pour mbam aucun fichier de nefaste donc pas besoin du rapport
ComboFix 09-09-25.01 - Sébastien 26/09/2009 23:34.1.2 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Basique 6.0.6002.2.1252.33.1036.18.2008.1073 [GMT 2:00]
Lancé depuis: c:usersSébastienDesktopComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:$recycle.binS-1-5-21-2435225641-3979886543-1385453349-500
c:$recycle.binS-1-5-21-2846373401-135836489-2259933115-500
c:windowsInstaller3cec5.msp
c:windowsInstaller640f8.msi
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-26 au 2009-09-26 ))))))))))))))))))))))))))))))))))))
.
2009-09-26 21:41 . 2009-09-26 21:41 -------- d-----w- c:usersDefaultAppDataLocal emp
2009-09-26 17:42 . 2009-09-10 12:54 38224 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-09-26 17:42 . 2009-09-26 19:14 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-09-26 17:42 . 2009-09-26 17:42 -------- d-----w- c:programdataMalwarebytes
2009-09-26 17:42 . 2009-09-10 12:53 19160 ----a-w- c:windowssystem32driversmbam.sys
2009-09-26 12:05 . 2009-09-26 12:05 -------- d-----w- c:program filesCommon FilesUninstall
2009-09-23 12:21 . 2009-04-02 13:21 84480 ----a-w- c:windowssystem32ff_vfw.dll
2009-09-23 12:21 . 2008-06-08 21:58 60273 ----a-w- c:windowssystem32pthreadGC2.dll
2009-09-23 12:20 . 2009-09-23 12:20 47360 ----a-w- c:windowssystem32driverspcouffin.sys
2009-09-23 12:20 . 2007-10-09 06:06 626688 ----a-w- c:windowssystem32msvcr80.dll
2009-09-23 12:20 . 2005-09-23 04:48 1171456 ----a-w- c:windowssystem32msvcr80d.dll
2009-09-23 12:20 . 2009-09-23 20:33 -------- d-----w- c:program filesVideo Convert Master
2009-09-20 20:21 . 2009-09-20 20:21 -------- d-----w- c:windowssystem32ca-ES
2009-09-20 20:21 . 2009-09-20 20:21 -------- d-----w- c:windowssystem32eu-ES
2009-09-20 20:21 . 2009-09-20 20:21 -------- d-----w- c:windowssystem32vi-VN
2009-09-20 20:04 . 2009-09-20 20:04 -------- d-----w- c:windowssystem32EventProviders
2009-09-19 19:16 . 2009-05-18 12:17 26600 ----a-w- c:windowssystem32driversGEARAspiWDM.sys
2009-09-19 19:16 . 2008-04-17 11:12 107368 ----a-w- c:windowssystem32GEARAspi.dll
2009-09-19 19:14 . 2009-09-19 19:14 -------- d-----w- c:program filesiPod
2009-09-19 19:14 . 2009-09-19 19:15 -------- d-----w- c:programdata{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-19 19:14 . 2009-09-19 19:15 -------- d-----w- c:program filesiTunes
2009-09-19 19:14 . 2009-09-19 19:14 -------- d-----w- c:program filesBonjour
2009-09-19 19:13 . 2009-09-19 19:13 -------- d-----w- c:program filesQuickTime
2009-09-19 19:13 . 2009-09-19 19:14 -------- d-----w- c:programdataApple Computer
2009-09-19 19:09 . 2009-09-19 19:14 -------- d-----w- c:program filesCommon FilesApple
2009-09-19 13:05 . 2009-04-11 06:28 754688 ----a-w- c:windowssystem32propsys.dll
2009-09-19 13:04 . 2009-04-11 06:28 777216 ----a-w- c:windowssystem32slcc.dll
2009-09-19 13:03 . 2009-04-11 06:28 83968 ----a-w- c:windowssystem32wbemwmiutils.dll
