voilà le rapport de combofix
ComboFix 08-11-02.05 - Samantha 2008-11-03 22:34:29.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.523 [GMT 1:00]
Lancé depuis: c:\documents and settings\Samantha\Bureau\C-Fix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Ellen\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\documents and settings\Lucie\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\documents and settings\Samantha\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\documents and settings\Tatyana\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
K:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-03 au 2008-11-03 ))))))))))))))))))))))))))))))))))))
.
2008-11-03 21:00 . 2008-11-03 21:00 <REP> d-------- c:\windows\system32\Service
2008-11-03 12:16 . 2008-11-03 12:16 <REP> d-------- c:\documents and settings\Samantha\Application Data\Malwarebytes
2008-11-03 12:15 . 2008-11-03 12:16 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-03 12:15 . 2008-11-03 12:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-03 12:15 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-03 12:15 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-03 11:52 . 2008-11-03 11:52 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-11-03 11:50 . 2008-11-03 11:50 <REP> d-------- c:\windows\ERUNT
2008-11-03 02:09 . 2008-11-03 12:13 <REP> d-------- C:\SDFix
2008-11-02 20:07 . 2008-11-02 17:23 144,912 --a------ c:\windows\system32\drivers\tmcomm.sys
2008-11-02 20:07 . 2008-11-02 17:23 50,192 --a------ c:\windows\system32\drivers\tmactmon.sys
2008-11-02 20:07 . 2008-11-02 17:23 49,680 --a------ c:\windows\system32\drivers\tmevtmgr.sys
2008-11-02 20:06 . 2008-11-02 20:06 60,928 --a------ c:\windows\system32\xvyu5i4c.exe
2008-11-02 17:26 . 2007-08-22 10:16 46,456 -ra------ c:\windows\system32\exitwx.exe
2008-11-02 17:23 . 2008-11-02 17:23 1,195,448 --a------ c:\windows\system32\drivers\vsapint.sys
2008-11-02 17:23 . 2008-11-02 17:23 661,808 --a------ c:\windows\system32\UfWSC.cpl
2008-11-02 17:23 . 2008-11-02 17:23 334,352 --a------ c:\windows\system32\drivers\TM_CFW.sys
2008-11-02 17:23 . 2008-11-02 17:23 205,328 --a------ c:\windows\system32\drivers\tmxpflt.sys
2008-11-02 17:23 . 2008-11-02 17:23 80,400 --a------ c:\windows\system32\drivers\tmtdi.sys
2008-11-02 17:23 . 2008-11-02 17:23 36,368 --a------ c:\windows\system32\drivers\tmpreflt.sys
2008-11-02 16:46 . 2008-11-02 16:46 <REP> d-------- c:\program files\Microsoft.NET
2008-11-02 16:46 . 2008-11-02 16:46 <REP> d-------- c:\program files\Microsoft Works
2008-11-01 13:44 . 2008-11-01 13:44 <REP> d-------- c:\program files\MSBuild
2008-11-01 13:40 . 2008-11-01 13:44 <REP> d-------- c:\windows\SHELLNEW
2008-11-01 13:40 . 2008-11-01 13:40 <REP> dr-h----- C:\MSOCache
2008-11-01 13:40 . 2008-11-02 16:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-26 21:32 . 2001-08-23 17:47 8,704 --a------ c:\windows\system32\kbdjpn.dll
2008-10-26 21:32 . 2001-08-23 17:47 8,704 --a--c--- c:\windows\system32\dllcache\kbdjpn.dll
2008-10-26 21:32 . 2001-08-23 17:47 8,192 --a------ c:\windows\system32\kbdkor.dll
2008-10-26 21:32 . 2001-08-23 17:47 8,192 --a--c--- c:\windows\system32\dllcache\kbdkor.dll
2008-10-26 21:32 . 2008-04-14 04:31 6,144 --a------ c:\windows\system32\kbd106.dll
2008-10-26 21:32 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101c.dll
2008-10-26 21:32 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101b.dll
2008-10-26 21:32 . 2008-04-14 04:31 6,144 --a--c--- c:\windows\system32\dllcache\kbd106.dll
2008-10-26 21:32 . 2001-08-17 22:55 6,144 --a--c--- c:\windows\system32\dllcache\kbd101c.dll
2008-10-26 21:32 . 2001-08-17 22:55 6,144 --a--c--- c:\windows\system32\dllcache\kbd101b.dll
2008-10-26 21:32 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\kbd103.dll
2008-10-26 21:32 . 2001-08-17 22:55 5,632 --a--c--- c:\windows\system32\dllcache\kbd103.dll
2008-10-26 19:02 . 2008-10-26 19:02 <REP> d-------- c:\windows\Sun
2008-10-24 18:43 . 2008-10-24 18:43 <REP> d-------- c:\program files\MSXML 4.0
