bonjour,voici le rapport demandé
a+ et bonne fétes
ComboFix 07-12-17.1 - jorandall62 2007-12-21 2:21:40.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1179 [GMT 1:00]
Running from: C:\Users\jorandall62\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-21 to 2007-12-21 ))))))))))))))))))))))))))))))))))))
.
2007-12-20 03:02 . 2007-12-20 03:02 <REP> d-------- C:\Program Files\MSXML 4.0
2007-12-19 00:18 . 2007-12-19 00:18 <REP> d-------- C:\Users\All Users\Ahead
2007-12-19 00:18 . 2007-12-19 00:18 <REP> d-------- C:\ProgramData\Ahead
2007-12-18 14:53 . 2007-12-20 18:40 <REP> d-------- C:\Softpepper files
2007-12-18 14:47 . 2007-12-18 14:47 <REP> d-------- C:\Program Files\SoftPepper
2007-12-18 14:46 . 2007-12-18 14:47 <REP> d-------- C:\Program Files\SoftPepper Video Converter 2.0
2007-12-17 23:36 . 2007-12-17 23:36 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\BSplayer Pro
2007-12-17 23:36 . 2007-12-17 23:42 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\BSplayer
2007-12-17 23:35 . 2007-12-17 23:35 <REP> d-------- C:\Program Files\Webteh
2007-12-17 00:15 . 2007-12-17 00:15 <REP> d-------- C:\Users\All Users\Avira
2007-12-17 00:15 . 2007-12-17 00:15 <REP> d-------- C:\ProgramData\Avira
2007-12-17 00:15 . 2007-12-17 00:15 <REP> d-------- C:\Program Files\Avira
2007-12-15 23:32 . 2007-12-17 22:43 121 --a------ C:\Windows\bdagent.INI
2007-12-15 22:45 . 2007-12-15 22:45 <REP> d-------- C:\Program Files\Trend Micro
2007-12-15 19:31 . 2007-12-15 19:31 <REP> d-------- C:\Users\jorandall62\Nouveau dossierbritney spears
2007-12-15 13:53 . 2007-12-15 13:53 <REP> d-------- C:\Users\All Users\WLInstaller
2007-12-15 13:53 . 2007-12-15 13:53 <REP> d-------- C:\ProgramData\WLInstaller
2007-12-15 00:36 . 2007-12-15 19:22 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\AVSMedia
2007-12-15 00:29 . 2007-02-27 19:36 53,248 --a------ C:\Windows\System32\xvid.ax
2007-12-14 23:48 . 2007-12-14 23:48 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\AVS4YOU
2007-12-14 23:39 . 2007-12-15 00:17 <REP> d-------- C:\Program Files\AVS4YOU
2007-12-14 23:39 . 2007-02-27 19:36 638,976 --a------ C:\Windows\System32\divx.dll
2007-12-14 23:39 . 2007-02-27 19:36 524,288 --a------ C:\Windows\System32\xvidcore.dll
2007-12-14 23:39 . 2007-02-27 19:36 139,264 --a------ C:\Windows\System32\xvidvfw.dll
2007-12-14 23:39 . 2007-02-27 19:36 81,920 --a------ C:\Windows\System32\AC3ACM.acm
2007-12-14 22:41 . 2007-12-14 22:41 138,752 --a------ C:\Windows\System32\drivers\sp_rsdrv2.sys
2007-12-14 22:38 . 2007-12-17 23:33 <REP> d-------- C:\Program Files\WinClamAVShield
2007-12-14 22:33 . 2007-12-14 22:33 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\Application Data
2007-12-14 22:33 . 2007-12-14 22:36 <REP> d-------- C:\Users\All Users\Spyware Terminator
2007-12-14 22:33 . 2007-12-14 22:36 <REP> d-------- C:\ProgramData\Spyware Terminator
2007-12-14 22:33 . 2007-12-17 23:34 <REP> d-------- C:\Program Files\Spyware Terminator
2007-12-14 17:46 . 2007-12-14 17:46 77,824 --a------ C:\Windows\System32\xcomm.dll
2007-12-14 17:32 . 2007-12-17 22:33 <REP> d-------- C:\Users\All Users\WholeSecurity
2007-12-14 17:32 . 2007-12-17 22:33 <REP> d-------- C:\ProgramData\WholeSecurity
2007-12-14 16:43 . 2007-12-14 16:43 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\BitDefender
2007-12-14 16:37 . 2007-12-14 16:42 <REP> d-------- C:\Users\All Users\BitDefender
2007-12-14 16:37 . 2007-12-14 16:42 <REP> d-------- C:\ProgramData\BitDefender
2007-12-14 16:37 . 2007-12-14 16:37 <REP> d-------- C:\Program Files\BitDefender
2007-12-14 16:36 . 2007-12-14 16:38 <REP> d-------- C:\Program Files\Common Files\BitDefender
2007-12-14 14:53 . 2007-12-14 14:53 543,232 --a------ C:\Windows\System32\FWPUCLNT.DLL
2007-12-14 14:53 . 2007-12-14 14:53 416,768 --a------ C:\Windows\System32\IKEEXT.DLL
2007-12-14 14:53 . 2007-12-14 14:53 317,440 --a------ C:\Windows\System32\BFE.DLL
