voici le rapport :
ComboFix 08-07-27.6 - antonin 2008-07-28 19:54:15.1 - FAT32x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.231 [GMT 2:00]
Endroit: C:\Documents and Settings\antonin\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N’EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\brigitte\Application Data\macromedia\Flash Player#SharedObjects\92D64AQX\www.broadcaster.com
C:\Documents and Settings\brigitte\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com
C:\Documents and Settings\brigitte\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com\settings.sol
C:\Documents and Settings\maxime\Application Data\macromedia\Flash Player#SharedObjects\U2568RUY\www.broadcaster.com
C:\Documents and Settings\maxime\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com
C:\Documents and Settings\maxime\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com\settings.sol
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache[u]0[/u]01AF723
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\Program Files\Need2Find\bar\Settings\settings.dat
C:\Program Files\Need2Find\bar\Settings\settings.htm
C:\WINDOWS\system32\acgjanoj.ini
C:\WINDOWS\system32\adlorlou.ini
C:\WINDOWS\system32\aeatdbqq.ini
C:\WINDOWS\system32\aemsjprf.ini
C:\WINDOWS\system32\aengbkfl.ini
C:\WINDOWS\system32\ahkrxhbu.ini
C:\WINDOWS\system32\aicabffa.ini
C:\WINDOWS\system32\ajytovjn.ini
C:\WINDOWS\system32\ammtclqc.ini
C:\WINDOWS\system32\ankaoslj.ini
C:\WINDOWS\system32\aodioexl.ini
C:\WINDOWS\system32\apfjgadt.ini
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\autorun.ini
C:\WINDOWS\system32\avhhwrmv.ini
C:\WINDOWS\system32\awhgdlei.ini
C:\WINDOWS\system32\aycdd.bak1
C:\WINDOWS\system32\aycdd.bak2
C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\aycdd.tmp
C:\WINDOWS\system32\bcuenlyo.ini
C:\WINDOWS\system32\bdoesxux.ini
C:\WINDOWS\system32\bejugcgt.ini
C:\WINDOWS\system32\bjxayaen.ini
C:\WINDOWS\system32\bklludii.ini
C:\WINDOWS\system32\blmrplvg.ini
C:\WINDOWS\system32\bmotupvc.ini
C:\WINDOWS\system32\bmtcfwgq.ini
C:\WINDOWS\system32\bpllepkp.ini
C:\WINDOWS\system32\brpwrmid.ini
C:\WINDOWS\system32\bsylbkkb.ini
C:\WINDOWS\system32\btybuwul.ini
C:\WINDOWS\system32\bvneyndr.ini
C:\WINDOWS\system32\byfuqjqh.ini
C:\WINDOWS\system32\cburrqaj.ini
C:\WINDOWS\system32\ccvwuirh.ini
C:\WINDOWS\system32\Check.exe
C:\WINDOWS\system32\cixpemsc.ini
C:\WINDOWS\system32\cjfgcttn.ini
C:\WINDOWS\system32\ckbomiui.ini
C:\WINDOWS\system32\ckyqekin.ini
C:\WINDOWS\system32\cnfmrkko.ini
C:\WINDOWS\system32\crdlgxvd.ini
C:\WINDOWS\system32\cvptrhln.ini
C:\WINDOWS\system32\cwipefrp.ini
C:\WINDOWS\system32\cxjggaly.ini
C:\WINDOWS\system32\dakcemao.ini
C:\WINDOWS\system32\dbjasbbm.ini
