ComboFix 09-06-15.03 - uyar 15/06/2009 23:21.1 - NTFSx86 NETWORK
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.2046.1621 [GMT 2:00]
Lancé depuis: c:\documents and settings\uyar\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\uyar\Bureau\CFScript.txt
AV: Antivirus BitDefender *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Pare-feu BitDefender *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
"C:\gunyrg.exe"
"c:\windows\dxp18989.dat"
"c:\windows\system32\perfc00C.dat"
"c:\windows\system32\perfh00C.dat"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\gunyrg.exe
c:\windows\dxp18989.dat
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-15 au 2009-06-15 ))))))))))))))))))))))))))))))))))))
.
2009-06-15 11:38 . 2009-06-15 11:40 -------- d-----w- C:\Lop SD
2009-06-15 11:06 . 2009-06-15 11:06 -------- d-----w- c:\windows\ERUNT
2009-06-15 08:42 . 2009-02-09 10:20 685056 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\_entreelist.dll
2009-06-15 08:42 . 2009-02-09 10:20 739840 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\_enviewlist.dll
2009-06-15 08:42 . 2009-06-15 08:42 79 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_5AE0493B2787E784FA51FC02BD6DF5B1.dll
2009-06-15 08:42 . 2009-06-15 08:42 3402 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0BE8D84D6CFFB324CB21CF08092EB725.dll
2009-06-15 08:42 . 2009-06-15 08:42 27 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_6BBFDF96D153C8B4988D68D79C0D2A4A.dll
2009-06-15 08:42 . 2009-06-15 08:42 215 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_CEDD6D12CC88FA34DBC844DEF5525D3D.dll
2009-06-15 08:42 . 2009-06-15 08:42 10 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0DC1503A46F231838AD88BCDDC8E8F7C.dll
2009-06-15 08:42 . 2009-06-15 08:42 634 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0AD2CD36C6A283C429947B3559546875.dll
2009-06-15 08:42 . 2009-06-15 08:42 833 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_000021599B0090400000000000F01FEC.dll
2009-06-15 08:42 . 2009-06-15 08:42 41 ----a-w- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_096825A1D2A65CB41B34C8A48E1DD969.dll
2009-06-15 08:42 . 2009-06-15 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-06-15 08:42 . 2009-06-15 08:42 -------- d-----w- c:\program files\Security Task Manager
2009-06-14 21:23 . 2009-06-14 21:25 -------- d-----w- c:\documents and settings\uyar\SmitfraudFix
2009-06-14 18:30 . 2009-06-14 18:32 -------- d-----w- c:\documents and settings\uyar\DoctorWeb
2009-06-14 18:17 . 2009-06-14 18:17 -------- d-----w- c:\documents and settings\uyar\Application Data\Malwarebytes
2009-06-14 18:17 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 18:17 . 2009-06-14 18:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-14 18:17 . 2009-06-14 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-14 18:17 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 18:01 . 2009-06-14 18:01 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-06-14 17:59 . 2009-06-14 17:59 -------- dc----w- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-14 17:31 . 2009-06-14 17:31 -------- d-----w- C:\sh4ldr
2009-06-14 17:30 . 2009-06-14 17:31 6853096 ----a-w- C:\SpyHunter-Compact-OS.exe
2009-06-14 17:30 . 2009-06-14 17:30 -------- d-----w- c:\program files\Enigma Software Group
2009-06-14 17:14 . 2009-06-14 17:14 -------- d-----w- C:\GenProc
