ComboFix 08-07-01.5 - Momo 2008-07-02 23:30:57.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.112 [GMT 2:00]
Endroit: C:\Documents and Settings\Momo\Bureau\ComboFix.exe
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))))))))
.
2008-07-02 21:07 . 2008-07-02 21:07 15,820,742 --a------ C:\upload_moi_MOMO-80D6D3A765.tar.gz
2008-07-02 20:16 . 2008-07-02 22:21 <REP> d-------- C:\Program Files\Navilog1
2008-07-02 20:09 . 2008-07-02 20:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-02 20:09 . 2008-07-02 20:09 <REP> d-------- C:\Documents and Settings\Momo\Application Data\Malwarebytes
2008-07-02 20:09 . 2008-07-02 20:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-02 20:09 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-02 20:09 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-02 19:49 . 2008-07-02 19:49 <REP> d-------- C:\cleanup
2008-07-02 19:43 . 2008-07-02 19:43 64,324 --a------ C:\WINDOWS\system32\tjrpmbsqwikwvoluo.exe
2008-07-02 13:54 . 2008-07-02 13:54 158,208 --a------ C:\WINDOWS\system32\sgifmmcreegydho.dll
2008-07-01 22:55 . 2008-07-01 22:58 <REP> d-------- C:\huk
2008-06-30 23:30 . 2008-06-30 23:30 <REP> d-------- C:\Program Files\Google
2008-06-30 23:29 . 2008-06-30 23:29 <REP> d-------- C:\WINDOWS\system32\Adobe
2008-06-30 00:27 . 2008-06-30 00:27 <REP> d-------- C:\Program Files\Virtools
2008-06-30 00:27 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-06-30 00:27 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-06-27 21:27 . 2008-06-27 22:23 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-27 21:26 . 2008-07-02 02:47 <REP> d-------- C:\Program Files\Gamenext
2008-06-27 21:26 . 2008-06-27 21:26 <REP> d-------- C:\Program Files\Fichiers communs\Oberon Media
2008-06-24 20:15 . 2008-06-24 20:15 445,440 --a------ C:\WINDOWS\system32\gnkoigkzhw.dll
2008-06-20 13:36 . 2008-06-20 13:36 268 --ah----- C:\sqmdata09.sqm
2008-06-20 13:36 . 2008-06-20 13:36 244 --ah----- C:\sqmnoopt09.sqm
2008-06-13 19:00 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 19:00 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-05 18:00 . 2008-06-05 18:00 268 --ah----- C:\sqmdata08.sqm
2008-06-05 18:00 . 2008-06-05 18:00 244 --ah----- C:\sqmnoopt08.sqm
2008-06-05 00:47 . 2008-06-05 00:47 268 --ah----- C:\sqmdata07.sqm
2008-06-05 00:47 . 2008-06-05 00:47 244 --ah----- C:\sqmnoopt07.sqm
2008-06-02 13:15 . 2008-06-02 13:15 268 --ah----- C:\sqmdata06.sqm
2008-06-02 13:15 . 2008-06-02 13:15 244 --ah----- C:\sqmnoopt06.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 21:36 --------- d-----w C:\Program Files\Wanadoo
2008-07-02 00:49 --------- d-----w C:\Program Files\MSN Messenger
2008-07-02 00:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kiwee Toolbar2
2008-06-26 17:54 0 ----a-w C:\Program Files\temp01
2008-06-24 01:10 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-06-08 21:23 --------- d-----w C:\Documents and Settings\Momo\Application Data\LimeWire
2008-05-30 22:13 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-30 22:13 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-30 22:13 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-30 22:13 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-30 22:13 --------- d-----w C:\Program Files\Symantec
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-21 07:02 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-04 17:41 44,544 ----a-w C:\WINDOWS\system32\agremove.exe
2007-12-31 10:24 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((( snapshot@2008-07-02_23.21.27.84 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-02 21:15:57 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 21:34:10 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-02 21:34:51 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_8b4.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8c5669e2-7afd-69b9-b9c5-e1eb443a929c}]
2008-07-02 13:54 158208 --a------ C:\WINDOWS\system32\sgifmmcreegydho.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eb19dca3-6c55-e06b-61fe-a60fc4187770}]
2008-06-24 20:15 445440 --a------ C:\WINDOWS\system32\gnkoigkzhw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:54 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 15:50 122880]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55 5674352]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-02-22 22:42 3537968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-30 23:30 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="C:\Program Files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2007-08-23 15:48 53248]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 14:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 14:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 14:17 118784]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-10-12 17:28 1282048]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-07-05 15:58 413696]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-07-05 15:51 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55 32768]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-09-17 01:27 52848]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 11:22 517768]
"{1036ec25-4ede-872d-ec78-2cd347cdf276}"="C:\WINDOWS\system32\sgifmmcreegydho.dll" [2008-07-02 13:54 158208]
"AGRSMMSG"="AGRSMMSG.exe" [2006-08-30 17:40 89542 C:\WINDOWS\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 16:21 16384000 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:54 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2007-07-05 15:52 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 10:27]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2007-04-02 12:24]
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-06-20 11:12]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f83dab8-b649-11dc-bc4a-000fb0d632f0}]
\Shell\Auto\command - cmd /C launch.bat
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-25 19:12:53 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - Momo.job"