Merci beaucoup pour l'analyse de ma dernière réponse (d'ailleurs, ou je peux trouver un totu pour l'analyse d'un sacn!)
j'ai suivi ta procédure et voila le resultat :
ComboFix 09-04-04.01 - .Wilou 2009-04-09 22:00:52.1 - NTFSx86
Lancé depuis: d:\desktop\ComboFix.exe
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Acer\Acer Bio Protection\PwdFilter.dll
c:\program files\Common Files\komo
c:\program files\Common Files\komo\komoa.lck
c:\program files\Common Files\komo\komod\class-barrel
c:\program files\Common Files\komo\komod\komoc.dll
c:\program files\Common Files\komo\komod\vocabulary
c:\program files\Common Files\komo\komol.lck
c:\program files\Common Files\komo\komom.lck
c:\program files\Common Files\komo\komop.exe
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\ISM
c:\program files\ISM\ism.exe
c:\program files\ISM\Uninstall.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\users\.Wilou\AppData\Local\Microsoft\Windows\Temporary Internet Files\bestwiner.stt
c:\users\.Wilou\AppData\Local\Microsoft\Windows\Temporary Internet Files\CPV.stt
c:\users\.Wilou\AppData\Local\Microsoft\Windows\Temporary Internet Files\fbk.sts
c:\users\.Wilou\AppData\Roaming\.#
c:\users\.Wilou\AppData\Roaming\GetModule
c:\users\.Wilou\AppData\Roaming\GetModule\dicik.gz
c:\users\.Wilou\AppData\Roaming\GetModule\kwdik.gz
c:\users\.Wilou\AppData\Roaming\GetModule\ofadik.gz
c:\users\.Wilou\AppData\Roaming\inst.exe
c:\windows\komo
c:\windows\komo\komo.dat
c:\windows\komo\wu
c:\windows\system32\atmtd.dll._
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\winsrc.dll.tmp
H:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-09 au 2009-04-09 ))))))))))))))))))))))))))))))))))))
.
2009-04-09 17:46 . 2009-04-09 17:46 <REP> d--hs---- C:\found.000
2009-04-09 17:29 . 2009-04-09 21:59 <REP> d-------- c:\users\.Wilou\AppData\Roaming\Vista Start Menu
2009-04-09 17:29 . 2009-04-09 17:29 <REP> d-------- c:\program files\Vista Start Menu
2009-04-09 14:58 . 2009-04-09 14:58 <REP> d-------- c:\program files\Launch Manager
2009-04-09 14:58 . 2007-12-03 15:11 207,368 --a------ c:\windows\UNINST32.EXE
2009-04-09 14:58 . 2006-11-02 21:29 21,264 --a------ c:\windows\System32\drivers\DKbFltr.sys
2009-04-09 14:58 . 2009-04-09 14:58 83 --a------ c:\windows\LManager.UNI
2009-04-04 15:50 . 2009-04-04 15:50 <REP> d-------- c:\program files\Common Files\Adobe AIR
2009-04-03 21:55 . 2009-04-03 21:55 <REP> d-------- c:\users\.Wilou\AppData\Roaming\UBitMenu
2009-04-03 19:07 . 2009-04-03 19:07 <REP> dr------- c:\users\.Wilou\Documents
2009-04-02 19:20 . 2007-12-26 17:30 1,970,176 --a------ c:\windows\System32\d3dx9.dll
2009-04-02 19:20 . 2007-12-26 17:30 679,936 --a------ c:\windows\System32\D3DX81ab.dll
2009-03-30 00:16 . 2009-04-09 15:36 <REP> d-------- c:\users\All Users\Cyberlink
2009-03-30 00:16 . 2009-04-09 15:36 <REP> d-------- c:\programdata\Cyberlink
2009-03-22 03:24 . 2008-10-27 19:37 192,307 --a------ C:\wubildr
2009-03-22 03:24 . 2008-10-27 19:37 8,192 --a------ C:\wubildr.mbr
2009-03-12 10:35 . 2009-03-12 10:36 <REP> d-------- c:\program files\Microsoft Visual Studio 9.0
2009-03-11 20:38 . 2008-12-16 05:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-11 20:38 . 2009-02-09 05:10 2,033,152 --a------ c:\windows\System32\win32k.sys
2009-03-11 20:38 . 2008-11-27 06:43 268,288 --a------ c:\windows\System32\schannel.dll
2009-03-11 20:38 . 2008-12-16 07:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-11 20:38 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-11 20:38 . 2008-12-16 07:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-11 12:51 . 2008-04-18 07:30 2,241,536 --a------ c:\windows\System32\msi.dll
2009-03-11 12:51 . 2008-04-18 07:30 332,800 --a------ c:\windows\System32\msihnd.dll
2009-03-11 12:51 . 2008-04-18 04:33 73,216 --a------ c:\windows\System32\msiexec.exe
2009-03-11 12:51 . 2008-04-18 04:33 2,560 --a------ c:\windows\System32\msimsg.dll
2009-03-11 12:46 . 2009-03-11 12:46 <REP> d-------- c:\windows\System32\Visual Studio 2008Templates
2009-03-11 12:46 . 2009-03-11 12:46 <REP> d-------- c:\windows\System32\Visual Studio 2008
