ComboFix 10-03-18.01 - FullMetalKnet 18/03/2010 22:09:18.1.4 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3327.2574 [GMT 1:00]
Lancé depuis: f:\documents and settings\FullMetalKnet\Bureau\sos.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
f:\windows\system32\_000006_.tmp.dll
f:\windows\system32\_000007_.tmp.dll
f:\windows\system32\_000008_.tmp.dll
f:\windows\system32\_000009_.tmp.dll
f:\windows\system32\_000013_.tmp.dll
f:\windows\system32\_000014_.tmp.dll
f:\windows\system32\_000015_.tmp.dll
f:\windows\system32\_000016_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy__VOIDcimmuicqpc
-------\Legacy__VOIDncbvpuxnqq
-------\Service__VOIDcimmuicqpc
-------\Service__VOIDncbvpuxnqq
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-18 au 2010-03-18 ))))))))))))))))))))))))))))))))))))
.
2010-03-18 20:44 . 2010-03-18 20:50 -------- d-----w- F:\tdsskiller
2010-03-18 20:13 . 2010-03-18 20:13 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Malwarebytes
2010-03-18 20:13 . 2010-01-07 15:07 38224 ----a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2010-03-18 20:13 . 2010-03-18 20:13 -------- d-----w- f:\program files\Malwarebytes' Anti-Malware
2010-03-18 20:13 . 2010-03-18 20:13 -------- d-----w- f:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-18 20:13 . 2010-01-07 15:07 19160 ----a-w- f:\windows\system32\drivers\mbam.sys
2010-03-18 19:24 . 2010-03-18 19:39 -------- d-----w- f:\program files\ZHPDiag
2010-03-18 17:26 . 2008-04-13 10:41 8192 -c--a-w- f:\windows\system32\dllcache\changer.sys
2010-03-18 17:26 . 2008-04-13 10:41 8192 ----a-w- f:\windows\system32\drivers\changer.sys
2010-03-18 17:25 . 2008-04-13 10:40 34688 -c--a-w- f:\windows\system32\dllcache\lbrtfdc.sys
2010-03-18 17:25 . 2008-04-13 10:40 34688 ----a-w- f:\windows\system32\drivers\lbrtfdc.sys
2010-03-18 17:25 . 2008-04-13 10:41 8576 -c--a-w- f:\windows\system32\dllcache\i2omgmt.sys
2010-03-18 17:25 . 2008-04-13 10:41 8576 ----a-w- f:\windows\system32\drivers\i2omgmt.sys
2010-03-18 17:17 . 2010-03-18 17:17 -------- d-----w- f:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-03-18 16:59 . 2010-03-18 20:19 -------- d-----w- f:\documents and settings\FullMetalKnet\Local Settings\Application Data\Windows Server
2010-03-12 21:17 . 2010-03-12 21:17 -------- d-----w- f:\documents and settings\Aline\Local Settings\Application Data\Google
2010-03-08 20:04 . 2010-03-08 20:04 -------- d-----w- f:\program files\Fichiers communs\Logitech
2010-03-08 20:04 . 2010-03-08 20:04 -------- d-----w- f:\documents and settings\FullMetalKnet\Local Settings\Application Data\Downloaded Installations
2010-03-08 20:03 . 2010-03-08 20:03 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Logitech
2010-03-08 20:00 . 2010-03-08 20:00 -------- d-----w- f:\documents and settings\Aline\Application Data\Logitech
2010-03-08 19:59 . 2010-03-08 19:59 53248 ----a-r- f:\documents and settings\Aline\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-03-08 19:59 . 2010-03-08 19:59 -------- d-----w- f:\program files\Common Files
2010-03-08 19:59 . 2010-03-08 19:59 -------- d-----w- f:\documents and settings\Aline\Application Data\Leadertech
2010-03-08 19:58 . 2008-05-02 01:38 301656 ----a-w- f:\windows\system32\BtCoreIf.dll
2010-03-08 19:58 . 2008-05-02 01:40 84496 ----a-w- f:\windows\system32\KemXML.dll
2010-03-08 19:58 . 2008-05-02 01:40 117264 ----a-w- f:\windows\system32\KemWnd.dll
2010-03-08 19:58 . 2008-05-02 01:39 145936 ----a-w- f:\windows\system32\KemUtil.dll
2010-03-08 19:58 . 2008-05-02 01:39 170512 ----a-w- f:\windows\system32\kemutb.dll
2010-03-08 19:58 . 2010-03-08 20:00 -------- d-----w- f:\documents and settings\All Users\Application Data\Logitech
2010-03-08 19:58 . 2010-03-08 19:58 -------- d-----w- f:\program files\Fichiers communs\Logishrd
2010-03-08 19:58 . 2010-03-08 19:58 -------- d-----w- f:\program files\Logitech