C:\WINDOWS\system32\dcidftwf.ini
C:\WINDOWS\system32\dduvgxvn.ini
C:\WINDOWS\system32\dfagierb.ini
C:\WINDOWS\system32\dfmxkonb.ini
C:\WINDOWS\system32\dhawlucv.ini
C:\WINDOWS\system32\dhpcuvfi.ini
C:\WINDOWS\system32\dihprmnq.ini
C:\WINDOWS\system32\dnhsvukf.ini
C:\WINDOWS\system32\dsmfynui.ini
C:\WINDOWS\system32\dtqontwy.ini
C:\WINDOWS\system32\dvuxrxhx.ini
C:\WINDOWS\system32\dvxpcbsl.ini
C:\WINDOWS\system32\dwimxcbb.ini
C:\WINDOWS\system32\ebdjyxtj.ini
C:\WINDOWS\system32\ebqifjuw.ini
C:\WINDOWS\system32\ebwhdshd.ini
C:\WINDOWS\system32\edbturtm.ini
C:\WINDOWS\system32\eepesbaa.ini
C:\WINDOWS\system32\eikeimxx.ini
C:\WINDOWS\system32\ejyklasd.ini
C:\WINDOWS\system32\epiecbqi.ini
C:\WINDOWS\system32\eruptnld.ini
C:\WINDOWS\system32\etpyxnbi.ini
C:\WINDOWS\system32\eyauobwl.ini
C:\WINDOWS\system32\fesfejsn.ini
C:\WINDOWS\system32\fgbapqji.ini
C:\WINDOWS\system32\fgjmecge.ini
C:\WINDOWS\system32\fniqvuih.ini
C:\WINDOWS\system32\fpxqetbw.ini
C:\WINDOWS\system32\fqhtfatt.ini
C:\WINDOWS\system32\fukelfjq.ini
C:\WINDOWS\system32\funckghn.ini
C:\WINDOWS\system32\fuyiqqng.ini
C:\WINDOWS\system32\fxxhdbnm.ini
C:\WINDOWS\system32\gdcgffor.ini
C:\WINDOWS\system32\gdrflqbh.ini
C:\WINDOWS\system32\gglqpflf.ini
C:\WINDOWS\system32\gjogwqvy.ini
C:\WINDOWS\system32\gknreepr.ini
C:\WINDOWS\system32\gnajppeo.ini
C:\WINDOWS\system32\grmryrai.ini
C:\WINDOWS\system32\guelgppa.ini
C:\WINDOWS\system32\guqnkhkx.ini
C:\WINDOWS\system32\gyomowix.ini
C:\WINDOWS\system32\hahkuxwm.ini
C:\WINDOWS\system32\hbptevgf.ini
C:\WINDOWS\system32\hcseunxc.ini
C:\WINDOWS\system32\hgdaewap.ini
C:\WINDOWS\system32\hgglfodh.ini
C:\WINDOWS\system32\hlxjhnbl.ini
C:\WINDOWS\system32\hpfayeps.ini
C:\WINDOWS\system32\huddneik.ini
C:\WINDOWS\system32\hufdbmnx.ini
C:\WINDOWS\system32\hwmcpayy.ini
C:\WINDOWS\system32\hyxaqbfs.ini
C:\WINDOWS\system32\ifentxsg.ini
C:\WINDOWS\system32\iiqnxcdw.ini
C:\WINDOWS\system32\ikxokcvv.ini
C:\WINDOWS\system32\inquuiut.ini
C:\WINDOWS\system32\itpwllen.ini
C:\WINDOWS\system32\ivbmujcn.ini
C:\WINDOWS\system32\iwbctcmd.ini
C:\WINDOWS\system32\ixmkxdxw.ini
C:\WINDOWS\system32\jbodmuvg.ini
C:\WINDOWS\system32\jfdwbxhn.ini
C:\WINDOWS\system32\jgfkgwnc.ini
C:\WINDOWS\system32\jiotmsrf.ini
C:\WINDOWS\system32\jkpfhcas.ini
C:\WINDOWS\system32\jpvpbgsm.ini
C:\WINDOWS\system32\jwceaahk.ini
C:\WINDOWS\system32\jwqwkwuj.ini
C:\WINDOWS\system32\jxxjhami.ini
C:\WINDOWS\system32\jyobnvws.ini
C:\WINDOWS\system32\kaytsdfe.ini
C:\WINDOWS\system32\kclefumn.ini
C:\WINDOWS\system32\kdlnpmql.ini
C:\WINDOWS\system32\kgrnbvcw.ini
C:\WINDOWS\system32\kiqdcbhj.ini
C:\WINDOWS\system32\kixdjhps.ini
C:\WINDOWS\system32\kohwjeoe.ini
C:\WINDOWS\system32\kpmpvplw.ini
C:\WINDOWS\system32\kqxinqbf.ini
