ComboFix 08-07-25.6 - jays 2008-07-26 14:25:21.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.358 [GMT 2:00]
Endroit: C:\Documents and Settings\jays\Bureau\telechargement\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\windows\BM13d3e0ea.txt
C:\windows\msnimport.exe
C:\windows\pskt.ini
C:\windows\system32\ccskapmy.dll
C:\windows\system32\jcrmjuni.ini
C:\windows\system32\mcrh.tmp
C:\windows\system32\nscqjgte.dll
C:\windows\system32\qddtjxth.ini
C:\WINDOWS\system32\qtmalxcx.ini
C:\windows\system32\sjnmez.dll
C:\windows\system32\twsgyuvy.dll
C:\windows\system32\vyaIRXbc.ini
C:\WINDOWS\system32\vyaIRXbc.ini2
C:\windows\system32\xcxlamtq.dll
C:\WINDOWS\system32\ympakscc.ini
C:\WINDOWS\system32\ympakscc.ini2
C:\WINDOWS\system32\ympakscc.tmp
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-26 to 2008-07-26 ))))))))))))))))))))))))))))))))))))
.
2008-07-26 14:12 . 2008-07-26 14:12 <REP> d-------- C:\Program Files\Trend Micro
2008-07-26 11:09 . 2008-07-26 11:09 <REP> d-------- C:\Program Files\Picasa2
2008-07-25 12:23 . 2008-06-20 13:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-07-25 12:23 . 2008-06-20 19:47 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-07-25 12:23 . 2008-06-20 13:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-07-25 12:23 . 2008-06-20 19:47 147,968 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-07-25 12:23 . 2008-06-20 13:40 138,496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-07-22 12:01 . 2008-03-03 14:25 5,702 --ah----- C:\WINDOWS\nod32restoretemdono.reg
2008-07-22 12:01 . 2008-03-03 18:21 568 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-07-22 12:00 . 2008-07-22 12:00 <REP> d-------- C:\Documents and Settings\jays\Application Data\ESET
2008-07-22 11:58 . 2008-07-22 11:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-07-22 11:16 . 2008-07-22 11:16 <REP> d-------- C:\_OTMoveIt
2008-07-22 10:28 . 2008-07-22 10:28 <REP> d-------- C:\VundoFix Backups
2008-07-20 12:21 . 2008-07-21 15:59 268 --a------ C:\WINDOWS\wininit.ini
2008-07-19 14:35 . 2006-04-11 10:32 51 --a------ C:\delnis.bat
2008-07-19 14:34 . 2008-07-19 14:34 <REP> d-------- C:\Program Files\Asus
2008-07-19 14:34 . 2006-01-10 10:50 24,576 -ra------ C:\WINDOWS\system32\AsIO.dll
2008-07-19 14:34 . 2005-12-22 04:22 5,685 -ra------ C:\WINDOWS\system32\drivers\AsIO.sys
2008-07-19 14:34 . 2004-09-07 11:41 5,120 --a------ C:\WINDOWS\system32\drivers\AsInsHelp64.sys
2008-07-19 14:34 . 2004-03-10 14:31 3,328 --a------ C:\WINDOWS\system32\drivers\AsInsHelp32.sys
2008-07-19 14:32 . 2001-09-11 15:20 1,285,632 --------- C:\WINDOWS\system32\SMMedia.dll
2008-07-19 14:32 . 2001-09-19 07:47 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll
2008-07-19 14:32 . 2005-08-11 07:49 393,088 -ra------ C:\WINDOWS\system32\drivers\senfilt.sys
2008-07-19 14:32 . 2005-10-05 11:21 141,312 -ra------ C:\WINDOWS\system32\drivers\ADIHdAud.sys
2008-07-19 14:32 . 2005-03-04 14:53 127,872 -ra------ C:\WINDOWS\system32\drivers\aeaudio.sys
2008-07-19 14:32 . 2005-05-04 09:20 53,248 --------- C:\WINDOWS\system32\wdmioctl.dll
2008-07-19 14:32 . 2005-09-26 16:20 49,152 --a------ C:\WINDOWS\system32\DSndUp.exe
2008-07-19 14:32 . 2002-04-17 15:05 45,056 --------- C:\WINDOWS\system32\CleanUp.exe
2008-07-19 14:32 . 2005-06-22 04:11 23,552 -ra------ C:\WINDOWS\system32\PostProc.dll
2008-07-19 13:13 . 2008-07-26 14:17 111,520 --a------ C:\WINDOWS\BM13d3e0ea.xml
2008-07-19 13:02 . 2008-07-19 13:02 <REP> d-------- C:\Program Files\Rollercoaster Rush
2008-07-19 13:02 . 2008-07-19 13:02 58,368 --------- C:\WINDOWS\version.exe
2008-07-17 12:32 . 2008-04-13 19:33 1,306,624 -----c--- C:\WINDOWS\system32\dllcache\msxml6.dll
2008-07-17 12:32 . 2008-04-13 19:32 103,424 -----c--- C:\WINDOWS\system32\dllcache\dpcdll.dll
2008-07-17 12:32 . 2008-04-13 19:04 93,184 -----c--- C:\WINDOWS\system32\dllcache\msxml6r.dll
2008-07-17 12:32 . 2008-04-13 11:45 46,592 --------- C:\WINDOWS\system32\drivers\irbus.sys
2008-07-17 12:32 . 2008-04-13 11:43 9,728 --------- C:\WINDOWS\system32\comsdupd.exe
2008-07-17 12:27 . 2008-07-17 12:32 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-07-17 12:21 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\[u]0/u02887_.tmp
2008-07-16 13:20 . 2004-02-22 10:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-07-16 13:20 . 2007-05-17 17:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-07-16 13:20 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-07-16 13:20 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-07-16 13:20 . 2006-04-05 08:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-07-16 13:20 . 2005-07-14 12:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-07-16 13:19 . 2008-07-16 13:17 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-07-16 13:19 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-07-16 13:19 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-07-16 13:19 . 2006-04-12 09:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-07-16 13:19 . 2005-02-13 00:00 186,880 -r-hs---- C:\WINDOWS\system32\RLOgg.ax