2009-09-19 13:03 . 2009-04-11 06:28 744448 ----a-w- c:windowssystem32wbemwbemcore.dll
2009-09-19 13:03 . 2009-04-11 06:28 30208 ----a-w- c:windowssystem32wbemwbemprox.dll
2009-09-19 13:03 . 2009-04-11 06:28 265728 ----a-w- c:windowssystem32wbem
epdrvfs.dll
2009-09-19 13:03 . 2009-04-11 06:28 189440 ----a-w- c:windowssystem32wbemmofd.dll
2009-09-19 13:03 . 2009-04-11 06:28 614912 ----a-w- c:windowssystem32wbemfastprox.dll
2009-09-19 13:03 . 2009-04-11 06:28 265728 ----a-w- c:windowssystem32wbemesscli.dll
2009-09-19 13:03 . 2009-04-11 06:28 705536 ----a-w- c:windowssystem32SmiEngine.dll
2009-09-19 13:03 . 2009-04-11 06:28 218624 ----a-w- c:windowssystem32wdscore.dll
2009-09-19 13:03 . 2009-04-11 06:27 130560 ----a-w- c:windowssystem32PkgMgr.exe
2009-09-19 13:03 . 2009-04-11 06:28 247808 ----a-w- c:windowssystem32drvstore.dll
2009-09-09 21:20 . 2009-09-09 21:20 -------- d-----w- c:program filesAxBx
2009-09-09 12:52 . 2009-09-09 12:52 -------- d-----w- c:program filesMicrosoft
2009-09-09 12:52 . 2009-09-09 12:52 -------- d-----w- c:program filesWindows Live
2009-09-08 18:39 . 2009-08-14 16:27 904776 ----a-w- c:windowssystem32drivers cpip.sys
2009-09-08 18:39 . 2009-08-14 13:49 9728 ----a-w- c:windowssystem32TCPSVCS.EXE
2009-09-08 18:39 . 2009-08-14 13:49 27136 ----a-w- c:windowssystem32NETSTAT.EXE
2009-09-08 18:39 . 2009-08-14 13:49 19968 ----a-w- c:windowssystem32ARP.EXE
2009-09-08 18:39 . 2009-08-14 13:48 30720 ----a-w- c:windowssystem32drivers cpipreg.sys
2009-09-08 18:39 . 2009-08-14 13:48 105984 ----a-w- c:windowssystem32
etiohlp.dll
2009-09-08 18:39 . 2009-08-14 15:53 17920 ----a-w- c:windowssystem32
etevent.dll
2009-09-08 18:39 . 2009-08-14 13:49 17920 ----a-w- c:windowssystem32ROUTE.EXE
2009-09-08 18:39 . 2009-08-14 13:49 11264 ----a-w- c:windowssystem32MRINFO.EXE
2009-09-08 18:39 . 2009-08-14 13:49 8704 ----a-w- c:windowssystem32HOSTNAME.EXE
2009-09-08 18:39 . 2009-08-14 13:49 10240 ----a-w- c:windowssystem32finger.exe
2009-09-08 18:36 . 2009-07-11 19:01 513536 ----a-w- c:windowssystem32wlansvc.dll
2009-09-08 18:36 . 2009-07-11 19:01 302592 ----a-w- c:windowssystem32wlansec.dll
2009-09-08 18:36 . 2009-07-11 19:01 293376 ----a-w- c:windowssystem32wlanmsm.dll
2009-09-08 18:36 . 2009-07-11 19:01 65024 ----a-w- c:windowssystem32wlanapi.dll
2009-09-08 18:36 . 2009-07-11 17:03 127488 ----a-w- c:windowssystem32L2SecHC.dll
2009-09-08 18:36 . 2009-04-11 06:28 68096 ----a-w- c:windowssystem32wlanhlp.dll
2009-09-08 18:36 . 2009-06-10 11:41 2868224 ----a-w- c:windowssystem32mf.dll
2009-09-08 18:36 . 2009-04-11 06:28 98816 ----a-w- c:windowssystem32mfps.dll
2009-09-08 18:36 . 2009-04-11 06:27 53248 ----a-w- c:windowssystem32
rinstaller.exe
2009-09-08 18:36 . 2009-04-11 06:27 24576 ----a-w- c:windowssystem32mfpmp.exe
2009-09-08 18:36 . 2009-04-11 04:54 2048 ----a-w- c:windowssystem32mferror.dll
2009-09-03 09:35 . 2009-09-03 09:35 -------- d-----w- c:program filesMarkAny
2009-09-02 19:49 . 2009-09-02 19:49 -------- d-----w- c:program filesAudacity 1.3 Beta (Unicode)