2009-03-11 12:44 . 2009-03-11 12:44 <REP> d-------- c:\program files\Common Files\Merge Modules
2009-03-11 12:36 . 2008-06-20 03:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-03-11 12:36 . 2008-06-20 03:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-03-11 12:35 . 2008-06-20 03:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-03-11 12:35 . 2008-06-20 03:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-03-11 12:35 . 2008-06-20 03:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-03-11 12:35 . 2008-06-20 03:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-03-11 12:35 . 2008-06-20 03:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-03-11 12:35 . 2008-06-20 03:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-03-11 12:27 . 2008-07-27 20:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-03-11 12:27 . 2008-07-27 20:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-03-11 12:27 . 2008-07-27 20:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-03-11 12:25 . 2008-07-27 20:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-03-11 12:25 . 2008-07-27 20:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-03-11 12:08 . 2009-03-11 12:08 <REP> d----c--- C:\Temp
2009-03-09 22:20 . 2009-03-09 22:20 <REP> d-------- c:\users\All Users\Office Genuine Advantage
2009-03-09 22:20 . 2009-03-09 22:20 <REP> d-------- c:\programdata\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 20:10 --------- d-----w c:\program files\Google
2009-04-09 19:58 205,054 ----a-w c:\users\All Users\nvModes.dat
2009-04-09 19:58 205,054 ----a-w c:\programdata\nvModes.dat
2009-04-09 13:39 319,456 ----a-w c:\windows\DIFxAPI.dll
2009-04-09 13:39 --------- d--h--w c:\program files\InstallShield Installation Information
2009-04-09 13:35 --------- d-----w c:\programdata\Google Updater
2009-04-08 12:48 --------- d-----w c:\users\.Wilou\AppData\Roaming\codeblocks
2009-04-06 06:26 --------- d-----w c:\program files\Microsoft SQL Server
2009-04-04 13:50 --------- d-----w c:\program files\Common Files\Adobe
2009-04-02 13:28 --------- d-----w c:\users\.Wilou\AppData\Roaming\dvdcss
2009-04-01 19:11 --------- d-----w c:\users\.Wilou\AppData\Roaming\Dev-Cpp
2009-03-29 10:48 --------- d-----w c:\program files\Common Files\Apple
2009-03-25 13:41 --------- d-----w c:\program files\Java
2009-03-12 08:41 --------- d-----w c:\programdata\Microsoft Help
2009-03-12 08:08 --------- d-----w c:\program files\Windows Mail
2009-02-27 17:16 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-25 20:32 --------- d-----w c:\users\.Wilou\AppData\Roaming\Sports Interactive
2009-02-25 20:31 --------- d-----w c:\programdata\Sports Interactive
2009-02-25 10:14 --------- d-----w c:\program files\eMule
2009-02-24 14:34 --------- d-----w c:\programdata\Electronic Arts
2009-02-23 14:42 --------- d-----w c:\program files\Electronic Arts
2009-02-22 15:46 --------- d-----w c:\program files\Ubisoft
2009-02-21 22:39 --------- d-----w c:\program files\Windows Live
2009-02-11 07:28 --------- d-----w c:\users\.Wilou\AppData\Roaming\Twain
2009-02-10 17:16 --------- d-----w c:\program files\WebShow
2009-02-10 13:52 --------- d-----w c:\program files\SixaxisDriver
2009-02-10 12:29 --------- d-----w c:\users\.Wilou\AppData\Roaming\DAEMON Tools Pro
2009-02-10 12:29 --------- d-----w c:\users\.Wilou\AppData\Roaming\DAEMON Tools Lite
2009-02-10 12:29 --------- d-----w c:\users\.Wilou\AppData\Roaming\DAEMON Tools
2009-02-09 19:27 --------- d-----w c:\programdata\DAEMON Tools Lite
2009-02-09 19:26 --------- d-----w c:\program files\DAEMON Tools Lite
2009-02-09 17:57 --------- d-----w c:\program files\Common Files\Nero
2009-02-09 17:26 --------- d-----w c:\programdata\Nero
2009-02-06 18:39 308,600 ----a-w c:\windows\WLXPGSS.SCR
2009-01-08 21:05 22,328 ----a-w c:\users\.Wilou\AppData\Roaming\PnkBstrK.sys
2008-11-09 13:51 47,360 ----a-w c:\users\.Wilou\AppData\Roaming\pcouffin.sys
2008-09-10 17:50 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-09-10 17:50 56 ---ha-w c:\programdata\ezsidmv.dat
