Code : Tout sélectionner
ComboFix 09-06-20.03 - Eddy 21/06/2009 11:07.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.1732 [GMT 2:00]
Lancé depuis: c:\users\Eddy\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081204-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1296 [VPS 081204-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3302922013-2445102521-3974403118-500
c:\$recycle.bin\S-1-5-21-3302922013-2445102521-3974403118-500\desktop.ini
c:\windows\system32\mdm.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-21 au 2009-06-21 ))))))))))))))))))))))))))))))))))))
.
2009-06-21 09:10 . 2009-06-21 09:10 -------- d-----w- c:\users\Eddy\AppData\Local\temp
2009-06-14 14:54 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-14 14:54 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-11 15:11 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-05-30 10:37 . 2009-06-08 20:51 -------- d-----w- c:\users\Public\Games
2009-05-24 14:57 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-05-24 14:57 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-05-24 14:57 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-05-24 14:57 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-05-24 14:57 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-05-24 14:57 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-05-24 14:57 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-05-24 14:53 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-05-24 14:53 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-05-24 14:53 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-05-24 14:53 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-05-24 14:53 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-05-24 11:53 . 2009-05-24 11:53 -------- d-----w- c:\program files\PicLensIE
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 07:30 . 2006-11-02 15:48 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-21 07:30 . 2006-11-02 15:48 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-20 13:18 . 2008-09-07 17:12 -------- d-----w- c:\program files\Trend Micro
2009-06-20 12:27 . 2008-03-24 12:45 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-20 11:48 . 2008-09-07 17:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 11:48 . 2008-09-08 15:09 3561743 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-18 07:56 . 2008-03-20 20:19 118344 ----a-w- c:\users\Eddy\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-17 09:27 . 2008-09-07 17:14 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-09-07 17:14 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 01:04 . 2007-12-03 08:40 -------- d-----w- c:\program files\Microsoft Works
2009-06-04 11:56 . 2008-03-23 17:20 -------- d-----w- c:\program files\DivX
2009-06-04 11:56 . 2009-04-04 11:15 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-05-26 18:38 . 2008-03-24 08:24 -------- d-----w- c:\users\Eddy\AppData\Roaming\LimeWire
2009-05-15 06:55 . 2008-03-20 20:18 -------- d-----w- c:\program files\Yahoo!
2009-05-15 06:54 . 2009-04-14 08:21 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-15 06:53 . 2007-12-03 08:34 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-13 01:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-09 05:50 . 2009-06-11 15:12 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-11 15:12 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
2009-04-23 12:42 . 2009-06-11 15:12 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-11 15:12 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 14:58 . 2009-04-21 16:27 954368 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-04-17 14:58 . 2009-04-21 16:27 344064 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-04-17 14:58 . 2009-04-21 16:27 103424 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-04-17 14:58 . 2009-04-21 16:27 1161626 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\avcodec-51.dll
2009-04-17 14:58 . 2009-04-21 16:27 71652 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\avutil-49.dll
2009-04-17 14:58 . 2009-04-21 16:27 65536 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-04-17 14:58 . 2009-04-21 16:27 4579328 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\cooliris18.dll