2010-03-08 19:58 . 2010-03-08 19:58 -------- d-----w- f:\documents and settings\Aline\Application Data\InstallShield
2010-03-08 19:57 . 2010-03-08 19:57 -------- d-----w- f:\documents and settings\All Users\Application Data\LogiShrd
2010-03-03 12:10 . 2008-04-13 10:45 10624 -c--a-w- f:\windows\system32\dllcache\gameenum.sys
2010-03-03 12:10 . 2008-04-13 10:45 10624 ----a-w- f:\windows\system32\drivers\gameenum.sys
2010-02-25 17:22 . 2010-02-25 17:22 -------- d-----w- f:\program files\Microsoft IntelliPoint
2010-02-25 17:18 . 2010-02-25 17:18 -------- d-----w- f:\program files\Microsoft IntelliType Pro
2010-02-24 10:33 . 2010-02-24 10:33 -------- d-----w- f:\program files\MWSnap
2010-02-23 08:59 . 2010-03-09 11:12 162640 ----a-w- f:\windows\system32\drivers\aswSP.sys
2010-02-23 08:59 . 2010-03-09 11:08 19024 ----a-w- f:\windows\system32\drivers\aswFsBlk.sys
2010-02-23 08:58 . 2010-03-09 11:09 23376 ----a-w- f:\windows\system32\drivers\aswRdr.sys
2010-02-23 08:58 . 2010-03-09 11:12 46672 ----a-w- f:\windows\system32\drivers\aswTdi.sys
2010-02-23 08:58 . 2010-03-09 11:08 100432 ----a-w- f:\windows\system32\drivers\aswmon2.sys
2010-02-23 08:58 . 2010-03-09 11:08 94800 ----a-w- f:\windows\system32\drivers\aswmon.sys
2010-02-23 08:58 . 2010-03-09 11:08 28880 ----a-w- f:\windows\system32\drivers\aavmker4.sys
2010-02-23 08:58 . 2010-03-09 11:24 153184 ----a-w- f:\windows\system32\aswBoot.exe
2010-02-23 08:58 . 2010-02-11 18:53 38848 ----a-w- f:\windows\system32\avastSS.scr
2010-02-23 08:42 . 2010-02-23 08:42 -------- d-----w- f:\documents and settings\Aline\Local Settings\Application Data\PCHealth
2010-02-23 07:52 . 2010-02-23 08:17 -------- d-----w- f:\program files\Windows Sidebar
2010-02-23 07:49 . 2007-10-22 19:20 -------- d-----w- F:\VAIO
2010-02-22 19:24 . 2010-02-22 19:24 -------- d-----w- f:\windows\system32\wbem\Repository
2010-02-22 19:22 . 2010-02-22 19:23 -------- d-s---w- f:\documents and settings\Administrateur.FULLMETAKNET.000
2010-02-22 19:22 . 2010-02-22 19:23 -------- d-----w- f:\documents and settings\Administrateur.FULLMETAKNET.000\Modèles
2010-02-22 19:22 . 2010-02-22 19:23 -------- d-----w- f:\documents and settings\Administrateur.FULLMETAKNET.000\Local Settings\Application Data\Microsoft
2010-02-22 15:39 . 2010-02-22 15:39 -------- d-----w- f:\documents and settings\Aline\Application Data\TeamViewer
2010-02-22 09:53 . 2010-02-22 19:23 -------- d-s---w- f:\documents and settings\Administrateur.FULLMETAKNET
2010-02-22 09:53 . 2010-02-22 19:23 -------- d-----w- f:\documents and settings\Administrateur.FULLMETAKNET\Modèles
2010-02-22 09:53 . 2010-02-22 19:23 -------- d-----w- f:\documents and settings\Administrateur.FULLMETAKNET\Local Settings\Application Data\Microsoft
2010-02-21 19:10 . 2010-02-22 19:24 -------- d-----w- f:\program files\SpeedFan
2010-02-21 18:12 . 2010-02-21 18:12 -------- d-----w- f:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-02-21 18:07 . 2010-03-18 18:18 -------- d-----w- f:\documents and settings\FullMetalKnet\Local Settings\Application Data\Temp
2010-02-21 18:07 . 2010-02-21 18:07 -------- d-----w- f:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-02-21 18:07 . 2010-03-13 21:17 -------- d-----w- f:\documents and settings\FullMetalKnet\Local Settings\Application Data\Google
2010-02-21 18:07 . 2010-03-09 19:50 -------- d-----w- f:\program files\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-18 21:07 . 2010-01-08 20:22 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\HPAppData
2010-03-18 19:18 . 2010-02-07 19:02 -------- d-----w- f:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-18 18:25 . 2010-02-07 19:02 -------- d-----w- f:\program files\Spybot - Search & Destroy
2010-03-18 18:09 . 2010-02-14 19:24 -------- d-----w- f:\program files\Reimage
2010-03-17 21:45 . 2010-01-08 19:39 -------- d-----w- f:\documents and settings\Aline\Application Data\HPAppData
