ComboFix 08-10-08.02 - Cédric 2008-10-08 20:41:27.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.961 [GMT -4:00]
Lancé depuis: C:\Documents and Settings\Cédric\Mes documents\Personnelle\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\tmp43.tmp
C:\WINDOWS\system32\tmp44.tmp
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NTNDIS
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-09 au 2008-10-09 ))))))))))))))))))))))))))))))))))))
.
2008-10-07 08:02 . 2008-10-07 08:02 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\XRay Engine
2008-10-07 08:02 . 2008-10-07 08:02 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\XRay Engine
2008-10-07 08:02 . 2008-10-07 08:02 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\XRay Engine
2008-10-07 07:45 . 2008-10-07 07:45 68 --ahs---- C:\WINDOWS\system32\windzfa0.sys
2008-10-06 21:25 . 2008-10-06 21:25 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-06 21:25 . 2008-10-06 21:25 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\Malwarebytes
2008-10-06 21:25 . 2008-10-06 21:25 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\Malwarebytes
2008-10-06 21:25 . 2008-10-06 21:25 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\Malwarebytes
2008-10-06 21:25 . 2008-10-06 21:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-06 21:25 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-06 21:25 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-06 21:14 . 2008-10-06 21:21 4,726 --a------ C:\Documents and Settings\Orph.egd
2008-10-06 21:12 . 2008-10-06 21:21 <REP> d-------- C:\ToolBar SD
2008-09-29 22:37 . 2008-09-29 22:37 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\zvprt40
2008-09-29 22:37 . 2008-09-29 22:37 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\zvprt40
2008-09-29 22:37 . 2008-09-29 22:37 <REP> d-------- C:\Documents and Settings\Cédric\Application Data\zvprt40
2008-09-29 22:37 . 2005-05-27 19:19 9,141 --a------ C:\WINDOWS\system32\zvprtmon.dll
2008-09-29 22:37 . 2005-05-27 19:19 8,407 --a------ C:\WINDOWS\system32\zvprtmonui.dll
2008-09-29 22:36 . 2008-09-29 22:37 <REP> d-------- C:\Program Files\zvprt40
2008-09-29 22:36 . 2008-09-29 22:36 <REP> d-------- C:\Program Files\Tukanas Files Converter
2008-09-28 16:21 . 2008-09-28 16:21 <REP> d-------- C:\Program Files\CCleaner
2008-09-27 19:45 . 2008-05-30 14:11 3,850,760 --a------ C:\WINDOWS\system32\D3DX9_38.dll
2008-09-27 19:45 . 2008-05-30 14:11 1,491,992 --a------ C:\WINDOWS\system32\D3DCompiler_38.dll
2008-09-27 19:45 . 2008-05-30 14:19 507,400 --a------ C:\WINDOWS\system32\XAudio2_1.dll
2008-09-27 19:45 . 2008-03-05 16:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll
2008-09-27 19:45 . 2008-05-30 14:11 467,984 --a------ C:\WINDOWS\system32\d3dx10_38.dll
2008-09-27 19:45 . 2008-05-30 14:18 238,088 --a------ C:\WINDOWS\system32\xactengine3_1.dll
2008-09-27 19:45 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll
2008-09-27 19:45 . 2008-05-30 14:17 65,032 --a------ C:\WINDOWS\system32\XAPOFX1_0.dll
2008-09-27 19:45 . 2008-05-30 14:17 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_4.dll
2008-09-27 19:45 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll
2008-09-27 19:44 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-09-27 19:44 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\system32\d3dx9_36.dll
2008-09-27 19:44 . 2008-03-05 15:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll
2008-09-27 19:44 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\system32\D3DCompiler_36.dll
2008-09-27 19:44 . 2008-02-05 23:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll
2008-09-27 19:44 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\system32\d3dx10_36.dll
2008-09-27 19:44 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\system32\xactengine2_10.dll
2008-09-27 19:42 . 2008-09-27 19:42 <REP> d-------- C:\WINDOWS\Logs
2008-09-27 11:05 . 2008-10-05 17:44 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-27 11:05 . 2008-10-05 17:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-17 20:41 . 2008-09-17 20:41 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-09-14 11:58 . 2008-09-14 11:58 <REP> d-------- C:\Program Files\SystemRequirementsLab
