ComboFix 11-11-01.03 - leydier 01/11/2011 17:02:43.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.660 [GMT 1:00]
Lancé depuis: c:\trombofix.exe\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\leydier\Bureau\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\documents and settings\leydier\Local Settings\Application Data\9cfd3235"
"c:\windows\system32\drivers\abokrjcj.sys"
"c:\windows\system32\drivers\ahzjbiec.sys"
"c:\windows\system32\drivers\ajcvqnrd.sys"
"c:\windows\system32\drivers\atmyfxoq.sys"
"c:\windows\system32\drivers\attlqhft.sys"
"c:\windows\system32\drivers\avvncbdn.sys"
"c:\windows\system32\drivers\bgjwvcap.sys"
"c:\windows\system32\drivers\bkfcizrv.sys"
"c:\windows\system32\drivers\bmbicibu.sys"
"c:\windows\system32\drivers\booeotiy.sys"
"c:\windows\system32\drivers\cikhmcix.sys"
"c:\windows\system32\drivers\cpzbsdyx.sys"
"c:\windows\system32\drivers\dciefels.sys"
"c:\windows\system32\drivers\dweyjqhh.sys"
"c:\windows\system32\drivers\dyhzzxfo.sys"
"c:\windows\system32\drivers\dyvrmaqx.sys"
"c:\windows\system32\drivers\edbjgmue.sys"
"c:\windows\system32\drivers\egscnlxa.sys"
"c:\windows\system32\drivers\ehfrluce.sys"
"c:\windows\system32\drivers\ejmsstux.sys"
"c:\windows\system32\drivers\eqspzxer.sys"
"c:\windows\system32\drivers\etydbbhb.sys"
"c:\windows\system32\drivers\ffoehtlw.sys"
"c:\windows\system32\drivers\fhkxmcqr.sys"
"c:\windows\system32\drivers\fllsvcuu.sys"
"c:\windows\system32\drivers\fuostfjq.sys"
"c:\windows\system32\drivers\futivxky.sys"
"c:\windows\system32\drivers\gbdgpvmp.sys"
"c:\windows\system32\drivers\gixhodhe.sys"
"c:\windows\system32\drivers\hrxbwvyq.sys"
"c:\windows\system32\drivers\htiyosgw.sys"
"c:\windows\system32\drivers\htppitnx.sys"
"c:\windows\system32\drivers\hvojtjsi.sys"
"c:\windows\system32\drivers\hxgsrnvb.sys"
"c:\windows\system32\drivers\ilupgdrf.sys"
"c:\windows\system32\drivers\ivokjffn.sys"
"c:\windows\system32\drivers\iwgbvuzz.sys"
"c:\windows\system32\drivers\jpjxgegu.sys"
"c:\windows\system32\drivers\jqlmmxmo.sys"
"c:\windows\system32\drivers\jtgloxjd.sys"
"c:\windows\system32\drivers\kezqjzwv.sys"
"c:\windows\system32\drivers\kgdlugom.sys"
"c:\windows\system32\drivers\kqphnpxx.sys"
"c:\windows\system32\drivers\lbbmnnck.sys"
"c:\windows\system32\drivers\lvznunwm.sys"
"c:\windows\system32\drivers\mebcuenk.sys"
"c:\windows\system32\drivers\mgqncrvd.sys"
"c:\windows\system32\drivers\mnpizyay.sys"
"c:\windows\system32\drivers\mqhiexdl.sys"
"c:\windows\system32\drivers\nnzmxxfr.sys"
"c:\windows\system32\drivers\nujliuxs.sys"
"c:\windows\system32\drivers\obcrrjka.sys"
"c:\windows\system32\drivers\pilomcls.sys"
"c:\windows\system32\drivers\pnsvathj.sys"
"c:\windows\system32\drivers\qtaqjlpz.sys"
"c:\windows\system32\drivers\rdvcwgbs.sys"
"c:\windows\system32\drivers\rlyubqzs.sys"
"c:\windows\system32\drivers\rotlldti.sys"
"c:\windows\system32\drivers\rypadabf.sys"
"c:\windows\system32\drivers\sdtgbmjp.sys"
"c:\windows\system32\drivers\sjrrmkgb.sys"
"c:\windows\system32\drivers\slimmnwe.sys"
"c:\windows\system32\drivers\sormzzom.sys"
"c:\windows\system32\drivers\tiuwbccl.sys"
"c:\windows\system32\drivers\tzmdahfe.sys"
"c:\windows\system32\drivers\uajicieq.sys"
"c:\windows\system32\drivers\ubqielxa.sys"
"c:\windows\system32\drivers\unxnybcn.sys"
"c:\windows\system32\drivers\uobzuams.sys"
"c:\windows\system32\drivers\uolngeap.sys"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\leydier\Application Data\Toolbar4
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\156783.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\arrow_refresh.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\basis.xml
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\cache\ded0070427585a10b47dc38c30725f43
