Voici le rapport combofix :
ComboFix 08-10-29.06 - Internity 2008-11-30 20:15:29.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.95 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\Internity\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\Internity\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
- Mode FONCTIONNALITES REDUITES -
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-30 ))))))))))))))))))))))))))))))))))))
.
2008-11-30 16:04 . 2008-11-30 16:04 268 --ah----- C:\sqmdata19.sqm
2008-11-30 16:03 . 2008-11-30 16:04 244 --ah----- C:\sqmnoopt19.sqm
2008-11-30 14:29 . 2008-11-30 19:32 <REP> d-------- C:\Program Files\Navilog1
2008-11-29 17:14 . 2008-11-29 17:14 268 --ah----- C:\sqmdata18.sqm
2008-11-29 17:14 . 2008-11-29 17:14 244 --ah----- C:\sqmnoopt18.sqm
2008-11-28 22:25 . 2008-11-28 22:25 268 --ah----- C:\sqmdata17.sqm
2008-11-28 22:25 . 2008-11-28 22:25 244 --ah----- C:\sqmnoopt17.sqm
2008-11-28 21:14 . 2008-11-28 21:14 268 --ah----- C:\sqmdata16.sqm
2008-11-28 21:14 . 2008-11-28 21:14 244 --ah----- C:\sqmnoopt16.sqm
2008-11-28 20:17 . 2008-11-28 20:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-28 20:17 . 2008-11-28 20:17 <REP> d-------- C:\Documents and Settings\Internity\Application Data\Malwarebytes
2008-11-28 20:17 . 2008-11-28 20:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-28 20:17 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-11-28 20:17 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-11-28 19:53 . 2008-11-30 18:00 <REP> d-------- C:\Program Files\Norton Security Scan
2008-11-28 19:53 . 2008-11-30 18:02 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-11-28 19:33 . 2008-11-28 19:33 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-11-28 19:30 . 2008-11-28 19:30 268 --ah----- C:\sqmdata15.sqm
2008-11-28 19:30 . 2008-11-28 19:30 244 --ah----- C:\sqmnoopt15.sqm
2008-11-28 19:25 . 2008-11-28 19:25 268 --ah----- C:\sqmdata14.sqm
2008-11-28 19:25 . 2008-11-28 19:25 244 --ah----- C:\sqmnoopt14.sqm
2008-11-28 16:42 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-11-28 16:42 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-11-28 16:42 . 2008-10-01 14:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-11-28 16:42 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-11-28 16:42 . 2008-05-18 20:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-11-28 16:42 . 2008-10-10 07:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-11-28 16:42 . 2008-08-18 11:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-11-28 16:42 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-11-28 16:42 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-11-28 14:09 . 2008-11-28 14:09 268 --ah----- C:\sqmdata13.sqm
2008-11-28 14:09 . 2008-11-28 14:09 244 --ah----- C:\sqmnoopt13.sqm
2008-11-28 14:01 . 2008-11-28 14:01 <REP> d-------- C:\WINDOWS\Sun
2008-11-28 13:52 . 2008-11-28 13:51 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-11-28 13:52 . 2008-11-28 13:51 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-11-28 13:51 . 2008-11-28 13:51 <REP> d-------- C:\Program Files\Java
2008-11-27 22:14 . 2008-11-27 22:14 268 --ah----- C:\sqmdata12.sqm
2008-11-27 22:14 . 2008-11-27 22:14 244 --ah----- C:\sqmnoopt12.sqm
2008-11-27 13:50 . 2008-11-27 13:50 268 --ah----- C:\sqmdata11.sqm
2008-11-27 13:50 . 2008-11-27 13:50 244 --ah----- C:\sqmnoopt11.sqm
2008-11-27 13:30 . 2008-11-27 13:30 268 --ah----- C:\sqmdata10.sqm
2008-11-27 13:30 . 2008-11-27 13:30 244 --ah----- C:\sqmnoopt10.sqm
2008-11-25 10:01 . 2008-11-25 10:01 <REP> d-------- C:\Documents and Settings\Internity\Application Data\Lavasoft
2008-11-25 09:57 . 2008-11-25 09:58 <REP> d-------- C:\Program Files\Spyware Doctor
2008-11-25 09:57 . 2008-11-25 09:57 <REP> d-------- C:\Documents and Settings\Internity\Application Data\PC Tools
