ComboFix 08-10-01.06 - Marie - Pierre 2008-10-02 21:16:46.6 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.183 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Marie - Pierre\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\Marie - Pierre\Bureau\CFScript
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
FILE ::
C:\Documents and Settings\Marie - Pierre\Local Settings\Temporary Internet Files\Content.IE5\AHN6585V\setup_sbd_fr[1].exe
C:\WINDOWS\system32\cjmest.dll
C:\WINDOWS\system32\crawsity.ini
C:\WINDOWS\system32\esfgwnlj.dll
C:\WINDOWS\system32\esxethvj.dll
C:\WINDOWS\system32\ixqfyj.dll
C:\WINDOWS\system32\jmfvwwqn.dll
C:\WINDOWS\system32\nokbexvg.ini
C:\WINDOWS\system32\NUuBIkkj.ini
C:\WINDOWS\system32\NUuBIkkj.ini2
C:\WINDOWS\system32\pqjbhp.dll
C:\WINDOWS\system32\vfqqbxcr.dll
C:\WINDOWS\system32\ywndwhfx.dll
C:\WINDOWS\system32\yyiiemkv.ini
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Defenza
C:\Program Files\Defenza\617F.sec
C:\Program Files\Defenza\Anti-Spyware.ben
C:\Program Files\Defenza\Antispyware Update Log.txt
C:\Program Files\Defenza\AntiSpywarePopMenu.dll
C:\Program Files\Defenza\ASSelectFolder.exe
C:\Program Files\Defenza\ASSelectFolder.HLP
C:\Program Files\Defenza\Backup\bmpSettingPageBK.pj1.bak
C:\Program Files\Defenza\Backup\bmpSettingPageBK.pj1.bk1
C:\Program Files\Defenza\Backup\btCheckall.pj1.bak
C:\Program Files\Defenza\Backup\btCheckallover.pj1.bak
C:\Program Files\Defenza\Backup\btCleanMyPC.pj1.bak
C:\Program Files\Defenza\Backup\btCleanMyPCover.pj1.bak
C:\Program Files\Defenza\Backup\btCleanNowInResultPage.pj1.bak
C:\Program Files\Defenza\Backup\btCleanNowInResultPageover.pj1.bak
C:\Program Files\Defenza\Backup\btCleanUp.pj1.bak
C:\Program Files\Defenza\Backup\btCleanUpover.pj1.bak
C:\Program Files\Defenza\Backup\btClose1.pj1.bak
C:\Program Files\Defenza\Backup\btClose1over.pj1.bak
C:\Program Files\Defenza\Backup\btQDelete.pj1.bak
C:\Program Files\Defenza\Backup\btQDeleteover.pj1.bak
C:\Program Files\Defenza\Backup\btQQuarantine.pj1.bak
C:\Program Files\Defenza\Backup\btQQuarantineover.pj1.bak
C:\Program Files\Defenza\Backup\btquarantine.pj1.bak
C:\Program Files\Defenza\Backup\btquarantineover.pj1.bak
C:\Program Files\Defenza\Backup\btscancancel.pj1.bak
C:\Program Files\Defenza\Backup\btscancancelover.pj1.bak
C:\Program Files\Defenza\Backup\btscannow.pj1.bak
C:\Program Files\Defenza\Backup\btscannowover.pj1.bak
C:\Program Files\Defenza\Backup\btscanresult.pj1.bak
C:\Program Files\Defenza\Backup\btscanresultover.pj1.bak
C:\Program Files\Defenza\Backup\btSeeDetail.pj1.bak
C:\Program Files\Defenza\Backup\btSeeDetailover.pj1.bak
C:\Program Files\Defenza\Backup\btSelectFile.pj1.bak
C:\Program Files\Defenza\Backup\btSelectFileover.pj1.bak
C:\Program Files\Defenza\Backup\btSelectScanfoldFile.pj1.bak
C:\Program Files\Defenza\Backup\btSelectScanfoldFileover.pj1.bak
C:\Program Files\Defenza\Backup\btSelModeFull.pj1.bak
C:\Program Files\Defenza\Backup\btSelModeFullover.pj1.bak
C:\Program Files\Defenza\Backup\btselmodequick.pj1.bak
C:\Program Files\Defenza\Backup\btselmodequickover.pj1.bak
C:\Program Files\Defenza\Backup\btsetting.pj1.bak
C:\Program Files\Defenza\Backup\btSettingBrowse.pj1.bak
C:\Program Files\Defenza\Backup\btSettingBrowseover.pj1.bak
C:\Program Files\Defenza\Backup\btsettingover.pj1.bak
C:\Program Files\Defenza\Backup\btUnCheckall.pj1.bak
C:\Program Files\Defenza\Backup\btUnCheckallover.pj1.bak
C:\Program Files\Defenza\Backup\btupdateDB.pj1.bak
C:\Program Files\Defenza\Backup\btupdateDBover.pj1.bak