2010-03-15 20:58 . 2010-01-21 23:00 537808 ----a-w- f:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-03-15 19:05 . 2010-01-23 09:16 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\uTorrent
2010-03-13 08:47 . 2010-01-03 18:09 71192 ----a-w- f:\documents and settings\Aline\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-12 22:15 . 2010-01-03 14:22 71192 ----a-w- f:\documents and settings\FullMetalKnet\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-12 18:44 . 2010-02-01 09:44 664 ----a-w- f:\windows\system32\d3d9caps.dat
2010-03-12 18:00 . 2010-01-03 13:57 -------- d-----w- f:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-12 15:12 . 2010-02-09 20:30 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Winamp
2010-03-11 07:17 . 2010-02-15 14:13 64164264 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Nokia\Ovi Suite\Software Updater\NokiaOviSuite2Installer.exe
2010-03-08 19:58 . 2010-03-08 19:58 0 ---ha-w- f:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-03-08 19:58 . 2010-01-03 09:25 -------- d--h--w- f:\program files\InstallShield Installation Information
2010-02-23 13:02 . 2010-02-09 16:02 -------- d-----w- f:\documents and settings\Aline\Application Data\vlc
2010-02-23 08:39 . 2010-02-07 16:41 -------- d-----w- f:\program files\TeamViewer
2010-02-22 10:00 . 2001-08-28 14:00 81386 ----a-w- f:\windows\system32\perfc00C.dat
2010-02-22 10:00 . 2001-08-28 14:00 503210 ----a-w- f:\windows\system32\perfh00C.dat
2010-02-14 15:40 . 2010-01-04 17:41 -------- d-----w- f:\program files\Fichiers communs\Adobe
2010-02-13 10:25 . 2010-02-13 10:24 -------- d-----w- f:\program files\Fichiers communs\Ahead
2010-02-13 10:24 . 2010-02-13 10:24 -------- d-----w- f:\program files\Ahead
2010-02-13 09:08 . 2010-02-13 08:59 -------- d-----w- f:\documents and settings\Aline\Application Data\dvdcss
2010-02-13 09:02 . 2010-02-13 09:00 -------- d-----w- f:\documents and settings\Aline\Application Data\Winamp
2010-02-10 20:47 . 2010-01-03 14:10 -------- d-----w- f:\program files\Alwil Software
2010-02-10 20:44 . 2010-02-10 20:44 -------- d-----w- f:\documents and settings\All Users\Application Data\Alwil Software
2010-02-10 20:32 . 2010-02-10 20:32 -------- d-----w- f:\program files\Driver-Soft
2010-02-10 20:19 . 2010-02-03 17:27 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\vlc
2010-02-10 20:18 . 2010-02-03 17:28 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\dvdcss
2010-02-09 20:30 . 2010-02-09 20:30 -------- d-----w- f:\program files\Winamp
2010-02-09 17:57 . 2010-02-09 17:57 -------- d--h--w- f:\documents and settings\All Users\Application Data\CanonBJ
2010-02-07 17:00 . 2010-02-07 17:00 -------- d-----w- f:\documents and settings\LocalService\Application Data\TeamViewer
2010-02-07 16:58 . 2010-02-07 16:41 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\TeamViewer
2010-02-05 13:03 . 2010-02-04 17:33 -------- d-----w- f:\program files\Nokia
2010-02-04 18:27 . 2010-02-04 17:34 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Nokia
2010-02-04 18:27 . 2010-02-04 17:33 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\PC Suite
2010-02-04 18:26 . 2010-02-04 18:26 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Nokia Ovi Suite
2010-02-04 18:26 . 2010-02-04 18:26 0 ---ha-w- f:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2010-02-04 18:26 . 2010-02-04 18:26 0 ---ha-w- f:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-02-04 18:25 . 2010-02-04 17:34 -------- d-----w- f:\documents and settings\All Users\Application Data\PC Suite
2010-02-04 18:18 . 2010-02-04 18:18 -------- d-----w- f:\documents and settings\All Users\Application Data\Nokia
2010-02-04 18:18 . 2010-02-04 18:18 0 ---ha-w- f:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-02-04 18:18 . 2010-02-04 18:18 0 ---ha-w- f:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-02-04 18:12 . 2010-02-04 18:12 -------- d-----w- f:\program files\Fichiers communs\Nokia
