ComboFix 09-02-26.02 - Didi 2009-02-27 17:37:50.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.223.61 [GMT 1:00]
Lancé depuis: c:\documents and settings\Didi.DIDIANDPACO\Mes documents\téléchargement-redlist\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Outdated)
FW: Pare-feu BitDefender *disabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Helper
c:\program files\NetProject
c:\program files\NetProject\ot.ico
c:\program files\NetProject\Thumbs.db
c:\program files\NetProject\ts.ico
c:\windows\BM839e7465.txt
c:\windows\BM839e7465.xml
c:\windows\cookies.ini
c:\windows\system32\acpluacv.ini
c:\windows\system32\aebdndmd.ini
c:\windows\system32\aedbfklc.ini
c:\windows\system32\aneiogja.ini
c:\windows\system32\aofqjhej.ini
c:\windows\system32\aptghejp.ini
c:\windows\system32\aqwsusle.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\avnlhvlf.ini
c:\windows\system32\awjacmrm.ini
c:\windows\system32\awyshktw.ini
c:\windows\system32\axvnnfel.ini
c:\windows\system32\bcojnwkj.ini
c:\windows\system32\bdycqmwn.ini
c:\windows\system32\berhxveq.ini
c:\windows\system32\bgfwcats.ini
c:\windows\system32\bhcngfwy.ini
c:\windows\system32\bndrphcx.ini
c:\windows\system32\bpdyidtm.ini
c:\windows\system32\bqatihti.ini
c:\windows\system32\cdlsyilc.ini
c:\windows\system32\cewicnow.ini
c:\windows\system32\chcgcstb.ini
c:\windows\system32\cksdcrrh.ini
c:\windows\system32\crejchdj.ini
c:\windows\system32\cwolorgs.ini
c:\windows\system32\dfmbftxo.ini
c:\windows\system32\dhkhtdqd.ini
c:\windows\system32\dlrgfxgo.ini
c:\windows\system32\dmdndbea.dll
c:\windows\system32\dmfbxost.ini
c:\windows\system32\dotcrclm.ini
c:\windows\system32\dpphutkq.ini
c:\windows\system32\dxyamqve.dll
c:\windows\system32\dywgljlj.ini
c:\windows\system32\ecnxwckp.ini
c:\windows\system32\eewtaqal.ini
c:\windows\system32\elhmruuw.ini
c:\windows\system32\epqyshrx.ini
c:\windows\system32\eqjdtiqp.ini
c:\windows\system32\eqyfdnnk.ini
c:\windows\system32\erqmkdoj.ini
c:\windows\system32\evqmayxd.ini
c:\windows\system32\fckmbrfi.ini
c:\windows\system32\fjkwyyfm.ini
c:\windows\system32\fkrbvtmn.ini
c:\windows\system32\fmgsjdjg.ini
c:\windows\system32\fmwjdudc.ini
c:\windows\system32\fnvfxllk.ini
c:\windows\system32\fsopmrsh.ini
c:\windows\system32\ftatwdws.ini
c:\windows\system32\ftplxqbu.ini
c:\windows\system32\fwnisuqc.ini
c:\windows\system32\gcpsxfbm.ini
c:\windows\system32\gencanol.ini
c:\windows\system32\gewfvbcp.ini
c:\windows\system32\gjwbfjqv.ini
c:\windows\system32\gmvmgmob.ini
c:\windows\system32\gndedfqs.ini
c:\windows\system32\gucymmqi.ini
c:\windows\system32\gyucvydu.ini
c:\windows\system32\hecinqfs.ini
c:\windows\system32\hfqqemek.ini
c:\windows\system32\hjkkopvq.ini
c:\windows\system32\hmfykelc.ini
c:\windows\system32\hqslxfqq.ini
c:\windows\system32\hrvgqcal.ini