2008-07-16 13:19 . 2005-01-18 00:26 179,200 -r-hs---- C:\WINDOWS\system32\DiracSplitter.ax
2008-07-16 13:19 . 2005-02-06 00:00 92,672 -r-hs---- C:\WINDOWS\system32\RLVorbisDec.ax
2008-07-16 13:19 . 2005-02-13 00:00 67,584 -r-hs---- C:\WINDOWS\system32\RLTheoraDec.ax
2008-07-16 13:19 . 2005-02-13 00:00 51,712 -r-hs---- C:\WINDOWS\system32\RLSpeexDec.ax
2008-07-16 13:17 . 2008-07-16 13:17 <REP> d-------- C:\Program Files\eRightSoft
2008-07-16 12:59 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-16 12:59 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-16 12:58 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-07-16 11:18 . 2008-07-12 04:52 233,472 --a------ C:\WINDOWS\system32\TubeFinder.exe
2008-07-16 10:24 . 2008-07-16 10:24 44 --a------ C:\WINDOWS\system32\msssc.dll
2008-07-15 22:52 . 2008-07-17 11:05 <REP> d-------- C:\Documents and Settings\jays\Application Data\skypePM
2008-07-15 22:52 . 2008-07-15 22:52 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-15 22:50 . 2008-07-15 22:50 <REP> d-------- C:\Program Files\Skype
2008-07-15 22:50 . 2008-07-15 22:50 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-07-15 22:50 . 2008-07-17 11:07 <REP> d-------- C:\Documents and Settings\jays\Application Data\Skype
2008-07-15 22:50 . 2008-07-15 22:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-14 11:30 . 2008-07-14 11:30 <REP> d-------- C:\Program Files\Apple Software Update
2008-07-14 11:30 . 2008-07-14 11:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-11 19:55 . 2008-07-16 12:55 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-07-11 19:55 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-07-08 13:27 . 2008-07-08 13:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Last.fm
2008-07-08 13:26 . 2008-07-08 13:26 <REP> d-------- C:\Program Files\Last.fm
2008-07-04 00:33 . 2008-07-04 00:33 <REP> d-------- C:\Program Files\Oxin's Style!
2008-06-30 12:14 . 2008-07-21 15:22 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-30 12:14 . 2008-06-30 12:14 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-29 19:36 . 2008-06-29 19:36 <REP> d-------- C:\WINDOWS\system32\xlive
2008-06-28 22:01 . 2008-06-28 22:01 <REP> d-------- C:\Program Files\Smallvideosoft
2008-06-28 22:01 . 2008-06-28 22:02 <REP> d-------- C:\Mp3 Output
2008-06-28 22:01 . 2008-06-28 22:01 4,762,112 --a------ C:\WINDOWS\system32\NCMedia.dll
2008-06-28 22:01 . 2007-02-25 15:36 383,238 --a------ C:\WINDOWS\system32\libmp3lame-0.dll
2008-06-27 20:59 . 2008-06-27 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 11:05 --------- d-----w C:\Program Files\eMule
2008-07-26 09:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-25 18:49 --------- d-----w C:\Documents and Settings\jays\Application Data\Azureus
2008-07-22 10:10 --------- d-----w C:\Program Files\Eset
2008-07-20 11:50 --------- d-----w C:\Program Files\Search Settings
2008-07-19 12:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-19 10:48 --------- d-----w C:\Program Files\Analog Devices
2008-07-17 12:46 --------- d-----w C:\Program Files\DivX
2008-07-17 09:22 --------- d-----w C:\Program Files\StuffPlug3
2008-07-16 09:37 --------- d-----w C:\Program Files\Free FLV Converter
2008-07-12 10:13 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-05 19:03 --------- d-----w C:\Program Files\Azureus
2008-07-02 11:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-02 10:58 --------- d-----w C:\Program Files\Common Files
2008-07-02 10:58 --------- d-----w C:\Program Files\CamStudio
2008-06-30 10:09 --------- d-----w C:\Program Files\Mindscape
2008-06-26 08:24 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-06-24 10:29 --------- d-----w C:\Program Files\vghd
2008-06-24 10:28 --------- d-----w C:\Documents and Settings\jays\Application Data\vghd
2008-06-24 10:04 162,432 ----a-w C:\windows\system32\drivers\ithsgt.sys
2008-06-24 10:04 12,032 ----a-w C:\windows\system32\drivers\lilsgt.sys
2008-06-24 09:55 --------- d-----w C:\Program Files\Atari
2008-06-24 09:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Codemasters
2008-06-24 09:41 --------- d-----w C:\Program Files\Convoi150
2008-06-20 11:51 361,600 ----a-w C:\windows\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\windows\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\windows\system32\drivers\tcpip6.sys
2008-06-19 08:03 --------- d-----w C:\Program Files\SuperTuxKart
2008-06-12 08:23 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-08 18:09 --------- d-----w C:\Program Files\HomePlayer
2008-06-05 09:01 --------- d-----w C:\Program Files\ENJOY Plus!
