ComboFix 08-10-19.04 - Principal 2008-10-20 19:24:16.2 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.97 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Principal\Bureau\Anti-virus,spyware\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\Principal\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
FILE ::
C:\Documents and Settings\All Users\Application Data\elipupaj.com
C:\Documents and Settings\Principal\Application Data\abel.reg
C:\Documents and Settings\Principal\Application Data\egywul.vbs
C:\Documents and Settings\Principal\Application Data\evoxa.exe
C:\Documents and Settings\Principal\Application Data\lucel.dll
C:\Documents and Settings\Principal\Application Data\rixadaw.bin
C:\Documents and Settings\Principal\Application Data\tofani.sys
C:\Documents and Settings\Principal\Application Data\usatoxyb.exe
C:\Documents and Settings\Principal\Application Data\wolyfe.dat
C:\Program Files\Fichiers communs\cocupu.bin
C:\Program Files\Fichiers communs\iqyrur.reg
C:\Program Files\Fichiers communs\kitiqo.dat
C:\Program Files\Fichiers communs\unacu.dat
C:\Program Files\Fichiers communs\wocydu.inf
C:\Program Files\Fichiers communs\xoratix.dll
C:\WINDOWS\baquqosupo.dll
C:\WINDOWS\bewihamo.com
C:\WINDOWS\cupamijyne.scr
C:\WINDOWS\ecojes._sy
C:\WINDOWS\efizinadez.inf
C:\WINDOWS\etaceq.bat
C:\WINDOWS\hisaxuge.exe
C:\WINDOWS\ihozap.reg
C:\WINDOWS\oqasyjin.inf
C:\WINDOWS\rediryjyw.sys
C:\WINDOWS\rusaba.lib
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\tahuhy.sys
C:\WINDOWS\system32\TDSSwpyd.dat
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\zypikyseli._dl
C:\WINDOWS\uqoboki.dat
C:\WINDOWS\urisanite.vbs
C:\WINDOWS\xosecezi.db
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\elipupaj.com
C:\Documents and Settings\Principal\Application Data\abel.reg
C:\Documents and Settings\Principal\Application Data\evoxa.exe
C:\Documents and Settings\Principal\Application Data\lucel.dll
C:\Documents and Settings\Principal\Application Data\usatoxyb.exe
C:\Program Files\Fichiers communs\iqyrur.reg
C:\Program Files\Fichiers communs\wocydu.inf
C:\Program Files\Fichiers communs\xoratix.dll
C:\WINDOWS\baquqosupo.dll
C:\WINDOWS\bewihamo.com
C:\WINDOWS\cupamijyne.scr
C:\WINDOWS\ecojes._sy
C:\WINDOWS\efizinadez.inf
C:\WINDOWS\etaceq.bat
C:\WINDOWS\hisaxuge.exe
C:\WINDOWS\ihozap.reg
C:\WINDOWS\oqasyjin.inf
C:\WINDOWS\rediryjyw.sys
C:\WINDOWS\rusaba.lib
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\AntiXPVSTFix.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\tahuhy.sys
C:\WINDOWS\system32\TDSSwpyd.dat
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\zypikyseli._dl
C:\WINDOWS\uqoboki.dat
C:\WINDOWS\urisanite.vbs
C:\WINDOWS\xosecezi.db
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-20 au 2008-10-20 ))))))))))))))))))))))))))))))))))))
.
2008-10-20 19:05 . 2008-10-20 19:05 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-20 19:05 . <REP> C:\WINDOWS\LastGood.Tmp
2008-10-20 18:57 . 2008-10-20 18:57 <REP> d-------- C:\Program Files\UsbFix
2008-10-20 18:39 . 2008-10-20 18:39 <REP> d-------- C:\WINDOWS\ERUNT
2008-10-20 18:17 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-10-20 18:17 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-10-20 18:17 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-10-20 18:17 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-20 17:52 . 2008-10-20 17:52 <REP> d-------- C:\Program Files\Trend Micro
2008-10-19 19:51 . 2008-10-16 12:17 <REP> d-------- C:\SDFix
2008-10-19 17:27 . 2008-10-19 17:27 <REP> d-------- C:\Program Files\Yahoo!