c:\windows\system32\hssfltvj.ini
c:\windows\system32\hypomdpv.ini
c:\windows\system32\icdsapyh.ini
c:\windows\system32\iemmtems.ini
c:\windows\system32\ifeugobg.ini
c:\windows\system32\igabeysj.ini
c:\windows\system32\ihlwlsao.ini
c:\windows\system32\iilrilts.ini
c:\windows\system32\ildkwfug.ini
c:\windows\system32\impogkso.ini
c:\windows\system32\imwchkwf.ini
c:\windows\system32\infvmhjn.ini
c:\windows\system32\inkgdrex.ini
c:\windows\system32\irobbsui.ini
c:\windows\system32\iycwhiai.ini
c:\windows\system32\jbkvltdc.ini
c:\windows\system32\jfffitmn.ini
c:\windows\system32\jitepoto.ini
c:\windows\system32\jjlgsusw.ini
c:\windows\system32\jtrijeeh.ini
c:\windows\system32\jtxnfguo.ini
c:\windows\system32\juahefbs.dll
c:\windows\system32\jvmbtgej.ini
c:\windows\system32\jvoxyoco.ini
c:\windows\system32\kblpoied.ini
c:\windows\system32\kcfdcadr.ini
c:\windows\system32\kclxsgtw.ini
c:\windows\system32\kelxthyl.ini
c:\windows\system32\kgjvyfgg.ini
c:\windows\system32\kjkbvddn.ini
c:\windows\system32\klnpjokc.ini
c:\windows\system32\krbrcrpl.ini
c:\windows\system32\krpwdkgn.ini
c:\windows\system32\kturkyoy.ini
c:\windows\system32\kxnealha.ini
c:\windows\system32\lbaunphr.ini
c:\windows\system32\ldoyigho.ini
c:\windows\system32\lijmbune.ini
c:\windows\system32\liqbgcub.ini
c:\windows\system32\ljlwdxig.ini
c:\windows\system32\ljscbdkx.ini
c:\windows\system32\luejgokc.ini
c:\windows\system32\lxhkrtag.ini
c:\windows\system32\magcsqxg.ini
c:\windows\system32\mbyhwdck.ini
c:\windows\system32\mcbcetdp.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\mjquwkui.ini
c:\windows\system32\mnfxgcdc.ini
c:\windows\system32\mohayerj.ini
c:\windows\system32\msrwxxqy.ini
c:\windows\system32\nagmdplm.ini
c:\windows\system32\navqmloh.ini
c:\windows\system32\ngkwmdad.dll
c:\windows\system32\niphagpt.ini
c:\windows\system32\njmumegv.ini
c:\windows\system32\nkepvtie.ini
c:\windows\system32\nkgupqdg.ini
c:\windows\system32\nmxpgpft.ini
c:\windows\system32\nrpwxemn.ini
c:\windows\system32\ntykelix.ini
c:\windows\system32\oafqurrd.ini
c:\windows\system32\oahxvuly.ini
c:\windows\system32\obkqkkbj.ini
c:\windows\system32\ocgbansj.ini
c:\windows\system32\oeuvsvau.dll
c:\windows\system32\oggoaoam.ini
c:\windows\system32\okrkjfun.ini
c:\windows\system32\olpcjsbv.ini
c:\windows\system32\ouvbakbx.ini
c:\windows\system32\ovrwihpx.ini
c:\windows\system32\OVwFOqss.ini
c:\windows\system32\OVwFOqss.ini2
c:\windows\system32\pcgfaycm.ini
c:\windows\system32\pdgmtntb.ini
c:\windows\system32\penboqsc.ini
c:\windows\system32\phfakeav.ini
c:\windows\system32\piykvnyo.ini
c:\windows\system32\poabfnih.ini
c:\windows\system32\prrbxfgk.ini
c:\windows\system32\putthssk.ini
c:\windows\system32\qfbntelw.ini
c:\windows\system32\qhxanppn.ini
c:\windows\system32\qoxuevry.ini
c:\windows\system32\QtwwDfhk.ini
