Voici le rapport ComboFix :
ComboFix 08-10-12.01 - Ophélie 2008-10-13 23:13:12.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1759 [GMT 2:00]
Lancé depuis: C:\Users\Ophélie\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Users\Ophélie\AppData\Roaming\Adobe\crc.dat
C:\Windows\system32\MSINET.oca
----- BITS: Il y a peut-être des sites infectés -----
hxxp://lovelypornovideo.net
hxxp://pornotube30.net
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-13 au 2008-10-13 ))))))))))))))))))))))))))))))))))))
.
2008-10-13 23:12 . 2008-10-13 23:12 <REP> d-------- C:\32788R22FWJFW
2008-10-13 18:22 . 2008-10-13 18:22 <REP> d-------- C:\Program Files\Alwil Software
2008-10-13 18:22 . 2008-07-19 16:36 51,280 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2008-10-13 17:39 . 2008-10-13 17:39 <REP> d-------- C:\rsit
2008-10-13 17:39 . 2008-10-11 08:31 401,720 --a------ C:\Ophélie.exe
2008-10-11 08:31 . 2008-10-11 08:31 401,720 --a------ C:\HiJackThis.exe
2008-10-11 08:28 . 2008-10-11 08:28 <REP> d-------- C:\Users\All Users\ParetoLogic Anti-Spyware
2008-10-11 08:28 . 2008-10-11 08:28 <REP> d-------- C:\ProgramData\ParetoLogic Anti-Spyware
2008-10-10 18:16 . 2008-10-10 18:16 <REP> d-------- C:\Users\All Users\Downloaded Installations
2008-10-10 18:16 . 2008-10-10 18:16 <REP> d-------- C:\ProgramData\Downloaded Installations
2008-10-10 00:35 . 2008-10-11 22:23 3,044,640 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-10-10 00:35 . 2008-10-11 22:23 43,940 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-10-10 00:31 . 2008-10-10 00:31 <REP> d-------- C:\Users\All Users\ParetoLogic Anti-Virus PLUS
2008-10-10 00:31 . 2008-10-11 22:38 <REP> d-------- C:\Users\All Users\ParetoLogic
2008-10-10 00:31 . 2008-10-10 00:31 <REP> d-------- C:\ProgramData\ParetoLogic Anti-Virus PLUS
2008-10-10 00:31 . 2008-10-11 22:38 <REP> d-------- C:\ProgramData\ParetoLogic
2008-10-10 00:31 . 2008-10-11 22:38 <REP> d-------- C:\Program Files\ParetoLogic
2008-10-10 00:31 . 2008-10-11 22:38 <REP> d-------- C:\Program Files\Common Files\ParetoLogic
2008-10-10 00:12 . 2008-10-10 00:14 <REP> d-------- C:\SmitfraudFix
2008-10-09 19:20 . 2008-10-09 22:30 <REP> d-------- C:\Program Files\SpyNoMore
2008-10-09 19:20 . 2008-10-09 19:20 1,152 --a------ C:\Windows\System32\windrv.sys
2008-10-09 18:57 . 2008-10-09 18:57 <REP> d-------- C:\Users\Ophélie\AppData\Roaming\Malwarebytes
2008-10-09 18:57 . 2008-10-09 18:57 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-10-09 18:57 . 2008-10-09 18:57 <REP> d-------- C:\ProgramData\Malwarebytes
2008-10-09 18:57 . 2008-10-10 10:05 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-09 18:57 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-09 18:57 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
2008-10-09 09:38 . 2008-10-09 09:38 <REP> d-------- C:\Users\Ophélie\AppData\Roaming\Bitdefender
2008-10-09 09:07 . 2008-10-13 23:14 81,984 --a------ C:\Windows\System32\bdod.bin
2008-10-09 09:03 . 2008-10-09 09:04 <REP> d-------- C:\Users\All Users\BitDefender
2008-10-09 09:03 . 2008-10-09 09:04 <REP> d-------- C:\ProgramData\BitDefender
2008-10-09 09:03 . 2008-10-09 09:03 <REP> d-------- C:\Program Files\Softwin
2008-10-09 09:02 . 2008-10-09 09:03 <REP> d-------- C:\Program Files\Common Files\Softwin
2008-10-09 08:58 . 2008-10-09 08:58 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-08 23:13 . 2008-10-08 23:13 <REP> d-------- C:\Users\Ophélie\AppData\Roaming\Simply Super Software
2008-10-08 23:13 . 2008-10-08 23:13 <REP> d-------- C:\Users\All Users\Simply Super Software
2008-10-08 23:13 . 2008-10-08 23:13 <REP> d-------- C:\ProgramData\Simply Super Software
