Voilà déjà le rapport ( enfin un truc qui met pas 3 ou 4 heures , lol ):
ComboFix 09-01-17.04 - Nathalie 2009-01-18 18:32:57.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2045.990 [GMT 1:00]
Lancé depuis: e:\nathalie\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 081123-0] *On-access scanning disabled* (Outdated)
.
ADS - Windows: deleted 72 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\AUTORUN.INF
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-18 au 2009-01-18 ))))))))))))))))))))))))))))))))))))
.
2009-01-18 18:20 . 2008-06-19 17:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2009-01-18 17:47 . 2009-01-18 18:36 6,965,280 --ahs---- c:\windows\System32\drivers\fidbox.dat
2009-01-18 17:47 . 2009-01-18 17:47 0 --ahs---- c:\windows\System32\drivers\fidbox.idx
2009-01-18 15:18 . 2009-01-18 15:18 <REP> d-------- c:\users\All Users\is-NUGQD
2009-01-18 15:18 . 2009-01-18 15:18 <REP> d-------- c:\programdata\is-NUGQD
2009-01-17 01:34 . 2009-01-18 17:49 13,542 --a------ c:\users\Nathalie\AppData\Roaming\nvModes.dat
2009-01-15 15:13 . 2009-01-15 15:13 <REP> d-------- c:\users\All Users\WindowsSearch
2009-01-15 15:13 . 2009-01-15 15:13 <REP> d-------- c:\programdata\WindowsSearch
2009-01-14 23:39 . 2009-01-15 19:12 <REP> d-------- C:\Didou
2009-01-14 23:38 . 2009-01-16 01:16 <REP> d-------- c:\users\Nathalie\AppData\Roaming\Desktopicon
2009-01-14 23:38 . 2009-01-15 14:30 <REP> d-------- c:\program files\Unlocker
2009-01-14 22:11 . 2009-01-18 13:21 <REP> d-------- c:\program files\Arovax AntiSpyware
2009-01-14 21:15 . 2009-01-14 21:15 <REP> d-------- c:\users\Nathalie\AppData\Roaming\Malwarebytes
2009-01-14 21:14 . 2009-01-14 21:14 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-14 21:14 . 2009-01-14 21:14 <REP> d-------- c:\programdata\Malwarebytes
2009-01-14 16:28 . 2009-01-18 18:17 <REP> d-------- c:\users\Nathalie\.housecall6.6
2009-01-14 13:31 . 2009-01-14 13:31 <REP> d-------- c:\users\Nathalie\AppData\Roaming\Uniblue
2009-01-13 23:37 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-01 19:29 . 2009-01-01 19:29 <REP> d-------- c:\program files\DVD Shrink
2009-01-01 18:21 . 2009-01-01 18:21 <REP> d-------- C:\CloneDVDTemp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 17:19 --------- d-----w c:\program files\Panda Security
2009-01-18 16:50 --------- d---a-w c:\programdata\TEMP
2009-01-18 16:31 --------- d-----w c:\program files\eMule
2009-01-16 23:46 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-01-16 21:52 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-16 00:16 --------- d-----w c:\program files\eChanblard
2009-01-15 20:40 --------- d-----w c:\program files\Mystery Museum
2009-01-15 13:17 --------- d-----w c:\program files\AxBx
2009-01-14 23:56 --------- d-----w c:\program files\Wyzo
2009-01-14 23:56 --------- d-----w c:\program files\vmntoolbar
2009-01-14 23:56 --------- d-----w c:\program files\FlashGet
2009-01-14 23:55 --------- d-----w c:\users\Nathalie\AppData\Roaming\uTorrent
2009-01-14 23:55 --------- d-----w c:\program files\Tumblebugs 2
2009-01-14 23:55 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-14 08:29 --------- d-----w c:\program files\Windows Mail
2009-01-11 12:36 --------- d-----w c:\users\Nathalie\AppData\Roaming\Wildfire
2009-01-02 19:58 --------- d-----w c:\program files\Free Easy Burner
2009-01-01 18:50 --------- d-----w c:\programdata\DVD Shrink
2009-01-01 17:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-01 17:16 --------- d-----w c:\program files\CCleaner
2009-01-01 17:13 --------- d-----w c:\program files\Xvid
