Et le dernier
ComboFix 08-07-27.5 - LuLu 2008-07-28 16:47:30.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.2.1252.1.1036.18.1458 [GMT 2:00]
Endroit: D:Documents and SettingsLuLuBureauComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
D:Program FilesFBrowserAdvisor
D:Program FilesFBrowsingAdvisor
D:Program FilesFBrowsingAdvisorIXPCOMEvents.xpt
D:Program FilesFBrowsingAdvisorLogo.png
D:Program FilesFBrowsingAdvisormain.db
D:Program FilesFBrowsingAdvisorunins000.dat
D:Program FilesFBrowsingAdvisorunins000.exe
D:Program FilesFBrowsingAdvisorXPCOMEvents.dll
K:Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Legacy_MEMSWEEP2
-------Service_MEMSWEEP2
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))))))))
.
2008-07-28 16:39 . 2008-07-28 16:39 2,384 --a------ D:WINDOWSsystem32 mp.reg
2008-07-28 16:38 . 2007-09-06 00:22 289,144 --a------ D:WINDOWSsystem32VCCLSID.exe
2008-07-28 16:38 . 2006-04-27 17:49 288,417 --a------ D:WINDOWSsystem32SrchSTS.exe
2008-07-28 16:38 . 2008-05-29 09:35 86,528 --a------ D:WINDOWSsystem32VACFix.exe
2008-07-28 16:38 . 2008-05-18 21:40 82,944 --a------ D:WINDOWSsystem32IEDFix.exe
2008-07-28 16:38 . 2008-07-02 13:33 82,432 --a------ D:WINDOWSsystem32IEDFix.C.exe
2008-07-28 16:38 . 2008-05-23 18:21 81,920 --a------ D:WINDOWSsystem32404Fix.exe
2008-07-28 16:38 . 2004-07-31 18:50 51,200 --a------ D:WINDOWSsystem32dumphive.exe
2008-07-28 16:38 . 2007-10-04 00:36 25,600 --a------ D:WINDOWSsystem32WS2Fix.exe
2008-07-28 16:21 . 2008-07-28 16:21 <REP> d-------- D:WINDOWSERUNT
2008-07-28 16:07 . 2008-07-28 16:33 <REP> d-------- D:SDFix
2008-07-26 10:49 . 2003-06-05 21:13 53,248 --a------ D:WINDOWSsystem32Process.exe
2008-07-26 10:48 . 2008-07-26 10:49 <REP> d-------- D:Program FilesNavilog1
2008-07-25 15:58 . 2008-07-25 15:58 <REP> d-------- D:Program FilesLavasoft
2008-07-25 15:58 . 2008-07-25 16:00 <REP> d-------- D:Documents and SettingsAll UsersApplication DataLavasoft
2008-07-23 20:08 . 2008-07-23 22:23 <REP> d-------- D:Program Filesa-squared Free
2008-07-19 16:39 . 2008-07-19 16:39 552 --a------ D:WINDOWSsystem32d3d8caps.dat
2008-07-19 15:40 . 2008-04-20 20:46 <REP> d--h----- D:Documents and SettingsAdministrateurVoisinage r,seau
2008-07-19 15:40 . 2008-04-20 20:46 <REP> d--h----- D:Documents and SettingsAdministrateurVoisinage d'impression
2008-07-19 15:40 . 2008-04-20 18:53 <REP> d--h----- D:Documents and SettingsAdministrateurModSles
2008-07-19 15:40 . 2008-04-20 20:46 <REP> d-------- D:Documents and SettingsAdministrateurMes documents
2008-07-19 15:40 . 2008-04-20 20:46 <REP> dr------- D:Documents and SettingsAdministrateurMenu D,marrer
2008-07-19 15:40 . 2008-04-20 20:46 <REP> d-------- D:Documents and SettingsAdministrateurFavoris
2008-07-19 15:40 . 2008-04-20 20:46 <REP> d-------- D:Documents and SettingsAdministrateurBureau
2008-07-19 15:40 . 2008-07-19 15:40 <REP> d-------- D:Documents and SettingsAdministrateur
2008-07-15 21:24 . 2008-07-17 17:59 <REP> d-------- D:Program FilesadslTV
2008-07-15 21:24 . 2008-07-15 21:24 <REP> d-------- D:Documents and SettingsLuLuApplication Datavlc
2008-07-14 20:31 . 2008-07-14 20:31 <REP> d-------- D:Program FilesAvira
2008-07-14 20:31 . 2008-07-14 20:31 <REP> d-------- D:Documents and SettingsAll UsersApplication DataAvira
2008-07-14 20:26 . 2008-07-25 18:19 <REP> d-------- D:Program FilesFrozen-Bubble
2008-07-14 20:22 . 2008-07-14 20:22 268 --ah----- D:sqmdata03.sqm
2008-07-14 20:22 . 2008-07-14 20:22 244 --ah----- D:sqmnoopt03.sqm
2008-07-13 14:32 . 2008-07-13 14:32 <REP> d-------- D:Program FilesSpybot - Search & Destroy
2008-07-13 14:32 . 2008-07-13 17:21 <REP> d-------- D:Documents and SettingsAll UsersApplication DataSpybot - Search & Destroy
2008-07-12 19:02 . 2008-07-12 19:02 <REP> d-------- D:Program FilesOpenAL
2008-07-12 19:02 . 2008-04-28 15:53 805,400 -ra------ D:WINDOWSsystem32 mpFC.tmp
2008-07-12 19:02 . 2008-04-28 15:53 805,400 -ra------ D:WINDOWSsystem32 mpFB.tmp
2008-07-12 19:02 . 2008-07-12 19:02 444,952 --a------ D:WINDOWSsystem32wrap_oal.dll