2008-10-24 14:54 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 19:14 . 2008-10-23 19:14 <REP> d--h----- c:\windows\PIF
2008-10-23 18:33 . 2008-04-14 03:34 92,160 --a------ c:\windows\system32\kswdmcap.ax
2008-10-23 18:33 . 2008-04-14 03:34 92,160 --a--c--- c:\windows\system32\dllcache\kswdmcap.ax
2008-10-23 18:33 . 2008-04-14 03:34 61,952 --a------ c:\windows\system32\kstvtune.ax
2008-10-23 18:33 . 2008-04-14 03:34 61,952 --a--c--- c:\windows\system32\dllcache\kstvtune.ax
2008-10-23 18:33 . 2008-04-14 03:33 54,784 --a------ c:\windows\system32\vfwwdm32.dll
2008-10-23 18:33 . 2008-04-14 03:33 54,784 --a--c--- c:\windows\system32\dllcache\vfwwdm32.dll
2008-10-23 18:33 . 2008-04-14 03:34 43,008 --a------ c:\windows\system32\ksxbar.ax
2008-10-23 18:33 . 2008-04-14 03:34 43,008 --a--c--- c:\windows\system32\dllcache\ksxbar.ax
2008-10-23 18:30 . 2008-10-23 18:30 <REP> d-------- c:\program files\Fichiers communs\FotoWire
2008-10-23 18:30 . 2008-10-23 18:30 <REP> d-------- c:\documents and settings\Lucie\Application Data\FotoWire
2008-10-23 18:29 . 2008-10-23 18:29 <REP> d-------- C:\SXS
2008-10-23 18:29 . 2004-02-25 17:03 53,248 -ra------ c:\windows\system32\InstMed.exe
2008-10-23 18:28 . 2008-10-23 18:30 <REP> d-------- c:\program files\Logitech
2008-10-23 18:28 . 2008-10-23 18:28 <REP> d-------- c:\program files\Fichiers communs\Logitech
2008-10-23 18:28 . 2004-02-14 05:04 469,696 --a------ c:\windows\system32\drivers\lvcm.sys
2008-10-23 18:28 . 2004-02-14 05:08 372,736 --a------ c:\windows\system32\LVUI2RC.dll
2008-10-23 18:28 . 1998-11-13 12:16 308,224 --a------ c:\windows\IsUn040c.exe
2008-10-23 18:28 . 2004-02-14 04:55 208,896 --a------ c:\windows\system32\lvcodec2.dll
2008-10-23 18:28 . 2004-02-14 05:01 204,800 --a------ c:\windows\system32\LVUI2.dll
2008-10-23 18:28 . 2004-02-14 04:53 110,592 --a------ c:\windows\system32\lvcoinst.dll
2008-10-23 18:28 . 2008-10-23 18:28 81,920 -r------- c:\windows\bwUnin-6.1.4.36-8876480L.exe
2008-10-23 18:28 . 2004-02-14 05:03 19,968 --a------ c:\windows\system32\drivers\LVUSBSta.sys
2008-10-23 18:28 . 2004-02-14 04:39 5,993 --a------ c:\windows\system32\lvcoinst.ini
2008-10-23 18:28 . 2008-10-23 18:28 260 --a------ c:\windows\_delis32.ini
2008-10-23 12:26 . 2008-11-02 16:46 <REP> d-------- c:\program files\eMule
2008-10-20 20:24 . 2008-10-20 20:24 <REP> dr------- c:\documents and settings\NetworkService\Mes documents
2008-10-20 10:06 . 2008-10-20 10:06 <REP> d-------- c:\documents and settings\Ellen\Application Data\vlc
2008-10-20 09:18 . 2008-10-20 09:18 <REP> d-------- c:\program files\Neuf
2008-10-19 16:01 . 2008-10-19 16:01 <REP> dr------- c:\documents and settings\NetworkService\Favoris
2008-10-18 12:24 . 2008-09-29 23:08 <REP> d--h----- c:\documents and settings\Guest\Voisinage réseau
2008-10-18 12:24 . 2008-09-29 23:08 <REP> d--h----- c:\documents and settings\Guest\Voisinage d'impression
2008-10-18 12:24 . 2008-09-29 21:16 <REP> d--h----- c:\documents and settings\Guest\Modèles
2008-10-18 12:24 . 2008-10-18 12:25 <REP> dr------- c:\documents and settings\Guest\Mes documents
2008-10-18 12:24 . 2008-09-29 23:08 <REP> dr------- c:\documents and settings\Guest\Menu Démarrer
2008-10-18 12:24 . 2008-10-18 12:25 <REP> dr------- c:\documents and settings\Guest\Favoris
2008-10-18 12:24 . 2008-11-01 13:38 <REP> d-------- c:\documents and settings\Guest\Bureau
2008-10-18 12:24 . 2008-10-18 12:24 <REP> d-------- c:\documents and settings\Guest
2008-10-15 16:45 . 2008-10-15 16:45 <REP> d-------- c:\documents and settings\Lucie\Application Data\Zoner
2008-10-15 15:39 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 15:39 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 15:39 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 15:39 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 15:39 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-15 15:39 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-11 18:20 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-10-11 18:20 . 2008-04-13 19:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-10-11 17:05 . 2008-10-11 17:05 <REP> d-------- c:\windows\EPSON PhotoStarter Essential
