Rapport de combo fix :
ComboFix 08-12-17.01 - Evelyne 2008-12-19 5:25:27.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1014.179 [GMT 1:00]
Lancé depuis: c:\documents and settings\Evelyne\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/B/COLOR
.
[color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:
/color
c:\windows\system32\ladasazo.dll
c:\windows\system32\kolopiro.dll
c:\windows\system32\yajosofo.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Evelyne\Local Settings\Application Data\ceaue.dat
c:\documents and settings\Evelyne\Local Settings\Application Data\ceaue.exe
c:\documents and settings\Evelyne\Local Settings\Application Data\ceaue_nav.dat
c:\documents and settings\Evelyne\Local Settings\Application Data\ceaue_navps.dat
c:\program files\internetgamebox
c:\program files\internetgamebox\language
c:\program files\internetgamebox\ressources\AttenteOff.html
c:\program files\internetgamebox\ressources\AttenteOn.html
c:\program files\internetgamebox\ressources\configv2_en.xml
c:\program files\internetgamebox\ressources\configv2_es.xml
c:\program files\internetgamebox\ressources\configv2_fr.xml
c:\program files\internetgamebox\ressources\favoris\defaultv2.swf
c:\program files\internetgamebox\skins\skinv2.skn
c:\windows\system32\awewibut.ini
c:\windows\system32\dasofupu.dll
c:\windows\system32\ekinuyit.ini
c:\windows\system32\hememefo.dll
c:\windows\system32\izohanek.ini
c:\windows\system32\kenahozi.dll
c:\windows\system32\kolopiro.dll.vir
c:\windows\system32\mafopiwo.dll
c:\windows\system32\mijikive.dll
c:\windows\system32\mizenode.dll
c:\windows\system32\onuzupup.ini
c:\windows\system32\pulobuha.dll
c:\windows\system32\pupuzuno.dll
c:\windows\system32\puzujoda.dll
c:\windows\system32\tiyunike.dll
c:\windows\system32\tubiwewa.dll
c:\windows\system32\tuneyevi.dll
c:\windows\system32\ufasezay.ini
c:\windows\system32\umapazug.ini
c:\windows\system32\uruyubof.ini
c:\windows\system32\uvuwehaw.ini
c:\windows\system32\vagivoho.dll
c:\windows\system32\wahewuvu.dll
c:\windows\system32\yajosofo.dll.vir
c:\windows\system32\yazesafu.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-19 au 2008-12-19 ))))))))))))))))))))))))))))))))))))
.
2008-12-19 05:39 . 2008-12-19 05:39 120 ---hs---- c:\windows\system32\uruyubof.ini
2008-12-19 04:28 . 2004-08-04 00:54 154,112 --a------ c:\windows\system32\irftp.exe
2008-12-19 04:28 . 2004-08-04 00:54 154,112 --a--c--- c:\windows\system32\dllcache\irftp.exe
2008-12-19 04:28 . 2004-08-04 00:54 28,160 --a------ c:\windows\system32\irmon.dll
2008-12-19 04:28 . 2004-08-04 00:54 28,160 --a--c--- c:\windows\system32\dllcache\irmon.dll
2008-12-19 04:28 . 2004-08-04 00:54 8,192 --a------ c:\windows\system32\wshirda.dll
2008-12-19 04:28 . 2004-08-04 00:54 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2008-12-18 17:03 . 2008-12-18 18:31 <REP> d-------- c:\windows\system32\CatRoot_bak
2008-12-18 15:34 . 2008-04-11 19:51 683,520 --a------ c:\windows\system32\SET18D.tmp
2008-12-18 15:33 . 2008-09-04 17:45 1,106,944 --a------ c:\windows\system32\SET17A.tmp
2008-12-18 15:26 . 2008-06-14 18:59 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-18 15:23 . 2008-12-18 15:23 <REP> d-------- c:\program files\Trend Micro
2008-12-18 15:19 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-18 15:19 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-18 15:19 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-18 15:19 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-18 14:06 . 2008-10-15 17:59 332,800 --a------ c:\windows\system32\SET17F.tmp
2008-12-18 13:15 . 2008-12-12 18:35 3,081,216 --a------ c:\windows\system32\SET1A0.tmp
2008-12-18 13:14 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-18 11:12 . 2006-12-07 07:40 2,362,184 --a------ c:\windows\system32\SET192.tmp
2008-12-18 10:59 . 2005-02-08 11:37 167,936 -ra------ c:\windows\system32\igfxres.dll
2008-12-18 10:45 . 2004-08-05 13:00 131,584 --a--c--- c:\windows\system32\dllcache\pmxviceo.dll