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\cog.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\computer_delete.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\descargar3.exe
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\favicon.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\games01.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\go_btn.png
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\icons.bmp
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\include_files\5563cef889bfa801bacf546650741142
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\include_files\a28fb005e91cf194594645214b0c743e
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\include_files\d218065c7312190b4bd44f226e0ddcb3
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\include_files\ed27fb3bbcc1f40fbf99c2f6a3664931
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\info.txt
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\logo.gif
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\stations.js
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\TbHelper2.exe
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\uninstall.exe
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\uninstaller.exe
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\update.exe
c:\documents and settings\leydier\Application Data\Toolbar4\8FFA7469-654F-423E-84FE-6A583CB1C284\version.txt
c:\program files\RechercherWeb Toolbar
c:\program files\RechercherWeb Toolbar\156783.png
c:\program files\RechercherWeb Toolbar\arrow_refresh.png
c:\program files\RechercherWeb Toolbar\basis.xml
c:\program files\RechercherWeb Toolbar\cog.png
c:\program files\RechercherWeb Toolbar\computer_delete.png
c:\program files\RechercherWeb Toolbar\descargar3.exe
c:\program files\RechercherWeb Toolbar\favicon.png
c:\program files\RechercherWeb Toolbar\games01.png
c:\program files\RechercherWeb Toolbar\go_btn.png
c:\program files\RechercherWeb Toolbar\icons.bmp
c:\program files\RechercherWeb Toolbar\info.txt
c:\program files\RechercherWeb Toolbar\logo.gif
c:\program files\RechercherWeb Toolbar\stations.js
c:\program files\RechercherWeb Toolbar\TbCommonUtils.dll
c:\program files\RechercherWeb Toolbar\tbcore3.dll
c:\program files\RechercherWeb Toolbar\tbhelper.dll
c:\program files\RechercherWeb Toolbar\TbHelper2.exe
c:\program files\RechercherWeb Toolbar\toolbar1.dll
c:\program files\RechercherWeb Toolbar\uninstall.exe
c:\program files\RechercherWeb Toolbar\uninstaller.exe
c:\program files\RechercherWeb Toolbar\update.exe
c:\program files\RechercherWeb Toolbar\version.txt
c:\windows\system32\
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_abokrjcj
-------\Service_ahzjbiec
-------\Service_ajcvqnrd
-------\Service_atmyfxoq
-------\Service_attlqhft
-------\Service_avvncbdn
-------\Service_bgjwvcap
-------\Service_bkfcizrv
-------\Service_bmbicibu
-------\Service_booeotiy
-------\Service_cikhmcix
-------\Service_cpzbsdyx
-------\Service_dciefels
-------\Service_dweyjqhh
-------\Service_dyhzzxfo
-------\Service_dyvrmaqx
-------\Service_edbjgmue
-------\Service_egscnlxa
-------\Service_ehfrluce
-------\Service_ejmsstux
-------\Service_eqspzxer
-------\Service_etydbbhb
-------\Service_ffoehtlw
-------\Service_fhkxmcqr
-------\Service_fllsvcuu
-------\Service_fuostfjq
-------\Service_futivxky
-------\Service_gbdgpvmp
-------\Service_gixhodhe
-------\Service_hrxbwvyq
-------\Service_htiyosgw
-------\Service_htppitnx
-------\Service_hvojtjsi
-------\Service_hxgsrnvb
-------\Service_ilupgdrf
-------\Service_ivokjffn
-------\Service_iwgbvuzz
-------\Service_jpjxgegu
-------\Service_jqlmmxmo
-------\Service_jtgloxjd
-------\Service_kezqjzwv
-------\Service_kgdlugom
-------\Service_kqphnpxx
-------\Service_lbbmnnck
-------\Service_lvznunwm
-------\Service_mebcuenk
-------\Service_mgqncrvd
-------\Service_mnpizyay
