Ouh la c'est long comme rapport :)))
Bon courage !!!
ComboFix 09-02-19.01 - Sebastien 2009-02-21 11:59:45.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3069.2235 [GMT 1:00]
Lancé depuis: c:\users\Sebastien\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\Sebastien\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1282 [VPS 081118-0] *On-access scanning enabled* (Updated)
FILE ::
c:\windows\System32\drivers\95187250.sys
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\_otmoveit
c:\_otmoveit\MovedFiles\
02212009_003821.log
c:\_otmoveit\MovedFiles\
02212009_003821.res
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\advdis.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\arj.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\arjpack.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avlib.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avp.dt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\Avp_io32.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avp_iont.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avp1.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avp3info.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avpgs.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avpgui.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avpmgr.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avs.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avspm.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avzkrnl.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avzproxy.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\avzscan.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\base64.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\base64p.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\basegui.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\avp_x.set
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\backup.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\bt.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\engine.dt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\keylogger.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\klavemu.kdl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\klavemu.kfb
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\krnldrv.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\megabase.avc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\neural.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\neurald.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\neurale.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\neuralm.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\ports.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\prt.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\repair.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\rootkit.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\scripts.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signf001.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signf002.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signf003.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signf004.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signf005.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signfavp.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\signfusr.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\sr.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\srdb.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\startup.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\syscheck.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\sysipu.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\tsw.avz
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bases\verdicts.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\bl.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\btdisk.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\btimages.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\buffer.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\cab.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\crpthlpr.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\data\BTImages.dat
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\data\sfdb.dat
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\deflate.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\dmap.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\drivers\95187250.cat
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\drivers\95187250.inf
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\drivers\95187250.sys
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\drivers\drvins32.exe
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\dtreg.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\explode.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\filemap.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\fsdrvplg.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\fssync.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\getsi.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\hashcont.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\hashmd5.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\hccmp.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\ichk2.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\inflate.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\inifile.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\is-PP866.cfg
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\is-PP866.com
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\is-PP866.exe
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\iwgen.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\kldirobj.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\klipc.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\l_llio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\lha.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\LOG\avptool_syscheck.zip
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\mailmsg.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\mdmap.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\memmodsc.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\memscan.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\Microsoft.VC80.CRT.manifest
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\minizip.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\minst.exe
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\mkavio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\msoe.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\msvcm80.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\msvcp80.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\msvcr80.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\nfio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\ntfsstrm.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\ods.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\params.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\passdmap.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\pdm.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\pdm2rt.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\prkernel.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\prloader.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\procmon.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\prremote.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\prseqio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\prutil.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\pxstub.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\qb.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\rar.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\reggrd.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\regmap.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\
0003_Scan_Objects_eventlog.rpt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\
0005_AVZ_CollectSysInfo_eventlog.rpt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\detected.idx