2009-01-01 17:13 --------- d-----w c:\program files\neodivx2006
2009-01-01 17:13 --------- d-----w c:\program files\Morgan
2009-01-01 17:10 --------- d-----w c:\program files\dlls
2009-01-01 17:09 --------- d-----w c:\program files\AviSynth 2.5
2008-12-22 14:03 --------- d-----w c:\program files\Google
2008-12-21 00:39 --------- d-----w c:\program files\Webtarot
2008-12-07 17:51 --------- d-----w c:\program files\Java
2008-12-03 19:09 --------- d-----w c:\program files\Common Files\Adobe
2008-12-01 21:13 --------- d-----w c:\program files\MSN Messenger
2008-12-01 20:42 339,968 ----a-w c:\windows\System32\pythoncom25.dll
2008-12-01 20:42 2,117,632 ----a-w c:\windows\System32\python25.dll
2008-12-01 20:42 114,688 ----a-w c:\windows\System32\pywintypes25.dll
2008-11-26 17:17 51,792 ----a-w c:\windows\system32\drivers\aswMonFlt.sys
2008-11-10 04:43 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-28 20:40 11,896 --sha-w c:\windows\System32\KGyGaAvL.sys
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-09-01 20:41 53,062 ----a-w c:\program files\__def.rip2
2008-09-01 20:38 500 ----a-w c:\program files\versions.xml
2008-08-24 15:07 174 --sha-w c:\program files\desktop.ini
2007-06-25 11:59 4,960,221 ----a-w c:\users\Nathalie\RivaEncoderSetup.exe
2008-08-19 23:12 8 --sha-r c:\windows\System32\
0C2CE139BA.sys
2008-08-30 20:41 104 --sh--r c:\windows\System32\DB0A761FF1.sys
2008-06-02 08:52 168 --sh--r c:\windows\System32\F11F760ADB.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2008-07-03 812952]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-14 411768]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-10-29 102400]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-07 7766016]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"FLMOFFICE4DMOUSE"="c:\program files\Trust\MI-4550XP WIRELESS OPTICAL MINI MOUSE\Mouse32a.exe" [2007-04-22 370176]
"ElbyCheckAnyDVD"="c:\program files\SlySoft\AnyDVD\ElbyCheck.exe" [2003-09-20 45056]
"CloneDVDElbyDelay"="c:\program files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 45056]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-12-11 530552]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-07 c:\windows\RtHDVCpl.exe]
"NDSTray.exe"="NDSTray.exe" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"vidc.X264"= x264vfw.dll
"vidc.i420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0FE4ECD0-7365-43D1-AA5F-B08C32E00B39}"= UDP:c:\program files\Internet Explorer\iexplore.exe:Internet Explorer
"{F268E92D-9119-490A-AE73-23F1C2284D13}"= TCP:c:\program files\Internet Explorer\iexplore.exe:Internet Explorer
"{A6CF94C9-E009-41B3-8E94-599EB1994F1E}"= UDP:c:\program files\TOSHIBA\Utilities\TACSPROP.exe:Accessibilité
"{33E9434B-9245-4CB6-8438-4870560A4B04}"= TCP:c:\program files\TOSHIBA\Utilities\TACSPROP.exe:Accessibilité
"TCP Query User{FF8D769A-C1B9-4A74-BD1A-4515E15D7915}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{C9EB0D1E-F7D0-4851-B190-99F979333FB7}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{E852F32D-AE1D-4797-8B6A-0CE73954B90A}d:\\easyguppy+\\smartmail\\smartsvr.exe"= UDP:d:\easyguppy+\smartmail\smartsvr.exe:SmartMail Server 2.0
"UDP Query User{456CE8FD-C768-495A-823A-9F0ED67F93AB}d:\\easyguppy+\\smartmail\\smartsvr.exe"= TCP:d:\easyguppy+\smartmail\smartsvr.exe:SmartMail Server 2.0
"TCP Query User{96794751-0EB8-4973-9E5E-DF95144CA821}c:\\program files\\easyguppy+\\abysswebserver\\abyssws.exe"= UDP:c:\program files\easyguppy+\abysswebserver\abyssws.exe:Abyss Web Server X1