2008-11-25 09:57 . 2008-08-25 12:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-11-25 09:57 . 2008-08-25 12:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-11-25 09:57 . 2008-08-25 12:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-11-25 09:57 . 2008-06-02 16:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-11-25 09:56 . 2008-11-25 09:56 <REP> d-------- C:\Program Files\Webroot
2008-11-25 09:56 . 2008-11-25 09:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-11-25 09:56 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-11-25 09:56 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-11-25 09:56 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-11-25 09:56 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2008-11-25 09:53 . 2008-11-25 09:53 <REP> d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-11-25 09:53 . 2008-11-25 09:53 <REP> d-------- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2008-11-25 09:53 . 2008-11-25 09:53 <REP> d-------- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-25 09:53 . 2008-11-25 09:53 <REP> d-------- C:\Documents and Settings\Internity\Application Data\Webroot
2008-11-25 09:52 . 2008-11-25 09:52 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-11-25 09:52 . 2008-11-26 11:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-25 09:51 . 2008-11-25 09:51 <REP> d-------- C:\Program Files\Lavasoft
2008-11-25 09:50 . 2008-11-26 11:59 <REP> d-------- C:\Temp
2008-11-25 09:47 . 2008-11-25 09:47 <REP> d-------- C:\WINDOWS\system32\GroupPolicy
2008-11-25 09:46 . 2008-11-28 22:25 <REP> d-------- C:\Program Files\Hitman Pro
2008-11-25 09:46 . 2006-02-28 13:43 1,077,344 --a------ C:\WINDOWS\system32\mscomctl.ocx
2008-11-24 21:28 . 2008-11-24 21:28 <REP> d-------- C:\WINDOWS\system32\Adobe
2008-11-12 18:07 . 2008-11-12 18:07 244 --ah----- C:\sqmnoopt09.sqm
2008-11-12 18:07 . 2008-11-12 18:07 232 --ah----- C:\sqmdata09.sqm
2008-11-12 17:48 . 2008-11-12 17:48 268 --ah----- C:\sqmdata08.sqm
2008-11-12 17:48 . 2008-11-12 17:48 244 --ah----- C:\sqmnoopt08.sqm
2008-11-12 17:45 . 2008-11-12 17:45 268 --ah----- C:\sqmdata07.sqm
2008-11-12 17:45 . 2008-11-12 17:45 244 --ah----- C:\sqmnoopt07.sqm
2008-11-12 17:16 . 2008-11-12 17:16 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-11-12 17:16 . 2008-11-12 17:16 417,839 --a------ C:\WINDOWS\system32\BtAssSvc.exe
2008-11-12 12:31 . 2008-11-12 12:31 268 --ah----- C:\sqmdata06.sqm
2008-11-12 12:31 . 2008-11-12 12:31 244 --ah----- C:\sqmnoopt06.sqm
2008-11-12 10:36 . 2008-11-12 10:36 <REP> d-------- C:\Program Files\Developer One
2008-11-11 21:02 . 2008-11-11 21:02 268 --ah----- C:\sqmdata05.sqm
2008-11-11 21:02 . 2008-11-11 21:02 244 --ah----- C:\sqmnoopt05.sqm
2008-11-10 21:51 . 2008-11-10 21:51 268 --ah----- C:\sqmdata04.sqm
2008-11-10 21:51 . 2008-11-10 21:51 244 --ah----- C:\sqmnoopt04.sqm
2008-11-10 19:43 . 2008-11-10 19:43 268 --ah----- C:\sqmdata03.sqm
2008-11-10 19:43 . 2008-11-10 19:43 244 --ah----- C:\sqmnoopt03.sqm
2008-11-10 17:31 . 2008-11-10 17:31 268 --ah----- C:\sqmdata02.sqm
2008-11-10 17:31 . 2008-11-10 17:31 244 --ah----- C:\sqmnoopt02.sqm
2008-11-07 19:49 . 2008-11-07 19:49 268 --ah----- C:\sqmdata01.sqm
2008-11-07 19:49 . 2008-11-07 19:49 244 --ah----- C:\sqmnoopt01.sqm
2008-11-07 10:19 . 2008-11-30 19:29 268 --ah----- C:\sqmdata00.sqm
2008-11-07 10:19 . 2008-11-30 19:29 244 --ah----- C:\sqmnoopt00.sqm
2008-10-27 13:41 . 2008-10-27 13:41 <REP> d-------- C:\Program Files\American Baby 2-in-1 Installer
2008-10-27 13:38 . 2008-10-27 13:38 <REP> d-------- C:\Program Files\RATP
2008-10-26 21:11 . 2008-11-12 17:08 <REP> d-------- C:\WINDOWS\Agenda Fusion for Pocket PC
2008-10-26 20:53 . 2008-11-21 22:35 <REP> d-------- C:\Program Files\Microsoft ActiveSync
2008-10-26 20:53 . 2005-10-21 02:47 30,592 --a------ C:\WINDOWS\system32\drivers\rndismpx.sys
2008-10-26 20:53 . 2005-10-21 02:47 12,800 --a------ C:\WINDOWS\system32\drivers\usb8023x.sys
2008-10-26 20:44 . 2008-10-26 20:44 <REP> d-------- C:\Intel
2008-10-26 20:20 . 2008-10-26 20:20 <REP> d-------- C:\Dell
2008-10-26 09:46 . 2008-10-26 09:46 <REP> d-------- C:\Documents and Settings\Internity\Application Data\Sony Corporation