2009-06-14 10:04 . 2009-06-14 18:19 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-14 10:04 . 2009-06-14 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-14 08:33 . 2009-06-14 08:33 -------- d-----w- c:\documents and settings\Administrateur\Application Data\BitDefender
2009-06-13 15:58 . 2009-06-13 16:03 -------- d-----w- c:\program files\PhotoFiltre Studio
2009-06-13 14:58 . 2009-06-13 14:58 161862 ----a-r- c:\documents and settings\uyar\Application Data\Microsoft\Installer\{21D6DDEC-88CC-43AF-BD8C-44ED5F25D5D3}\_C6380A4D79A855C6E96072.exe
2009-06-13 14:58 . 2009-06-13 14:58 161862 ----a-r- c:\documents and settings\uyar\Application Data\Microsoft\Installer\{21D6DDEC-88CC-43AF-BD8C-44ED5F25D5D3}\_BC2645D60F872811451D1F.exe
2009-06-13 14:58 . 2009-06-13 14:58 -------- d-----w- c:\program files\Tronics
2009-06-12 20:49 . 2008-10-18 12:48 -------- d--h--w- c:\documents and settings\All Users\lib
2009-06-12 20:45 . 2009-06-12 20:45 -------- d-----w- c:\program files\MauZ Php Editor
2009-06-10 15:39 . 2009-06-10 15:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-10 15:39 . 2009-06-10 15:54 -------- d-----w- c:\program files\Nsasoft
2009-06-10 14:51 . 2009-06-10 14:58 -------- d-----w- c:\program files\Cheatbook Database 2009
2009-06-10 11:33 . 2009-06-13 08:28 -------- d-----w- c:\program files\Empire of Sports
2009-06-07 18:55 . 2009-06-07 18:55 25512 ----a-w- c:\windows\system32\drivers\ggsemc.sys
2009-06-07 18:55 . 2009-06-07 18:55 13224 ----a-w- c:\windows\system32\drivers\ggflt.sys
2009-06-04 17:41 . 2008-03-21 11:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-06-03 22:04 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-06-03 22:04 . 2009-06-03 22:04 -------- d-----w- c:\windows\system32\fr-FR
2009-06-03 22:01 . 2009-06-03 22:04 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-03 22:01 . 2009-06-03 22:01 -------- d-----w- c:\program files\MSBuild
2009-06-03 22:00 . 2009-06-03 22:00 -------- d-----w- c:\program files\Reference Assemblies
2009-06-03 22:00 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-03 22:00 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-03 22:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-03 22:00 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-03 22:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-03 22:00 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-03 22:00 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-03 22:00 . 2009-06-03 22:00 -------- d-----w- C:\89df2e162e3b59b058b2
2009-06-03 21:58 . 2009-06-03 21:58 -------- d-----w- c:\program files\MSXML 6.0
2009-05-31 22:51 . 2009-05-31 22:51 10134 ----a-r- c:\documents and settings\uyar\Application Data\Microsoft\Installer\{B3940EA5-7872-487E-AF15-CF20DBD65F1B}\_8ECC23A7EE16983412592E.exe
2009-05-31 22:51 . 2009-05-31 22:51 10134 ----a-r- c:\documents and settings\uyar\Application Data\Microsoft\Installer\{B3940EA5-7872-487E-AF15-CF20DBD65F1B}\_2E6FA81F66FC2982781BC3.exe
2009-05-31 22:51 . 2009-05-31 22:51 -------- d-----w- c:\program files\Bits N Bytes
2009-05-29 21:50 . 2009-06-13 15:01 -------- d-----w- c:\documents and settings\uyar\Local Settings\Application Data\assembly
2009-05-28 20:04 . 2009-05-28 20:04 -------- d-----w- c:\documents and settings\All Users\Application Data\RoboForm
2009-05-28 18:49 . 2009-05-28 18:49 -------- d-----w- c:\program files\Trend Micro
2009-05-26 15:46 . 2009-05-26 15:46 -------- d-----w- c:\documents and settings\uyar\Local Settings\Application Data\F4
