Voici le rapport combofix:
ComboFix 08-11-16.01 - katemouse 2008-11-16 22:56:15.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1206 [GMT 1:00]
Lancé depuis: c:\users\katemouse\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CYLBGFVA\ComboFix.exe
* Un nouveau point de restauration a été créé
.
[i] ADS - Windows: deleted 24 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AutoRun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-16 au 2008-11-16 ))))))))))))))))))))))))))))))))))))
.
2008-11-16 20:47 . 2008-11-16 21:14 300 --a------ c:\windows\System32\User Agent -- Post Platform
2008-11-16 20:31 . 2008-11-16 20:31 <REP> d-------- c:\users\All Users\Grisoft
2008-11-16 20:31 . 2008-11-16 20:31 <REP> d-------- c:\programdata\Grisoft
2008-11-16 14:34 . 2008-11-16 22:29 <REP> d-------- c:\program files\Ad-remover
2008-11-13 20:40 . 2008-11-16 09:38 <REP> d-------- c:\users\katemouse\.homeplayer
2008-11-13 20:39 . 2008-11-13 20:40 <REP> d-------- c:\program files\HomePlayer
2008-11-13 18:57 . 2008-11-13 18:57 <REP> d-------- c:\program files\FpTest
2008-11-13 10:04 . 2008-11-13 10:04 <REP> d-------- c:\program files\Freeplayer
2008-11-12 11:39 . 2008-02-23 05:38 170,496 --a------ c:\windows\System32\tcpipcfg.dll
2008-11-12 11:39 . 2008-02-23 03:41 22,528 --a------ c:\windows\System32\netiougc.exe
2008-11-12 11:38 . 2008-10-22 12:31 1,221,008 --a------ c:\windows\System32\zpeng25.dll
2008-11-12 10:56 . 2008-10-13 10:56 4 ----s---- c:\windows\system\WINDEAIV.ISD
2008-11-12 10:21 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 10:21 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 10:21 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-10 21:57 . 2008-11-10 21:57 <REP> d-------- c:\users\All Users\WindowsSearch
2008-11-10 21:57 . 2008-11-10 21:57 <REP> d-------- c:\programdata\WindowsSearch
2008-11-10 21:39 . 2008-11-11 01:34 2,828 --ahs---- c:\windows\System32\KGyGaAvL.sys
2008-11-10 21:39 . 2008-11-11 01:34 88 -r-hs---- c:\windows\System32\AD2D806586.sys
2008-11-10 21:38 . 2008-11-10 21:39 <REP> d-------- c:\users\katemouse\AppData\Roaming\Corel
2008-11-10 21:37 . 2008-11-10 21:37 <REP> d-------- c:\users\All Users\Corel
2008-11-10 21:37 . 2008-11-10 21:37 <REP> d-------- c:\programdata\Corel
2008-11-10 21:32 . 2008-11-10 21:32 <REP> d-------- c:\program files\Corel
2008-11-10 21:32 . 2008-11-10 21:35 <REP> d-------- c:\program files\Common Files\Corel
2008-10-29 21:07 . 2008-10-29 21:07 <REP> d-------- c:\program files\Trend Micro
2008-10-29 09:31 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-29 09:31 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-29 09:31 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-22 19:47 . 2008-10-22 19:51 <REP> d-------- c:\users\katemouse\AppData\Roaming\DivX
2008-10-22 19:43 . 2008-10-22 21:08 <REP> d-------- c:\program files\Common Files\PX Storage Engine
2008-10-22 18:00 . 2008-10-22 18:00 <REP> d-------- c:\users\katemouse\AppData\Roaming\NeroDigital(TM)
2008-10-22 17:27 . 2008-10-22 17:27 <REP> d-------- c:\users\All Users\LightScribe
2008-10-22 17:27 . 2008-10-22 17:27 <REP> d-------- c:\programdata\LightScribe
2008-10-22 17:06 . 2008-10-22 17:06 4,767 --a------ c:\windows\Irremote.ini
2008-10-22 16:42 . 2008-10-22 17:04 <REP> d-------- c:\program files\Nero
2008-10-22 16:39 . 2008-10-22 16:39 <REP> d-------- c:\program files\Common Files\LightScribe
2008-10-22 15:23 . 2007-06-25 22:03 111,332 --------- c:\windows\hpqins13.dat.temp
2008-10-22 09:40 . 2008-10-23 09:27 <REP> d-------- c:\users\katemouse\AppData\Roaming\Nero
2008-10-22 09:34 . 2008-10-22 17:36 <REP> d-------- c:\users\All Users\Nero
2008-10-22 09:34 . 2008-10-22 17:36 <REP> d-------- c:\programdata\Nero
2008-10-22 09:34 . 2008-10-22 17:24 <REP> d-------- c:\program files\Common Files\Nero
2008-10-20 10:07 . 2008-10-20 10:07 <REP> d-------- c:\users\katemouse\AppData\Roaming\Media Player Classic
2008-10-17 00:42 . 2008-11-12 17:53 51,792 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2008-10-16 22:48 . 2008-09-18 03:16 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-10-16 22:48 . 2008-08-27 02:06 288,768 --a------ c:\windows\System32\drivers\srv.sys
2008-10-16 22:47 . 2008-09-18 06:09 3,601,464 --a------ c:\windows\System32\ntkrnlpa.exe
2008-10-16 22:47 . 2008-09-18 06:09 3,549,240 --a------ c:\windows\System32\ntoskrnl.exe
