voila le raport et une petit question voila jai brancher les clée usb et mon disc dur externe a mon petit pc ya til un risque pour lui?(il marche tre bien pour linstant^^ et jespére que sa va continuer^^
)
voila le raport
ComboFix 09-06-13.01 - user 13/06/2009 20:23.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.626 [GMT 2:00]
Lancé depuis: c:\documents and settings\user\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\user\Bureau\CFscriptB.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\system32\GameMon.des"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\GamesBar
c:\program files\Boonty
c:\program files\BoontyGames
c:\documents and settings\All Users\Application Data\GamesBar\onload\loading.gif
c:\program files\BoontyGames\Components\Joystick.ico
c:\program files\BoontyGames\Components\start.url
c:\program files\BoontyGames\Cradle of Rome\bass.dll
c:\program files\BoontyGames\Cradle of Rome\Config.xml
c:\program files\BoontyGames\Cradle of Rome\CradleOfRome.exe
c:\program files\BoontyGames\Cradle of Rome\Fenetre.bmp
c:\program files\BoontyGames\Cradle of Rome\fenetrepop.bmp
c:\program files\BoontyGames\Cradle of Rome\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Cradle of Rome\Hiscores.xml
c:\program files\BoontyGames\Cradle of Rome\log.html
c:\program files\BoontyGames\Cradle of Rome\Music\menu.ogg
c:\program files\BoontyGames\Cradle of Rome\Music\track_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Music\track_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Music\track_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Profiles.xml
c:\program files\BoontyGames\Cradle of Rome\res.pak
c:\program files\BoontyGames\Cradle of Rome\Save\JMP.xml
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\~pleasewait.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\buy_connectionrequired.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\connectionrequired.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_br.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_de.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_en.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_fr.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_it.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_nb.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_nl.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_po.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_sp.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\css\ShellStyle_us.css
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\FLEXnet Activation Service Installer.dll
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bg_nomjeu.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bg_table.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgDELOCK.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgDELOCK_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgERROR.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgERROR_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgERROR_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgERROR_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgERROR_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgOK.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgOK_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgOK_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgOK_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgOK_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgREDUC.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgREDUC_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgREDUC_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgREDUC_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgREDUC_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSECURE.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSECURE_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSECURE_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSECURE_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSECURE_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSUPPORT.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Coin.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\bkgSUPPORT_Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBkg.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottomLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottomLeftC.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottomLeftCN.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottomLeftCR.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocBottomRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocCoinCadenas.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocError.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocExpiredTop.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocJouezMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocJouezTop.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocTop.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocTopLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\blocTopRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\boontysecure.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Bottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomLeftEast.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomLeftNorth.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomRightNorth.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BottomRightWest.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btAcheterLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btAcheterMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btAcheterRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtBlueLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtBlueMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtBlueRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btJouerLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btJouerMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btJouerRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_acheter.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_fermer.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_infos.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_jouer.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_nomjeu2.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_reactiver.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_reduc.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_suivant.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\btn_suivant2.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtnBuyExit.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtYellowLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtYellowMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtYellowQuestion.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\BtYellowRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_Off.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgLeft_On.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_Off.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgMiddle_On.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_Off.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\ButtonBkgRight_On.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\CacheImgJeu.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\caddie.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\cadenas.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\CloseOff.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\CloseOn.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\fleche.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\flechetrial.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\greypoint.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\jeu.jpg
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\jouer_gratuitement.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Left.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\MaximizeOff.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\MaximizeOn.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\MinimizeOff.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\MinimizeOn.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopBottom.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopBottomLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopBottomRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopTop.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopTopLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\PopTopRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Right.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\scroll.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\scroll_bkg.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\separator2.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\separatorEnd.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\separatorMiddle.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\separatorStart.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Shell_popup_03.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Shell_popup_06.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Shell_popup_08.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Shell_popup_09.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\spacer.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\test.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\Top.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\TopLeft.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\TopLeftSouth.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\TopRight.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\TopRightWest.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\transp.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\Images\wait.gif
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\js\ShellScripts.js
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\manualtransaction.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\pageerror.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\pleasewait.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\repairstart.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\thankyou.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\transfailure.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\trialexit.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\trialexpired.html
c:\program files\BoontyGames\Cradle of Rome\SHELL_DEFAULT_HTML\trialstart.html
c:\program files\BoontyGames\Cradle of Rome\Sound\arrow_use_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\bmb_use_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\bn_activate_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\bn_cancel_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\bn_select_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\congratulations_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_built.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_built_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_built_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_built_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_select_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\constr_select_error_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\end_level_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\episode_complete_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\field_over_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\field_start_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\hm_use_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\int_btn_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\int_btn_down.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\int_label_counter_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\int_nag_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\int_panel_open.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead_bonus_04.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead_empty_04.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead_food_04.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead_gold_04.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_dead_stuff_04.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_mismatch_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_move_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_select_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_01_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_02_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_03_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_04_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_05_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_06_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_07_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\it_tonal_signal_08_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\lck_dead_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\light_use_02.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\lives_down.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\lives_up.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\mix_use_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\panel_down.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\panel_up.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\people_hint.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\plus_use_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\pzl_cell_dead.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\salut_blow_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\salut_fly_01.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\str_use_03.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\time_left.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\time_warning.ogg
