ComboFix 09-01-07.01 - Paul 2009-01-07 21:14:43.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1252.1.1036.18.1023.648 [GMT 1:00]
Lancé depuis: c:documents and settingsPaulBureauComboFix.exe
Commutateurs utilisés :: c:documents and settingsPaulBureauWindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:documents and settingsAll UsersApplication DataSoftware Licensors
c:documents and settingsPaulLocal SettingsApplication Datausbyglsq.dat
c:documents and settingsPaulLocal SettingsApplication Datausbyglsq.exe
c:documents and settingsPaulLocal SettingsApplication Datausbyglsq_nav.dat
c:documents and settingsPaulLocal SettingsApplication Datausbyglsq_navps.dat
c:windowssystem32mdm.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-07 au 2009-01-07 ))))))))))))))))))))))))))))))))))))
.
2009-01-05 21:06 . 2009-01-05 21:06 <REP> d-------- c:program filesMalwarebytes' Anti-Malware
2009-01-05 21:06 . 2009-01-04 18:38 38,496 --a------ c:windowssystem32driversmbamswissarmy.sys
2009-01-05 21:06 . 2009-01-04 18:38 15,504 --a------ c:windowssystem32driversmbam.sys
2009-01-04 11:02 . 2009-01-04 11:02 <REP> d-------- C:QUARANTINE
2009-01-02 10:51 . 2009-01-02 10:56 <REP> d-------- c:program fileseMule
2009-01-01 09:22 . 2009-01-01 09:22 268 --ah----- C:sqmdata18.sqm
2009-01-01 09:22 . 2009-01-01 09:22 244 --ah----- C:sqmnoopt18.sqm
2008-12-29 13:33 . 2008-07-26 16:26 4,658,584 -ra------ c:windowssystem32driverslvuvc.sys
2008-12-29 13:33 . 2008-07-26 16:25 627,864 -ra------ c:windowssystem32driverslvrs.sys
2008-12-29 13:33 . 2008-07-26 16:23 195,096 -ra------ c:windowssystem32lvci11801048.dll
2008-12-29 13:33 . 2008-07-26 15:46 25,974 -ra------ c:windowssystem32Repository.reg
2008-12-29 13:33 . 2008-07-26 16:26 23,832 -ra------ c:windowssystem32driverslvuvcflt.sys
2008-12-29 13:33 . 2008-04-14 03:34 20,992 --a------ c:windowssystem32dshowext.ax
2008-12-29 13:33 . 2008-04-14 03:34 20,992 --a--c--- c:windowssystem32dllcachedshowext.ax
2008-12-29 13:33 . 2008-12-29 15:17 0 --a------ c:windowssystem32driverslvuvc.hs
2008-12-29 13:33 . 2009-01-07 21:19 0 --a------ c:windowssystem32driverslogiflt.iad
2008-12-29 13:31 . 2008-12-29 13:31 <REP> d-------- c:documents and settingsPaulApplication DataLeadertech
2008-12-29 13:31 . 2008-12-29 13:31 127,034 -r------- c:windowswUnin-8.1.1.50-8876480SL.exe
2008-12-29 13:29 . 2008-12-31 08:50 <REP> d-------- c:documents and settingsAll UsersApplication DataLogishrd
2008-12-29 13:28 . 2008-12-29 13:33 <REP> d-------- c:program filesFichiers communsLogiShrd
2008-12-29 13:28 . 2008-12-29 13:28 <REP> d-------- c:documents and settingsAll UsersApplication DataLogitech
2008-12-23 14:27 . 2001-08-23 17:04 12,288 --a------ c:windowssystem32driversmouhid.sys
2008-12-23 14:27 . 2001-08-23 17:04 12,288 --a--c--- c:windowssystem32dllcachemouhid.sys
2008-12-19 20:53 . 2008-12-20 09:17 <REP> d-------- C:Sauvegarde PC portable
2008-12-19 17:13 . 2008-12-20 17:22 <REP> d-------- c:program filesBackup4all
2008-12-19 17:13 . 2008-12-19 17:13 <REP> d-------- c:documents and settingsPaulApplication DataSoftland
2008-12-17 12:25 . 2008-12-17 12:25 268 --ah----- C:sqmdata17.sqm
2008-12-17 12:25 . 2008-12-17 12:25 244 --ah----- C:sqmnoopt17.sqm
2008-12-17 09:31 . 2008-12-17 09:31 268 --ah----- C:sqmdata16.sqm
2008-12-17 09:31 . 2008-12-17 09:31 244 --ah----- C:sqmnoopt16.sqm
2008-12-16 18:12 . 2008-12-16 18:12 268 --ah----- C:sqmdata15.sqm
2008-12-16 18:12 . 2008-12-16 18:12 244 --ah----- C:sqmnoopt15.sqm
2008-12-15 22:40 . 2008-12-15 22:40 268 --ah----- C:sqmdata14.sqm
2008-12-15 22:40 . 2008-12-15 22:40 244 --ah----- C:sqmnoopt14.sqm
2008-12-14 18:52 . 2008-12-14 18:52 <REP> d-------- c:program filesMahjong
2008-12-14 18:52 . 2008-12-14 18:52 <REP> d-------- c:program filesAbsolutist_Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 07:07 --------- d-----w c:program filesFichiers communsLogitech
