bonjour voila le resultat du scan
ComboFix 09-09-06.06 - sandrine 07/09/2009 22:12.1.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.255.100 [GMT 2:00]
Running from: c:\documents and settings\sandrine\Mes documents\andmat.exe
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Internet Security *disabled* {825036E0-9F94-4752-8789-8B92454AF49B}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-563910005-252613686-1624482462-1003
c:\windows\Installer\1ae9f4.msi
c:\windows\Installer\1bc2ce0.msi
c:\windows\Installer\29e3d8b.msp
c:\windows\Installer\29e3d94.msp
c:\windows\Installer\29e3da6.msp
c:\windows\Installer\f09a22.msp
c:\windows\Installer\f09a23.msp
c:\windows\Installer\f09a24.msp
c:\windows\Installer\f09a25.msp
c:\windows\Installer\f09a26.msp
c:\windows\Installer\f09a27.msp
c:\windows\Installer\f09a28.msp
c:\windows\Installer\f09a29.msp
c:\windows\Installer\f09a2a.msp
c:\windows\Installer\f5905c.msp
c:\windows\Installer\f5905d.msp
c:\windows\Installer\f5905e.msp
c:\windows\Installer\f5905f.msp
c:\windows\Installer\f59060.msp
c:\windows\Installer\f59061.msp
c:\windows\Installer\f59062.msp
c:\windows\Installer\f59063.msp
c:\windows\Installer\f59064.msp
c:\windows\Installer\f59065.msp
c:\windows\Installer\f73173.msp
c:\windows\Installer\f7317d.msp
c:\windows\Installer\f73188.msp
c:\windows\Installer\f7319c.msp
c:\windows\Installer\f7319d.msp
c:\windows\Installer\f731ae.msp
c:\windows\pack.epk
c:\windows\system32\drivers\Sonyhcp.dll
c:\windows\system32\qpkcgjxhy.dat
c:\windows\system32\qpkcgjxhy_navup.dat
.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.
2009-09-07 18:47 . 2009-09-07 18:47 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\program files\Fichiers communs\PCCamera
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\program files\PhotoFiltre
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle VideoSpin
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\program files\Pinnacle
2009-09-07 18:44 . 2009-09-07 18:44 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2009-09-07 18:43 . 2009-09-07 18:43 -------- d-----w- c:\program files\XviD
2009-09-07 18:42 . 2009-09-07 18:42 -------- d-----w- c:\windows\Options
2009-09-07 18:42 . 2009-09-07 18:42 -------- d-----w- c:\program files\Digital Video
2009-09-06 21:43 . 2008-06-14 17:33 272768 ------w- c:\windows\system32\dllcache\bthport.sys
2009-09-06 21:43 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-09-06 21:43 . 2008-04-11 19:05 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-09-06 21:43 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-09-06 21:43 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-09-06 21:43 . 2009-03-06 14:20 286720 ------w- c:\windows\system32\dllcache\pdh.dll
2009-09-06 21:43 . 2009-02-09 11:24 2191104 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-06 21:43 . 2009-02-09 11:23 111104 ------w- c:\windows\system32\dllcache\services.exe
2009-09-06 21:43 . 2009-02-09 10:53 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-09-06 21:43 . 2009-02-09 10:53 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-09-06 21:43 . 2009-02-09 10:53 685568 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-09-06 21:42 . 2009-02-09 10:53 735744 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-09-06 21:42 . 2009-02-09 10:53 739840 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-09-06 21:42 . 2009-02-09 10:53 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-06 21:42 . 2009-02-09 11:23 2147328 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-06 21:42 . 2009-02-09 11:23 2025984 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-06 21:42 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-06 21:42 . 2008-12-16 12:31 354304 ------w- c:\windows\system32\dllcache\winhttp.dll
2009-09-06 21:41 . 2008-10-15 16:35 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-09-06 21:24 . 2009-09-06 21:24 -------- d-----w- c:\windows\l2schemas
2009-09-06 21:24 . 2009-09-06 21:24 -------- d-----w- c:\windows\system32\fr
2009-09-06 21:24 . 2009-09-06 21:24 -------- d-----w- c:\windows\system32\bits
2009-09-06 21:11 . 2009-09-06 21:11 -------- d-----w- c:\windows\EHome
2009-09-06 20:15 . 2009-09-06 20:15 -------- d-sh--w- c:\documents and settings\frederic\IECompatCache