c:\program files\BoontyGames\Cradle of Rome\Sound\tm_use.ogg
c:\program files\BoontyGames\Cradle of Rome\SpMU.lnk
c:\program files\BoontyGames\Cradle of Rome\trial.ini
c:\program files\BoontyGames\Cradle of Rome\unins000.dat
c:\program files\BoontyGames\Cradle of Rome\unins000.exe
c:\program files\BoontyGames\cradleofrome{305166}.exe
c:\windows\system32\GameMon.des
H:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IMSPCLOJ
-------\Service_iMSPCLOj
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-13 au 2009-06-13 ))))))))))))))))))))))))))))))))))))
.
2009-06-13 18:20 . 2009-06-13 18:20 -------- d-----w- C:\pouet
2009-06-13 15:29 . 2009-06-13 15:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-13 15:07 . 2009-05-26 11:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-13 15:07 . 2009-06-13 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-13 15:07 . 2009-05-26 11:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 18:02 . 2009-06-12 18:02 -------- d-----w- c:\temp\google
2009-06-12 17:24 . 2009-06-12 17:26 -------- dc-h--w- c:\windows\ie8
2009-06-10 16:20 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-10 16:20 . 2009-03-24 14:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-10 16:20 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-10 16:20 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-10 16:20 . 2009-06-10 16:20 -------- d-----w- c:\program files\Avira
2009-06-10 16:20 . 2009-06-10 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-10 11:44 . 2009-06-10 11:44 -------- d-----w- c:\program files\LG Electronics
2009-06-10 11:44 . 2007-07-11 13:51 19840 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys
2009-06-10 11:44 . 2007-07-11 08:45 21632 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2009-06-10 11:44 . 2007-07-11 08:40 12416 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2009-06-10 11:38 . 2009-06-11 17:31 -------- d-----w- c:\program files\LG PC Suite 2
2009-06-05 16:18 . 2009-06-05 16:18 246424 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-04 17:05 . 2009-06-04 17:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-06-04 17:05 . 2009-06-04 17:05 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Sonic_Solutions
2009-06-03 05:52 . 2009-06-03 05:52 -------- d-----w- c:\documents and settings\user\Application Data\Big Fish Games
2009-06-02 20:28 . 2009-06-02 20:28 -------- d-----w- c:\documents and settings\All Users\Application Data\LightScribe
2009-06-02 20:27 . 2005-11-09 07:00 12800 ----a-w- c:\windows\system32\ogg.dll
2009-06-02 20:27 . 2005-11-09 07:00 1012736 ----a-w- c:\windows\system32\vorbis.dll
2009-06-02 20:27 . 2009-06-02 20:27 -------- d-----w- c:\documents and settings\user\Application Data\Droppix
2009-06-02 20:26 . 2009-06-02 20:43 -------- d-----w- c:\program files\Fichiers communs\Droppix
2009-06-02 16:35 . 2005-11-09 07:00 462848 ----a-w- c:\windows\system32\HHActiveX.dll
2009-06-02 16:35 . 2005-11-09 07:00 89088 ----a-w- c:\windows\system32\atl71.dll
2009-06-02 16:35 . 2009-06-02 20:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Droppix
2009-06-01 20:04 . 2009-06-01 20:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Vso
2009-06-01 20:02 . 2009-06-01 20:16 -------- d-----w- c:\documents and settings\user\Application Data\Vso
2009-06-01 20:02 . 2009-06-01 20:16 47360 ----a-w- c:\documents and settings\user\Application Data\pcouffin.sys
2009-06-01 20:02 . 2009-06-01 20:02 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-01 19:57 . 2009-06-01 19:57 -------- d-----w- c:\documents and settings\user\Application Data\Canneverbe_Limited
2009-06-01 19:31 . 2009-06-01 19:31 -------- d-----w- c:\documents and settings\user\Application Data\AVS4YOU
2009-06-01 19:31 . 2009-06-01 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-06-01 19:30 . 2009-03-02 13:02 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-06-01 19:29 . 2009-06-01 19:55 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2009-06-01 19:29 . 2002-01-05 14:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-06-01 19:29 . 2002-01-05 13:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-05-31 19:03 . 2009-05-31 19:03 -------- d-----w- c:\documents and settings\All Users\Application Data\AdventureChronicles1
2009-05-31 18:12 . 2009-05-31 18:12 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Oberon Games
2009-05-30 12:03 . 2009-05-30 12:03 -------- d-----w- c:\documents and settings\user\Application Data\Nero
2009-05-29 10:49 . 2009-05-29 10:49 -------- d-----w- c:\documents and settings\All Users\Application Data\IM
2009-05-29 10:48 . 2009-05-29 10:51 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\IM
2009-05-29 10:47 . 2009-05-29 10:47 -------- d-----w- c:\documents and settings\All Users\Application Data\IncrediMail
2009-05-28 17:08 . 2009-05-28 17:09 -------- d-----w- c:\documents and settings\user\Application Data\DeepBurner
2009-05-28 17:08 . 2009-06-01 19:24 -------- d-----w- c:\program files\Astonsoft
2009-05-28 16:13 . 2009-05-28 16:13 -------- d-----w- c:\documents and settings\All Users\Application Data\GameHouse
2009-05-28 04:27 . 2006-09-26 11:03 98304 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-05-28 04:27 . 2006-09-26 11:03 161976 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\zylomgamesplayer.dll
2009-05-26 15:01 . 2009-05-26 15:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Seagate
2009-05-26 15:00 . 2009-05-26 15:00 -------- d-sh--w- c:\windows\ftpcache
2009-05-20 20:21 . 2009-05-30 11:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-05-20 20:21 . 2009-06-03 15:07 -------- d-----w- c:\program files\Fichiers communs\Nero
2009-05-16 16:34 . 2009-05-16 16:34 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 15:13 . 2008-01-09 16:21 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-12 18:06 . 2007-06-25 12:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-12 17:58 . 2006-08-31 10:19 -------- d-----w- c:\program files\Google
2009-06-10 18:22 . 2006-10-05 16:31 57 ----a-w- c:\documents and settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat
2009-06-10 18:18 . 2006-10-05 16:36 50 -c--a-w- c:\windows\system32\bridf05a.dat
2009-06-10 16:17 . 2007-02-07 08:41 -------- d-----w- c:\program files\AntivirusFirewall