2009-04-17 14:58 . 2009-04-21 16:27 4534272 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-04-17 14:58 . 2009-04-21 16:27 131868 ----a-w- c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\libs\avformat-52.dll
2009-03-27 06:14 . 2007-11-06 19:00 453152 ----a-w- c:\windows\system32\nvuninst.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-01-13 09:27 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-01-14 13:12 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-01-14 13:12 216064 --sh--r- c:\windows\System32\nbDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2009-02-01 91440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-09-07 326176]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-21 204908]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2007-09-11 187936]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-08-01 151552]
"PlayMovie"="c:\program files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-13 178280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-13 185896]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-10-11 4702208]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-01-23 101136]
c:\users\Eddy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-3-24 113664]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-2-1 91440]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-2-1 688128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{373E8EAC-90BD-4077-A98B-229D024BA92A}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{341455D4-4840-431F-A42C-FF5E73706B09}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"TCP Query User{756A61B2-7296-42B5-82AE-46DFDA013302}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{72FB1B19-ADA6-483B-B1FC-B1C5880CA387}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{CDF0B3A2-50CE-461E-83EA-B57359CE24A6}c:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:c:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"{D6A4396D-7AA3-417E-92D3-4E862C8F4EE4}"= UDP:5721:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{60E8AC59-9088-465C-92F5-93E69364F218}"= UDP:1034:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{AE755AF4-280D-49AA-AB18-0877EBCCE0D5}"= UDP:5678:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{19140EE7-3C16-4A46-A517-4441E242F0E5}"= UDP:999:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{BAF77C11-1182-4F32-866D-6FDBCDFDCB2A}"= UDP:26675:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{7CA64A65-8629-4362-84B8-CAFFC255D88A}"= UDP:990:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
"TCP Query User{9D79F755-6C75-414B-80A9-BEE24CA2F25A}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{47808666-FCE9-42B9-8C2D-D10589EFA480}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{A5C9FE96-EFF3-456C-99F9-C4112BB746B3}"= UDP:5721:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{E425894E-D23F-4D0C-BBBF-2777752F1CF7}"= UDP:1034:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{9410C6CD-6B21-4E1E-9B91-FDF1B533F36B}"= UDP:5678:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{75232D07-ED74-4D05-82FC-B5E04C145549}"= UDP:999:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{F9B8E7DE-9B73-4C14-ADE2-E9418249D9F9}"= UDP:26675:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{4413F88B-85AC-4302-8A37-6FC062BB0082}"= UDP:990:LocalSubnet:LocalSubnet|IF={0470F218-A000-4ED5-B050-A89C43F2EC53}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
"TCP Query User{2C5502A6-47A4-4316-A9C0-F370E8C9F23C}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus
"UDP Query User{3C6F0D96-8C13-47AC-A655-5321066CABDC}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus
"{59290CEB-F702-4D2A-8C1D-5A33C5FAF493}"= UDP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{23782D07-7232-442F-8C4F-CD1C3DF19129}"= TCP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{32A5BBE7-2183-4533-915C-27B8B52CF5A7}"= UDP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{A3E2BED9-6B53-49CC-9262-E31614E0516B}"= TCP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{2EF9D665-B45C-48D7-9570-D0DDF8B59938}"= UDP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{4EC8DE94-448C-4761-ACE7-231EA238F893}"= TCP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{5007CF2C-67E7-4735-B65C-2B4C4F482D57}"= UDP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"{7DDD9D95-5467-4D4E-90AB-15924352D34C}"= TCP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"TCP Query User{7138A0E9-5529-434A-9AB0-E07B34DC164D}c:\\program files\\acer arcade live\\acer homemedia\\acer homemedia.exe"= UDP:c:\program files\acer arcade live\acer homemedia\acer homemedia.exe:HomeMedia