2008-10-26 09:41 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-10-26 09:39 . 2008-10-26 09:39 <REP> d-------- C:\Program Files\Sony
2008-10-26 09:39 . 2006-11-02 16:57 118,520 --a------ C:\WINDOWS\system32\PxInsI64.exe
2008-10-26 09:39 . 2006-10-18 19:43 115,960 --a------ C:\WINDOWS\system32\PxCpyI64.exe
2008-10-26 09:39 . 2006-11-02 16:57 36,624 --a------ C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-10-26 09:39 . 2006-08-28 21:48 2,560 --a------ C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-26 09:39 . 2006-08-28 21:48 2,432 --a------ C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-26 09:38 . 2008-10-26 09:38 <REP> d-------- C:\Documents and Settings\Internity\Application Data\InstallShield
2008-10-24 18:21 . 2008-10-24 18:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-24 13:19 . 2008-10-16 14:06 268,648 --a------ C:\WINDOWS\system32\mucltui.dll
2008-10-24 13:19 . 2008-10-16 14:06 208,744 --a------ C:\WINDOWS\system32\muweb.dll
2008-10-24 13:19 . 2008-10-16 14:06 27,496 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-10-24 13:11 . 2004-08-03 22:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-10-24 13:11 . 2004-08-03 21:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-10-24 13:10 . 2004-08-03 22:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-10-24 13:10 . 2004-08-03 22:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-10-24 13:10 . 2004-08-03 22:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2008-10-24 13:10 . 2004-08-19 15:10 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
2008-10-24 13:10 . 2004-08-03 22:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-10-24 13:10 . 2004-08-03 22:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-10-24 10:25 . 2004-08-19 16:10 91,648 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-10-24 10:25 . 2004-08-19 16:10 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-10-24 10:25 . 2004-08-19 16:09 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-24 10:25 . 2004-08-19 16:10 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-10-24 10:25 . 2004-08-19 16:10 28,672 --a------ C:\WINDOWS\system32\vidcap.ax
2008-10-24 10:25 . 2005-10-28 14:48 24,576 -ra------ C:\WINDOWS\system32\RunSetup.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 18:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-29 10:30 --------- d-----w C:\Program Files\Google
2008-10-26 08:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-24 11:10 453,632 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-10-24 09:24 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-10-18 16:42 --------- d-----w C:\Documents and Settings\Internity\Application Data\dvdcss
2008-10-16 13:13 202,776 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w C:\WINDOWS\system32\wups.dll
2008-09-15 15:39 1,846,144 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-04 16:45 1,106,944 ----a-w C:\WINDOWS\system32\msxml3.dll
2008-08-20 05:37 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:44 2,138,112 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:44 2,017,792 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2007-10-12 16:45 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
------- Sigcheck -------
2008-04-14 03:34 14336 e4bdf223cd75478bf44567b4d5c2634d C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\svchost.exe
2006-03-02 13:00 14336 2979b03d5382a602623c0535b16ab9c0 C:\WINDOWS\system32\svchost.exe
2006-03-02 13:00 14336 2979b03d5382a602623c0535b16ab9c0 C:\WINDOWS\system32\dllcache\svchost.exe
2008-04-14 03:33 82432 fb836f9e62d82904c983ad21296a5d9c C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ws2_32.dll
2006-03-02 13:00 82944 eed74b969b2ca1acc558ff60fb420e28 C:\WINDOWS\system32\ws2_32.dll
2006-03-02 13:00 82944 eed74b969b2ca1acc558ff60fb420e28 C:\WINDOWS\system32\dllcache\ws2_32.dll
