Here is the Combofix log, followed by the new DDS.txt log:
ComboFix 09-08-24.05 - msardi 2009-08-24 15:55.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.2.1036.18.894.448 [GMT -4:00]
Running from: c:\documents and settings\msardi\Bureau\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\msardi\Application Data\inst.exe
C:\LOG44.tmp
c:\recycler\S-1-5-21-1229272821-343818398-725345543-1003
c:\recycler\S-1-5-21-1229272821-343818398-725345543-500
c:\windows\Installer\1148b4.msp
c:\windows\Installer\1148ba.msp
c:\windows\Installer\1148c0.msp
c:\windows\Installer\1148c6.msp
c:\windows\Installer\1359db.msp
c:\windows\Installer\157edd6.msp
c:\windows\Installer\157eddc.msp
c:\windows\Installer\157ede2.msp
c:\windows\Installer\157ede8.msp
c:\windows\Installer\157edee.msp
c:\windows\Installer\157edf4.msp
c:\windows\Installer\157edfa.msp
c:\windows\Installer\1e8f4d.msp
c:\windows\Installer\1e8f53.msp
c:\windows\Installer\1e8f59.msp
c:\windows\Installer\1e8f5f.msp
c:\windows\Installer\1e8f65.msp
c:\windows\Installer\1e8f6b.msp
c:\windows\Installer\1e8f71.msp
c:\windows\Installer\20228b.msp
c:\windows\Installer\20229e.msp
c:\windows\Installer\2022a4.msp
c:\windows\Installer\2022aa.msp
c:\windows\Installer\2022b0.msp
c:\windows\Installer\2022b6.msp
c:\windows\Installer\2022bc.msp
c:\windows\Installer\276f46.msp
c:\windows\Installer\276f4c.msp
c:\windows\Installer\276f52.msp
c:\windows\Installer\276f58.msp
c:\windows\Installer\276f5e.msp
c:\windows\Installer\276f64.msp
c:\windows\Installer\276f6a.msp
c:\windows\Installer\34f04e.msp
c:\windows\Installer\34f054.msp
c:\windows\Installer\34f05a.msp
c:\windows\Installer\34f060.msp
c:\windows\Installer\34f066.msp
c:\windows\Installer\34f06c.msp
c:\windows\Installer\34f072.msp
c:\windows\Installer\3a9b3c.msp
c:\windows\Installer\3a9b42.msp
c:\windows\Installer\3a9b48.msp
c:\windows\Installer\3a9b4e.msp
c:\windows\Installer\3a9b54.msp
c:\windows\Installer\3a9b5a.msp
c:\windows\Installer\3a9b60.msp
c:\windows\Installer\3ff68f4.msp
c:\windows\Installer\3ff68fa.msp
c:\windows\Installer\3ff6900.msp
c:\windows\Installer\3ff6906.msp
c:\windows\Installer\3ff690c.msp
c:\windows\Installer\3ff6912.msp
c:\windows\Installer\3ff6918.msp
c:\windows\Installer\456f6.msp
c:\windows\Installer\456fc.msp
c:\windows\Installer\45702.msp
c:\windows\Installer\45708.msp
c:\windows\Installer\4570e.msp
c:\windows\Installer\45714.msp
c:\windows\Installer\4571a.msp
c:\windows\Installer\4aeeb6d.msp
c:\windows\Installer\4aeeb73.msp
c:\windows\Installer\4aeeb79.msp
c:\windows\Installer\4aeeb7f.msp
c:\windows\Installer\4aeeb85.msp
c:\windows\Installer\4aeeb8b.msp
c:\windows\Installer\52f0b.msp
c:\windows\Installer\56dea0.msp
c:\windows\Installer\74aff2.msp
c:\windows\Installer\74aff8.msp
c:\windows\Installer\74affe.msp
c:\windows\Installer\74b004.msp
c:\windows\Installer\74b00a.msp
c:\windows\Installer\74b010.msp
c:\windows\Installer\74b016.msp
c:\windows\Installer\7b26db.msp
c:\windows\Installer\7b26e1.msp
c:\windows\Installer\7b26e7.msp
c:\windows\Installer\7b26ed.msp
c:\windows\Installer\7b26f3.msp
c:\windows\Installer\7b26f9.msp
c:\windows\Installer\7b26ff.msp
c:\windows\Installer\a789e4.msp
c:\windows\Installer\a789ea.msp
c:\windows\Installer\a789f0.msp
c:\windows\Installer\a789f6.msp
c:\windows\Installer\a789fc.msp
c:\windows\Installer\a78a02.msp
c:\windows\Installer\a78a08.msp
c:\windows\Installer\d8d92b8.msi
c:\windows\Installer\WMEncoder.msi
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\drivers\SKYNETdubhhmna.sys
c:\windows\system32\netskt.sys
c:\windows\system32\SKYNETlxmrivft.dll
c:\windows\system32\SKYNETmlwxidmr.dat
c:\windows\system32\SKYNETnpylgogv.dll
c:\windows\system32\SKYNETvkapmkct.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETltoirkro
-------\Legacy_SKYNETltoirkro
-------\Legacy_6TO4
-------\Service_6to4
-------\Legacy_netskt
-------\Service_netskt
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.