2008-10-08 23:13 . 2006-05-25 15:52 162,304 --a------ C:\Windows\System32\ztvunrar36.dll
2008-10-08 23:13 . 2003-02-02 20:06 153,088 --a------ C:\Windows\System32\UNRAR3.dll
2008-10-08 23:13 . 2005-08-26 01:50 77,312 --a------ C:\Windows\System32\ztvunace26.dll
2008-10-08 23:13 . 2002-03-06 01:00 75,264 --a------ C:\Windows\System32\unacev2.dll
2008-10-08 23:13 . 2006-06-19 13:01 69,632 --a------ C:\Windows\System32\ztvcabinet.dll
2008-10-08 22:59 . 2008-10-08 23:15 <REP> d-------- C:\Program Files\Trojan Remover
2008-10-08 22:42 . 2008-10-08 22:42 <REP> d-------- C:\Users\All Users\mlcrirgl
2008-10-08 22:42 . 2008-10-13 18:41 <REP> d-------- C:\Users\All Users\EnMnt
2008-10-08 22:42 . 2008-10-08 22:42 <REP> d-------- C:\Users\All Users\adwfkvwz
2008-10-08 22:42 . 2008-10-08 22:42 <REP> d-------- C:\ProgramData\mlcrirgl
2008-10-08 22:42 . 2008-10-13 18:41 <REP> d-------- C:\ProgramData\EnMnt
2008-10-08 22:42 . 2008-10-08 22:42 <REP> d-------- C:\ProgramData\adwfkvwz
2008-10-06 12:46 . 2008-10-10 00:12 5,544 --a------ C:\Windows\System32\tmp.reg
2008-10-06 12:46 . 2008-10-06 12:46 691 --a------ C:\Users\Ophélie\AppData\Roaming\GetValue.vbs
2008-10-06 12:46 . 2008-10-06 12:46 35 --a------ C:\Users\Ophélie\AppData\Roaming\SetValue.bat
2008-10-06 10:29 . 2008-10-06 10:29 <REP> d-------- C:\Users\Ophélie\AppData\Roaming\Grisoft
2008-10-06 10:27 . 2008-10-06 10:27 <REP> d-------- C:\Users\All Users\Grisoft
2008-10-06 10:27 . 2008-10-06 10:27 <REP> d-------- C:\ProgramData\Grisoft
2008-10-06 10:27 . 2007-05-30 14:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2008-10-06 09:53 . 2008-10-06 10:23 <REP> d--hs---- C:\Windows\T3Bo6WxpZQ
2008-10-06 09:53 . 2008-10-09 11:35 <REP> d-------- C:\Windows\System32\tz1
2008-10-06 09:53 . 2008-10-09 09:14 <REP> d-------- C:\Windows\System32\EV02
2008-10-06 09:53 . 2008-10-06 09:54 <REP> d-------- C:\Windows\System32\ci
2008-10-06 09:53 . 2008-10-06 09:53 <REP> d-------- C:\Temp\xp34
2008-10-06 09:53 . 2008-10-13 23:13 <REP> d-------- C:\Temp
2008-10-06 09:53 . 2008-10-06 09:53 79,080 --a------ C:\Windows\System32\zmyqnazrcw.exe
2008-10-03 10:27 . 2008-10-03 10:27 <REP> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-10-03 10:27 . 2008-04-07 05:38 22,872 -ra------ C:\Windows\System32\AdobePDFUI.dll
2008-10-03 09:49 . 2008-10-09 19:20 <REP> d-------- C:\Users\Ophélie\AppData\Roaming\Download Manager
2008-10-01 12:40 . 2008-10-01 12:40 382 --a------ C:\Windows\ODBC.INI
2008-09-28 21:47 . 2008-09-28 21:47 <REP> d-------- C:\Program Files\eRightSoft
2008-09-28 21:47 . 2008-09-28 21:47 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-09-28 19:31 . 2008-09-28 19:31 <REP> d-------- C:\Users\Ophélie\Bluetooth Software
2008-09-28 19:31 . 2008-09-28 19:31 <REP> d-------- C:\Users\Ophélie\Bluetooth Software
2008-09-28 19:29 . 2008-09-28 19:29 118 --a------ C:\Windows\System32\MRT.INI
2008-09-28 10:06 . 2008-09-28 10:06 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-09-26 13:13 . 2008-09-26 13:16 <REP> d-------- C:\Users\All Users\Lavasoft
2008-09-26 13:13 . 2008-09-26 13:16 <REP> d-------- C:\ProgramData\Lavasoft
2008-09-26 13:13 . 2008-09-26 13:13 <REP> d-------- C:\Program Files\Lavasoft
2008-09-26 12:53 . 2008-09-26 12:53 <REP> d-------- C:\Program Files\Guitar Pro 5
2008-09-26 12:51 . 2008-09-26 12:52 <REP> d-------- C:\Program Files\MagicDisc
2008-09-26 12:51 . 2008-07-28 17:19 116,736 --a------ C:\Windows\System32\drivers\mcdbus.sys
2008-09-24 19:07 . 2008-09-24 19:07 <REP> d-------- C:\Program Files\CCleaner
2008-09-23 09:25 . 2008-07-19 07:09 1,811,656 --a------ C:\Windows\System32\wuaueng.dll
2008-09-23 09:25 . 2008-07-19 05:44 1,524,736 --a------ C:\Windows\System32\wucltux.dll