C:\WINDOWS\system32\kucyrycu.ini
C:\WINDOWS\system32\kudwygel.ini
C:\WINDOWS\system32\kvsjudqs.ini
C:\WINDOWS\system32\kygifund.ini
C:\WINDOWS\system32\kywmixvj.ini
C:\WINDOWS\system32\laovyufc.ini
C:\WINDOWS\system32\ldgyntqc.ini
C:\WINDOWS\system32\ldpugxgi.ini
C:\WINDOWS\system32\lepltfka.ini
C:\WINDOWS\system32\lfcxvopl.ini
C:\WINDOWS\system32\lfufmndx.ini
C:\WINDOWS\system32\lgfvycqa.ini
C:\WINDOWS\system32\lkpgywlg.ini
C:\WINDOWS\system32\lkpvqlqn.ini
C:\WINDOWS\system32\lmtavvoh.ini
C:\WINDOWS\system32\lofostfs.ini
C:\WINDOWS\system32\lpwjlvig.ini
C:\WINDOWS\system32\lrxbhfui.ini
C:\WINDOWS\system32\luykmrvu.ini
C:\WINDOWS\system32\lvhyptpx.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfudqfmo.ini
C:\WINDOWS\system32\mjbxgrdo.ini
C:\WINDOWS\system32\mmkmruqs.ini
C:\WINDOWS\system32\mnqnfyqk.ini
C:\WINDOWS\system32\moelxbhl.ini
C:\WINDOWS\system32\mpgmcsyv.ini
C:\WINDOWS\system32\msiksamg.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mtcuiijv.ini
C:\WINDOWS\system32\mtfkllxu.ini
C:\WINDOWS\system32\mwqoqidh.ini
C:\WINDOWS\system32\mxpjbbfp.ini
C:\WINDOWS\system32\nablatta.ini
C:\WINDOWS\system32\nasfvxwm.ini
C:\WINDOWS\system32\nigpjyta.ini
C:\WINDOWS\system32\nnxwqtkf.ini
C:\WINDOWS\system32\nptihoxu.ini
C:\WINDOWS\system32\nrqywoso.ini
C:\WINDOWS\system32\nubkqrns.ini
C:\WINDOWS\system32\nulieltn.ini
C:\WINDOWS\system32\nvvmefkl.ini
C:\WINDOWS\system32\nweyafig.ini
C:\WINDOWS\system32\oacdlrqq.ini
C:\WINDOWS\system32\oaqcfygh.ini
C:\WINDOWS\system32\obbgpfpu.ini
C:\WINDOWS\system32\obmceimp.ini
C:\WINDOWS\system32\ocpflslp.ini
C:\WINDOWS\system32\ofkqfvee.ini
C:\WINDOWS\system32\ofskcrbr.ini
C:\WINDOWS\system32\ogkekyvn.ini
C:\WINDOWS\system32\oimqhawk.ini
C:\WINDOWS\system32\ojjhboam.ini
C:\WINDOWS\system32\oomocrnk.ini
C:\WINDOWS\system32\oqcgntic.ini
C:\WINDOWS\system32\owhrybgy.ini
C:\WINDOWS\system32\owirlqxk.ini
C:\WINDOWS\system32\owxnrayi.ini
C:\WINDOWS\system32\pahwsylu.ini
C:\WINDOWS\system32\pblcqhlf.ini
C:\WINDOWS\system32\pcsektvh.ini
C:\WINDOWS\system32\pddhklpo.ini
C:\WINDOWS\system32\pftowlpg.ini
C:\WINDOWS\system32\plgyvhfq.ini
C:\WINDOWS\system32\pnvrbohv.ini
C:\WINDOWS\system32\psertrii.ini
C:\WINDOWS\system32\puijmixy.ini
C:\WINDOWS\system32\qcxnjcpa.ini
C:\WINDOWS\system32\qhcvbkpf.ini
C:\WINDOWS\system32\qhsiasnh.ini
C:\WINDOWS\system32\qjlkmssj.ini
C:\WINDOWS\system32\qjmmayki.ini
C:\WINDOWS\system32\qkphwfeb.ini
C:\WINDOWS\system32\quhvfwhu.ini
C:\WINDOWS\system32\quopwxdh.ini
C:\WINDOWS\system32\qwijnjpi.ini
C:\WINDOWS\system32\rcsoywew.ini
C:\WINDOWS\system32\redgrdew.ini
C:\WINDOWS\system32\rfbwjvup.ini
C:\WINDOWS\system32\rgefwcys.ini
C:\WINDOWS\system32\rhaklugf.ini
C:\WINDOWS\system32\rihnqops.ini
C:\WINDOWS\system32\rjqpcvja.ini