2007-12-14 14:53 . 2007-12-14 14:53 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2007-12-14 14:53 . 2007-12-14 14:53 84,992 --a------ C:\Windows\System32\drivers\FWPKCLNT.SYS
2007-12-14 14:34 . 2007-12-14 14:34 <REP> d-------- C:\Windows\BDOSCAN8
2007-12-14 13:43 . 2007-12-14 14:28 <REP> d-------- C:\Program Files\Panda Security
2007-12-14 00:02 . 2007-01-18 13:00 3,968 --a------ C:\Windows\System32\drivers\AvgArCln.sys
2007-12-13 22:04 . 2007-12-17 22:13 <REP> d-------- C:\Program Files\Navilog1
2007-12-13 17:19 . 2007-12-13 17:19 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\Grisoft
2007-12-13 17:18 . 2007-12-13 17:18 <REP> d-------- C:\Users\All Users\Grisoft
2007-12-13 17:18 . 2007-12-13 17:18 <REP> d-------- C:\ProgramData\Grisoft
2007-12-13 17:18 . 2007-05-30 13:10 10,872 --a------ C:\Windows\System32\drivers\AvgAsCln.sys
2007-12-13 17:13 . 2007-12-13 17:13 <REP> d-------- C:\Program Files\CCleaner
2007-12-13 00:01 . 2007-12-13 00:01 <REP> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-12-12 23:40 . 2007-12-14 00:57 <REP> d-a------ C:\Users\All Users\TEMP
2007-12-12 23:40 . 2007-12-14 00:57 <REP> d-a------ C:\ProgramData\TEMP
2007-12-12 23:39 . 2007-12-12 23:39 <REP> d-------- C:\Users\All Users\PC Tools
2007-12-12 23:39 . 2007-12-12 23:39 <REP> d-------- C:\ProgramData\PC Tools
2007-12-12 22:35 . 2007-12-12 22:35 <REP> d-------- C:\Program Files\Ratajik Software
2007-12-12 22:35 . 2007-12-12 22:36 67 --a------ C:\Windows\StationRipper.INI
2007-12-12 20:33 . 2007-12-12 20:33 <REP> d-------- C:\Program Files\TVAntsX
2007-12-12 17:26 . 2007-10-01 16:24 163,640 --a------ C:\Windows\System32\drivers\ssidrv.sys
2007-12-12 17:26 . 2007-10-01 16:24 23,864 --a------ C:\Windows\System32\drivers\sskbfd.sys
2007-12-12 17:26 . 2007-10-01 16:24 21,816 --a------ C:\Windows\System32\drivers\sshrmd.sys
2007-12-12 17:26 . 2007-10-01 16:24 20,280 --a------ C:\Windows\System32\drivers\SSFS0BB9.sys
2007-12-12 17:25 . 2007-12-12 17:25 <REP> d-------- C:\Users\All Users\Webroot
2007-12-12 17:25 . 2007-12-12 17:25 <REP> d-------- C:\ProgramData\Webroot
2007-12-12 17:25 . 2007-10-01 16:40 1,526,072 --a------ C:\Windows\WRSetup.dll
2007-12-12 17:18 . 2007-12-12 17:43 164 --a------ C:\install.dat
2007-12-12 00:25 . 2007-12-12 00:25 1,327,104 --a------ C:\Windows\System32\quartz.dll
2007-12-12 00:25 . 2007-12-12 00:25 223,232 --a------ C:\Windows\System32\WMASF.DLL
2007-12-12 00:25 . 2007-12-12 00:25 9,728 --a------ C:\Windows\System32\LAPRXY.DLL
2007-12-12 00:25 . 2007-12-12 00:25 2,048 --a------ C:\Windows\System32\asferror.dll
2007-12-12 00:21 . 2007-12-12 00:21 130,048 --a------ C:\Windows\System32\drivers\srv2.sys
2007-12-12 00:21 . 2007-12-12 00:21 101,888 --a------ C:\Windows\System32\drivers\mrxsmb.sys
2007-12-12 00:21 . 2007-12-12 00:21 84,992 --a------ C:\Windows\System32\drivers\srvnet.sys
2007-12-12 00:21 . 2007-12-12 00:21 58,368 --a------ C:\Windows\System32\drivers\mrxsmb20.sys
2007-12-12 00:18 . 2007-12-12 00:18 3,504,824 --a------ C:\Windows\System32\ntkrnlpa.exe
2007-12-12 00:18 . 2007-12-12 00:18 3,470,520 --a------ C:\Windows\System32\ntoskrnl.exe
2007-12-12 00:18 . 2007-12-12 00:18 2,048 --a------ C:\Windows\System32\tzres.dll
2007-12-09 12:24 . 2007-12-09 12:24 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\SopCast
2007-12-09 12:24 . 2007-12-09 12:25 <REP> d-------- C:\Program Files\SopCast
2007-12-09 00:06 . 2007-12-09 00:06 <REP> d-------- C:\Users\jorandall62\AppData\Roaming\eBay
2007-12-08 21:02 . 2007-12-08 21:02 <REP> d-------- C:\Users\All Users\eBay
2007-12-08 21:02 . 2007-12-08 21:02 <REP> d-------- C:\ProgramData\eBay
2007-12-08 21:01 . 2007-12-08 21:01 <REP> d-------- C:\Program Files\eBay
2007-12-01 21:35 . 2007-12-01 21:40 <REP> d-------- C:\Program Files\a-squared Anti-Dialer
2007-12-01 10:23 . 2007-12-05 23:24 <REP> d-------- C:\Program Files\Spyware-Secure
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 01:09 --------- d-----w C:\Program Files\Spyware Doctor