2006-04-20 13:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 11:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2006-03-02 13:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 12:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 18:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-14 03:34 512000 dd73d6b9f6b4cb630cf35b438b540174 C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\winlogon.exe
2006-03-02 13:00 506368 123eea158f74d0f67a51dcdf065d1091 C:\WINDOWS\system32\winlogon.exe
2006-03-02 13:00 506368 123eea158f74d0f67a51dcdf065d1091 C:\WINDOWS\system32\dllcache\winlogon.exe
2008-04-13 20:20 182656 1df7f42665c94b825322fae71721130d C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ndis.sys
2006-03-02 13:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2006-03-02 13:00 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:53 36608 3bb22519a194418d5fec05d800a19ad0 C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ip6fw.sys
2006-03-02 13:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2006-03-02 13:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-02 19:13 2059008 5311776074b6c13f983dc75baeac9c0c C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2007-02-28 17:08 2061440 7a56a64eb50399613587e90292dd2aab C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 14:39 2065024 dcbc1a6d150b5ee1bd6257186157b0f3 C:\WINDOWS\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 14:23 2068096 8da71f1900721e1e4fcb5b02d55fb771 C:\WINDOWS\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 18:26 2068096 755b50949d0dbc0f0136b0db58765331 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2006-03-02 13:00 2017280 35567c8c50986c2bc5c3efd79cb045e4 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-02 19:08 2017280 50b3a210b6fa8d3089a36a32e7d8b21f C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 17:02 2017792 11c942f6519575079baa9f14aee35e88 C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 14:44 2059776 f9720d61df1e3e47614c4fc891f3fe44 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2008-04-14 03:07 2067968 b71a8f101cefaf82fc5ec16130a54a3f C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ntkrnlpa.exe
2008-08-14 14:44 2017792 7d0242cd4b2242bc766435dc1a1d49fa C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 14:44 2059776 f9720d61df1e3e47614c4fc891f3fe44 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-03-02 19:13 2181632 3e2a0a4a0c0b19fc113618a9562a3b2a C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2007-02-28 17:08 2184192 8e244108562e0e452eb68dff64cb08a9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 14:39 2188032 c6649255e51f145b6e15c505ab68e459 C:\WINDOWS\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 14:23 2191232 c8d4d5974f9671da0a37175650912960 C:\WINDOWS\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 18:26 2191232 d79210549bbf09b7638e860440504299 C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2006-03-02 13:00 2150400 36f32a5a83df734e022734d93860a9a4 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-02 19:07 2137600 e75f7aa5a33479f29c636fd0890f5762 C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 17:02 2138112 c7a39c47c064ae50417a944b60f37b6a C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 14:44 2182400 449566d74b5c261a3a54aa216f0c532b C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2008-04-14 03:08 2191104 099d639da1ef6968d4e41795bb507e6b C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ntoskrnl.exe
2008-08-14 14:44 2138112 f54f9151170d876d9540cb8021cc83d5 C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 14:44 2182400 449566d74b5c261a3a54aa216f0c532b C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-04-14 03:34 109056 54cb50058851d95e56ec70d09f70857f C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\services.exe
2006-03-02 13:00 108544 63dcde1a0d86eeb8924d6738ff616ead C:\WINDOWS\system32\services.exe
2006-03-02 13:00 108544 63dcde1a0d86eeb8924d6738ff616ead C:\WINDOWS\system32\dllcache\services.exe
2008-04-14 03:34 13312 91e6024d6d4dcdecdb36c43ecf9bbecb C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\lsass.exe
2006-03-02 13:00 13312 259af82a0932eea4f316f92db94707b6 C:\WINDOWS\system32\lsass.exe
