salut,voila c est fait
ComboFix 08-11-17.01 - fabien 2008-11-18 11:30:32.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.984 [GMT 1:00]
Lancé depuis: c:\users\fabien\Desktop\genesis.exe
Commutateurs utilisés :: c:\users\fabien\Desktop\CFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
c:\program files\Setup.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Setup.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-18 au 2008-11-18 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 10:30 3,670,016 --sha-w c:\users\Invité\ntuser.dat
2008-11-18 10:30 3,670,016 --sha-w c:\users\Invité\ntuser.dat
2008-11-17 21:26 352,614 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2008-11-17 20:14 --------- d-----w c:\programdata\Google Updater
2008-11-16 20:57 --------- d-----w c:\programdata\Spybot - Search & Destroy
2008-11-16 11:41 --------- d-----w c:\program files\MozBackup
2008-11-14 15:03 5,418 ----a-w C:\Internet Explorer.reg
2008-11-14 14:07 --------- d-----w c:\program files\Java
2008-11-14 14:01 --------- d-----w c:\program files\MSN Messenger
2008-11-14 13:52 --------- d-----w c:\users\fabien\AppData\Roaming\Skype
2008-11-14 12:33 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-13 10:05 --------- d-----w c:\program files\IObit
2008-11-13 09:34 --------- d-----w c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-11-13 09:34 --------- d-----w c:\program files\SDHelper (Spybot - Search & Destroy)
2008-11-13 09:34 --------- d-----w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-13 09:34 --------- d-----w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-12 11:49 --------- d-----w c:\programdata\Microsoft Help
2008-11-12 10:36 --------- d-----w c:\users\fabien\AppData\Roaming\uTorrent
2008-11-11 11:08 --------- d-----w c:\program files\iWizz
2008-11-10 13:34 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 13:34 --------- d-----w c:\program files\Electronic Arts
2008-10-27 15:56 --------- d-----w c:\users\julie\AppData\Roaming\Skype
2008-10-21 19:06 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-21 06:41 2,071,552 ----a-w c:\windows\Internet Logs\xDB8E0B.tmp
2008-10-18 11:40 --------- d-----w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-18 11:40 --------- d-----w c:\program files\iTunes
2008-10-18 11:39 --------- d-----w c:\program files\iPod
2008-10-16 21:13 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-10-16 21:09 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w c:\windows\System32\wups2.dll
2008-10-16 20:56 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-10-16 13:08 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-10-16 12:56 31,232 ----a-w c:\windows\System32\wuapp.exe
2008-10-15 18:27 --------- d-----w c:\program files\Windows Mail
2008-10-08 11:35 --------- d-----w c:\users\fabien\AppData\Roaming\Apple Computer
2008-10-06 20:08 --------- d-----w c:\program files\Hercules
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-10-01 21:13 --------- d-----w c:\programdata\Apple Computer
2008-10-01 20:02 --------- d-----w c:\program files\QuickTime
2008-10-01 20:02 --------- d-----w c:\program files\Common Files\Apple
2008-10-01 20:02 --------- d-----w c:\program files\Bonjour
2008-10-01 20:01 --------- d-----w c:\program files\Apple Software Update
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-24 13:11 --------- d-----w c:\program files\Sun
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 ----a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 ----a-w c:\windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-09-10 03:40 1,334,272 ----a-w c:\windows\System32\msxml6.dll
2008-09-07 08:33 3,610 ----a-w c:\windows\System32\ealregsnapshot1.reg
2008-09-05 05:14 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-08-29 08:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-08-26 09:30 91,989 ----a-w c:\windows\Internet Logs\vsmon_2nd_2008_08_26_09_35_17_small.dmp.zip
2008-08-26 09:25 6,214,853 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-08-15 10:25 81,920 ----a-w c:\users\fabien\AppData\Roaming\ezpinst.exe
2008-08-15 10:25 47,360 ----a-w c:\users\fabien\AppData\Roaming\pcouffin.sys
2008-03-22 14:20 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((
snapshot@2008-11-17_23.06.49,99 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-18 10:29:47 6,332,416 ----a-w c:\windows\ERDNT\Hiv-backup\schema.dat
- 2008-07-18 20:08:20 72,256 ------w c:\windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe
+ 2008-10-16 13:08:00 70,416 ------w c:\windows\SoftwareDistribution\SelfUpdate\Handler\WuSetupV.exe
- 2008-11-17 21:25:29 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-18 07:52:20 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-11-17 21:25:29 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-18 07:52:20 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-17 21:25:29 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-18 07:52:20 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-11-17 22:03:13 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-11-18 10:30:04 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-11-13 09:15:12 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2008-11-18 07:52:23 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
- 2008-11-17 07:00:06 507,510 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2008-11-18 07:50:18 508,144 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
- 2008-11-12 11:47:15 151,558,119 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-11-18 07:51:54 151,850,822 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-10-16 21:12:19 561,688 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wuapi.dll
+ 2008-10-16 20:55:59 83,456 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wudriver.dll
+ 2008-10-16 21:08:57 34,328 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wups.dll
+ 2008-10-16 12:56:04 31,232 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuapp.exe
+ 2008-10-16 13:08:00 162,064 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuwebv.dll
+ 2008-10-16 21:09:43 51,224 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuauclt.exe
+ 2008-10-16 21:13:38 1,809,944 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuaueng.dll
+ 2008-10-16 21:09:43 43,544 ----a-w c:\windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wups2.dll
+ 2008-10-16 20:56:28 1,524,736 ----a-w c:\windows\winsxs\x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.2.6001.788_none_a8125d5406872725\wucltux.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"="" [?]
"?????????"="??????????????e" [?]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"EPSON Stylus DX5000 Series"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE" [2006-09-22 139264]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"gStart"="c:\garmin\gStart.exe" [2007-08-23 1891416]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\windows\system32\SysMonitor.exe" [2006-11-23 319488]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-12 275800]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"OWCWebCamDV"="c:\windows\system\wcdvtray.exe" [2004-05-20 1056768]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-01-09 959976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-12 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-12 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-12 81920]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 c:\windows\RtHDVCpl.exe]
c:\users\fabien\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-13 528384]
Google Updater.lnk - c:\program files\Google\Google Updater\GoogleUpdater.exe [2007-11-13 161264]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2007-06-09 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{13E09A81-2E8C-4502-B660-66214B593F50}"= UDP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{19200CF2-4EFD-4575-8347-F5C49104B8E6}"= TCP:c:\program files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{BFC01D75-54E3-41E6-A710-C9B948DBE735}"= UDP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{E2509781-8847-485F-9B69-AC24D0C6C333}"= TCP:c:\program files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{74E1DA07-00C3-48EA-A933-35D52CB685AB}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{196622AD-3BBE-400B-9B43-09766EC092D2}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{7CF4E46F-40BD-4F20-B6D4-59A734580406}"= UDP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{66DFF60B-8534-402D-811D-3A1951C59156}"= TCP:c:\program files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{F00E42DF-657C-44C5-8220-A23CFA5547F0}"= UDP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{D16AAB87-16FC-44F2-891D-1CFD768B7275}"= TCP:c:\program files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"TCP Query User{AFD79617-8233-4A49-86A0-642DA4AFB536}c:\\program files\\tribalweb\\tribalweb.exe"= UDP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{5DB20C64-74ED-453F-BBDB-CE7A1E8A4133}c:\\program files\\tribalweb\\tribalweb.exe"= TCP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"{C1E85424-82C4-4D6A-AACA-759709D47508}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{6B39DB1D-B680-4A74-88C9-E47D09F9C655}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"TCP Query User{71181CFB-281D-4AE2-8731-7997A9E2DD98}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{DA686BE5-1786-40C5-A1C5-B91A21DB4042}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{90A44A9B-8D80-4B4A-8F41-8B020136729A}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus
"UDP Query User{792984AB-29DF-4FF4-8DB1-C6087E5BB870}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus
"{5D5860FB-A4F8-4D3F-BEBB-1228DE9484A2}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{712011DF-0212-447A-9211-7AC82E739C10}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{DA81E1BA-B6F4-4018-B83B-63EFEC274BAF}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{0BE003A0-0746-431E-9ADB-792FA77B1951}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{8BE0B5C1-C4BB-4224-A213-097447C92A63}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{43BB173A-FD58-473A-A4D6-E9912BCFBC79}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{34E5B6BA-B60E-4A90-987D-7507C70767AF}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"{1BF350D5-C985-4897-A59E-1A3893DCA74D}"= UDP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{342C0F50-7F3C-4862-B005-291C67AC74E3}"= TCP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{F9A16C84-AC49-4CAB-961B-5F07493A6DFA}"= UDP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{6B8E5C89-A1A7-4F16-B449-B4BCEBFDDD38}"= TCP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{D85FE803-EEB1-4522-8083-5D1E702DF59D}"= UDP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{78822203-60C0-462F-97E3-11EF1B56EF48}"= TCP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{35209FC3-9EDA-468F-B8B1-4BDB2CFC6545}"= UDP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"{86710BC6-A12C-4BAA-AF22-7EE6CC21C2DA}"= TCP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"{D6713E73-AC3C-4433-883C-4748BD668ABD}"= UDP:c:\program files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{156D4B17-1011-4665-B78D-96DB6A249564}"= TCP:c:\program files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{1B4C14BA-481F-4D9F-B2A3-2D2F25EE6D0C}"= UDP:c:\program files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{AC068AB6-AB2A-4771-B26E-8BA2F86F4F77}"= TCP:c:\program files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{0C42FC42-0D51-42CE-8D0F-E99864A723EF}"= UDP:c:\program files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{239076C9-62F7-4A6C-957B-57613BEAA74A}"= TCP:c:\program files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe:PMSRegisterFile
"{4C319941-6F9E-4E62-879F-5C4F74068EAC}"= UDP:c:\program files\Pinnacle\Studio 11\programs\umi.exe:umi
"{894B848A-DDA4-4463-AB30-9AFBED9508BB}"= TCP:c:\program files\Pinnacle\Studio 11\programs\umi.exe:umi
"{34026DDB-B2E3-429F-ABEF-7E26D52F8EF0}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{91D336ED-5EEA-4102-B156-13D68C27ACBC}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{EA740C9F-7754-4D1C-AB41-28984B5DE724}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{27AC79EA-16A0-4CA9-B38C-A5C481CFB51E}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{356F2CC0-44BA-4118-AE0A-B560AF7A2291}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{2A96A5FE-9204-4829-8604-BE95AFF00ABF}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{EA18A8FB-73BE-44EA-8949-F985205DC12D}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{9632D0D1-9A05-4DF0-AD0A-FF9E2EF09A5A}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{767B3E8C-9835-4A31-94FD-7E94E1BE9F8C}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{8259BD77-6B53-4FEA-AEF7-DDF4C595E504}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{1F003F0D-6F46-44BE-A097-36937A52DF07}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{D4BF3B89-AB57-453B-9AB7-22839745E3F5}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{8A51583A-3724-418D-99C3-49BBA91AF90F}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{48498E53-CA9E-4C7C-80DC-FFB0574A9C02}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{5398E5EE-8FDE-43DB-BBFC-AF43B03E6ECD}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"TCP Query User{81CD2C40-BBDA-44F1-BF62-3B0A09A604D8}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{0EA6C978-6074-44BA-B74D-0A4921C9DF54}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{51FAFD2B-0D93-4CEF-9E62-92470CC0993F}c:\\users\\fabien\\desktop\\wow-frfr-installer-downloader.exe"= UDP:c:\users\fabien\desktop\wow-frfr-installer-downloader.exe:wow-frfr-installer-downloader.exe
"UDP Query User{02A6B6D7-7258-4ECB-A03B-D0DD58C07B21}c:\\users\\fabien\\desktop\\wow-frfr-installer-downloader.exe"= TCP:c:\users\fabien\desktop\wow-frfr-installer-downloader.exe:wow-frfr-installer-downloader.exe
"TCP Query User{38420CA7-F6BD-448A-93A5-C1F4A18CE1EF}d:\\world of warcraft\\wow-2.2.0-frfr-downloader.exe"= UDP:d:\world of warcraft\wow-2.2.0-frfr-downloader.exe:Blizzard Downloader
"UDP Query User{F51B2A20-3778-44E8-A8E5-81CB0D82CA50}d:\\world of warcraft\\wow-2.2.0-frfr-downloader.exe"= TCP:d:\world of warcraft\wow-2.2.0-frfr-downloader.exe:Blizzard Downloader
"TCP Query User{D7CA2E70-B47D-403E-8B21-8D65736F9610}d:\\world of warcraft\\repair.exe"= UDP:d:\world of warcraft\repair.exe:Blizzard Repair Utility
"UDP Query User{97FC7CCA-8091-46C7-9867-B080A9237ECD}d:\\world of warcraft\\repair.exe"= TCP:d:\world of warcraft\repair.exe:Blizzard Repair Utility
"TCP Query User{0BE70C07-5D2F-4A3D-BED1-367823557DB7}c:\\users\\fabien\\desktop\\burningcrusade.exe"= UDP:c:\users\fabien\desktop\burningcrusade.exe:burningcrusade.exe
"UDP Query User{2C239094-E309-4599-BFDA-207B596256D0}c:\\users\\fabien\\desktop\\burningcrusade.exe"= TCP:c:\users\fabien\desktop\burningcrusade.exe:burningcrusade.exe
"TCP Query User{0705A0FA-4DED-43F1-B629-4DB72C805F97}d:\\world of warcraft\\backgrounddownloader.exe"= UDP:d:\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"UDP Query User{5BE00316-95E4-4041-887F-AB9A7AA9F33D}d:\\world of warcraft\\backgrounddownloader.exe"= TCP:d:\world of warcraft\backgrounddownloader.exe:Blizzard Downloader
"TCP Query User{C437127F-9D9E-4505-8377-A924D27BEC9B}c:\\program files\\tribalweb\\tribalweb.exe"= UDP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"UDP Query User{039C8F65-6BA6-4652-A667-D468FE26C9D3}c:\\program files\\tribalweb\\tribalweb.exe"= TCP:c:\program files\tribalweb\tribalweb.exe:tribalweb
"TCP Query User{240EB27B-4EF1-4A0D-9D22-27FEA1939110}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus
"UDP Query User{185DC852-E4EC-43B7-A59D-23A9A57D9DAF}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus
"{98E5CD92-1A91-43DF-A88A-09CA55A32BBF}"= UDP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{3247E318-8CD6-4E72-9613-780A00AA11EA}"= TCP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"TCP Query User{7C1C0C27-8FB9-4213-B620-5C492D6065D6}c:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= UDP:c:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"UDP Query User{1CD87096-8618-452B-9898-08BFA4B2867E}c:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= TCP:c:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"TCP Query User{579AC8E4-F80B-4EBA-B905-05F0FBB5DA7D}c:\\program files\\ea games\\battlefield 2\\bf2voipserver_w32ded.exe"= UDP:c:\program files\ea games\battlefield 2\bf2voipserver_w32ded.exe:BF2VoipServer_w32ded
"UDP Query User{2E98ABDB-B29A-4F24-B5DE-8A64E8CB9469}c:\\program files\\ea games\\battlefield 2\\bf2voipserver_w32ded.exe"= TCP:c:\program files\ea games\battlefield 2\bf2voipserver_w32ded.exe:BF2VoipServer_w32ded
"TCP Query User{D2DD7FC9-9514-4688-8A77-4B8076B22227}c:\\program files\\acer zone\\acer plug and record\\component\\arawp.exe"= UDP:c:\program files\acer zone\acer plug and record\component\arawp.exe:Plug n Record
"UDP Query User{B75DDD95-EDB3-490C-9CF5-8668AB8CD777}c:\\program files\\acer zone\\acer plug and record\\component\\arawp.exe"= TCP:c:\program files\acer zone\acer plug and record\component\arawp.exe:Plug n Record
"TCP Query User{D8CF6A47-C49D-4047-95A2-6557B51D8652}c:\\program files\\acer zone\\acer plug and record\\component\\dvax2process.exe"= UDP:c:\program files\acer zone\acer plug and record\component\dvax2process.exe:DVAX2Process
