ComboFix 10-02-08.06 - Laurent 09/02/2010 10:36:27.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.642 [GMT 1:00]
Lancé depuis: C:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Laurent\LOCALS~1\Temp\sessmgr.exe
c:\documents and settings\Laurent\Application Data\\Microsoft\logman.exe
c:\documents and settings\Laurent\Application Data\cisvc.exe
c:\documents and settings\Laurent\Application Data\clipsrv.exe
c:\documents and settings\Laurent\Application Data\cmstp.exe
c:\documents and settings\Laurent\Application Data\comrepl.exe
c:\documents and settings\Laurent\Application Data\dllhst3g.exe
c:\documents and settings\Laurent\Application Data\ieudinit.exe
c:\documents and settings\Laurent\Application Data\inst.exe
c:\documents and settings\Laurent\Application Data\Microsoft\clipsrv.exe
c:\documents and settings\Laurent\Application Data\Microsoft\comrepl.exe
c:\documents and settings\Laurent\Application Data\Microsoft\logman.exe
c:\documents and settings\Laurent\Application Data\Microsoft\mstsc.exe
c:\documents and settings\Laurent\Application Data\Microsoft\spoolsv.exe
c:\documents and settings\Laurent\Application Data\mqtgsvc.exe
c:\documents and settings\Laurent\Application Data\mstsc.exe
c:\documents and settings\Laurent\Application Data\sessmgr.exe
c:\documents and settings\Laurent\Local Settings\Application Data\cmstp.exe
c:\documents and settings\Laurent\Local Settings\Application Data\esentutl.exe
c:\documents and settings\Laurent\Local Settings\Application Data\Microsoft\mstinit.exe
c:\documents and settings\Laurent\Local Settings\Application Data\Microsoft\rsvp.exe
c:\documents and settings\Laurent\Local Settings\Application Data\Microsoft\sessmgr.exe
c:\documents and settings\Laurent\Local Settings\Application Data\sessmgr.exe
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\101.gif
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\102.gif
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\103.gif
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\104.gif
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\105.gif
c:\documents and settings\Laurent\Local Settings\Temporary Internet Files\106.gif
C:\install.exe
C:\setup.exe
C:\Thumbs.db
c:\windows\CISVC.exe
c:\windows\cmstp.exe
c:\windows\comrepl.exe
c:\windows\dllhst3g.exe
c:\windows\rsvp.exe
c:\windows\sessmgr.exe
c:\windows\spoolsv.exe
c:\windows\system\cisvc.exe
c:\windows\system\comrepl.exe
c:\windows\system\dllhst3g.exe
c:\windows\system\esentutl.exe
c:\windows\system\mqtgsvc.exe
c:\windows\system32\drivers\cmstp.exe
c:\windows\system32\drivers\esentutl.exe
c:\windows\system32\drivers\logman.exe
c:\windows\system32\drivers\mstinit.exe
c:\windows\system32\drivers\mstsc.exe
c:\windows\system32\drivers\sessmgr.exe
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-09 au 2010-02-09 ))))))))))))))))))))))))))))))))))))
.
2010-02-09 09:49 . 2009-11-18 13:22 95232 ----a-w- c:\windows\system32\drivers\esentutl.exe
2010-02-09 09:49 . 2009-11-18 13:22 95232 ----a-w- c:\windows\spoolsv.exe
2010-02-09 09:16 . 2010-02-09 09:16 5115824 ----a-w- C:\mbam-setup.exe
2010-02-03 19:33 . 2010-02-03 19:33 1217 ----a-w- C:\FindyKill_Upload_Me_CLARKENT.zip
2010-02-03 18:56 . 2010-02-03 20:23 -------- d-----w- C:\FyK
2010-02-02 21:39 . 2010-02-02 21:39 -------- d-----w- C:\ArcSoftTMTPlatinum3.0.1.161
2010-01-31 09:52 . 2010-01-31 09:52 -------- d-----w- C:\avz4
2010-01-31 09:50 . 2010-01-31 09:52 5125238 ----a-w- C:\avz4.zip
2010-01-30 15:25 . 2010-01-30 15:25 -------- d-----w- c:\documents and settings\Laurent\Local Settings\Application Data\RapidSolution
2010-01-30 15:24 . 2010-01-30 15:25 1285464 ----a-w- C:\Tunebite_7_01net.exe
2010-01-30 14:57 . 2010-01-30 14:57 -------- d-----w- c:\documents and settings\Laurent\Local Settings\Application Data\vdownloader
2010-01-30 14:56 . 2010-01-30 14:56 -------- d-----w- c:\program files\Fichiers communs\eBay
2010-01-30 14:56 . 2010-01-30 14:56 -------- d-----w- C:\vdownloader-latest
2010-01-30 13:50 . 2010-01-30 13:52 -------- d-----w- C:\appareil défectueux
2010-01-30 09:20 . 2010-01-30 09:20 -------- d-----w- c:\program files\SDP Multimedia
2010-01-30 09:19 . 2010-01-30 09:19 1384960 ----a-w- C:\sdp-multimedia_sdp_multimedia_2.3.0_anglais_32700.msi