2008-12-18 10:44 . 2004-08-05 13:00 92,416 --a--c--- c:\windows\system32\dllcache\mga.sys
2008-12-18 10:44 . 2004-08-05 13:00 92,032 --a--c--- c:\windows\system32\dllcache\mga.dll
2008-12-18 10:44 . 2001-08-23 17:47 65,536 --a--c--- c:\windows\system32\dllcache\EXCH_mailmsg.dll
2008-12-18 10:44 . 2004-08-05 13:00 36,864 --a--c--- c:\windows\system32\dllcache\iprip.dll
2008-12-18 10:44 . 2004-08-05 13:00 33,792 --a--c--- c:\windows\system32\dllcache\lmmib2.dll
2008-12-18 10:44 . 2004-08-05 13:00 23,040 --a--c--- c:\windows\system32\dllcache\lpdsvc.dll
2008-12-18 10:44 . 2004-08-05 13:00 19,456 --a--c--- c:\windows\system32\dllcache\lprmon.dll
2008-12-18 10:44 . 2004-08-05 13:00 18,432 --a--c--- c:\windows\system32\dllcache\jupiw.dll
2008-12-18 10:44 . 2004-08-05 13:00 7,680 --a--c--- c:\windows\system32\dllcache\migregdb.exe
2008-12-18 10:42 . 2004-08-05 13:00 334,336 --a--c--- c:\windows\system32\dllcache\aqueue.dll
2008-12-18 10:41 . 2004-05-13 00:39 876,653 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
2008-12-18 10:39 . 2008-12-18 10:39 488 -rah----- c:\windows\system32\logonui.exe.manifest
2008-12-18 10:38 . 2004-08-05 13:00 16,384 --a--c--- c:\windows\system32\dllcache\isignup.exe
2008-12-18 10:38 . 2008-12-18 10:38 749 -rah----- c:\windows\WindowsShell.Manifest
2008-12-18 10:38 . 2008-12-18 10:38 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
2008-12-18 10:38 . 2008-12-18 10:38 749 -rah----- c:\windows\system32\sapi.cpl.manifest
2008-12-18 10:38 . 2008-12-18 10:38 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
2008-12-18 10:35 . 2004-08-05 13:00 218,624 --a--c--- c:\windows\system32\dllcache\icwconn1.exe
2008-12-18 10:35 . 2004-08-05 13:00 86,016 --a--c--- c:\windows\system32\dllcache\icwconn2.exe
2008-12-18 10:35 . 2004-08-05 13:00 32,768 --a--c--- c:\windows\system32\dllcache\icwdl.dll
2008-12-18 10:35 . 2004-08-05 13:00 20,480 --a--c--- c:\windows\system32\dllcache\inetwiz.exe
2008-12-18 10:11 . 2004-08-05 13:00 571,392 --a------ c:\windows\system32\TINTLGNT.IME
2008-12-18 10:11 . 2004-08-05 13:00 571,392 --a--c--- c:\windows\system32\dllcache\tintlgnt.ime
2008-12-18 10:11 . 2004-08-05 13:00 480,256 --a--c--- c:\windows\system32\dllcache\cintsetp.exe
2008-12-18 10:11 . 2004-08-05 13:00 455,168 --a--c--- c:\windows\system32\dllcache\tintsetp.exe
2008-12-18 10:11 . 2004-08-05 13:00 198,656 --a--c--- c:\windows\system32\dllcache\cintime.dll
2008-12-18 10:11 . 2004-08-05 13:00 173,568 --a--c--- c:\windows\system32\dllcache\chtskf.dll
2008-12-18 10:11 . 2004-08-05 13:00 97,792 --a--c--- c:\windows\system32\dllcache\chtmbx.dll
2008-12-18 10:11 . 2004-08-05 13:00 56,320 --a--c--- c:\windows\system32\dllcache\chtskdic.dll
2008-12-18 10:11 . 2004-08-05 13:00 44,032 --a--c--- c:\windows\system32\dllcache\tintlphr.exe
2008-12-18 10:11 . 2004-08-05 13:00 21,504 --a--c--- c:\windows\system32\dllcache\cintlgnt.ime
2008-12-18 10:11 . 2004-08-05 13:00 21,504 --a------ c:\windows\system32\CINTLGNT.IME
2008-12-18 10:11 . 2004-08-05 13:00 10,240 --a--c--- c:\windows\system32\dllcache\tmigrate.dll
2008-12-18 10:10 . 2004-08-05 13:00 10,096,640 --a--c--- c:\windows\system32\dllcache\hwxcht.dll
2008-12-18 10:10 . 2004-08-05 13:00 482,304 --a------ c:\windows\system32\PINTLGNT.IME
2008-12-18 10:10 . 2004-08-05 13:00 482,304 --a--c--- c:\windows\system32\dllcache\pintlgnt.ime
2008-12-18 10:10 . 2004-08-05 13:00 70,144 --a--c--- c:\windows\system32\dllcache\pintlphr.exe
2008-12-18 10:10 . 2004-08-05 13:00 67,584 --a--c--- c:\windows\system32\dllcache\pmigrate.dll
2008-12-18 10:10 . 2004-08-05 13:00 59,392 --a--c--- c:\windows\system32\dllcache\imscinst.exe
2008-12-18 10:10 . 2004-08-05 13:00 16,254 --a------ c:\windows\system32\PINTLPAE.HLP
2008-12-18 10:10 . 2004-08-05 13:00 14,821 --a------ c:\windows\system32\PINTLPAD.HLP
2008-12-17 14:35 . 2008-12-17 14:35 <REP> d-------- c:\documents and settings\Evelyne\Tracing
2008-12-17 14:34 . 2008-12-17 14:34 <REP> d-------- c:\program files\Microsoft Silverlight