2009-06-10 16:14 . 2009-04-10 10:50 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-06-10 16:14 . 2004-08-05 12:00 95500 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-10 16:14 . 2004-08-05 12:00 538212 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-10 11:38 . 2006-08-31 10:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-04 18:18 . 2008-07-06 14:22 -------- d-----w- c:\program files\DivX
2009-06-03 11:33 . 2006-08-31 10:15 -------- d-----w- c:\program files\Ahead
2009-06-03 11:33 . 2006-08-31 10:15 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-06-03 05:50 . 2009-05-10 05:57 -------- d-----w- c:\program files\Oberon Media
2009-06-03 04:25 . 2008-05-30 04:24 -------- d-----w- c:\documents and settings\user\Application Data\Zylom
2009-06-02 20:28 . 2006-09-30 11:01 107504 -c--a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-30 16:15 . 2009-03-16 18:14 -------- d-----w- c:\program files\LucasArts
2009-05-28 18:07 . 2008-03-16 21:09 -------- d-----w- c:\documents and settings\user\Application Data\U3
2009-05-28 17:05 . 2009-04-03 16:56 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-05-21 09:35 . 2007-11-11 18:34 -------- d-----w- c:\program files\Warcraft III
2009-05-17 17:12 . 2008-12-04 16:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-16 16:33 . 2008-07-05 14:11 -------- d-----w- c:\program files\3DO
2009-05-13 16:23 . 2009-05-02 09:17 -------- d-----w- c:\program files\Dofus
2009-05-10 18:58 . 2009-05-10 18:11 -------- d-----w- c:\documents and settings\user\Application Data\Petroglyph
2009-05-10 16:19 . 2009-05-10 16:19 717296 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-10 16:19 . 2009-05-10 16:19 -------- d-----w- c:\documents and settings\user\Application Data\DAEMON Tools
2009-05-10 07:06 . 2009-05-10 07:06 -------- d-----w- c:\documents and settings\user\Application Data\iWin
2009-05-10 05:58 . 2009-05-10 05:58 -------- d-----w- c:\documents and settings\All Users\Application Data\MythPeople
2009-05-07 14:45 . 2009-05-07 14:45 -------- d-----w- c:\documents and settings\user\Application Data\Anabel
2009-05-02 09:13 . 2009-04-22 14:29 -------- d-----w- c:\program files\WorldOfGoo
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-24 16:06 . 2009-01-09 10:50 -------- d-----w- c:\program files\Messenger Plus! Live
2009-04-22 17:54 . 2007-05-24 17:23 -------- d-----w- c:\program files\Windows Live Safety Center
2009-04-22 17:44 . 2009-04-22 17:44 -------- d-----w- c:\documents and settings\user\Application Data\LG Electronics
2009-04-22 14:29 . 2009-04-22 14:29 -------- d-----w- c:\documents and settings\All Users\Application Data\2DBoy
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
2009-04-17 16:43 . 2009-04-17 16:43 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{CF7FA811-2435-11DE-B7A3-005056806466}\ARPPRODUCTICON.exe
2009-04-17 09:07 . 2007-06-21 16:50 -------- d-----w- c:\program files\Java
2009-04-17 09:06 . 2009-04-17 09:06 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-15 12:08 . 2008-11-05 17:25 -------- d-----w- c:\program files\Inkscape
2009-03-28 11:13 . 2009-03-28 11:13 2081496 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s5_l4.exe
2009-03-22 11:07 . 2007-11-11 18:37 158742 ----a-w- c:\windows\War3Unin.dat
2009-03-19 15:12 . 2009-03-19 15:12 363246 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ARPPRODUCTICON.exe
2009-03-19 15:12 . 2009-03-19 15:12 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\UNINST_Uninstall_G_408FFBEED62349E08B232864A94D2864.exe
2009-03-19 15:12 . 2009-03-19 15:12 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
2009-03-19 15:12 . 2009-03-19 15:12 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
2009-03-19 15:12 . 2009-03-19 15:12 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
2009-03-19 15:12 . 2009-03-19 15:12 25214 ----a-r- c:\documents and settings\user\Application Data\Microsoft\Installer\{548EAC70-EE00-11DD-908C-005056806466}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-13_16.30.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-13 18:29 . 2009-06-13 18:29 16384 c:\windows\temp\Perflib_Perfdata_454.dat
+ 2009-06-13 18:22 . 2009-06-13 18:22 401408 c:\windows\system32\CF14410.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"MediaDICO38"="c:\program files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe" [2006-05-08 252416]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"SetDefPrt"="c:\program files\Brother\Brmfl05a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 933888]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2006-06-01 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Contr“leur d'‚tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2008-5-5 802816]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=SMNT40.dll
"aux1"=SMNT40.dll
"wave1"=SMNT40.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader
"6999:TCP"= 6999:TCP:Blizzard Downloader
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [10/06/2009 18:20 108289]
S2 gupdate1c9a8a55b7f282;Service Google Update (gupdate1c9a8a55b7f282);c:\program files\Google\Update\GoogleUpdate.exe [19/03/2009 17:11 133104]
.
Contenu du dossier 'Tâches planifiées'
2009-06-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-08 19:23]
2009-06-13 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-19 15:11]
2009-06-13 c:\windows\Tasks\User_Feed_Synchronization-{A5446996-D901-429D-91F3-C58421C53F5C}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.orange.fr/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: ajouter cette page à vos favoris Orange - c:\docume~1\user\LOCALS~1\Temp\cce48C.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: traduire la page - c:\docume~1\user\LOCALS~1\Temp\cce48A.html
IE: traduire le texte sélectionné - c:\docume~1\user\LOCALS~1\Temp\cce48B.html
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {317153FE-B7FB-419B-AC87-0B2EC97D7A04} -
hxxp://www.subdo.com/activex/vb2s.cabFF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-13 20:30
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1244)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\RACHook38.DLL
c:\windows\system32\ieframe.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\brsvc01a.exe
c:\windows\system32\brss01a.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\drivers\CDANTSRV.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\CF14410.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDico38.exe
c:\program files\Micro Application\38 Dictionnaires et Recueils de Correspondance\RAC38.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2009-06-13 20:35 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-13 18:35
ComboFix2.txt 2009-06-13 16:34
Avant-CF: 23 485 550 592 octets libres
Après-CF: 23 442 612 224 octets libres
498 --- E O F --- 2009-05-27 15:46