ComboFix 08-07-14.2 - Nasred 2008-07-15 17:41:58.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.225 [GMT 2:00]
Endroit: C:Documents and SettingsNasredBureauComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:Program Fileswebmediaplayer
C:WINDOWSBMbfd2f54b.txt
C:WINDOWSeqex.exe
C:WINDOWSfsrpknov.dll
C:WINDOWSpack.epk
C:WINDOWSpskt.ini
C:WINDOWSsystem32ayHhOXyb.ini
C:WINDOWSsystem32ayHhOXyb.ini2
C:WINDOWSsystem32efcAPHXn.dll
C:WINDOWSsystem32hgGvUmjk.dll
C:WINDOWSsystem32iifgHxVN.dll
C:WINDOWSsystem32iwfulewb.dll
C:WINDOWSsystem32lhejqeeq.ini
C:WINDOWSsystem32NVxHgfii.ini
C:WINDOWSsystem32NVxHgfii.ini2
C:WINDOWSsystem32qeeqjehl.dll
C:WINDOWSsystem32sbjsteuvg.dat
C:WINDOWSsystem32sbjsteuvg_nav.dat
C:WINDOWSsystem32sbjsteuvg_navps.dat
C:WINDOWSsystem32utlhtdat.ini
C:WINDOWSsystem32xcjuaqgo.ini
.
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-06-15 to 2008-07-15 ))))))))))))))))))))))))))))))))))))
.
2008-07-15 00:23 . 2008-07-15 17:14 110,428 --a------ C:WINDOWSBMbfd2f54b.xml
2008-07-14 15:53 . 2008-06-14 19:59 272,768 --------- C:WINDOWSsystem32driversthport.sys
2008-07-14 15:53 . 2008-06-14 19:59 272,768 -----c--- C:WINDOWSsystem32dllcachethport.sys
2008-07-13 18:18 . 2008-07-13 18:18 64,324 --a------ C:WINDOWSsystem32 qbdbfkrndkahib.exe
2008-07-11 18:44 . 2004-08-19 16:10 91,648 --a------ C:WINDOWSsystem32kswdmcap.ax
2008-07-11 18:44 . 2004-08-19 16:10 91,648 --a--c--- C:WINDOWSsystem32dllcachekswdmcap.ax
2008-07-11 18:44 . 2004-08-19 16:10 61,952 --a------ C:WINDOWSsystem32kstvtune.ax
2008-07-11 18:44 . 2004-08-19 16:10 61,952 --a--c--- C:WINDOWSsystem32dllcachekstvtune.ax
2008-07-11 18:44 . 2004-08-19 16:09 54,784 --a------ C:WINDOWSsystem32vfwwdm32.dll
2008-07-11 18:44 . 2004-08-19 16:09 54,784 --a--c--- C:WINDOWSsystem32dllcachevfwwdm32.dll
2008-07-11 18:44 . 2004-08-19 16:10 43,008 --a------ C:WINDOWSsystem32ksxbar.ax
2008-07-11 18:44 . 2004-08-19 16:10 43,008 --a--c--- C:WINDOWSsystem32dllcacheksxbar.ax
2008-07-11 18:44 . 2004-08-19 16:10 28,672 --a------ C:WINDOWSsystem32vidcap.ax
2008-07-11 18:44 . 2004-08-19 16:10 28,672 --a--c--- C:WINDOWSsystem32dllcachevidcap.ax
2008-07-11 18:42 . 2000-10-31 12:00 307,200 --a------ C:WINDOWSvidcap32.Exe
2008-07-11 18:42 . 2003-05-15 17:17 61,440 --a------ C:WINDOWSsystem32VM31bSTI.dll
2008-07-11 18:42 . 2002-08-22 17:02 53,248 --a------ C:WINDOWSStillCap.exe
2008-07-11 18:42 . 2002-10-16 09:29 49,152 --a------ C:WINDOWSamcap.exe
2008-07-11 18:42 . 2004-06-09 15:37 40,960 --a------ C:WINDOWSVM_STI.EXE
2008-07-11 18:42 . 2004-03-08 17:00 24,576 --a------ C:WINDOWSsystem32RunSetup.dll
2008-07-11 18:42 . 2004-03-08 17:00 24,576 --a------ C:WINDOWSRunSetup.dll
2008-07-11 18:41 . 2008-07-11 18:41 <REP> d-------- C:WINDOWSCatRoot
2008-07-11 18:41 . 2008-07-11 18:41 <REP> d-------- C:Program FilesVimicro
2008-07-11 18:41 . 2004-06-18 16:52 233,557 --a------ C:WINDOWSsystem32VM31bPrp.Ax
2008-07-11 18:41 . 2002-08-22 16:34 147,456 --a------ C:WINDOWSVMCap.exe
2008-07-11 18:41 . 2004-08-17 11:44 91,263 --a------ C:WINDOWSsystem32driversusbVM31b.sys
2008-06-29 21:51 . 2008-06-29 21:51 58,594 --a------ C:WINDOWSsystem32mpx.exe
2008-06-26 03:33 . 2008-07-15 17:16 <REP> d-------- C:Documents and SettingsNasredApplication DataLimeWire