2010-01-29 11:00 . 2010-01-29 11:04 -------- d-----w- C:\concert dm lievin
2010-01-28 18:33 . 2010-01-30 11:46 -------- d-----w- C:\videocacheview
2010-01-28 18:32 . 2010-01-28 18:32 69631 ----a-w- C:\videocacheview.zip
2010-01-26 21:17 . 2010-02-09 09:33 3852017 ----a-r- C:\ComboFix.exe
2010-01-19 22:48 . 2010-01-19 22:48 165440 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-13 08:39 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 07:43 . 2008-12-04 13:02 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-13 09:04 . 2009-03-05 11:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-12 16:25 . 2001-10-04 00:54 966038 ----a-w- c:\windows\system32\perfh00C.dat
2010-01-12 16:25 . 2001-10-04 00:54 310858 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-21 19:07 . 2004-08-03 22:54 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-07 09:41 . 2009-12-07 09:41 812 ----a-w- C:\IoPageLockLimit1024Mo.reg
2009-11-24 14:19 . 2006-08-30 15:24 73496 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:58 . 2004-08-03 22:54 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-18 13:22 . 2010-02-09 09:49 95232 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\mstinit.exe
2009-11-18 13:22 . 2010-02-09 09:49 95232 ----a-w- c:\documents and settings\Laurent\Local Settings\Application Data\esentutl.exe
2009-11-18 13:19 . 2009-11-18 13:19 74703 ----a-w- c:\windows\system32\mfc45.dll
2009-10-17 13:59 . 2009-10-17 13:59 9451515 ----a-w- c:\program files\vlc-0.8.6-win32.exe
1997-03-24 06:50 . 2007-06-27 20:47 10089 ----a-w- c:\program files\README.TXT
2008-05-04 14:48 . 2006-10-05 19:18 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-05-04 14:48 . 2006-10-05 19:18 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-05-04 14:48 . 2008-03-10 11:29 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-05-04 14:48 . 2008-03-10 11:29 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-05-04 14:48 . 2006-10-05 19:18 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-01-12 09:14 . 2008-01-12 09:13 24 --sh--w- c:\windows\SAA0050C7.tmp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 110592]
"BootSkin Startup Jobs"="c:\program files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 270336]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"Windows Media Connect 2"="c:\program files\Windows Media Connect 2\WMCCFG.exe" [2006-10-18 8704]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Esent Utl"="c:\docume~1\Laurent\LOCALS~1\APPLIC~1\esentutl.exe" [2009-11-18 95232]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Esent Utl"="c:\windows\System32\drivers\esentutl.exe" [2009-11-18 95232]
"Cisvc"="c:\docume~1\Laurent\LOCALS~1\APPLIC~1\MICROS~1\cisvc.exe" [2009-11-18 95232]
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Spool"="c:\windows\spoolsv.exe" [2009-11-18 95232]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=c:\docume~1\Laurent\LOCALS~1\APPLIC~1\mstinit.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 21:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2006-11-20 04:00 116096 ----a-w- c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
2004-12-16 15:49 49152 ----a-w- c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2008-10-17 11:32 89024 ----a-w- c:\program files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Belgacom]
2006-06-22 08:34 192512 ----a-w- c:\program files\Belgacom\bin\sprtcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
2005-04-22 15:51 1236992 ----a-w- c:\program files\D-Link\AirPlus G\AirGCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-02 21:28 133104 ----atw- c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-11-20 12:20 290088 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 14:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 15:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2005-09-22 16:42 90112 ------r- c:\windows\soundman.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
2006-12-27 15:53 73840 ----a-r- c:\program files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-01-01 09:58 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Alcohol Soft\\Alcohol 120\\Alcohol.exe"=
"c:\\Program Files\\Alcohol Soft\\Alcohol 120\\AxCmd.exe"=