2008-09-23 09:25 . 2008-07-19 07:09 563,912 --a------ C:\Windows\System32\wuapi.dll
2008-09-23 09:25 . 2008-07-18 22:08 163,904 --a------ C:\Windows\System32\wuwebv.dll
2008-09-23 09:25 . 2008-07-19 05:44 83,456 --a------ C:\Windows\System32\wudriver.dll
2008-09-23 09:25 . 2008-07-19 07:10 53,448 --a------ C:\Windows\System32\wuauclt.exe
2008-09-23 09:25 . 2008-07-19 07:10 45,768 --a------ C:\Windows\System32\wups2.dll
2008-09-23 09:25 . 2008-07-19 07:10 36,552 --a------ C:\Windows\System32\wups.dll
2008-09-23 09:25 . 2008-07-18 20:44 31,232 --a------ C:\Windows\System32\wuapp.exe
2008-09-15 00:02 . 2008-09-15 00:03 <REP> d-------- C:\Program Files\Audio - Video
2008-09-15 00:00 . 2008-09-15 00:00 <REP> d-------- C:\Program Files\Utilitaires
2008-09-14 18:11 . 2008-09-14 18:11 <REP> d-------- C:\Program Files\IKEA HomePlanner
2008-09-14 18:10 . 2008-09-26 13:13 <REP> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-14 12:45 . 2008-10-01 08:26 <REP> d-------- C:\Users\All Users\FLEXnet
2008-09-14 12:45 . 2008-10-01 08:26 <REP> d-------- C:\ProgramData\FLEXnet
2008-09-13 21:25 . 2008-09-28 10:05 <REP> d-------- C:\Program Files\VistaCodecPack
2008-09-13 21:23 . 2008-09-13 21:23 <REP> d-------- C:\Users\All Users\VistaCodecs
2008-09-13 21:23 . 2008-09-13 21:23 <REP> d-------- C:\ProgramData\VistaCodecs
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-13 21:18 4,718,592 --sha-w C:\Users\Ophélie\ntuser.dat
2008-10-13 21:18 4,718,592 --sha-w C:\Users\Ophélie\ntuser.dat
2008-10-13 21:14 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Adobe
2008-10-13 20:45 --------- d-----w C:\Users\Ophélie\AppData\Roaming\uTorrent
2008-10-11 20:17 1,890 ----a-w C:\Windows\System32\ealregsnapshot1.reg
2008-10-11 20:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-11 20:17 --------- d-----w C:\Program Files\Electronic Arts
2008-10-11 06:31 401,720 ----a-w C:\Ophélie.exe
2008-10-10 16:13 --------- d---a-w C:\ProgramData\TEMP
2008-10-09 20:39 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-10-09 17:20 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Download Manager
2008-10-09 16:57 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Malwarebytes
2008-10-09 07:38 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Bitdefender
2008-10-08 21:13 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Simply Super Software
2008-10-06 10:46 691 ----a-w C:\Users\Ophélie\AppData\Roaming\GetValue.vbs
2008-10-06 10:46 35 ----a-w C:\Users\Ophélie\AppData\Roaming\SetValue.bat
2008-10-06 09:13 --------- d-s---w C:\Users\Ophélie\AppData\Roaming\Microsoft
2008-10-06 08:29 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Grisoft
2008-10-03 08:26 --------- d-----w C:\Program Files\Common Files\Adobe
2008-10-01 13:51 87,552 ----a-w C:\Windows\System32\VACFix.exe
2008-10-01 06:26 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Winamp
2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\o4Patch.exe
2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\IEDFix.C.exe
2008-09-12 08:15 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Apple Computer
2008-09-12 08:14 --------- d-----w C:\ProgramData\Apple Computer
2008-09-12 08:14 --------- d-----w C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-12 08:14 --------- d-----w C:\Program Files\iTunes
2008-09-12 08:13 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Real
2008-09-12 08:13 --------- d-----w C:\Program Files\QuickTime
2008-09-12 08:13 --------- d-----w C:\Program Files\Common Files\Apple
2008-09-12 08:12 --------- d-----w C:\ProgramData\Apple
2008-09-12 08:10 --------- d-----w C:\Program Files\Real
2008-09-12 08:10 --------- d-----w C:\Program Files\Common Files\xing shared