c:\windows\system32\QtwwDfhk.ini2
c:\windows\system32\QYaIknpo.ini
c:\windows\system32\QYaIknpo.ini2
c:\windows\system32\qyiccmth.ini
c:\windows\system32\raabwjao.dll
c:\windows\system32\rnsqjggt.ini
c:\windows\system32\rsmmjgdm.ini
c:\windows\system32\sbfehauj.ini
c:\windows\system32\sbsftppo.ini
c:\windows\system32\scdiljak.ini
c:\windows\system32\sgauxbky.ini
c:\windows\system32\sgghtrqd.ini
c:\windows\system32\sklsawpc.ini
c:\windows\system32\smqjsmuu.ini
c:\windows\system32\sobjdxgm.dll
c:\windows\system32\sojnhlee.ini
c:\windows\system32\sxpvmqrg.ini
c:\windows\system32\tccvlcmg.ini
c:\windows\system32\timlevyc.ini
c:\windows\system32\tjxxbgco.ini
c:\windows\system32\tkchwwcx.ini
c:\windows\system32\tktqguwu.ini
c:\windows\system32\tqowcbjd.ini
c:\windows\system32\tqwhiymc.ini
c:\windows\system32\ttpnlryl.ini
c:\windows\system32\tvjaetun.ini
c:\windows\system32\txdygfwt.ini
c:\windows\system32\txqminrm.ini
c:\windows\system32\uadshvjw.ini
c:\windows\system32\uasdjtox.ini
c:\windows\system32\udpyfvce.ini
c:\windows\system32\ufthqgyp.ini
c:\windows\system32\unvoucrj.ini
c:\windows\system32\upjagyfm.ini
c:\windows\system32\uqttqwdv.ini
c:\windows\system32\urxcpyiu.ini
c:\windows\system32\usduvpyj.ini
c:\windows\system32\usrptgxx.ini
c:\windows\system32\usxgyuuv.ini
c:\windows\system32\uusqmkic.ini
c:\windows\system32\uvwhvlmf.ini
c:\windows\system32\uybcoiau.ini
c:\windows\system32\uychfdeg.ini
c:\windows\system32\vcaqrciy.ini
c:\windows\system32\vnbrqgnp.ini
c:\windows\system32\vodxmfhc.ini
c:\windows\system32\vqgsdmyc.ini
c:\windows\system32\vrhsnouf.ini
c:\windows\system32\vrnljjwi.ini
c:\windows\system32\vsgocnxi.ini
c:\windows\system32\vwwtjsie.ini
c:\windows\system32\vwwvdyul.ini
c:\windows\system32\wclcmsgb.ini
c:\windows\system32\wdjlprud.ini
c:\windows\system32\weulscrt.ini
c:\windows\system32\wfghpjhg.ini
c:\windows\system32\wgtuidtk.ini
c:\windows\system32\whgqbrdv.ini
c:\windows\system32\wjvhsdau.dll
c:\windows\system32\wlylutrt.ini
c:\windows\system32\wmsxpqys.ini
c:\windows\system32\wqruahqp.ini
c:\windows\system32\wrgawocl.ini
c:\windows\system32\wtgsxlck.dll
c:\windows\system32\wtuirmkf.ini
c:\windows\system32\xcacanpr.ini
c:\windows\system32\xcqmbqex.ini
c:\windows\system32\xdmrhtao.ini
c:\windows\system32\xfgdtikq.ini
c:\windows\system32\xkggmxgq.ini
c:\windows\system32\xlthsvgc.ini
c:\windows\system32\xmypblww.ini
c:\windows\system32\xnsygqlx.ini
c:\windows\system32\xnuggmau.ini
c:\windows\system32\xpqmonvk.ini
c:\windows\system32\xrciboop.ini
c:\windows\system32\xwradiuv.ini
c:\windows\system32\yaafehgq.ini
c:\windows\system32\yaydpvbe.ini
c:\windows\system32\yefdhodh.ini
c:\windows\system32\ymtiodpb.ini
c:\windows\system32\yxnlftfv.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-27 au 2009-02-27 ))))))))))))))))))))))))))))))))))))
.