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\detected.rpt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\eventlog.rpt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\report\report.rpt
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\resip.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\scmhlpr.dll
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\sfdb.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\avz.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\avzkrnl.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\credits.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\hints.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\iso3166-1.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\main.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\oas.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\prot.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\report.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\scan.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\service.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\en\settings.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\enums.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\activity.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\application.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\Arrow.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\background.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\badmail.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\banner.gif
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\Banner.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\battery.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\bootsect.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\collapse.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\danger24.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\danger32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\dialer.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\disk.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\display.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\error.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\expand.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\floppy.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\Goodmail.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\gripper.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\help.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\help16.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\i16.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\i24.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\i32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\ids.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\ie.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\info.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\integrity.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\internet.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\internet16.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\intranet.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kav_en.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kav_ru.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kav2006.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kav2006rus.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_bs.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_caps.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_ctrl.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_enter.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_lshift.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_normal.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_rshift.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_slash.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_space.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kbdbtn_tab.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\key.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\kl.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\local.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\lockbutton.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\locked.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\logo.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\mail.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\mail_bad.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\main_off16.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\main_off32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\main_on16.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\main_on32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\memory.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\msg_bad.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\msg_deleted.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\msg_good.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\msg_new.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\msg_question.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\navstate.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\navstate2.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\network.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\nonrecursive.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\notepad.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\Notify.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\office.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\ok.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\ok24.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\ok32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\password.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\pause.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\popup_allowed.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\popup_blocked.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\Privacy.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\rdisk.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\regedit.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\regicons.ico
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\run.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\settings.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\startupobj.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\stealth.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\stop.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\t_hdr.bmp
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\t_row.bmp
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\taskbar.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antihacker32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antihackerX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antispam32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antispamX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antispy32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\antispyX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\datafiles.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\datafiles32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\file32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\fileX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\mail32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\mailX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\pdm32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\pdmX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\prot32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\protection.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\scan32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\scanX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\support.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\support32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\updater32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\updaterX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\web32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\tasks\webX.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\title.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\trusted.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\unkobj.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\unlocked.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\visa.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\warning.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\warning24.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\warning32.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\images\wizard.png