2009-08-22 13:35 . 2009-08-22 13:35 -------- d-----w- c:\program files\ERUNT
2009-08-22 13:32 . 2009-08-22 13:32 -------- d-----w- c:\program files\Trend Micro
2009-08-22 07:57 . 2009-08-22 07:57 -------- d-----w- c:\documents and settings\testre\Local Settings\Application Data\Adobe
2009-08-16 23:33 . 2009-08-16 23:33 -------- d-----w- c:\documents and settings\msardi\Application Data\Windows Search
2009-08-15 13:37 . 2009-08-15 13:37 -------- d-----w- c:\documents and settings\msardi\Application Data\Malwarebytes
2009-08-15 13:37 . 2009-08-15 13:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 02:46 . 2009-08-15 02:46 -------- d-----w- c:\documents and settings\testre\Local Settings\Application Data\Identities
2009-08-15 02:46 . 2009-08-15 02:46 -------- d-----w- c:\documents and settings\testre\Application Data\Windows Desktop Search
2009-08-14 18:14 . 2009-08-14 18:14 -------- d-----w- c:\documents and settings\msardi\Application Data\Windows Desktop Search
2009-08-14 18:13 . 2009-08-15 00:43 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-08-14 18:10 . 2009-08-15 01:24 -------- d-----w- c:\program files\Windows Desktop Search
2009-08-14 18:10 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2009-08-14 18:10 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2009-08-14 18:10 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2009-08-14 12:58 . 2009-08-22 23:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-14 12:57 . 2009-08-22 23:49 152576 ----a-w- c:\documents and settings\msardi\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-14 09:48 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-14 06:17 . 2009-08-14 06:17 -------- d-----w- c:\documents and settings\LocalService\Bureau
2009-08-14 06:15 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-14 06:14 . 2009-08-14 06:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-14 06:14 . 2009-07-08 17:28 2920112 -c--a-w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-08-14 06:14 . 2009-08-14 06:14 -------- d-----w- c:\program files\Lavasoft
2009-08-12 10:42 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 17:55 . 2009-08-11 17:55 -------- d-----w- C:\lexmark
2009-08-05 09:00 . 2009-08-05 09:00 205312 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 16:53 . 2007-07-05 20:32 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-08-22 23:50 . 2007-02-26 14:55 -------- d-----w- c:\program files\Java
2009-08-22 08:01 . 2007-11-22 06:04 -------- d-----w- c:\program files\Mozilla Firefox 3 Beta 1
2009-08-14 18:11 . 2004-08-05 10:00 94688 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-14 18:11 . 2004-08-05 10:00 536152 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-14 11:03 . 2008-04-05 17:21 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-14 10:59 . 2008-04-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-14 06:14 . 2008-04-05 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-13 02:55 . 2009-08-13 02:55 129 ----a-w- c:\documents and settings\testre\Local Settings\Application Data\fusioncache.dat
2009-08-12 15:04 . 2009-06-12 12:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-11 03:20 . 2008-06-23 13:39 78192 ----a-w- c:\documents and settings\ma.damour\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-07 10:15 . 2007-07-16 20:34 -------- d-----w- c:\documents and settings\msardi\Application Data\U3
2009-08-07 01:05 . 2009-01-01 00:15 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-05 09:00 . 2004-08-05 10:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 09:33 . 2007-12-23 00:16 -------- d-----w- c:\documents and settings\msardi\Application Data\Apple Computer
2009-08-02 08:13 . 2008-06-26 18:46 -------- d-----w- c:\program files\Xvid
2009-07-23 21:35 . 2009-07-05 14:13 -------- d-----w- c:\program files\adslTV
2009-07-23 21:29 . 2009-06-27 06:50 -------- d-----w- c:\documents and settings\msardi\Application Data\Copernic
2009-07-23 21:27 . 2009-06-12 17:58 -------- d-----w- c:\program files\IMAPSize
2009-07-23 21:26 . 2008-05-30 06:08 -------- d-----w- c:\documents and settings\msardi\Application Data\vlc
2009-07-17 19:03 . 2004-08-05 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-05 10:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 06:57 . 2009-07-09 06:57 -------- d-----w- c:\documents and settings\msardi\Application Data\InstallShield
2009-07-05 09:29 . 2009-07-05 09:29 -------- d-----w- c:\program files\Free
2009-07-03 16:57 . 2006-03-04 03:35 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-30 20:27 . 2009-06-28 21:45 -------- d-----w- c:\program files\Google
2009-06-27 23:06 . 2009-06-27 23:06 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-06-27 23:04 . 2009-06-27 23:04 -------- d-----w- c:\program files\Microsoft
2009-06-27 23:04 . 2009-06-27 23:04 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-06-27 23:03 . 2008-09-22 03:54 -------- d-----w- c:\program files\Windows Live