2008-12-29 14:18 --------- d--h--w c:program filesInstallShield Installation Information
2008-12-29 12:31 --------- d-----w c:program filesLogitech
2008-12-10 19:20 --------- d-----w c:program filesFichiers communsAdobe
2008-11-29 09:54 --------- d-----w c:program filesNetwork Associates
2008-11-29 09:54 --------- d-----w c:program filesFichiers communsCisco Systems
2008-11-29 09:54 --------- d-----w c:documents and settingsAll UsersApplication DataNetwork Associates
2008-11-29 09:54 --------- d-----w c:documents and settingsAll UsersApplication DataMcAfee
2008-11-29 09:53 --------- d-----w c:program filesFichiers communsNetwork Associates
2008-11-29 09:00 --------- d-----w c:documents and settingsPaulApplication DataMalwarebytes
2008-11-29 09:00 --------- d-----w c:documents and settingsAll UsersApplication DataMalwarebytes
2008-11-22 18:41 --------- d-----w c:program filesTrend Micro
2008-11-22 16:51 --------- d-----w c:documents and settingsAll UsersApplication DataOffice Genuine Advantage
2008-11-21 17:27 --------- d-----w c:program filesQUAD Utilities
2008-11-21 17:13 --------- d---a-w c:documents and settingsAll UsersApplication DataTEMP
2008-11-10 16:52 --------- d-----w c:program filesPuzzle Bobble 2x
2008-11-10 16:38 --------- d-----w c:program filesThe Learning Company
2008-05-10 06:34 284 ----a-w c:documents and settingsPaulApplication DataViewerApp.dat
1999-04-06 12:27 99,840 ----a-w c:program filesFichiers communsIRAABOUT.DLL
1998-12-09 02:53 70,144 ----a-w c:program filesFichiers communsIRAMDMTR.DLL
1998-12-09 02:53 48,640 ----a-w c:program filesFichiers communsIRALPTTR.DLL
1998-12-09 02:53 31,744 ----a-w c:program filesFichiers communsIRAWEBTR.DLL
1998-12-09 02:53 186,368 ----a-w c:program filesFichiers communsIRAREG.DLL
1998-12-09 02:53 17,920 ----a-w c:program filesFichiers communsIRASRIAL.DLL
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerURLSearchHooks]
"{631ac2d4-57b3-42b0-a148-da33b462c1a3}"= "c:program filesAbsolutist_Games bAbso.dll" [2007-07-31 1391640]
[HKEY_CLASSES_ROOTclsid{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
[HKEY_LOCAL_MACHINE~Browser Helper Objects{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
2007-07-31 16:33 1391640 --a------ c:program filesAbsolutist_Games bAbso.dll
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
"{631ac2d4-57b3-42b0-a148-da33b462c1a3}"= "c:program filesAbsolutist_Games bAbso.dll" [2007-07-31 1391640]
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerToolbarWebbrowser]
"{631AC2D4-57B3-42B0-A148-DA33B462C1A3}"= "c:program filesAbsolutist_Games bAbso.dll" [2007-07-31 1391640]
[HKEY_CLASSES_ROOTclsid{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"ctfmon.exe"="c:windowssystem32ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:program filesMessengermsmsgs.exe" [2008-04-14 1695232]
"msnmsgr"="c:program filesWindows LiveMessengermsnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NeroCheck"="c:windowssystem32NeroCheck.exe" [2001-07-09 155648]
"MaxtorOneTouch"="c:program filesMaxtorManagerAppOnetouch.exe" [2006-08-11 712704]
"mxomssmenu"="c:program filesMaxtorOneTouch Statusmaxmenumgr.exe" [2006-08-11 81920]
"ShStatEXE"="c:program filesNetwork AssociatesVirusScanSHSTAT.EXE" [2004-09-22 94208]
"McAfeeUpdaterUI"="c:program filesNetwork AssociatesCommon FrameworkUpdaterUI.exe" [2006-07-25 131072]
"Network Associates Error Reporting Service"="c:program filesFichiers communsNetwork AssociatesTalkBackTBMon.exe" [2003-10-07 147514]
"LogitechCommunicationsManager"="c:program filesFichiers communsLogiShrdLComMgrCommunications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:program filesLogitechQuickCamQuickcam.exe" [2008-08-14 2407184]
