ComboFix 08-10-07.06 - Guillaume Drago 2008-10-08 16:43:06.1 -
FAT32x86
Lancé depuis: C:Documents and SettingsGuillaume DragoBureauComboFix.exe
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:Temp1cb
C:Temp1cbsyscheck.log
C:WINDOWSsystem32MSINET.oca
C:WINDOWSsystem32WLCtrl32.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_FOS26
-------Legacy_SMTPDRV
-------Service_Fos26
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-08 au 2008-10-08 ))))))))))))))))))))))))))))))))))))
.
2030-10-31 17:13 . 2008-03-21 21:30 129,784 --------- C:WINDOWSsystem32pxafs.dll
2030-10-31 17:13 . 2008-03-21 21:30 120,056 --------- C:WINDOWSsystem32pxcpyi64.exe
2030-10-31 17:13 . 2008-03-21 21:30 118,520 --------- C:WINDOWSsystem32pxinsi64.exe
2030-10-31 17:13 . 2008-03-21 21:30 9,464 --------- C:WINDOWSsystem32driverscdralw2k.sys
2030-10-31 17:13 . 2008-03-21 21:30 9,336 --------- C:WINDOWSsystem32driverscdr4_xp.sys
2030-10-30 17:52 . 2030-10-30 17:52 304 --ah----- C:sqmdata17.sqm
2030-10-30 17:52 . 2030-10-30 17:52 244 --ah----- C:sqmnoopt17.sqm
2030-10-29 23:27 . 2030-10-29 23:27 268 --ah----- C:sqmdata16.sqm
2030-10-29 23:27 . 2030-10-29 23:27 244 --ah----- C:sqmnoopt16.sqm
2030-10-28 22:54 . 2030-10-28 22:54 268 --ah----- C:sqmdata15.sqm
2030-10-28 22:54 . 2030-10-28 22:54 244 --ah----- C:sqmnoopt15.sqm
2030-10-28 01:19 . 2030-10-28 01:19 268 --ah----- C:sqmdata14.sqm
2030-10-28 01:19 . 2030-10-28 01:19 244 --ah----- C:sqmnoopt14.sqm
2030-10-27 00:19 . 2030-10-27 00:19 268 --ah----- C:sqmdata13.sqm
2030-10-27 00:19 . 2030-10-27 00:19 244 --ah----- C:sqmnoopt13.sqm
2030-10-26 00:14 . 2030-10-26 00:14 268 --ah----- C:sqmdata12.sqm
2030-10-26 00:14 . 2030-10-26 00:14 244 --ah----- C:sqmnoopt12.sqm
2030-10-24 23:42 . 2030-10-24 23:42 244 --ah----- C:sqmnoopt11.sqm
2030-10-24 23:42 . 2030-10-24 23:42 232 --ah----- C:sqmdata11.sqm
2030-10-24 23:32 . 2030-10-24 23:32 244 --ah----- C:sqmnoopt10.sqm
2030-10-24 23:32 . 2030-10-24 23:32 232 --ah----- C:sqmdata10.sqm
2030-10-24 23:27 . 2030-10-24 23:28 244 --ah----- C:sqmnoopt09.sqm
2030-10-24 23:27 . 2030-10-24 23:28 232 --ah----- C:sqmdata09.sqm
2030-10-24 23:26 . 2030-10-24 23:26 244 --ah----- C:sqmnoopt08.sqm
2030-10-24 23:26 . 2030-10-24 23:26 232 --ah----- C:sqmdata08.sqm
2030-10-24 23:25 . 2030-10-24 23:25 244 --ah----- C:sqmnoopt07.sqm
2030-10-24 23:25 . 2030-10-24 23:25 232 --ah----- C:sqmdata07.sqm
2030-10-10 21:00 . 2030-10-10 21:00 268 --ah----- C:sqmdata06.sqm
2030-10-10 21:00 . 2030-10-10 21:00 244 --ah----- C:sqmnoopt06.sqm
2030-10-10 19:57 . 2030-10-10 19:58 244 --ah----- C:sqmnoopt05.sqm
2030-10-10 19:57 . 2030-10-10 19:57 244 --ah----- C:sqmnoopt04.sqm
2030-10-10 19:57 . 2030-10-10 19:58 232 --ah----- C:sqmdata05.sqm
2030-10-10 19:57 . 2030-10-10 19:57 232 --ah----- C:sqmdata04.sqm
2008-10-08 14:03 . 2008-10-08 14:03 <REP> d-------- C:Program FilesLavasoft
2008-10-08 14:02 . 2008-10-08 14:02 <REP> d-------- C:Documents and SettingsAll UsersApplication DataLavasoft
2008-10-08 14:01 . 2008-10-08 14:01 <REP> d-------- C:Documents and SettingsGuillaume DragoApplication Data.clamwin
2008-10-08 13:59 . 2008-10-08 14:00 <REP> d-------- C:Program FilesFichiers communsWise Installation Wizard
