ComboFix 08-08-04.01 - Administrateur 2008-08-05 11:27:44.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1546 [GMT 2:00]
Endroit: C:Documents and SettingsAdministrateurBureauComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:Documents and SettingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr0.dat
C:Documents and SettingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr1.dat
C:Program FilesHewlett-PackardIAMBinASWLNPkg.dll
E:Autorun.inf
----- BITS: Possible sites infect,s -----
http://ftp.hp.com.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_ASBroker
-------Service_ASBroker
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-07-05 to 2008-08-05 ))))))))))))))))))))))))))))))))))))
.
2008-08-02 13:19 . 2008-08-03 21:51 <REP> d-------- C:Program FilesNavilog1
2008-08-01 22:18 . 2008-08-01 22:18 <REP> d-------- C:Program FilesAd-Aware
2008-08-01 22:18 . 2008-08-01 22:22 <REP> d-------- C:Documents and SettingsAll UsersApplication DataLavasoft
2008-08-01 22:17 . 2008-08-01 22:17 <REP> d-------- C:Program FilesFichiers communsWise Installation Wizard
2008-08-01 21:41 . 2008-08-01 21:42 <REP> d-------- C:Program FilesSpybot - Search & Destroy
2008-08-01 21:41 . 2008-08-01 22:09 <REP> d-------- C:Documents and SettingsAll UsersApplication DataSpybot - Search & Destroy
2008-07-29 13:03 . 2008-08-01 08:45 <REP> d-------- C:Program FileseMule
2008-07-29 12:56 . 2008-07-29 14:48 <REP> d-------- C:Program FilesuTorrent
2008-07-29 12:55 . 2008-08-01 21:30 <REP> d-------- C:Documents and SettingsAdministrateurApplication DatauTorrent
2008-07-22 00:29 . 2008-07-22 00:29 <REP> d-------- C:Documents and SettingsAdministrateur.jnlp-applet
2008-07-20 22:52 . 2008-07-20 22:52 <REP> d-------- C:Documents and SettingsAdministrateurApplication Datadvdcss
2008-07-20 22:48 . 2008-07-20 22:48 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataInterVideo
2008-07-19 01:40 . 2008-07-19 01:40 <REP> d-------- C:WINDOWSSQLTools9_KB948109_ENU
2008-07-19 01:38 . 2008-07-19 01:38 <REP> d-------- C:WINDOWSSQL9_KB948109_ENU
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 09:15 --------- d-----w C:Program FilesMozilla Thunderbird
2008-08-05 07:54 --------- d-----w C:Program FilesVinciDC
2008-08-05 07:54 --------- d-----w C:Program FilesDiffuse
2008-08-01 16:08 --------- d-----w C:Documents and SettingsAdministrateurApplication DataNotepad++
2008-08-01 14:31 --------- d-----w C:Program FilesNotepad++
2008-07-31 18:17 --------- d-----w C:Documents and SettingsAdministrateurApplication DataOpenOffice.org2
2008-07-28 21:23 --------- d-----w C:Documents and SettingsAdministrateurApplication Datagtk-2.0
2008-07-28 18:00 --------- d-----w C:Program FilesSyncBack
2008-07-25 08:27 --------- d-----w C:Program FilesJava
2008-07-18 23:40 --------- d-----w C:Program FilesMicrosoft SQL Server
2008-06-27 16:31 --------- d-----w C:Program FilesLRose
2008-06-23 17:27 --------- d-----w C:Program FilesThe GodFather
2008-06-20 10:45 360,320 ----a-w C:WINDOWSsystem32drivers cpip.sys
2008-06-20 10:44 138,368 ----a-w C:WINDOWSsystem32driversafd.sys
2008-06-20 09:52 225,920 ----a-w C:WINDOWSsystem32drivers cpip6.sys
2008-06-14 17:59 272,768 ------w C:WINDOWSsystem32driversthport.sys
2008-06-06 21:27 --------- d-----w C:Program FilesGuitar FX BOX 2.7
2007-10-14 16:57 56 --sha-w C:WINDOWSSMINSThpboot.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"Gadwin PrintScreen"="C:Program FilesGadwin SystemsPrintScreenPrintScreen.exe" [2007-08-20 10:42 495616]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="C:WINDOWSsystem32NvCpl.dll" [2007-05-25 14:07 8429568]
"NvMediaCenter"="C:WINDOWSsystem32NvMcTray.dll" [2007-05-25 14:07 81920]