-------\Service_mqhiexdl
-------\Service_nnzmxxfr
-------\Service_nujliuxs
-------\Service_obcrrjka
-------\Service_pilomcls
-------\Service_pnsvathj
-------\Service_qtaqjlpz
-------\Service_rdvcwgbs
-------\Service_rlyubqzs
-------\Service_rotlldti
-------\Service_rypadabf
-------\Service_sdtgbmjp
-------\Service_sjrrmkgb
-------\Service_slimmnwe
-------\Service_sormzzom
-------\Service_tiuwbccl
-------\Service_tzmdahfe
-------\Service_uajicieq
-------\Service_ubqielxa
-------\Service_unxnybcn
-------\Service_uobzuams
-------\Service_uolngeap
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-10-01 au 2011-11-01 ))))))))))))))))))))))))))))))))))))
.
.
2011-11-01 16:19 . 2011-11-01 16:19 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\MpKsldf1d4841.sys
2011-11-01 15:58 . 2011-11-01 16:00 -------- d-----w- C:\TROMBOFIX.EXE
2011-11-01 00:57 . 2011-11-01 00:57 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\MpKsledea8767.sys
2011-11-01 00:56 . 2011-11-01 16:19 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\offreg.dll
2011-10-31 23:25 . 2011-10-31 23:27 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2011-10-31 22:42 . 2011-10-31 22:42 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-10-31 22:27 . 2011-10-31 22:42 -------- d-----w- C:\ZHP
2011-10-31 22:26 . 2011-10-31 22:42 -------- d-----w- c:\program files\ZHPDiag
2011-10-31 16:54 . 2011-10-31 16:54 41680 ----a-w- c:\windows\system32\drivers\qwuehfge.sys
2011-10-31 16:39 . 2011-10-31 16:39 41680 ----a-w- c:\windows\system32\drivers\odjevbjh.sys
2011-10-31 16:24 . 2011-10-31 16:24 41680 ----a-w- c:\windows\system32\drivers\tckgqnfx.sys
2011-10-31 16:09 . 2011-10-31 16:09 41680 ----a-w- c:\windows\system32\drivers\twcslgee.sys
2011-10-31 15:55 . 2011-10-06 19:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\mpengine.dll
2011-10-31 15:55 . 2011-10-31 15:55 41680 ----a-w- c:\windows\system32\drivers\vtdpnnjx.sys
2011-10-31 15:09 . 2011-10-31 15:09 -------- d-----w- c:\documents and settings\leydier\Local Settings\Application Data\FixItCenter
2011-10-31 14:48 . 2011-10-31 14:48 -------- d-----w- c:\windows\MATS
2011-10-31 14:48 . 2011-10-31 14:48 -------- d-----w- c:\program files\Microsoft Fix it Center
2011-10-31 14:43 . 2011-10-31 14:43 -------- d-----w- c:\documents and settings\leydier\Application Data\ElevatedDiagnostics
2011-10-31 13:10 . 2011-10-31 13:25 11368 ----a-w- C:\FixitRegBackup.reg
2011-10-30 14:43 . 2011-10-30 14:43 -------- d-----w- c:\windows\system32\wbem\Repository
2011-10-30 12:56 . 2011-10-30 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}(2)
2011-10-30 12:37 . 2011-10-30 12:37 -------- d-----w- c:\documents and settings\leydier\Application Data\TuneUp Software
2011-10-30 12:37 . 2011-10-30 14:41 -------- d-----w- c:\program files\TuneUp Utilities 2011
2011-10-30 12:36 . 2011-10-30 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2011-10-30 12:08 . 2011-10-30 12:08 -------- d-----w- c:\documents and settings\leydier\Application Data\Uniblue
2011-10-29 22:17 . 2011-10-30 14:42 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-29 21:32 . 2011-10-31 22:42 -------- d-sh--w- c:\documents and settings\leydier\Local Settings\Application Data\9cfd3235
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-06 19:48 . 2011-07-10 08:03 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-26 09:41 . 2011-09-26 09:41 614400 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 09:41 . 1979-12-31 23:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 09:41 . 1979-12-31 23:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 1979-12-31 23:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 1979-12-31 23:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-09-02 06:22 . 2011-06-21 06:18 404640 -c--a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-17 21:24 . 1979-12-31 23:00 832512 ----a-w- c:\windows\system32\wininet.dll