C:\Program Files\Defenza\Backup\btupdateLicense.pj1.bak
C:\Program Files\Defenza\Backup\btupdateLicenseover.pj1.bak
C:\Program Files\Defenza\Backup\btupdates.pj1.bak
C:\Program Files\Defenza\Backup\btupdatesover.pj1.bak
C:\Program Files\Defenza\Backup\close.pj1.bak
C:\Program Files\Defenza\Backup\closeover.pj1.bak
C:\Program Files\Defenza\Backup\help.pj1.bak
C:\Program Files\Defenza\Backup\helpover.pj1.bak
C:\Program Files\Defenza\Backup\ListHead.pj1.bak
C:\Program Files\Defenza\Backup\ListHeadover.pj1.bak
C:\Program Files\Defenza\Backup\mini.pj1.bak
C:\Program Files\Defenza\Backup\miniover.pj1.bak
C:\Program Files\Defenza\Backup\pcd-as.exe.bak
C:\Program Files\Defenza\Backup\pcd-as.exe.bk1
C:\Program Files\Defenza\Backup\quaratinepage.pj1.bak
C:\Program Files\Defenza\Backup\quaratinepage.pj1.bk1
C:\Program Files\Defenza\Backup\SBTEDef.idx.bak
C:\Program Files\Defenza\Backup\SBTEDef.idx.bk1
C:\Program Files\Defenza\Backup\scan-disable.pj1.bak
C:\Program Files\Defenza\Backup\scan-disable.pj1.bk1
C:\Program Files\Defenza\Backup\ScanBT.pj1.bak
C:\Program Files\Defenza\Backup\ScanBTover.pj1.bak
C:\Program Files\Defenza\Backup\scanchoice-up.pj1.bak
C:\Program Files\Defenza\Backup\scanchoice-up.pj1.bk1
C:\Program Files\Defenza\Backup\scanpage1.pj1.bak
C:\Program Files\Defenza\Backup\scanpage1.pj1.bk1
C:\Program Files\Defenza\Backup\scanpage2.pj1.bak
C:\Program Files\Defenza\Backup\scanpage2.pj1.bk1
C:\Program Files\Defenza\Backup\scanresults-over.pj1.bak
C:\Program Files\Defenza\Backup\scanresults-over.pj1.bk1
C:\Program Files\Defenza\Backup\Setting.ini.bak
C:\Program Files\Defenza\Backup\Setting.ini.bk1
C:\Program Files\Defenza\Backup\SettingCancel.pj1.bak
C:\Program Files\Defenza\Backup\SettingCancelover.pj1.bak
C:\Program Files\Defenza\Backup\Settingclose.pj1.bak
C:\Program Files\Defenza\Backup\Settingcloseover.pj1.bak
C:\Program Files\Defenza\Backup\Settinghelp.pj1.bak
C:\Program Files\Defenza\Backup\Settinghelpover.pj1.bak
C:\Program Files\Defenza\Backup\SettingOK.pj1.bak
C:\Program Files\Defenza\Backup\SettingOKover.pj1.bak
C:\Program Files\Defenza\Backup\settings-down.pj1.bak
C:\Program Files\Defenza\Backup\settings-down.pj1.bk1
C:\Program Files\Defenza\Backup\SettingSchedule.pj1.bak
C:\Program Files\Defenza\Backup\SettingScheduleDown.pj1.bak
C:\Program Files\Defenza\Backup\SettingScheduleover.pj1.bak
C:\Program Files\Defenza\Backup\SettingSet.pj1.bak
C:\Program Files\Defenza\Backup\SettingSetDown.pj1.bak
C:\Program Files\Defenza\Backup\SettingSetover.pj1.bak
C:\Program Files\Defenza\Backup\SettingUpdate.pj1.bak
C:\Program Files\Defenza\Backup\SettingUpdateDown.pj1.bak
C:\Program Files\Defenza\Backup\SettingUpdateover.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd1.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd1over.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd2.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd2over.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd3.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd3over.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd4.pj1.bak
C:\Program Files\Defenza\Backup\StateShowWnd4over.pj1.bak
C:\Program Files\Defenza\Backup\ThreadInfoClose.pj1.bak
C:\Program Files\Defenza\Backup\ThreadInfoCloseover.pj1.bak
C:\Program Files\Defenza\Backup\threat-over.pj1.bak
C:\Program Files\Defenza\Backup\threat-over.pj1.bk1
C:\Program Files\Defenza\Backup\txtbox-bg.pj1.bak
C:\Program Files\Defenza\Backup\txtbox-bg.pj1.bk1
C:\Program Files\Defenza\Backup\Updatepage.pj1.bak