"SoundMAXPnP"="C:Program FilesAnalog DevicesCoresmax4pnp.exe" [2007-01-05 18:36 872448]
"PDF Complete"="C:Program FilesPDF Completepdfsty.exe" [2007-05-08 08:38 331552]
"PTHOSTTR"="C:Program FilesHewlett-PackardHP ProtectTools Security ManagerPTHOSTTR.EXE" [2007-01-09 15:52 145184]
"SynTPEnh"="C:Program FilesSynapticsSynTPSynTPEnh.exe" [2007-01-12 15:36 827392]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_07injusched.exe" [2008-06-10 04:27 144784]
"CognizanceTS"="C:PROGRA~1HEWLET~1IAMBinASTSVCC.dll" [2003-12-22 19:12 17920]
"Recguard"="C:WINDOWSSminstRecguard.exe" [2005-12-20 16:51 1187840]
"Reminder"="C:WINDOWSCreatorRemind_XP.exe" [2006-03-09 17:38 806912]
"Scheduler"="C:WINDOWSSMINSTScheduler.exe" [2006-10-09 11:23 697976]
"HP Software Update"="c:Program FilesHpHP Software UpdateHPWuSchd2.exe" [2005-02-16 23:11 49152]
"Cpqset"="C:Program FilesHewlett-PackardDefault Settingscpqset.exe" [2007-05-03 10:52 57344]
"AccelerometerSysTrayApplet"="C:WINDOWSsystem32AccelerometerSt.exe" [2007-01-24 14:28 124928]
"HPWWANGSAssistant"="c:SWSetupHPQWWANHPWWanGSAssistant.exe" [2007-05-03 16:33 4032056]
"Symantec PIF AlertEng"="C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" [2007-03-12 10:22 517768]
"FileZilla Server Interface"="C:Program FilesFileZilla ServerFileZilla Server Interface.exe" [2007-02-27 16:55 937984]
"WatchDog"="C:Program FilesInterVideoDVD CheckDVDCheck.exe" [2007-05-23 11:00 192512]
"nwiz"="nwiz.exe" [2007-05-25 14:07 1626112 C:WINDOWSsystem32
wiz.exe]
"MsmqIntCert"="mqrt.dll" [2007-07-06 14:50 177152 C:WINDOWSsystem32mqrt.dll]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32CTFMON.EXE" [2004-08-05 10:00 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon
otifyDeviceNP]
2007-04-30 08:19 49152 C:WINDOWSsystem32DeviceNP.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=APSHook.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\WINDOWS\system32\mqsvc.exe"=
"C:\WINDOWS\SMINST\Scheduler.exe"=
"C:\Program Files\Diffuse\diffuse-server.exe"=
"C:\Program Files\wamp\Apache2\bin\httpd.exe"=
"C:\Program Files\FileZilla Server\FileZilla server.exe"=
"C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe"=
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe"=
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe"=
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe"=
"C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe"=
"C:\Program Files\THQ\Gas Powered Games\Supreme Commander\bin\SupremeCommander.exe"=
"C:\Program Files\X-Chat 2\xchat.exe"=
"C:\Program Files\Maple 9\bin.win\mserver.exe"=
"C:\Program Files\Messenger\msmsgs.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
"C:\Program Files\VinciDC\DCPlusPlus.exe"=
"C:\Program Files\Copytracker\apache\bin\apache.exe"=
"C:\Program Files\Copytracker\mysql\bin\mysqld.exe"=
"C:\Program Files\Microsoft Games\Age of Empires II\empires2.exe"=
"C:\WINDOWS\system32\dpvsetup.exe"=
"C:\Program Files\uTorrent\uTorrent.exe"=
"C:\Program Files\eMule\emule.exe"=
"C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"=
"C:\Program Files\Team17\Worms Armageddon\wa.exe"=
"C:\Program Files\WinHTTrack\WinHTTrack.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"5972:TCP"= 5972:TCP:Port TCP pour emule
"31807:UDP"= 31807:UDP:PORT UDP pour Emule
R0 SafeBoot;SafeBoot;C:WINDOWSsystem32driversSafeBoot.sys [2007-04-26 19:23]
R0 SbAlg;SbAlg;C:WINDOWSsystem32driversSbAlg.sys [2006-10-09 13:31]
R0 SbFsLock;SbFsLock;C:WINDOWSsystem32driversSbFsLock.sys [2007-03-29 16:54]
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-07-19 16:35]
R1 RsvLock;RsvLock;C:WINDOWSsystem32driversRsvLock.sys [2007-04-26 19:23]
R2 ASChannel;Canal de communication local;C:WINDOWSSystem32svchost.exe [2004-08-05 10:00]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 16:37]