2006-03-02 13:00 13312 259af82a0932eea4f316f92db94707b6 C:\WINDOWS\system32\dllcache\lsass.exe
2008-04-14 03:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\ctfmon.exe
2006-03-02 13:00 15360 64e41e8fee655b03e3f19ded21ba5118 C:\WINDOWS\system32\ctfmon.exe
2006-03-02 13:00 15360 64e41e8fee655b03e3f19ded21ba5118 C:\WINDOWS\system32\dllcache\ctfmon.exe
2008-04-14 03:34 26624 e74ddb12188c2ff57a78624dbf7332fc C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\userinit.exe
2006-03-02 13:00 25088 84717891f0734c611721f56c60b5fbc3 C:\WINDOWS\system32\userinit.exe
2006-03-02 13:00 25088 84717891f0734c611721f56c60b5fbc3 C:\WINDOWS\system32\dllcache\userinit.exe
2008-04-14 03:33 297984 710bc85a8c22626ee094439e3ea0d38c C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\termsrv.dll
2006-03-02 13:00 297984 78f90c3e230ad122bcb116abad5fefe9 C:\WINDOWS\system32\termsrv.dll
2006-03-02 13:00 297984 78f90c3e230ad122bcb116abad5fefe9 C:\WINDOWS\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-09-03 94208]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-29 21755688]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-06-21 70952]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 413696]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-31 266497]
"HostManager"="C:\Program Files\Fichiers communs\AOL\1192277694\ee\AOLSoftware.exe" [2006-09-26 50736]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-09 335872]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2004-06-02 184320]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"eTCertManger"="C:\WINDOWS\system32\eTCrtMng.exe" [2007-08-15 98304]
"BigDogPath"="C:\WINDOWS\VM_STI.EXE" [2005-10-28 53248]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-28 136600]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-01 4865600]
"NWEReboot"="" [BU]
"TFncKy"="TFncKy.exe" [BU]
"ATIModeChange"="Ati2mdxx.exe" [2004-06-02 C:\WINDOWS\system32\Ati2mdxx.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-02 C:\WINDOWS\agrsmmsg.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 15360]
C:\Documents and Settings\Internity\Menu D‚marrer\Programmes\D‚marrage\
Outil de d‚tection de support Picture Motion Browser.lnk - C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-10-26 385024]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-10 110592]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2007-11-18 155648]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\1192277694\\ee\\aolsoftware.exe"=
"C:\\Program Files\\AOL 9.0 VR\\waol.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-06-02 5632]
R2 BluetoothAssistant;Bluetooth Assistant;C:\WINDOWS\system32\BtAssSvc.exe [2008-11-12 417839]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-11-28 152984]
R3 VSBC;Virtual Serial Bus Enumerator (Eltima Software);C:\WINDOWS\system32\DRIVERS\evsbc.sys [2007-06-12 26448]
S3 AKSUP;AKSUP;C:\WINDOWS\system32\drivers\aksup.sys [2006-01-22 34406]
S3 atimtai;atimtai;C:\WINDOWS\system32\DRIVERS\atimtai.sys [2001-08-23 281728]
S3 evserial;Virtual Serial Ports Driver (Eltima Softwate);C:\WINDOWS\system32\DRIVERS\evserial.sys [2007-06-12 52944]
S3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys [2007-09-11 15904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09a3fe81-1c65-11dd-af7d-00038a000015}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{201f8266-a69f-11dc-af20-00038a000015}]
\Shell\Auto\command - AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
.
Contenu du dossier 'Tâches planifiées'
2008-05-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2008-11-30 C:\WINDOWS\Tasks\Norton Security Scan for Internity.job
- C:\Program Files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-30 20:16:43
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Heure de fin: 2008-11-30 20:20:36
ComboFix-quarantined-files.txt 2008-11-30 19:20:26
ComboFix2.txt 2008-11-28 18:42:32
Avant-CF: 107 555 254 272 octets libres
Après-CF: 107,623,735,296 octets libres
323 --- E O F --- 2008-11-28 21:26:56