2008-09-13 14:31 . 2008-09-13 14:31 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-13 14:31 . 2008-09-13 14:31 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-13 14:31 . 2008-09-13 14:31 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-13 14:29 . 2008-09-13 14:31 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-13 14:22 . 2008-09-13 14:22 <REP> d-------- C:\WINDOWS\EHome
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 00:44 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-10-08 22:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-10-04 02:02 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Xfire
2008-10-04 02:02 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Xfire
2008-10-04 02:02 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Xfire
2008-09-28 00:28 138,280 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-28 00:18 --------- d-----w C:\Documents and Settings\Cédric\Application Data\IGN_DLM
2008-09-28 00:18 --------- d-----w C:\Documents and Settings\Cédric\Application Data\IGN_DLM
2008-09-28 00:18 --------- d-----w C:\Documents and Settings\Cédric\Application Data\IGN_DLM
2008-09-27 23:47 279,712 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys
2008-09-27 23:47 25,888 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys
2008-09-27 22:38 --------- d-----w C:\Program Files\Cheat Engine
2008-09-13 22:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-13 21:01 --------- d-----w C:\Program Files\MSN Messenger
2008-09-11 00:40 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Move Networks
2008-09-11 00:40 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Move Networks
2008-09-11 00:40 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Move Networks
2008-09-07 18:37 --------- d-----w C:\Documents and Settings\Cédric\Application Data\SPORE
2008-09-07 18:37 --------- d-----w C:\Documents and Settings\Cédric\Application Data\SPORE
2008-09-07 18:37 --------- d-----w C:\Documents and Settings\Cédric\Application Data\SPORE
2008-09-02 02:10 --------- d-----w C:\Program Files\AviSynth 2.5
2008-09-02 02:09 --------- d-----w C:\Program Files\eRightSoft
2008-09-01 16:07 --------- d-----w C:\Documents and Settings\Cédric\Application Data\teamspeak2
2008-09-01 16:07 --------- d-----w C:\Documents and Settings\Cédric\Application Data\teamspeak2
2008-09-01 16:07 --------- d-----w C:\Documents and Settings\Cédric\Application Data\teamspeak2
2008-08-28 01:34 --------- d-----w C:\Program Files\Sony
2008-08-28 01:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-08-23 02:41 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Red Alert 3 Beta
2008-08-23 02:41 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Red Alert 3 Beta
2008-08-23 02:41 --------- d-----w C:\Documents and Settings\Cédric\Application Data\Red Alert 3 Beta
2008-08-23 01:48 --------- d-----w C:\Program Files\Tales of Pirates Online
2008-08-22 22:51 9,161 ----a-w C:\Program Files\unins000.dat
2008-08-22 22:50 667,913 ----a-w C:\Program Files\unins000.exe
2008-08-22 22:50 --------- d-----w C:\Program Files\Data
2008-08-20 03:07 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-20 01:24 24 ----a-w C:\Documents and Settings\Cédric\jagex_runescape_preferences.dat
2008-08-20 01:24 24 ----a-w C:\Documents and Settings\Cédric\jagex_runescape_preferences.dat
2008-08-18 13:54 --------- d-----w C:\Program Files\ArmA Edit
2008-08-14 23:53 --------- d-----w C:\Documents and Settings\Cédric\Application Data\gtk-2.0
2008-08-14 23:53 --------- d-----w C:\Documents and Settings\Cédric\Application Data\gtk-2.0
2008-08-14 23:53 --------- d-----w C:\Documents and Settings\Cédric\Application Data\gtk-2.0
2008-07-30 19:29 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-30 19:19 51,611 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-07-30 19:19 4,837 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-12-24 21:50 22,328 ----a-w C:\Documents and Settings\Cédric\Application Data\PnkBstrK.sys