2008-12-17 14:33 . 2008-12-17 14:33 <REP> d-------- c:\program files\Microsoft Office Outlook Connector
2008-12-17 14:33 . 2008-12-08 17:01 55,136 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys
2008-12-17 14:31 . 2008-12-17 14:31 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-12-17 14:31 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll
2008-12-17 14:28 . 2008-12-17 14:28 <REP> d-------- c:\program files\Windows Live SkyDrive
2008-12-17 14:28 . 2008-12-17 14:34 <REP> d-------- c:\program files\Microsoft
2008-12-17 14:18 . 2008-12-17 14:18 <REP> d-------- c:\program files\Fichiers communs\Windows Live
2008-12-14 14:09 . 2007-09-07 02:41 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-12-14 14:09 . 2007-09-07 02:41 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-14 14:09 . 2007-12-28 01:47 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-12-14 14:09 . 2007-09-07 02:41 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-12-14 14:09 . 2007-09-07 02:41 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-12-14 14:09 . 2007-09-07 02:41 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-12-14 14:09 . 2007-09-07 02:41 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-12-14 14:09 . 2008-12-14 14:09 <REP> d-------- c:\documents and settings\Administrateur
2008-12-12 00:21 . 2008-12-12 00:23 <REP> d-------- C:\Virtual
2008-12-12 00:19 . 2008-12-12 00:19 <REP> d-------- c:\documents and settings\All Users\Application Data\BufferZone
2008-12-12 00:18 . 2008-12-12 00:18 <REP> d-------- c:\windows\E4153266612C460FAB94C9DB6802459A.TMP
2008-12-12 00:18 . 2008-12-12 00:18 <REP> d-------- c:\program files\securedie
2008-12-12 00:18 . 2008-12-12 00:19 <REP> d-------- c:\program files\Secured IE
2008-12-10 18:23 . 2008-12-10 18:23 <REP> d-------- c:\program files\Avira
2008-12-10 18:23 . 2008-12-10 18:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-08 18:22 . 2008-12-08 18:22 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-08 18:21 . 2008-12-08 18:21 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-05 00:11 . 2008-12-05 00:11 308,584 --a------ c:\windows\WLXPGSS.SCR
2008-12-02 22:37 . 2008-12-02 22:37 49,480 --a------ c:\windows\system32\sirenacm.dll
2008-12-02 17:23 . 2008-12-02 17:23 <REP> d-------- c:\program files\Citrix
2008-11-27 20:17 . 2008-12-08 18:23 <REP> d-------- c:\program files\iTunes
2008-11-27 20:17 . 2008-12-08 18:22 <REP> d-------- c:\program files\iPod
2008-11-27 20:13 . 2008-12-08 18:22 <REP> d-------- c:\program files\QuickTime
2008-11-20 19:58 . 2008-12-08 18:19 <REP> d-------- c:\documents and settings\NetworkService\Application Data\agi
2008-11-19 17:23 . 2008-11-19 17:23 <REP> d-------- c:\program files\Kiwee Toolbar
2008-11-19 17:23 . 2008-12-08 18:19 <REP> d-------- c:\documents and settings\LocalService\Application Data\agi
2008-11-19 17:21 . 2008-11-19 17:21 2,117,632 --a------ c:\windows\system32\python25.dll
2008-11-19 17:21 . 2008-09-16 17:26 1,332,197 --a------ c:\windows\system32\pythondll.zip
2008-11-19 17:21 . 2008-11-19 17:21 339,968 --a------ c:\windows\system32\pythoncom25.dll
2008-11-19 17:21 . 2008-11-19 17:21 114,688 --a------ c:\windows\system32\pywintypes25.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-19 04:41 --------- d-----w c:\documents and settings\Evelyne\Application Data\EoRezo
2008-12-19 03:47 95,976 ----a-w c:\windows\system32\ladasazo.dll
2008-12-19 03:47 85,281 --sha-w c:\windows\system32\fobuyuru.dll
2008-12-17 13:33 --------- d-----w c:\program files\Windows Live
2008-12-11 23:27 --------- d-----w c:\program files\eMule
2008-12-11 15:11 --------- d-----w c:\program files\Symantec
2008-12-11 15:11 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2008-12-11 14:59 --------- d-----w c:\program files\Norton AntiVirus
2008-12-10 17:19 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-10 17:18 --------- d-----w c:\documents and settings\Evelyne\Application Data\Apple Computer