2008-06-26 03:31 . 2008-07-15 17:09 <REP> d-------- C:Program FilesLimeWire
2008-06-26 03:26 . 2008-07-03 20:33 <REP> d-------- C:Program FilesWindows Live Safety Center
2008-06-25 12:52 . 2008-06-25 12:52 287 --a------ C:WINDOWSgame.ini
2008-06-15 22:52 . 2008-06-15 22:53 <REP> d-------- C:Documents and SettingsAll UsersApplication DataSweetIM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-14 23:10 --------- d--h--w C:Program FilesInstallShield Installation Information
2008-07-14 22:57 --------- d-----w C:Program FilesKONAMI
2008-07-13 18:49 --------- d-----w C:Documents and SettingsNasredApplication DatauTorrent
2008-07-13 18:43 --------- d-----w C:Program FileseMule
2008-06-27 12:30 --------- d-----w C:Program FilesEA SPORTS
2008-05-20 18:29 --------- d-----w C:Program FilesMSECache
2008-05-17 13:01 --------- d-----w C:Program FilesiTunes
2008-05-17 13:00 --------- d-----w C:Program FilesiPod
2008-05-17 12:57 --------- d-----w C:Program FilesQuickTime
2008-05-17 12:37 --------- d-----w C:Documents and SettingsNasredApplication DataApple Computer
2008-05-17 12:34 --------- d-----w C:Program FilesSafari
2008-05-07 05:15 1,293,824 ----a-w C:WINDOWSsystem32quartz.dll
2008-04-23 04:16 826,368 ----a-w C:WINDOWSsystem32wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32ctfmon.exe" [2004-08-19 17:09 15360]
"MsnMsgr"="C:Program FilesWindows LiveMessengermsnmsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"HP Component Manager"="C:Program FilesHPhpcoretechhpcmpmgr.exe" [2003-12-22 09:38 241664]
"HPDJ Taskbar Utility"="C:WINDOWSsystem32spooldriversw32x863hpztsb10.exe" [2004-03-04 17:46 172032]
"DataLayer"="C:PROGRA~1FICHIE~1PCSuiteDATALA~1DATALA~1.EXE" [2004-08-24 14:30 986624]
"HP Software Update"="C:Program FilesHPHP Software UpdateHPWuSchd2.exe" [2007-03-11 21:34 49152]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_05injusched.exe" [2008-02-22 04:25 144784]
"PCSuiteTrayApplication"="C:PROGRA~1NokiaNOKIAP~1TRAYAP~1.EXE" [2004-08-17 17:04 148992]
"KONICA MINOLTA PagePro 1300WStatusDisplay"="C:WINDOWSsystem32MSTMON_N.EXE" [2004-11-25 03:04 151552]
"NeroFilterCheck"="C:WINDOWSsystem32NeroCheck.exe" [2001-07-09 12:50 155648]
"TkBellExe"="C:Program FilesFichiers communsRealUpdate_OB
ealsched.exe" [2008-03-25 10:27 185896]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2008-03-28 23:37 413696]
"BigDogPath"="C:WINDOWSVM_STI.EXE" [2004-06-09 15:37 40960]
"CARPService"="carpserv.exe" [2004-08-11 06:43 4608 C:WINDOWSsystem32carpserv.exe]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32CTFMON.EXE" [2004-08-19 17:09 15360]
"swg"="C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2007-07-13 18:57 68856]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"vidc.yv12"= yv12vfw.dll
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\Program Files\Activision\Call of Duty 2\CoD2MP_s.exe"=
"C:\Program Files\Real\RealPlayer\realplay.exe"=
"C:\Program Files\eMule\emule.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\IncrediMail\bin\ImpCnt.exe"=
"C:\Program Files\IncrediMail\bin\IncrediMail_Install.exe"=
"C:\Program Files\KONAMI\Pro Evolution Soccer 6\PES6.exe"=
"C:\WINDOWS\system32\dplaysvr.exe"=
"C:\Program Files\Mozilla Firefox\firefox.exe"=