2007-12-19 21:19 --------- d-----w C:\ProgramData\Google Updater
2007-12-18 23:16 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-18 23:12 --------- d-----w C:\ProgramData\Nero
2007-12-17 10:35 --------- d-----w C:\Program Files\Web Hottest Videos Personal Player
2007-12-17 10:25 --------- d-----w C:\Program Files\MultiMedia France Toolbar
2007-12-17 10:06 --------- d-----w C:\Program Files\Common Files\SysDepannage
2007-12-17 09:47 --------- d-----w C:\Program Files\Common Files\MonContenuassistant
2007-12-14 23:30 --------- d-----w C:\Program Files\Common Files\AVSMedia
2007-12-12 07:24 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-12-11 23:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-11 23:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-11 23:23 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-08 20:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-21 18:11 --------- d-----w C:\Program Files\AVSMedia
2007-11-18 22:40 --------- d-----w C:\Users\jorandall62\AppData\Roaming\Webroot
2007-11-18 22:40 --------- d-----w C:\Program Files\Webroot
2007-11-16 11:46 --------- d-----w C:\Program Files\Micro Application
2007-11-16 11:34 36,864 ----a-w C:\Windows\System32\wmdmps.dll
2007-11-16 11:34 311,296 ----a-w C:\Windows\System32\mswmdm.dll
2007-11-16 11:34 31,744 ----a-w C:\Windows\System32\wmdmlog.dll
2007-11-14 00:05 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 00:02 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-14 00:02 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-11-14 00:02 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-11-14 00:02 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-11-14 00:02 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-11-14 00:02 23,040 ----a-w C:\Windows\system32\drivers\usbuhci.sys
2007-11-14 00:02 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-11-14 00:02 192,000 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-11-14 00:01 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-13 11:19 --------- d-----w C:\Users\jorandall62\AppData\Roaming\sysdepannage
2007-11-12 23:42 --------- d-----w C:\Program Files\easyrencontre
2007-11-10 21:40 --------- d-----w C:\Program Files\DivX
2007-11-08 23:41 --------- d-----w C:\Program Files\Common Files\Real
2007-11-08 16:51 --------- d-----w C:\Program Files\Real
2007-11-08 01:21 --------- d-----w C:\Users\jorandall62\AppData\Roaming\Ahead
2007-11-04 09:17 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-04 09:17 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-04 09:17 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-04 09:17 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-04 09:17 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-04 09:17 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-04 09:17 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-04 09:17 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2007-11-04 09:17 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-04 09:17 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-04 09:17 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-01 20:51 --------- d-----w C:\ProgramData\AVS4YOU
2007-10-30 12:50 --------- d-----w C:\Program Files\Picasa2
2007-10-21 21:09 --------- d-----w C:\Program Files\3DO
2007-10-21 21:08 --------- d-----w C:\Program Files\HEAT
2007-10-21 21:01 --------- d-----w C:\Program Files\Mplayer
2007-10-20 00:56 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2007-10-20 00:56 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2007-10-10 09:39 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-10-10 09:39 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-10-10 09:39 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-10-10 09:39 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-10-10 09:33 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-10-10 09:33 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2007-10-10 09:33 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-09-26 22:29 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2007-09-26 22:29 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2007-09-26 22:29 39,936 ----a-w C:\Windows\System32\slcinst.dll