2008-12-10 05:01 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-08 17:22 --------- d-----w c:\program files\Fichiers communs\Apple
2008-12-08 17:20 --------- d-----w c:\documents and settings\Evelyne\Application Data\Ooze defy win
2008-12-08 17:19 --------- d-----w c:\program files\Safari
2008-11-06 16:50 --------- d-----w c:\program files\EoRezo
2008-10-30 23:41 --------- d-----w c:\documents and settings\Evelyne\Application Data\Image Zone Express
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-24 08:04 21,840 ----atw c:\windows\system32\SIntfNT.dll
2008-10-24 08:04 17,212 ----atw c:\windows\system32\SIntf32.dll
2008-10-24 08:04 12,067 ----atw c:\windows\system32\SIntf16.dll
2008-10-23 18:47 4,608 ----a-w c:\windows\system32\w95inf32.dll
2008-10-23 18:47 2,272 ----a-w c:\windows\system32\w95inf16.dll
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\SET175.tmp
2008-10-19 18:43 --------- d-----w c:\program files\PhotoFiltre
2008-10-19 15:11 --------- d-----w c:\documents and settings\Evelyne\Application Data\Printer Info Cache
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 10:38 663,552 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-07-02 19:07 15,397 ----a-w c:\program files\settings.dat
2008-03-08 19:14 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "c:\program files\securedie\tbsecu.dll" [2007-09-06 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8a5b62c-517f-42a5-85ae-29b5497fb15f}]
2008-08-20 22:03 1780248 --a------ c:\program files\Come2PlayK2P\tbCome.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
2007-09-06 12:28 1453080 --a------ c:\program files\securedie\tbsecu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b8a5b62c-517f-42a5-85ae-29b5497fb15f}"= "c:\program files\Come2PlayK2P\tbCome.dll" [2008-08-20 1780248]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "c:\program files\securedie\tbsecu.dll" [2007-09-06 1453080]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B8A5B62C-517F-42A5-85AE-29B5497FB15F}"= "c:\program files\Come2PlayK2P\tbCome.dll" [2008-08-20 1780248]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"= "c:\program files\securedie\tbsecu.dll" [2007-09-06 1453080]
[HKEY_CLASSES_ROOT\clsid\{b8a5b62c-517f-42a5-85ae-29b5497fb15f}]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-28 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 860160]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2005-02-08 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-02-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-08 126976]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-03-29 233534]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-05-04 794624]
"Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-24 28672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Proc Deaf Delete Peak"="c:\documents and settings\All Users\Application Data\file joy proc deaf\Exit Copy.exe" [2008-12-19 7565824]
"EoEngine"="c:\program files\EoRezo\EoEngine.exe" [2008-11-01 472912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-05 44032]
"c8f15057"="c:\windows\system32\fobuyuru.dll" [2008-12-19 85281]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-05 c:\windows\system32\bthprops.cpl]
"AGRSMMSG"="AGRSMMSG.exe" [2005-04-13 c:\windows\AGRSMMSG.exe]
c:\documents and settings\Evelyne\Menu D‚marrer\Programmes\D‚marrage\
TribalWeb.lnk - c:\program files\TribalWeb\tribalweb.exe [2007-09-27 1077248]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-21 45056]
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Symantec\\LiveUpdate\\AluSchedulerSvc.exe"=
"c:\\Program Files\\HPQ\\HP Wireless Assistant\\HP Wireless Assistant.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\Symantec Shared\\Security Center\\SymSCUI.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2008-12-17 55136]
S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\DRIVERS\adiusbae.sys []
