Bonjour à tous et à nos chers spécialistes en informatique. Après avoir désinfecté ma machine avec combofix, j'ai obtenu le rapport suivant que je vous sommet afin que vous me conseilliez sur d'autres mesures eventuelles à prendre pour protéger mon ordinateur ou continuer la désinfection. Merci d' avance! Voici le rapport:
ComboFix 09-06-22.01 - stephane 24/06/2009 1:04.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.510.279 [GMT 0:00]
Lancé depuis: c:\documents and settings\stephane\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 080923-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\stephane\LOCALS~1\Temp\E_4
c:\program files\instant access
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\windows\system32\bycool1
C:\Autorun.inf
c:\docume~1\stephane\LOCALS~1\Temp\E_4\com.run
c:\docume~1\stephane\LOCALS~1\Temp\E_4\dp1.fne
c:\docume~1\stephane\LOCALS~1\Temp\E_4\eAPI.fne
c:\docume~1\stephane\LOCALS~1\Temp\E_4\internet.fne
c:\docume~1\stephane\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\stephane\LOCALS~1\Temp\E_4\RegEx.fnr
c:\docume~1\stephane\LOCALS~1\Temp\E_4\shell.fne
c:\program files\hp\digital imaging\bin\hpqddcmn.dll
c:\program files\instant access\Center\NoCreditCard.lnk
c:\program files\instant access\DesktopIcons\NoCreditCard.lnk
c:\program files\instant access\Multi\20090403180417\Common\module.php
c:\program files\instant access\Multi\20090403180417\dialerexe.ini
c:\program files\instant access\Multi\20090403180417\js\js_api_dialer.php
c:\program files\instant access\Multi\20090403180417\medias\button1.gif
c:\program files\instant access\Multi\20090403180417\medias\button2.gif
c:\program files\instant access\Multi\20090403180417\medias\button3.gif
c:\program files\instant access\Multi\20090403180417\medias\button4.gif
c:\program files\instant access\Multi\20090403180417\medias\dialer.ico
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\windows\dialerexe.ini
c:\windows\system32\AutoRun.inf
c:\windows\system32\com.run
c:\windows\system32\dp1.fne
c:\windows\system32\eAPI.fne
c:\windows\system32\hpzids01.dll
c:\windows\system32\internet.fne
c:\windows\system32\krnln.fnr
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\RegEx.fnr
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ul.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-24 au 2009-06-24 ))))))))))))))))))))))))))))))))))))
.
2009-06-23 20:25 . 2009-06-23 21:32 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-06-23 20:23 . 2009-06-23 23:50 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-06-23 20:23 . 2009-06-23 20:23 -------- d-----w- c:\program files\Fichiers communs\iS3
2009-06-22 22:34 . 2009-06-23 00:11 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-22 21:35 . 2009-06-14 16:07 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-22 20:31 . 2009-06-22 20:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-22 20:31 . 2009-06-22 20:31 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 20:31 . 2009-06-22 20:31 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 20:31 . 2009-06-22 20:31 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-22 20:31 . 2009-06-23 20:04 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-22 20:30 . 2009-06-22 20:30 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-22 20:30 . 2009-06-22 20:30 -------- d-----w- c:\program files\AVG
2009-06-22 20:30 . 2009-06-23 23:30 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-17 14:44 . 2009-06-17 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-16 09:13 . 2009-06-16 09:13 -------- d-----w- c:\docume~1\stephane\APPLIC~1\HP
2009-06-16 09:08 . 2009-06-16 09:08 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2009-06-16 08:50 . 2007-03-28 14:01 117760 ----a-w- c:\windows\system32\hpzll5ha.dll
2009-06-16 08:40 . 2009-06-16 08:40 -------- d-----w- c:\docume~1\stephane\APPLIC~1\HPAppData
2009-06-16 08:40 . 2009-06-16 08:40 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY
2009-06-16 08:38 . 2009-06-16 08:38 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-06-16 08:38 . 2009-06-16 08:40 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-06-16 08:32 . 2008-04-13 18:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-06-16 08:32 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-06-16 08:29 . 2009-06-16 09:08 155969 ----a-w- c:\windows\HPHins15.dat
2009-06-16 08:29 . 2007-08-28 06:45 2828 ------w- c:\windows\hphmdl15.dat
2009-06-13 21:50 . 2009-06-13 21:48 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-13 18:26 . 2009-06-13 18:26 -------- d-----w- c:\program files\Open Workbench
2009-06-13 11:33 . 2009-06-24 01:17 -------- d-----w- c:\docume~1\stephane\APPLIC~1\skypePM
2009-06-13 11:33 . 2009-06-13 11:33 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-06-13 11:29 . 2009-06-23 18:56 -------- d-----w- c:\docume~1\stephane\APPLIC~1\Skype
2009-06-13 11:29 . 2009-06-13 11:29 -------- d-----w- c:\program files\Fichiers communs\Skype
2009-06-13 11:28 . 2009-06-13 11:29 -------- d-----r- c:\program files\Skype
2009-06-13 11:28 . 2009-06-13 11:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-06-08 13:07 . 2009-06-08 13:07 -------- d-----w- c:\program files\Fichiers communs\PCSuite
2009-06-08 13:07 . 2009-06-08 13:07 -------- d-----w- c:\program files\Fichiers communs\Nokia
2009-06-08 13:05 . 2008-08-26 10:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-06-08 13:04 . 2009-06-08 13:04 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-08 13:03 . 2009-02-09 07:37 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-06-08 13:03 . 2009-02-09 07:37 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-06-08 13:03 . 2009-02-09 07:32 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-06-08 13:01 . 2009-06-08 13:00 34227512 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_fre.exe