2008-06-05 09:01 --------- d-----w C:\Documents and Settings\jays\Application Data\ENJOY Plus!
2008-06-05 09:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\ENJOY Plus!
2008-04-27 20:21 737,280 ----a-w C:\windows\iun6002.exe
2007-11-14 12:10 22,328 ----a-w C:\Documents and Settings\jays\Application Data\PnkBstrK.sys
2007-11-18 22:40 88 --sh--r C:\windows\system32\F93955F30A.sys
2007-11-18 22:41 2,516 --sha-w C:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-12-04 02:59 5724184]
"SkinClock"="C:\Program Files\Clock Tray Skins\ClockTraySkins.exe" [2007-08-08 22:58 448000]
"ctfmon.exe"="C:\windows\system32\ctfmon.exe" [2008-04-13 19:34 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-08-14 04:51 352256]
"Launch LCDMon"="C:\Program Files\Fichiers communs\Logitech\LCD Manager\lcdmon.exe" [2007-04-26 16:54 774168]
"Launch LGDCore"="C:\Program Files\Fichiers communs\Logitech\G-series Software\LGDCore.exe" [2007-04-26 17:22 1132056]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43 8466432]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43 81920]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 12:41 196608]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07 69632]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-01 13:25 185896]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 03:11 925696]
"Launch PC Probe II"="C:\Program Files\Asus\PC Probe II\Probe2.exe" [2006-07-28 17:39 2129408]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-02-20 11:06 1443072]
"Corel Photo Downloader"="C:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2007-08-16 13:00 531272]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 15:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 19:34 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2007-11-15 11:10 72208 c:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-05-24 10:38 210168 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"SeePassword"=C:\Program Files\SeePassword\SeePassword.exe
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"G:\\BMW M3 Challenge\\BMW.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\English\\setup.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"C:\\Program Files\\Virtual RC Racing\\vrcrace.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3y.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\windows\system32\drivers\sfsync03.sys [2005-12-06 17:11]
R0 videX32;videX32;C:\windows\system32\DRIVERS\videX32.sys [2006-02-23 05:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\windows\system32\DRIVERS\xfilt.sys [2006-02-23 05:39]
R2 ithsgt;ithsgt;C:\windows\system32\DRIVERS\ithsgt.sys [2008-06-24 12:04]
R2 lilsgt;lilsgt;C:\windows\system32\DRIVERS\lilsgt.sys [2008-06-24 12:04]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\windows\system32\regedt32.exe [2002-08-30 14:00]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-07-14 C:\windows\Tasks\AppleSoftwareUpdate.job - s!:C:\Program Files\Apple Software Update\SoftwareUpdate.exe-taskSYSTEM0 []
.
- - - - ORPHANS REMOVED - - - -
BHO-{07D048B7-90DF-4A3D-9859-73D473F23A75} - (no file)
BHO-{28190BCD-143B-4A75-8599-C6153C3FCAF3} - C:\windows\system32\cbXRIayv.dll
BHO-{425E07B2-1857-407C-9490-CC5F5ECFB746} - (no file)
BHO-{5ED6FA40-C937-4BE6-982D-02ADD07E9784} - (no file)
BHO-{AD3A7EEC-290B-4CB6-B67A-9E7957D2F746} - (no file)
BHO-{b1cd4257-1538-46ca-9826-213706f58262} - (no file)
BHO-{EBA0F461-D69F-4BE7-9F08-467E81EF96F3} - C:\windows\system32\khfFWoPf.dll
ShellExecuteHooks-{EBA0F461-D69F-4BE7-9F08-467E81EF96F3} - C:\windows\system32\khfFWoPf.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyOverride = localhost;*.local
O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-26 14:32:05
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Eset\ESET Smart Security\ekrn.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Fichiers communs\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Fichiers communs\Logitech\LCD Manager\Applets\LCDCountdown.exe
C:\Program Files\Fichiers communs\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Fichiers communs\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-26 14:37:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-26 12:37:33
Pre-Run: 24,352,620,544 octets libres
Post-Run: 24,738,045,952 octets libres
295 --- E O F --- 2008-07-25 10:26:48