voilà...j'ai utilisé ComboFix et voici le résultat...
ComboFix 08-11-18.02 - Propriétaire 2008-11-18 21:25:31.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.298 [GMT 1:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-18 au 2008-11-18 ))))))))))))))))))))))))))))))))))))
.
2008-11-16 19:01 . 2008-11-16 19:01 <REP> d-------- c:\program files\JRE
2008-11-15 15:03 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-15 15:03 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-10 09:14 . 2008-11-17 14:26 <REP> d-------- c:\program files\Navilog1
2008-11-10 00:34 . 2008-11-10 00:34 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\OpenOffice.org
2008-11-09 14:03 . 2008-11-09 15:30 <REP> d--h----- C:\$AVG8.VAULT$
2008-11-09 10:57 . 2008-11-09 10:57 <REP> d-------- c:\documents and settings\Thomas\Application Data\Malwarebytes
2008-11-09 10:00 . 2008-11-09 10:26 <REP> d-------- c:\documents and settings\Thomas\Application Data\AVGTOOLBAR
2008-11-09 02:29 . 2008-11-16 19:01 <REP> d-------- c:\program files\OpenOffice.org 3
2008-11-09 01:45 . 2008-11-09 14:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-09 01:45 . 2008-11-09 01:45 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Malwarebytes
2008-11-09 01:45 . 2008-11-09 01:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-09 01:45 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-09 01:45 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-08 22:09 . 2008-06-10 02:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-11-08 14:29 . 2008-11-08 14:44 <REP> d-------- c:\documents and settings\TEMP\Application Data\AVGTOOLBAR
2008-11-08 09:29 . 2008-11-18 15:43 <REP> d-------- c:\windows\system32\drivers\Avg
2008-11-08 09:29 . 2008-11-08 09:29 <REP> d-------- c:\program files\AVG
2008-11-08 09:29 . 2008-11-08 20:53 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\AVGTOOLBAR
2008-11-08 09:29 . 2008-11-10 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-11-08 09:29 . 2008-11-08 09:29 98,440 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-11-08 09:29 . 2008-11-08 09:29 90,632 --a------ c:\windows\system32\drivers\avgtdix.sys
2008-11-08 09:29 . 2008-11-08 09:29 12,936 --a------ c:\windows\system32\drivers\avgrkx86.sys
2008-11-08 09:29 . 2008-11-08 09:29 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-11-06 11:14 . 2008-11-06 11:14 <REP> d-------- c:\program files\Boonty
2008-11-01 16:07 . 2008-11-01 16:07 <REP> d-------- c:\documents and settings\All Users\Application Data\wmp
2008-10-29 21:49 . 2008-11-17 18:57 1,426 --a------ c:\windows\
0
2008-10-29 21:49 . 2008-11-17 18:57 190 --a------ c:\windows\Faux
2008-10-29 21:49 . 2008-11-17 18:57 87 --a------ c:\windows\Times New Roman
2008-10-29 21:44 . 2008-10-29 21:44 <REP> d-------- c:\program files\Mindscape
2008-10-24 12:38 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 23:03 . 2008-10-23 23:03 <REP> d-------- c:\program files\Fichiers communs\xing shared
2008-10-23 18:18 . 2008-10-26 07:14 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\U3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 20:32 --------- d-----w c:\documents and settings\Propriétaire\Application Data\skypePM
2008-11-18 20:32 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Skype
2008-11-18 20:30 17,408 ----a-w c:\windows\system32\drivers\USBCRFT.SYS
2008-11-15 18:06 1,838 ----a-w c:\documents and settings\TEMP\Application Data\wklnhst.dat
2008-11-09 09:02 --------- d-----w c:\documents and settings\Thomas\Application Data\Apple Computer
2008-11-08 21:42 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2008-11-08 21:09 --------- d-----w c:\program files\Java
2008-11-06 10:14 --------- d-----w c:\program files\BoontyGames
2008-11-05 17:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-03 21:19 --------- d-----w c:\program files\a-squared Anti-Malware
2008-11-02 19:00 --------- d-----w c:\program files\VoipCheapCom
2008-11-02 19:00 --------- d-----w c:\documents and settings\Propriétaire\Application Data\LimeWire
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 22:02 --------- d-----w c:\program files\Fichiers communs\Real
2008-10-16 13:14 --------- d--h--w c:\documents and settings\Propriétaire\Application Data\yahoo!