2009-06-27 23:01 . 2009-06-27 23:01 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-06-25 08:26 . 2004-08-05 10:00 736768 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:26 . 2004-08-05 10:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:26 . 2004-08-05 10:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:26 . 2004-08-05 10:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:26 . 2004-08-05 10:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:26 . 2004-08-05 10:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-05 10:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:40 . 2004-08-05 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2004-08-05 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 10:44 . 2004-08-05 10:00 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:44 . 2004-08-05 10:00 82944 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-14 20:35 . 2007-07-05 19:48 78192 ----a-w- c:\documents and settings\msardi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-10 14:14 . 2004-08-05 10:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:21 . 2007-02-26 12:42 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2004-08-05 10:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-10 00:38 . 2009-06-10 00:38 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-05 15:42 . 2009-03-23 13:56 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 15:42 . 2008-09-13 01:43 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-03 19:10 . 2004-08-05 10:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 12:52 . 2009-05-31 12:52 3584 ----a-r- c:\documents and settings\msardi\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-03-08 82011]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-11-07 122940]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-22 149280]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-27 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DfLogon]
2006-07-22 16:52 49152 ----a-w- c:\windows\system32\LogonDll.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C /k

*\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\eCopy\\Desktop 9.0\\Bin\\eCopyDesktop.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox 3 Beta 1\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2007-02-26 3456]
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2006-07-22 119168]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-08-14 64160]
R0 ThwSpace;ThwSpace;c:\windows\system32\drivers\ThwSpace.sys [2006-07-22 68096]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-07-03 1029456]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-14 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\msardi\Application Data\Mozilla\Firefox\Profiles\ruztgqrj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ig?hl=fr
FF - prefs.js: keyword.URL - hxxp://www.google.ca/search?q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\QuickTime Alternative\Plugins\npqtplugin8.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-24 16:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,69,33,8e,c9,dd,
20,b3,90,e2,63,26,f1,3f,c8,ff,68,bd,0f,86,2a,02,4c,42,65,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,b6,1b,25,66,81,
cb,48,a5,6a,9c,d6,61,af,45,84,18,04,b6,2f,46,ac,fa,b2,0b,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,06,77,ba,67,1c,
0d,d0,27,ff,7c,85,e0,43,d4,0e,fe,15,1c,87,7f,fe,ac,a4,c6,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,af,7a,01,37,e5,
48,f4,8e,86,8c,21,01,be,91,eb,e7,ab,01,2f,b2,63,7a,5b,1b,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,4e,f0,bf,e1,75,
38,96,f1,f5,1d,4d,73,a8,13,5c,05,25,46,22,bd,3c,49,f7,17,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:50,93,e5,ab,ec,6a,4e,ab,4e,31,73,4b,5c,
60,4e,c9,df,20,58,62,78,6b,cf,c8,b9,7e,bf,4f,c5,fe,02,62,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,d4,27,e5,10,58,
e4,76,07,fb,a7,78,e6,12,2f,9a,ea,7b,d6,6f,b2,e9,5f,d0,51,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,44,07,22,55,21,
fb,32,6c,01,3a,48,fc,e8,04,4a,f1,5d,b6,1f,26,cf,ae,34,57,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:51,fa,6e,91,28,9e,14,cc,01,7d,3c,9c,87,
dc,6d,a8,f6,0f,4e,58,98,5b,89,c9,d0,17,07,6f,b6,fe,ea,6b,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,fc,d1,b5,64,8c,
c3,11,f9,3d,ce,ea,26,2d,45,aa,78,2e,cd,70,8e,91,9c,8d,3f,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,8a,07,52,35,a8,
82,83,f7,2a,b7,cc,b5,b9,7f,41,e7,4f,6a,35,6c,2c,3d,80,03,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,6a,de,b4,7b,88,
a6,85,23,6c,43,2d,1e,aa,22,2f,9c,02,59,fb,bb,56,c1,d2,46,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LogonDll.dll
- - - - - - - > 'lsass.exe'(936)
c:\program files\Bonjour\mdnsNSP.dll
- - - - - - - > 'explorer.exe'(2384)
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\fr-fr\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\fr-fr\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\system32\BCMWLTRY.EXE
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\searchindexer.exe
c:\program files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\McAfee\Common Framework\Mctray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
.