2007-12-24 21:50 22,328 ----a-w C:\Documents and Settings\Cédric\Application Data\PnkBstrK.sys
2007-12-24 21:50 22,328 ----a-w C:\Documents and Settings\Cédric\Application Data\PnkBstrK.sys
2007-03-24 06:04 2,997,162 ----a-w C:\Program Files\BlitzMissions.big
2007-03-24 05:33 19,052,033 ----a-w C:\Program Files\BlitzMaps.big
2007-02-27 00:31 14,133,505 ----a-w C:\Program Files\BlitzINI.big
2007-02-16 09:46 17,416,436 ----a-w C:\Program Files\BlitzEnglish.big
2007-02-14 20:56 1,544 ----a-w C:\Program Files\Blitzkrieg2.exe.xml
2007-02-14 20:54 17,416,436 ----a-w C:\Program Files\BlitzSpanish.big
2007-02-14 20:52 17,416,436 ----a-w C:\Program Files\BlitzItalian.big
2007-02-14 20:52 17,416,427 ----a-w C:\Program Files\BlitzKorean.big
2007-02-14 20:51 195,520,736 ----a-w C:\Program Files\BlitzArt.big
2007-02-14 20:51 17,416,427 ----a-w C:\Program Files\BlitzGerman.big
2007-02-14 20:44 17,416,427 ----a-w C:\Program Files\BlitzFrench.big
2007-02-14 20:35 103,431,593 ----a-w C:\Program Files\BlitzAudio.big
2006-12-27 17:22 1 ----a-w C:\Documents and Settings\Cédric\SI.bin
2006-12-27 17:22 1 ----a-w C:\Documents and Settings\Cédric\SI.bin
2006-10-13 00:43 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2006-09-30 17:24 19,058 ----a-w C:\Program Files\Blitzkrieg2R2.6.jpeg
2006-09-30 07:40 554 ----a-w C:\Program Files\blitzlauncher.ini
2006-09-30 05:53 1,440,054 ----a-w C:\Program Files\Install_Final.bmp
2006-09-30 04:05 32 ----a-w C:\Program Files\blitz.ver
2006-09-27 19:16 8,497,631 ----a-w C:\Program Files\BlitzWindow.big
2006-09-27 15:14 966,656 ----a-w C:\Program Files\Blitzkrieg2.exe
2004-07-20 20:01 1,097,728 ----a-w C:\Program Files\blitzbuilder.exe
2004-07-20 19:49 48,045,763 ----a-w C:\Program Files\BlitzTerrain.big
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
2008-03-16 12:30 216,064 --sh--r C:\WINDOWS\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Steam"="f:\program files\steam\steam.exe" [2008-10-08 1410296]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"\\Pc-de-serge\EPSON Stylus Photo R220 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"igndlm.exe"="D:\Program Files\IGN\Download Manager\dlm.exe" [2008-08-01 1103216]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-03-14 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2006-06-09 110592]
"PCMService"="C:\Program Files\Acer TV-FM\PCMService.exe" [2006-03-29 143360]
"\\Pc-de-serge\EPSON Stylus Photo R220 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE" [2005-03-09 98304]
"lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-05-07 435120]
"lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-03-05 20480]
"FaxCenterServer"="C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" [2007-05-07 312240]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-01-31 51048]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-08-24 714608]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 286720]
"SansaDispatch"="C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe" [2007-10-22 75584]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 C:\WINDOWS\soundman.exe]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 C:\WINDOWS\sm56hlpr.exe]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
"VIDC.XFR1"= xfcodec.dll
"vidc.dvsd"= pdvcodec.dll
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Acer TV-FM\\PowerCinema.exe"=
"C:\\Program Files\\Acer TV-FM\\PCMService.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"F:\\StubInstaller.exe"=
"F:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"E:\\Program Files\\NovaLogic\\Joint Operations Typhoon Rising\\JOINTOPS.EXE"=
"F:\\Program Files\\Xfire\\Xfire.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"F:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"F:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"F:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"C:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"C:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"=
"C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"C:\\WINDOWS\\system32\\lxdicfg.exe"=