C:\Program Files\Defenza\Backup\Updatepage.pj1.bk1
C:\Program Files\Defenza\DefinitionUpdates\Ver2512-2712.exe
C:\Program Files\Defenza\DefinitionUpdates\Ver2712-2853.exe
C:\Program Files\Defenza\DefinitionUpdates\Ver2853-2912.exe
C:\Program Files\Defenza\InMisc.dll
C:\Program Files\Defenza\MFC71.dll
C:\Program Files\Defenza\pcd-as.chm
C:\Program Files\Defenza\pcd-as.exe
C:\Program Files\Defenza\PcdasResults1.xml
C:\Program Files\Defenza\pcdreg.dll
C:\Program Files\Defenza\pcdscanner.exe
C:\Program Files\Defenza\SBCSScan.exe
C:\Program Files\Defenza\SBTE.dll
C:\Program Files\Defenza\SBTEDef.idx-backup
C:\Program Files\Defenza\SBTEDef.idx
C:\Program Files\Defenza\Setting\activate.ico
C:\Program Files\Defenza\Setting\contents\btCheckall.pj1
C:\Program Files\Defenza\Setting\contents\btCheckallover.pj1
C:\Program Files\Defenza\Setting\contents\btCleanMyPC.pj1
C:\Program Files\Defenza\Setting\contents\btCleanMyPCover.pj1
C:\Program Files\Defenza\Setting\contents\btCleanNowInResultPage.pj1
C:\Program Files\Defenza\Setting\contents\btCleanNowInResultPageover.pj1
C:\Program Files\Defenza\Setting\contents\btCleanUp.pj1
C:\Program Files\Defenza\Setting\contents\btCleanUpover.pj1
C:\Program Files\Defenza\Setting\contents\btClose1.pj1
C:\Program Files\Defenza\Setting\contents\btClose1over.pj1
C:\Program Files\Defenza\Setting\contents\btQDelete.pj1
C:\Program Files\Defenza\Setting\contents\btQDeleteover.pj1
C:\Program Files\Defenza\Setting\contents\btQQuarantine.pj1
C:\Program Files\Defenza\Setting\contents\btQQuarantineover.pj1
C:\Program Files\Defenza\Setting\contents\btquarantine.pj1
C:\Program Files\Defenza\Setting\contents\btquarantineover.pj1
C:\Program Files\Defenza\Setting\contents\btscancancel.pj1
C:\Program Files\Defenza\Setting\contents\btscancancelover.pj1
C:\Program Files\Defenza\Setting\contents\btscannow.pj1
C:\Program Files\Defenza\Setting\contents\btscannowover.pj1
C:\Program Files\Defenza\Setting\contents\btscanresult.pj1
C:\Program Files\Defenza\Setting\contents\btscanresultover.pj1
C:\Program Files\Defenza\Setting\contents\btSeeDetail.pj1
C:\Program Files\Defenza\Setting\contents\btSeeDetailover.pj1
C:\Program Files\Defenza\Setting\contents\btSelectFile.pj1
C:\Program Files\Defenza\Setting\contents\btSelectFileover.pj1
C:\Program Files\Defenza\Setting\contents\btSelectScanfoldFile.pj1
C:\Program Files\Defenza\Setting\contents\btSelectScanfoldFileover.pj1
C:\Program Files\Defenza\Setting\contents\btSelModeFull.pj1
C:\Program Files\Defenza\Setting\contents\btSelModeFullover.pj1
C:\Program Files\Defenza\Setting\contents\btselmodequick.pj1
C:\Program Files\Defenza\Setting\contents\btselmodequickover.pj1
C:\Program Files\Defenza\Setting\contents\btsetting.pj1
C:\Program Files\Defenza\Setting\contents\btSettingBrowse.pj1
C:\Program Files\Defenza\Setting\contents\btSettingBrowseover.pj1
C:\Program Files\Defenza\Setting\contents\btsettingover.pj1
C:\Program Files\Defenza\Setting\contents\btUnCheckall.pj1
C:\Program Files\Defenza\Setting\contents\btUnCheckallover.pj1
C:\Program Files\Defenza\Setting\contents\btupdateDB.pj1
C:\Program Files\Defenza\Setting\contents\btupdateDBover.pj1
C:\Program Files\Defenza\Setting\contents\btupdateLicense.pj1
C:\Program Files\Defenza\Setting\contents\btupdateLicenseover.pj1
C:\Program Files\Defenza\Setting\contents\btupdates.pj1
C:\Program Files\Defenza\Setting\contents\btupdatesover.pj1
C:\Program Files\Defenza\Setting\contents\close.pj1
C:\Program Files\Defenza\Setting\contents\closeover.pj1
C:\Program Files\Defenza\Setting\contents\help.pj1