2009-09-02 19:11 . 2008-07-03 00:48 319456 ----a-w- c:windowssystem32DIFxAPI.dll
2009-09-02 19:10 . 2008-02-22 13:33 14976 ----a-w- c:windowssystem32driverssscdmdfl.sys
2009-09-02 19:10 . 2008-02-22 13:33 12160 ----a-w- c:windowssystem32driverssscdwhnt.sys
2009-09-02 19:10 . 2008-02-22 13:33 12160 ----a-w- c:windowssystem32driverssscdwh.sys
2009-09-02 19:10 . 2008-02-22 13:33 114304 ----a-w- c:windowssystem32driverssscdmdm.sys
2009-09-02 19:10 . 2008-02-22 13:33 87936 ----a-w- c:windowssystem32driverssscdbus.sys
2009-09-02 19:10 . 2008-02-22 13:33 12160 ----a-w- c:windowssystem32driverssscdcmnt.sys
2009-09-02 19:10 . 2008-02-22 13:33 12160 ----a-w- c:windowssystem32driverssscdcm.sys
2009-09-02 19:08 . 2009-09-03 09:34 -------- d-----w- c:program filesSamsung
2009-08-30 13:37 . 2009-08-30 13:37 -------- d-----w- c:program filesGanymede
2009-08-30 09:26 . 2009-09-26 11:54 -------- d-----w- C:My Music
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 19:15 . 2008-01-21 07:23 669566 ----a-w- c:windowssystem32perfh00C.dat
2009-09-26 19:15 . 2008-01-21 07:23 123556 ----a-w- c:windowssystem32perfc00C.dat
2009-09-26 19:04 . 2009-04-18 19:01 -------- d-----w- c:programdataPartner
2009-09-23 11:58 . 2009-06-30 18:59 -------- d-----w- c:program filesCommon FilesAVSMedia
2009-09-23 11:58 . 2009-06-30 18:59 -------- d-----w- c:program filesAVS4YOU
2009-09-21 18:54 . 2009-05-13 14:24 -------- d-----w- c:program filesJava
2009-09-20 20:22 . 2006-11-02 12:35 -------- d-----w- c:program filesWindows Calendar
2009-09-20 20:22 . 2006-11-02 11:18 -------- d-----w- c:program filesWindows Mail
2009-09-20 20:22 . 2006-11-02 12:35 -------- d-----w- c:program filesWindows Sidebar
2009-09-20 20:22 . 2006-11-02 12:35 -------- d-----w- c:program filesWindows Photo Gallery
2009-09-20 20:22 . 2006-11-02 12:35 -------- d-----w- c:program filesWindows Collaboration
2009-09-20 20:21 . 2006-11-02 12:35 -------- d-----w- c:program filesWindows Defender
2009-09-09 11:43 . 2009-07-31 09:13 -------- d-----w- c:programdataTrackMania
2009-09-08 20:39 . 2009-04-20 20:29 -------- d-----w- c:program filesMicrosoft Silverlight
2009-09-08 20:39 . 2008-12-23 04:16 -------- d-----w- c:programdataMicrosoft Help
2009-09-03 09:35 . 2008-12-23 04:08 -------- d--h--w- c:program filesInstallShield Installation Information
2009-09-03 09:35 . 2009-07-24 14:24 -------- d-----w- c:program filesPC Connectivity Solution
2009-09-02 20:29 . 2009-09-02 20:29 0 ---ha-w- c:windowssystem32driversMsft_User_WpdMtpDr_01_00_00.Wdf
2009-09-02 19:10 . 2009-07-24 14:26 -------- d-----w- c:program filesDIFX
2009-08-24 16:58 . 2009-04-19 17:30 -------- d-----w- c:program filesCommon FilesReal
2009-08-24 16:58 . 2009-08-24 16:58 -------- d-----w- c:program filesCommon Filesxing shared
2009-08-17 16:10 . 2009-07-19 11:53 1279456 ----a-w- c:windowssystem32aswBoot.exe
2009-08-17 16:05 . 2009-07-19 11:53 114768 ----a-w- c:windowssystem32driversaswSP.sys
2009-08-17 16:05 . 2009-07-19 11:53 20560 ----a-w- c:windowssystem32driversaswFsBlk.sys