2008-10-19 17:27 . 2008-10-19 17:27 <REP> d-------- C:\Program Files\CCleaner
2008-10-19 17:22 . 2008-10-19 17:22 <REP> d-------- C:\Program Files\RegCleaner
2008-10-19 16:53 . 2008-10-19 16:53 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-19 16:53 . 2008-10-19 16:53 <REP> d-------- C:\Documents and Settings\Principal\Application Data\Malwarebytes
2008-10-19 16:53 . 2008-10-19 16:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-19 16:53 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-19 16:53 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-19 16:35 . 2008-10-20 08:53 2,504 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-19 15:11 . 2008-10-19 15:11 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-10-19 15:00 . 2005-11-30 19:34 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-10-19 15:00 . 2005-11-30 19:16 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-19 15:00 . 2005-11-30 19:16 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-19 15:00 . 2005-11-30 19:16 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-19 15:00 . 2005-11-30 19:43 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-10-19 15:00 . 2005-11-30 19:16 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-19 15:00 . 2005-11-30 19:43 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-10-19 15:00 . 2005-11-30 19:16 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-10-19 15:00 . 2005-11-30 19:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-10-19 15:00 . 2008-10-19 15:00 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-19 14:16 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-19 14:16 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-19 14:16 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-19 14:16 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-19 14:16 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-19 14:16 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-19 14:05 . 2008-10-19 14:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SITEguard
2008-10-19 14:01 . 2008-10-19 14:01 <REP> d-------- C:\Program Files\Fichiers communs\iS3
2008-10-19 14:01 . 2008-10-19 14:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-10-06 18:49 . 2008-10-06 18:49 <REP> d-------- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 13:00 --------- d-----w C:\Program Files\YDKJWIN
2008-09-19 12:57 --------- d-----w C:\Program Files\DAEMON Tools
2008-09-19 12:53 639,224 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-08-19 13:59 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-19 13:59 249,856 ------w C:\WINDOWS\Setup1.exe
2008-08-19 13:47 51,716 ----a-w C:\WINDOWS\system32\pdf995mon.dll
2008-08-19 13:47 249,856 ----a-w C:\WINDOWS\system32\pdfmona.dll
2006-01-13 17:12 1,018 ----a-w C:\Program Files\WinRAR.zip
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- C:\WINDOWS\Setup1.exe ----
Company: Microsoft Corporation
File Description: Visual Basic 6.0 Setup Toolkit
File Version: 6.00.9782
Product Name: Visual Basic
Copyright: Copyright (C) 1987-1999 Microsoft Corporation
Original file name: setup1.exe
MD5: c6264b17629f6f9f0bd2ba7671ceff69
---- C:\WINDOWS\ST6UNST.EXE ----
Company: Microsoft Corporation
File Description: Visual Basic Setup Toolkit Uninstaller
File Version: 6.00.9782
Product Name: Microsoft© Visual Basic for Windows
Copyright: Copyright ¸ 1987-2000 Microsoft Corp.
Original file name: ST6UNST.DLL
MD5: ea4e2ba0d35eeadee23b0c1397c71367
C:\WINDOWS\system32\pdf995mon.dll -- Unable to find file version info.
MD5: af238673651efc0226ea74239b502a6f
---- C:\WINDOWS\system32\pdfmona.dll ----
Company: TODO: <Company name>
File Description: TODO: <File description>
File Version: 1.0.0.1
Product Name: TODO: <Product name>
Copyright: TODO: (c) <Company name>. All rights reserved.
