voici le rapport
ComboFix 08-03-30.1 - yves 2008-03-30 14:00:51.3 - NTFSx86 MINIMAL
Endroit: C:\Documents and Settings\yves\Bureau\Combo-Fix.exe
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
TimedOut: progfile.dat
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\down
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-28 to 2008-03-30 ))))))))))))))))))))))))))))))))))))
.
2008-03-30 10:36 . 2008-03-30 10:36 17,353,166 --a------ C:\upload_moi_ACER-7989E0343A.tar.gz
2008-03-30 08:22 . 2008-03-30 08:22 <REP> d-------- C:\Program Files\Trend Micro
2008-03-30 00:05 . 2008-03-30 00:10 <REP> d-------- C:\Program Files\Le Robert
2008-03-29 23:02 . 2008-03-29 23:10 <REP> d-------- C:\Program Files\Navilog1
2008-03-29 20:50 . 2008-03-29 20:50 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-29 19:46 . 2008-03-29 19:46 <REP> d-------- C:\Muestras
2008-03-29 18:49 . 2008-03-29 18:49 <REP> d-------- C:\Program Files\CCleaner
2008-03-29 13:40 . 2008-03-29 14:46 <REP> d-------- C:\Program Files\CDex_170b2
2008-03-29 13:30 . 2008-03-29 13:30 <REP> d-------- C:\Documents and Settings\yves\Application Data\AccurateRip
2008-03-29 13:30 . 2008-03-29 13:30 33,846 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-03-29 13:30 . 2008-03-29 13:30 12,915 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-03-28 21:39 . 2008-03-28 21:39 <REP> d--h----- C:\WINDOWS\PIF
2008-03-28 15:01 . 2008-03-28 15:02 <REP> d-------- C:\Documents and Settings\yves\Application Data\Sites
2008-03-28 15:01 . 2008-03-28 15:02 <REP> d-------- C:\Documents and Settings\yves\Application Data\Dynamique
2008-03-28 15:01 . 2008-03-28 15:02 <REP> d-------- C:\Documents and Settings\yves\Application Data\Classes de site
2008-03-28 15:00 . 2008-03-28 19:48 <REP> d-------- C:\Program Files\vmntoolbar
2008-03-28 15:00 . 2008-03-28 15:05 <REP> d-------- C:\Program Files\Visicom Media
2008-03-28 14:28 . 2008-03-28 14:31 <REP> d-------- C:\Program Files\Crystal FTP Free
2008-03-28 14:28 . 2008-03-28 14:28 <REP> d-------- C:\Documents and Settings\yves\Application Data\Crystal FTP
2008-03-26 14:16 . 2008-03-26 16:40 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-26 14:16 . 2008-03-26 14:16 3,120 --a------ C:\WINDOWS\MF_C421.lfa
2008-03-26 14:16 . 2008-03-26 14:16 3,120 --a------ C:\WINDOWS\MF_C420.lfa
2008-03-26 14:15 . 2008-03-26 21:28 <REP> d-------- C:\Program Files\Blaze Media Pro
2008-03-25 22:41 . 2008-03-25 22:44 <REP> d-------- C:\Program Files\Monkey's Audio
2008-03-25 21:23 . 2008-03-29 13:29 4,230,520 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2008-03-25 21:23 . 2008-03-25 22:37 27,958 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.bmp
2008-03-25 21:23 . 2008-03-25 22:38 2,275 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
2008-03-24 12:02 . 2008-03-24 12:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NtiDvdCopy
2008-03-22 19:28 . 2008-03-22 19:28 <REP> d-------- C:\Program Files\Fichiers communs\DVDVIDEOSOFT
2008-03-22 19:28 . 2008-03-22 19:28 <REP> d-------- C:\Program Files\DVDVIDEOSOFT
2008-03-22 19:24 . 2008-03-22 19:24 <REP> d-------- C:\Documents and Settings\yves\Application Data\Search Settings
2008-03-22 18:54 . 2008-03-22 18:54 <REP> d-------- C:\Program Files\Search Settings
2008-03-22 18:53 . 2008-03-22 19:24 <REP> d-------- C:\Program Files\Free FLV Converter
2008-03-22 18:53 . 2008-03-22 18:54 <REP> d-------- C:\Program Files\Dealio
2008-03-22 18:53 . 2007-06-19 00:22 364,544 --a------ C:\WINDOWS\system32\PropertyGrid.ocx
2008-03-22 18:53 . 2005-10-13 14:42 208,500 --a------ C:\WINDOWS\system32\ReyXpBasics.tlb
2008-03-22 18:53 . 2004-03-09 01:00 84,512 --a------ C:\WINDOWS\system32\PICCLP32.OCX
2008-03-22 18:53 . 2005-09-28 02:31 24,576 --a------ C:\WINDOWS\system32\ControlSubX.ocx
2008-03-22 18:53 . 1998-07-13 01:00 9,728 --a------ C:\WINDOWS\system32\PCCLPFR.DLL