2009-05-25 20:21 . 2009-05-25 20:36 -------- d-----w- c:\program files\Null Logics Software
2009-05-25 20:08 . 2009-05-25 20:36 -------- d-----w- c:\program files\MSN Password Recovery
2009-05-25 19:30 . 2009-05-25 19:30 -------- d-----w- C:\Pass Revelator
2009-05-25 13:54 . 2009-05-25 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-05-25 11:21 . 2009-05-25 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\F4
2009-05-25 11:18 . 2009-05-25 11:22 -------- d-----w- c:\documents and settings\uyar\Application Data\F4
2009-05-23 16:40 . 2009-06-10 18:18 -------- d-----w- c:\program files\Windows Live Safety Center
2009-05-23 10:40 . 2009-05-23 10:40 -------- d-----w- c:\program files\Fichiers communs\Logitech
2009-05-20 10:48 . 2009-05-20 10:48 -------- d-----w- c:\windows\Sun
2009-05-19 19:07 . 2009-05-19 19:06 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-19 19:06 . 2009-05-19 19:06 -------- d-----w- c:\program files\Java
2009-05-19 19:06 . 2009-05-19 19:06 152576 ----a-w- c:\documents and settings\uyar\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-18 12:25 . 2009-05-18 12:25 -------- d-----w- c:\documents and settings\uyar\Application Data\Généatique2009
2009-05-18 12:24 . 2006-01-30 07:32 5632 ----a-w- c:\windows\system32\pxc25pm.dll
2009-05-18 12:24 . 2004-12-07 05:11 258352 ----a-w- c:\windows\system32\unicows.dll
2009-05-18 12:24 . 2009-05-18 12:24 -------- d-----w- c:\program files\Tracker Software
2009-05-17 08:51 . 2005-02-14 07:57 32768 ----a-w- c:\documents and settings\All Users\Application Data\Sony Ericsson\Sony Ericsson PC Suite\LiveUpdate\Temp\CleanBuild.exe
2009-05-17 08:49 . 2009-05-17 08:49 -------- d-----w- c:\documents and settings\uyar\Local Settings\Application Data\Sony Ericsson
2009-05-17 08:48 . 2009-05-17 08:50 -------- d-----w- c:\program files\Avanquest update
2009-05-17 08:48 . 2009-05-17 08:48 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-14 16:32 . 2009-05-12 17:13 81984 ----a-w- c:\windows\system32\bdod.bin
2009-06-08 18:51 . 2009-06-08 18:51 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-06-04 17:41 . 2009-06-04 17:41 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01007.Wdf
2009-06-04 17:41 . 2009-06-04 17:41 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-06-04 07:24 . 2009-05-12 16:16 14864 ----a-w- c:\documents and settings\uyar\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-03 14:38 . 2009-05-12 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\BitDefender
2009-05-30 06:53 . 2009-05-12 16:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-23 18:51 . 2009-05-12 15:53 86815 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-23 13:22 . 2009-05-12 17:15 -------- d-----w- c:\program files\Logitech
2009-05-17 08:47 . 2009-05-17 08:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-05-17 08:47 . 2009-05-13 13:46 -------- d-----w- c:\program files\Sony Ericsson
2009-05-14 10:24 . 2009-05-12 18:37 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-13 23:56 . 2009-05-13 23:56 -------- d-----w- c:\program files\MSXML 4.0
2009-05-13 20:06 . 2009-05-13 19:58 -------- d-----w- c:\documents and settings\uyar\Application Data\PhotoFiltre Studio X
2009-05-13 19:56 . 2009-05-13 19:56 -------- d-----w- c:\program files\PhotoFiltre Studio X
2009-05-13 19:16 . 2009-05-12 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-05-13 14:31 . 2009-05-13 14:31 0 ----a-w- c:\windows\nsreg.dat