2010-02-04 18:11 . 2010-02-04 18:11 -------- d-----w- f:\program files\PC Connectivity Solution
2010-02-04 18:10 . 2010-02-04 18:10 12212040 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2010-02-04 18:10 . 2010-02-04 18:10 13930312 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2010-02-04 18:10 . 2010-02-04 18:10 61440 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx86.exe
2010-02-04 18:10 . 2010-02-04 18:10 58880 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx64.exe
2010-02-04 18:10 . 2010-02-04 18:10 77824 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2010-02-04 18:10 . 2010-02-04 18:10 50000 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
2010-02-04 18:09 . 2010-02-04 18:09 -------- d-----w- f:\documents and settings\All Users\Application Data\OviInstallerCache
2010-02-04 18:09 . 2010-02-04 18:09 95992424 ----a-w- f:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Nokia_Ovi_Suite_11_update.exe
2010-02-04 18:00 . 2010-02-04 18:00 -------- d-----w- f:\documents and settings\Aline\Application Data\PC Suite
2010-02-04 18:00 . 2010-02-04 18:00 -------- d-----w- f:\documents and settings\Aline\Application Data\Nokia
2010-02-04 17:53 . 2010-02-04 17:53 -------- d-----w- f:\program files\Casio FA-124 FR
2010-02-04 17:51 . 2010-02-04 17:51 -------- d-----w- f:\program files\CASIO
2010-02-04 17:51 . 2010-01-03 09:25 -------- d-----w- f:\program files\Fichiers communs\InstallShield
2010-02-04 17:33 . 2010-02-04 17:33 -------- d-----w- f:\program files\DIFX
2010-02-04 17:31 . 2010-02-04 17:31 -------- d-----w- f:\documents and settings\All Users\Application Data\Installations
2010-02-03 17:27 . 2010-02-03 17:27 -------- d-----w- f:\program files\VideoLAN
2010-01-31 17:55 . 2010-01-31 17:55 503808 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46b9a8cb-n\msvcp71.dll
2010-01-31 17:55 . 2010-01-31 17:55 499712 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46b9a8cb-n\jmc.dll
2010-01-31 17:55 . 2010-01-31 17:55 348160 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46b9a8cb-n\msvcr71.dll
2010-01-31 17:55 . 2010-01-31 17:55 61440 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7c49189c-n\decora-sse.dll
2010-01-31 17:55 . 2010-01-31 17:55 12800 ----a-w- f:\documents and settings\FullMetalKnet\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7c49189c-n\decora-d3d.dll
2010-01-28 07:29 . 2010-01-28 07:29 -------- d-----w- f:\program files\Fichiers communs\Java
2010-01-28 07:29 . 2010-01-28 07:26 411368 ----a-w- f:\windows\system32\deploytk.dll
2010-01-28 07:29 . 2010-01-28 07:29 -------- d-----w- f:\program files\Java
2010-01-28 07:26 . 2010-01-28 07:26 503808 ----a-w- f:\documents and settings\Aline\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5d000f5d-n\msvcp71.dll
2010-01-28 07:26 . 2010-01-28 07:26 499712 ----a-w- f:\documents and settings\Aline\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5d000f5d-n\jmc.dll
2010-01-28 07:26 . 2010-01-28 07:26 348160 ----a-w- f:\documents and settings\Aline\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5d000f5d-n\msvcr71.dll
2010-01-28 07:26 . 2010-01-28 07:26 61440 ----a-w- f:\documents and settings\Aline\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7506f557-n\decora-sse.dll
2010-01-28 07:26 . 2010-01-28 07:26 12800 ----a-w- f:\documents and settings\Aline\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7506f557-n\decora-d3d.dll
2010-01-25 19:11 . 2010-01-25 19:11 -------- d-----w- f:\program files\Defraggler
2010-01-25 19:08 . 2010-01-05 17:20 -------- d-----w- f:\program files\CCleaner
2010-01-25 17:07 . 2010-01-08 19:04 -------- d-----w- f:\program files\HP
2010-01-25 17:07 . 2010-01-10 14:42 -------- d-----w- f:\program files\SpreadsheetConverter
2010-01-23 09:16 . 2010-01-22 19:09 -------- d-----w- f:\program files\uTorrent