2009-02-27 10:34 . 2009-01-09 20:19 1,089,883 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-02-26 17:43 . 2009-02-26 17:43 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\FireShot
2009-02-26 12:17 . 2009-02-26 12:19 <REP> d-------- C:\3f6d10fcb69f823f0e2e7c1445813c6a
2009-02-25 00:32 . 2009-02-25 00:31 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-24 10:40 . 2009-02-24 10:40 <REP> d-------- c:\program files\Opera
2009-02-22 18:36 . 2009-02-22 18:36 <REP> d-------- c:\program files\Playlogic
2009-02-21 22:48 . 2009-02-22 20:53 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\.gimp-2.6
2009-02-21 22:48 . 2009-02-21 22:48 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\.gegl-0.0
2009-02-21 22:38 . 2009-02-21 22:38 <REP> d-------- c:\program files\GIMP-2.0
2009-02-21 21:02 . 2009-02-21 21:02 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\GamesCafe
2009-02-21 21:02 . 2009-02-21 21:02 4,096 --a------ c:\windows\d3dx.dat
2009-02-18 19:18 . 2009-02-23 16:46 <REP> d-------- c:\windows\LastGood
2009-02-17 23:03 . 2009-02-17 23:03 <REP> d-------- c:\program files\Cité
2009-02-16 18:06 . 2009-02-16 18:06 <REP> d-------- c:\program files\Free
2009-02-16 13:14 . 2009-02-26 21:33 <REP> d--h----- C:\$AVG8.VAULT$
2009-02-16 04:40 . 2009-02-16 04:40 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\BitDefender
2009-02-16 04:04 . 2009-02-16 04:04 <REP> d-------- c:\program files\Stardock
2009-02-16 04:04 . 2009-02-16 04:04 <REP> d-------- c:\program files\Fichiers communs\Stardock
2009-02-16 03:51 . 2009-02-16 03:51 <REP> d-------- c:\windows\LastGood.Tmp
2009-02-16 03:51 . 2009-02-16 03:51 132 --a------ C:\httpdwl.dat
2009-02-16 03:50 . 2009-02-16 03:50 815 --a------ C:\rtsr_eml_sr.dat
2009-02-16 03:50 . 2009-02-16 03:50 128 --a------ C:\dwl.dat
2009-02-16 03:28 . 2009-02-27 12:43 <REP> d-------- c:\windows\system32\drivers\Avg
2009-02-16 03:28 . 2009-02-27 12:43 98,440 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-02-16 03:28 . 2009-02-27 12:43 90,632 --a------ c:\windows\system32\drivers\avgtdix.sys
2009-02-16 03:28 . 2009-02-27 12:43 12,936 --a------ c:\windows\system32\drivers\avgrkx86.sys
2009-02-16 03:28 . 2009-02-27 12:43 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-02-16 03:06 . 2009-02-16 03:07 21,598 --a------ c:\windows\system32\oemlogo.bmp
2009-02-16 03:06 . 2009-02-16 03:07 37 --a------ c:\windows\system32\oeminfo.ini
2009-02-16 02:58 . 2009-02-16 02:58 <REP> d--h----- c:\windows\Icons
2009-02-15 18:55 . 2008-04-14 03:33 21,504 --a------ c:\windows\system32\hidserv.dll
2009-02-15 18:55 . 2008-04-14 03:33 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2009-02-13 22:36 . 2009-02-16 02:50 2,287,104 --a------ c:\windows\system32\TUKernel.exe
2009-02-13 18:35 . 2009-02-13 18:35 <REP> d-------- c:\program files\Consumer Update Firmware
2009-02-13 00:17 . 2009-02-13 00:17 2,117,632 --a------ c:\windows\system32\python25.dll
2009-02-13 00:17 . 2008-09-16 17:26 1,332,197 --a------ c:\windows\system32\pythondll.zip
2009-02-13 00:17 . 2009-02-13 00:17 339,968 --a------ c:\windows\system32\pythoncom25.dll
2009-02-13 00:17 . 2009-02-13 00:17 114,688 --a------ c:\windows\system32\pywintypes25.dll
2009-02-13 00:15 . 2009-02-13 00:17 <REP> d-------- c:\program files\AGI
2009-02-12 18:12 . 2009-02-12 18:12 16 --a------ C:\asdict.dat
2009-02-12 17:51 . 2009-02-12 17:51 <REP> d-------- c:\windows\system32\MpEngineStore
2009-02-11 23:11 . 2009-02-11 23:11 850 --a------ c:\windows\system32\ProductTweaks.xml
2009-02-11 23:11 . 2009-02-11 23:11 385 --a------ c:\windows\system32\user_gensett.xml
2009-02-11 19:39 . 2009-02-27 12:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Avg8
2009-02-10 20:19 . 2009-02-10 20:19 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\Teleca
2009-02-10 17:50 . 2009-02-10 17:50 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\Sony Ericsson
2009-02-10 17:48 . 2009-02-11 11:19 <REP> d-------- c:\program files\Fichiers communs\Teleca Shared
2009-02-10 17:48 . 2009-02-10 17:48 <REP> d-------- c:\program files\Fichiers communs\Sony Ericsson Shared