2008-03-21 21:54 . 2008-03-21 21:54 <REP> d-------- C:\Program Files\LimeWire
2008-03-21 21:54 . 2008-03-21 22:56 <REP> d-------- C:\Documents and Settings\yves\Application Data\LimeWire
2008-03-21 14:30 . 2008-03-21 14:30 <REP> d-------- C:\Program Files\Alcohol Soft
2008-03-20 13:07 . 2008-03-20 13:07 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-03-20 13:06 . 2008-03-20 13:06 <REP> d-------- C:\Program Files\Vente Flash
2008-03-18 12:41 . 2008-03-18 12:41 <REP> d-------- C:\Program Files\ExplorerXP
2008-03-18 11:15 . 2008-03-18 11:43 <REP> d-------- C:\Program Files\Windows scrabble
2008-03-13 09:38 . 2008-03-13 09:38 <REP> d-------- C:\Program Files\Stardock
2008-03-13 09:38 . 2008-03-13 09:38 <REP> d--h----- C:\Documents and Settings\All Users\Application Data\{A850D4D9-871B-4234-908D-21C457767270}
2008-03-12 18:28 . 2008-03-12 18:30 <REP> d-------- C:\Program Files\Virtual Magnifying Glass
2008-03-12 15:34 . 2008-03-12 15:53 <REP> d-------- C:\Documents and Settings\yves\Application Data\gtk-2.0
2008-03-12 15:34 . 2008-03-12 15:34 <REP> d-------- C:\Documents and Settings\yves\.thumbnails
2008-03-12 15:31 . 2008-03-12 15:55 <REP> d-------- C:\Documents and Settings\yves\.gimp-2.4
2008-03-12 15:30 . 2008-03-12 15:30 <REP> d-------- C:\Program Files\GIMP-2.0
2008-03-11 19:57 . 2008-03-11 19:57 <REP> d-------- C:\Program Files\Conjugaison
2008-03-10 23:54 . 2008-03-14 18:09 <REP> d-------- C:\Program Files\OCCT
2008-03-09 22:49 . 2008-03-09 22:49 <REP> d-------- C:\Documents and Settings\yves\Application Data\Ulead Systems
2008-03-09 22:43 . 2008-03-09 22:43 <REP> d-------- C:\Program Files\Fichiers communs\Ulead Systems
2008-03-09 22:43 . 2008-03-09 22:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-03-06 12:19 . 2008-03-06 12:19 <REP> d-------- C:\Program Files\SFRWidget
2008-03-01 10:51 . 2008-03-01 10:51 <REP> d-------- C:\Program Files\IObit
2008-02-28 20:35 . 2008-02-28 20:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\IM
2008-02-28 20:30 . 2008-02-28 20:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-02-24 14:26 . 2008-02-24 14:26 <REP> d-------- C:\Documents and Settings\yves\Application Data\GlarySoft
2008-02-24 14:17 . 2008-02-24 14:17 <REP> d-------- C:\Program Files\Glary Utilities
2008-02-22 20:54 . 2008-02-22 20:54 <REP> d-------- C:\Program Files\Fichiers communs\Vbox
2008-02-22 11:55 . 2008-02-22 11:55 3,120 --------- C:\WINDOWS\.lfa
2008-02-21 22:06 . 2008-02-21 22:06 <REP> d-------- C:\Program Files\Logiciels Sebastien GRENIER
2008-02-21 10:31 . 2008-02-21 10:31 <REP> d-------- C:\Documents and Settings\yves\Application Data\AchrafCherti
2008-02-21 10:28 . 2008-02-21 10:28 <REP> d-------- C:\Program Files\UltraSplitter
2008-02-20 13:08 . 2008-02-20 13:08 <REP> d-------- C:\Program Files\KC Softwares
2008-02-18 12:54 . 2008-03-26 20:04 <REP> d-------- C:\Documents and Settings\yves\Application Data\U3
2008-02-16 21:22 . 2008-02-16 21:22 <REP> d-------- C:\Documents and Settings\yves\Application Data\Ashampoo
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Ashampoo
2008-02-16 19:35 . 2008-02-16 19:35 <REP> d-------- C:\Program Files\scrabbleproB1.0.7
2008-02-16 19:35 . 2002-03-13 17:46 53,248 --a------ C:\WINDOWS\system32\zlib.dll
2008-02-15 18:40 . 2008-02-15 18:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\espionServerData
2008-02-15 18:35 . 2008-02-15 18:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-02-15 18:30 . 2008-02-15 18:30 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2008-02-14 21:14 . 2008-02-14 21:14 <REP> d-------- C:\Documents and Settings\yves\Application Data\Leadertech
2008-02-12 17:43 . 2008-02-12 17:43 <REP> d-------- C:\Program Files\Photodex Presenter
2008-02-12 17:43 . 2008-02-12 17:43 <REP> d-------- C:\Program Files\Photodex
2008-02-11 21:48 . 2008-02-11 21:48 <REP> d-------- C:\Program Files\Photo Story 3 for Windows
