ComboFix 08-08-19.06 - Gidjo 2008-08-21 14:37:25.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1760 [GMT 2:00]
Endroit: C:\Users\Gidjo\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-21 to 2008-08-21 ))))))))))))))))))))))))))))))))))))
.
2008-08-21 12:43 . 2008-08-21 12:43 818 --a------ C:\prefs.js
2008-08-21 12:39 . 2008-08-21 12:39 1,409 --a------ C:\Windows\System32\~TEMP.FOT
2008-08-21 12:30 . 2008-08-21 12:30 0 --a------ C:\Windows\System32\tviresource.val
2008-08-21 11:59 . 2008-08-21 11:59 <REP> d-------- C:\Windows\TweakVI
2008-08-21 11:59 . 2008-08-21 12:43 <REP> d-------- C:\Program Files\TweakVI
2008-08-20 15:39 . 2008-08-20 15:39 <REP> d-------- C:\ProgramData\Avira
2008-08-20 15:39 . 2008-08-20 15:39 <REP> d-------- C:\Program Files\Avira
2008-08-20 12:26 . 2008-08-20 13:24 <REP> d-------- C:\Program Files\Navilog1
2008-08-20 10:29 . 2008-08-20 10:29 <REP> d-------- C:\Program Files\Trend Micro
2008-08-20 00:07 . 2008-08-20 00:07 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\Grisoft
2008-08-20 00:06 . 2007-03-08 01:51 129,784 --------- C:\Windows\System32\pxafs.dll
2008-08-20 00:05 . 2008-08-20 00:12 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\Winamp
2008-08-20 00:05 . 2008-08-20 00:07 <REP> d-------- C:\Program Files\Winamp
2008-08-20 00:05 . 2007-05-30 14:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2008-08-20 00:04 . 2008-08-20 00:04 <REP> d-------- C:\ProgramData\Grisoft
2008-08-19 23:38 . 2008-08-19 23:38 <REP> d-------- C:\Program Files\Sun
2008-08-16 11:21 . 2008-08-19 23:40 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-08-16 11:21 . 2008-08-16 11:22 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-16 11:10 . 2008-08-16 11:10 <REP> d-------- C:\Program Files\CCleaner
2008-08-15 18:12 . 2008-08-15 18:23 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\MyPhoneExplorer
2008-08-15 18:12 . 2008-08-15 18:12 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\AD ON Multimedia
2008-08-15 18:08 . 2008-08-15 18:12 <REP> d-------- C:\Program Files\MyPhoneExplorer
2008-08-14 17:32 . 2008-08-14 17:32 <REP> d-------- C:\Program Files\ElcomSoft
2008-08-14 14:30 . 2008-07-16 03:32 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-14 13:43 . 2008-06-27 03:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-08-14 13:43 . 2008-06-27 06:15 827,392 --a------ C:\Windows\System32\wininet.dll
2008-08-14 13:43 . 2008-06-19 05:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-14 13:43 . 2008-04-18 07:48 269,312 --a------ C:\Windows\System32\es.dll
2008-08-14 13:42 . 2008-04-10 07:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
2008-08-11 17:28 . 2008-06-11 14:48 188,960 --a------ C:\Windows\System32\nvapps.xml
2008-08-11 14:20 . 2008-08-11 17:44 <REP> d-------- C:\Program Files\PeerGuardian2
2008-08-08 15:19 . 2008-08-08 15:19 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\Nosibay
2008-08-08 15:19 . 2008-08-08 15:19 <REP> d-------- C:\Program Files\Nosibay
2008-08-08 14:24 . 2008-08-08 14:33 <REP> d--h----- C:\Windows\msdownld.tmp
2008-08-08 14:17 . 2008-08-08 14:17 <REP> d-------- C:\Program Files\Lavalys
2008-08-07 14:43 . 2008-08-16 18:50 <REP> d-------- C:\Program Files\a-squared Free
2008-08-05 19:01 . 2008-08-05 19:05 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\FMZilla
2008-08-05 19:01 . 2008-08-05 19:01 <REP> d-------- C:\downloads
2008-08-05 16:10 . 2008-08-05 16:11 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\Notepad++
2008-08-05 16:10 . 2008-08-05 16:10 <REP> d-------- C:\Program Files\Notepad++
2008-08-05 02:55 . 2008-08-07 14:07 <REP> d-------- C:\Program Files\GameTop.com
2008-08-04 15:33 . 2008-08-04 15:35 <REP> d-------- C:\Program Files\NVIDIA Corporation
2008-08-04 13:10 . 2006-06-14 13:44 12,288 --a------ C:\Windows\System32\drivers\EIO.sys