2007-09-26 22:29 351,232 ----a-w C:\Windows\System32\SLUI.exe
2007-09-26 22:29 33,280 ----a-w C:\Windows\System32\slwmi.dll
2007-09-26 22:29 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2007-09-26 22:29 223,232 ----a-w C:\Windows\System32\SLC.dll
2007-09-26 22:29 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2007-09-26 22:29 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2007-09-25 22:05 229,888 ----a-w C:\Windows\System32\msshsq.dll
2007-09-16 16:51 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot@2007-12-17_19.48.59,49 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-17 18:00:51 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2007-12-21 01:11:14 67,584 --s-a-w C:\Windows\bootstat.dat
- 2006-12-10 15:55:04 28,672 ----a-w C:\Windows\ehome\DiscWriter.dll
+ 2007-06-04 09:59:30 34,352 ----a-w C:\Windows\ehome\DiscWriter.dll
- 2006-12-10 15:54:00 24,576 ----a-w C:\Windows\ehome\Interop.NeroMCEWrapper.dll
+ 2007-05-30 09:38:32 24,576 ----a-w C:\Windows\ehome\Interop.NeroMCEWrapper.dll
+ 2007-12-18 23:17:39 25,214 ----a-r C:\Windows\Installer\{7516254D-7F98-49DD-8209-5D2208BD1036}\ARPPRODUCTICON.exe
- 2007-12-12 19:51:56 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-12-17 19:17:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-12 19:51:56 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-17 19:17:10 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-12 19:51:56 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-17 19:17:10 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-12-17 18:02:44 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-21 01:12:52 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-21 01:12:52 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2007-12-17 18:02:39 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-21 01:21:50 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-21 01:21:50 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2007-12-17 15:56:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-12-21 01:11:32 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-17 15:56:06 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-21 01:11:32 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-17 15:56:06 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-21 01:11:32 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2007-12-17 18:43:19 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2007-12-21 01:21:27 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2007-12-21 01:21:27 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2004-07-26 15:16:10 1,568,768 ----a-w C:\Windows\System32\imagX7.dll
+ 2004-07-26 16:16:10 1,568,768 ----a-w C:\Windows\System32\imagX7.dll
- 2004-07-26 15:16:10 476,320 ----a-w C:\Windows\System32\imagXpr7.dll
+ 2004-07-26 16:16:10 476,320 ----a-w C:\Windows\System32\imagXpr7.dll
- 2004-07-26 15:16:10 262,144 ----a-w C:\Windows\System32\imagXR7.dll
+ 2004-07-26 16:16:10 262,144 ----a-w C:\Windows\System32\imagXR7.dll
- 2004-07-26 15:16:10 471,040 ----a-w C:\Windows\System32\imagXRA7.dll
+ 2004-07-26 16:16:10 471,040 ----a-w C:\Windows\System32\imagXRA7.dll
+ 2003-04-18 15:46:22 1,233,920 ----a-w C:\Windows\System32\msxml4.dll
+ 2003-04-18 15:29:26 82,432 ----a-w C:\Windows\System32\msxml4r.dll
+ 2007-08-29 13:14:46 95,600 ----a-w C:\Windows\System32\NeroCo.dll
- 2007-12-14 22:43:58 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
+ 2007-12-18 22:39:21 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
- 2004-07-09 07:43:56 364,544 ----a-w C:\Windows\System32\TwnLib4.dll
+ 2004-07-09 08:43:56 364,544 ----a-w C:\Windows\System32\TwnLib4.dll
