ComboFix 08-09-05.02 - MSI 2008-09-06 11:47:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.720 [GMT 2:00]
Endroit: C:\Documents and Settings\MSI\Bureau\C-Fix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_poof
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-06 to 2008-09-06 ))))))))))))))))))))))))))))))))))))
.
2008-09-06 01:45 . 2008-09-06 01:45 8,725,584 --a------ C:\upload_moi_ORDINATEUR.tar.gz
2008-09-05 20:56 . 2008-09-05 20:56 <REP> d-------- C:\Documents and Settings\All Users\ModŠles
2008-09-05 20:41 . 2008-09-06 11:54 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-05 12:32 . 2008-09-05 12:51 <REP> d-------- C:\ToolBar SD
2008-09-04 20:30 . 2008-09-04 21:30 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-09-04 11:00 . 2008-09-04 11:00 25 --a------ C:\WINDOWS\OverlayXP.ini
2008-09-03 14:12 . 2008-09-05 20:56 <REP> d-------- C:\Program Files\SweetIM
2008-09-03 14:12 . 2008-09-03 14:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SweetIM
2008-09-03 11:50 . 2007-02-28 13:00 108,752 --a------ C:\WINDOWS\system32\drivers\dptrackerd.sys
2008-09-02 14:34 . 2008-09-02 14:34 77,824 --a----t- C:\WINDOWS\system32\DRWEBSP.DLL
2008-09-01 17:12 . 2008-09-01 17:12 <REP> d--h----- C:\Documents and Settings\MSI\Voisinage r‚seau
2008-08-31 21:21 . 2008-08-31 21:21 <REP> d-------- C:\Documents and Settings\MSI\Application Data\vlc
2008-08-31 19:28 . 2008-08-31 19:28 <REP> d-------- C:\Program Files\Trend Micro
2008-08-31 11:38 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-08-31 11:37 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-08-30 14:49 . 2008-09-04 18:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-29 10:49 . 2008-09-05 12:49 2,188 --a------ C:\Documents and Settings\Orph.egd
2008-08-28 11:38 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-08-28 11:38 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-08-28 11:38 . 2008-08-28 11:38 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-08-28 11:38 . 2008-08-28 11:38 3,120 --a------ C:\WINDOWS\118294.78
2008-08-28 11:38 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-08-26 19:59 . 2008-08-28 10:56 <REP> d-------- C:\Documents and Settings\MSI\SecurityScans
2008-08-24 18:38 . 2008-08-24 18:38 <REP> d-------- C:\Program Files\Avira
2008-08-24 18:38 . 2008-08-24 18:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-24 13:04 . 2008-09-05 11:28 <REP> d-------- C:\Program Files\SpywareBlaster
2008-08-22 21:51 . 2008-08-22 21:51 <REP> d-------- C:\Documents and Settings\MSI\Application Data\GlarySoft
2008-08-22 21:47 . 2008-08-22 21:47 <REP> d-------- C:\Program Files\Glary Utilities
2008-08-20 19:40 . 2008-08-20 19:41 <REP> d-------- C:\WINDOWS\AU_Temp
2008-08-20 19:40 . 2008-08-20 19:41 25,220,881 --a------ C:\WINDOWS\VPTNFILE.489
2008-08-20 19:40 . 2008-08-20 19:41 25,220,881 --a------ C:\WINDOWS\LPT$VPN.489
2008-08-19 15:09 . 2008-08-19 15:09 <REP> d-------- C:\Documents and Settings\MSI\Application Data\PCF-VLC
2008-08-17 22:40 . 2008-08-17 22:40 <REP> d-------- C:\Documents and Settings\All Users\.elscdweb
2008-08-17 22:40 . 2008-08-17 22:40 137,344 --a------ C:\WINDOWS\system32\drivers\hwpsgt.sys
2008-08-17 22:40 . 2008-08-17 22:40 12,032 --a------ C:\WINDOWS\system32\drivers\tansgt.sys
2008-08-17 22:40 . 2008-08-17 22:40 9,344 --a------ C:\WINDOWS\system32\drivers\enosgt.sys
2008-08-17 22:37 . 2008-08-17 22:37 <REP> d--h----- C:\Program Files\Zero G Registry
2008-08-16 23:24 . 2006-05-05 11:41 453,120 --------- C:\WINDOWS\system32\DllCache\mrxsmb.sys
2008-08-16 23:24 . 2006-05-05 11:47 174,592 --------- C:\WINDOWS\system32\DllCache\rdbss.sys
