ComboFix 08-03-21.2 - mariajose 2008-03-22 10:21:34.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.248 [GMT 1:00]
Endroit: C:\Users\mariajose\Desktop\ComboFix.exe
Command switches used :: C:\Users\mariajose\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Windows\System32\WinSecure.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\System32\WinSecure.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-22 to 2008-03-22 ))))))))))))))))))))))))))))))))))))
.
2008-03-21 09:36 . 2008-03-21 16:14 5,196 --a------ C:\Windows\System32\PerfStringBackup.TMP
2008-03-19 16:47 . 2008-03-22 09:04 37,888 --a------ C:\Windows\System32\rar.exe
2008-03-19 16:07 . 2008-03-19 16:07 <REP> d-------- C:\Program Files\Safari
2008-03-17 16:37 . 2008-03-17 16:37 <REP> d-------- C:\Program Files\eMule
2008-03-16 19:55 . 2008-03-16 19:55 <REP> d-------- C:\Program Files\Micro Application
2008-03-16 19:55 . 2008-03-16 20:00 40 --a------ C:\Windows\NAVIGMA.INI
2008-03-15 11:03 . 2007-12-04 17:10 16,640 --a------ C:\Windows\System32\drivers\PalmUSBD.sys
2008-03-15 11:02 . 2008-03-15 11:02 <REP> d-------- C:\Users\mariajose\AppData\Roaming\Arcsoft
2008-03-15 11:01 . 2008-03-15 11:01 <REP> d-------- C:\Users\mariajose\AppData\Roaming\HotSync
2008-03-15 11:01 . 2008-03-15 11:01 <REP> d-------- C:\Users\All Users\HotSync
2008-03-15 11:01 . 2008-03-15 11:01 <REP> d-------- C:\ProgramData\HotSync
2008-03-15 11:00 . 2008-03-21 23:02 <REP> d-------- C:\Program Files\Palm
2008-03-09 19:07 . 2008-03-09 19:09 28 --a------ C:\Windows\wazpnmp.sys
2008-03-08 12:02 . 2008-03-08 12:02 104,608 --a------ C:\Windows\System32\GDIPFONTCACHEV1.DAT
2008-03-07 13:40 . 2008-03-07 13:40 13,035 --a------ C:\Windows\System32\drivers\SymRedir.cat
2008-03-07 13:40 . 2008-03-07 13:40 1,358 --a------ C:\Windows\System32\drivers\SymRedir.inf
2008-03-07 13:39 . 2008-03-07 13:39 191,536 --a------ C:\Windows\System32\drivers\symtdi.sys
2008-03-07 13:39 . 2008-03-07 13:39 145,968 --a------ C:\Windows\System32\drivers\symfw.sys
2008-03-07 13:39 . 2008-03-07 13:39 39,984 --a------ C:\Windows\System32\drivers\symids.sys
2008-03-07 13:39 . 2008-03-07 13:39 37,936 --a------ C:\Windows\System32\drivers\symndisv.sys
2008-03-07 13:39 . 2008-03-07 13:39 27,696 --a------ C:\Windows\System32\drivers\symredrv.sys
2008-03-07 13:39 . 2008-03-07 13:39 12,848 --a------ C:\Windows\System32\drivers\symdns.sys
2008-03-03 23:20 . 2003-03-18 21:20 1,060,864 --a------ C:\Windows\System32\MFC71.dll
2008-03-03 23:20 . 1998-06-16 23:00 516,173 --a------ C:\Windows\System32\MSVCP60D.DLL
2008-03-03 23:20 . 1998-06-16 23:00 385,100 --a------ C:\Windows\System32\MSVCRTD.DLL
2008-03-03 23:20 . 2000-11-29 02:07 307,200 --a------ C:\Windows\System32\msvcr70.dll
2008-03-03 23:20 . 2003-08-07 15:01 237,568 --a------ C:\Windows\System32\lame_enc.dll
2008-03-03 15:40 . 2008-03-22 09:02 54,156 --ah----- C:\Windows\QTFont.qfn
2008-03-03 15:40 . 2008-03-07 20:07 1,409 --a------ C:\Windows\QTFont.for
2008-03-02 20:44 . 1998-06-24 00:00 164,144 --a------ C:\Windows\System32\COMCT232.OCX
2008-03-02 20:43 . 2008-03-03 23:20 <REP> d-------- C:\Program Files\Free Audio Pack
2008-03-02 20:25 . 2008-03-03 15:32 <REP> d-------- C:\audiograbber
2008-03-02 19:52 . 2008-03-02 20:40 204 --a------ C:\Windows\CDPlayer.ini
2008-03-02 18:50 . 2008-03-02 18:50 <REP> d-------- C:\Users\mariajose\AppData\Roaming\CyberLink
2008-03-01 20:22 . 2008-03-19 17:04 <REP> d-------- C:\Users\mariajose\AppData\Roaming\Apple Computer
2008-03-01 20:22 . 2008-03-03 15:37 <REP> d-------- C:\Program Files\iPod
2008-03-01 20:21 . 2008-03-03 15:38 <REP> d-------- C:\Program Files\iTunes
2008-03-01 20:19 . 2008-03-01 20:21 <REP> d-------- C:\Users\All Users\Apple Computer
2008-03-01 20:19 . 2008-03-01 20:21 <REP> d-------- C:\ProgramData\Apple Computer
2008-03-01 20:19 . 2008-03-01 20:19 <REP> d-------- C:\Program Files\QuickTime
2008-03-01 09:59 . 2008-03-01 09:59 244 --ah----- C:\sqmnoopt01.sqm