"UDP Query User{43F683C2-46EC-4C55-9B99-A146AF71B68E}c:\\program files\\acer arcade live\\acer homemedia\\acer homemedia.exe"= TCP:c:\program files\acer arcade live\acer homemedia\acer homemedia.exe:HomeMedia
"TCP Query User{021EE87C-D84C-412F-AA39-C6EF6C25A89A}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"UDP Query User{CE262C37-FA9B-4252-8950-AA200C84B304}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever
"TCP Query User{5FC54304-A933-4D01-A60F-628EC9FBC2E1}c:\\program files\\trackmania nations eswc\\tmnationseswc.exe"= UDP:c:\program files\trackmania nations eswc\tmnationseswc.exe:TmNationsESWC
"UDP Query User{0FC5DABF-B8C3-4807-8EE0-263B2B40E1F5}c:\\program files\\trackmania nations eswc\\tmnationseswc.exe"= TCP:c:\program files\trackmania nations eswc\tmnationseswc.exe:TmNationsESWC
"{EBC1912F-87AD-4C04-BDD6-606A678FDC8A}"= UDP:c:\users\Eddy\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{EAAC40D8-BE9F-423F-9C10-6913525E8E24}"= TCP:c:\users\Eddy\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"TCP Query User{B53CF21B-3506-4F35-AE3B-39CF8697BC1B}c:\\windows\\wincra\\mirc.exe"= UDP:c:\windows\wincra\mirc.exe:mIRC
"UDP Query User{21056BB3-C2FA-4A3D-A348-CA9456E5898C}c:\\windows\\wincra\\mirc.exe"= TCP:c:\windows\wincra\mirc.exe:mIRC
"TCP Query User{3855EAE7-5ABC-4631-AC1D-D2E0862A9ED1}c:\\program files\\windows sidebar\\sidebar.exe"= UDP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"UDP Query User{DF5D117E-0A8E-488F-81D9-C662A32E97CE}c:\\program files\\windows sidebar\\sidebar.exe"= TCP:c:\program files\windows sidebar\sidebar.exe:Volet Windows
"TCP Query User{2AE0E321-EB2F-4DBF-B6E9-D905B5B92160}c:\\program files\\tmunitedforever\\tmforever.exe"= UDP:c:\program files\tmunitedforever\tmforever.exe:TmForever
"UDP Query User{B1DFDA7D-01CC-47E6-B1D8-1BB6D83A8382}c:\\program files\\tmunitedforever\\tmforever.exe"= TCP:c:\program files\tmunitedforever\tmforever.exe:TmForever
"TCP Query User{1A1699CB-7107-427E-964F-0210FB3C2ABF}c:\\program files\\tmunitedforever\\tmforever.exe"= UDP:c:\program files\tmunitedforever\tmforever.exe:TmForever
"UDP Query User{238FC0F3-0462-419B-8C7B-AA5595445D2E}c:\\program files\\tmunitedforever\\tmforever.exe"= TCP:c:\program files\tmunitedforever\tmforever.exe:TmForever
"TCP Query User{4BFA47AD-9A67-4EC4-845A-307C2208F6CB}c:\\program files\\trackmania nations eswc\\tmnationseswc.exe"= UDP:c:\program files\trackmania nations eswc\tmnationseswc.exe:TmNationsESWC
"UDP Query User{10FA0B00-4BF5-4640-8F37-70641826AFAC}c:\\program files\\trackmania nations eswc\\tmnationseswc.exe"= TCP:c:\program files\trackmania nations eswc\tmnationseswc.exe:TmNationsESWC
"{C289E9A8-8936-4040-9EAA-30E2416EAC22}"= UDP:c:\program files\Windows Mail\WinMail.exe:Windows Mail
"{A7098C03-B8F7-42FD-8599-D41E685AAEF9}"= TCP:c:\program files\Windows Mail\WinMail.exe:Windows Mail
"{0B52F3B6-49D9-4C5B-998D-2D7C1D3E012A}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{2AA27F40-898A-44D9-97D9-1E3F57A4DC1C}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2FAE7164-251D-4FA6-B584-B9CC42B570B0}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DE758204-1CBC-4695-A708-ED9B6FB2D74C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{75185400-12CA-450D-B839-2AC70E6DC418}c:\\program files\\logitech\\desktop messenger\\8876480\\program\\logitechdesktopmessenger.exe"= UDP:c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe:Logitech Desktop Messenger
"UDP Query User{CE6A2373-F891-4608-80D0-F544F6E9B8C3}c:\\program files\\logitech\\desktop messenger\\8876480\\program\\logitechdesktopmessenger.exe"= TCP:c:\program files\logitech\desktop messenger\8876480\program\logitechdesktopmessenger.exe:Logitech Desktop Messenger
