((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE~\Browser Helper Objects{A057A204-BACC-4D26-8988-34A187E2698B}]
2007-12-14 21:33 1974512 --a------ C:\PROGRA~1\MYFBTO~1\MYFBTO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{A057A204-BACC-4D26-8988-34A187E2698B}
[HKEY_CLASSES_ROOT\clsid{a057a204-bacc-4d26-8988-34a187e2698b}]
[HKEY_CLASSES_ROOT\myfbtoolbar.MYFBTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
“{A057A204-BACC-4D26-8988-34A187E2698B}”= C:\PROGRA~1\MYFBTO~1\MYFBTO~1.DLL [2007-12-14 21:33 1974512]
[HKEY_CLASSES_ROOT\clsid{a057a204-bacc-4d26-8988-34a187e2698b}]
[HKEY_CLASSES_ROOT\myfbtoolbar.MYFBTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2006-03-25 04:00 15360]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-06-15 07:04 68856]
“MsnMsgr”=“C:\Program Files\Windows Live\Messenger\MsnMsgr.exe” [2007-10-18 11:34 5724184]
“googletalk”=“C:\Program Files\Google\Google Talk\googletalk.exe” [2007-04-19 05:39 3297280]
“Octoshape Streaming Services”=“C:\Program Files\Octoshape Streaming Services\User\OctoshapeClient.exe” [2006-02-13 16:33 214648]
“Skype”=“C:\Program Files\Skype\Phone\Skype.exe” [2007-09-13 13:31 22880040]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-11-03 09:59 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-08-05 19:34 64512]
“hpWirelessAssistant”=“C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe” [2006-05-03 20:58 458752]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-08-18 08:00 7585792]
“NvMediaCenter”=“C:\WINDOWS\system32\NvMcTray.dll” [2006-08-18 08:00 86016]
“nwiz”=“nwiz.exe” [2006-08-18 08:00 1617920 C:\WINDOWS\system32\nwiz.exe]
“MsmqIntCert”=“regsvr32 /s mqrt.dll”
“High Definition Audio Property Page Shortcut”=“CHDAudPropShortcut.exe” [2006-07-26 22:44 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
“SynTPEnh”=“C:\Program Files\Synaptics\SynTP\SynTPEnh.exe” [2007-09-15 02:27 1015808]
“QPService”=“C:\Program Files\HP\QuickPlay\QPService.exe” [2006-07-11 19:55 102400]
“HP Software Update”=“C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe” [2005-02-16 21:11 49152]
“QlbCtrl”=“C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe” [2006-06-19 09:33 163840]
“Cpqset”=“C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe” [2006-05-30 14:02 40960]
“RecGuard”=“C:\Windows\SMINST\RecGuard.exe” [2005-10-11 08:23 1187840]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 13:00 79224]
“ZoneAlarm Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [2007-03-09 00:02 919280]
“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe” [2007-03-16 11:45 63712]
“EoEngine”=“”
“EoSudoku”=“”
“SynTPStart”=“C:\Program Files\Synaptics\SynTP\SynTPStart.exe” [2007-09-15 02:29 102400]
“TkBellExe”=“C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe” [2007-11-24 22:24 185896]
“QuickTime Task”=“C:\Program Files\QuickTime\QTTask.exe” [2008-01-10 15:27 385024]
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2008-01-15 03:22 267048]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2008-01-11 22:16 39792]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2006-03-25 04:00 15360]
“DWQueuedReporting”=“C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe” [2007-03-22 19:29 39264]
C:\Documents and Settings\User\Menu D‚marrer\Programmes\D‚marrage
Outil de d‚tection de support de Cyber-shot Viewer.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2006-01-28 17:08:01 155648]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-28 16:57:29 113664]
DSLMON.lnk - C:\Program Files\Menara\dslmon.exe [2007-04-23 21:23:41 839680]
D‚marrage rapide de HP Photosmart Premier.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 07:39:30 73728]
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2007-10-06 08:21:09 57344]
Quick Shelf.lnk - C:\WINDOWS\Installer{08001201-5D65-445A-B3B4-3DCE72BA0C6C}\ENCICONS.EXE [2007-01-30 09:28:13 11264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme
R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys [2006-06-06 20:39]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 17:20]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-05 23:49]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 17:55]
Newly Created Service - USNJSVC
Newly Created Service - WLSETUPSVC
.
Contenu du dossier ‘Scheduled Tasks/Tâches planifiées’
“2008-02-16 11:53:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job”
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
“2008-02-17 16:40:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job”
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
“2008-02-17 16:13:19 C:\WINDOWS\Tasks\User_Feed_Synchronization-{80BB2F36-6F5B-4A4B-ACD0-E54ACD0C284C}.job”
- C:\WINDOWS\system32\msfeedssync.exe
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 16:59:22
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés …
Balayage caché autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe???<?@? ???W???Y?@???<?@
Balayage des fichiers cachés …
Scan terminé avec succès
Les fichiers cachés: 0