2009-09-06 17:40 . 2009-09-06 17:40 -------- d-----w- c:\documents and settings\frederic\Local Settings\Application Data\Downloaded Installations
2009-09-06 17:38 . 2009-09-06 17:38 -------- d-----w- c:\program files\GIMP-2.0
2009-09-06 17:38 . 2009-09-06 17:38 -------- d-----w- c:\program files\ArcSoft
2009-09-06 17:37 . 2009-09-06 17:37 -------- d-----w- c:\program files\Easy GIF Animator
2009-09-06 17:37 . 2009-09-06 17:37 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-06 17:37 . 2009-09-06 17:37 -------- d-----w- c:\documents and settings\All Users\Application Data\GeoVid
2009-09-06 17:37 . 2009-09-06 17:37 -------- d-----w- c:\program files\GeoVid
2009-09-06 17:34 . 2009-09-06 17:34 -------- d-----w- c:\documents and settings\sandrine\Local Settings\Application Data\WMTools Downloaded Files
2009-09-06 17:28 . 2009-09-06 17:28 -------- d-----w- c:\program files\CCleaner
2009-09-06 17:28 . 2009-09-06 17:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-06 17:28 . 2009-09-06 17:28 -------- d-----w- c:\program files\FDF
2009-09-05 17:10 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-09-04 13:19 . 2009-09-04 13:19 -------- d-----w- c:\documents and settings\sandrine\Application Data\OpenOffice.org
2009-09-04 13:14 . 2009-09-04 13:14 -------- d-----w- c:\program files\OpenOffice.org 3
2009-09-02 21:16 . 2009-09-02 21:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2009-09-02 17:00 . 2009-09-05 16:53 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-01 20:19 . 2009-09-01 20:19 -------- d-----w- c:\documents and settings\frederic\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-31 15:37 . 2009-09-06 17:38 -------- d-----w- c:\program files\VirtualDub
2009-08-30 22:08 . 2009-09-06 17:38 -------- d-----w- c:\documents and settings\frederic\Tracing
2009-08-30 21:51 . 2009-08-30 21:51 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-08-30 11:56 . 2009-09-06 17:39 -------- d-----w- c:\documents and settings\frederic\Application Data\Momindum Studio
2009-08-28 16:36 . 2009-08-28 16:36 -------- d-sh--w- c:\documents and settings\matteo\IETldCache
2009-08-24 18:01 . 2009-09-06 17:35 -------- d-----w- c:\program files\Fichiers communs\Adobe AIR
2009-08-24 18:00 . 2009-08-24 18:00 -------- d-----w- c:\documents and settings\sandrine\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-22 13:08 . 2009-08-22 13:08 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-16 22:39 . 2009-08-16 22:39 -------- d-----w- c:\windows\ie8updates
2009-08-16 13:46 . 2009-07-03 16:57 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-16 13:46 . 2009-07-03 16:57 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-08-16 10:37 . 2009-08-16 10:37 -------- d-sh--w- c:\documents and settings\andrea\PrivacIE
2009-08-16 10:26 . 2009-08-16 10:26 -------- d-sh--w- c:\documents and settings\andrea\IETldCache
2009-08-15 22:15 . 2009-09-06 17:32 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-15 22:15 . 2009-08-15 22:15 -------- d-----w- c:\program files\MSBuild
2009-08-15 22:14 . 2009-08-15 22:14 -------- d-----w- c:\program files\Reference Assemblies
2009-08-15 22:13 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 22:13 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-15 22:13 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 22:13 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-15 22:13 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 22:13 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-15 22:13 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 22:06 . 2009-08-15 22:06 -------- d-----w- c:\program files\MSXML 6.0
2009-08-15 21:58 . 2009-09-06 21:20 -------- d-----w- c:\windows\ServicePackFiles
2009-08-15 19:43 . 2009-08-15 19:43 -------- d-sh--w- c:\documents and settings\frederic\PrivacIE
2009-08-15 19:38 . 2009-08-15 19:38 -------- d-sh--w- c:\documents and settings\frederic\IETldCache
2009-08-15 19:23 . 2009-08-15 19:23 -------- d-sh--w- c:\documents and settings\sandrine\IECompatCache
2009-08-15 19:21 . 2009-08-15 19:21 -------- d-sh--w- c:\documents and settings\sandrine\PrivacIE
2009-08-15 19:05 . 2009-08-15 19:05 -------- d-sh--w- c:\documents and settings\sandrine\IETldCache
2009-08-15 18:55 . 2009-09-06 17:31 -------- d-----w- C:\3cef31add32caaa59d84bf4be7