"UDP Query User{5F330433-D0B1-403A-8E8E-1BFAED8DBB21}c:\\program files\\easyguppy+\\abysswebserver\\abyssws.exe"= TCP:c:\program files\easyguppy+\abysswebserver\abyssws.exe:Abyss Web Server X1
"TCP Query User{8636AACA-7A41-4E03-B17D-559290C7D9B5}c:\\program files\\easyguppy+\\smartmail\\smartsvr.exe"= UDP:c:\program files\easyguppy+\smartmail\smartsvr.exe:SmartMail Server 2.0
"UDP Query User{208629CB-6811-4988-B927-B908873A32B1}c:\\program files\\easyguppy+\\smartmail\\smartsvr.exe"= TCP:c:\program files\easyguppy+\smartmail\smartsvr.exe:SmartMail Server 2.0
"TCP Query User{010F67A1-55B5-4A3A-B1D0-6227F50EF200}c:\\program files\\easyguppy+\\hermes\\hermes.exe"= UDP:c:\program files\easyguppy+\hermes\hermes.exe:Hermes EMail Server
"UDP Query User{908BFCB8-7427-477A-94E8-7914755AD4DB}c:\\program files\\easyguppy+\\hermes\\hermes.exe"= TCP:c:\program files\easyguppy+\hermes\hermes.exe:Hermes EMail Server
"TCP Query User{7C313C33-9499-4469-BD50-90A707E52E87}c:\\program files\\easyguppy+\\abysswebserver\\abyssws.exe"= UDP:c:\program files\easyguppy+\abysswebserver\abyssws.exe:Abyss Web Server X1
"UDP Query User{DE314A43-245B-4867-8F77-C78969D05AFE}c:\\program files\\easyguppy+\\abysswebserver\\abyssws.exe"= TCP:c:\program files\easyguppy+\abysswebserver\abyssws.exe:Abyss Web Server X1
"TCP Query User{15676EF7-640B-4C21-9CC6-488BB2C5ED9E}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{8F7C88E3-3CB5-46F3-A8E0-1D9982730CED}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{234FDEA3-5378-4D05-9D1A-B3CE6D221E9D}c:\\program files\\easyphp\\mysql\\bin\\mysqld-nt.exe"= UDP:c:\program files\easyphp\mysql\bin\mysqld-nt.exe:mysqld-nt
"UDP Query User{2EF69854-C043-4DBF-BA19-CBFFF3F45970}c:\\program files\\easyphp\\mysql\\bin\\mysqld-nt.exe"= TCP:c:\program files\easyphp\mysql\bin\mysqld-nt.exe:mysqld-nt
"TCP Query User{78446F71-0C69-4035-9878-C141EDDE911F}c:\\program files\\easyphp\\apache\\apache.exe"= UDP:c:\program files\easyphp\apache\apache.exe:Apache
"UDP Query User{8CECFA8E-2A3B-4BB4-A9EC-7A13D794E8F1}c:\\program files\\easyphp\\apache\\apache.exe"= TCP:c:\program files\easyphp\apache\apache.exe:Apache
"TCP Query User{C90B1E50-0A7D-4CFA-AC0B-48E6231313DF}c:\\program files\\easyguppy+\\hermes\\hermes.exe"= UDP:c:\program files\easyguppy+\hermes\hermes.exe:Hermes EMail Server
"UDP Query User{CCDCFA53-8B6C-4334-82CB-749320FF65C8}c:\\program files\\easyguppy+\\hermes\\hermes.exe"= TCP:c:\program files\easyguppy+\hermes\hermes.exe:Hermes EMail Server
"TCP Query User{F1263BFB-66C3-46DE-8567-CAD9524463F6}c:\\program files\\easyphp\\mysql\\bin\\mysqld-nt.exe"= UDP:c:\program files\easyphp\mysql\bin\mysqld-nt.exe:mysqld-nt
"UDP Query User{B726A403-CBCC-4C20-91EB-0A62BEBB945F}c:\\program files\\easyphp\\mysql\\bin\\mysqld-nt.exe"= TCP:c:\program files\easyphp\mysql\bin\mysqld-nt.exe:mysqld-nt
"TCP Query User{B3FBF006-75F6-4764-B1C3-0606F7FC1726}c:\\program files\\easyphp\\apache\\apache.exe"= UDP:c:\program files\easyphp\apache\apache.exe:Apache
"UDP Query User{C8E73682-AA2F-43FC-9760-CDAF1B784138}c:\\program files\\easyphp\\apache\\apache.exe"= TCP:c:\program files\easyphp\apache\apache.exe:Apache
"{FE83CCAD-9A93-4969-998B-F22EA64DA84F}"= UDP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{0F6C5D06-208A-4894-B836-D1D87FDB0EB2}"= TCP:c:\program files\Pinnacle\Studio 10\programs\RM.exe:Render Manager
"{E782D0B8-92CE-46E6-8C24-C5AB664C2A71}"= UDP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{3DFC8559-F75B-4051-8A7C-4BA11B49152A}"= TCP:c:\program files\Pinnacle\Studio 10\programs\PMSRegisterFile.exe:PMSRegisterFile