2010-01-23 08:11 . 2010-01-23 08:11 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\3M
2010-01-22 19:55 . 2010-01-22 19:07 -------- d-----w- f:\documents and settings\Aline\Application Data\uTorrent
2010-01-22 11:45 . 2010-01-22 11:45 -------- d-----w- f:\documents and settings\Aline\Application Data\3M
2010-01-22 11:45 . 2010-01-22 11:45 -------- d-----w- f:\program files\3M
2010-01-20 19:07 . 2010-01-06 16:07 -------- d-----w- f:\documents and settings\All Users\Application Data\Messenger Plus!
2010-01-20 16:57 . 2010-01-05 17:15 -------- d-----w- f:\program files\Messenger Plus! Live
2010-01-18 17:41 . 2010-01-18 17:41 -------- d-----w- f:\documents and settings\Aline\Application Data\Wallpaper
2010-01-18 17:19 . 2010-01-18 17:19 -------- d-----w- f:\program files\WBFS
2010-01-18 17:17 . 2010-01-03 14:00 -------- d-----w- f:\program files\MSBuild
2010-01-18 17:17 . 2010-01-18 17:17 -------- d-----w- f:\program files\Reference Assemblies
2010-01-18 17:09 . 2010-01-18 17:08 -------- d-----w- f:\documents and settings\FullMetalKnet\Application Data\Wallpaper
2010-01-18 17:08 . 2010-01-18 17:08 -------- d-----w- f:\program files\Wallpaper
2010-01-08 19:13 . 2010-01-08 19:03 219353 ----a-w- f:\windows\hpoins46.dat
2010-01-04 11:25 . 2009-12-31 17:21 86331 ----a-w- f:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-03 14:25 . 2010-01-03 14:25 0 ----a-w- f:\windows\nsreg.dat
2009-12-31 17:19 . 2009-12-31 17:19 21892 ----a-w- f:\windows\system32\emptyregdb.dat
2009-12-31 16:50 . 2008-04-13 10:15 353792 ----a-w- f:\windows\system32\drivers\srv.sys
2009-12-22 05:09 . 2008-04-13 17:33 671232 ----a-w- f:\windows\system32\wininet.dll
2009-12-22 05:08 . 2008-04-13 17:33 81920 ----a-w- f:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="f:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"msnmsgr"="f:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Wallpaper"="f:\program files\Wallpaper\Wallpaper.exe" [2007-08-20 233472]
"NokiaOviSuite2"="f:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2009-12-10 401728]
"SpybotSD TeaTimer"="f:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="f:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer" [X]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2008-06-26 13574144]
"nwiz"="nwiz.exe" [2008-06-26 1657376]
"NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2008-06-26 86016]
"HP Software Update"="f:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="f:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-01-11 246504]
"WinampAgent"="f:\program files\Winamp\winampa.exe" [2010-01-13 37888]
"RTHDCPL"="RTHDCPL.EXE" [2009-12-10 18789920]
"avast5"="f:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
"itype"="f:\program files\Microsoft IntelliType Pro\itype.exe" [2006-11-22 813912]
"IntelliPoint"="f:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
f:\documents and settings\Aline\Menu D‚marrer\Programmes\D‚marrage\
Logitech . Enregistrement du produit.lnk - f:\program files\Common Files\LogiShrd\eReg\Common\eReg.exe [2009-4-8 517384]
f:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - f:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
Logitech SetPoint.lnk - f:\program files\Logitech\SetPoint\SetPoint.exe [2010-3-8 805392]
Post-it© Software Notes Lite.lnk - f:\program files\3M\PSNLite\PsnLite.exe [2004-10-15 2080768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 ----a-w- f:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- f:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- f:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 09:50 155648 ----a-w- f:\windows\system32\NeroCheck.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Données\\eMule0.49b\\emule.exe"=
"f:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"f:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"f:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"f:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"f:\\Program Files\\Messenger\\msmsgs.exe"=
