ComboFix 08-11-27.01 - Propriétaire 2008-11-27 9:34:27.1 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.188 [GMT -5:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Propriétaire\Application Data\inst.exe
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\[u]0
/u07ECAEC.urr
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\[u]0
/u0016731
c:\program files\MyWebSearch\bar\Cache\[u]0
/u07EF1FC
c:\program files\MyWebSearch\bar\Cache\[u]0
/u07EF289.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u07EF325.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u07EF4DA.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u07EF5D4.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u250D5EE.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u250D6B9.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u250D774.bin
c:\program files\MyWebSearch\bar\Cache\[u]0
/u250D88E.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\gzrglq.dll
c:\windows\system32\iettmn.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\oblaprtu.dll
c:\windows\system32\qoMccCvw.dll
c:\windows\system32\rtCLlUtv.ini
c:\windows\system32\rtCLlUtv.ini2
c:\windows\system32\tmxfkgxf.dll
c:\windows\system32\vtUlLCtr.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-27 au 2008-11-27 ))))))))))))))))))))))))))))))))))))
.
2008-11-26 20:48 . 2008-11-26 20:48 <REP> d--hs---- c:\windows\ftpcache
2008-11-25 13:44 . 2008-11-25 13:44 <REP> d-------- c:\program files\HiYo
2008-11-25 13:44 . 2008-11-25 13:44 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\HiYo
2008-11-25 13:44 . 2008-11-25 13:44 <REP> d-------- c:\documents and settings\All Users\Application Data\HiYo
2008-11-24 21:51 . 2008-11-24 21:51 <REP> d-------- c:\program files\SPRILL
2008-11-24 21:47 . 2008-11-24 21:47 <REP> d-------- c:\program files\ReflexiveArcade
2008-11-24 21:47 . 2008-11-24 21:47 <REP> d-------- c:\program files\Neptune's Secret
2008-11-24 21:46 . 2008-11-24 21:46 <REP> d-------- c:\program files\Mystery Stories Island of Hope
2008-11-24 21:45 . 2008-11-24 21:45 <REP> d-------- c:\program files\GameHouse
2008-11-24 21:45 . 2008-11-24 21:45 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\GameHouse
2008-11-24 21:45 . 2008-11-24 21:45 <REP> d-------- c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-11-24 21:44 . 2008-11-24 21:44 <REP> d-------- c:\program files\Mystere a Londres
2008-11-24 21:40 . 2008-11-24 21:40 <REP> d-------- c:\program files\Little Shop 3
2008-11-24 21:38 . 2008-11-24 21:38 <REP> d-------- c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-11-20 15:51 . 2008-11-20 15:51 268 --ah----- C:\sqmdata02.sqm
2008-11-20 15:51 . 2008-11-20 15:51 244 --ah----- C:\sqmnoopt02.sqm
2008-11-19 09:06 . 2008-11-19 09:06 <REP> d-------- c:\windows\Diner Dash Flo Through Time
2008-11-19 09:06 . 2008-11-19 09:06 <REP> d-------- c:\program files\Diner Dash Flo Through Time
2008-11-16 11:44 . 2008-09-03 15:28 <REP> d-------- c:\program files\Les Affaires Perdues de Sherlock Holmes
2008-11-16 11:41 . 2008-11-16 11:41 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\MysteryStudio
2008-11-12 16:24 . 2008-11-12 16:24 <REP> d-------- c:\program files\AskTBar
2008-11-12 10:38 . 2008-09-04 12:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 10:38 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 21:25 . 2008-11-11 21:25 <REP> d-------- c:\program files\Astonsoft
2008-11-11 21:25 . 2008-11-11 21:25 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\DeepBurner
2008-11-11 21:13 . 2008-11-11 21:13 <REP> d-------- c:\program files\Easy Avi Divx Xvid to DVD Burner
2008-11-11 21:13 . 2008-11-11 21:18 67 --a------ c:\windows\Easy Avi Divx Xvid to DVD Burner.INI
2008-11-11 21:06 . 2008-11-11 21:06 <REP> d-------- c:\program files\honestech Burn DVD 3.2 Trial
2008-11-11 20:28 . 2008-11-11 22:45 1,256,292,352 --a------ C:\image.iso
2008-11-11 19:38 . 2008-11-11 19:38 <REP> d-------- c:\program files\LimeWire
2008-11-10 13:24 . 2008-11-10 13:24 <REP> d-------- c:\program files\mIRC
2008-11-10 13:24 . 2008-11-10 13:24 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\mIRC
2008-11-07 19:46 . 2008-11-07 19:46 <REP> d-------- c:\program files\Cooking Academy
2008-11-07 19:46 . 2008-11-07 19:46 <REP> d-------- c:\documents and settings\All Users\Application Data\Fugazo
2008-11-06 11:11 . 2008-11-06 11:11 <REP> d-------- c:\windows\Jewelleria
2008-11-06 11:11 . 2008-11-06 11:11 <REP> d-------- c:\program files\Jewelleria
2008-11-06 11:11 . 2008-11-06 11:11 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\SulusGames
2008-11-05 14:19 . 2008-11-05 14:19 24 --ahs---- c:\windows\9D922F23F2EBBCB7
2008-10-27 13:34 . 2008-10-27 13:34 <REP> d-------- c:\program files\Wedding Dash
2008-10-27 13:05 . 2008-10-27 13:05 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\PlayFirst
2008-10-27 13:05 . 2008-10-27 13:05 <REP> d-------- c:\documents and settings\All Users\Application Data\PlayFirst
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-25 02:40 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 20:43 --------- d-----w c:\documents and settings\All Users\Application Data\vsosdk
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 03:34 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Zylom