2008-09-12 08:10 --------- d-----w C:\Program Files\Common Files\Real
2008-09-12 08:08 --------- d-----w C:\Program Files\Java
2008-09-12 08:06 --------- d-----w C:\Program Files\Common Files\Java
2008-09-11 18:13 --------- d-----w C:\Users\Ophélie\AppData\Roaming\SPORE
2008-09-11 17:45 --------- d-----w C:\ProgramData\LightScribe
2008-09-11 17:38 --------- d-----w C:\ProgramData\Electronic Arts
2008-09-11 05:30 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-09-11 05:28 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-09-11 05:27 --------- d-----w C:\Users\Ophélie\AppData\Roaming\DAEMON Tools
2008-09-09 21:38 --------- d-----w C:\Program Files\Acer GameZone
2008-09-09 20:25 --------- d-----w C:\Program Files\Winamp
2008-09-09 20:17 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Nero
2008-09-09 20:17 --------- d-----w C:\Program Files\Common Files\Nero
2008-09-09 20:16 --------- d-----w C:\ProgramData\Nero
2008-09-09 20:16 --------- d-----w C:\Program Files\Nero
2008-09-09 18:03 --------- d-----w C:\Users\Ophélie\AppData\Roaming\CyberLink
2008-09-09 18:00 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-09 17:55 --------- d-----w C:\Program Files\Microsoft Works
2008-09-09 17:49 --------- d-----w C:\Program Files\Video Convert Master
2008-09-09 17:48 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Vso
2008-09-09 17:47 81,920 ----a-w C:\Users\Ophélie\AppData\Roaming\ezpinst.exe
2008-09-09 17:47 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-09-09 17:47 47,360 ----a-w C:\Users\Ophélie\AppData\Roaming\pcouffin.sys
2008-09-09 16:34 --------- d-----w C:\Users\Ophélie\AppData\Roaming\WinRAR
2008-09-09 11:48 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-09 11:44 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-09 11:29 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-09-09 11:29 --------- d-----w C:\Program Files\Windows Live
2008-09-09 11:25 --------- d-----w C:\ProgramData\WLInstaller
2008-09-09 11:21 --------- d-----w C:\Program Files\uTorrent
2008-09-09 10:42 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Mozilla
2008-09-09 07:44 --------- d-----w C:\ProgramData\McAfee
2008-09-09 07:42 --------- d-----w C:\ProgramData\SiteAdvisor
2008-09-09 07:28 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Identities
2008-09-09 07:27 --------- d-----w C:\Users\Ophélie\AppData\Roaming\Macromedia
2008-09-09 07:27 --------- d-----w C:\Program Files\Acer
2008-09-09 07:24 --------- d-sh--w C:\ProgramData\Modèles
2008-09-09 07:24 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-09-09 07:24 --------- d-sh--w C:\ProgramData\Favoris
2008-09-09 07:24 --------- d-sh--w C:\ProgramData\Bureau
2008-09-09 07:24 --------- d-sh--w C:\Program Files\Fichiers communs
2008-09-08 21:38 88,576 ----a-w C:\Windows\System32\AntiXPVSTFix.exe
2008-08-18 10:19 82,432 ----a-w C:\Windows\System32\404Fix.exe
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-07-25 08:34 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\Windows\System32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-07-16 18:51 2,041,363 ----a-w C:\Windows\System32\x264vfw.dll
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 02:00 39472 --a------ C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"ParetoLogic Anti-Spyware"="C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" [2006-10-11 2613248]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Adobe Reader Speed Launcher"="c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-08-28 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-08-28 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-08-28 137752]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [2007-09-07 102400]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-10-10 1286144]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-01-03 521776]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2008-01-08 842248]