2009-06-08 13:01 . 2009-06-08 13:01 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-08 13:01 . 2009-06-08 13:01 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-08 13:01 . 2009-06-08 13:01 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 00:59 . 2009-04-01 11:18 -------- d-----w- c:\docume~1\stephane\APPLIC~1\U3
2009-06-18 17:02 . 2009-04-23 23:45 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-06-17 14:44 . 2009-04-03 12:36 -------- d-----w- c:\program files\Google
2009-06-16 08:40 . 2009-01-28 20:45 -------- d-----w- c:\program files\Hp
2009-06-16 08:35 . 2009-01-29 06:11 -------- d-----w- c:\program files\Fichiers communs\HP
2009-06-14 08:22 . 2009-01-29 09:45 -------- d-----w- c:\program files\SuperCopier2
2009-06-13 21:47 . 2009-01-28 20:56 -------- d-----w- c:\program files\Java
2009-06-13 21:38 . 2009-02-11 09:25 -------- d-----w- c:\documents and settings\All Users\Application Data\UniversalisV13
2009-06-08 13:07 . 2009-04-23 23:40 -------- d-----w- c:\program files\Nokia
2009-06-08 13:01 . 2009-04-23 23:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-06-08 07:28 . 2009-05-12 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-13 14:21 . 2009-02-13 09:04 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-05-13 08:59 . 2009-05-13 08:59 -------- d-----w- c:\program files\Alwil Software
2009-05-12 10:05 . 2009-01-28 21:05 86128 ----a-w- c:\documents and settings\stephane\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 09:30 . 2009-01-29 05:27 -------- d-----w- c:\program files\Microsoft Works
2009-05-12 09:29 . 2009-05-12 09:29 -------- d-----w- c:\program files\MSBuild
2009-05-12 09:26 . 2009-05-12 09:26 -------- d-----w- c:\program files\Microsoft.NET
2009-05-12 09:18 . 2009-05-12 09:18 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-05-07 15:43 . 2009-05-07 15:43 -------- d-----w- c:\docume~1\stephane\APPLIC~1\Leadertech
2009-05-05 10:23 . 2009-05-05 10:23 -------- d-----w- c:\program files\PowerISO
2009-04-27 22:54 . 2009-04-27 22:54 -------- d-----w- c:\program files\Real
2009-04-25 22:27 . 2009-04-23 23:45 -------- d-----w- c:\docume~1\stephane\APPLIC~1\Nokia
2009-04-25 09:44 . 2009-01-28 20:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-23 23:38 . 2009-04-23 23:38 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Installer\CommonCustomActions\UninstCCD.exe
2009-04-23 23:38 . 2009-04-23 23:38 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-04-23 23:38 . 2009-04-23 23:38 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Installer\CommonCustomActions\UninstPCS.exe
2009-04-23 23:01 . 2009-04-23 23:38 36041528 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{A8C3710A-0BCA-4F10-9EC3-A302A1F1FA82}\Nokia_PC_Suite_rel_7_0_8_2_fre_web.exe
2009-04-17 20:06 . 2001-08-28 12:00 76930 ----a-w- c:\windows\system32\perfc00C.dat
2009-04-17 20:06 . 2001-08-28 12:00 471816 ----a-w- c:\windows\system32\perfh00C.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 16:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-07-11 223984]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-13 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-13 148888]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-11 794624]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-11 98304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-07-11 223984]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-22 1948440]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-9-30 57344]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-2 110592]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-2-19 1205840]
HP Digital Imaging Monitor.lnk - c:\program files\Hp\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= cmd.exe
"2"= mmc.exe
"3"= rstrui.exe
"4"= regedit.exe
"5"= regedt32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-22 20:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [13/05/2009 09:00 78416]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [22/06/2009 20:31 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [22/06/2009 20:31 108552]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13/05/2009 09:00 20560]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [22/06/2009 20:30 298776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [04/03/2009 20:18 55152]
R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 18:08 533360]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [28/01/2009 20:32 200192]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [19/02/2009 06:20 69656]
S2 gupdate1c9b458c509f77a;Google Update Service (gupdate1c9b458c509f77a);c:\program files\Google\Update\GoogleUpdate.exe [03/04/2009 12:36 133104]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [19/02/2009 06:20 104344]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-06-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-13 14:44]
2009-06-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-03 12:36]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-XP-E6619D4D - c:\windows\system32\XP-E6619D4D.EXE
.
------- Examen supplémentaire -------
.
uStart Page = Travaillez plus.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 01:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\stephane\LOCALS~1\Temp\mc22.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\•€|ÿÿÿÿ"•€|þ»Ñw*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2800)
c:\program files\SuperCopier2\SC2Hook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\McAfee\Common Framework\Mctray.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\HPQ\shared\hpqwmi.exe
c:\program files\Hp\Digital Imaging\bin\hpqste08.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Heure de fin: 2009-06-24 1:23 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-24 01:23
Avant-CF: 1 408 786 432 octets libres
Après-CF: 1 609 216 000 octets libres
287 --- E O F --- 2009-04-16 07:54