**************************************************************************
.
Completion time: 2009-08-24 16:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-24 20:10
Pre-Run: 6*853*095*424 octets libres
Post-Run: 6*846*529*536 octets libres
462 --- E O F --- 2009-08-15 01:24
DDS (Ver_09-07-30.01) - NTFSx86
Run by msardi at 16:30:04,40 on 2009-08-24
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professionnel 5.1.2600.3.1252.2.1036.18.894.260 [GMT -4:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\Program Files\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\msardi\Bureau\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.fr/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
BHO: Aide pour le lien d'Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\fichiers communs\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\fichie~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\fichiers communs\installshield\updateservice\issch.exe" -start
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime alternative\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1214231055399
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214231182426
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - hxxp://geo.ville.quebec.qc.ca/carte_int/acgm.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: DfLogon - LogonDll.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\msardi\applic~1\mozilla\firefox\profiles\ruztgqrj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ig?hl=fr
FF - prefs.js: keyword.URL - hxxp://www.google.ca/search?q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin2.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin3.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin4.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin5.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin6.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin7.dll
FF - plugin: c:\program files\quicktime alternative\plugins\npqtplugin8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2007-2-26 3456]
R0 DeepFrz;DeepFrz;c:\windows\system32\drivers\DeepFrz.sys [2006-7-22 119168]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-14 64160]
R0 ThwSpace;ThwSpace;c:\windows\system32\drivers\ThwSpace.sys [2006-7-22 68096]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2007-2-26 104000]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2006-11-30 144960]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2006-11-30 54872]
R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2007-2-26 72264]
R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2007-2-26 34152]
R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2007-2-26 168776]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456]
=============== Created Last 30 ================
2009-08-24 16:09 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-24 15:46 229,376 a------- c:\windows\PEV.exe
2009-08-24 15:46 161,792 a------- c:\windows\SWREG.exe
2009-08-24 15:46 98,816 a------- c:\windows\sed.exe
2009-08-22 09:32 <DIR> --d----- c:\program files\Trend Micro
2009-08-16 19:33 <DIR> --d----- c:\docume~1\msardi\applic~1\Windows Search
2009-08-15 09:37 <DIR> --d----- c:\docume~1\msardi\applic~1\Malwarebytes
2009-08-15 09:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-14 14:14 <DIR> --d----- c:\docume~1\msardi\applic~1\Windows Desktop Search
2009-08-14 14:10 <DIR> --d----- c:\program files\Windows Desktop Search
2009-08-14 14:10 192,000 -c------ c:\windows\system32\dllcache\offfilt.dll
2009-08-14 14:10 98,304 -c------ c:\windows\system32\dllcache\nlhtml.dll
2009-08-14 14:10 29,696 -c------ c:\windows\system32\dllcache\mimefilt.dll
2009-08-14 08:58 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-14 05:48 15,688 a------- c:\windows\system32\lsdelete.exe
2009-08-14 02:15 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-08-14 02:14 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-14 02:14 <DIR> --d----- c:\program files\Lavasoft
2009-08-12 06:43 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 06:42 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-08-11 13:57 507 a------- c:\windows\LMAAM2DD.ini
2009-08-11 13:55 <DIR> --d----- C:\lexmark
2009-08-05 05:00 205,312 -c------ c:\windows\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-14 14:11 536,152 a------- c:\windows\system32\perfh00C.dat
2009-08-14 14:11 94,688 a------- c:\windows\system32\perfc00C.dat
2009-08-05 05:00 205,312 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 15:03 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-03 12:57 915,456 -------- c:\windows\system32\wininet.dll
2009-06-25 04:26 736,768 a------- c:\windows\system32\lsasrv.dll
2009-06-25 04:26 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 04:26 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 04:26 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 04:26 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-25 04:26 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-16 10:40 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 10:40 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-15 06:44 78,848 a------- c:\windows\system32\telnet.exe
2009-06-15 06:44 82,944 a------- c:\windows\system32\tlntsess.exe
2009-06-10 10:14 85,504 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:21 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 02:15 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-05 11:42 2,060,288 a------- c:\windows\system32\usbaaplrc.dll
2009-06-03 15:10 1,297,408 a------- c:\windows\system32\quartz.dll
2009-01-30 22:51 47,360 a------- c:\docume~1\msardi\applic~1\pcouffin.sys
2008-06-23 10:15 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\historique\history.ie5\mshist012008062320080624\index.dat
============= FINISH: 16:30:52,68 ===============