"{CAA2419D-31AE-4026-9381-CA7F6A948B23}"= UDP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"{D705A3DE-4FA0-4B9F-8741-3E4933C46FF6}"= TCP:c:\program files\Pinnacle\Studio 10\programs\umi.exe:umi
"TCP Query User{332EC824-8160-42DC-8660-7210A3431876}c:\\program files\\pinnacle\\shared files\\programs\\mediamanager\\pmsmanager.exe"= UDP:c:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe:MediaManager Application
"UDP Query User{584B609B-A261-4109-AA0F-FD5AEBD9350A}c:\\program files\\pinnacle\\shared files\\programs\\mediamanager\\pmsmanager.exe"= TCP:c:\program files\pinnacle\shared files\programs\mediamanager\pmsmanager.exe:MediaManager Application
"{A7A7CA52-AF48-446F-9708-9F031C776B23}"= UDP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"{69E438DA-04D5-49C3-9FED-BC8385D992C9}"= TCP:c:\program files\Pinnacle\Studio 10\programs\Studio.exe:Studio
"TCP Query User{66D5AF8D-0717-453D-B74B-C96DA6AD1CAE}c:\\program files\\filezilla\\filezilla.exe"= UDP:c:\program files\filezilla\filezilla.exe:FileZilla
"UDP Query User{AAD8766A-1D4D-424E-A2F7-60E424DEE2E9}c:\\program files\\filezilla\\filezilla.exe"= TCP:c:\program files\filezilla\filezilla.exe:FileZilla
"TCP Query User{69E3F8D1-9D8D-4A1B-A408-3DF381E37CBB}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F4292BD8-DA4D-4133-876F-BA5B81AF545E}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{9C744C86-C925-4B62-8869-5D0B750145C6}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{BCC9A147-EE14-424B-B2C9-81A92022C03B}c:\\program files\\turbo torrent\\ttorrent.exe"= UDP:c:\program files\turbo torrent\ttorrent.exe:ttorrent
"UDP Query User{AB68ADA8-E84E-4BB2-83B2-CF77C29D7584}c:\\program files\\turbo torrent\\ttorrent.exe"= TCP:c:\program files\turbo torrent\ttorrent.exe:ttorrent
"TCP Query User{AAFFE296-4AAE-4DF8-A01F-D3F45449129F}c:\\program files\\wyzo\\wyzo.exe"= UDP:c:\program files\wyzo\wyzo.exe:Wyzo
"UDP Query User{E3A1C3A4-86C4-4D0E-BA01-0C1F32EB0BD4}c:\\program files\\wyzo\\wyzo.exe"= TCP:c:\program files\wyzo\wyzo.exe:Wyzo
"TCP Query User{6D315A7F-E9A6-48C0-A397-C200D1F8E0AF}c:\\program files\\wyzo\\wyzo.exe"= UDP:c:\program files\wyzo\wyzo.exe:Wyzo
"UDP Query User{0F2666C6-4305-4526-BD8B-F9C715D2A996}c:\\program files\\wyzo\\wyzo.exe"= TCP:c:\program files\wyzo\wyzo.exe:Wyzo
"TCP Query User{65BB0789-5EA2-45E6-B2C5-22F0393BA9E4}f:\\fscommand\\vividas.exe"= UDP:f:\fscommand\vividas.exe:Vividas Player
"UDP Query User{C6336C46-3112-4160-B92A-81C48D15E3F1}f:\\fscommand\\vividas.exe"= TCP:f:\fscommand\vividas.exe:Vividas Player
"{26506F15-E7D4-4D0A-8561-47B7D23128D2}"= UDP:c:\program files\AOL 9.0\aol.exe:AOL 9.0
"{532B1ABC-CE9E-4561-A487-E1BCF1D32E71}"= TCP:c:\program files\AOL 9.0\aol.exe:AOL 9.0
"{45A668C1-4BC1-423D-AC8E-10F165DE4611}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL - Informations sur le système
"{4E0E5643-0512-4649-9522-7D4B04CE8396}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL - Informations sur le système
"{DA5927FF-B781-437C-B618-C52384905332}"= UDP:c:\program files\TechCity Solutions\AOLSAV\Brain.exe:AOL Auto-diagnostic
"{6180A60B-8E87-4B1E-BA43-A3CBFA9C2F09}"= TCP:c:\program files\TechCity Solutions\AOLSAV\Brain.exe:AOL Auto-diagnostic
"TCP Query User{9FD782F5-8295-4D11-B7B6-079C72845F11}c:\\users\\nathalie\\appdata\\local\\temp\\st_ng_setupwizard\\stinstall.exe"= UDP:c:\users\nathalie\appdata\local\temp\st_ng_setupwizard\stinstall.exe:stinstall.exe
"UDP Query User{A9B80479-C243-4182-996E-CE647C76FAA9}c:\\users\\nathalie\\appdata\\local\\temp\\st_ng_setupwizard\\stinstall.exe"= TCP:c:\users\nathalie\appdata\local\temp\st_ng_setupwizard\stinstall.exe:stinstall.exe