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\avz.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\main.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\oas.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\prot.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\report.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\scan.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\service.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\layout\settings.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\prot.loc
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\skin.ini
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\skin\sounds\Infected.wav
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\startup.exe
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\stdcomp.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\stenum2.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\stored.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\superio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\tempfile.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\thpimpl.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\timer.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\tm.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\unarj.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\uniarc.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\unlzx.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\unreduce.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\unshrink.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\unstored.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\vmarea.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\wdiskio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\winreg.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\xorio.ppl
c:\_otmoveit\MovedFiles\
02212009_003821\Outils\Virus Removal Tool\is-PP866\zcompare.ppl
c:\programdata\is-PP866
c:\programdata\is-PP866\~PRCustomProps#122.dat
c:\programdata\is-PP866\~PRObjects#122.dat
c:\users\All Users\is-PP866\~PRCustomProps#122.dat
c:\users\All Users\is-PP866\~PRObjects#122.dat
c:\windows\System32\drivers\95187250.sys
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IS-PP866DRV
-------\Service_is-PP866drv
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-21 au 2009-02-21 ))))))))))))))))))))))))))))))))))))
.
2009-02-20 19:20 . 2009-02-20 19:40 <REP> d-------- C:\Lop SD
2009-02-20 18:48 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-20 18:48 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-20 18:48 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-20 18:48 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-20 18:48 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-20 18:48 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-20 18:48 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-20 18:48 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-20 18:43 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-20 18:43 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-20 18:43 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-20 18:43 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-20 18:43 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-20 16:59 . 2009-02-20 18:25 <REP> d-------- c:\program files\EsetOnlineScanner
2009-02-20 13:56 . 2009-02-20 13:56 <REP> d-------- c:\users\Sebastien\AppData\Roaming\Malwarebytes
2009-02-20 13:56 . 2009-02-20 13:56 <REP> d-------- c:\users\All Users\Malwarebytes
2009-02-20 13:56 . 2009-02-20 13:56 <REP> d-------- c:\programdata\Malwarebytes
2009-02-20 13:56 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-20 13:56 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-20 11:19 . 2009-02-20 11:20 <REP> d-------- C:\rsit
2009-02-20 01:26 . 2009-02-21 12:03 437,846,048 --ahs---- c:\windows\System32\drivers\fidbox.dat
2009-02-20 01:26 . 2009-02-21 12:03 5,133,128 --ahs---- c:\windows\System32\drivers\fidbox.idx
2009-02-15 20:38 . 2009-02-15 20:38 <REP> d-------- c:\program files\Microsoft
2009-02-15 19:42 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-15 19:42 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-15 19:42 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-15 19:42 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-15 19:42 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-15 16:36 . 2009-02-15 16:36 <REP> d--hs---- C:\found.000
2009-02-11 20:41 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 20:41 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a------ c:\windows\System32\sirenacm.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 18:12 --------- d-----w c:\programdata\NVIDIA
2009-02-20 14:52 --------- d-----w c:\programdata\Zylom
2009-02-20 00:06 --------- d---a-w c:\programdata\TEMP
2009-02-19 22:07 --------- d-----w c:\users\Sebastien\AppData\Roaming\DNA
2009-02-19 00:27 --------- d-----w c:\program files\DNA
2009-02-15 19:47 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-15 19:37 --------- d-----w c:\program files\Windows Live
2009-02-15 18:20 --------- d-----w c:\programdata\HP Product Assistant
2009-02-12 02:01 --------- d-----w c:\programdata\Microsoft Help
2009-02-12 02:00 --------- d-----w c:\program files\Windows Mail
2009-02-05 21:06 51,792 ----a-w c:\windows\system32\drivers\aswMonFlt.sys
2009-02-04 23:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 22:16 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2007-11-28 19:41 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-11-28 19:41 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-11-28 19:41 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-11-28 19:41 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-11-28 19:41 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-06-16 23:08 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-16 23:08 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-16 23:08 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-02-21_ 1.28.24,06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-02-21 00:01:24 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-02-21 11:06:06 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-02-21 00:01:24 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-02-21 11:06:06 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-02-21 00:02:56 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-21 11:16:33 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-21 11:16:33 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-02-21 00:02:51 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-21 11:18:41 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-21 11:18:41 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-02-21 00:03:14 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-21 11:09:59 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-21 00:03:14 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-21 11:09:59 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-21 00:03:14 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-21 11:09:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-02-21 00:07:12 117,790 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-21 11:13:37 117,790 ----a-w c:\windows\System32\perfc009.dat
- 2009-02-21 00:07:12 144,214 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-02-21 11:13:37 144,214 ----a-w c:\windows\System32\perfc00C.dat
- 2009-02-21 00:07:12 628,288 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-21 11:13:37 628,288 ----a-w c:\windows\System32\perfh009.dat
- 2009-02-21 00:07:12 716,060 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-02-21 11:13:37 716,060 ----a-w c:\windows\System32\perfh00C.dat