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2005-08-02 15:46 187,904 --sha-r c:\windows\LldpbG91\asappsrv.dll
2008-07-24 18:26 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-07-24 18:26 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-07-24 18:26 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-05 00:38 121392 --a------ c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-05-16 213936]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"VistaStartMenu"="c:\program files\Vista Start Menu\VistaStartMenu.exe" [2009-03-06 2171392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-03-11 397312]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 526896]
"eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-03-07 544768]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-07 13527584]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-07 92704]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-10-03 178712]
"ZPdtWzdVitaKey MC3000"="c:\program files\Acer\Acer Bio Protection\PdtWzd.exe" [2008-04-08 3642368]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-03-05 167936]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2008-03-04 167936]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-22 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-06 148888]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-03-13 805384]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-04-24 723760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2008-04-08 17:27 3024384 c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
--------- 2008-03-05 15:55 147456 c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cogad]
--a------ 2009-01-15 10:44 56832 c:\users\.Wilou\AppData\Roaming\cogad\cogad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
--a------ 2009-02-06 20:17 3325952 c:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2009-01-05 18:49 133104 c:\users\.Wilou\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 11:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{49D39706-E2E2-43B9-A364-9303B76DC1B6}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{3D3DE517-3166-4E93-B5C7-B3CCE0C172C2}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{498011BF-7211-443F-939B-5DDB64FF079A}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{22FE577E-43C8-4B8F-9F10-B01EA6F75C86}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{7F06B4FC-9FA5-49A5-8234-9E9C544AA303}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{4F849E18-5DF4-47CD-8C88-A42DEED3D782}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{33848A1F-9210-4361-8098-054468A7A0E8}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{DA18B09E-E83C-47AD-8473-C6CE01FEAF6E}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{ECDEFD53-71C6-4097-B016-B42979566158}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PlayMovie.exe:Acer Play Movie
"{B0706A4C-D606-4C2E-A02B-CC6900B6F2FC}"= c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe:Acer Play Movie Resident Program
"{B6A4A1FC-107D-4C31-87EF-786BECE5F395}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:Acer HomeMedia
"{923A2BA8-2413-4ED5-B3B2-E25CB80ED639}"= c:\program files\Acer\Acer VCM\VC.exe:Acer VCM
"{E85C1D03-267C-4D66-A336-C4F5B954147F}"= UDP:c:\users\.Wilou\Jeux\PES2008.exe:Pro Evolution Soccer 2008
"{246C9FDC-B1DF-40B4-A141-6D5C30999B36}"= TCP:c:\users\.Wilou\Jeux\PES2008.exe:Pro Evolution Soccer 2008
"{1EF9788F-AB75-419A-BEEF-F594F76F8FC0}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{13FCD551-A658-49F4-8E4C-F1B578614D81}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{C998FF00-C361-4C47-96A2-5EEC9068D2C6}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{ED04FDFA-AA0E-4CCB-A6DD-A284E6FDD968}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{416F0977-95C0-437D-B9AC-3FBDD9F90B04}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{34BBD43B-C46E-4990-96F9-C35726341621}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{BFE6722E-73AE-4BC3-87D7-6FC4433CD3AE}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{88D95229-989F-4E40-A920-09CC80C89A30}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{4C7AA2B8-A226-4EBD-A050-AB16D19790AB}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{49702048-E430-4964-8AA6-979BA9944A12}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{C2ABE6DD-10FD-4E1D-A090-3E6D0B160432}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{F05B4041-B8A1-44B3-A3B7-9DB7744A0AED}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{61A7A51D-54D8-4F95-8BBE-BCEBD59655D6}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{14A5D192-3C7B-42CF-993A-71E074CF4D00}"= UDP:c:\program