Bonjour plm69,
Oui j'ai bien supprimé la sélection après le rapport.
Voici le rapport de ComboFix comme tu m'a demandé :
ComboFix 08-09-05.05 - Sébastien 2008-09-08 11:25:20.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1165 [GMT 2:00]
Endroit: C:\Users\Sébastien\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-08 to 2008-09-08 ))))))))))))))))))))))))))))))))))))
.
2008-09-07 20:56 . 2008-09-07 20:56 <REP> d-------- C:\Users\Sébastien\AppData\Roaming\Malwarebytes
2008-09-07 20:56 . 2008-09-07 20:56 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-09-07 20:56 . 2008-09-07 20:56 <REP> d-------- C:\ProgramData\Malwarebytes
2008-09-07 20:56 . 2008-09-07 20:56 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-07 20:56 . 2008-09-02 00:16 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-09-07 20:56 . 2008-09-02 00:16 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
2008-09-07 15:03 . 2008-09-07 15:15 <REP> d-------- C:\Program Files\BHODemon 2
2008-09-06 22:54 . 2008-09-06 22:54 <REP> d-------- C:\Windows\BDOSCAN8
2008-09-06 18:54 . 2008-09-06 20:17 0 --ah----- C:\ntuser.dat.LOG2
2008-09-06 18:54 . 2008-09-06 20:17 0 --ah----- C:\ntuser.dat.LOG1
2008-09-06 18:54 . 2008-09-06 18:54 0 --a------ C:\ntuser.dat
2008-09-06 12:12 . 2008-09-06 12:19 <REP> d-------- C:\Update
2008-09-05 15:44 . 2008-09-05 15:44 <REP> d--hs---- C:\Windows\ftpcache
2008-09-05 13:37 . 2008-09-05 13:37 <REP> d-------- C:\Program Files\EA GAMES
2008-09-04 13:32 . 2008-09-04 13:47 <REP> d-------- C:\Users\All Users\eMule
2008-09-04 13:32 . 2008-09-04 13:47 <REP> d-------- C:\ProgramData\eMule
2008-09-04 02:23 . 2008-09-04 02:23 <REP> d-------- C:\Program Files\VDOWNLOADER
2008-09-04 02:13 . 2008-09-04 02:13 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-04 02:11 . 2008-09-04 02:11 <REP> d-------- C:\Program Files\iTunes
2008-09-04 02:11 . 2008-09-04 02:11 <REP> d-------- C:\Program Files\iPod
2008-08-27 17:54 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-08-27 17:54 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-08-27 17:54 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-08-27 17:54 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-08-27 17:54 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-08-27 17:54 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-08-27 17:54 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-08-27 17:54 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-08-27 17:54 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-08-14 07:30 . 2008-07-16 03:32 2,048 --a------ C:\Windows\System32\tzres.dll
2008-08-13 22:37 . 2008-06-19 05:31 361,984 --a------ C:\Windows\System32\IPSECSVC.DLL
2008-08-13 22:29 . 2008-04-18 07:48 269,312 --a------ C:\Windows\System32\es.dll
2008-08-13 22:24 . 2008-06-27 03:55 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2008-08-13 22:24 . 2008-06-27 06:15 827,392 --a------ C:\Windows\System32\wininet.dll
2008-08-13 22:13 . 2008-04-10 07:12 738,304 --a------ C:\Windows\System32\inetcomm.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-08 09:26 5,505,024 --sha-w C:\Users\Sébastien\NTUSER.DAT
2008-09-08 09:26 5,505,024 --sha-w C:\Users\Sébastien\NTUSER.DAT
2008-09-07 19:49 --------- d-----w C:\Users\Sébastien\AppData\Roaming\LimeWire
2008-09-07 18:56 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Malwarebytes
2008-09-06 15:46 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-09-06 10:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-06 10:23 --------- d-----w C:\Program Files\Common Files\Sony Shared
2008-09-06 10:21 --------- d-----w C:\ProgramData\Sony Corporation
2008-09-05 14:35 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-05 13:35 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Azureus
2008-09-04 10:15 --------- d-----w C:\Program Files\MessengerDiscovery
2008-09-04 03:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-04 02:23 136 ----a-w C:\Users\Sébastien\AppData\Roaming\wklnhst.dat
2008-09-03 21:58 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-19 07:13 --------- d-s---w C:\Users\Sébastien\AppData\Roaming\Microsoft
2008-08-14 06:43 --------- d-----w C:\Program Files\Windows Mail
2008-08-10 13:59 --------- d-----w C:\Program Files\Google BAE
2008-08-02 02:21 --------- d-----w C:\Program Files\Restauration fichiers
2008-08-02 01:59 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Roxio
2008-08-02 01:59 --------- d-----w C:\ProgramData\Roxio