Original file name: pdfmona64.dll
MD5: 96b3d3a80bfe72450e63597de0ea4970
---- Directory of C:\Program Files\YDKJWIN ----
2008-10-08 19:13 935 --a------ C:\Program Files\YDKJWIN\Riviera\YDKJ.SET
2008-10-08 19:13 441620 --a------ C:\Program Files\YDKJWIN\Riviera\GrooveD.srf
2008-09-19 15:01 73728 --a------ C:\Program Files\YDKJWIN\Riviera\AAFntPlt.dat
2008-09-19 15:01 5640 --a------ C:\Program Files\YDKJWIN\Riviera\CDQList.win
2008-09-19 15:01 0 --a------ C:\Program Files\YDKJWIN\Riviera\UseOnce.win
2008-09-19 15:00 43 --a------ C:\Program Files\YDKJWIN\Riviera\ydkjf._hd
2008-09-19 15:00 3835 --a------ C:\Program Files\YDKJWIN\install.log
2008-09-19 15:00 145 --a------ C:\Program Files\YDKJWIN\Riviera\profile.ini
2008-09-17 13:16 8448 --a------ C:\Program Files\YDKJWIN\Riviera\BigQFile.win
2008-09-17 13:15 496168 --a------ C:\Program Files\YDKJWIN\Riviera\GrooveC.srf
2008-09-17 13:13 596844 --a------ C:\Program Files\YDKJWIN\Riviera\GrooveB.srf
2008-09-15 17:43 702092 --a------ C:\Program Files\YDKJWIN\Riviera\GrooveA.srf
2008-09-15 15:17 74 --a------ C:\Program Files\YDKJWIN\Riviera\HiScore.dkj
1998-08-05 20:30 133960 --a------ C:\Program Files\YDKJWIN\Riviera\qheaders.srf
1998-01-13 17:33 382616 --a------ C:\Program Files\YDKJWIN\Riviera\DDGameSd.srf
1998-01-13 17:28 16834784 --a------ C:\Program Files\YDKJWIN\Riviera\jacksnd1.srf
1998-01-13 17:22 2159312 --a------ C:\Program Files\YDKJWIN\Riviera\jattack1.srf
1998-01-13 17:14 1501640 --a------ C:\Program Files\YDKJWIN\Riviera\fonts.srf
1998-01-13 15:37 368640 --a------ C:\Program Files\YDKJWIN\ydkj32.exe
1998-01-05 14:09 3052 --a------ C:\Program Files\YDKJWIN\Riviera\usd.txt
1997-12-17 21:26 3756 --a------ C:\Program Files\YDKJWIN\lisezmoi.txt
1997-12-17 17:50 88644 --a------ C:\Program Files\YDKJWIN\Uninst.exe
1997-12-16 17:13 52 --a------ C:\Program Files\YDKJWIN\BMG.URL
1996-09-29 17:22 59824 --a------ C:\Program Files\YDKJWIN\UNWISE.EXE
1996-08-28 11:39 46 --a------ C:\Program Files\YDKJWIN\Bezerk.URL
((((((((((((((((((((((((((((( snapshot@2008-10-20_18.12.30.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-07 14:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-10-20 16:39:30 6,389,760 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000001\ntuser.dat
+ 2008-10-20 16:39:30 180,224 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000002\UsrClass.dat
+ 2008-08-07 14:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-10-20 16:39:22 6,389,760 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0/u0000001\ntuser.dat
+ 2008-10-20 16:39:22 180,224 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0/u0000002\UsrClass.dat
- 2005-05-26 02:16:24 75,544 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 17:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2005-05-26 02:16:24 75,544 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-30 17:19:20 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
- 2005-05-26 02:16:30 467,224 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2007-07-30 17:19:36 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2005-05-26 02:16:30 125,720 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2005-05-26 02:16:30 1,343,768 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2005-05-26 02:16:32 128,792 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-30 17:19:32 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2005-05-26 02:16:30 41,240 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2005-05-26 02:19:32 173,536 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 17:19:28 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
- 2005-05-26 02:16:30 467,224 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 17:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2005-05-26 02:16:30 125,720 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 17:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2005-05-26 02:16:30 1,343,768 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 17:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2005-05-26 02:16:32 128,792 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 17:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2005-05-26 02:16:30 41,240 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 17:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
- 2005-05-26 02:16:30 18,200 ----a-w C:\WINDOWS\system32\wups2.dll
+ 2007-07-30 17:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
- 2005-05-26 02:19:32 173,536 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 17:19:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 22058792]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-05-12 102400]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 688218]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2004-09-21 81920]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2005-05-10 11776]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-10-17 590848]
"mm_server"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_server.exe" [2005-05-10 102400]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SiSPower"="SiSPower.dll" [2005-02-16 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 219136]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2005-11-30 331776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSmhct.sys]
@="driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\System32\\rtcshare.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\LeechFTP\\Leechftp.exe"=
"C:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8321:TCP"= 8321:TCP:*:Disabled:emule
"16502:UDP"= 16502:UDP:*:Disabled:emule
R0 rmedia;Ricoh MediaCard Driver;C:\WINDOWS\system32\DRIVERS\rmedia.sys [2004-10-27 67456]
R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\system32\ASNDIS5.SYS [2002-09-09 16269]
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2004-06-17 193280]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 26496]
*Newly Created Service* - RMEDIA
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-20 19:28:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
C:\WINDOWS\SYSTEM32\ASWLSVC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM32\ASWL2K.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGUPSVC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MIM.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Heure de fin: 2008-10-20 19:31:35 - La machine a redémarré [Principal]
ComboFix-quarantined-files.txt 2008-10-20 17:31:28
ComboFix2.txt 2008-10-20 16:13:06
Avant-CF: 26,234,552,320 octets libres
Après-CF: 26,218,627,072 octets libres
324