2008-10-08 13:59 . 2008-10-08 13:59 <REP> d-------- C:Program FilesClamWin
2008-10-08 13:59 . 2008-10-08 13:59 <REP> d-------- C:Documents and SettingsAll Users.clamwin
2008-10-08 13:18 . 2001-09-14 12:10 <REP> d-------- C:Documents and SettingsAdministrateurWINDOWS
2008-10-08 13:18 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsAdministrateurVoisinage réseau
2008-10-08 13:18 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsAdministrateurVoisinage d'impression
2008-10-08 13:18 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsAdministrateurModèles
2008-10-08 13:18 . 2001-09-14 12:02 <REP> dr------- C:Documents and SettingsAdministrateurMes documents
2008-10-08 13:18 . 2001-09-14 11:43 <REP> dr------- C:Documents and SettingsAdministrateurMenu Démarrer
2008-10-08 13:18 . 2001-09-14 12:02 <REP> dr------- C:Documents and SettingsAdministrateurFavoris
2008-10-08 13:18 . 2001-09-14 11:43 <REP> d-------- C:Documents and SettingsAdministrateurBureau
2008-10-08 13:18 . 2001-09-14 14:50 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataSymantec
2008-10-08 13:18 . 2001-09-14 15:57 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataSony Corporation
2008-10-08 13:18 . 2001-09-14 13:45 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataInterTrust
2008-10-08 13:17 . 2008-10-08 13:18 <REP> d-------- C:Documents and SettingsAdministrateur
2008-10-08 13:10 . 2008-10-08 13:10 <REP> d--hs---- C:FOUND.002
2008-10-07 21:22 . 2008-10-07 21:22 <REP> d--hs---- C:FOUND.001
2008-10-07 20:40 . 2008-10-08 16:50 7 --a------ C:WINDOWSsystem32ANIWZCSUSERNAME{2356F30A-F204-48D7-98F6-7817F78A636F}
2008-10-07 20:39 . 2008-10-07 20:39 <REP> d--hs---- C:FOUND.000
2008-10-07 20:32 . 2008-10-07 20:32 <REP> d-------- C:Documents and SettingsTEMP.NOM-00CL76THY97
2008-10-07 17:36 . 2001-09-14 12:10 <REP> d-------- C:Documents and SettingsTEMPWINDOWS
2008-10-07 17:36 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsTEMPVoisinage réseau
2008-10-07 17:36 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsTEMPVoisinage d'impression
2008-10-07 17:36 . 2001-09-14 11:43 <REP> d--h----- C:Documents and SettingsTEMPModèles
2008-10-07 17:36 . 2008-10-07 17:36 <REP> dr------- C:Documents and SettingsTEMPMes documents
2008-10-07 17:36 . 2001-09-14 11:43 <REP> dr------- C:Documents and SettingsTEMPMenu Démarrer
2008-10-07 17:36 . 2001-09-14 12:02 <REP> dr------- C:Documents and SettingsTEMPFavoris
2008-10-07 17:36 . 2001-09-14 11:43 <REP> d-------- C:Documents and SettingsTEMPBureau
2008-10-07 17:36 . 2008-10-07 17:36 <REP> d-------- C:Documents and SettingsTEMP
2008-10-07 13:46 . 2008-10-07 13:46 <REP> d-------- C:WINDOWSsystem32fr
2008-10-07 13:46 . 2008-10-07 13:46 <REP> d-------- C:WINDOWSl2schemas
2008-10-04 10:57 . 2008-09-10 00:04 38,528 --a------ C:WINDOWSsystem32driversmbamswissarmy.sys
2008-10-03 19:50 . 2008-10-03 19:50 <REP> d-------- C:Documents and SettingsGuillaume Drago.gimp-2.6
2008-10-03 19:50 . 2008-10-03 19:50 <REP> d-------- C:Documents and SettingsGuillaume Drago.gegl-0.0
2008-09-25 20:53 . 2008-09-25 20:53 <REP> d-------- C:Documents and SettingsGuillaume Drago.thumbnails
2008-09-25 18:27 . 2008-09-25 18:27 <REP> d-------- C:Program FilesiPod
2008-09-25 18:26 . 2008-09-25 18:26 <REP> d-------- C:Program FilesiTunes