C:\WINDOWS\system32\rlikxytg.ini
C:\WINDOWS\system32\rqrymanh.ini
C:\WINDOWS\system32\rrmuwdox.ini
C:\WINDOWS\system32\rtjoopqe.ini
C:\WINDOWS\system32\ryjhwwms.ini
C:\WINDOWS\system32\sdcdrmpa.ini
C:\WINDOWS\system32\sjqgnvwp.ini
C:\WINDOWS\system32\sqctcjhs.ini
C:\WINDOWS\system32\surnwgqd.ini
C:\WINDOWS\system32\tabxrvic.ini
C:\WINDOWS\system32\thtugwmf.ini
C:\WINDOWS\system32\tknrjshl.ini
C:\WINDOWS\system32\tloqkxem.ini
C:\WINDOWS\system32\tmifgrot.ini
C:\WINDOWS\system32\tmxncsuj.ini
C:\WINDOWS\system32\tmxtkehb.ini
C:\WINDOWS\system32\tojuvygh.ini
C:\WINDOWS\system32\tunaaluw.ini
C:\WINDOWS\system32\ufdhirrm.ini
C:\WINDOWS\system32\ufnnakgk.ini
C:\WINDOWS\system32\ugeddqmv.ini
C:\WINDOWS\system32\ugqbuceu.ini
C:\WINDOWS\system32\uhgisilu.ini
C:\WINDOWS\system32\ukibgcps.ini
C:\WINDOWS\system32\unkrxhof.ini
C:\WINDOWS\system32\uoxrpgsy.ini
C:\WINDOWS\system32\usueosog.ini
C:\WINDOWS\system32\utjpxmwp.ini
C:\WINDOWS\system32\uubjrxut.ini
C:\WINDOWS\system32\uyqcmvlm.ini
C:\WINDOWS\system32\vccebrpg.ini
C:\WINDOWS\system32\vcjnbwwo.ini
C:\WINDOWS\system32\vgbfuael.ini
C:\WINDOWS\system32\vodyhbhi.ini
C:\WINDOWS\system32\vyudnrvl.ini
C:\WINDOWS\system32\wdohhaac.ini
C:\WINDOWS\system32\wejbkefy.ini
C:\WINDOWS\system32\wfisqoso.ini
C:\WINDOWS\system32\wfqccsqx.ini
C:\WINDOWS\system32\wgubmxfb.ini
C:\WINDOWS\system32\wgxifmpa.ini
C:\WINDOWS\system32\wihxoxpq.ini
C:\WINDOWS\system32\wlgyrbkg.ini
C:\WINDOWS\system32\wslmhxty.ini
C:\WINDOWS\system32\wsrlhlrx.ini
C:\WINDOWS\system32\wsxhiadi.ini
C:\WINDOWS\system32\wuidbjmf.ini
C:\WINDOWS\system32\wvsjjlcp.ini
C:\WINDOWS\system32\wwcimlei.ini
C:\WINDOWS\system32\wycdd.ini2
C:\WINDOWS\system32\wycdd.tmp
C:\WINDOWS\system32\xamynfyw.ini
C:\WINDOWS\system32\xbwkkcjq.ini
C:\WINDOWS\system32\xjtkgdqk.ini
C:\WINDOWS\system32\xnjvajow.ini
C:\WINDOWS\system32\xnoapqwx.ini
C:\WINDOWS\system32\xrsrsrdc.ini
C:\WINDOWS\system32\xsgtbkxo.ini
C:\WINDOWS\system32\xunyuioq.ini
C:\WINDOWS\system32\xxhtcjcl.ini
C:\WINDOWS\system32\xxkhdcbl.ini
C:\WINDOWS\system32\xxlixbcr.ini
C:\WINDOWS\system32\xxtvsran.ini
C:\WINDOWS\system32\ycmwoqtd.ini
C:\WINDOWS\system32\ydlhmmxh.ini
C:\WINDOWS\system32\ydvfefxa.ini
C:\WINDOWS\system32\yjmphkgs.ini
C:\WINDOWS\system32\yjwnqged.ini
C:\WINDOWS\system32\ymoshbsk.ini
C:\WINDOWS\system32\ynnqeoxq.ini
C:\WINDOWS\system32\yojxhucf.ini
C:\WINDOWS\system32\ypvkeaws.ini
C:\WINDOWS\system32\yvmnkccl.ini
C:\WINDOWS\system32\yvvknrrq.ini
C:\WINDOWS\system32\yxlncfcd.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DOMAINSERVICE
-------\Legacy_WINDOWS_LOG
-------\Service_Windows Log
((((((((((((((((((((((((((((( Fichiers cr??s 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))))))))
.