- 2009-02-21 00:03:17 6,368 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3327374385-1407952491-1078166200-1000_UserData.bin
+ 2009-02-21 00:37:44 6,368 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3327374385-1407952491-1078166200-1000_UserData.bin
- 2009-02-21 00:03:17 61,680 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-21 00:37:44 61,782 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-02-21 00:03:13 42,348 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-21 00:37:41 42,364 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-02-20 10:11:00 313,446 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2009-02-21 10:12:47 314,252 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2007-10-02 2560000]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-04 136600]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"TVEService"="c:\program files\Packard Bell\TVenhance\TVEService.exe" [2007-11-21 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-20 c:\windows\RtHDVCpl.exe]
"LchMHotkey"="LchMHKey.exe" [2007-01-22 c:\windows\LchMHKey.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\media\Palm\Hotsync.exe [2008-01-03 1392640]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{77AD26D5-7C92-4019-8BA3-AA8EDB5477C7}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F063E9CA-7CFF-4446-AA47-7BAA5AE4F44D}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{12BF6E5E-D828-4679-81DD-0C72515EA187}"= c:\program files\Packard Bell\TVenhance\TVEnhance.exe:CyberLink TVEnhance
"{0B7B4DDA-B8B8-44B6-8BB8-5952797C07CE}"= c:\program files\Packard Bell\TVenhance\TVEService.exe:CyberLink TVEnhance Resident Program
"TCP Query User{4C042A33-A926-4420-8632-D563330AFEF7}c:\\modem\\emule\\emule.exe"= UDP:c:\modem\emule\emule.exe:eMule
"UDP Query User{210D35C7-AC9C-4DDD-9BD4-25134FBA5522}c:\\modem\\emule\\emule.exe"= TCP:c:\modem\emule\emule.exe:eMule
"{ACE6BEE7-285B-47CD-AFFB-1565309075AA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{987635F7-A8C6-4613-A398-EC5684DEB448}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{8DF9B043-1CB9-4FA5-9A14-6870095C26F0}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{00D1929C-A72B-475F-9F62-A3CB42F91567}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{0AC4966A-248A-4969-9FE7-FA1193C61D79}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{13F8C08D-1B4A-4FC7-91DA-08D501D146D6}"= UDP:c:\media\iTunes\iTunes.exe:iTunes
"{4855DE63-656F-4D11-85FE-2652041EC1CE}"= TCP:c:\media\iTunes\iTunes.exe:iTunes
"{043F122F-F0EB-47C5-AACB-AE86C84DB782}"= UDP:c:\jeux\Sega JO PEKIN 2008\Beijing.exe:Beijing 2008™
"{592243D6-6BE3-4163-B163-708E9D89C7E4}"= TCP:c:\jeux\Sega JO PEKIN 2008\Beijing.exe:Beijing 2008™
"{5804C84E-7E66-458D-A969-0F94AF2AFA90}"= UDP:c:\jeux\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{3D61E9E2-D81B-4449-8E8A-49FB15553708}"= TCP:c:\jeux\KONAMI\Pro Evolution Soccer 2008\PES2008.exe:Pro Evolution Soccer 2008
"{24B78BD1-F87B-41AC-A898-FD1593F93773}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{FE7B50BD-32F2-4841-B465-6198B549CCB9}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{1FEBD5A3-ACCA-47F4-98B8-F06EEBCEC839}"= UDP:c:\modem\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{7C74F798-C694-4FDF-A1A6-9E2779EC3B84}"= TCP:c:\modem\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"TCP Query User{4C6F088A-9945-4996-A748-0A3CDACC2E3D}c:\\program files\\real\\realplayer\\recordingmanager.exe"= UDP:c:\program files\real\realplayer\recordingmanager.exe:RealNetworks Download and Record Manager
"UDP Query User{55775FC7-9B7D-4073-A464-93634851F04B}c:\\program files\\real\\realplayer\\recordingmanager.exe"= TCP:c:\program files\real\realplayer\recordingmanager.exe:RealNetworks Download and Record Manager
"{3860248C-73CC-40C3-8049-D0D79D7E59F8}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{97F25F43-A47D-4976-9D1A-DD791AF52E44}"= TCP:c:\program files\DNA\btdna.exe:DNA
"TCP Query User{0C8D21B7-2524-4D6D-9BC1-ADBC22621851}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{4D50A86C-B8CA-4154-9B27-24AA7ED1A7BF}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{2BD43F83-E757-4189-BACF-0A59EEC8D826}"= UDP:5721:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}:@%systemroot%\WindowsMobile\wmdc.exe,-4002
"{633EA252-BE5E-40C9-88DB-986C2D1A7478}"= UDP:1034:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}:@%systemroot%\WindowsMobile\wmdc.exe,-4003
"{27062EA4-0109-49B2-BCAE-850717C6C47A}"= UDP:5678:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4004
"{C9893C8B-0F2D-4C53-AB51-F7EFC52A62A5}"= UDP:999:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}|%systemroot%\WindowsMobile\wmdHost.exe:@%systemroot%\WindowsMobile\wmdc.exe,-4005
"{1A30B867-A0D9-4D38-9381-88FEC48F0B90}"= UDP:26675:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}:@%systemroot%\WindowsMobile\wmdc.exe,-4006
"{3D61920A-4D3F-4B31-85CA-EE03D446B0A5}"= UDP:990:LocalSubnet:LocalSubnet|IF={43E4CD71-4352-4740-83D8-0433C35BFDA3}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdc.exe,-4001
"TCP Query User{D48124B5-32FB-4EBD-8DD2-7C1DA7E2B35C}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{1ABE5C14-5DEB-4743-BB73-F1918FB0AC84}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Modem\\BitTorrent\\bittorrent.exe"= c:\modem\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-06-01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-06-01 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2008-06-01 51792]
R2 SrvCDEject;SrvCDEject;c:\program files\Packard Bell\SrvCDEject.exe [2008-04-17 600064]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\Packard Bell\TVenhance\Kernel\TV\TVECapSvc.exe [2008-04-17 290909]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\Packard Bell\TVenhance\Kernel\TV\TVESched.exe [2008-04-17 114779]
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\System32\drivers\3xHybrid.sys [2008-04-18 1116800]
R3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;c:\windows\System32\drivers\WlanUIG.sys [2008-06-01 379456]
R3 X10Hid;X10 Hid Device;c:\windows\System32\drivers\x10hid.sys [2008-04-17 13976]
S4 FLMCKUSB;AuthenTec TruePrint USB Driver (AES3400, AES3500, AES4000);c:\windows\System32\drivers\FLMckUSB.sys [2008-04-18 69810]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\L]
\shell\AutoRun\command - L:\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{28c6694a-bc28-11dd-868a-0060b3b143a5}]
\shell\AutoRun\command - L:\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{89f2161e-2f72-11dd-8866-806e6f6e6963}]
\shell\AutoRun\command - F:\Autorun.exe
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://fr.yahoo.com/
mStart Page =
hxxp://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&p(...)
uInternet Settings,ProxyOverride = *.local
DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} -
hxxps://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
FF - ProfilePath -
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.accept.default", "application/x-shockwave-flash,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-21 12:18:57
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\SEBAST~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(3408)
c:\program files\Softex\OmniPass\SCUREDLL.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\program files\Softex\OmniPass\OmniServ.exe
c:\windows\System32\audiodg.exe
c:\modem\AdAware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\windows\System32\IoctlSvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\progra~1\COMMON~1\X10\Common\X10nets.exe
c:\windows\System32\WUDFHost.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\mHotkey.exe
c:\windows\CDCtr.exe
c:\windows\ModHIDKey.exe
c:\windows\System32\conime.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\System32\rundll32.exe
c:\program files\Softex\OmniPass\opvapp.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-02-21 12:21:19 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-21 11:21:13
ComboFix2.txt 2009-02-21 00:30:05
Avant-CF: 364 861 956 096 octets libres
Après-CF: 365,046,390,784 octets libres
592 --- E O F --- 2009-02-20 17:59:06