2008-09-25 18:26 . 2008-09-25 18:26 <REP> d-------- C:Documents and SettingsAll UsersApplication Data{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-25 18:21 . 2008-09-25 18:21 <REP> d-------- C:Program FilesBonjour
2008-09-25 18:17 . 2008-09-25 18:17 <REP> d-------- C:Program FilesQuickTime
2008-09-25 18:13 . 2008-09-25 18:13 <REP> d-------- C:Program FilesApple Software Update
2008-09-25 13:00 . 2004-08-20 00:09 221,184 --a------ C:WINDOWSsystem32wmpns.dll
2008-09-25 12:59 . 2008-09-25 12:59 <REP> d-------- C:Program FilesWindows Media Connect 2
2008-09-25 12:49 . 2008-09-25 12:49 <REP> d-------- C:WINDOWSsystem32driversUMDF
2008-09-24 22:24 . 2008-09-24 22:24 <REP> d-------- C:Documents and SettingsGuillaume DragoApplication DataSharePod
2008-09-21 11:07 . 2002-11-15 18:36 40,960 --a------ C:XP_FixLogon.exe
2008-09-17 13:47 . 2008-04-14 04:33 1,306,624 --------- C:WINDOWSsystem32msxml6.dll
2008-09-17 13:47 . 2008-04-14 04:33 1,306,624 --------- C:WINDOWSsystem32dllcachemsxml6.dll
2008-09-17 13:47 . 2008-04-14 04:33 651,264 --------- C:WINDOWSsystem32dot3ui.dll
2008-09-17 13:47 . 2008-04-14 04:33 397,312 --------- C:WINDOWSsystem32mmcex.dll
2008-09-17 13:47 . 2008-04-14 04:33 293,376 --------- C:WINDOWSsystem32qagentrt.dll
2008-09-17 13:47 . 2008-04-14 04:33 290,304 --------- C:WINDOWSsystem32
httpaa.dll
2008-09-17 13:47 . 2008-04-14 04:33 233,472 --------- C:WINDOWSsystem32azroles.dll
2008-09-17 13:45 . 2008-04-14 04:33 12,800 --------- C:WINDOWSsystem32credssp.dll
2008-09-17 13:45 . 2008-04-13 20:40 10,240 --------- C:WINDOWSsystem32driverssffp_mmc.sys
2008-09-17 13:45 . 2008-04-14 04:33 9,216 --------- C:WINDOWSsystem32dot3dlg.dll
2008-09-17 13:45 . 2008-04-14 04:33 7,168 --------- C:WINDOWSsystem32itsprx4.dll
2008-09-17 13:45 . 2008-04-14 04:31 6,144 --------- C:WINDOWSsystem32kbdpash.dll
2008-09-17 13:45 . 2008-04-14 04:31 6,144 --------- C:WINDOWSsystem32kbdnepr.dll
2008-09-17 13:45 . 2008-04-14 04:31 6,144 --------- C:WINDOWSsystem32kbdiultn.dll
2008-09-17 13:45 . 2008-04-14 04:31 6,144 --------- C:WINDOWSsystem32kbdbhc.dll
2008-09-17 13:44 . 2006-12-28 21:01 19,569 --a------ C:WINDOWS
005594_.tmp
2008-09-17 13:44 . 2008-04-14 04:10 2,524 --------- C:WINDOWSsystem32pid.inf
2008-09-11 16:39 . 2008-10-02 22:05 16 --a------ C:WINDOWSsystem32ANIWZCSUSERNAME{466652F9-2C89-4BB1-BCEE-2CED38E22E52}
2008-09-09 18:05 . 2008-09-09 18:05 <REP> d-------- C:Program FilesTI Education
2008-09-09 18:05 . 1999-04-18 22:00 9,152 --a------ C:WINDOWSsystem32driversTicalc.sys
2008-09-09 18:05 . 2008-09-09 18:20 342 --a------ C:WINDOWSWlink83.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 14:46 26,496 ----a-w C:WINDOWSsystem32driversFos26.sys
2008-10-08 13:54 90,112 ----a-w C:WINDOWSDUMP1dda.tmp
2008-09-23 10:27 90,112 ----a-w C:WINDOWSDUMP64e3.tmp
2008-09-09 22:03 17,200 ----a-w C:WINDOWSsystem32driversmbam.sys
2008-09-07 14:59 --------- d-----w C:Program FilesGuitar Pro 4 Demo
2008-09-07 14:56 --------- d-----w C:Program FilesGuitar Pro 3
2008-09-07 08:46 --------- d-----w C:Program FilesIZArc
2008-09-06 12:19 --------- d-----w C:Program FilesRegCleaner
2008-09-04 15:39 --------- d-----w C:Program FilesANI
2008-09-04 15:38 --------- d-----w C:Program FilesD-Link