C:\Program Files\Defenza\Setting\contents\helpover.pj1
C:\Program Files\Defenza\Setting\contents\ListHead.pj1
C:\Program Files\Defenza\Setting\contents\ListHeadover.pj1
C:\Program Files\Defenza\Setting\contents\mini.pj1
C:\Program Files\Defenza\Setting\contents\miniover.pj1
C:\Program Files\Defenza\Setting\contents\ScanBT.pj1
C:\Program Files\Defenza\Setting\contents\ScanBTover.pj1
C:\Program Files\Defenza\Setting\contents\SettingCancel.pj1
C:\Program Files\Defenza\Setting\contents\SettingCancelover.pj1
C:\Program Files\Defenza\Setting\contents\Settingclose.pj1
C:\Program Files\Defenza\Setting\contents\Settingcloseover.pj1
C:\Program Files\Defenza\Setting\contents\Settinghelp.pj1
C:\Program Files\Defenza\Setting\contents\Settinghelpover.pj1
C:\Program Files\Defenza\Setting\contents\SettingOK.pj1
C:\Program Files\Defenza\Setting\contents\SettingOKover.pj1
C:\Program Files\Defenza\Setting\contents\SettingSchedule.pj1
C:\Program Files\Defenza\Setting\contents\SettingScheduleDown.pj1
C:\Program Files\Defenza\Setting\contents\SettingScheduleover.pj1
C:\Program Files\Defenza\Setting\contents\SettingSet.pj1
C:\Program Files\Defenza\Setting\contents\SettingSetDown.pj1
C:\Program Files\Defenza\Setting\contents\SettingSetover.pj1
C:\Program Files\Defenza\Setting\contents\SettingUpdate.pj1
C:\Program Files\Defenza\Setting\contents\SettingUpdateDown.pj1
C:\Program Files\Defenza\Setting\contents\SettingUpdateover.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd1.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd1over.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd2.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd2over.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd3.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd3over.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd4.pj1
C:\Program Files\Defenza\Setting\contents\StateShowWnd4over.pj1
C:\Program Files\Defenza\Setting\contents\ThreadInfoClose.pj1
C:\Program Files\Defenza\Setting\contents\ThreadInfoCloseover.pj1
C:\Program Files\Defenza\Setting\icon.ico
C:\Program Files\Defenza\Setting\resource\bmpSettingPageBK.pj1
C:\Program Files\Defenza\Setting\resource\quaratinepage.pj1
C:\Program Files\Defenza\Setting\resource\scan-disable.pj1
C:\Program Files\Defenza\Setting\resource\scanchoice-up.pj1
C:\Program Files\Defenza\Setting\resource\scanpage1.pj1
C:\Program Files\Defenza\Setting\resource\scanpage2.pj1
C:\Program Files\Defenza\Setting\resource\scanresults-over.pj1
C:\Program Files\Defenza\Setting\resource\settings-down.pj1
C:\Program Files\Defenza\Setting\resource\threat-over.pj1
C:\Program Files\Defenza\Setting\resource\txtbox-bg.pj1
C:\Program Files\Defenza\Setting\resource\Updatepage.pj1
C:\Program Files\Defenza\Setting\Setting.ini
C:\Program Files\Defenza\SpywareSetting.ini
C:\Program Files\Defenza\SpywareString.ini
C:\Program Files\Defenza\SUpdate.dat
C:\Program Files\Defenza\SUpdate.exe
C:\Program Files\Defenza\uninstall.ico
C:\Program Files\Defenza\UpdateIDXDBDLL.dll
C:\WINDOWS\system32\cjmest.dll
C:\WINDOWS\system32\crawsity.ini
C:\WINDOWS\system32\esxethvj.dll
C:\WINDOWS\system32\ixqfyj.dll
C:\WINDOWS\system32\jmfvwwqn.dll
C:\WINDOWS\system32\nokbexvg.ini
C:\WINDOWS\system32\NUuBIkkj.ini
C:\WINDOWS\system32\NUuBIkkj.ini2
C:\WINDOWS\system32\pqjbhp.dll
C:\WINDOWS\system32\vfqqbxcr.dll
C:\WINDOWS\system32\ywndwhfx.dll
C:\WINDOWS\system32\yyiiemkv.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-02 au 2008-10-02 ))))))))))))))))))))))))))))))))))))
.