2008-03-01 09:59 . 2008-03-01 09:59 232 --ah----- C:\sqmdata01.sqm
2008-02-28 20:47 . 2008-02-28 20:47 <REP> d-------- C:\Users\mariajose\AppData\Roaming\LGSync
2008-02-28 20:44 . 2008-02-28 20:44 <REP> d-------- C:\Program Files\LG Electronics
2008-02-28 20:43 . 2008-02-28 20:44 <REP> d-------- C:\Program Files\LGE GSM PC Sync
2008-02-28 20:43 . 2004-09-16 11:31 1,703,936 --a------ C:\Windows\System32\gdiplus.dll
2008-02-28 20:43 . 2005-09-26 22:55 419,240 --a------ C:\Windows\System32\Vsflex7L.ocx
2008-02-28 20:43 . 2000-05-22 00:00 244,416 --a------ C:\Windows\System32\Msflxgrd.ocx
2008-02-28 20:43 . 2005-10-04 10:39 44,544 --a------ C:\Windows\System32\msxml4a.dll
2008-02-28 20:43 . 2005-06-28 22:12 36,864 --a------ C:\Windows\System32\CSDLGE1LIB.dll
2008-02-24 23:07 . 2008-02-24 23:07 <REP> d-------- C:\Program Files\Common Files\xing shared
2008-02-22 19:58 . 2008-02-22 19:59 <REP> d-------- C:\Users\mariajose\AppData\Roaming\App Launcher Gadget
2008-02-22 19:17 . 2008-02-22 19:17 <REP> d-------- C:\Users\All Users\Emjysoft
2008-02-22 19:17 . 2008-02-22 19:17 <REP> d-------- C:\ProgramData\Emjysoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-22 09:11 --------- d-----w C:\Program Files\Piratrax
2008-03-22 08:05 --------- d---a-w C:\ProgramData\TEMP
2008-03-21 22:02 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-21 22:02 --------- d-----w C:\Program Files\Picasa2
2008-03-21 22:02 --------- d-----w C:\Program Files\Microsoft Works
2008-03-21 22:02 --------- d-----w C:\Program Files\Google
2008-03-21 22:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-20 07:31 --------- d-----w C:\Users\mariajose\AppData\Roaming\LimeWire
2008-03-17 21:34 --------- d-----w C:\ProgramData\Symantec
2008-03-17 20:46 --------- d-----w C:\ProgramData\WLInstaller
2008-03-17 15:37 --------- d-----w C:\ProgramData\eMule
2008-03-14 10:30 --------- d-----w C:\Program Files\Java
2008-03-08 10:49 --------- d-----w C:\Program Files\MSBuild
2008-03-03 14:33 --------- d-----w C:\Program Files\worldTVRT
2008-03-03 14:33 --------- d-----w C:\Program Files\RegCleaner
2008-03-03 14:33 --------- d-----w C:\Program Files\Macrogaming
2008-02-28 19:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-24 22:07 --------- d-----w C:\Program Files\Common Files\Real
2008-02-20 19:31 --------- d-----w C:\Program Files\OLYMPUS
2008-02-19 21:21 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-19 21:17 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-02-19 20:38 --------- d-----w C:\Users\mariajose\AppData\Roaming\Download Manager
2008-02-18 15:36 --------- d-----w C:\Users\mariajose\AppData\Roaming\Nokia
2008-02-18 14:22 --------- d-----w C:\Program Files\LimeWire
2008-02-18 10:14 --------- d-----w C:\Program Files\Common Files\Java
2008-02-17 23:40 --------- d-----w C:\Users\mariajose\AppData\Roaming\vlc
2008-02-17 23:40 --------- d-----w C:\Program Files\adslTV
2008-02-17 22:18 --------- d-----w C:\Program Files\Zattoo
2008-02-15 20:43 --------- d-----w C:\Program Files\CCleaner
2008-02-15 19:55 --------- d-----w C:\Program Files\ToniArts
2008-02-15 11:18 --------- d-----w C:\Users\mariajose\AppData\Roaming\Corel Photo Album
2008-02-14 09:32 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 09:32 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 09:22 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 09:22 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 09:22 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 09:22 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 09:22 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 09:11 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 09:11 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 09:11 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 09:11 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-12 16:28 --------- d-----w C:\Program Files\Corel
2008-02-12 16:19 --------- d-----w C:\Users\mariajose\AppData\Roaming\Corel
2008-02-12 16:18 --------- d-----w C:\Program Files\Common Files\Corel