2009-05-13 11:48 . 2009-05-12 21:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-12 21:26 . 2009-05-12 21:01 -------- d-----w- c:\program files\Messenger Plus! Live
2009-05-12 21:12 . 2009-05-12 19:09 826856 ----a-w- c:\documents and settings\uyar\Application Data\MSNInstaller\msnauins.exe
2009-05-12 19:09 . 2009-05-12 19:09 -------- d-----w- c:\documents and settings\uyar\Application Data\MSNInstaller
2009-05-12 18:39 . 2009-05-12 18:39 50 ----a-w- c:\windows\system32\bridf08b.dat
2009-05-12 18:39 . 2009-05-12 18:39 -------- d-----w- c:\program files\Brother
2009-05-12 18:39 . 2009-05-12 18:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Brother
2009-05-12 18:39 . 2009-05-12 18:39 -------- d-----w- c:\documents and settings\uyar\Application Data\InstallShield
2009-05-12 18:37 . 2009-05-12 18:36 -------- d-----w- c:\program files\Windows Live
2009-05-12 18:37 . 2009-05-12 18:37 -------- d-----w- c:\program files\Microsoft
2009-05-12 18:37 . 2009-05-12 18:37 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-12 18:32 . 2009-05-12 18:32 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-05-12 18:05 . 2009-05-12 17:36 -------- d-----w- c:\program files\NOS
2009-05-12 18:05 . 2009-05-12 17:36 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-05-12 17:48 . 2009-05-12 16:22 -------- d--ha-w- c:\documents and settings\All Users\Application Data\GTek
2009-05-12 17:47 . 2009-05-12 17:47 -------- d-----w- c:\program files\7-Zip
2009-05-12 17:39 . 2009-05-12 17:39 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-05-12 17:33 . 2009-05-12 17:33 1915520 ----a-w- c:\documents and settings\uyar\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-05-12 17:32 . 2009-05-12 16:27 -------- d-----w- c:\program files\X10 Hardware
2009-05-12 17:30 . 2009-05-12 16:09 -------- d-----w- c:\program files\Intel
2009-05-12 17:15 . 2009-05-12 17:15 -------- d-----w- c:\documents and settings\uyar\Application Data\Leadertech
2009-05-12 17:15 . 2009-05-12 17:10 -------- d-----w- c:\program files\Fichiers communs\logishrd
2009-05-12 17:15 . 2009-05-12 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-05-12 17:10 . 2009-05-12 17:10 -------- d-----w- c:\documents and settings\All Users\Application Data\X10 Settings
2009-05-12 16:49 . 2009-05-12 16:49 -------- d-----w- c:\documents and settings\uyar\Application Data\BitDefender
2009-05-12 16:49 . 2009-05-12 16:48 -------- d-----w- c:\program files\BitDefender
2009-05-12 16:49 . 2009-05-12 16:48 -------- d-----w- c:\program files\Fichiers communs\BitDefender
2009-05-12 16:41 . 2009-05-12 16:41 -------- d-----w- c:\program files\FreeBot
2009-05-12 16:38 . 2009-05-12 16:38 -------- d-----w- c:\program files\Free
2009-05-12 16:34 . 2009-05-12 16:34 -------- d-----w- c:\documents and settings\LocalService\Application Data\X10 Commander
2009-05-12 16:28 . 2009-05-12 16:28 -------- d-----w- c:\program files\Realtek
2009-05-12 16:28 . 2009-05-12 16:13 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2009-05-12 16:27 . 2009-05-12 16:27 -------- d-----w- c:\program files\Common Files
2009-05-12 16:22 . 2009-05-12 16:22 -------- d--h--w- c:\documents and settings\uyar\Application Data\GTek
2009-05-12 16:22 . 2009-05-12 16:22 29184 ----a-w- c:\windows\system32\drivers\goprot51.sys
2009-05-12 16:22 . 2009-05-12 16:22 -------- d-----w- c:\program files\Fichiers communs\Intel
2009-05-12 16:16 . 2009-05-12 16:16 -------- d-----w- c:\documents and settings\uyar\Application Data\ATI