2008-08-16 23:05 . 2007-01-23 21:29 546,304 --------- C:\WINDOWS\system32\DllCache\hhctrl.ocx
2008-08-16 16:15 . 2008-08-24 18:27 121 --a------ C:\WINDOWS\bdagent.INI
2008-08-16 16:14 . 2008-08-24 18:27 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-08-16 11:49 . 2008-08-16 11:51 <REP> d-------- C:\WINDOWS\system32\DLA
2008-08-16 11:49 . 2006-07-21 11:21 99,176 --a------ C:\WINDOWS\system32\drivers\DRVMCDB.SYS
2008-08-16 11:49 . 2006-10-26 16:21 92,920 --a------ C:\WINDOWS\DLA.EXE
2008-08-16 11:49 . 2006-10-26 16:21 56,056 --a------ C:\WINDOWS\system32\DLAAPI_W.DLL
2008-08-16 11:49 . 2007-02-09 12:34 51,768 --a------ C:\WINDOWS\system32\drivers\DRVNDDM.SYS
2008-08-16 11:49 . 2007-02-08 20:05 28,120 --a------ C:\WINDOWS\system32\drivers\DLARTL_M.SYS
2008-08-16 11:49 . 2007-02-08 20:05 12,856 --a------ C:\WINDOWS\system32\drivers\DLACDBHM.SYS
2008-08-16 11:49 . 2008-08-16 11:49 164 --a------ C:\WINDOWS\wininit.ini
2008-08-16 11:38 . 2008-08-16 11:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-08-14 01:34 . 2008-09-05 20:45 <REP> d-------- C:\Program Files\ZebHelpProcess 2
2008-08-12 22:18 . 2008-08-12 22:18 <REP> d-------- C:\WINDOWS\system32\MyFirewall
2008-08-12 19:21 . 2008-05-01 16:31 331,776 --------- C:\WINDOWS\system32\DllCache\msadce.dll
2008-08-12 19:21 . 2008-07-07 22:18 253,952 --------- C:\WINDOWS\system32\DllCache\es.dll
2008-08-12 19:20 . 2008-07-22 17:43 84,632 --------- C:\WINDOWS\system32\DllCache\apps.chm
2008-08-12 19:20 . 2008-06-24 18:30 74,240 --------- C:\WINDOWS\system32\DllCache\mscms.dll
2008-08-12 19:20 . 2008-07-22 17:40 9,696 --------- C:\WINDOWS\system32\DllCache\drvmain.sdb
2008-08-12 18:50 . 2004-08-19 16:09 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-08-12 18:49 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-08-12 18:48 . 2004-08-19 16:00 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-08-11 15:02 . 2008-08-11 15:02 <REP> d---s---- C:\Documents and Settings\LocalService\Mes documents
2008-08-11 15:02 . 2008-08-11 15:02 <REP> d---s---- C:\Documents and Settings\LocalService\Favoris
2008-08-10 13:05 . 2008-08-10 13:05 4 --a------ C:\WINDOWS\system32\wnsm2i.rdb
2008-08-08 19:34 . 2008-08-16 11:54 <REP> d-------- C:\logs
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 09:50 788,512 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-06 09:50 7,240 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-06 09:50 213,024 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-06 09:50 1,808 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-05 18:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\webcamXP5
2008-09-05 18:03 --------- d-----w C:\Program Files\PC Tools Firewall Plus
2008-09-05 11:06 --------- d-----w C:\Program Files\SpywareGuard
2008-09-02 12:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-02 12:28 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-01 22:16 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-08-31 09:35 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-29 22:17 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-08-29 22:17 --------- d-----w C:\Program Files\C-Media
2008-08-29 22:17 --------- d-----w C:\Documents and Settings\MSI\Application Data\FaxCtr
2008-08-29 22:17 --------- d-----w C:\Documents and Settings\MSI\Application Data\dvdcss
2008-08-29 22:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Backup
2008-08-24 11:10 --------- d-----w C:\Program Files\BeClean
2008-08-20 17:41 91,744 ----a-w C:\WINDOWS\BPMNT.dll
2008-08-20 17:41 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-08-20 17:41 333,576 ----a-w C:\WINDOWS\TSC.exe