2011-08-17 21:24 . 1979-12-31 23:00 1830912 ------w- c:\windows\system32\inetcpl.cpl
2011-08-17 21:24 . 2010-12-28 09:15 78336 ------w- c:\windows\system32\ieencode.dll
2011-08-17 21:24 . 1979-12-31 23:00 17408 ----a-w- c:\windows\system32\corpol.dll
2011-08-17 13:49 . 1979-12-31 23:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-17 12:22 . 2010-12-28 09:15 389120 ------w- c:\windows\system32\html.iec
2011-08-12 11:51 . 2010-12-28 10:54 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2001-10-25 15:14 . 2010-12-21 14:23 372736 -c--a-w- c:\program files\Super_PR.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-01_00.59.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-01 01:06 . 2011-11-01 01:06 18944 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\f9f6ed920c3f3d419a2c2ca689ee74cf\Microsoft.PowerShell.Security.resources.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 31744 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ea08066566f0fa46bc79ed28d0fea9ef\Microsoft.PowerShell.Commands.Utility.resources.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 37376 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\c39024e478399b41b97bd5ed061d6dcb\Microsoft.PowerShell.ConsoleHost.resources.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 20992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\5ac9fb729c8c0a47bb6009f11691e77d\Microsoft.PowerShell.Commands.Management.resources.ni.dll
+ 2011-11-01 01:05 . 2011-11-01 01:05 81920 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\94414d43c583824f8c0cab50021717ad\Microsoft.Build.Framework.ni.dll
+ 2011-11-01 01:05 . 2011-11-01 01:05 15360 c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\7cf819c35cb15a41a7d72ec60fd30b51\dfsvc.ni.exe
+ 2011-11-01 01:04 . 2011-11-01 01:04 26624 c:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\785099e0752d364d876506db119ad7e5\Accessibility.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1C.tmp\System.Transactions.dll
+ 2011-11-01 01:24 . 2011-11-01 01:24 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\eca7663c94d03d4c90c8b820235a6ec2\System.Web.RegularExpressions.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\a144e4bdc3569642ac59e0344fe8766b\System.Security.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 184320 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\d1dd020f38eaf74fb02c597905bc4847\System.Management.Automation.resources.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\7bb22a8afa9adc4281f33be8ac6c5229\System.EnterpriseServices.Wrapper.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\7bb22a8afa9adc4281f33be8ac6c5229\System.EnterpriseServices.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\09ae7b1538b88e4eaa29d91721bd85c3\System.DirectoryServices.Protocols.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 962560 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\3283d7cd97d0394ea4e37d0ad6c1082a\System.Configuration.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 524288 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\eeab8760adcca94fb3b50468e7b4866a\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 552960 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\91ef5ebd3b228243aded3b7841b2890a\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 176128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\07e1ae01db71a34a94ee1ee9e05777e9\Microsoft.PowerShell.Security.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\aa497155dac68e468a2c3f1f3fbd51bf\Microsoft.Build.Utilities.ni.dll
+ 2011-11-01 01:05 . 2011-11-01 01:05 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\59267e45eaec314ea322f39f5c7b7834\Microsoft.Build.Engine.ni.dll