R2 HpFkCryptService;Drive Encryption Service;c:Program FilesHewlett-PackardDrive EncryptionHpFkCrypt.exe [2007-04-27 10:58]
R2 pdfcDispatcher;PDF Document Manager;C:Program FilesPDF Completepdfsvc.exe [2007-05-08 08:38]
R2 SWIHPWMI;SWIHPWMI;C:Program FilesHPQSharedSierra WirelessWin32UnicodeSWIHPWMI.exe [2006-12-04 16:13]
R3 IFXTPM;IFXTPM;C:WINDOWSsystem32DRIVERSIFXTPM.SYS [2007-04-04 21:16]
R3 rismc32;RICOH Smart Card Reader;C:WINDOWSsystem32DRIVERS
ismc32.sys [2006-12-20 03:08]
S3 DAMDrv;DAMDrv;C:WINDOWSsystem32DRIVERSDAMDrv.sys [2007-04-23 13:13]
S3 FLCDLOCK;Verrouillage des périphériques / Audition HP ProtectTools;C:WINDOWSsystem32flcdlock.exe [2007-04-30 08:28]
S3 usbscan;Pilote de scanneur USB;C:WINDOWSsystem32DRIVERSusbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2004-08-03 23:08]
S3 wampapache;wampapache;C:Program Fileswampapache2inhttpd.exe [2007-01-10 01:17]
S3 wampmysqld;wampmysqld;C:Program Fileswampmysqlinmysqld-nt.exe [2007-05-04 11:00]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
Cognizance REG_MULTI_SZ ASBroker ASChannel
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{26a48d29-6c4b-11dc-924f-0017a4ea814c}]
ShellAutoRuncommand - G:m9j.com
ShellexploreCommand - G:m9j.com
ShellopenCommand - G:m9j.com
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:Program FilesFichiers communsLightScribeLSRunOnce.exe"
.
Contenu du dossier 'Scheduled Tasks/Tches planifi,es'
2008-07-28 C:WINDOWSTasksSyncBack Centrale.job
- C:Program FilesSyncBackSyncBack.exe [2006-10-30 16:16]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:Documents and SettingsAdministrateurApplication DataMozillaFirefoxProfilesf31zeqbv.default
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.netvibes.com/**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-05 11:34:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
Cpqset = C:Program FilesHewlett-PackardDefault Settingscpqset.exe????????T??????????????|?M?|?????M?|&?@
Balayage des fichiers cach,s ...
Scan termin, avec succSs
Les fichiers cach,s: 0
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicespdfcDispatcher]
"ImagePath"="C:Program FilesPDF Completepdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
------------------------ Other Running Processes ------------------------
.
C:Program FilesWIDCOMMBluetooth Softwareintwdins.exe
C:Program FilesAd-Awareaawservice.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:WINDOWSsystem32scardsvr.exe
C:WINDOWSsystem32msdtc.exe
C:Program FilesFileZilla ServerFileZilla server.exe
C:Program FilesFichiers communsInterVideoRegMgriviRegMgr.exe
C:Program FilesFichiers communsLightScribeLSSrvc.exe
C:Program FilesMicrosoft SQL ServerMSSQL.1MSSQLBinnsqlservr.exe
C:WINDOWSsystem32
vsvc32.exe
C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
C:Program FilesMicrosoft SQL Server90Sharedsqlbrowser.exe
C:Program FilesMicrosoft SQL Server90Sharedsqlwriter.exe
C:WINDOWSsystem32mqsvc.exe
C:Program FilesHewlett-PackardSharedhpqWmiEx.exe
C:WINDOWSsystem32mqtgsvc.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:WINDOWSsystem32
undll32.exe
C:Program FilesHewlett-PackardHP Wireless AssistantHPWAMain.exe
C:Program FilesHewlett-PackardHP Quick Launch ButtonsQLBCTRL.exe
C:Program FilesHewlett-PackardSharedHpqToaster.exe
C:Program FilesWIDCOMMBluetooth SoftwareBTTray.exe
C:Program FilesVinciDCDCPlusPlus.exe
C:PROGRA~1WIDCOMMBLUETO~1BTSTAC~1.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-05 11:39:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-05 09:39:05
Pre-Run: 18,999,377,920 octets libres
Post-Run: 19,068,010,496 octets libres
217 --- E O F --- 2008-07-23 16:08:04