"SoundMan"="SOUNDMAN.EXE" [2002-07-12 c:windowsSOUNDMAN.EXE]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
c:documents and settingsPaulMenu D,marrerProgrammesD,marrage
Outil de notification Live Search.lnk - c:documents and settingsPaulApplication DataMicrosoftLive SearchNotification-LiveSearch.exe [2008-11-30 143360]
c:documents and settingsPaulMenu D,marrerProgrammesD,marrage
Outil de notification Live Search.lnk - c:documents and settingsPaulApplication DataMicrosoftLive SearchNotification-LiveSearch.exe [2008-11-30 143360]
c:documents and settingsPaulMenu D,marrerProgrammesD,marrage
Outil de notification Live Search.lnk - c:documents and settingsPaulApplication DataMicrosoftLive SearchNotification-LiveSearch.exe [2008-11-30 143360]
c:documents and settingsAll UsersMenu D,marrerProgrammesD,marrage
Logitech Desktop Messenger.lnk - c:program filesLogitechDesktop Messenger8876480ProgramLogitechDesktopMessenger.exe [2008-12-29 66864]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\WINDOWS\system32\dpvsetup.exe"=
"c:\Program Files\Messenger\msmsgs.exe"=
"c:\Program Files\Network Associates\Common Framework\FrameworkService.exe"=
"c:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"c:\Program Files\Windows Live\Messenger\livecall.exe"=
"c:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"=
"c:\Program Files\eMule\emule.exe"=
R1 NaiAvTdi1;NaiAvTdi1;c:windowssystem32driversmvstdi5x.sys [2008-11-29 58464]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:windowssystem32driverswg111v3.sys [2007-04-23 224896]
S3 Camdrv30;Philips ToUcam XS;c:windowssystem32driverscamdrv30.sys [2008-08-19 171264]
S3 DUBE100;D-Link DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:windowssystem32driversDUBE100.sys [2007-05-07 11935]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{de9ebfb4-d1b2-11dd-8f39-001e2a3a5234}]
ShellAutoRuncommand - E:InstallTomTomHOME.exe
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{f7130f0b-cde7-11dd-8f2e-001e2a3a5234}]
ShellAutoRuncommand - F:setupSNK.exe
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
Trusted Zone: *.windowsupdate.microsoft.com
Trusted Zone: download.windowsupdate.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:program filesLogitechDesktop Messenger8876480ProgramGAPlugProtocol-8876480.dll
O16 -: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} -
hxxp://bobtv.fr/download/cfweb_www.bobt ... module.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-07 21:20:12
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(652)
c:windowssystem32EntApi.dll
- - - - - - - > 'explorer.exe'(5908)
c:windowsTEMPlogishrdLVPrcInj01.dll
c:windowssystem32EntApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:program filesFichiers communsLogiShrdLVCOMSERLVComSer.exe
c:program filesFichiers communsLogiShrdLVMVFMLVPrcSrv.exe
c:program filesMaxtorMaxtor BackupMaxBackServiceInt.exe
c:program filesNetwork AssociatesCommon FrameworkFrameworkService.exe
c:program filesNetwork AssociatesVirusScanMcshield.exe
c:program filesNetwork AssociatesVirusScanVsTskMgr.exe
c:program filesNetwork AssociatesCommon Framework
aPrdMgr.exe
c:program filesMaxtorUtilsSyncServices.exe
c:program filesFichiers communsLogiShrdLVCOMSERLVComSer.exe
c:documents and settingsPaulApplication DataMicrosoftLive SearchMise-a-jour-LiveSearch.exe
c:program filesFichiers communsLogiShrdLQCVFXCOCIManager.exe
c:windowssystem32wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-01-07 21:25:27 - La machine a redémarré [Paul]
ComboFix-quarantined-files.txt 2009-01-07 20:24:49
Avant-CF: 126 738 235 392 octets libres
Après-CF: 126,855,553,024 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)WINDOWS
[operating systems]
c:cmdconsBOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)WINDOWS="Microsoft Windows XP