"{479EBDB5-A5E3-4847-97F3-D442AF2F1CFF}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{51C75828-6DD8-433C-8786-4574793C3CA4}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{3D28BBE2-7248-4CD4-9007-51F713FEA922}"= UDP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{39F831B1-E22D-41F5-8C22-1997BFFE294E}"= TCP:c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger
"{4A5E9010-4CAE-4D7D-BDBA-2B95496E4857}"= UDP:c:\users\Eddy\AppData\Roaming\Facebook\facebook.exe:Facebook
"{25AE4D58-662A-4BAF-9C72-C143E5C9C5D1}"= TCP:c:\users\Eddy\AppData\Roaming\Facebook\facebook.exe:Facebook
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [06/04/2008 19:26 114768]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Live\Acer PlayMovie\[u]0[/u]00.fcl [20/03/2008 22:18 39408]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [03/12/2007 11:00 269448]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [06/04/2008 19:26 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [21/03/2008 00:45 51792]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [24/03/2008 14:45 809296]
S2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\System32\drivers\adildr.sys [23/03/2008 17:44 56088]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\System32\drivers\usbiad.sys [13/06/2005 06:57 31579]
S3 qcusbmdm;Qualcomm Proprietary USB Driver (PID 3197);c:\windows\System32\drivers\qcusbmdm.sys [28/09/2008 14:40 59632]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [24/03/2008 20:37 80744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-AnumanLive - c:\users\Eddy\AppData\Roaming\Anuman Interactive\AnumanLive\AnumanLive.exe
HKLM-Run-Apanel - c:\acersw\config\NewSetApanel.cmd
HKLM-Run-mirc - c:\windows\WINCRA\mirc.exe
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.forum-samsung.com/forum/index.php?&&CODE=00
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://fr.fr.acer.yahoo.com
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {21B0CC3E-A723-49DA-B74F-E9BF3A52FBE9} = 86.64.145.144 84.103.237.144
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.neufportail.fr/
FF - component: c:\users\Eddy\AppData\Roaming\Mozilla\Firefox\Profiles\7x6kj937.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-21 11:10
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Live\Acer PlayMovie\[u]0[/u]00.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,62,3c,c4,b4,a6,
b5,b0,72,e2,63,26,f1,3f,c8,ff,68,eb,4a,5e,f0,c8,c0,74,f3,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,b0,09,80,cb,25,
92,b4,5e,6a,9c,d6,61,af,45,84,18,c5,8f,6a,3d,ec,2f,90,f0,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,c5,4c,5c,ba,d0,
8a,05,36,ff,7c,85,e0,43,d4,0e,fe,0e,bf,88,84,e1,63,9a,7e,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,08,51,e9,16,51,
46,cb,1b,86,8c,21,01,be,91,eb,e7,13,de,f2,da,5c,57,ef,86,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,c9,e8,05,eb,96,
3a,85,79,f5,1d,4d,73,a8,13,5c,05,fd,3d,64,d0,ca,5e,ca,2d,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,b5,c6,5f,27,
bd,62,5b,df,20,58,62,78,6b,cf,c8,42,6b,20,be,8d,11,fd,e4,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,6f,f2,01,fb,b3,
a9,75,0a,fb,a7,78,e6,12,2f,9a,ea,76,e4,44,94,45,7b,47,80,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,0c,b8,26,d7,cb,
f1,f7,04,01,3a,48,fc,e8,04,4a,f1,52,48,5e,b6,9e,b7,96,2e,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,37,83,da,4e,d7,
a0,a8,28,f6,0f,4e,58,98,5b,89,c9,10,f4,1c,80,8b,ab,64,f5,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,36,d4,20,54,89,
31,8d,17,3d,ce,ea,26,2d,45,aa,78,b8,c4,cf,94,de,99,5f,dd,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,75,55,9b,3c,ca,
59,8e,32,2a,b7,cc,b5,b9,7f,41,e7,0c,80,43,1c,51,d5,7b,8c,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\Windows\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,ac,0c,b1,99,a1,
7b,6f,db,6c,43,2d,1e,aa,22,2f,9c,de,f7,66,b7,44,3f,7f,d3,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0[/u]004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-06-21 11:12
ComboFix-quarantined-files.txt 2009-06-21 09:12
Avant-CF: 171 020 017 664 octets libres
Après-CF: 170 451 202 048 octets libres
344 --- E O F --- 2009-06-18 20:31
Mais j'ai vu dans le rapport q'il a été supprimé si j'ai bien compris.