"C:\Program Files\Messenger\msmsgs.exe"=
"C:\Program Files\KONAMI\Pro Evolution Soccer 2008\PES2008.exe"=
"C:\Program Files\Fichiers communs\AOL\Loader\aolload.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
"C:\Program Files\Bonjour\mDNSResponder.exe"=
"C:\Program Files\iTunes\iTunes.exe"=
"C:\Program Files\QuickTime\QuickTimePlayer.exe"=
"C:\Program Files\LimeWire\LimeWire.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"18233:TCP"= 18233:TCP:NortonAV
"17234:TCP"= 17234:TCP:NortonAV
"15373:TCP"= 15373:TCP:NortonAV
"14803:TCP"= 14803:TCP:NortonAV
"13418:TCP"= 13418:TCP:NortonAV
"17341:TCP"= 17341:TCP:NortonAV
"19676:TCP"= 19676:TCP:BitComet 19676 TCP
"19676:UDP"= 19676:UDP:BitComet 19676 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1254:UDP"= 1254:UDP:Windows Media Format SDK (iexplore.exe)
"1255:UDP"= 1255:UDP:Windows Media Format SDK (iexplore.exe)
"1270:UDP"= 1270:UDP:Windows Media Format SDK (iexplore.exe)
"1271:UDP"= 1271:UDP:Windows Media Format SDK (iexplore.exe)
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-05-16 01:16]
R2 MLPTDR_N;MLPTDR_N;C:WINDOWSsystem32MLPTDR_N.SYS [2003-07-19 03:55]
R3 ZSMC302;VIMICRO USB PC Camera;C:WINDOWSsystem32DriversusbVM31b.sys [2004-08-17 11:44]
S3 MEMSWEEP2;MEMSWEEP2;C:WINDOWSsystem3242.tmp []
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contenu du dossier 'Scheduled Tasks/Tches planifi,es'
"2008-07-05 21:17:02 C:WINDOWSTasksAppleSoftwareUpdate.job"
- C:Program FilesApple Software UpdateSoftwareUpdate.exe
"2008-07-04 15:15:00 C:WINDOWSTasksMaintenance en 1 clic.job"
- C:Program FilesTuneUp Utilities 2006SystemOptimizer.exe
"2008-03-09 06:58:04 C:WINDOWSTasksUniblue SpeedUpMyPC Nag.job"
- C:Program FilesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe
"2008-03-09 06:58:03 C:WINDOWSTasksUniblue SpeedUpMyPC.job"
- C:Program FilesUniblueSpeedUpMyPC 3SpeedUpMyPC.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-L07FXLRD_5279640 - C:Program FilesMicrosoft EtudesMicrosoft Encarta 2007 - Etudes DVDEDICT.EXE
HKCU-Run-Performance Center - C:Program FilesAscentivePerformance CenterApcMain.exe
HKCU-Run-L07FXLRD_3748218 - C:Program FilesMicrosoft EtudesMicrosoft Encarta 2007 - Etudes DVDEDICT.EXE
HKCU-Run-BitComet - C:Program FilesBitCometBitComet.exe
HKLM-Run-WinampAgent - C:Program FilesWinampwianmpa.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-15 17:54:29
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
Balayage des fichiers cach,s ...
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicesMEMSWEEP2]
"ImagePath"="??C:WINDOWSsystem3242.tmp"
.
------------------------ Other Running Processes ------------------------
.
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
C:Program FilesBonjourmDNSResponder.exe
C:WINDOWSsystem32driversCDANTSRV.EXE
C:Program FilesFichiers communsMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32
undll32.exe
C:PROGRA~1FICHIE~1PCSuiteServicesSERVIC~1.EXE
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesHPhpcoretechcomphptskmgr.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-15 18:08:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-15 16:07:44
Pre-Run: 17,102,692,352 octets libres
Post-Run: 18,919,174,144 octets libres
197 --- E O F --- 2008-07-14 20:33:08