2008-10-11 17:05 . 2008-10-11 17:05 <REP> d-------- c:\windows\EPSON CardMonitor Essential
2008-10-11 17:05 . 2008-10-11 17:05 <REP> d-------- c:\documents and settings\All Users\Application Data\UDL
2008-10-11 17:05 . 2003-07-02 00:00 131,072 --a------ c:\windows\system32\Epcmlib.dll
2008-10-11 17:04 . 2008-10-11 17:04 <REP> d-------- c:\program files\ArcSoft
2008-10-11 17:04 . 2001-08-23 15:25 1,706,800 --a------ c:\windows\system32\gdiplus.dll
2008-10-11 17:04 . 1995-07-31 11:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-10-11 17:01 . 1999-06-15 10:31 96,768 --a------ c:\windows\SlantAdj.dll
2008-10-11 17:01 . 1999-12-07 01:03 73,216 --a------ c:\windows\ADE.DLL
2008-10-11 17:01 . 1999-04-26 23:17 3,136 --a------ c:\windows\Ade001.bin
2008-10-11 17:01 . 1999-08-09 22:50 72 --------- c:\windows\system32\epDPE.ini
2008-10-11 17:00 . 2008-10-11 17:03 <REP> d-------- c:\program files\Smart Panel
2008-10-11 17:00 . 2004-02-01 01:00 413,696 --a------ c:\windows\system32\PICSDK.dll
2008-10-11 17:00 . 2002-11-14 23:00 114,688 --a------ c:\windows\system32\EpPicPrt.dll
2008-10-11 17:00 . 2002-11-14 23:00 65,536 --a------ c:\windows\system32\EPPicMgr.dll
2008-10-11 17:00 . 2004-02-01 01:00 34,782 --a------ c:\windows\system32\EPPICPrinterDB.dat
2008-10-11 17:00 . 2004-02-01 01:00 27,030 --a------ c:\windows\system32\EPPICPattern1.dat
2008-10-11 17:00 . 2004-02-01 01:00 5,978 --a------ c:\windows\system32\EPPICLocal_FR.cfg
2008-10-11 17:00 . 2004-02-01 01:00 22 --a------ c:\windows\system32\PICSDK.ini
2008-10-11 16:59 . 2008-10-11 17:06 <REP> d-------- c:\program files\epson
2008-10-11 16:59 . 2004-04-20 06:03 79,654 --a------ c:\windows\system32\E_FLM9CE.DLL
2008-10-11 16:59 . 2003-05-21 03:27 64,000 --a------ c:\windows\system32\E_FBCB9CE.DLL
2008-10-11 16:59 . 2003-06-30 23:00 46,080 --a------ c:\windows\system32\escimgd.dll
2008-10-11 16:59 . 2000-06-07 02:01 34,304 --a------ c:\windows\system32\E_FBCH9CE.DLL
2008-10-11 16:59 . 2003-04-10 06:40 31,744 --a------ c:\windows\system32\E_DCINST.DLL
2008-10-11 16:59 . 2003-08-05 23:00 29,184 --a------ c:\windows\system32\escwiadn.dll
2008-10-11 16:59 . 2003-06-30 23:00 22,528 --a------ c:\windows\system32\esccmd.dll
2008-10-11 16:59 . 2008-10-11 16:59 25 --a------ c:\windows\CDE RX420FG.ini
2008-10-11 10:45 . 2008-10-21 17:57 16,384 --a------ c:\windows\DCEBoot.exe
2008-10-11 10:41 . 2008-10-11 10:44 <REP> d-------- c:\windows\nview
2008-10-11 10:41 . 2006-07-20 20:58 208,896 --a------ c:\windows\system32\nvudisp.exe
2008-10-11 10:41 . 2005-06-17 12:41 61,440 -ra------ c:\windows\system32\vuins32.dll
2008-10-11 10:41 . 2008-11-03 21:00 51,048 --a------ c:\windows\system32\nvapps.xml
2008-10-11 10:41 . 2005-11-16 15:51 42,496 -ra------ c:\windows\system32\drivers\fetnd5bv.sys
2008-10-11 10:41 . 2006-07-20 20:58 16,960 --a------ c:\windows\system32\nvdisp.nvu
2008-10-09 16:39 . 2008-10-09 16:39 <REP> d-------- c:\program files\Windows Media Connect 2
2008-10-09 16:38 . 2008-10-09 16:38 <REP> d-------- c:\windows\system32\LogFiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-03 20:39 --------- d-----w c:\documents and settings\All Users\Application Data\Trend Micro
2008-11-03 00:57 2,882 ----a-w c:\windows\system32\tmp.reg
2008-11-02 19:07 --------- d-----w c:\program files\Trend Micro
2008-10-10 06:58 82,944 ----a-w c:\windows\system32\o4Patch.exe
2008-10-10 06:58 82,944 ----a-w c:\windows\system32\IEDFix.C.exe
2008-10-01 13:51 87,552 ----a-w c:\windows\system32\VACFix.exe
2008-09-30 18:15 --------- d-----w c:\program files\Windows Live
2008-09-30 18:14 --------- dcsh--w c:\program files\Fichiers communs\WindowsLiveInstaller
2008-09-30 18:13 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-09-30 18:06 --------- d-----w c:\program files\Google
2008-09-29 22:09 9,388 ----a-w c:\windows\system32\drivers\iaStor.PNF
2008-09-29 22:09 7,280 ----a-w c:\windows\system32\drivers\viamraid.PNF
2008-09-29 22:09 63,240 ----a-w c:\windows\system32\drivers\Si3112r.PNF
2008-09-29 22:09 6,984 ----a-w c:\windows\system32\drivers\SiSRaid.PNF