2008-09-04 15:37 --------- d-----w C:Documents and SettingsGuillaume DragoApplication DataInstallShield
2008-08-29 08:18 87,336 ----a-w C:WINDOWSsystem32dns-sd.exe
2008-08-29 07:53 61,440 ----a-w C:WINDOWSsystem32dnssd.dll
2008-07-25 08:36 524,288 ----a-w C:WINDOWSsystem32DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:WINDOWSsystem32qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:WINDOWSsystem32ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:WINDOWSsystem32libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:WINDOWSsystem32DivXWMPExtType.dll
2008-07-18 20:10 94,920 ----a-w C:WINDOWSsystem32dllcachecdm.dll
2008-07-18 20:10 94,920 ----a-w C:WINDOWSsystem32cdm.dll
2008-07-18 20:10 53,448 ----a-w C:WINDOWSsystem32wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:WINDOWSsystem32dllcachewuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:WINDOWSsystem32wups2.dll
2008-07-18 20:10 36,552 ----a-w C:WINDOWSsystem32wups.dll
2008-07-18 20:10 36,552 ----a-w C:WINDOWSsystem32dllcachewups.dll
2008-07-18 20:09 563,912 ----a-w C:WINDOWSsystem32wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:WINDOWSsystem32dllcachewuapi.dll
2008-07-18 20:09 325,832 ----a-w C:WINDOWSsystem32wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:WINDOWSsystem32dllcachewucltui.dll
2008-07-18 20:09 205,000 ----a-w C:WINDOWSsystem32wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:WINDOWSsystem32dllcachewuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:WINDOWSsystem32wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:WINDOWSsystem32dllcachewuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:WINDOWSsystem32mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:WINDOWSsystem32muweb.dll
2008-03-12 09:29 32 ----a-w C:Documents and SettingsAll UsersApplication Dataezsid.dat
2008-03-11 18:36 32,768 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008030320080310index.dat
2008-03-24 17:21 49,152 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008031020080317index.dat
2008-03-24 18:02 32,768 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008032420080325index.dat
2008-03-25 17:52 49,152 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008032520080326index.dat
2008-03-26 14:00 32,768 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008032620080327index.dat
2008-03-27 19:05 32,768 --sha-w C:WINDOWSsystem32configsystemprofileLocal SettingsHistoriqueHistory.IE5MSHist012008032720080328index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="C:Program FilesSpybot - Search & DestroyTeaTimer.exe" [2008-08-18 1832272]
"swg"="C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2008-03-24 68856]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Apoint"="C:Program FilesApointApoint.exe" [2001-08-22 114688]
"AudioDeck"="C:Program FilesVIAVIAudioiSBADeckADeck.exe" [2007-08-09 528384]
"ANIWZCS2Service"="C:Program FilesANIANIWZCS2 ServiceWZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Wireless G DWA-110"="C:Program FilesD-LinkD-Link Wireless G DWA-110AirGCFG.exe" [2007-05-04 1662976]
"ClamWin"="C:Program FilesClamWininClamTray.exe" [2008-09-05 86016]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSSystem32CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.dvsd"= C:PROGRA~1FICHIE~1SONYSH~1DVLibsonydv.dll