"PLFSetI"="C:\Windows\PLFSetI.exe" [2007-10-23 200704]
"WarReg_PopUp"="C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"Adobe Acrobat Speed Launcher"="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-10-05 967048]
"BDMCon"="c:\PROGRA~1\softwin\BITDEF~1\bdmcon.exe" [2007-04-02 290816]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 69632]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-08 C:\Windows\RtHDVCpl.exe]
C:\Users\Oph‚lie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2008-09-26 575488]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-08-28 739880]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2008-03-27 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{51C55F9E-C308-4c95-89AB-8858D8AFD819}"= "C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll" [2006-10-11 94208]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.divxa32"= divxa32.acm
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{6142F206-1869-45B6-B7A7-A193709123BF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{ADA7CF22-6C16-4A79-8094-D1013029FB69}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{79B3B07D-AC20-4AFE-86B1-3C47E3108258}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{15E569B6-6EE9-455B-926D-68A59C9B8BE3}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{09EB2569-6B1B-44E9-99D3-115913B1F260}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{3E38C4A3-2E69-4D99-B5FC-EE570EB03C07}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{393380AB-67C4-446B-9566-A2C45B0F245A}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{4B52C0C3-2E70-430A-8E86-0D2AF0DA788E}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{75212C3C-2CD7-42E2-89E3-F5E501839157}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:µTorrent
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-08-29 81448]
R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-08-29 99880]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-05-17 28464]
R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-08-29 17448]
R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-08-07 51712]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-07-23 180736]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dca9701-7e43-11dd-bf37-a8f5d7a3558f}]
\shell\Auto\command - H:\Start.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e71b93ef-4592-11dd-84c2-806e6f6e6963}]
\shell\AutoRun\command - E:\Office2003.exe
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Tâches planifiées'
2008-10-11 C:\Windows\Tasks\ParetoLogic Anti-Spyware.job
- C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe [2006-10-11 19:05]
2008-10-13 C:\Windows\Tasks\ParetoLogic Registration.job
- C:\Windows\system32\rundll32.exe [2006-11-02 11:45]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-EnMnt - C:\ProgramData\EnMnt\bivutyxe.exe
HKLM-Run-zmosdizlutpif - C:\Windows\system32\cfagzuonlxmmuaso.dll
HKLM-Run-SNM - C:\Program Files\SpyNoMore\SNM.exe
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-TkBellExe - realsched.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Users\Ophélie\AppData\Roaming\Mozilla\Firefox\Profiles\5vxi6rx3.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-13 23:18:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-13 23:19:21
ComboFix-quarantined-files.txt 2008-10-13 21:19:09
Avant-CF: 104,372,785,152 octets libres
Après-CF: 104,043,745,280 octets libres
331 --- E O F --- 2008-10-11 06:30:09