2009-08-17 16:05 . 2009-07-19 11:53 53328 ----a-w- c:windowssystem32driversaswMonFlt.sys
2009-08-17 16:04 . 2009-07-19 11:53 51376 ----a-w- c:windowssystem32driversaswTdi.sys
2009-08-17 16:04 . 2009-07-19 11:53 23152 ----a-w- c:windowssystem32driversaswRdr.sys
2009-08-17 16:02 . 2009-07-19 11:53 97480 ----a-w- c:windowssystem32AvastSS.scr
2009-08-11 19:59 . 2009-08-11 19:59 -------- d--h--w- c:programdataCanonBJ
2009-08-11 19:58 . 2009-08-11 19:58 -------- d--h--w- c:program filesCanonBJ
2009-07-31 09:11 . 2009-07-31 09:10 -------- d-----w- c:program filesTmNationsForever
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:windowssystem32sirenacm.dll
2009-07-25 03:23 . 2009-05-13 14:25 411368 ----a-w- c:windowssystem32deploytk.dll
2009-07-21 21:52 . 2009-07-28 18:26 915456 ----a-w- c:windowssystem32wininet.dll
2009-07-21 21:47 . 2009-07-28 18:26 109056 ----a-w- c:windowssystem32iesysprep.dll
2009-07-21 21:47 . 2009-07-28 18:26 71680 ----a-w- c:windowssystem32iesetup.dll
2009-07-21 20:13 . 2009-07-28 18:26 133632 ----a-w- c:windowssystem32ieUnatt.exe
2009-07-17 13:54 . 2009-08-13 10:51 71680 ----a-w- c:windowssystem32atl.dll
2009-07-15 12:40 . 2009-08-13 10:51 8147456 ----a-w- c:windowssystem32wmploc.DLL
2009-07-15 12:39 . 2009-08-13 10:51 313344 ----a-w- c:windowssystem32wmpdxm.dll
2009-07-15 12:39 . 2009-08-13 10:51 4096 ----a-w- c:windowssystem32dxmasf.dll
2009-07-15 12:39 . 2009-08-13 10:51 7680 ----a-w- c:windowssystem32spwmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:program filesmozilla firefoxpluginslibdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:program filesmozilla firefoxpluginsssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SmpcSys"="c:program filesPACKARD BELLSetUpMyPCSmpSys.exe" [2008-07-07 1038136]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:program filesCommon FilesNeroLibNMIndexStoreSvr.exe" [2008-04-28 1828136]
"swg"="c:program filesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2009-04-18 68856]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2008-01-21 202240]
"AutoStartNPSAgent"="c:program filesSamsungSamsung New PC StudioNPSAgent.exe" [2009-04-16 102400]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Windows Defender"="c:program filesWindows DefenderMSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:program filesIntelIntel Matrix Storage Manageriaanotif.exe" [2008-04-15 178712]
"Google Desktop Search"="c:program filesGoogleGoogle Desktop SearchGoogleDesktop.exe" [2008-12-23 24064]
"SmpcSys"="c:program filesPackard BellSetupMyPCSmpSys.exe" [2008-07-07 1038136]
"IgfxTray"="c:windowssystem32igfxtray.exe" [2008-07-11 150040]
"HotKeysCmds"="c:windowssystem32hkcmd.exe" [2008-07-11 170520]
"Persistence"="c:windowssystem32igfxpers.exe" [2008-07-11 145944]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2007-06-08 894512]
"PCMAgent"="c:program filesCyberLinkPowerCinemaPCMAgent.exe" [2008-03-21 143360]