2008-09-29 22:09 20,152 ----a-w c:\windows\system32\drivers\INFCACHE.1
2008-09-29 22:09 12,432 ----a-w c:\windows\system32\drivers\adpu320.PNF
2008-09-29 22:09 12,204 ----a-w c:\windows\system32\drivers\nvraid.PNF
2008-09-29 22:09 10,828 ----a-w c:\windows\system32\drivers\iaAHCI.PNF
2008-09-29 20:58 --------- d-----w c:\program files\Java
2008-09-29 20:30 --------- d-----w c:\program files\microsoft frontpage
2008-09-29 20:25 --------- d-----w c:\program files\Fichiers communs\Java
2008-09-29 20:20 --------- d-----w c:\program files\Services en ligne
2008-09-29 20:17 --------- d-----w c:\program files\Windows Plus
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-08 21:38 88,576 ----a-w c:\windows\system32\AntiXPVSTFix.exe
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-18 10:19 82,432 ----a-w c:\windows\system32\404Fix.exe
2008-08-14 13:23 2,147,328 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:23 2,025,984 ----a-w c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-20 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-10-23 16384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-20 7581696]
"EPSON Stylus Photo RX420 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE" [2004-04-09 98304]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-02-25 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-02-25 454656]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-02-25 212992]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-11-02 970808]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 c:\windows\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2006-07-20 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-10-23 169472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
R3 usbstor;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbscan;Pilote de scanneur USB;c:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\test\Command - Explorer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23a7a86a-96d4-11dd-87a6-00161763a5d3}]
\shell\test\Command - J:\Explorer.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-02 c:\windows\Tasks\At100.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-26 c:\windows\Tasks\At101.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-26 c:\windows\Tasks\At102.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-26 c:\windows\Tasks\At103.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-26 c:\windows\Tasks\At104.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-26 c:\windows\Tasks\At105.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At106.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At107.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At108.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-03 c:\windows\Tasks\At109.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At110.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-30 c:\windows\Tasks\At111.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-02 c:\windows\Tasks\At112.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At113.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-02 c:\windows\Tasks\At114.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-02 c:\windows\Tasks\At115.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-01 c:\windows\Tasks\At116.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-10-30 c:\windows\Tasks\At117.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-02 c:\windows\Tasks\At118.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-03 c:\windows\Tasks\At119.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
2008-11-02 c:\windows\Tasks\At120.job
- c:\windows\system32\xvyu5i4c.exe [2008-11-02 20:06]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-EoEngine - (no file)
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-03 22:38:14
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-03 22:39:16
ComboFix-quarantined-files.txt 2008-11-03 21:39:12
Avant-CF: 301 779 324 928 octets libres
Après-CF: 304,646,873,088 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
302 --- E O F --- 2008-10-24 17:44:06