2008-02-12 15:43 --------- d-----w C:\Users\mariajose\AppData\Roaming\PC Suite
2008-02-12 15:42 --------- d-----w C:\ProgramData\PC Suite
2008-02-12 15:42 --------- d-----w C:\Program Files\DIFX
2008-02-12 15:03 --------- d-----w C:\ProgramData\Downloaded Installations
2008-02-12 14:58 --------- d-----w C:\ProgramData\Installations
2008-02-10 16:29 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-09 14:47 --------- d-----w C:\Program Files\DreamMail4
2008-02-03 17:46 --------- d-----w C:\ProgramData\IM
2008-02-03 17:45 --------- d-----w C:\Program Files\IncrediMail
2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
2008-02-01 10:10 --------- d-----w C:\Program Files\Norton Internet Security
2008-01-23 09:04 --------- d-----w C:\Program Files\Sony Corporation
2008-01-09 21:57 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-04 14:55 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-01-03 17:19 53,248 ----a-r C:\Windows\System32\USBPort.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot@2008-03-22_ 9.18.36.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-22 08:00:49 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-03-22 09:11:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-03-22 08:00:49 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-22 09:11:58 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-22 08:00:49 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-22 09:11:58 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VirtualExpanderFile.1]
@={E4000AC4-5E5F-4956-807A-C5854405D64F}
[HKEY_CLASSES_ROOT\CLSID\{E4000AC4-5E5F-4956-807A-C5854405D64F}]
2008-03-22 09:02 73728 --a------ C:\Program Files\Sony Corporation\VirtualExpander\VEShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 13:34 2159104 C:\Windows\System32\oobefldr.dll]
"Acer Tour Reminder"="" []
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-21 12:59 171448]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 20:43 95800]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 13:34 1004136]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 02:02 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 02:05 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 02:02 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 08:38 4390912 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 04:00 815104]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 23:04 464168]
"Acer Tour"="" []
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 05:33 107112]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-11-21 05:30 22696]
"eDSMSNfix"="C:\Acer\Empowering Technology\eDSMSNfix.exe" [2007-02-08 18:40 13312]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-12-08 13:35 614400]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
"eRecoveryService"="" []
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-01-17 08:01 151552]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 02:48 275800]
"VX3000"="C:\Windows\vVX3000.exe" [2006-12-06 00:38 707360]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 15:30 81920]
"Corel Photo Downloader"="C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-02 17:59 106496]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-24 23:06 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [ ]
C:\Users\mariajose\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
VirtualExpander.lnk - C:\Users\mariajose\AppData\Local\Sony Corporation\VirtualExpander\VirtualExpander.exe [2008-01-23 10:03:53 474808]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-03-27 12:53:59 528384]
HotSync Manager.lnk - C:\Program Files\Palm\Hotsync.exe [2008-01-03 18:28:08 1392640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=eNetHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{33E4AD5A-0D1E-4552-9E61-1BC120999AE1}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{D52FE3E9-C6D6-4E0D-88E8-646134DC2F54}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{984A92F8-4B63-4795-A094-E07569EF5B2E}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\MagicDirector.exe:CyberLink MagicDirector