"CLMLServer"="c:program filesCyberLinkPowerCinemaKernelCLMLCLMLSvc.exe" [2008-04-11 196608]
"PlayMovie"="c:program filesCyberLinkPlayMoviePMVService.exe" [2008-03-31 172032]
"Adobe Reader Speed Launcher"="c:program filesAdobeReader 9.0ReaderReader_sl.exe" [2009-02-27 35696]
"avast!"="c:progra~1ALWILS~1Avast4ashDisp.exe" [2009-08-17 81000]
"TkBellExe"="c:program filesCommon FilesRealUpdate_OB
ealsched.exe" [2009-09-23 198160]
"QuickTime Task"="c:program filesQuickTimeQTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:program filesiTunesiTunesHelper.exe" [2009-09-08 305440]
"SunJavaUpdateSched"="c:program filesJavajre6injusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="c:program filesMalwarebytes' Anti-Malwarembam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:windowsRtHDVCpl.exe [2008-09-18 6294048]
"Skytel"="Skytel.exe" - c:windowsSkyTel.exe [2008-09-18 1833504]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
[hkey_local_machinesoftwaremicrosoftwindowscurrentversionexplorerShellExecuteHooks]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=c:progra~1GoogleGOOGLE~1GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalSymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalWinDefend]
@="Service"
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerSvc]
"VistaSp2"=hex(b):f2,96,9c,ed,30,3a,ca,01
[HKLM~servicessharedaccessparametersfirewallpolicyFirewallRules]
"{8F5CA79B-0708-4E43-8C5E-39609878C24C}"= UDP:c:program filesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{4E4F7B70-2142-4469-A480-4A0D49BF50AE}"= TCP:c:program filesMicrosoft OfficeOffice12ONENOTE.EXE:Microsoft Office OneNote
"{15C785B7-450D-4E56-BE56-0C11AA225197}"= c:program filesCyberLinkPowerCinemaPowerCinema.exe:CyberLink PowerCinema
"{358A569C-EA37-4322-8E9E-A33A10D5E6FA}"= c:program filesCyberLinkPowerCinemaPCMService.exe:CyberLink PowerCinema Resident Program
"{3728B1F5-6241-4DD2-B709-0045176A3F38}"= c:program filesCyberLinkPowerCinemaKernelDMPCLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{6BC5574D-1D6C-4B2D-89B9-E43828CBC23D}"= c:program filesCyberLinkPowerCinemaKernelDMSCLMSService.exe:CyberLink Media Server
"{E892C56F-B3F0-4EA8-9BB8-60D1A199B375}"= c:program filesCyberLinkPlayMoviePlayMovie.exe:CyberLink PlayMovie
"{01752972-EAB6-469F-9F50-881A40CC9B01}"= c:program filesCyberLinkPlayMoviePMVService.exe:CyberLink PlayMovie Resident Program
"{1F505424-9A62-434A-A256-6799527D2973}"= UDP:c:program filesSonyMedia Manager for PSPMediaManager.exe:Media Manager for PSP 3.0
"{43F0339F-0C8A-4376-83E1-328D5086A9AD}"= TCP:c:program filesSonyMedia Manager for PSPMediaManager.exe:Media Manager for PSP 3.0
"{81AFF5A0-E016-4551-8B39-77D8EBDF34BD}"= TCP:6004|c:program filesMicrosoft OfficeOffice12outlook.exe:Microsoft Office Outlook
"{DFCCE956-7B5D-40A0-97CA-A48F10AB940D}"= UDP:c:usersSébastienAppDataLocalTemp7zS2F4E.tmpSymNRT.exe:Norton Removal Tool
"{350C0708-E00D-47F9-BCA3-7FC4695B7F13}"= TCP:c:usersSébastienAppDataLocalTemp7zS2F4E.tmpSymNRT.exe:Norton Removal Tool