+ 2011-11-01 01:05 . 2011-11-01 01:05 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\660f691655dcb5478c641b1a2349c16c\CustomMarshalers.ni.dll
+ 2011-11-01 01:05 . 2011-11-01 01:05 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\19f432bc74d65540b4810e634af1b6b5\AspNetMMCExt.ni.dll
+ 2011-11-01 01:24 . 2011-11-01 01:24 1945600 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP20.tmp\System.Web.Services.dll
+ 2011-11-01 01:24 . 2011-11-01 01:24 2310144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\8c47c56d21d87b4faa778d21f9a0fc5c\System.Web.Mobile.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 5271552 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\44ba66180535a349b2f1ae77c1b1b6cd\System.Management.Automation.ni.dll
+ 2011-11-01 01:22 . 2011-11-01 01:22 1220608 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ae6259926f88144abb75c831d52b8396\System.DirectoryServices.ni.dll
+ 2011-11-01 01:07 . 2011-11-01 01:07 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\ae92eca9129986408131ae25ace532ea\System.Deployment.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 1724416 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\598720969af2de428426ccbf82ebbead\Microsoft.VisualBasic.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 1069056 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9bc5904fe86152478012894d53309a18\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2011-11-01 01:06 . 2011-11-01 01:06 1691648 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\8070dba44d29ee4090d231b264a378af\Microsoft.Build.Tasks.ni.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
2011-06-10 06:24 165256 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Connexion SFR 9props.exe"="c:\program files\SFR\Kit\9props.exe" [2011-06-10 959880]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-25 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^PC Clone EX.LNK]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\PC Clone EX.LNK
backup=c:\windows\pss\PC Clone EX.LNKCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-05 17:04 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2010-10-27 17:17 207424 -c--a-w- c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
2001-09-15 00:15 245760 ----a-w- c:\windows\system32\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
2001-08-24 08:40 35328 -c--a-w- c:\progra~1\MOUSEW~1\system\EM_EXEC.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
2010-01-18 17:27 139944 ----a-w- c:\program files\Lexmark S300-S400 Series\ezprint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxeamon.exe]
2010-01-18 17:27 770728 -c--a-w- c:\program files\Lexmark S300-S400 Series\lxeamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSC]
2011-06-15 13:16 997920 ----a-w- c:\program files\Microsoft Security Client\msseces.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 15:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2011-04-22 12:21 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TomTomHOMEService"=2 (0x2)
"lxea_device"=2 (0x2)
"lxeaCATSCustConnectService"=2 (0x2)
"ACDaemon"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\lxeacoms.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\scan\\scanman6.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Adobe\\Reader 10.0\\Reader\\AcroRd32.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Fichiers communs\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\Program Files\\Microsoft Fix it Center\\MatsWiz.exe"=
"c:\\Program Files\\Microsoft Fix it Center\\FixitCenter1st.exe"=
"c:\\Program Files\\Microsoft Fix it Center\\FixitCenter.exe"=
"c:\\Program Files\\CCleaner\\CCleaner.exe"=
"c:\\Program Files\\SFR\\Kit\\9launch.exe"=
"c:\\Program Files\\ZHPDiag\\ZHPDiag.exe"=
.