2009-02-10 17:47 . 2009-02-10 17:47 <REP> d-------- c:\program files\Sony Ericsson
2009-02-10 17:41 . 2009-02-10 17:48 <REP> d-------- c:\documents and settings\All Users\Application Data\Teleca
2009-02-10 17:41 . 2009-02-10 17:48 <REP> d-------- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-02-08 20:37 . 2009-02-08 20:37 266,192 --a------ c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-02-08 06:16 . 2008-09-26 09:52 10,384 --a------ c:\windows\system32\drivers\LBeepKE.sys
2009-02-08 06:15 . 2009-02-08 06:15 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-08 06:15 . 2009-02-08 06:15 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2009-02-08 06:15 . 2009-02-08 06:15 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-08 06:15 . 2009-02-08 06:15 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-02-08 06:10 . 2009-02-08 06:10 <REP> d-------- c:\program files\Logitech
2009-02-08 06:10 . 2009-02-08 06:11 <REP> d-------- c:\program files\Fichiers communs\Logishrd
2009-02-08 06:08 . 2009-02-27 11:26 <REP> d-------- c:\documents and settings\All Users\Application Data\LogiShrd
2009-02-08 04:32 . 2009-02-26 12:53 <REP> d-------- c:\program files\Microsoft Silverlight
2009-02-04 01:05 . 2009-02-04 01:05 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\FogelSoft
2009-02-04 00:43 . 2009-02-10 12:46 <REP> d-------- c:\program files\ViStart
2009-02-04 00:43 . 2009-02-04 00:44 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\ViStart
2009-02-04 00:40 . 2009-02-04 00:40 <REP> d-------- c:\program files\ViOrb
2009-02-04 00:35 . 2009-02-17 22:15 <REP> d-------- c:\program files\iColorFolder
2009-02-03 21:33 . 2009-02-27 00:13 <REP> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-02-03 01:35 . 2009-02-24 16:58 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\dvdcss
2009-02-03 01:07 . 2009-02-03 01:07 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\vlc
2009-02-03 01:03 . 2009-02-03 01:03 <REP> d-------- c:\program files\VideoLAN
2009-02-03 00:58 . 2009-02-03 01:00 3,532 --a------ C:\drmHeader.bin
2009-02-02 23:07 . 2009-02-02 23:07 <REP> d-------- c:\program files\Microsoft
2009-02-01 17:02 . 2009-02-16 04:30 <REP> d-------- c:\program files\FlashGet
2009-01-31 03:51 . 2009-01-31 03:51 <REP> d-------- c:\program files\AVG
2009-01-29 21:32 . 2009-01-29 21:32 <REP> d-------- c:\program files\Alcohol Soft
2009-01-28 17:16 . 2009-01-28 17:16 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\Anuman Interactive
2009-01-28 16:17 . 2009-01-28 16:17 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\DAEMON Tools Pro
2009-01-28 16:17 . 2009-01-28 16:17 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\DAEMON Tools
2009-01-28 16:16 . 2009-01-28 16:16 <REP> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-01-28 15:51 . 2009-01-28 15:51 <REP> d-------- c:\documents and settings\Didi.DIDIANDPACO\Application Data\DAEMON Tools Lite
2009-01-28 15:51 . 2009-01-28 15:51 717,296 --a------ c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 16:46 25,930 ----a-w c:\windows\system32\drivers\FLockXP.sys
2009-02-27 10:25 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-27 10:25 --------- d-----w c:\program files\ma-config.com
2009-02-27 10:25 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-02-24 23:30 --------- d-----w c:\program files\Java
2009-02-22 17:43 278,984 ----a-w c:\windows\system32\drivers\atksgt.sys
2009-02-21 21:58 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\gtk-2.0
2009-02-16 03:30 --------- d-----w c:\program files\DivX
2009-02-16 02:55 --------- d-----w c:\program files\Fichiers communs\BitDefender
2009-02-16 02:55 --------- d-----w c:\program files\BitDefender
2009-02-15 21:57 230,432 ----a-w C:\PA7302.DAT
2009-02-12 19:28 --------- d-----w c:\program files\Google
2009-02-11 18:50 --------- d-----w c:\program files\epson
2009-02-11 18:40 --------- d-----w c:\program files\Fichiers communs\GTK
2009-02-11 18:37 --------- d-----w c:\program files\Gestion Clubs & Associations