2009-05-12 16:14 . 2009-05-12 16:13 -------- d-----w- c:\program files\ATI Technologies
2009-05-12 15:59 . 2009-05-12 15:59 127 ----a-w- c:\documents and settings\uyar\Local Settings\Application Data\fusioncache.dat
2009-05-12 15:54 . 2009-05-12 15:54 -------- d-----w- c:\program files\microsoft frontpage
2009-05-12 15:53 . 2009-05-12 15:53 -------- d-----w- c:\program files\Services en ligne
2009-05-12 15:51 . 2009-05-12 15:51 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2009-05-12 15:50 . 2009-05-12 15:50 -------- d-----w- c:\program files\Windows Plus
2009-05-07 15:43 . 2006-03-24 12:00 347136 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 13:51 . 2009-05-06 13:51 478904 ----a-w- c:\documents and settings\All Users\Application Data\F4\EoS-Launcher.exe
2009-04-29 04:31 . 2006-03-24 12:00 672256 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:31 . 2006-03-24 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:09 . 2006-03-24 12:00 1846784 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:17 . 2006-03-24 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-08 12:29 . 2009-04-08 12:29 56448 ----a-w- c:\windows\system32\drivers\xusb21.sys
2009-04-06 16:17 . 2009-04-06 16:17 21200 ----a-w- c:\documents and settings\All Users\Application Data\F4\IHelper.exe
2009-03-05 16:08 . 2009-05-14 10:25 49664 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\89df2e162e3b59b058b2 ----
2009-06-03 22:00 . 2008-06-19 05:33 72 ------w- c:\89df2e162e3b59b058b2\amd64\msxpsinc.ppd
2009-06-03 22:00 . 2008-06-19 05:33 2204 ------w- c:\89df2e162e3b59b058b2\i386\msxpsdrv.inf
2009-06-03 22:00 . 2008-06-19 09:03 73 ------w- c:\89df2e162e3b59b058b2\i386\msxpsinc.gpd
2009-06-03 22:00 . 2008-06-19 05:33 72 ------w- c:\89df2e162e3b59b058b2\i386\msxpsinc.ppd
2009-06-03 22:00 . 2008-06-19 05:33 2204 ------w- c:\89df2e162e3b59b058b2\amd64\msxpsdrv.inf
2009-06-03 22:00 . 2008-07-06 12:06 10929 ------w- c:\89df2e162e3b59b058b2\amd64\msxpsdrv.cat
2009-06-03 22:00 . 2008-07-06 12:06 10929 ------w- c:\89df2e162e3b59b058b2\i386\msxpsdrv.cat
2009-06-03 22:00 . 2008-07-06 12:06 147456 ------w- c:\89df2e162e3b59b058b2\amd64\filterpipelineprintproc.dll
2009-06-03 22:00 . 2008-07-06 12:06 89088 ------w- c:\89df2e162e3b59b058b2\i386\filterpipelineprintproc.dll
2009-06-03 22:00 . 2008-07-06 12:06 765440 ------w- c:\89df2e162e3b59b058b2\i386\mxdwdrv.dll
2009-06-03 22:00 . 2008-07-06 12:06 1676288 ------w- c:\89df2e162e3b59b058b2\i386\xpssvcs.dll
2009-06-03 22:00 . 2008-07-06 12:06 748032 ------w- c:\89df2e162e3b59b058b2\amd64\mxdwdrv.dll
2008-07-06 15:36 . 2008-07-06 15:36 2936832 ------w- c:\89df2e162e3b59b058b2\amd64\xpssvcs.dll
2008-06-19 09:03 . 2008-06-19 09:03 73 ------w- c:\89df2e162e3b59b058b2\amd64\msxpsinc.gpd
---- Directory of C:\sh4ldr ----
2009-06-14 17:31 . 2009-03-27 15:16 55296 ----a-w- c:\sh4ldr\installutil.exe
2009-06-14 17:31 . 2009-04-03 14:21 80384 ----a-w- c:\sh4ldr\shospostremover.exe
2009-06-14 17:31 . 2009-01-26 12:20 1654800 ----a-w- c:\sh4ldr\vmlinuz
2009-06-14 17:31 . 2009-04-02 16:02 185833 ----a-w- c:\sh4ldr\shldr
2009-06-14 17:31 . 2009-03-30 12:49 4802039 ----a-w- c:\sh4ldr\initrd.gz
2009-06-14 17:31 . 2009-06-14 17:31 1413 ----a-w- c:\sh4ldr\unins000.dat
2009-06-14 17:31 . 2009-06-14 17:31 695578 ----a-w- c:\sh4ldr\unins000.exe
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-24 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2006-07-10 303104]