S3 fsssvc;Windows Live Contrôle parental;"c:\program files\Windows Live\Family Safety\fsssvc.exe" [2008-12-08 533344]
S3 npkycryp;npkycryp;\??\c:\program files\Gravity\RO\npkycryp.sys []
S3 ovt530;Webcam Deluxe;c:\windows\system32\Drivers\ov530vid.sys [2007-09-11 161792]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0683c52d-b685-11dd-a97c-00150044db48}]
\Shell\Auto\command - cmd /C launch.bat
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fc5556c-8ed2-11dc-a70f-00150044db48}]
\Shell\AutoRun\command - E:\autoplay.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-19 c:\windows\Tasks\A738181791A38C5B.job
- c:\docume~1\evelyne\applic~1\oozede~1\GreatBallUp.exe []
2008-12-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{42fc8449-482b-4b7a-91ba-6fa9aa193ea7} - c:\windows\system32\vagivoho.dll
HKCU-Run-Hope Trans - c:\docume~1\Evelyne\APPLIC~1\OOZEDE~1\Burn base.exe
HKCU-Run-ceaue - c:\documents and settings\evelyne\local settings\application data\ceaue.exe
HKLM-Run-vizonojope - c:\windows\system32\zimuworo.dll
HKLM-Run-CPMcbc263cb - c:\windows\system32\kolopiro.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://lo.st#home
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Evelyne\Application Data\Mozilla\Firefox\Profiles\w9ttrjpv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://lo.st#home
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - component: c:\documents and settings\Evelyne\Application Data\Mozilla\Firefox\Profiles\w9ttrjpv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
FF - component: c:\documents and settings\Evelyne\Application Data\Mozilla\Firefox\Profiles\w9ttrjpv.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
[color=red]ATTENTION: FIREFOX POLICES IS IN FORCE
/color
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosting_flags", 9);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6BF52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.version", 3);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.rights.3.shown", false);
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-19 05:37:51
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe????????6?8?1?9??????? ???B?????????????hLC? ??????
Recherche de fichiers cachés ...
c:\windows\system32\uruyubof.ini 120 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\searchindexer.exe
c:\program files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
c:\program files\Apoint2K\ApntEx.exe
c:\windows\system32\rundll32.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\windows\system32\rundll32.exe
c:\program files\HPQ\shared\hpqwmi.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\Hp\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2008-12-19 5:46:01 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-19 04:45:49
Avant-CF: 35 021 230 080 octets libres
Après-CF: 35,250,487,296 octets libres
401 --- E O F --- 2008-12-18 17:09:33
Rapport deHijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:55, on 19/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lo.st#home
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Come2PlayK2P Toolbar - {b8a5b62c-517f-42a5-85ae-29b5497fb15f} - C:\Program Files\Come2PlayK2P\tbCome.dll
O2 - BHO: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O3 - Toolbar: PrintMe - {97387E2B-B2FA-4E4A-A607-F3B5C134F71C} - C:\Program Files\EFI\PrintMeToolbar\htpmcap.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Come2PlayK2P Toolbar - {b8a5b62c-517f-42a5-85ae-29b5497fb15f} - C:\Program Files\Come2PlayK2P\tbCome.dll
O3 - Toolbar: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Proc Deaf Delete Peak] C:\Documents and Settings\All Users\Application Data\file joy proc deaf\Exit Copy.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [c8f15057] rundll32.exe "C:\WINDOWS\system32\fobuyuru.dll",b
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: TribalWeb.lnk = C:\Program Files\TribalWeb\tribalweb.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe