bonjour
voici ca a marché c'était bien F5
ComboFix 08-04-03.3 - angy 2008-04-03 19:20:49.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.762 [GMT 2:00]
Endroit: C:\Documents and Settings\angy\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\Icon.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-03 to 2008-04-03 ))))))))))))))))))))))))))))))))))))
.
2008-04-03 19:14 . 2007-09-24 02:36 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-04-03 19:14 . 2007-09-24 02:36 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-04-03 19:14 . 2007-09-24 02:39 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-04-03 19:14 . 2007-09-24 02:39 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-04-03 19:14 . 2007-09-24 02:39 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-04-03 19:14 . 2007-09-24 02:39 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-04-03 19:14 . 2007-09-24 02:36 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
2008-04-03 19:14 . 2007-09-24 02:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
2008-04-03 19:14 . 2007-09-24 02:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-04-03 16:44 . 2008-04-03 19:11 <REP> d-------- C:\Documents and Settings\angy\Application Data\OpenOffice.org2
2008-04-03 16:42 . 2008-04-03 16:42 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-03-04 15:06 . 2008-03-04 15:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-03 21:21 . 2008-03-03 21:22 <REP> d-------- C:\WINDOWS\AU_Temp
2008-03-03 20:37 . 2008-03-03 20:37 <REP> d-------- C:\WINDOWS\report
2008-03-03 20:37 . 2008-03-03 21:21 <REP> d-------- C:\WINDOWS\AU_Backup
2008-03-03 20:37 . 2008-03-03 20:37 35,382,261 --a------ C:\WINDOWS\VPTNFILE.133
2008-03-03 20:37 . 2008-03-03 20:37 1,922,894 --a------ C:\WINDOWS\tsc.ptn
2008-03-03 20:37 . 2008-03-03 21:22 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2008-03-03 20:37 . 2008-03-03 20:37 267,845 --a------ C:\WINDOWS\tsc.exe
2008-03-03 20:37 . 2008-03-03 21:21 86,094 --a------ C:\WINDOWS\BPMNT.dll
2008-03-03 20:37 . 2008-03-03 20:37 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2008-03-03 20:37 . 2008-03-03 21:20 823 --a------ C:\WINDOWS\tsc.ini
2008-03-03 20:34 . 2008-03-03 20:34 <REP> d-------- C:\WINDOWS\AU_Log
2008-03-03 20:34 . 2008-03-03 20:34 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-03-03 20:34 . 2008-03-03 20:34 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-03-03 20:34 . 2008-03-03 20:34 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-03-03 20:34 . 2008-03-03 21:21 170 --a------ C:\WINDOWS\GetServer.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-03 14:41 --------- d-----w C:\Program Files\Java
2008-04-01 17:03 --------- d-----w C:\Documents and Settings\angy\Application Data\MiniLyrics
2008-04-01 15:12 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-03-30 20:26 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-11 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-04 12:47 --------- d-----w C:\Program Files\Yahoo!
2008-03-01 21:55 --------- d-----w C:\Program Files\Minilyrics
2008-03-01 21:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-28 15:08 --------- d-----w C:\Program Files\Windows Live
2008-02-11 18:55 --------- d-----w C:\Program Files\Google
2008-02-11 12:56 --------- d-----w C:\Program Files\Elaborate Bytes
2008-02-11 12:17 --------- d-----w C:\Program Files\tradutor
2008-02-10 23:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 23:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 22:22 --------- d-----w C:\Program Files\AOL 9.0
2008-02-10 00:18 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-20 19:53 49,816 ----a-w C:\Documents and Settings\angy\Application Data\GDIPFONTCACHEV1.DAT
2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D}]
2004-03-17 12:22 820736 --a------ C:\WINDOWS\system32\pbfrv2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D}"= "C:\WINDOWS\system32\pbfrv2.dll" [2004-03-17 12:22 820736]
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d}]
[HKEY_CLASSES_ROOT\pbfrv2.PBFRV2]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D}"= C:\WINDOWS\system32\pbfrv2.dll [2004-03-17 12:22 820736]
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-a0e8-ed6ab685fa7d}]
[HKEY_CLASSES_ROOT\pbfrv2.PBFRV2]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 18:44 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 18:43 688218]
"VTTimer"="VTTimer.exe" [2005-03-08 03:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-09-14 13:47 167936 C:\WINDOWS\system32\VTTrayp.exe]
"STDSB"="C:\WINDOWS\system32\drivers\STDSB.exe" [2003-12-17 16:50 28672]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 18:39 90112 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 11:04 245760]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-24 16:46 98304]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-20 00:02 249896]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-08-24 16:46 26112]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
C:\Documents and Settings\angy\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 MTC0007_STDSB;Scroll Bar Driver;C:\WINDOWS\system32\drivers\STDSB.sys [2005-08-25 15:00]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S2 STDSB;STDSB;C:\WINDOWS\system32\DRIVERS\STDSB.sys [2005-08-25 15:00]
S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 03:00]
*Newly Created Service* - SERIAL
*Newly Created Service* - STDSB
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-03 19:22:56
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
Temps d'accomplissement: 2008-04-03 19:23:46
ComboFix-quarantined-files.txt 2008-04-03 17:23:31
Pre-Run: 38,604,226,560 octets libres
Post-Run: 38,591,844,352 octets libres
.
2008-03-11 20:07:04 --- E O F ---