2008-08-04 12:41 . 2008-08-04 12:41 45 --a------ C:\Windows\System32\initdebug.nfo
2008-08-03 21:47 . 2008-08-03 21:47 <REP> d-------- C:\Users\Gidjo\soccer-trainer
2008-07-31 05:44 . 2008-07-31 05:44 <REP> d-------- C:\ProgramData\WindowsSearch
2008-07-27 19:08 . 2008-08-16 11:10 <REP> d-------- C:\Program Files\VS Revo Group
2008-07-23 12:46 . 2008-07-30 11:10 <REP> d-------- C:\Program Files\EvilLyrics
2008-07-23 12:39 . 2008-07-23 12:39 51,600 --a------ C:\Windows\System32\RadLightMPCUninstall.exe
2008-07-23 11:36 . 2008-07-23 11:36 <REP> d-------- C:\Users\Gidjo\AppData\Roaming\PCF-VLC
2008-07-23 10:28 . 2008-07-23 10:28 <REP> d-------- C:\Windows\System32\Bayo
2008-07-23 10:28 . 2008-08-07 14:08 <REP> d-------- C:\Program Files\Bayo
2008-07-23 10:28 . 2002-01-13 17:12 188,416 --a------ C:\Windows\System32\CP30FW.DLL
2008-07-23 10:28 . 2008-07-23 10:28 108,144 --a------ C:\Windows\System32\CmdLineExt.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-21 11:09 164,047 ----a-w C:\ProgramData\nvModes.dat
2008-08-21 10:48 45,056 ----a-w C:\Windows\System32\acovcnt.exe
2008-08-21 09:00 --------- d-----w C:\Program Files\Alwil Software
2008-08-19 21:37 --------- d-----w C:\Program Files\Java
2008-08-19 00:04 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-16 09:04 --------- d-----w C:\ProgramData\NVIDIA
2008-08-14 22:42 --------- d-----w C:\Program Files\Windows Mail
2008-08-14 12:32 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-10 19:41 27,839 ----a-w C:\Users\Gidjo\AppData\Roaming\nvModes.dat
2008-08-08 10:06 --------- d-----w C:\Program Files\ASUS
2008-08-04 13:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-03 14:41 --------- d-----w C:\ProgramData\ma-config.com
2008-08-03 14:41 --------- d-----w C:\Program Files\ma-config.com
2008-07-19 12:47 --------- d-----w C:\Users\Gidjo\AppData\Roaming\DivX
2008-07-19 12:45 --------- d-----w C:\Program Files\DivX
2008-07-19 12:45 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-07-17 19:21 --------- d-----w C:\Users\Gidjo\AppData\Roaming\vlc
2008-07-17 19:20 --------- d-----w C:\Program Files\VideoLAN
2008-07-16 15:50 --------- d---a-w C:\ProgramData\TEMP
2008-07-16 14:37 --------- d-----w C:\Users\Gidjo\AppData\Roaming\SystemRequirementsLab
2008-07-16 14:37 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-07-16 11:41 --------- d-----w C:\ProgramData\comodo
2008-07-16 11:04 85,008 ----a-w C:\Windows\system32\drivers\cmdguard.sys
2008-07-16 11:04 25,104 ----a-w C:\Windows\system32\drivers\cmdhlp.sys
2008-07-16 11:04 143,104 ----a-w C:\Windows\System32\guard32.dll
2008-07-16 11:04 --------- d-----w C:\Users\Gidjo\AppData\Roaming\Comodo
2008-07-16 11:04 --------- d-----w C:\Program Files\COMODO
2008-07-11 23:16 --------- d-----w C:\Users\Gidjo\AppData\Roaming\AKVIS LLC
2008-07-11 23:11 --------- d-----w C:\Program Files\AKVIS
2008-07-11 11:46 --------- d-----w C:\ProgramData\Adobe Systems
2008-07-11 11:37 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-11 11:36 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-07-10 18:57 --------- d-----w C:\Program Files\SNES
2008-07-09 17:47 --------- d-----w C:\Program Files\Opera
2008-07-08 19:41 --------- d-----w C:\Program Files\Electronic Arts
2008-07-08 18:46 1,626 ----a-w C:\Windows\System32\ealregsnapshot1.reg
2008-07-07 20:13 --------- d-----w C:\Program Files\CSR
2008-07-04 17:39 --------- d-----w C:\ProgramData\LogiShrd
2008-07-04 17:38 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-07-04 17:38 --------- d-----w C:\Users\Gidjo\AppData\Roaming\Logitech
2008-07-04 17:37 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-07-04 17:36 --------- d-----w C:\ProgramData\Logitech
2008-07-04 17:36 --------- d-----w C:\Program Files\Logitech