2008-07-28 19:06 . 2008-07-28 19:07 d-------- C:\Program Files\Avira
2008-07-28 19:06 . 2008-07-28 19:07 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-28 18:58 . 2008-07-28 18:58 d-------- C:\Program Files\RegistryQuick
2008-07-28 12:43 . 2008-07-28 12:43 d-------- C:\UT2004Demo
2008-07-28 12:14 . 2008-07-28 12:16 5,374 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-07-27 18:49 . 2008-07-27 18:49 d-------- C:\Program Files\Navilog1
2008-07-27 15:47 . 2008-07-27 15:47 d-------- C:\VundoFix Backups
2008-07-27 12:34 . 2008-07-27 12:34 d-------- C:\Program Files\Java
2008-07-27 12:34 . 2008-07-27 12:34 d-------- C:\Program Files\Fichiers communs\Java
2008-07-27 12:34 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-27 11:41 . 2008-07-27 11:41 d-------- C:\Program Files\Malwarebytes’ Anti-Malware
2008-07-27 11:41 . 2008-07-27 11:41 d-------- C:\Documents and Settings\antonin\Application Data\Malwarebytes
2008-07-27 11:41 . 2008-07-27 11:41 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 11:41 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-27 11:41 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-26 18:14 . 2008-07-26 18:14 d-------- C:\Program Files\SpeedFan
2008-07-26 18:14 . 2008-07-26 18:14 45 --a------ C:\WINDOWS\system32\initdebug.nfo
2008-07-25 19:01 . 2008-07-28 12:22 162,008 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-25 19:01 . 2008-07-28 12:22 111,928 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-07-25 19:01 . 2008-07-25 19:01 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-07-25 18:38 . 2008-07-25 18:38 d-------- C:\Program Files\WarRock
2008-07-18 11:40 . 2008-07-18 11:40 61 --a------ C:\WINDOWS\yesmessenger.ini
2008-07-17 18:58 . 2004-11-10 23:38 1,711 --a------ C:\WINDOWS\system32\storm.dll
2008-07-17 18:44 . 2008-07-17 18:44 d-------- C:\Program Files\Firefly Studios
2008-07-16 16:05 . 2008-07-16 16:05 d-------- C:\Documents and Settings\antonin\Application Data\fltk.org
2008-07-16 13:12 . 2008-07-16 13:12 d-------- C:\Program Files\Warcraft III
2008-07-13 14:24 . 2003-10-15 17:52 200,704 -ra------ C:\WINDOWS\sel3110.exe
2008-07-13 14:24 . 2003-10-15 17:52 174,530 -ra------ C:\WINDOWS\system32\drivers\ov519vid.sys
2008-07-13 14:24 . 2003-10-15 17:52 40,960 -ra------ C:\WINDOWS\system32\ov519ext.dll
2008-07-13 14:24 . 2003-10-15 17:52 25,211 -ra------ C:\WINDOWS\system32\drivers\ov519cmd.sys
2008-07-13 14:24 . 2003-10-15 17:52 25,099 -ra------ C:\WINDOWS\system32\ov519ext.ax
2008-07-12 20:41 . 2008-07-12 20:41 d-------- C:\Program Files\Panicware
2008-07-08 22:48 . 2008-07-08 22:48 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-07-06 20:11 . 2008-07-06 20:11 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-05 14:18 . 2008-07-05 14:15 1,048,576 --a------ C:\WINDOWS\system32\Engine.dll
2008-07-05 13:17 . 2008-07-05 13:16 374,272 --a------ C:\WINDOWS\system32\mss32.dll
2008-07-05 13:17 . 2008-07-05 13:17 35 --a------ C:\WINDOWS\Worldbuilder.INI
2008-07-02 11:19 . 2008-07-06 20:38 1,686 --a------ C:\WINDOWS\system32\ealregsnapshot1.reg
2008-06-28 20:33 . 2008-06-28 20:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-28 20:33 . 2008-06-28 20:33 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 10:16 71,634 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-07-18 18:58 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-14 11:22 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 21:10 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-07-12 21:10 219,648 ----a-w C:\WINDOWS\system32\dllcache\uxtheme.dll
2008-06-26 09:20 258,352 ----a-w C:\WINDOWS\system32\unicows.dll
2008-06-23 17:26 --------- d-----w C:\Program Files\DarkandLight
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 04:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-17 20:42 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-16 13:22 --------- d-----w C:\Program Files\Microsoft Games