2008-08-20 17:41 1,213,784 ----a-w C:\WINDOWS\vsapi32.dll
2008-08-20 17:40 69,689 ----a-w C:\WINDOWS\UNZIP.DLL
2008-08-20 17:40 507,904 ----a-w C:\WINDOWS\TMUPDATE.DLL
2008-08-20 17:40 286,720 ----a-w C:\WINDOWS\PATCH.EXE
2008-08-16 09:38 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-08-12 19:10 1,485,568 ----a-w C:\WINDOWS\system32\drivers\v3engine.sys
2008-08-08 08:59 --------- d-----w C:\Program Files\VideoLAN
2008-08-06 15:09 --------- d-----w C:\Program Files\lx_cats
2008-08-03 08:58 --------- d-----w C:\Program Files\wLite
2008-08-01 15:28 --------- d-----w C:\Program Files\Avanquest Connection Manager
2008-08-01 15:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-08-01 10:32 --------- d-----w C:\Documents and Settings\MSI\Application Data\InfraRecorder
2008-08-01 10:14 --------- d-----w C:\Program Files\InfraRecorder
2008-07-30 07:19 --------- d-----w C:\Program Files\Windows Live
2008-07-30 07:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-27 11:41 --------- d-----w C:\Program Files\CCleaner
2008-07-26 10:01 --------- d-----w C:\Program Files\Lexmark Fax Solutions
2008-07-22 15:41 37,440 ----a-w C:\WINDOWS\system32\drivers\pssdklbf.drv
2008-07-22 15:41 30,272 ----a-w C:\WINDOWS\system32\drivers\pssdk31.drv
2008-07-20 10:57 --------- d-----w C:\Documents and Settings\MSI\Application Data\Canneverbe_Limited
2008-07-07 19:24 164 ----a-w C:\install.dat
2001-11-23 11:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
2008-06-01 11:03 23 --sha-w C:\WINDOWS\system32\defbacacc3_z.dll
2008-03-16 20:32 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008031620080317\index.dat
.
------- Sigcheck -------
2007-07-18 21:14 506368 fa7c7c2b461130a792adf6a28f1d652b C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"LClock"="lclock.exe" [2004-12-08 C:\WINDOWS\LClock.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SweetIM"="C:\Program Files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 44544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)
"HideShutdownScripts"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoDispCPL"= 0 (0x0)
"NoDispAppearancePage"= 0 (0x0)
"NoDispScrSavPage"= 0 (0x0)
"NoDispSettingsPage"= 0 (0x0)
"NoVisualStyleChoice"= 0 (0x0)
"NoColorChoice"= 0 (0x0)
"NoSizeChoice"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
"HideLogonScripts"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
"NoResolveSearch"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoRunasInstallPrompt"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoThemesTab"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"RestrictCpl"= 0 (0x0)
"DisallowCpl"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"RestrictRun"= 0 (0x0)
"DisallowRun"= 0 (0x0)
"NoRecycleFiles"= 0 (0x0)
"ForceRecycleBinSize"= 0 (0x0)
"NoCustomizeWebView"= 0 (0x0)
"NoViewContextMenu"= 0 (0x0)
"NoWinKeys"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
"NoDFSTab"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoCustomizeThisFolder"= 0 (0x0)
"NoWebView"= 0 (0x0)
"DontShowSuperHidden"= 0 (0x0)
"NoOnlinePrintsWizard"= 0 (0x0)
"NoPublishingWizard"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuMorePrograms"= 0 (0x0)
"NoStartMenuEjectPC"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"StartMenuLogoff"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoDisconnect"= 0 (0x0)
"NoNtSecurity"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"GreyMSIAds"= 0 (0x0)
"ForceMaxRecentDocs"= 0 (0x0)
"NoSMBalloonTip"= 0 (0x0)
"NoSMBalloonTips"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"HideClock"= 0 (0x0)
"HideSCAVolume"= 0 (0x0)