2008-07-04 17:34 --------- d-----w C:\Users\Gidjo\AppData\Roaming\InstallShield
2008-07-04 17:34 --------- d-----w C:\Program Files\Intel
2008-07-04 14:35 --------- d-----w C:\Program Files\Cisco
2008-07-04 14:33 --------- d-----w C:\ProgramData\Intel
2008-07-01 22:06 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-07-01 17:12 --------- d-----w C:\ProgramData\Autodesk
2008-07-01 10:24 --------- d-----w C:\Program Files\Autodesk
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-25 17:43 --------- d-----w C:\Program Files\Blender Foundation
2008-06-24 19:51 --------- d-----w C:\Program Files\Common Files\Xara
2008-06-24 19:50 --------- d-----w C:\Program Files\Xara
2008-06-18 17:52 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-06-13 18:06 88,921 ----a-w C:\Windows\Internet Logs\vsmon_2nd_2008_06_13_15_18_19_small.dmp.zip
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-11 00:07 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-06-11 00:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-06-11 00:04 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-06-11 00:04 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-06-06 10:28 430,080 ----a-w C:\Windows\ntuneoem.dll
2008-06-06 10:28 29,952 ----a-w C:\Windows\nvoclock.sys
2008-06-04 14:29 446,464 ----a-w C:\Windows\System32\nvuninst.exe
2008-05-30 12:19 507,400 ----a-w C:\Windows\System32\XAudio2_1.dll
2008-05-30 12:18 238,088 ----a-w C:\Windows\System32\xactengine3_1.dll
2008-05-30 12:17 65,032 ----a-w C:\Windows\System32\XAPOFX1_0.dll
2008-05-30 12:17 25,608 ----a-w C:\Windows\System32\X3DAudio1_4.dll
2008-05-30 12:11 467,984 ----a-w C:\Windows\System32\d3dx10_38.dll
2008-05-30 12:11 3,850,760 ----a-w C:\Windows\System32\D3DX9_38.dll
2008-05-30 12:11 1,491,992 ----a-w C:\Windows\System32\D3DCompiler_38.dll
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin
2008-05-23 13:26 1,034,776 ----a-w C:\Windows\System32\imsmudlg.exe
2008-05-23 09:11 36,640 ----a-w C:\Windows\nvflash.sys
2008-05-22 22:18 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-05-02 10:00 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 03:08 143360 --a------ C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 23:33 125952]
"Mon Widget RMC"="C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe" [2008-01-25 13:55 185608]
"Speech Recognition"="C:\Windows\Speech\Common\sapisvr.exe" [2008-01-18 23:33 49664]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-06-06 12:25 114688]
"TweakVI"="C:\Program Files\TweakVI\tweakvi.exe" [2008-08-18 11:21 6034080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 14:36 36864]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 15:24 857648]
"ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 18:27 61440]
"ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2008-03-07 01:06 37232]
"ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2008-03-07 01:06 33136]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 17:41 178712]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-07-16 13:04 1655552]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 14:01 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 14:01 92704]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 13:04 4423680 C:\Windows\RtHDVCpl.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 03:12 76304 C:\Windows\KHALMNPR.Exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoAddPrinter"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\Windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{87ED12F3-6222-4998-9FE8-00269EE4E557}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{0DDD164C-AAE9-4838-B829-E51724592E06}"= UDP:D:\Program Files\FM2008\fm.exe:Football Manager 2008
"{C8A19D57-4C03-416C-89FF-A4D073EB981E}"= TCP:D:\Program Files\FM2008\fm.exe:Football Manager 2008