2008-06-14 17:59 272,768 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-12 18:21 --------- d-----w C:\Program Files\uTorrent
2008-06-12 18:21 --------- d-----w C:\Documents and Settings\antonin\Application Data\uTorrent
2008-06-07 07:08 --------- d-----w C:\Documents and Settings\brigitte\Application Data\EoRezo
2008-06-05 18:22 --------- d-----w C:\Program Files\Visicom Media
2008-06-05 18:22 --------- d-----w C:\Program Files\eoRezo
2008-06-01 16:12 --------- d-----w C:\Program Files\American Conquest
2008-06-01 13:03 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-06-01 13:02 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-06-01 13:02 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-01 12:48 --------- d-----w C:\Program Files\Real
2008-06-01 08:25 --------- d-----w C:\Documents and Settings\antonin\Application Data\Nero
2008-06-01 08:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-06-01 07:07 --------- d-----w C:\Documents and Settings\antonin\Application Data\CDBurnerXP_Soft
2008-05-29 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Micrelec
2008-05-29 17:30 --------- d-----w C:\Program Files\eMule
2008-05-14 17:57 158,456 ------w C:\WINDOWS\system32\pxwma.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2006-09-02 17:07 81,920 ----a-w C:\Documents and Settings\antonin\Application Data\ezpinst.exe
2006-09-02 17:07 47,360 ----a-w C:\Documents and Settings\antonin\Application Data\pcouffin.sys
2004-07-22 08:51 3,432,656 ----a-w C:\Program Files\ManagedDX.CAB
2004-07-19 20:58 1,156,363 ----a-w C:\Program Files\BDANT.cab
2004-07-19 20:53 976,020 ----a-w C:\Program Files\BDAXP.cab
2004-07-16 12:30 3,858 ----a-w C:\Program Files\directx redist.txt
2004-07-09 12:17 13,265,040 ----a-w C:\Program Files\dxnt.cab
2004-07-09 07:13 703,080 ----a-w C:\Program Files\BDA.cab
2004-07-09 07:13 15,493,481 ----a-w C:\Program Files\DirectX.cab
2004-07-09 02:08 472,576 ----a-w C:\Program Files\DXSETUP.exe
2004-07-09 02:08 2,242,560 ----a-w C:\Program Files\dsetup32.dll
2004-07-09 01:03 62,976 ----a-w C:\Program Files\DSETUP.dll
2007-12-02 08:58 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-02 08:58 56 --sh–r C:\WINDOWS\system32\58D2CF5E0D.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
Note les ?l?ments vides & les ?l?ments initiaux l?gitimes ne sont pas list?s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“msnmsgr”=“C:\Program Files\Windows Live\Messenger\msnmsgr.exe” [2007-10-18 11:34 5724184]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-05 05:00 15360]
“AlcoholAutomount”=“C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe” [2008-03-20 18:46 217544]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2008-07-27 12:36 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“TkBellExe”=“C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe” [2008-06-01 15:02 185896]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 04:27 144784]
“RegistryQuick.exe”=“C:\Program Files\RegistryQuick\RegistryQuick.exe” [2008-03-15 22:34 4019200]
“avgnt”=“C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” [2008-06-12 14:28 266497]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-05 05:00 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegedit”= 0 (0x0)
“NoFind”= 0 (0x0)
“NoRun”= 0 (0x0)
“NoDesktop”= 0 (0x0)
“NoClose”= 0 (0x0)
“StartMenuLogOff”= 0 (0x0)
“HideClock”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“vidc.yv12”= yv12vfw.dll
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^EPSON Status Monitor 3 Environment Check.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\EPSON Status Monitor 3 Environment Check.lnk
backup=C:\WINDOWS\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM~\startupfolder\C:^Documents and Settings^antonin^Menu Démarrer^Programmes^Démarrage^Event Reminder.lnk]
path=C:\Documents and Settings\antonin\Menu Démarrer\Programmes\Démarrage\Event Reminder.lnk
backup=C:\WINDOWS\pss\Event Reminder.lnkStartup
