 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-17 12:46 1,863,608 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-15 16:10 --------- d-----w D:\Documents and Settings\All Users\Application Data\CyberLink
2008-07-15 14:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-22 10:57 --------- d-----w C:\Program Files\BoontyGames
2008-06-22 10:36 --------- d-----w D:\Documents and Settings\All Users\Application Data\BOONTY
2008-06-20 20:43 --------- d-----w C:\Program Files\FoxTarot4
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-14 15:38 --------- d-----w D:\Documents and Settings\fred.114067890310\Application Data\LimeWire
2008-06-10 13:52 --------- d-----w D:\Documents and Settings\fred.114067890310\Application Data\TaoUSign
2008-06-01 20:26 --------- d-----w C:\Program Files\Ludi
2008-05-29 17:35 88,774 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-28 14:16 96,966 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-28 14:16 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-05-17 18:28 --------- d-----w C:\Program Files\LimeWire
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,293,824 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-23 20:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:41 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:41 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2006-12-06 19:26 4,096 -c--a-w D:\Documents and Settings\jelena\log.dat
2006-10-26 09:00 459,432 -c--a-w D:\Documents and Settings\jelena\data.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="C:\APPS\SMP\SmpSys.exe" [2005-11-17 10:51 975360]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-24 01:14 68856]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 17:07 196608]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-05-06 10:32 185896]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-08-02 17:35 7110656]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-15 19:58 98304]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 13:16 185896]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 12:45 75304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"D:\\Documents and Settings\\fred.114067890310\\Bureau\\WoW-frFR-Installer-downloader.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 15:58]
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-08-18 14:02]
S3 motccgp;Motorola USB Composite Device Driver;C:\WINDOWS\system32\DRIVERS\motccgp.sys [2007-11-02 14:36]
S3 motccgpfl;MotCcgpFlService;C:\WINDOWS\system32\DRIVERS\motccgpfl.sys [2007-01-22 18:33]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-07-17 15:00:00 C:\WINDOWS\Tasks\Extension de garantie.job"
- C:\APPS\SMP\PBCARNOT.EXE
"2008-07-17 15:00:02 C:\WINDOWS\Tasks\Master CD_DVD Creator.job"
- C:\Apps\SMP\MCDCHECK.EXE
"2008-07-17 14:53:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{3BB35E2E-9AE6-4FDE-A691-9E5BDBD93044} - C:\WINDOWS\qndsfmao.dll
HKLM-Run-EoEngine - (no file)
SSODL-evgratsm-{FE20D465-AD3F-4B3E-B78D-9B9348582583} - C:\WINDOWS\evgratsm.dll
SSODL-kvxqmtre-{3C17080B-CEF1-4BF5-AC3D-F6EC78106D25} - C:\WINDOWS\kvxqmtre.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-17 17:23:23
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
**************************************************************************
.
Temps d'accomplissement: 2008-07-17 17:25:30
ComboFix-quarantined-files.txt 2008-07-17 15:24:26
Pre-Run: 17,494,343,680 octets libres
Post-Run: 17,474,314,240 octets libres
225 --- E O F --- 2008-07-10 11:43:03