"C:\\WINDOWS\\system32\\lxdicoms.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"E:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"E:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"E:\\Program Files\\THQ\\Company of Heroes Opposing Fronts\\RelicCOH.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"C:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"E:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2.exe"=
"E:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter 2\\graw2_dedicated.exe"=
"D:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"D:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"F:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"E:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"E:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"E:\Program Files\Combat Arms\CombatArms.exe"= E:\Program Files\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"E:\Program Files\Combat Arms\Engine.exe"= E:\Program Files\Combat Arms\Engine.exe:*Enabled:Engine.exe
"E:\\Program Files\\Combat Arms\\NMService.exe"=
"E:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"E:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"E:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"E:\\Program Files\\Atari\\ArmA\\arma.exe"=
"E:\\Program Files\\Atari\\ArmA\\arma_server.exe"=
"D:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"D:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"E:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"E:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"D:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"D:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9103:UDP"= 9103:UDP:Supreme Commander
"30340:UDP"= 30340:UDP:Supreme Commander 2
"30341:UDP"= 30341:UDP:Supreme Commander 3
"28910:TCP"= 28910:TCP:Gamespy TCP 28910
"29900:TCP"= 29900:TCP:Gamespy TCP 29900
"29901:TCP"= 29901:TCP:Gamespy TCP 29901
"29920:TCP"= 29920:TCP:Gamespy TCP 29920
"27900:UDP"= 27900:UDP:Gamespy UDP 27900
"27901:UDP"= 27901:UDP:Gamespy UDP 27901
"29910:UDP"= 29910:UDP:Gamespy UDP 29910
"30260:UDP"= 30260:UDP:CoH UDP 30260
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 35328]
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe [2008-01-31 149864]
R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-04-26 517040]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2006-10-16 472832]
S2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-04-26 99248]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 DBKDRVR54;DBKDRVR54;C:\Program Files\Cheat Engine\dbk32.sys [ ]
S3 XDva025;XDva025;C:\WINDOWS\system32\XDva025.sys [ ]
S3 XDva078;XDva078;C:\WINDOWS\system32\XDva078.sys [ ]
S3 XDva081;XDva081;C:\WINDOWS\system32\XDva081.sys [ ]
S3 XDva092;XDva092;C:\WINDOWS\system32\XDva092.sys [ ]
S3 XDva093;XDva093;C:\WINDOWS\system32\XDva093.sys [2008-02-16 27605]
S3 XDva189;XDva189;C:\WINDOWS\system32\XDva189.sys [ ]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 402432]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c535093-6a0e-11dd-9c12-00155839ea51}]
\Shell\AutoRun\command - M:\CDGO.exe
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Tâches planifiées'
2008-10-07 C:\WINDOWS\Tasks\Norton Internet Security - Effectuer une analyse complète du système - Cédric.job
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 13:19]
2008-10-08 C:\WINDOWS\Tasks\User_Feed_Synchronization-{9B765A64-48AE-4C85-BBA0-0DCC44FEB1C9}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
2008-10-08 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 12:20]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Cédric\Application Data\Mozilla\Firefox\Profiles\lu1igjyf.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://sympatico.msn.ca/defaultf.aspx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-08 20:48:45
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Heure de fin: 2008-10-08 20:57:59 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-09 00:57:53
Avant-CF: 15 030 472 704 octets libres
Après-CF: 15,263,932,416 octets libres
338 --- E O F --- 2008-09-14 00:36:25
voila le rapport