2009-02-11 17:57 --------- d-----w c:\program files\TuneUp Utilities 2009
2009-02-08 05:19 --------- d-----w c:\program files\sisagp
2009-02-05 23:08 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\OpenOffice.org2
2009-02-03 23:48 --------- d-----w c:\program files\Mozilla Thunderbird
2009-02-02 22:07 --------- d-----w c:\program files\Windows Live
2009-01-30 01:11 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\HPAppData
2009-01-28 19:24 --------- d-----w c:\program files\Maxis
2009-01-27 17:01 --------- d-----w c:\program files\Sonic Foundry ACID 2.0
2009-01-27 16:57 --------- d-----w c:\documents and settings\All Users\Application Data\SecTaskMan
2009-01-27 16:20 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-27 15:59 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\Hide IP NG
2009-01-25 23:41 --------- d-----w c:\program files\File Lock
2009-01-25 04:25 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\TuneUp Software
2009-01-25 04:23 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-01-25 04:21 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-01-21 21:42 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\Notepad++
2009-01-21 21:40 --------- d-----w c:\program files\Notepad++
2009-01-19 22:23 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\Mumble
2009-01-19 19:31 --------- d-----w c:\program files\Mumble
2009-01-16 18:53 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\FDRLab
2009-01-13 18:51 --------- d-----w c:\documents and settings\Didi.DIDIANDPACO\Application Data\.purple
2009-01-13 07:17 --------- d-----w c:\program files\Pidgin
2009-01-11 09:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-08 00:48 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-01-08 00:18 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-01-06 14:08 --------- d-----w c:\documents and settings\All Users\Application Data\RH_Backups
2009-01-06 02:51 --------- d-----w c:\program files\RegHealer
2009-01-03 13:32 --------- d--h--w c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}
2009-01-03 02:02 --------- d-----w c:\program files\CCleaner
2008-11-29 10:55 357,768 ----a-w c:\documents and settings\Didi.DIDIANDPACO\SymXPep2.dll
2008-03-19 16:28 13 ---h--w c:\documents and settings\All Users\Application Data\1ÌØ13.sys
2000-03-14 23:00 142,848 ----a-w c:\documents and settings\Compte et budget\setup.exe
2007-08-28 12:54 237,568 ----a-w c:\program files\mozilla firefox\plugins\CrazyTalk4Native.dll
2006-05-25 17:43 204,895 ----a-w c:\program files\mozilla firefox\plugins\ctdomemhelper.dll
2005-09-29 13:41 77,824 ----a-w c:\program files\mozilla firefox\plugins\ctframeplayerobject.dll
2006-06-19 12:10 426,081 ----a-w c:\program files\mozilla firefox\plugins\ctplayerobject.dll
2005-02-02 11:19 458,752 ----a-w c:\program files\mozilla firefox\plugins\imagickrt.dll
2006-04-10 17:35 139,264 ----a-w c:\program files\mozilla firefox\plugins\rlcontentclass.dll
2005-11-09 10:10 204,800 ----a-w c:\program files\mozilla firefox\plugins\RLMusicPacker.dll
2005-11-09 10:42 106,496 ----a-w c:\program files\mozilla firefox\plugins\RLMusicUnpacker.dll
2006-01-04 10:22 212,992 ----a-w c:\program files\mozilla firefox\plugins\RLVoicePacker.dll
2006-01-04 10:21 167,936 ----a-w c:\program files\mozilla firefox\plugins\RLVoiceUnpacker.dll
2008-11-18 13:30 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008111820081119\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-01-20 1451248]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-25 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-27 1235736]
"SigmatelSysTrayApp"="sttray.exe" [2006-07-27 c:\windows\sttray.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\windows\system32\logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-27 12:43 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Run Google Web Accelerator.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Run Google Web Accelerator.lnk
backup=c:\windows\pss\Run Google Web Accelerator.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViStart]