2008-10-16 22:47 . 2008-10-02 02:32 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2008-10-16 22:47 . 2008-10-02 04:49 827,392 --a------ c:\windows\System32\wininet.dll
2008-10-16 22:44 . 2008-08-05 10:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-10-16 22:44 . 2008-08-05 10:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-10-16 22:44 . 2008-08-05 10:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-10-16 22:44 . 2008-08-05 10:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-10-16 22:44 . 2008-08-05 10:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-16 20:13 . 2008-10-16 20:13 <REP> d-------- c:\users\All Users\Log
2008-10-16 20:13 . 2008-10-16 20:15 <REP> d-------- c:\users\All Users\G DATA
2008-10-16 20:13 . 2008-10-16 20:13 <REP> d-------- c:\programdata\Log
2008-10-16 20:13 . 2008-10-16 20:15 <REP> d-------- c:\programdata\G DATA
2008-10-16 20:13 . 2008-10-16 20:13 <REP> d--hs---- C:\#GDATA.Trash.Store#
2008-10-16 20:11 . 2008-10-16 20:13 <REP> d-------- c:\program files\Common Files\G DATA
2008-10-16 20:10 . 2008-10-16 20:10 <REP> d-------- c:\users\katemouse\AppData\Roaming\InstallShield
2008-10-16 17:24 . 2008-10-16 17:24 <REP> d-------- c:\users\katemouse\AppData\Roaming\Micro Application
2008-10-16 17:23 . 2008-11-16 21:59 <REP> d-a------ c:\users\All Users\TEMP
2008-10-16 17:23 . 2008-11-16 21:59 <REP> d-a------ c:\programdata\TEMP
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-16 21:56 --------- d-----w c:\users\katemouse\AppData\Roaming\DNA
2008-11-16 21:34 --------- d-----w c:\programdata\Microsoft Help
2008-11-16 21:24 352,608 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2008-11-16 21:05 --------- d-----w c:\program files\MSN Messenger
2008-11-16 21:05 --------- d-----w c:\program files\DNA
2008-11-16 17:01 --------- d-----w c:\programdata\Spybot - Search & Destroy
2008-11-16 12:29 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-16 08:38 --------- d-----w c:\users\katemouse\AppData\Roaming\BitTorrent
2008-11-16 08:38 --------- d-----w c:\programdata\HP Product Assistant
2008-11-14 10:05 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-14 10:05 --------- d-----w c:\program files\Micro Application
2008-11-14 09:30 352,608 ---ha-w c:\windows\system32\drivers\vsconfig(251).xml
2008-11-13 23:42 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-13 09:14 --------- d-----w c:\users\katemouse\AppData\Roaming\vlc
2008-11-12 21:16 88,551 ----a-w c:\users\katemouse\AppData\Roaming\nvModes.dat
2008-11-12 09:49 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-11-08 16:35 33,433,763 ----a-w c:\windows\Internet Logs\vsmon_on_demand_2008_11_08_14_22_14_full.dmp.zip
2008-11-08 13:22 3,297,280 ----a-w c:\windows\Internet Logs\xDB7177.tmp
2008-10-31 08:34 --------- d-----w c:\users\katemouse\AppData\Roaming\Hewlett-Packard
2008-10-22 20:11 --------- d-----w c:\program files\Common Files\Roxio Shared
2008-10-22 20:10 --------- d-----w c:\programdata\Roxio
2008-10-22 15:10 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-22 15:10 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-22 11:32 293,776 ----a-w c:\windows\system32\drivers\vsdatant.sys
2008-10-22 11:31 46,480 ----a-w c:\windows\System32\vsutil_loc040c.dll
2008-10-21 08:50 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-21 08:40 --------- d-----w c:\users\katemouse\AppData\Roaming\Roxio
2008-10-20 13:59 93,257 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_10_20_15_50_00_small.dmp.zip
2008-10-20 13:54 5,512,330 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-10-19 00:53 242,176 ----a-w c:\windows\Internet Logs\xDB74B2.tmp
2008-10-17 15:20 837,120 ----a-w c:\windows\Internet Logs\xDB8249.tmp
2008-10-17 15:20 1,799,168 ----a-w c:\windows\Internet Logs\xDB8382.tmp
2008-10-17 13:00 3,016,704 ----a-w c:\windows\Internet Logs\xDB9C5D.tmp
2008-10-17 13:00 1,798,656 ----a-w c:\windows\Internet Logs\xDBA0A2.tmp
2008-10-16 23:42 --------- d-----w c:\program files\Alwil Software
2008-10-16 22:38 2,732,032 ----a-w c:\windows\Internet Logs\xDB730C.tmp
2008-10-16 22:38 1,789,952 ----a-w c:\windows\Internet Logs\xDB7417.tmp
2008-10-16 22:00 --------- d-----w c:\program files\Windows Mail
2008-10-16 18:40 --------- d-----w c:\program files\Hewlett-Packard
2008-10-16 07:57 352,616 ---ha-w c:\windows\system32\drivers\vsconfig(445).xml