"{A08B3597-60AA-4403-8241-2F23BCDF0753}"= UDP:C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit
"{384A09AD-251F-4DB6-B081-AB9A674E335D}"= TCP:C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit
"{E7296AFF-B20E-483B-82B9-18E9DF9B8733}"= UDP:C:\Program Files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor
"{D81DB5E6-A902-4527-A20E-41F2E636AC8A}"= TCP:C:\Program Files\Autodesk\Backburner\monitor.exe:backburner 2.3 monitor
"{2BB7C796-AA6A-4B47-974D-627BEB7636B5}"= UDP:C:\Program Files\Autodesk\Backburner\manager.exe:backburner 2.3 manager
"{0AED09D4-BA6F-494A-95DF-0CF1F0A2D1D9}"= TCP:C:\Program Files\Autodesk\Backburner\manager.exe:backburner 2.3 manager
"{71D59552-E353-439C-A9B8-5D35022283EA}"= UDP:C:\Program Files\Autodesk\Backburner\server.exe:backburner 2.3 server
"{A276C060-56DB-4770-9BAA-D4BC9C520C3A}"= TCP:C:\Program Files\Autodesk\Backburner\server.exe:backburner 2.3 server
"{0CDA39B3-01DF-4306-81F8-AB3D9645581D}"= UDP:C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit
"{15B36B6D-F5C6-4EC5-81F3-355E39B7B352}"= TCP:C:\Program Files\Autodesk\3ds Max 9\3dsmax.exe:Autodesk 3ds Max 9 32-bit
"{38679AFB-2082-4360-8531-E229B4886FAB}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{E04EDBE7-AB69-43B7-9BB8-0648786E0853}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{73C9F461-1F08-4289-9D57-51085F14FFD7}"= UDP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{63A586BE-EC41-4467-BA29-875EC883B520}"= TCP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"TCP Query User{F38AC080-737D-4BF7-A436-251283B729D6}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{FE22DDC9-80B0-4AC3-A096-B3F9049758B8}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{92F6A8BE-BB0C-4CD5-8920-5F32B09FBAB9}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{BCC32568-0FEB-418B-AD93-F64BF0C06663}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys [2008-07-16 13:04]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys [2008-07-16 13:04]
R2 NVR0FLASHDev;NVR0FLASHDev;C:\Windows\nvflash.sys [2008-05-23 11:11]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 09:42]
R2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;C:\Windows\System32\StkCSrv.exe [2007-04-19 08:42]
R2 UpdateCenterService;Update Center Service;C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe [2008-05-23 11:14]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2007-03-15 08:41]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys [2007-04-21 02:14]
R3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;C:\Windows\system32\Drivers\StkCMini.sys [2007-05-30 09:22]
S2 ASDR;ASDR;C:\Windows\System32\ASDR.exe []
S3 hid8101;hid8101;C:\Windows\system32\DRIVERS\system32.sys [2006-07-23 15:28]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 20:57]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{49e3fbea-0e4b-11dd-af6a-001fc624b686}]
\shell\AutoRun\command - G:\Setup.exe -auto
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Gidjo\AppData\Roaming\Mozilla\Firefox\Profiles\hvviynss.default\
FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npdivx32.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Users\Gidjo\AppData\Roaming\Mozilla\Firefox\Profiles\hvviynss.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-21 14:49:16
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
C:\ADSM_PData_0150
Scan terminé avec succès
Les fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\Windows\system32\winlogon.exe
-> C:\Windows\system32\guard32.dll
PROCESS: C:\Windows\system32\lsass.exe
-> C:\Windows\system32\guard32.dll
.
Temps d'accomplissement: 2008-08-21 14:50:32
ComboFix-quarantined-files.txt 2008-08-21 12:50:27
Pre-Run: 66,055,102,464 octets libres
Post-Run: 65,598,816,256 octets libres
276 --- E O F --- 2008-08-20 12:36:14