c:\program files\ViStart\ViStart [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-11-23 01:36 203720 c:\program files\Alcohol Soft\Alcohol 120\AxCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
--a------ 2009-02-27 12:42 1235736 c:\progra~1\AVG\AVG8\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2007-06-13 08:16 528384 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2008-10-10 14:46 69632 c:\windows\KHALMNPR.Exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
"PAC7302_Monitor"=c:\windows\PixArt\PAC7302\Monitor.exe
"ezShieldProtector for Px"=c:\windows\system32\ezSP_Px.exe
"SoundMan"=SOUNDMAN.EXE
"SiSPower"=Rundll32.exe SiSPower.dll,ModeAgent
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Bbox\\eSKernel.exe"=
"c:\\Program Files\\BboxUpdate\\BTLiveUpdate.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:*:Disabled:Shareaza
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-02-16 12936]
R0 FILELOCK;FILELOCK;c:\windows\system32\drivers\FLockXP.sys [2007-07-20 25930]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-02-16 98440]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-02-16 90632]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-02-08 10384]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [2006-03-02 14336]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2007-12-19 2368]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [2004-10-20 21344]
S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys --> c:\windows\system32\DRIVERS\ShlDrv51.sys [?]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-16 874776]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-16 231704]
S2 gupdate1c983436e4fd71a;Google Update Service (gupdate1c983436e4fd71a);c:\program files\Google\Update\GoogleUpdate.exe [2009-01-31 133104]
S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\DRIVERS\PavProc.sys --> c:\windows\system32\DRIVERS\PavProc.sys [?]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-01-25 603904]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\system32\drivers\PAC7302.SYS [2008-11-17 457856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-02-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 21:33]
2009-02-27 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 15:04]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{77AB5974-55A3-4737-9FD5-B93C64307F78} - (no file)
Toolbar-{de753e88-4f10-45e4-b890-79ab94795a02} - (no file)
Notify-jkkIARhi - jkkIARhi.dll
MSConfigStartUp-BDAgent - c:\program files\BitDefender\BitDefender 2009\bdagent.exe
MSConfigStartUp-BitDefender Antiphishing Helper - c:\program files\BitDefender\BitDefender 2009\IEShow.exe
MSConfigStartUp-Flashget - c:\program files\FlashGet\FlashGet.exe
MSConfigStartUp-FocusinXP - c:\docume~1\DIDI~1.DID\LOCALS~1\Temp\Rar$EX16.797\FocusinXP.exe
MSConfigStartUp-Shareaza - c:\program files\Shareaza\Shareaza.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uStart Page =
hxxp://www.aliceadsl.fr
uInternet Settings,ProxyServer = socks=
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
DPF: CabBuilder -
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Didi.DIDIANDPACO\Application Data\Mozilla\Firefox\Profiles\xuqe718i.default\
FF - prefs.js: browser.search.selectedEngine -
FF - component: c:\documents and settings\Didi.DIDIANDPACO\Application Data\Mozilla\Firefox\Profiles\xuqe718i.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}\platform\WINNT\components\ColorZilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRLCT4Player.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.pipelining.ssl - true
FF - user.js: network.http.pipelining.maxrequests - 8
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-27 19:18:33
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\avgrsstx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-02-27 19:23:17 - La machine a redémarré [Didi]
ComboFix-quarantined-files.txt 2009-02-27 18:23:12
Avant-CF: 191,883,382,784 octets libres
Après-CF: 191,898,386,432 octets libres
572 --- E O F --- 2009-02-27 09:46:11