"{B4B25DD9-874E-4C02-95BF-10A4887A02D7}"= UDP:c:program filesSamsungSamsung New PC Studio
psasvr.exe:KTF MUSIC AoD Server
"{93322A75-7629-4003-9FA5-B52F78E4F446}"= TCP:c:program filesSamsungSamsung New PC Studio
psasvr.exe:KTF MUSIC AoD Server
"{70F5D41F-31AA-452E-9EAB-C93E0D3436CE}"= UDP:c:program filesSamsungSamsung New PC Studio
psvsvr.exe:KTF MUSIC VoD Server
"{01064121-A111-418F-9706-4F6811EB4ACB}"= TCP:c:program filesSamsungSamsung New PC Studio
psvsvr.exe:KTF MUSIC VoD Server
"TCP Query User{CF42AAE7-8B39-449A-814E-8E51CF3B8232}c:\program files\tmnationsforever\tmforever.exe"= UDP:c:program files mnationsforever mforever.exe:TmForever
"UDP Query User{B7231BBB-6A61-4C0E-87F4-8CD4FAA320C7}c:\program files\tmnationsforever\tmforever.exe"= TCP:c:program files mnationsforever mforever.exe:TmForever
"TCP Query User{22D5D6C1-28D1-4C09-9713-258214B4E177}c:\program files\tmnationsforever\tmforever.exe"= UDP:c:program files mnationsforever mforever.exe:TmForever
"UDP Query User{6E33AA18-8FF4-425E-8535-9A8ACA057B8C}c:\program files\tmnationsforever\tmforever.exe"= TCP:c:program files mnationsforever mforever.exe:TmForever
"{CB7BA08C-D7B9-41BD-8305-209699D31BFF}"= UDP:c:program filesSamsungSamsung New PC Studio
psasvr.exe:KTF MUSIC AoD Server
"{A3944D06-F9A8-4FCC-AE16-A2782DC747E7}"= TCP:c:program filesSamsungSamsung New PC Studio
psasvr.exe:KTF MUSIC AoD Server
"{5348442F-8DBD-4C99-90AD-FA066EDC47F7}"= UDP:c:program filesSamsungSamsung New PC Studio
psvsvr.exe:KTF MUSIC VoD Server
"{ADE62239-7B1C-48FA-9DCB-C72EF4A08592}"= TCP:c:program filesSamsungSamsung New PC Studio
psvsvr.exe:KTF MUSIC VoD Server
"{E530D0F0-AE8F-464B-83F5-CEB550C9D39E}"= UDP:c:program filesBonjourmDNSResponder.exe:Bonjour
"{3F5F20E6-1C0A-49BD-8F3B-6301C2A9ADE1}"= TCP:c:program filesBonjourmDNSResponder.exe:Bonjour
"{BDB30FAA-EC2C-47F9-9C12-F4BC32473E02}"= UDP:c:program filesiTunesiTunes.exe:iTunes
"{EC9A5281-24F9-4EE9-95A4-780BCBC034D6}"= TCP:c:program filesiTunesiTunes.exe:iTunes
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
R1 aswSP;avast! Self Protection;c:windowsSystem32driversaswSP.sys [19/07/2009 13:53 114768]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:program filesCyberLinkPlayMovie 00.fcl [07/01/2009 09:46 41456]
R2 aswFsBlk;aswFsBlk;c:windowsSystem32driversaswFsBlk.sys [19/07/2009 13:53 20560]
R2 aswMonFlt;aswMonFlt;c:windowsSystem32driversaswMonFlt.sys [19/07/2009 13:53 53328]
R2 ETService;Empowering Technology Service;c:program filesPACKARD BELLPackard Bell Recovery ManagementServiceETService.exe [07/01/2009 09:41 24576]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:windowssystem32svchost.exe -k netsvcs [21/01/2008 04:33 21504]
R2 FsUsbExService;FsUsbExService;c:windowsSystem32FsUsbExService.Exe [24/07/2009 16:25 233472]
R3 FsUsbExDisk;FsUsbExDisk;c:windowsSystem32FsUsbExDisk.Sys [24/07/2009 16:25 36608]
R3 O2MDRDR;O2MDRDR;c:windowsSystem32driverso2media.sys [22/08/2008 09:03 51288]