"NMSSupport"="c:\program files\Fichiers communs\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-03-29 375296]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-03-19 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-02-23 69632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"BVRPLiveUpdate"="c:\program files\Avanquest update\Engine\Setup.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-19 148888]
"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-04-02 868352]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-11-17 17676288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-24 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"DisableLocalUserRun"= 1 (0x1)
"DisableLocalUserRunOnce"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisableLocalUserRun"= 1 (0x1)
"DisableLocalUserRunOnce"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^uyar^Menu Démarrer^Programmes^Démarrage^FreeBot.lnk]
path=c:\documents and settings\uyar\Menu Démarrer\Programmes\Démarrage\FreeBot.lnk
backup=c:\windows\pss\FreeBot.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^uyar^Menu Démarrer^Programmes^Démarrage^Logitech . Enregistrement du produit.lnk]
path=c:\documents and settings\uyar\Menu Démarrer\Programmes\Démarrage\Logitech . Enregistrement du produit.lnk
backup=c:\windows\pss\Logitech . Enregistrement du produit.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\Empire of Sports\\NetworkDiagnostic.exe"=
"c:\\Program Files\\Empire of Sports\\EmpireOfSports.exe"=
"c:\\Documents and Settings\\uyar\\Local Settings\\Application Data\\F4\\ClientUpdater\\ClientUpdater.exe"=
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [12/02/2009 16:52 104328]
S2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [06/10/2008 18:16 82696]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [20/01/2009 19:16 172032]
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [18/09/2008 12:09 111112]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [07/06/2009 20:55 13224]
S3 s3017bus;Sony Ericsson Device 3017 driver (WDM);c:\windows\system32\drivers\s3017bus.sys [17/05/2009 10:47 83880]
S3 s3017mdfl;Sony Ericsson Device 3017 USB WMC Modem Filter;c:\windows\system32\drivers\s3017mdfl.sys [17/05/2009 10:47 15016]
S3 s3017mdm;Sony Ericsson Device 3017 USB WMC Modem Driver;c:\windows\system32\drivers\s3017mdm.sys [17/05/2009 10:47 110632]
S3 s3017mgmt;Sony Ericsson Device 3017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s3017mgmt.sys [17/05/2009 10:47 104616]
S3 s3017nd5;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (NDIS);c:\windows\system32\drivers\s3017nd5.sys [17/05/2009 10:47 25512]
S3 s3017obex;Sony Ericsson Device 3017 USB WMC OBEX Interface;c:\windows\system32\drivers\s3017obex.sys [17/05/2009 10:47 100648]
S3 s3017unic;Sony Ericsson Device 3017 USB Ethernet Emulation SEMC3017 (WDM);c:\windows\system32\drivers\s3017unic.sys [17/05/2009 10:47 110120]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.com/
mStart Page =
hxxp://www.cooxer.com/
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-15 23:23
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1940)
c:\windows\system32\msi.dll
.
Heure de fin: 2009-06-15 23:25 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-15 21:25
ComboFix2.txt 2009-06-15 09:01
Avant-CF: 293 187 264 512 octets libres
Après-CF: 293 199 638 528 octets libres
296 --- E O F --- 2009-06-10 22:12