2008-10-15 17:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-13 03:23 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2008-10-13 02:26 --------- d-----w c:\documents and settings\All Users\Application Data\Astar Games
2008-10-13 02:25 --------- d-----w c:\program files\Laura Jones and the Gates of Good and Evil
2008-10-13 02:20 --------- d-----w c:\program files\orange
2008-10-13 02:20 --------- d-----w c:\program files\GamesBar
2008-10-13 02:20 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-10-13 02:19 --------- d-----w c:\program files\Big City Adventures-Sydney Australia
2008-10-13 02:17 --------- d-----w c:\program files\Zylom Games
2008-10-13 02:17 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-10-08 18:08 --------- d-----w c:\documents and settings\Propriétaire\Application Data\InterVideo
2008-10-05 21:20 --------- d-----w c:\documents and settings\Propriétaire\Application Data\LimeWire
2008-10-05 21:19 --------- d-----w c:\program files\Google
2008-10-05 21:18 --------- d-----w c:\program files\Java
2008-10-05 21:18 --------- d-----w c:\program files\Fichiers communs\Java
2008-10-05 03:49 --------- d-----w c:\program files\Viewpoint
2008-10-05 03:49 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Viewpoint
2008-10-05 03:49 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2008-10-05 00:24 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-04 04:39 --------- d-----w c:\program files\SlySoft
2008-10-04 04:34 --------- d-----w c:\documents and settings\All Users\Application Data\SlySoft
2008-10-03 18:12 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-28 17:10 --------- d-----w c:\program files\MétéoMédia
2008-09-27 22:18 --------- d-----w c:\documents and settings\Propriétaire\Application Data\U3
2008-09-23 19:21 60,416 ----a-w c:\windows\ALCFDRTM.EXE
2008-09-23 19:17 47,360 ----a-w c:\documents and settings\Propriétaire\Application Data\pcouffin.sys
2008-09-23 16:25 106,496 ----a-w c:\windows\system32\ATL71.DLL
2008-09-15 16:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 16:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 11:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-28 08:47 74,752 ----a-w c:\windows\system32\msw3prt.dll
2008-08-28 08:47 74,752 ------w c:\windows\system32\dllcache\msw3prt.dll
2008-08-28 08:47 105,472 ----a-w c:\windows\system32\win32spl.dll
2008-08-28 08:47 105,472 ------w c:\windows\system32\dllcache\win32spl.dll
2008-08-27 10:11 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"WeatherEye"="c:\program files\MétéoMédia\MétéoÉclair\WeatherEye.exe" [2008-09-04 4501912]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-16 68856]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-07-17 2153408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-25 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-25 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-25 114688]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-09-23 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"HiYo"="c:\program files\HiYo\bin\HiYo.exe" [2008-10-23 300336]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-04-15 c:\windows\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-04-23 c:\windows\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Nikon Monitor.lnk - c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=gzrglq.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-19 20:16 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a------ 2005-10-11 04:54 1687552 c:\program files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2005-10-11 10:55 163840 c:\program files\Fichiers communs\Roxio Shared\SharedCOM8\RoxWatchTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-03 19:02 36352 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-09-23 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-09-23 20560]
R2 Viewpoint Service;Viewpoint Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" [2008-10-04 30152]
R3 epstw2k;Pilote SCSI du port parallèle SCM;c:\windows\system32\DRIVERS\epstw2k.sys [2008-09-23 114944]
R3 scsiscan;Pilote de scanneur SCSI;c:\windows\system32\DRIVERS\scsiscan.sys [2008-09-23 11520]
S3 KTalk;KTalk;\??\c:\docume~1\PROPRI~1\LOCALS~1\Temp\ktalk.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acbea23f-3882-11d9-86b1-806d6172696f}]
\Shell\AutoRun\command - e:\autorun\cdstarter.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{27C9CE32-A649-4148-86E2-3ECAEC0F55F7} - c:\windows\system32\vtUlLCtr.dll
BHO-{ebc34eac-83dd-44e5-b0c1-7d853256c353} - c:\windows\system32\gzrglq.dll
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-27 09:38:24
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
c:\program files\FICHIERS COMMUNS\ROXIO SHARED\SHAREDCOM8\ROXMEDIADB.EXE
c:\program files\FICHIERS COMMUNS\ROXIO SHARED\SHAREDCOM8\ROXWATCH.EXE
c:\windows\SYSTEM32\MSPMSPSV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
c:\program files\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Heure de fin: 2008-11-27 9:40:03 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-27 14:40:00
Avant-CF: 36 476 682 240 octets libres
Après-CF: 37,441,077,248 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
319 --- E O F --- 2008-11-13 04:09:49