2008-10-02 18:55 . 2008-10-02 18:55 <REP> d-------- C:\Program Files\Navilog1
2008-10-01 23:05 . 2008-10-01 23:05 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-10-01 23:04 . <REP> C:\WINDOWS\LastGood.Tmp
2008-10-01 20:33 . 2008-10-01 20:33 <REP> d-------- C:\Program Files\Trend Micro
2008-09-29 12:32 . 2008-09-29 12:32 <REP> d-------- C:\Program Files\crocpopup+
2008-09-29 12:32 . 1998-06-24 00:00 108,336 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
2008-09-18 19:32 . 2008-09-18 19:32 <REP> d-------- C:\Program Files\StofWare
2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-18 16:27 . 2008-09-18 16:27 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-18 13:39 . 2008-09-18 13:39 <REP> d-------- C:\Program Files\Alwil Software
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-06 20:20 --------- d-----w C:\Documents and Settings\Marie - Pierre\Application Data\OpenOffice.org2
2008-08-06 20:16 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-08-06 14:50 --------- d-----w C:\Program Files\ExpertHelper
2008-08-06 14:33 --------- d-----w C:\Documents and Settings\Marie - Pierre\Application Data\LimeWire
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2007-10-09 16:38 41,384 ----a-w C:\Documents and Settings\Marie - Pierre\Application Data\GDIPFONTCACHEV1.DAT
2006-02-05 17:44 421 ----a-w C:\Program Files\Spybot - Search & Destroy.lnk
.
((((((((((((((((((((((((((((( snapshot@2008-10-01_21.09.34.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-16 17:34:48 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2008-08-13 13:03:26 65,536 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2008-08-13 13:03:26 798,720 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2008-10-02 19:20:26 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_548.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [X]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-27 98304]
"CrocPopup+ "="C:\Program Files\crocpopup+\Crocpopup+.exe" [2005-01-07 1007616]
"SoundMan"="SOUNDMAN.EXE" [2005-06-08 C:\WINDOWS\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-04-13 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=pqjbhp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2005-06-20 09:03 352256 C:\Program Files\acer\eRecovery\Monitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-05 05:00 208952 C:\WINDOWS\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaSync]
--a------ 2005-06-01 14:25 421888 C:\Program Files\acer\Acer eConsole\MediaSync.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-05 05:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
--a------ 2005-05-11 18:15 45056 c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-05 05:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-05 05:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-07-15 01:07 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
--a------ 2005-05-13 12:57 53248 C:\WINDOWS\system32\VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
--a------ 2005-05-13 12:57 143360 C:\WINDOWS\system32\VTTrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\WINDOWS\\System32\\dpvsetup.exe"=
"C:\\Program Files\\eChanblard\\emule.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\World of Warcraft Trial\\BackgroundDownloader.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 69632]
R2 Machnm32;Machnm32 Driver;C:\WINDOWS\System32\Machnm32.sys [2003-08-13 2304]
R3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 162176]
S3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
S3 UsbSagCom;Mobile Device Full USB Driver;C:\WINDOWS\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f80f300-28a1-11db-adb6-000fea2dab90}]
\Shell\AutoRun\command - J:\JDLightning\Windows\JDLightning.exe
.
Contenu du dossier 'Tâches planifiées'
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-02 21:20:40
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\PROGRAM FILES\ACER\ACER ECONSOLE\MEDIASERVERSERVICE.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\PASTISVC.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Heure de fin: 2008-10-02 21:23:35 - La machine a redémarré [Marie - Pierre]
ComboFix-quarantined-files.txt 2008-10-02 19:23:28
ComboFix4.txt 2008-10-02 16:32:10
ComboFix5.txt 2008-10-02 19:14:58
ComboFix3.txt 2008-10-02 16:51:38
ComboFix2.txt 2008-10-02 17:23:02
Avant-CF: 25ÿ736ÿ052ÿ736 octets libres
Après-CF: 25,697,222,656 octets libres
428 --- E O F --- 2008-09-19 11:31:21