2008-10-16 07:56 262,144 ----a-w C:\ntuser.dat
2008-10-14 16:24 --------- d-----w c:\documents and settings\TEMP\Application Data\Apple Computer
2008-10-07 20:12 --------- d-----w c:\program files\eBay
2008-10-07 17:26 --------- d-----w c:\documents and settings\All Users\Application Data\WholeSecurity
2008-10-07 08:53 --------- d-----w c:\program files\Macrogaming
2008-10-05 16:15 --------- d-----w c:\program files\Google
2008-10-04 20:57 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Apple Computer
2008-10-04 16:31 --------- d-----w c:\program files\AAALOGO2008
2008-10-04 16:11 --------- d-----w c:\program files\iTunes
2008-10-04 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 16:10 --------- d-----w c:\program files\iPod
2008-10-04 15:56 --------- d-----w c:\program files\Safari
2008-10-04 15:38 --------- d-----w c:\program files\Kiwee Toolbar2
2008-10-04 15:38 --------- d-----w c:\documents and settings\All Users\Application Data\Kiwee Toolbar2
2008-10-04 14:26 --------- d-----w c:\program files\Incredijeux
2008-10-04 14:24 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-04 14:23 --------- d-----w c:\documents and settings\Propriétaire\Application Data\iWin
2008-10-04 14:21 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-10-04 14:17 --------- d-----w c:\program files\Microsoft Silverlight
2008-09-27 10:27 --------- d-----w c:\program files\Bonjour
2008-09-27 10:26 --------- d-----w c:\program files\QuickTime
2008-09-27 10:26 --------- d-----w c:\program files\Fichiers communs\Apple
2008-09-27 10:26 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-09-27 10:23 --------- d-----w c:\program files\Apple Software Update
2008-09-27 10:22 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-09-27 09:57 --------- d-----w c:\program files\Wyzo
2008-09-22 20:28 --------- d-----w c:\program files\Zylom Games
2008-09-22 19:23 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Zylom
2008-09-22 19:23 --------- d-----w c:\documents and settings\Propriétaire\Application Data\SpinTop Games
2008-09-21 14:55 --------- d-----w c:\program files\MSN Messenger
2008-09-21 14:53 --------- d-----w c:\program files\SweetIM
2008-09-21 14:53 --------- d-----w c:\documents and settings\All Users\Application Data\SweetIM
2008-09-21 12:35 --------- d-----w c:\program files\LimeWire
2008-09-18 14:19 --------- d-----r c:\documents and settings\TEMP\Application Data\Brother
2008-02-13 21:22 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-11-18 16:18 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-07-17 16:37 23,572 ----a-w c:\documents and settings\Propriétaire\Application Data\wklnhst.dat
2006-11-09 07:10 20,822 ----a-w c:\documents and settings\Titou\Application Data\wklnhst.dat
2006-01-26 13:08 444 ----a-w c:\documents and settings\Thomas\Application Data\wklnhst.dat
2006-09-14 12:01 1,160 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-07-06 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VoipCheapCom"="c:\program files\VoipCheapCom\VoipCheapCom.exe" [2008-09-13 9218872]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-01 21898024]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2006-06-18 311340]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 1211176]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"Ashampoo PopUpBlocker"="c:\progra~1\Ashampoo\ASHAMP~1\PopUpKiller.exe" [2004-02-03 1216000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-10-23 185896]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"SetDefPrt"="c:\program files\Brother\Brmfl04b\BrStDvPt.exe" [2004-05-25 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"Keyboard Status"="c:\progra~1\Medion\KeyStat\KeyStat.exe" [2005-01-25 411648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-03-10 40960]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-08 1235736]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-01-12 344064]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"Dit"="Dit.exe" [2004-07-20 c:\windows\Dit.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
eBayCenter.lnk - c:\program files\eBayCenter\eBayCenter.exe [2006-07-15 1011712]
eBayer 3.lnk - c:\program files\eBayer 3\ebayer3d.exe [2006-02-11 397312]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-09-03 450560]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-11-09 819200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\eBayCenter\\eBayCenter.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VoipCheapCom\\VoipCheapCom.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\Drivers\avgrkx86.sys [2008-11-08 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-08 98440]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-11-08 90632]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-08 874776]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-08 231704]
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2005-09-18 802048]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;c:\windows\system32\Drivers\BrSerIf.sys [2004-06-12 51712]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;c:\windows\system32\Drivers\BrUsbSer.sys [2004-01-10 11648]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [2005-09-09 1272000]
S1 ensqio;ensqio;c:\windows\system32\DRIVERS\ensqio.sys []
S1 sbpcint4;SB AudioPCI 128;c:\windows\system32\DRIVERS\sbpcint4.sys []
S3 CardReaderFilter;Card Reader Filter;\??\c:\windows\system32\Drivers\USBCRFT.SYS [2005-09-01 17408]
S3 wbscr;Winbond Smartcard Reader for I/O;c:\windows\system32\drivers\wbscr.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8f343358-a126-11dd-96e2-001109e2e899}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2008-09-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-18 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-07-07 17:26]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Yahoo! Pager - ~c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
HKCU-Run-LDM - \Program\BackWeb-8876480.exe
HKLM-Run-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
HKLM-Run-eBayToolbar - c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe
HKLM-Run-RegistryMechanic - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\3ybmjjck.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://search.sweetim.com/search.asp?src=2&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:(...)
FF -: plugin - c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 21:31:22
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\brss01a.exe
c:\windows\system32\scardsvr.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\IncrediMail\bin\IMApp.exe
c:\program files\YesMessenger\YesMessenger.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Heure de fin: 2008-11-18 21:39:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-18 20:39:39
Avant-CF: 37 483 986 944 octets libres
Après-CF: 37,470,797,824 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptOut
293 --- E O F --- 2008-11-15 14:16:42