"{C332BCF8-C1B2-445A-A7EC-DE306F509BDE}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\PowerDV.exe:CyberLink PowerDV
"{B8CB0604-E1FA-4B1C-8240-42D5A1AD71BC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{93A7CCE9-D57B-4A93-891E-185F3644F87C}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{96D8EF61-3BCD-471A-A763-19C40BE217C3}"= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F55E5589-4553-4913-BB7C-F2F01ECFF984}"= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{9192A714-664F-4D2A-AD21-D55E72B572AD}"= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{54A7BD7E-6832-490E-B3A2-9C721F314FD3}"= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{B0429827-DA2A-4038-97B9-CDFD525C4B8D}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{268B1339-6633-4F79-A99B-C2E020B72C39}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{E39E8711-051D-48C7-A3EC-22356BA2B0BC}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{2F20B8F5-454D-44BB-91C2-CAD1241E5A92}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{89D8A9A4-7726-4203-8C2C-2561DB78ADDD}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{1C19F45A-FF66-43DA-8379-C6FD92F0E4B5}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{0056D6E8-A822-4FBC-A25C-7887B3619474}"= Disabled:UDP:C:\Program Files\Magentic\bin\MgImp.exe:Magentic
"{9160DF3F-1AC2-417F-AA5D-BF8DAA00943A}"= Disabled:TCP:C:\Program Files\Magentic\bin\MgImp.exe:Magentic
"{4443CB74-D0EC-4628-BF0C-391D95C245D6}"= Disabled:UDP:C:\Program Files\Magentic\bin\Magentic.exe:Magentic
"{3DF6E298-F158-4960-9671-0B04172A5FF9}"= Disabled:TCP:C:\Program Files\Magentic\bin\Magentic.exe:Magentic
"{003FB132-DB65-4C3F-A3CE-25A7DDF4DC01}"= Disabled:UDP:C:\Program Files\Magentic\bin\MgApp.exe:Magentic
"{26AE01BF-D018-438A-98BA-3FC878EB1422}"= Disabled:TCP:C:\Program Files\Magentic\bin\MgApp.exe:Magentic
"{40AE951A-F6A4-4F20-BD3E-BBB2E7F48254}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{BF34B8FC-F3C3-4446-9ED1-6C06517158B4}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{CE137CD6-967A-4AFB-9F3A-462243988503}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{C5165BFA-C8C1-46F2-B3E7-EDC00999D683}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-06 23:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-06 23:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-06 23:04]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080314.001\IDSvix86.sys [2008-02-13 17:18]
R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-06 23:04]
R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 19:07]
R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-04-24 19:17]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 11:57]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-01-04 23:13]
R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 08:33]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-05 01:39]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-06 03:29]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 13:39]
S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 05:18]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb684c2d-ad97-11dc-82b0-806e6f6e6963}]
\shell\AutoRun\command - E:\AUTORUN.EXE
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-21 21:17:29 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - mariajose.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeB/TASK:
"2008-03-21 21:04:32 C:\Windows\Tasks\User_Feed_Synchronization-{54F5BB1E-258E-4285-86DE-AE544FA29283}.job"
- C:\Windows\system32\msfeedssync.exe
"2007-12-20 11:55:11 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-22 10:24:10
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-22 10:24:50
ComboFix-quarantined-files.txt 2008-03-22 09:24:46
ComboFix2.txt 2008-03-22 08:18:59
.
2008-03-12 21:33:59 --- E O F ---