"VIDC.MJPG"= sonymjpg.dll
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalFos26.sys]
@=""
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageMicrosoft Office.lnk
backup=C:WINDOWSpssMicrosoft Office.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NETGEAR WG111v2 Smart Wizard.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageNETGEAR WG111v2 Smart Wizard.lnk
backup=C:WINDOWSpssNETGEAR WG111v2 Smart Wizard.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^Guillaume Drago^Menu Démarrer^Programmes^Démarrage^Deewoo.lnk]
path=C:Documents and SettingsGuillaume DragoMenu DémarrerProgrammesDémarrageDeewoo.lnk
backup=C:WINDOWSpssDeewoo.lnkStartup
[HKLM~startupfolderC:^Documents and Settings^Guillaume Drago^Menu Démarrer^Programmes^Démarrage^DW_Start.lnk]
path=C:Documents and SettingsGuillaume DragoMenu DémarrerProgrammesDémarrageDW_Start.lnk
backup=C:WINDOWSpssDW_Start.lnkStartup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:Program FilesAdobeReader 8.0Reader
eader_sl.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregApoint]
--a------ 2001-08-22 17:23 114688 C:Program FilesApointApoint.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregctfmon.exe]
--a------ 2008-04-14 04:34 15360 C:WINDOWSsystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregiTunesHelper]
--a------ 2008-09-10 17:40 289576 C:Program FilesiTunesiTunesHelper.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:Program FilesWindows LiveMessengermsnmsgr.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNAV Agent]
--a------ 2001-08-21 10:28 74832 C:PROGRA~1NORTON~1Navapw32.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
--a------ 2008-09-06 15:09 413696 C:Program FilesQuickTimeQTTask.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSpybotSD TeaTimer]
-rahs---- 2008-08-18 18:41 1832272 C:Program FilesSpybot - Search & DestroyTeaTimer.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:Program FilesJavajre1.6.0_03injusched.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregswg]
--a------ 2008-03-24 20:20 68856 C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAtiPTA]
--a------ 2001-07-05 14:53 217088 C:WINDOWSsystem32atiptaxx.exe
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\Mozilla Firefox\firefox.exe"=
"C:\WINDOWS\System32\dpvsetup.exe"=
"C:\Program Files\Messenger\msmsgs.exe"=
"C:\Program Files\Bonjour\mDNSResponder.exe"=
"C:\Program Files\iTunes\iTunes.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2D]
ShellAutoRuncommand - D:setupSNK.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{3748de90-5e46-11dc-960c-0800462f86b6}]
shellSetupcommand - setup.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{3f2954ac-16d4-11dd-96d5-00146cb35e41}]
shellSetupcommand - setup.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{611b0580-6235-11dc-9617-0800462f86b6}]
shellSetupcommand - setup.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{7268c750-62a8-11dc-9618-0800462f86b6}]
shellSetupcommand - setup.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{7c254600-e91d-11dc-9689-00146cb35e41}]
shellSetupcommand - setup.exe
.