"{6655B008-BECB-4857-934E-694077BF4969}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4D04B72D-958F-473D-B7BD-066F5EAC5008}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{15134A52-6852-41D9-B376-C1AC23F4BD2A}"= UDP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{C21038E0-2708-4E51-B271-3E948F1BF613}"= UDP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{AA1F3696-EBAD-477E-9D03-DB5AD1E07255}"= TCP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{69C234C6-5262-4F83-A41B-68763A62E264}"= TCP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{58E13ECD-08E9-4233-8853-430550B3C2C4}"= UDP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{D71F6AAF-DF12-4DA9-A0A9-2CCB8DEBD767}"= UDP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9F5E29E9-3E08-4F71-90E5-D35A3294593F}"= TCP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{9039B31B-DC5A-432A-9F91-4CC6C0936B60}"= TCP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{AFBE59DA-BF9D-4D64-B266-3BBC6C344F6D}"= UDP:c:\program files\Common Files\AOL\1201426196\ee\aolsoftware.exe:AOL Shared Components
"{CE1E3600-BF5A-4A3C-AF95-22073329996D}"= TCP:c:\program files\Common Files\AOL\1201426196\ee\aolsoftware.exe:AOL Shared Components
"{690ED12D-4FCA-45AE-BD0F-34495A2EDAA1}"= UDP:c:\program files\AOL 9.0 VR\waol.exe:AOL
"{33DC21EC-5965-4379-A05C-9D9A02845DA5}"= TCP:c:\program files\AOL 9.0 VR\waol.exe:AOL
"{1EF4C412-8D57-43FE-9C9E-2FBC449D136B}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{B2AE22C9-1E12-45AD-877A-1ED3E7576E19}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{437F86C7-DA58-4707-AFF7-E76072BE37F2}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{273B0168-3E19-49FC-8141-4FF196F16C8D}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{F5DE8D37-BA8F-4CF5-9044-621A16995FA1}"= UDP:c:\program files\FlashGet\flashget.exe:Flashget
"{3FC0EAFD-B98C-4A0F-B642-90CCDA895AF3}"= TCP:c:\program files\FlashGet\flashget.exe:Flashget
"TCP Query User{074103B7-278A-4B82-B0A3-A501CC81BE4F}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{B8073E78-00C3-4400-8582-31007A249849}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet
"{BFC575A1-6FCE-4564-9828-D10EC3A57C36}"= UDP:c:\program files\Java\jre1.6.0_03\bin\java.exe:java
"{88219BA8-5E9C-441A-B1E3-F831670770BB}"= TCP:c:\program files\Java\jre1.6.0_03\bin\java.exe:java
"TCP Query User{198804FC-4029-46BE-A7B2-7CA34EC91AE6}c:\\program files\\easyphp1-7\\apache\\apache.exe"= UDP:c:\program files\easyphp1-7\apache\apache.exe:apache
"UDP Query User{BDF95F34-71D7-499A-8244-5CC5173CECFD}c:\\program files\\easyphp1-7\\apache\\apache.exe"= TCP:c:\program files\easyphp1-7\apache\apache.exe:apache
"TCP Query User{291171A9-4ECC-4912-B658-E07CBC3CC831}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{F9A9FC54-A9D8-45D1-A93B-CA0EE5A814DB}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"{B20D779A-9A3F-44C8-BED8-661F149B368D}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{512AD055-10DF-4616-A15B-4A0CB212D0F5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{E630C077-22DD-482C-9E96-9565BFD706E3}c:\\program files\\echanblard\\emule.exe"= UDP:c:\program files\echanblard\emule.exe:eMule
"UDP Query User{4B92796C-77B1-4F2D-9602-8701231B89D9}c:\\program files\\echanblard\\emule.exe"= TCP:c:\program files\echanblard\emule.exe:eMule