2008-08-02 01:39 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Adobe
2008-08-02 01:27 --------- d-----w C:\ProgramData\FLEXnet
2008-08-02 01:27 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-08-02 01:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-25 04:55 --------- d-----w C:\Program Files\Sony
2008-07-24 18:28 --------- d-----w C:\ProgramData\VAIO Media Platform
2008-07-22 18:22 --------- d-----w C:\Users\Sébastien\AppData\Roaming\InstallShield Installation Information
2008-07-22 17:06 --------- d-----w C:\Users\Sébastien\AppData\Roaming\InterVideo
2008-07-22 02:42 --------- d-----w C:\Program Files\Unreal Tournament 3
2008-07-19 14:36 51,280 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-07-18 22:41 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Image Zone Express
2008-07-18 22:26 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Printer Info Cache
2008-07-18 12:38 --------- d-----w C:\Users\Sébastien\AppData\Roaming\Canneverbe_Limited
2008-07-13 18:56 --------- d-----w C:\Program Files\MyFree Codec
2008-07-13 12:55 --------- d-----w C:\Program Files\Java
2008-07-10 19:57 --------- d-----w C:\Program Files\CDBurnerXP
2008-07-10 18:29 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-07-10 18:27 --------- d-----w C:\Users\Sébastien\AppData\Roaming\DataCast
2008-07-10 18:26 --------- d-----w C:\Program Files\Samsung
2008-07-10 18:19 --------- d-----w C:\Program Files\MarkAny
2008-07-04 19:31 174 --sha-w C:\Program Files\desktop.ini
2008-07-04 19:08 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-07-04 19:08 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-17 23:22 428,544 ----a-w C:\Windows\System32\EncDec.dll
2008-06-17 23:22 293,376 ----a-w C:\Windows\System32\psisdecd.dll
2008-06-15 15:48 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-06-15 15:46 988,216 ----a-w C:\Windows\System32\winload.exe
2008-06-15 15:46 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-06-15 15:46 615,992 ----a-w C:\Windows\System32\ci.dll
2008-06-15 15:46 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-06-15 15:46 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-06-15 15:46 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-06-15 15:46 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-06-15 15:46 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-06-15 15:46 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-06-15 15:46 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-06-15 15:45 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-06-15 15:44 295,936 ----a-w C:\Windows\System32\gdi32.dll
2008-06-15 15:43 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-06-15 15:42 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-06-15 15:42 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-06-15 15:42 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-06-15 15:42 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-06-15 15:42 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-06-15 15:42 1,695,744 ----a-w C:\Windows\System32\gameux.dll
2008-06-15 15:41 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-06-15 15:35 201,728 ----a-w C:\Windows\System32\inook-v4-3.scr
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 311296]
"MarketingTools"="C:\Program Files\Sony\Marketing Tools\MarketingTools.exe" [2007-11-28 36864]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"SMSTray"="C:\Program Files\Samsung\EmoDio\SMSTray.exe" [2008-06-23 479232]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-09-02 1244848]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-08 C:\Windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-04-08 C:\Windows\SkyTel.exe]
C:\Users\S‚bastien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2007-06-01 49152]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-10-30 748072]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= "C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 21:05 