Contenu du dossier 'Tâches planifiées'
2007-07-16 C:WINDOWSTasksSymantec NetDetect.job
- C:Program FilesSymantecLiveUpdateNDETECT.EXE [2001-05-04 12:05]
2008-10-03 C:WINDOWSTasksNorton AntiVirus - Analyser mon ordinateur.job
- C:PROGRA~1NORTON~1NAVW32.exe [2001-08-21 10:29]
2008-10-08 C:WINDOWSTasksVérifier les mises à jour de Windows Live Toolbar.job
- C:Program FilesWindows Live ToolbarMSNTBUP.EXE [2007-10-19 11:20]
2008-10-08 C:WINDOWSTasksUser_Feed_Synchronization-{2D261215-4E1A-4AD7-96E5-A305FE9CB170}.job
- C:WINDOWSsystem32msfeedssync.exe [2007-08-13 18:36]
2008-09-25 C:WINDOWSTasksAppleSoftwareUpdate.job
- C:Program FilesApple Software UpdateSoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-avgnt - C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
MSConfigStartUp-dbar_starter - C:Documents and SettingsGuillaume DragoApplication DataDeskbar_{991EAA86-A5B5-4b44-B1ED-2AD405E8497B}starter.exe
MSConfigStartUp-ExploreUpdSched - C:WINDOWSsystem32
cntmkdm.exe
MSConfigStartUp-Host Process - C:WINDOWSFontssvchost.exe
MSConfigStartUp-LSA Shellu - C:Documents and SettingsGuillaume Dragolsass.exe
MSConfigStartUp-runner1 - C:WINDOWSmrofinu1188.exe
MSConfigStartUp-spa_start - C:WINDOWSsystem32{424dff1f-3820-df37-6ba7-fd5dea8c0b1c}.dll
MSConfigStartUp-WebSUpdater - C:Program Fileswinviwupda.exe
MSConfigStartUp-WinUpdater - C:Program Fileswinviupdate.exe
MSConfigStartUp-{82446a2a-7891-b199-2d4c-e6b56c8b7041} - C:WINDOWSsystem32{424dff1f-3820-df37-6ba7-fd5dea8c0b1c}.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:Documents and SettingsGuillaume DragoApplication DataMozillaFirefoxProfiles1c9uvidf.default
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.com/FF -: plugin - C:Program FilesiTunesMozilla Plugins
pitunes.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-10-08 16:49:53
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:Program FilesLavasoftAd-Awareaawservice.exe
C:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
C:WINDOWSSystem32ati2evxx.exe
C:Program FilesApointApntex.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesNorton AntiVirus
avapsvc.exe
C:WINDOWSSYSTEM32WSCNTFY.EXE
C:WINDOWSsystem32imapi.exe
.
**************************************************************************
.
Heure de fin: 2008-10-08 16:55:06 - La machine a redémarré [Guillaume Drago]
ComboFix-quarantined-files.txt 2008-10-08 14:54:46
Avant-CF: 1 216 110 592 octets libres
Après-CF: 1,364,377,600 octets libres
309 --- E O F --- 2008-10-07 11:58:08