2009-08-15 18:55 . 2009-09-06 17:43 -------- d-----w- C:\676eccb17b96452705082b1ecc128b11
2009-08-15 18:51 . 2009-09-06 17:31 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 20:07 . 2004-08-16 16:41 588040 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-07 20:07 . 2004-08-16 16:41 111062 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-07 20:07 . 2009-09-07 20:07 4728 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-09-07 19:37 . 2005-07-12 13:36 -------- d-----w- c:\program files\OpenOffice.org1.1.4
2009-09-07 18:44 . 2007-10-07 15:58 -------- d-----w- c:\program files\Trust
2009-09-07 18:43 . 2008-03-11 10:39 -------- d-----w- c:\program files\Windows Live Favorites
2009-09-07 18:42 . 2008-06-14 14:35 -------- d-----w- c:\program files\PhotoViewer V208G_French
2009-09-07 16:56 . 2005-01-06 10:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-06 20:22 . 2005-08-03 12:18 81344 -c--a-w- c:\documents and settings\frederic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-06 17:38 . 2009-06-16 17:23 -------- d-----w- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-09-06 17:38 . 2009-03-13 15:09 -------- d-----w- c:\program files\AoA Audio Extractor
2009-09-06 17:38 . 2009-06-16 19:37 -------- d-----w- c:\program files\AVS4YOU
2009-09-06 17:38 . 2009-06-16 19:43 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2009-09-06 17:38 . 2006-01-24 19:10 -------- d-----w- c:\program files\MSN Apps
2009-09-06 17:38 . 2006-10-08 19:42 -------- d-----w- c:\program files\Creative
2009-09-06 17:37 . 2005-09-06 12:30 -------- d-----w- c:\program files\Microsoft Money 2005
2009-09-06 17:34 . 2005-01-31 22:21 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-09-06 17:34 . 2005-02-14 21:26 -------- d-----w- c:\documents and settings\frederic\Application Data\AdobeUM
2009-09-06 17:28 . 2009-03-23 20:34 -------- d-----w- c:\program files\a-squared Free
2009-09-05 21:47 . 2009-06-21 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-09-05 11:08 . 2007-04-30 16:45 81344 -c--a-w- c:\documents and settings\andrea\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-05 10:45 . 2007-08-27 20:58 -------- d-----w- c:\documents and settings\sandrine\Application Data\Ulead Systems
2009-09-05 10:43 . 2005-01-28 17:12 81344 -c--a-w- c:\documents and settings\sandrine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 13:11 . 2008-05-21 17:20 -------- d-----w- c:\program files\OpenOffice.org 2.4
2009-09-04 13:10 . 2008-05-21 17:24 -------- d-----w- c:\documents and settings\sandrine\Application Data\OpenOffice.org2
2009-09-03 21:59 . 2009-03-10 20:26 -------- d-----w- c:\documents and settings\frederic\Application Data\OpenOffice.org2
2009-08-30 21:55 . 2009-02-23 11:38 -------- d-----w- c:\program files\Microsoft
2009-08-30 21:53 . 2008-01-20 19:46 -------- d-----w- c:\program files\Windows Live
2009-08-22 22:11 . 2009-06-25 21:35 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-16 10:46 . 2008-05-22 12:22 -------- d-----w- c:\documents and settings\andrea\Application Data\OpenOffice.org2
2009-08-05 09:00 . 2004-08-16 16:40 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:35 . 2004-08-16 16:41 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:35 . 2004-08-16 16:40 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-18 16:20 . 2004-08-16 16:41 1506816 ----a-w- c:\windows\system32\shdocvw(2).dll
2009-07-17 18:56 . 2004-08-16 16:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 18:56 . 2004-08-16 16:39 58880 ----a-w- c:\windows\system32\atl(2)(2).dll
2009-07-17 13:20 . 2009-07-17 13:20 -------- d-----w- c:\program files\UnFREEz
2009-07-15 18:54 . 2009-07-15 18:54 -------- d-----w- c:\documents and settings\sandrine\Application Data\U3
2009-07-13 08:08 . 2004-08-10 22:45 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:57 . 2004-08-16 16:41 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-16 16:41 663552 ----a-w- c:\windows\system32\wininet(2)(2).dll
2009-06-26 16:18 . 2004-08-16 16:41 618496 ----a-w- c:\windows\system32\urlmon(2)(2).dll
2009-06-17 09:27 . 2009-06-27 21:22 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2009-06-27 21:22 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 10:44 . 2004-08-16 16:41 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:14 . 2004-08-16 16:39 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:21 . 2004-08-16 17:03 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:30 . 2004-08-16 16:41 132096 ----a-w- c:\windows\system32\wkssvc(2)(2).dll