files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{F37ED06B-2061-4EC5-90A1-C5C258210F60}"= TCP:c:\program files\Cyanide\GameCenter\GameCenter.exe:GameCenter
"{22BA0F2E-0641-4128-8E28-337D258ABA8C}"= UDP:c:\program files\Cyanide\Pro Cycling Manager - Season 2008\PCM.exe:Pro Cycling Manager - Season 2008
"{2CA41536-8BF9-4464-829A-7572141BE52A}"= TCP:c:\program files\Cyanide\Pro Cycling Manager - Season 2008\PCM.exe:Pro Cycling Manager - Season 2008
"{9971A3C2-C12B-4D35-B07C-8D5B1C9DC7D3}"= UDP:c:\program files\Cyanide\Pro Cycling Manager - Season 2008\Autorun\Exe\Autorun.exe:Pro Cycling Manager - Season 2008 - AutoRun
"{F22CCCA6-AB94-453C-8661-BC23E5ED2051}"= TCP:c:\program files\Cyanide\Pro Cycling Manager - Season 2008\Autorun\Exe\Autorun.exe:Pro Cycling Manager - Season 2008 - AutoRun
"{F520BDA8-C596-4602-8538-E0ACE504BEC8}"= UDP:d:\desktop\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{CCC3E262-E5A0-454B-84BA-1C43C08D22A5}"= TCP:d:\desktop\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{E6772248-28AF-4797-BB1B-B88B6C55B4DD}"= UDP:d:\desktop\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{6C8849FE-CDFA-42E8-BF29-225A0B9039C2}"= TCP:d:\desktop\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{B67DF441-23DB-4A25-824A-577812FE7DA9}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{D4337A21-96B9-42A7-9DDF-7ACC3F860837}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{36D90931-4241-46FF-972E-7FA7B8466722}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C9F6B417-0506-4D41-BA12-8E88E0D4310F}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{890DB800-B8F0-4878-8748-02EEC1356C8B}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{CF32A552-F0B2-49D7-8C83-06BDDA9AC44E}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{E06E6C30-C004-431E-AB94-E83817B0BB23}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{07C9F213-028F-45AA-81EE-977B82CC7731}e:\\crack\\pes2009.exe"= UDP:e:\crack\pes2009.exe:Pro Evolution Soccer 2009
"UDP Query User{1C150845-4FBF-4B7E-B498-F45FD0F6BA4C}e:\\crack\\pes2009.exe"= TCP:e:\crack\pes2009.exe:Pro Evolution Soccer 2009
"TCP Query User{BB6F0D55-60D8-4B6A-8150-36ACE37CCA90}d:\\documents\\my games\\crack\\pes2009.exe"= UDP:d:\documents\my games\crack\pes2009.exe:Pro Evolution Soccer 2009
"UDP Query User{50A9C3E6-2421-41F7-B0B8-19FED97BF0D8}d:\\documents\\my games\\crack\\pes2009.exe"= TCP:d:\documents\my games\crack\pes2009.exe:Pro Evolution Soccer 2009
"{F61CB41F-2BEB-4640-AFFE-B497BC8EFC94}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8DEF2310-E14E-4B7F-9A59-BB71BCFF29C6}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F7AF19D7-321B-49A2-A203-EE31AB3CD32D}"= UDP:c:\program files\Team MediaPortal\MediaPortal TV Server\TvService.exe:MediaPortal TV Server
"{CA1802E5-6379-43F5-802B-C27025B3F7F2}"= TCP:c:\program files\Team MediaPortal\MediaPortal TV Server\TvService.exe:MediaPortal TV Server
"{2BFAE209-92EB-4689-9E8E-49755502DF2D}"= UDP:c:\program files\Team MediaPortal\MediaPortal\MediaPortal.exe:MediaPortal
"{EC5E0E8E-4850-45C1-867F-7D4A475FB86E}"= TCP:c:\program files\Team MediaPortal\MediaPortal\MediaPortal.exe:MediaPortal
"{40E51BD8-221B-4211-907F-C47C3AA5B992}"= UDP

LocalSubnet:LocalSubnet:Microsoft SQL (TCP)
"{200D69B7-D258-466F-A3C1-47E332A35E9A}"= TCP

LocalSubnet:LocalSubnet:Microsoft SQL (UDP)
"{ED53CFC4-8BBA-42E8-80D0-8D6F9337DF80}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2008\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{E3891B14-D308-412E-9432-9E2D331B8795}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2008\vty-0143\PES2008.exe:Pro Evolution Soccer 2008