"UDP Query User{9F9788AF-2342-4EE2-8C1E-DE5A5A523065}c:\\program files\\acer zone\\acer plug and record\\component\\dvax2process.exe"= TCP:c:\program files\acer zone\acer plug and record\component\dvax2process.exe:DVAX2Process
"TCP Query User{16EA32F9-86EE-4847-81F5-E28EFE45E196}c:\\program files\\ivisit\\ivisit.exe"= UDP:c:\program files\ivisit\ivisit.exe: iVisit
"UDP Query User{5DCC460B-78F7-4B4B-A461-72D79B25541F}c:\\program files\\ivisit\\ivisit.exe"= TCP:c:\program files\ivisit\ivisit.exe: iVisit
"{F0EE66A1-98D3-4E64-AEC8-298140413069}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{8DA581D3-98FD-44F6-B643-B2DEF9DFA21A}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"TCP Query User{4F63A05E-9ED6-4EB3-B50B-71D6F99FCA8A}c:\\program files\\skype\\phone\\skype.exe"= Disabled:UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{5006CC75-D841-4D8F-8F74-E8827310455B}c:\\program files\\skype\\phone\\skype.exe"= Disabled:TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"{8946A6AE-D9E1-4A58-9DEA-6B200C414780}"= UDP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{F6C475EA-6F9A-46AA-A8CD-B5BAAA687D21}"= TCP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{97481649-5786-4DFE-926A-B32D9669B9EB}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{9645CCD5-26F1-45FE-9912-065E607BC980}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{C622CCB0-802D-4E6A-97A8-36CCE1FFD42E}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{4E52FB25-DFA1-43B4-ADFB-EC0B62F2B83C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{C899A550-AC33-4763-837F-FA779CA89683}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{0FD710D9-A1B2-4726-9BB9-A15BDD85EB92}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{72280A4B-8837-4F25-BFCF-D2EB304893DA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{C32C53D7-A147-4C22-8618-1D1E9AE6CB4A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B51E24C6-BF47-41C1-91F0-3F8F618286A3}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{E5ADE5CF-B45B-4454-A58A-8AE7FE5A17B5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{87A96019-BECF-45A5-A13E-3ED4CDB7FF97}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B6FEDBE6-18A9-46FE-81B5-722BB6355F81}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{2D293F25-BE7D-4D21-B0A1-C4741C05C060}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{B9AFB8D2-94B6-4CE1-8840-4C0445DCE5A9}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{6EB28614-D01B-41AA-8D5D-D371CCDB5C28}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{DF9DB6BD-20DE-45A9-BEAF-BF2BA29C9CAF}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{3536F45B-6379-4E23-A18B-76355D4DA23D}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{CD871DE2-49EA-471D-800A-DA4ABD45227D}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{8D6E128A-A7D3-4307-9F4D-45B1E3F9C5DC}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 sonypvl3;sonypvl3;c:\windows\system32\drivers\sonypvl3.sys [2007-06-09 19507]
R1 sonypvf3;sonypvf3;c:\windows\system32\drivers\sonypvf3.sys [2007-06-09 619390]
R1 sonypvt3;sonypvt3;c:\windows\system32\drivers\sonypvt3.sys [2007-06-09 423454]
R2 MSCamSvc;MSCamSvc;"c:\program files\Microsoft LifeCam\MSCamS32.exe" [2007-01-04 240408]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-11-13 809296]
R2 UxTuneUp;TuneUp Extension de thème;c:\windows\System32\svchost.exe -k netsvcs [2008-03-22 21504]
R2 WebCamDV;WebCamDV DV to Webcam Converter;c:\windows\system32\DRIVERS\WebCamDV.sys [2004-09-17 212608]
R3 camfilt2;camfilt2;c:\windows\system32\DRIVERS\camfilt2.sys [2008-10-06 94720]
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;c:\windows\system32\drivers\wcdvaud.sys [2004-09-17 12672]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-06-09 306432]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{426d911f-1815-11dc-881d-0019214cc7ff}]
\shell\AutoRun\command - J:\Autorun.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-14 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 14:39]
2008-11-18 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 11:37:55
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-18 11:39:19
ComboFix-quarantined-files.txt 2008-11-18 10:39:16
ComboFix2.txt 2008-11-17 22:07:47
Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Après-CF: 60,651,958,272 octets libres
317 --- E O F --- 2008-11-12 11:49:51