"f:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"f:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"f:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
R1 aswSP;aswSP;f:\windows\system32\drivers\aswSP.sys [23/02/2010 09:59 162640]
R2 aswFsBlk;aswFsBlk;f:\windows\system32\drivers\aswFsBlk.sys [23/02/2010 09:59 19024]
R2 TeamViewer5;TeamViewer 5;f:\program files\TeamViewer\Version5\TeamViewer_Service.exe [11/02/2010 12:42 172328]
S2 gupdate;Service Google Update (gupdate);f:\program files\Google\Update\GoogleUpdate.exe [21/02/2010 19:07 135664]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\g:\ntglm7x.sys --> g:\NTGLM7X.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2010-03-18 f:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- f:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 18:07]
2010-03-18 f:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- f:\program files\Google\Update\GoogleUpdate.exe [2010-02-21 18:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: E&xporter vers Microsoft Excel - f:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - f:\documents and settings\FullMetalKnet\Application Data\Mozilla\Firefox\Profiles\jgvghi9u.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSeymour.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - plugin: f:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: f:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: f:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: f:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - f:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
f:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
f:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
f:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "
http://www.firefox.com");
f:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
f:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="F?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(688)
f:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
f:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'Explorer.EXE'(124)
f:\windows\system32\eappprxy.dll
f:\windows\system32\WPDShServiceObj.dll
f:\windows\system32\PortableDeviceTypes.dll
f:\windows\system32\PortableDeviceApi.dll
f:\program files\Logitech\SetPoint\lgscroll.dll
f:\program files\Logitech\SetPoint\GameHook.dll
.
------------------------ Autres processus actifs ------------------------
.
f:\program files\Alwil Software\Avast5\AvastSvc.exe
f:\program files\Java\jre6\bin\jqs.exe
f:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
f:\windows\system32\nvsvc32.exe
f:\program files\TeamViewer\Version5\TeamViewer.exe
f:\windows\system32\RUNDLL32.EXE
f:\program files\Fichiers communs\Nokia\MPlatform\NokiaMServer.exe
f:\windows\RTHDCPL.EXE
f:\windows\Mixer.exe
f:\program files\Microsoft IntelliPoint\dpupdchk.exe
f:\progra~1\3M\PSNLite\PSNGive.exe
f:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
f:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
f:\program files\HP\Digital Imaging\bin\hpqbam08.exe
f:\program files\Fichiers communs\Nokia\NoA\nokiaaserver.exe
f:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
f:\program files\PC Connectivity Solution\ServiceLayer.exe
f:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
f:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Heure de fin: 2010-03-18 22:15:21 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-03-18 21:15
Avant-CF: 13 448 908 800 octets libres
Après-CF: 13 657 382 912 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(1)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(1)partition(3)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 1658627DA9DFA7918A97CFB0DC9DEE95
sans maitrise la puissance n'est rien!!!