R3 O2SDRDR;O2SDRDR;c:windowsSystem32driverso2sd.sys [12/06/2008 03:28 43608]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:windowsSystem32driversRTL8187B.sys [23/12/2008 14:07 288768]
S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:program filesAdobePhotoshop Elements 6.0PhotoshopElementsFileAgent.exe [11/09/2007 01:45 124832]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:program filesGoogleGoogle Desktop SearchGoogleDesktop.exe [23/12/2008 06:22 24064]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - FSUSBEXDISK
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvchost - NetSvcs
ezSharedSvc
.
Contenu du dossier 'Tâches planifiées'
2009-09-26 c:windowsTasksUser_Feed_Synchronization-{B9C89ACD-8B37-44C3-813B-73EFBF0EBE63}.job
- c:windowssystem32msfeedssync.exe [2009-07-28 20:13]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://fr.yahoo.com/
mStart Page =
hxxp://homepage.packardbell.com/rdr.asp ... ynote_sl35
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:progra~1MICROS~2Office12EXCEL.EXE/3000
FF - ProfilePath - c:usersSébastienAppDataRoamingMozillaFirefoxProfileskbmzopti.default
FF - prefs.js: browser.startup.homepage -
hxxp://fr.yahoo.com/
FF - component: c:program filesRealRealPlayerrowserrecordfirefoxextcomponents
prpffbrowserrecordext.dll
FF - plugin: c:program filesMozilla Firefoxplugins
p-mswmp.dll
FF - plugin: c:program filesVideo Convert Mastercodec
ealrowserplugins
ppl3260.dll
FF - plugin: c:program filesVideo Convert Mastercodec
ealrowserplugins
prpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationDotNetAssistantExtension
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-DLD.EXE - (no file)
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-NPSStartup - (no file)
AddRemove-HijackThis - c:usersSébastienDesktopHijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-26 23:41
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINESYSTEMControlSet001Services{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="??c:program filesCyberLinkPlayMovie 00.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERSS-1-5-21-2435225641-3979886543-1385453349-1000SoftwareSony Creative SoftwareM*e*d*i*a* *M*a*n*a*g*e*r* *f*o*r* *P*S*P*"!3.0]
"Percents"="0.0059 0.1499 0.3864 0.4607 0.7584 0.8574 0.8763 "
"Increment"=".005882"
"FRT"="7NS6Gh7gJWibmNHg36HRrQEDq4JIM27AmhjinPvL9LaVhENpRtuwlA=="
"PLCK"="v166GPStE5aDqEM9Or407/9yrAyxnFDN"
"PHSH"=""
[HKEY_LOCAL_MACHINESYSTEMControlSet001ControlClass{4D36E96D-E325-11CE-BFC1-08002BE10318} 000AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINESYSTEMControlSet001ControlClass{4D36E96D-E325-11CE-BFC1-08002BE10318} 001AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINESYSTEMControlSet001ControlClass{4D36E96D-E325-11CE-BFC1-08002BE10318} 002AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-09-26 23:42
ComboFix-quarantined-files.txt 2009-09-26 21:42
Avant-CF: 95 903 387 648 octets libres
Après-CF: 95 841 521 664 octets libres
300 --- E O F --- 2009-09-20 20:17
Merci de ton aide precieuse !