R1 FNETURPX;FNETURPX;c:\windows\system32\drivers\FNETURPX.SYS [19/12/2010 14:26 7040]
R1 MpKsldf1d4841;MpKsldf1d4841;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\MpKsldf1d4841.sys [01/11/2011 17:19 28752]
R1 MpKsledea8767;MpKsledea8767;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2EEABEE5-AB1A-4775-8672-18CBD5E57D52}\MpKsledea8767.sys [01/11/2011 01:57 28752]
R3 CVIAAUD;NEC VIA 3D Environmental Audio;c:\windows\system32\drivers\cviaaud.sys [01/01/1980 320864]
R3 CVIAHALA;CVIAHALA;c:\windows\system32\drivers\cviahal.sys [01/01/1980 214688]
R3 PxHelper;PxHelper;c:\windows\system32\drivers\PxHelper.sys [19/12/2010 12:17 15776]
S1 MpKsl01167cd6;MpKsl01167cd6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{047EBC34-A7BC-493A-817C-A4CD4426A7EA}\MpKsl01167cd6.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{047EBC34-A7BC-493A-817C-A4CD4426A7EA}\MpKsl01167cd6.sys [?]
S1 MpKsl0e16056f;MpKsl0e16056f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6E7BED0D-7738-4DDC-B2AC-B5DB95995737}\MpKsl0e16056f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{6E7BED0D-7738-4DDC-B2AC-B5DB95995737}\MpKsl0e16056f.sys [?]
S1 MpKsl15a74f0b;MpKsl15a74f0b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C804D43E-1277-4E84-8A48-3B2827FCEC42}\MpKsl15a74f0b.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C804D43E-1277-4E84-8A48-3B2827FCEC42}\MpKsl15a74f0b.sys [?]
S1 MpKsl1a422d4f;MpKsl1a422d4f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B9A4682C-4F5D-44EB-B468-8739F8C120FA}\MpKsl1a422d4f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B9A4682C-4F5D-44EB-B468-8739F8C120FA}\MpKsl1a422d4f.sys [?]
S1 MpKsl1bfbfc32;MpKsl1bfbfc32;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F60AAE2B-AC6B-4E47-9E1A-195ED50749DC}\MpKsl1bfbfc32.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F60AAE2B-AC6B-4E47-9E1A-195ED50749DC}\MpKsl1bfbfc32.sys [?]
S1 MpKsl2c9fb12f;MpKsl2c9fb12f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A83E1A8B-4886-4693-A8EC-D323A3B0E250}\MpKsl2c9fb12f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A83E1A8B-4886-4693-A8EC-D323A3B0E250}\MpKsl2c9fb12f.sys [?]
S1 MpKsl307e05bc;MpKsl307e05bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68A16570-9BE3-4A3E-869E-2A8DB83AB516}\MpKsl307e05bc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{68A16570-9BE3-4A3E-869E-2A8DB83AB516}\MpKsl307e05bc.sys [?]
S1 MpKsl39b772c2;MpKsl39b772c2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{353E8CA6-C5F2-4F72-8D8D-06F2B429ECB3}\MpKsl39b772c2.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{353E8CA6-C5F2-4F72-8D8D-06F2B429ECB3}\MpKsl39b772c2.sys [?]
S1 MpKsl53841977;MpKsl53841977;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BE7B5757-43A8-410A-9393-D3BD7A9B3862}\MpKsl53841977.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BE7B5757-43A8-410A-9393-D3BD7A9B3862}\MpKsl53841977.sys [?]
S1 MpKsl68035b7c;MpKsl68035b7c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D36E30A-605A-4CB1-8DDE-11465C57C274}\MpKsl68035b7c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{3D36E30A-605A-4CB1-8DDE-11465C57C274}\MpKsl68035b7c.sys [?]
S1 MpKsl6c8c5fba;MpKsl6c8c5fba;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EBEB62D-C684-4068-BBA6-7BF34577C267}\MpKsl6c8c5fba.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7EBEB62D-C684-4068-BBA6-7BF34577C267}\MpKsl6c8c5fba.sys [?]
S1 MpKsl7e3cac6d;MpKsl7e3cac6d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{482F684A-4B14-40FD-B48B-D28C42CF4E89}\MpKsl7e3cac6d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{482F684A-4B14-40FD-B48B-D28C42CF4E89}\MpKsl7e3cac6d.sys [?]