"{28C0470A-69B2-44ED-8FF7-E77D44D91551}"= UDP:d:\documents\My Games\Crack\pes2009.exe:Pro Evolution Soccer 2009
"{BC33C22E-4664-450E-A74D-6296CCA8183E}"= TCP:d:\documents\My Games\Crack\pes2009.exe:Pro Evolution Soccer 2009
"{7EA57069-DABF-44F1-9295-7A5BD2B76F90}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{1D8FBB5F-F73E-4BF8-9034-10FFDF69D45B}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{F09EFA92-2CED-4E0C-A687-E6038CE3D62B}"= UDP:g:\crack\pes2009.exe:Pro Evolution Soccer 2009
"{DDBF791D-6786-4C66-8CD5-E72D892F6EBA}"= TCP:g:\crack\pes2009.exe:Pro Evolution Soccer 2009
"{1935DB85-0C05-4599-98FA-E9DBAC5D0C13}"= UDP:e:\crack\pes2009.exe:Pro Evolution Soccer 2009
"{C96D37C7-7EEA-4485-862E-F5B5F15913D5}"= TCP:e:\crack\pes2009.exe:Pro Evolution Soccer 2009
"TCP Query User{5B207E9A-230B-4706-B1D4-7956A0528715}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{0FAB7B16-1FB9-4D54-8056-809D337CC902}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{BD3288D1-4C68-4513-9D2B-7FACA29CB506}"= UDP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"{D4B4EADC-A567-4528-982C-9C54C6783083}"= TCP:c:\program files\KONAMI\Pro Evolution Soccer 2009\pes2009.exe:Pro Evolution Soccer 2009
"TCP Query User{4CC9C9D2-7E74-48B0-86CD-3A9DA16AF7A1}c:\\program files\\ea games\\battlefield 1942\\bf1942.exe"= UDP:c:\program files\ea games\battlefield 1942\bf1942.exe:BF1942
"UDP Query User{20DE7785-0C2D-4D79-842E-13B2BAD6EEB2}c:\\program files\\ea games\\battlefield 1942\\bf1942.exe"= TCP:c:\program files\ea games\battlefield 1942\bf1942.exe:BF1942
"TCP Query User{933EBA6A-530E-4043-BBDC-32F3FD5EC817}c:\\program files\\ea games\\battlefield 1942\\bf1942.exe"= UDP:c:\program files\ea games\battlefield 1942\bf1942.exe:BF1942
"UDP Query User{8F15EC89-79ED-4DF1-BAC8-B7A621183EB3}c:\\program files\\ea games\\battlefield 1942\\bf1942.exe"= TCP:c:\program files\ea games\battlefield 1942\bf1942.exe:BF1942
"{83AD2061-75CD-4AD9-8AF1-AF1C2A02F354}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D67A845D-A133-4875-BBED-845C3305C328}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{C8E44766-C582-4692-8122-EAADDE512180}"= UDP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{77C88D9E-3A30-4A04-B401-529CF2883C36}"= TCP:c:\windows\System32\PnkBstrA.exe:PnkBstrA
"{0675B83C-61D3-4E50-A332-3E265F78E90D}"= UDP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{77B5A308-BC16-4E06-B707-DD8921A6B6FE}"= TCP:c:\windows\System32\PnkBstrB.exe:PnkBstrB
"{6EC86D25-49A7-4E15-A5E1-959BCD5DCD90}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\farcry2.exe:Far Cry 2
"{F2BD727A-1686-486B-93DE-B0CD04F2703F}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\farcry2.exe:Far Cry 2
"{0059C1BE-6854-4F3F-B684-109E6F7137FE}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{CDA7944F-8C29-4E7C-B91E-9F57F7EC217E}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{A830F725-3424-48CE-A4A6-4B1C53195BD3}"= UDP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editeur
"{42897759-D994-42C5-B094-70F16CC01BDA}"= TCP:c:\program files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editeur
"TCP Query User{68B5BFE9-5AE8-40BE-A576-C9A4A8B50CAB}h:\\my games\\cod 4\\iw3mp.exe"= UDP:h:\my games\cod 4\iw3mp.exe:iw3mp
"UDP Query User{D46D12EB-A18F-43EC-B426-E4F8154C8B41}h:\\my games\\cod 4\\iw3mp.exe"= TCP:h:\my games\cod 4\iw3mp.exe:iw3mp
"TCP Query User{BC3A7451-4F18-4DDA-8B65-767017E8F40D}c:\\program files\\java\\jre6\\bin\\java.exe"= UDP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"UDP Query User{3D900C14-D77D-49C9-88A4-A1BB5231FE80}c:\\program files\\java\\jre6\\bin\\java.exe"= TCP:c:\program files\java\jre6\bin\java.exe:Java(TM) Platform SE binary
"TCP Query User{E89A9B6A-547A-4E0F-B463-DC34640B8503}c:\\users\\.wilou\\appdata\\local\\google\\chrome\\application\\chrome.exe"= UDP:c:\users\.wilou\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"UDP Query User{DBF5BBB3-4153-4266-9475-750C0835C7B9}c:\\users\\.wilou\\appdata\\local\\google\\chrome\\application\\chrome.exe"= TCP:c:\users\.wilou\appdata\local\google\chrome\application\chrome.exe:chrome.exe