2008-10-14 16:01 --------- d-----w c:\program files\Combined Community Codec Pack
2008-10-13 10:10 --------- d-----w c:\programdata\Yahoo! Companion
2008-10-09 08:52 --------- d-----w c:\program files\BitTorrent
2008-10-06 12:26 --------- d-----w c:\users\katemouse\AppData\Roaming\Thunderbird
2008-10-04 16:52 --------- d-----w c:\users\katemouse\AppData\Roaming\Yahoo!
2008-10-04 09:39 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 09:39 --------- d-----w c:\program files\iTunes
2008-10-04 09:38 --------- d-----w c:\programdata\Apple Computer
2008-10-04 09:38 --------- d-----w c:\program files\iPod
2008-10-02 12:09 --------- d-----w c:\program files\MSECache
2008-10-02 12:01 --------- d-----w c:\program files\MSBuild
2008-10-02 11:57 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-22 20:35 108,683 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_22_21_30_16_small.dmp.zip
2008-09-22 18:55 101,511 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_22_18_50_24_small.dmp.zip
2008-09-22 11:09 --------- d-----w c:\program files\Common Files\Adobe
2008-09-22 10:45 --------- d-----w c:\programdata\FLEXnet
2008-09-21 18:22 98,057 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_21_18_50_02_small.dmp.zip
2008-09-21 18:22 111,754 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_21_19_56_31_small.dmp.zip
2008-09-19 16:05 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-09-16 00:11 161,096 ----a-w c:\windows\System32\DivXCodecVersionChecker.exe
2008-09-13 16:43 103,466 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_13_15_16_27_small.dmp.zip
2008-09-09 10:31 1,610,752 ----a-w c:\windows\Internet Logs\xDB7464.tmp
2008-09-07 16:14 104,245 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_09_07_17_10_30_small.dmp.zip
2008-09-02 12:06 1,576,448 ----a-w c:\windows\Internet Logs\xDB7869.tmp
2008-08-29 08:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-08-27 13:31 92,160 ----a-w c:\windows\System32\ezUninst.exe
2008-08-27 13:31 85,504 ----a-w c:\windows\System32\ezShellStart.exe
2008-08-27 13:31 49,152 ----a-w c:\windows\System32\ezUPBHook.dll
2008-08-27 13:31 33,792 ----a-w c:\windows\System32\ezntsvc.exe
2008-08-27 13:31 241,664 ----a-w c:\windows\System32\ezSetup.exe
2008-08-27 13:31 15,360 ----a-w c:\windows\System32\ezMAPIHelper.exe
2008-07-04 14:21 174 --sha-w c:\program files\desktop.ini
2008-06-29 13:23 22 --sha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-07-28 11:46 160496 --a------ c:\program files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"BitTorrent DNA"="c:\users\katemouse\Program Files\DNA\btdna.exe" [2008-11-12 342336]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-01 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-01 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-01 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-12 81000]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2008-10-22 399504]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-10-22 981904]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-07 44128]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-09-03 19:12 111936 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
--a------ 2007-08-28 12:00 531272 c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
--a------ 2008-06-09 09:16 2363392 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2008-05-14 21:56 468264 c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-19 08:33 1233920 c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 21:43 729088 c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-09-16 12:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2008-03-28 01:05 1045800 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 2007-01-10 15:12 317128 c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{63E473AA-F42E-438A-967D-10594C088465}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{1A90FF4E-81FD-49EC-9AF3-13D3900B672C}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{1008E960-FD61-418F-82BE-D43B5CD952FC}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{AAB044DC-0ECB-4561-A13C-FBF00C273110}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{D7FF1023-08CE-4B7A-926C-10DADA14BCC0}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{B9B182D1-35E6-4224-B513-78D0FC634770}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{4CE3CB47-DC35-4495-9E80-25FA91560A48}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{1576F02E-3A66-45C5-9E3A-5121FB1F11DD}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{1BC4F933-64B1-492C-A255-702AFE873092}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{B30684C1-E3C3-440B-B5B3-7285D30F219B}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{36771738-54B7-4A49-9C1D-67E5B4CD668C}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