2009-06-10 06:15 . 2004-08-16 16:41 132096 ----a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "c:\program files\AGI\common\agcutils.dll" [2009-09-05 43520]
[HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
[HKEY_CLASSES_ROOT\agcutils.AGSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{647B16D8-AD7B-4983-82D7-82A270FC9E6D}]
[HKEY_CLASSES_ROOT\agcutils.AGSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2009-04-10 16:04 277648 ----a-w- c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll" [2009-04-10 277648]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "c:\program files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll" [2009-04-10 277648]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 95800]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-04-24 251240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2004-10-08 81920]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-01-06 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-24 282624]
"CPnumericableHelper"="c:\program files\ControleParental\CPnumericableHelper.exe" [2007-02-26 49152]
"KiweeHook"="c:\program files\Kiwee Toolbar\2.8.167\kwtbaim.exe" [2009-04-10 56456]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Controleur de calendrier pour Ulead Photo Express"="c:\program files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-05-14 67072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\andrea\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\frederic\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 1.1.4.lnk - c:\program files\OpenOffice.org1.1.4\program\quickstart.exe [2004-10-28 61440]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\sandrine\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
Outil de d‚tection de support de Cyber-shot Viewer.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-7-5 155648]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HOTSYNCSHORTCUTNAME.lnk - c:\program files\Palm\Hotsync.exe [2004-6-9 471040]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SharedAccess"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [10/04/2009 18:02 10240]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [25/06/2009 23:35 108289]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Multimedia Keyboard & Mouse Driver\V5\KMWDSrv.exe [08/05/2007 17:00 2179072]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [24/04/2009 13:57 92008]
S2 CPnumericable;CPnumericable;c:\program files\ControleParental\CPnumericable.exe [30/01/2007 18:24 204800]
S3 PAC207;Trust WB-1200p Mini Webcam;c:\windows\system32\drivers\PFC027.sys [24/02/2005 12:29 162176]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2005-01-28 c:\windows\Tasks\HDReg.job
- c:\apps\HDReg\HDRegRem.exe [2005-01-06 10:14]
2005-01-24 c:\windows\Tasks\Rappel d'enregistrement 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-16 02:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-YeppStudioAgent - c:\program files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.fr/
uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:4343
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
DPF: CabBuilder -
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} -
hxxp://www.king.com/ctl/kingcomie.cab
FF - ProfilePath - c:\documents and settings\sandrine\Application Data\Mozilla\Firefox\Profiles\hyaheqi6.default\
FF - prefs.js: browser.search.selectedEngine - Kiwee Live Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.orange.fr/
FF - prefs.js: keyword.URL -
hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&v(...)
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 4343
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-07 22:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2423109536-2257666781-3639394454-1007\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Completion time: 2009-09-07 22:35
ComboFix-quarantined-files.txt 2009-09-07 20:35
Pre-Run: 113 203 617 792 octets libres
Post-Run: 115 621 822 464 octets libres
318 --- E O F --- 2009-09-07 19:53