"HideSCANetwork"= 0 (0x0)
"HideSCAPower"= 0 (0x0)
"NoTaskGrouping"= 0 (0x0)
"NoActiveDesktopChanges"= 0 (0x0)
"NoWebServices"= 0 (0x0)
"NoFileUrl"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"SpecifyDefaultButtons"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoClose"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoRunasInstallPrompt"= 0 (0x0)
"PromptRunasInstallNetPath"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoDevMgrUpdate"= 0 (0x0)
"NoThumbnailCache"= 0 (0x0)
"ForceCopyAclwithFile"= 0 (0x0)
"StartRunNoHOMEPATH"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"C-Media Mixer"=Mixer.exe /startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\lxcrcoms.exe"=
"C:\\Program Files\\Wireless LAN Utility\\SiSCFG.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"443:UDP"= 443:UDP:*:Disabled:UDP port 443 ooVoo
"37674:TCP"= 37674:TCP:*:Disabled:TCP port 37674 ooVoo
"37674:UDP"= 37674:UDP:*:Disabled:UDP port 37674 ooVoo
"37675:UDP"= 37675:UDP:*:Disabled:UDP port 37675 ooVoo
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2007-02-08 28120]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-03-12 159896]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\WINDOWS\system32\drivers\pctmp.sys [2008-02-21 40856]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\WINDOWS\system32\drivers\pctssipc.sys [2008-02-21 18328]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 46112]
R2 tansgt;tansgt;C:\WINDOWS\system32\drivers\tansgt.sys [2008-08-17 12032]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-03-25 24592]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
R3 VBEngNT;VBEngNT;C:\WINDOWS\system32\Drivers\VBEngNT.Sys [2007-10-05 1040561]
R3 VBFilter;VBFilter;C:\WINDOWS\system32\Drivers\VBFilter.Sys [2007-10-02 27096]
R3 VBRec;VBRec;C:\WINDOWS\system32\Drivers\VBRec.Sys [2007-10-02 18528]
S2 VBShld;VBShld;C:\WINDOWS\system32\Drivers\VBShld.Sys [2007-10-02 271232]
S3 ARCSOFTVIRTUALCAPTURE;Magic-i Virtual Driver;C:\WINDOWS\system32\DRIVERS\ArcSoftVirtualCapture.sys [2006-12-07 15104]
S3 DCamUSBPremier;Premier USB Video Camera;C:\WINDOWS\system32\Drivers\mpixvid.sys [2004-07-01 81921]
S3 PAC207;Webcam 1200;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [ ]
S3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2008-06-16 7808]
S3 PsSdk31;PsSdk31;C:\WINDOWS\system32\Drivers\pssdk31.drv [2008-07-22 30272]
S3 PsSdkLBF;PsSdkLBF;C:\WINDOWS\system32\Drivers\pssdklbf.drv [2008-07-22 37440]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-11-02 215552]
S3 SISNPF;SIS Netgroup Packet Filter;C:\WINDOWS\system32\drivers\SISNPF.sys [2005-04-14 31872]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{90e70112-4b40-11dd-99ec-0019e00e6978}]
\Shell\AutoRun\command - G:\DPFMate.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
Notify-LMIinit - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\MSI\Application Data\Mozilla\Firefox\Profiles\6vu1h72y.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-06 11:53:10
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PsSdk31]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\pssdk31.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PsSdkLBF]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\pssdklbf.drv"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\lxcrcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\SpywareGuard\sgmain.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-06 11:56:22 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-06 09:56:15
Pre-Run: 3,365,347,328 octets libres
Post-Run: 3,304,198,144 octets libres
394 --- E O F --- 2008-07-13 15:45:35