"TCP Query User{FCF0ACC3-610A-42D8-8CC1-2500247F33FF}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{1B94D5B9-E273-4570-855E-D1AB2101D7F0}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{CAD3B3CF-2515-464C-9C99-E9ABC3E250C9}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{BF6A189B-7A24-4D75-A101-F4A7FC635C1D}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{EE66F7E5-3D41-4776-A579-9AA695E89940}c:\\users\\nathalie\\appdata\\local\\emule\\emule.exe"= UDP:c:\users\nathalie\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{2C0A27AC-C711-4162-9378-61295B2D9171}c:\\users\\nathalie\\appdata\\local\\emule\\emule.exe"= TCP:c:\users\nathalie\appdata\local\emule\emule.exe:emule.exe
"TCP Query User{EB47A0B7-B89D-4F09-85B8-A7E5164ED788}c:\\program files\\gimp-2.0\\lib\\gimp\\2.0\\plug-ins\\script-fu.exe"= UDP:c:\program files\gimp-2.0\lib\gimp\2.0\plug-ins\script-fu.exe:script-fu
"UDP Query User{B3F9154F-BA46-4EBA-A6C9-8D6B800A176A}c:\\program files\\gimp-2.0\\lib\\gimp\\2.0\\plug-ins\\script-fu.exe"= TCP:c:\program files\gimp-2.0\lib\gimp\2.0\plug-ins\script-fu.exe:script-fu
"TCP Query User{8714A1F4-58C3-4D96-8ED1-2CFB4B257814}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{9D63AD89-CD4A-42E6-9782-0C617D226654}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{23695A41-B01E-48BD-87BF-8A5581298988}c:\\program files\\echanblard\\emule.exe"= UDP:c:\program files\echanblard\emule.exe:eMule
"UDP Query User{F92F0619-D65A-4554-8EA7-3AE59CC285CC}c:\\program files\\echanblard\\emule.exe"= TCP:c:\program files\echanblard\emule.exe:eMule
"{2851369F-CA3E-42BD-905B-C9B44701E09B}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{7E4F2EA2-4AA6-4007-B3F3-1EAC42384B99}c:\\wamp\\bin\\apache\\apache2.2.8\\bin\\httpd.exe"= UDP:c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe:Apache HTTP Server
"UDP Query User{B219F9B8-DDB2-4CCA-BBD3-5D764BF4790D}c:\\wamp\\bin\\apache\\apache2.2.8\\bin\\httpd.exe"= TCP:c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe:Apache HTTP Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2008-04-04 111184]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [2006-12-18 7168]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2008-04-04 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2007-04-03 51792]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-12-03 809296]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - IS-NUGQDDRV
*NewlyCreated* - UTIZNJC5
*Deregistered* - utiznjc5
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\shell\AutoRun\command - D:\auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\auto.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{afbb54f2-c2df-11dd-acd8-00038a000015}]
\shell\AutoRun\command - setupSNK.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-17 c:\windows\Tasks\User_Feed_Synchronization-{D9B30BB4-63C0-47D4-A444-A174F9308500}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/ig?hl=fr
IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} -
http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR
c:\windows\Downloaded Program Files\InstallerControl.dll - O16 -: CabBuilder
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
c:\windows\Downloaded Program Files\OSDC5.OSD
FF - ProfilePath - c:\users\Nathalie\AppData\Roaming\Mozilla\Firefox\Profiles\9mju1c94.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - uStart
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/
FF - prefs.js: keyword.URL - http //fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-18 18:36:19
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-18 18:39:39
ComboFix-quarantined-files.txt 2009-01-18 17:39:35
Avant-CF: 20,213,547,008 octets libres
Après-CF: 19,967,655,936 octets libres
296 --- E O F --- 2009-01-16 01:02:18