2008-02-11 14:49 . 2000-05-11 13:06 397,312 --a------ C:\WINDOWS\system32\MSRDO20.DLL
2008-02-11 14:49 . 2000-08-02 15:44 151,552 --a------ C:\WINDOWS\system32\rdocurs.dll
2008-02-11 14:49 . 1998-10-19 12:34 37,062 --a------ C:\WINDOWS\system32\odbcinst.hlp
2008-02-11 14:49 . 1998-10-19 12:34 324 --a------ C:\WINDOWS\system32\odbcinst.cnt
2008-02-11 14:48 . 2008-02-11 14:48 <REP> d-------- C:\Program Files\Fichiers communs\Micro Application Shared
2008-02-10 10:28 . 2008-02-10 10:28 <REP> d-------- C:\Program Files\IVCsoft
2008-02-07 12:01 . 2008-02-07 12:15 <REP> d-------- C:\Documents and Settings\yves\Application Data\COWON
2008-02-05 10:02 . 2008-02-05 10:02 <REP> d-------- C:\Program Files\FDSoftware
2008-02-04 19:23 . 2008-02-04 19:23 693,792 --a------ C:\WINDOWS\system32\OGACheckControl.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-30 06:21 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-03-29 18:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-29 15:38 --------- d-----w C:\Program Files\Unlocker
2008-03-29 14:21 --------- d-----w C:\Program Files\eMule
2008-03-29 13:38 --------- d-----w C:\Program Files\ZGuideTV
2008-03-29 13:07 --------- d-----w C:\Documents and Settings\yves\Application Data\FileZilla
2008-03-29 13:05 --------- d-----w C:\Program Files\FileZilla Client
2008-03-29 11:32 --------- d-----w C:\Program Files\dBpowerAMP
2008-03-28 17:46 --------- d-----w C:\Documents and Settings\yves\Application Data\Dealio
2008-03-27 13:19 --------- d-----w C:\Program Files\MediaCoder
2008-03-26 23:10 --------- d-----w C:\Documents and Settings\yves\Application Data\XnView
2008-03-26 08:35 --------- d-----w C:\Program Files\Radio Fr Solo
2008-03-26 05:07 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-03-25 12:40 --------- d-----w C:\Documents and Settings\yves\Application Data\Image Zone Express
2008-03-21 12:18 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-03-17 18:31 --------- d-----w C:\Documents and Settings\yves\Application Data\Simple Sudoku
2008-03-12 08:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-09 20:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-09 20:43 --------- d-----w C:\Program Files\Ulead Systems
2008-03-09 20:43 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-03-07 09:55 --------- d-----w C:\Program Files\IncrediMail
2008-03-06 21:00 --------- d-----w C:\Program Files\Micro Application
2008-03-06 13:03 --------- d-----w C:\Program Files\7-Zip
2008-02-24 12:28 --------- d-----w C:\Program Files\Simple Sudoku
2008-02-24 12:28 --------- d-----w C:\Program Files\Nvu
2008-02-24 12:28 --------- d-----w C:\Program Files\ExtracteurIcones
2008-02-24 12:28 --------- d-----w C:\Program Files\EnveloppesEditor1.09
2008-02-24 12:28 --------- d-----w C:\Program Files\CartaGoGo
2008-02-22 18:54 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-20 11:15 --------- d-----w C:\Program Files\XnView
2008-02-15 16:26 43,528 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-15 16:26 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-02-15 16:26 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-02-15 16:26 116,472 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-02-10 09:54 --------- d-----w C:\Program Files\NCH Software
2008-02-09 23:00 --------- d-----w C:\Program Files\Konvertor
2008-02-01 07:39 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-01 07:39 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-01 07:39 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-01 07:39 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-01 07:39 --------- d-----w C:\Program Files\Symantec
2008-01-21 15:47 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-21 15:47 253,952 ------w C:\WINDOWS\Setup1.exe
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-05 08:31 1,014,784 ----a-w C:\WINDOWS\system32\logonuiX.exe
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
.