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FB85C566-1426-4061-A6AF-355763165489}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{6577B77C-94EA-48C5-B53D-77FC09FCE658}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9873C3D8-F154-4078-B199-40678603180C}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{C944CEFD-08EC-483D-AA1F-B221AE14BACA}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{B237A732-517C-49E4-9E7A-C36BB73D238B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{D73FD778-0FBC-4824-AE37-D116B3555F9B}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{2A491979-CD5A-458B-8EA9-9B9E77BEB2CE}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{3DF21D36-BB7B-4A73-879E-E7C4518FECAF}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{95C85DE2-0DA5-4D7D-9BE9-A1958E6BE57C}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{D506EF81-EC61-4367-A787-6B88D1CC642F}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{12F7A85E-27B4-49F4-AB05-CE15989EEAFC}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{01FA14D3-AD43-4A46-9749-0DF8E17D505C}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= UDP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
"UDP Query User{31145688-F27C-4D12-BDBE-83E4D8C36036}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= TCP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
"{8993068E-5026-429A-8C34-584995291845}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E958A512-312A-4962-BB3B-66203F00E71D}"= UDP:C:\Windows\System32\muzapp.exe:MUZ AOD APP player
"{7E0D62CF-62F0-44F2-A7D3-8C3305C3DCCC}"= TCP:C:\Windows\System32\muzapp.exe:MUZ AOD APP player
"{1835A9EC-0922-4017-A44F-DEC5A4EAB6E9}"= UDP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{D15FA77D-8640-496A-94D3-36CB7092F589}"= TCP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{369809A9-4B3C-4B35-A106-B3BF09D15431}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{373DFB27-E110-495A-BBAB-AFE48AC5F03E}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{8D2D94EB-A8D7-471D-8D41-7BA726D0EF76}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= UDP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
"UDP Query User{B75E1BC3-8F72-43FD-A44E-12D4195B30B3}C:\\program files\\messengerdiscovery\\messengerdiscovery live.exe"= TCP:C:\program files\messengerdiscovery\messengerdiscovery live.exe:MessengerDiscovery Live the Windows Live Messenger addon
"TCP Query User{5FC03BBB-6BDF-4148-B488-A48C2FFB8F71}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{F4EA32B0-4541-4BE5-8FF8-0F8D6DF3A97B}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"TCP Query User{C8693D0F-8215-4137-B1D0-EC08EEAF7DF5}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{89DF408D-ED14-4F3C-B04B-0B3A3EEEBD05}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"TCP Query User{F0409410-FCCE-4497-AB57-3455DE5E8C24}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{0113383D-074D-4F5D-AFBE-0D1F23BD9067}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"{EF4B6CF3-7AED-45B3-A391-876429020E06}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{26A93DEF-8387-495E-884B-D10100C33FAD}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{FF5477EB-7D6C-4055-BC97-7325E9600661}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{CC935AFC-E766-4847-9DFB-F591FB44D66C}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{3155121B-5D56-4CF5-B002-985891E65F02}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{D3A3568F-91CD-4DD6-82B9-02CB34633A82}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-17 11032]
R2 uCamMonitor;CamMonitor;C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe [2007-10-31 125440]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-28 292128]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2007-10-29 17920]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-10-19 2930176]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-10-17 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-10-17 43904]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-11-16 818688]
S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-11-15 81448]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-11-15 99880]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-11-15 28464]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-11-15 17448]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2008-03-17 87328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSSMSGS - winopz32.rom
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Sébastien\AppData\Roaming\Mozilla\Firefox\Profiles\azw0foaz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.orange.fr
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-08 11:28:48
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-08 11:30:14
ComboFix-quarantined-files.txt 2008-09-08 09:29:54
Pre-Run: 86,445,375,488 octets libres
Post-Run: 86,417,723,392 octets libres
248 --- E O F --- 2008-09-08 08:56:06