"{94F15797-9AAD-4053-8C12-4200B6DEEDA5}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{F89D54A2-C181-432B-B417-678BBAD6F084}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box
"{7089E830-54A1-4823-A3E0-25B9F303850D}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box
"{373F0B24-B3EA-4CD8-BC3F-2091575A9AF0}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box
"{22DAA3BE-08D1-4BAB-85AE-4B97A3C6E0D8}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box
"{21809064-041F-4ED1-83C1-D8FFFBB101C2}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box
"{586FBAAE-3678-4345-ADC4-E61A8B0A98CB}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box
"TCP Query User{25334941-1B62-4091-BB7C-6219731371E9}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{96ABD8D3-A1BF-4083-8A79-2238F9B724A0}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{A537F69F-EFD2-41F0-8C69-EE90840EEBE1}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{D2DA099E-63A4-4F4A-A342-E34773048877}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSfsu.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x86\\encryption.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x86\encryption.exe:*:Enabled:encryption
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x86\\decryption.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x86\decryption.exe:*:Enabled:decryption
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSMgr.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe:*:Enabled:eDSMgr
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDStbmngr.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe:*:Enabled:eDStbmngr
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDSfsu.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x64\\encryption.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x64\encryption.exe:*:Enabled:encryption
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x64\\decryption.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x64\decryption.exe:*:Enabled:decryption
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDSMgr.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe:*:Enabled:eDSMgr
"c:\\Program Files\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDStbmngr.exe"= c:\program files\Acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe:*:Enabled:eDStbmngr
R2 appdrvrem01;Application Driver Auto Removal Service (01); [x]
R2 gupdate1c99cf4bdde3720;Service Google Update (gupdate1c99cf4bdde3720);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-04 133104]
R3 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-03-07 24576]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-03-13 80912]
R3 Lsistac;Lsistac; [x]
R3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\DRIVERS\xpadfl02.sys [2006-12-24 27904]
S0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\Drivers\AlfaFF.sys [2008-04-08 43184]
S1 appdrv01;Application Driver (01);c:\windows\system32\Drivers\appdrv01.sys [2008-09-02 2915944]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\
000.fcl [2008-03-05 09:25 41456]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2008-01-16 81504]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr.sys [2008-12-08 55264]
S2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;c:\windows\system32\libusbd-nt.exe [2005-03-09 18944]
S2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [2008-01-16 122368]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2008-01-10 233472]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-02-15 595248]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2007-12-18 54784]
S3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1E60x86.sys [2008-03-11 48128]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2005-03-09 33792]
S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-02-15 40752]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}