- 2007-12-17 18:03:03 10,030 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-641817250-3860369117-549646289-1000_UserData.bin
+ 2007-12-21 01:13:22 10,760 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-641817250-3860369117-549646289-1000_UserData.bin
- 2007-12-17 18:03:03 89,214 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-12-21 01:13:19 89,826 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2007-12-17 18:03:00 47,074 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-12-21 01:13:13 48,130 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-07-14 15:29:44 966,656 ----a-w C:\Windows\UNNeroBackItUp.exe
+ 2007-03-20 20:22:04 972,336 ----a-w C:\Windows\UNNeroBackItUp.exe
- 2006-07-14 15:29:44 966,656 ----a-w C:\Windows\UNNeroMediaHome.exe
+ 2007-06-27 18:05:02 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
- 2006-07-14 15:29:44 966,656 ----a-w C:\Windows\UNNeroShowTime.exe
+ 2007-02-28 15:41:02 972,336 ----a-w C:\Windows\UNNeroShowTime.exe
- 2006-07-14 15:29:44 966,656 ----a-w C:\Windows\UNNeroVision.exe
+ 2007-08-03 13:58:48 972,072 ----a-w C:\Windows\UNNeroVision.exe
- 2006-07-14 15:29:44 966,656 ----a-w C:\Windows\UNRecode.exe
+ 2007-08-03 14:04:08 972,072 ----a-w C:\Windows\UNRecode.exe
+ 2007-12-18 22:23:56 1,233,920 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d\msxml4.dll
+ 2007-12-18 22:23:59 82,432 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\msxml4r.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A}
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{92085AD4-F48A-450D-BD93-B28CC7DF67CE}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}
[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-16 18:37]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 15:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-16 17:43]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-16 18:38]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 16:02]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"NvSvc"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"NvCplDaemon"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"NvMediaCenter"="RUNDLL32.exe" [2006-11-02 10:45 C:\Windows\System32\rundll32.exe]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-04-20 00:17]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2007-10-31 10:51]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2007-12-14 17:47]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-17 00:18]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe" [2007-09-17 10:36]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-04-20 00:17]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-16 18:37:43]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\Windows\system32\Drivers\SSFS0BB9.SYS [2007-10-01 16:24]
R1 bdftdif;bdftdif;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2007-10-19 13:17]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2007-12-14 22:41]
R3 nvlddmkm;nvlddmkm;C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-09-12 04:28]
R3 Ph3xIB32;Philips 713x Inbox PCI TV Card;C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2007-04-03 09:43]
R3 scan;BitDefender Threat Scanner;C:\Windows\System32\svchost.exe -kbdx []
R3 X10Hid;X10 Hid Device;C:\Windows\system32\Drivers\x10hid.sys [2006-11-17 10:31]
S3 3xHybrid;Philips SAA713x PCI Card;C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-01-08 18:43]
S3 bdfsfltr;bdfsfltr;C:\Windows\system32\DRIVERS\bdfsfltr.sys [2007-08-02 16:03]
S3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2007-08-08 13:12]
S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 08:36]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-12-21 01:19:01 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-21 02:24:43
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-21 2:26:36
C:\ComboFix2.txt ... 2007-12-20 21:09
C:\ComboFix3.txt ... 2007-12-17 20:15
.
2007-12-12 07:24:45 --- E O F ---