"{0E783F94-B720-4DA7-AEBE-C6258185FB27}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{DA296A10-9DB0-4B86-9CFA-668FE3F2F3D4}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{1E2C1796-2594-4781-A553-7E2E56999963}c:\\users\\katemouse\\program files\\dna\\btdna.exe"= UDP:c:\users\katemouse\program files\dna\btdna.exe:btdna.exe
"UDP Query User{9A24FB35-129E-49BC-9CE8-DE79196E7C67}c:\\users\\katemouse\\program files\\dna\\btdna.exe"= TCP:c:\users\katemouse\program files\dna\btdna.exe:btdna.exe
"TCP Query User{1BED0227-6925-48F9-9F60-517084351F60}c:\\users\\katemouse\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\users\katemouse\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{73D44474-059A-498A-91B1-3C7FFEDC67B5}c:\\users\\katemouse\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\users\katemouse\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{FF083115-4EFB-44A9-92D1-CE30827F719C}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{6C747823-8531-40A7-8FA4-D6E79010814D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CF536A77-EE81-41F8-9A05-8DB670C0D252}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{CC9F2E96-E3D4-4BEE-B10B-CCC35CB3EB8B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{43FDC484-8DC8-40B0-A958-57B5BF064669}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{72D1E481-FD4E-4B09-A233-E8D5A59466A6}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{1685E1E7-F3DC-4141-A24D-6AFBC9A1E971}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"{D0A4C594-B2D8-410E-9F27-C71ECD7B821F}"= c:\program files\HP\Digital Imaging\bin\hpqpse.exe:hpqpse.exe
"{CB7DF873-78A0-44A9-A51F-705005D8A41A}"= c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe
"{B523222F-038E-4C31-AFC9-851BFFABC4BA}"= c:\program files\HP\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe
"{6619C05F-D7AB-4601-BFC0-0EF86D58A10D}"= c:\program files\HP\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe
"{CC6ADC79-4D63-409C-A01C-B9786D4E36EA}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{576C7F5F-1972-453D-923B-4C328AC9C204}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{A54E425C-4476-4099-A44D-E95A135ABE89}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-17 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-10-17 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2008-10-17 51792]
R2 MBAMService;MBAMService;"c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe" [2008-09-09 170640]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-24 935208]
R2 QPCapSvc;QuickPlay Background Capture Service (QBCS);"c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe" [2008-06-29 292248]
R2 QPSched;QuickPlay Task Scheduler (QTS);"c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe" [2008-06-29 116112]
R3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys [2008-09-09 15504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Scan for katemouse.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]
2008-11-16 c:\windows\Tasks\Malwarebytes' Scheduled Update for katemouse.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2008-10-22 16:10]
2008-11-13 c:\windows\Tasks\NeroLiveEpgUpdate-PC-de-katemouse_katemouse.job
- c:\program files\Nero\Nero 9\Nero Live\NeroLive.exe [2008-09-18 12:51]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\users\katemouse\AppData\Roaming\Mozilla\Firefox\Profiles\86g351bh.default\
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - c:\users\katemouse\Program Files\DNA\plugins\npbtdna.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-16 22:59:25
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-16 23:01:20
ComboFix-quarantined-files.txt 2008-11-16 22:01:16
Avant-CF: 75 165 106 176 octets libres
Après-CF: 75,142,524,928 octets libres
319 --- E O F --- 2008-11-16 21:34:10