------- Sigcheck -------
Cryptography Services Error !!
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadwin PrintScreen"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 10:42 495616]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 22:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-02-03 11:22 160568]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-02-25 14:07 243072]
"Magnifying Glass"="C:\Program Files\Virtual Magnifying Glass\Magnifying Glass.exe" [2006-06-06 19:42 441344]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2004-06-18 07:05 659456]
"Le Petit Robert Hyperappel"="C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe" [2001-10-11 13:11 22560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-03-30 00:13 52840]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-12 00:19 7626752]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2006-05-10 08:02:00 5517312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Acer Empowering Technology.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Acer Empowering Technology.lnk
backup=C:\WINDOWS\pss\Acer Empowering Technology.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Acer WLAN 11g USB Dongle.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Acer WLAN 11g USB Dongle.lnk
backup=C:\WINDOWS\pss\Acer WLAN 11g USB Dongle.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
--a------ 2006-04-18 19:54 49152 C:\WINDOWS\system32\SysMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2007-09-25 23:26 69632 C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 04:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cloneur Expert Monitor]
--a------ 2007-09-25 23:26 439211 C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-10 22:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-11-12 12:48 157592 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
--a------ 2006-03-17 15:00 345088 C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a------ 2005-09-29 14:01 67584 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eRecoveryService]
--a------ 2006-06-01 14:40 413696 C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
--a------ 2004-08-10 22:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2004-08-10 22:00 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-02-25 14:07 243072 C:\Program Files\IncrediMail\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LaunchApp]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 2004-08-10 22:00 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ntiMUI]
--a------ 2005-05-11 17:15 45056 c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-07-12 00:19 7626752 C:\WINDOWS\system32\NvCpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-07-12 00:19 86016 C:\WINDOWS\system32\NvMcTray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-07-12 00:19 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-10 22:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-10 22:00 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-06-01 02:48 16208384 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2006-05-16 04:04 2879488 C:\WINDOWS\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WarReg_PopUp]
--a------ 2006-09-23 13:08 61440 C:\Acer\WR_PopUp\WarReg_PopUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Radio Fr Solo\\Radio_Fr_Solo.exe"=
"C:\\Program Files\\Radio Fr Solo\\RFSUpdate.exe"=
"C:\\Program Files\\Radio Fr Solo\\RFScheduler.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Adobe\\Photoshop Elements 6.0\\AdobePhotoshopElementsMediaServer.exe"=
"C:\\Program Files\\Logiciels Sebastien GRENIER\\Sudoku\\sudoku.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Crystal FTP Free\\crystalftp.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58787:TCP"= 58787:TCP:Pando P2P TCP Listening Port
"58787:UDP"= 58787:UDP:Pando P2P UDP Listening Port
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9e75f2f-de0b-11dc-bc9e-001921514e5a}]
\Shell\AutoRun\command - N:\LaunchU3.exe -a
*Newly Created Service* - MDMXSDK
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-28 21:02:00 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - yves.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-30 14:03:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Le Petit Robert Hyperappel = C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe??????????????????????????????????????????????????????????????????????????????????????????????????????????\??? /??\??????????????????????|? ??\???Q??|x???m??|????????\???n??|Z????????????,K????????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-30 14:03:23
ComboFix-quarantined-files.txt 2008-03-30 12:03:15
Pre-Run: 44,551,049,216 octets libres
Post-Run: 44,533,612,544 octets libres
.
2008-03-12 08:03:32 --- E O F ---