"c:\\Program Files\\innotek VirtualBox\\VirtualBox.exe"=
"c:\\Program Files\\Proxy Switcher Standard\\ProxySwitcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Media Connect 2\\WMCCFG.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Office 2007\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4672:UDP"= 4672:UDP:udp
"4662:TCP"= 4662:TCP:tcp
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [13/03/2008 16:52 33800]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [11/01/2008 19:54 39584]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [11/01/2008 19:54 27744]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [13/03/2008 16:49 472320]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/12/2008 10:25 54752]
S0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\drivers\tffsport.sys [14/03/2008 10:55 149376]
S3 Fadpu16E;Fadpu16E;\??\c:\docume~1\Laurent\LOCALS~1\Temp\Fadpu16E.sys --> c:\docume~1\Laurent\LOCALS~1\Temp\Fadpu16E.sys [?]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [5/08/2009 21:48 704864]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 16:13 234864]
S3 TVService;TVService;c:\program files\Team MediaPortal\MediaPortal TV Server\TvService.exe [10/10/2008 0:31 184320]
S3 VBoxTAP;VirtualBox TAP Adapter;c:\windows\system32\drivers\VBoxTAP.sys [11/01/2008 19:55 47296]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [11/01/2008 19:54 30688]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [16/07/2007 20:56 685816]
.
Contenu du dossier 'Tâches planifiées'
2009-12-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-02-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-2025429265-725345543-1003Core.job
- c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 21:28]
2010-02-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-2025429265-725345543-1003UA.job
- c:\documents and settings\Laurent\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 21:28]
2010-02-09 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyServer = 127.0.0.1:8080
uInternet Settings,ProxyOverride = local;*.local
uSearchURL,(Default) = hxxp://
www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\Office 2007\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Laurent\Application Data\Mozilla\Firefox\Profiles\ohyo8ne6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://
www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Registry Compact - c:\program files\Systerac XP Tools 4\regcomp.exe
HKLM-Run-dbvstart - c:\documents and settings\Laurent\Mes documents\dreambox_viewer\dreambox viewer\mfaraj dreambox viewer4\mfaraj dreambox viewer4\mfaraj dreambox viewer\dbvstart.bat
HKLM-Explorer_Run-DllHst - c:\docume~1\Laurent\APPLIC~1\dllhst3g.exe
HKLM-Explorer_Run-IEudinit - c:\docume~1\Laurent\APPLIC~1\ieudinit.exe
HKLM-Explorer_Run-Cisvc - c:\windows\System\cisvc.exe
HKLM-Explorer_Run-CmSTP - c:\windows\System32\drivers\cmstp.exe
HKLM-Explorer_Run-SessMgr - c:\windows\System32\drivers\sessmgr.exe
HKLM-Explorer_Run-rsvp - c:\docume~1\Laurent\LOCALS~1\APPLIC~1\MICROS~1\rsvp.exe
HKLM-Explorer_Run-ClipSrv - c:\docume~1\Laurent\APPLIC~1\MICROS~1\clipsrv.exe
HKCU-Explorer_Run-ComRepl - c:\docume~1\Laurent\APPLIC~1\MICROS~1\comrepl.exe
HKCU-Explorer_Run-DllHst - c:\windows\dllhst3g.exe
MSConfigStartUp-Pando - c:\program files\Pando Networks\Pando\Pando.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\adobe\SHOCKW~1\UNWISE.EXE
AddRemove-eMule - c:\program files\eMule 0.49\Uninstall.exe
AddRemove-Mihov Image Resizer - c:\program files\Mihov Image Resizer\Uninstall.exe
AddRemove-mIRC - c:\documents and settings\Laurent\Mes documents\laurent\Save\save\backups\mIRC\mirc.exe
AddRemove-Titan Poker - c:\poker\Titan Poker\_SetupPoker.exe
AddRemove-{CA567AD5-33A4-403D-86D1-EE2D38251951}_is1 - c:\program files\VDOWNLOADER\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-09 10:48
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3508)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Heure de fin: 2010-02-09 10:53:53 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-02-09 09:53
Avant-CF: 18.161.754.112 octets libres
Après-CF: 18.347.741.184 octets libres
Current=5 Default=5 Failed=1 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - 0FD2CF7F5166AB0B7FEC189749250A11