[HKLM~\startupfolder\C:^Documents and Settings^antonin^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
path=C:\Documents and Settings\antonin\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a------ 2004-08-05 05:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
–a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\DWTRIG20.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
–a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a------ 2005-02-24 22:32 5537792 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd]
--------- 2004-06-10 13:48 286720 C:\WINDOWS\vsnpstd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a------ 2008-06-01 15:02 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
–a------ 2008-04-01 20:49 36352 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tweak UI]
–a------ 2001-03-19 00:41 110640 C:\WINDOWS\system32\TWEAKUI.CPL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“WLSetupSvc”=3 (0x3)
“usnjsvc”=3 (0x3)
“StarWindService”=2 (0x2)
“ose”=3 (0x3)
“OneStep Search Service”=2 (0x2)
“NVSvc”=2 (0x2)
“MDM”=2 (0x2)
“LiveUpdate”=3 (0x3)
“iPod Service”=3 (0x3)
“IDriverT”=3 (0x3)
“gusvc”=3 (0x3)
“DomainService”=2 (0x2)
“Boonty Games”=3 (0x3)
“avast! Web Scanner”=3 (0x3)
“avast! Mail Scanner”=3 (0x3)
“avast! Antivirus”=2 (0x2)
“aswUpdSv”=2 (0x2)
“Acer Media Server”=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
“DisableNotifications”= 1 (0x1)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 7.0.1.325\French\setup.exe”=
“C:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“C:\Program Files\Windows Live\Messenger\livecall.exe”=
“C:\Program Files\ACER\Acer eConsole\eConsole.exe”=
“C:\Program Files\uTorrent\uTorrent.exe”=
“C:\UT2004Demo\System\UT2004.exe”=
“C:\Program Files\Firefly Studios\Stronghold 2\Stronghold2.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“3389:TCP”= 3389:TCP:@xpsp2res.dll,-22009
“94:TCP”= 94:TCP:VRS Recording System Web Control Panel
R2 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 14:46]
S3 DMSKSSRh;DMSKSSRh;C:\DOCUME~1\antonin\LOCALS~1\Temp\DMSKSSRh.sys []
S3 XDva090;XDva090;C:\WINDOWS\system32\XDva090.sys []
S4 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2006-05-31 19:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{7d4181ac-9c17-11db-8bd1-00148543a75d}]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
Newly Created Service - SSMDRV
.
Contenu du dossier ‘Scheduled Tasks/T?ches planifi?es’
2008-07-27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
.
-
BHO-{07420948-750F-424B-853C-D07F423B96A3} - (no file)
BHO-{857732CE-B872-4B2F-98DB-C559F98DEB9E} - C:\WINDOWS\system32\ddcya.dll
MSConfigStartUp-avast! - C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
MSConfigStartUp-BitTorrent DNA - C:\Program Files\DNA\btdna.exe
MSConfigStartUp-Cld2000 - C:\Program Files\Calendrier\Cld2000.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
MSConfigStartUp-swg - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Search Page = www.google.com…
R0 -: HKCU-Main,SearchMigratedDefaultURL = www.google.com…
R0 -: HKCU-Main,Search Bar = www.google.com…
R0 -: HKLM-Main,Default_Search_URL = www.google.com…
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R0 -: HKCU-Search,SearchAssistant = www.google.com…
R1 -: HKCU-SearchURL,(Default) = www.google.com…
R0 -: HKLM-Search,SearchAssistant = www.google.com…
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-07-28 20:00:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cach?s …
Balayage cach? autostart entries …
Balayage des fichiers cach?s …
Scan termin? avec succ?s
Les fichiers cach?s: 0
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
C:\PROGRAM FILES\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
C:\WINDOWS\system32\wscntfy.exe
.
.
Temps d’accomplissement: 2008-07-28 20:02:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 18:02:32
Pre-Run: 27,694,661,632 octets libres
Post-Run: 29,183,049,728 octets libres
567 — E O F — 2008-07-27 13:06:37