*Deregistered* - AFD
*Deregistered* - AlfaFF
*Deregistered* - appdrv01
*Deregistered* - Beep
*Deregistered* - bowser
*Deregistered* - cdfs
*Deregistered* - circlass
*Deregistered* - CLFS
*Deregistered* - Compbatt
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DritekPortIO
*Deregistered* - DXGKrnl
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - fssfltr
*Deregistered* - HTTP
*Deregistered* - int15
*Deregistered* - IpFilterDriver
*Deregistered* - IPNAT
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - luafv
*Deregistered* - mfeapfk
*Deregistered* - mfeavfk
*Deregistered* - mfebopk
*Deregistered* - mfehidk
*Deregistered* - mferkdk
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - msahci
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - NTIPPKernel
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - PSDFilter
*Deregistered* - PSDNServ
*Deregistered* - psdvdisk
*Deregistered* - QWAVEdrv
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - RasSstp
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - sptd
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - h:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fcf77fa-bac0-11dd-b0cb-001e4cf082a3}]
\shell\AutoRun\command - J:\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{64469455-c5eb-11dd-9b45-00a0d1a3fdd9}]
\shell\AutoRun\command - itsduel.exe
\shell\explore\Command - itsduel.exe
\shell\open\Command - itsduel.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6585c45b-a06c-11dd-a34b-00a0d1a3fdd9}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL E:\setup.hta
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf95e8ab-d1e3-11dd-b8fe-00a0d1a3fdd9}]
\shell\AutoRun\command - h:\wd_windows_tools\WDSetup.exe
.
Contenu du dossier 'Tâches planifiées'
2009-04-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 08:58]
2009-03-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-04 20:11]
2009-02-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-61279146-674483815-1989799525-1000.job
- c:\users\.Wilou\AppData\Local\Google\Update\GoogleUpdate.exe [2009-01-05 18:49]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-58591838160495013117588163934894 - c:\program files\AV9\av2009.exe
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-GetModule35 - c:\program files\GetModule\GetModule35.exe
MSConfigStartUp-GetPack28 - c:\program files\GetPack\GetPack28.exe
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-VnrPack16 - c:\program files\VnrPack\VnrPack16.exe
MSConfigStartUp-VnrPack22 - c:\program files\VnrPack\VnrPack22.exe
MSConfigStartUp-VnrPack23 - c:\program files\VnrPack\VnrPack23.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://
www.google.fr/ig
mStart Page = hxxp://fr.fr.acer.yahoo.com
uInternet Settings,ProxyServer = proxy.efrei.fr:3128
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
Trusted Zone: tellmemorecampus.com\www2
Trusted Zone: tellmemorecampus.com\www2
FF - ProfilePath - c:\users\.Wilou\AppData\Roaming\Mozilla\Firefox\Profiles\5nic8nds.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.fr/ig
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\.Wilou\AppData\Local\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-09 22:12:12
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(1192)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\rundll32.exe
c:\program files\Acer\Acer Bio Protection\CompPtcVUI.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\acer\Mobility Center\MobilityService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\System32\PnkBstrA.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\System32\rundll32.exe
c:\program files\McAfee\Common Framework\Mctray.exe
c:\program files\Launch Manager\LManager.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
.
**************************************************************************
.
Heure de fin: 2009-04-09 22:22:28 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-09 20:22:19
Avant-CF: 29 337 108 480 octets libres
Après-CF: 33,973,706,752 octets libres
513 --- E O F --- 2009-04-09 07:56:18
Voila !