S1 MpKsl8478db31;MpKsl8478db31;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4ADC9FB8-0633-4A89-96E8-D065CDF04FA8}\MpKsl8478db31.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4ADC9FB8-0633-4A89-96E8-D065CDF04FA8}\MpKsl8478db31.sys [?]
S1 MpKsl8f34221f;MpKsl8f34221f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D00B33A8-2010-47E0-AE88-4608E8070937}\MpKsl8f34221f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D00B33A8-2010-47E0-AE88-4608E8070937}\MpKsl8f34221f.sys [?]
S1 MpKsl8fbb6121;MpKsl8fbb6121;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{55DB2C13-43A4-45A7-BBBB-893A5020F818}\MpKsl8fbb6121.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{55DB2C13-43A4-45A7-BBBB-893A5020F818}\MpKsl8fbb6121.sys [?]
S1 MpKsl98b7b3f0;MpKsl98b7b3f0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AE9AE752-E286-4525-9BAA-3342F8C5ECD5}\MpKsl98b7b3f0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AE9AE752-E286-4525-9BAA-3342F8C5ECD5}\MpKsl98b7b3f0.sys [?]
S1 MpKslc340bc73;MpKslc340bc73;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{84D3DC1C-1D20-476D-9D9B-9BA06841B6DD}\MpKslc340bc73.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{84D3DC1C-1D20-476D-9D9B-9BA06841B6DD}\MpKslc340bc73.sys [?]
S1 MpKsld4fd4d25;MpKsld4fd4d25;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{047EBC34-A7BC-493A-817C-A4CD4426A7EA}\MpKsld4fd4d25.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{047EBC34-A7BC-493A-817C-A4CD4426A7EA}\MpKsld4fd4d25.sys [?]
S1 MpKslf7f9de36;MpKslf7f9de36;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C0D6660-FA85-49F7-AA61-8855DDF81F6A}\MpKslf7f9de36.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7C0D6660-FA85-49F7-AA61-8855DDF81F6A}\MpKslf7f9de36.sys [?]
S1 MpKslfcb37bf8;MpKslfcb37bf8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{86D7DFF5-8AF1-4CE6-9894-DB62A2D407F4}\MpKslfcb37bf8.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{86D7DFF5-8AF1-4CE6-9894-DB62A2D407F4}\MpKslfcb37bf8.sys [?]
S1 mplmvswf;mplmvswf;\??\c:\windows\system32\drivers\mplmvswf.sys --> c:\windows\system32\drivers\mplmvswf.sys [?]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [13/06/2011 22:09 267568]
S3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [01/11/2011 00:25 111872]
S4 lxea_device;lxea_device;c:\windows\system32\lxeacoms.exe -service --> c:\windows\system32\lxeacoms.exe -service [?]
S4 lxeaCATSCustConnectService;lxeaCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxeaserv.exe [10/07/2011 09:39 91240]
S4 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [22/04/2011 13:21 92592]
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - MPKSLDF1D4841
.
Contenu du dossier 'Tâches planifiées'
.
2011-11-01 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 21:09]
.
2011-10-31 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2011-06-13 21:09]
.
2011-11-01 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-03-16 15:50]
.
2011-11-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2010-12-19 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2010-12-19 02:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
mStart Page = hxxp://wwwmywebsites.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-{8FFA7469-654F-423E-84FE-6A583CB1C284} - c:\program files\RechercherWeb Toolbar\tbcore3.dll
WebBrowser-{8FFA7469-654F-423E-84FE-6A583CB1C284} - c:\program files\RechercherWeb Toolbar\tbcore3.dll
AddRemove-RechercherWeb Toolbar - c:\program files\RechercherWeb Toolbar\uninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-01 17:20
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(3056)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
.
**************************************************************************
.
Heure de fin: 2011-11-01 17:27:47 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-11-01 16:27
ComboFix2.txt 2011-11-01 01:08
.
Avant-CF: 19 612 540 928 octets libres
Après-CF: 19 583 737 856 octets libres
.
- - End Of File - - 334500788A038E1D5D1234DE476A45C0