2008-07-12 19:02 . 2008-07-12 19:02 109,080 --a------ D:WINDOWSsystem32OpenAL32.dll
2008-07-12 18:35 . 2008-07-12 18:35 <REP> d-------- D:Program FilesCodemasters
2008-06-30 13:28 . 2008-06-30 13:28 244 --ah----- D:sqmnoopt02.sqm
2008-06-30 13:28 . 2008-06-30 13:28 232 --ah----- D:sqmdata02.sqm
2008-06-28 12:35 . 2008-06-28 12:36 <REP> d-------- D:Documents and SettingsAll UsersApplication DataApple Computer
2008-06-28 12:33 . 2008-06-28 12:33 <REP> d-------- D:Program FilesFichiers communsApple
2008-06-28 12:29 . 2008-06-28 12:29 <REP> d-------- D:Program FilesApple Software Update
2008-06-28 12:29 . 2008-06-28 12:29 <REP> d-------- D:Documents and SettingsAll UsersApplication DataApple
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 20:24 --------- d-----w D:Program FileseMule
2008-07-27 20:15 --------- d-----w D:Documents and SettingsLuLuApplication DataAzureus
2008-07-25 16:40 --------- d-----w D:Program FilesEA GAMES
2008-07-25 13:58 --------- d-----w D:Program FilesFichiers communsWise Installation Wizard
2008-07-21 19:42 --------- d-----w D:Documents and SettingsAll UsersApplication DataTrackMania
2008-07-18 15:03 --------- d-----w D:Documents and SettingsLuLuApplication Datagtk-2.0
2008-07-13 17:05 --------- d-----w D:Program FilesJava
2008-07-12 18:03 --------- d-----w D:Program FilesLimeWire
2008-07-12 16:35 --------- d--h--w D:Program FilesInstallShield Installation Information
2008-07-03 11:45 --------- d-----w D:Program FilesAzureus
2008-07-01 12:19 --------- d-----w D:Documents and SettingsLuLuApplication DataSkype
2008-07-01 12:18 --------- d-----w D:Documents and SettingsLuLuApplication DataskypePM
2008-06-28 10:36 --------- d-----w D:Program FilesQuickTime
2008-06-28 10:36 --------- d-----w D:Documents and SettingsLuLuApplication DataApple Computer
2008-06-24 20:50 --------- d-----w D:Documents and SettingsLuLuApplication DataNotepad++
2008-06-24 20:47 --------- d-----w D:Program FilesNotepad++
2008-06-20 17:41 247,808 ----a-w D:WINDOWSsystem32mswsock.dll
2008-06-20 10:45 360,320 ----a-w D:WINDOWSsystem32drivers cpip.sys
2008-06-20 10:44 138,368 ----a-w D:WINDOWSsystem32driversafd.sys
2008-06-20 09:52 225,920 ----a-w D:WINDOWSsystem32drivers cpip6.sys
2008-06-19 07:32 --------- d-----w D:Program FilesSkype
2008-06-19 07:32 --------- d-----w D:Program FilesFichiers communsSkype
2008-06-19 07:32 --------- d-----w D:Documents and SettingsAll UsersApplication DataSkype
2008-06-14 17:59 272,768 ------w D:WINDOWSsystem32driversthport.sys
2008-06-11 20:00 --------- d-----w D:Documents and SettingsLuLuApplication DataAhead
2008-06-10 20:20 --------- d-----w D:Program FilesFichiers communsAhead
2008-06-10 20:06 --------- d-----w D:Program FilesNero
2008-05-16 09:58 12,632 ----a-w D:WINDOWSsystem32lsdelete.exe
2008-05-07 05:15 1,293,824 ----a-w D:WINDOWSsystem32quartz.dll
2008-05-03 12:35 36,734 ----a-w D:WINDOWSsystem32OggDSuninst.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SuperCopier2.exe"="D:Program FilesSuperCopier2SuperCopier2.exe" [2006-07-07 18:45 1052672]
"ctfmon.exe"="D:WINDOWSsystem32ctfmon.exe" [2004-08-05 14:00 15360]
"DAEMON Tools Lite"="D:Program FilesDAEMON Tools Litedaemon.exe" [2008-04-01 11:39 486856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="D:Program FilesFichiers communsAheadLibNMBgMonitor.exe" [2006-04-21 17:03 94208]
"SpybotSD TeaTimer"="D:Program FilesSpybot - Search & DestroyTeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="D:WINDOWSsystem32NvCpl.dll" [2007-12-05 01:41 8523776]
"SmcService"="D:PROGRA~1SygateSPFsmc.exe" [2004-10-15 19:40 2577632]
"SunJavaUpdateSched"="D:Program FilesJavajre1.6.0_07injusched.exe" [2008-06-10 04:27 144784]
"PWRISOVM.EXE"="D:Program FilesPowerISOPWRISOVM.EXE" [2006-07-29 13:07 188416]
"PCSuiteTrayApplication"="D:Program FilesNokiaNokia PC Suite 6LaunchApplication.exe" [2006-11-28 14:12 222720]
"LVCOMSX"="D:WINDOWSsystem32LVCOMSX.EXE" [2005-07-19 17:32 221184]
"QuickTime Task"="D:Program FilesQuickTimeqttask.exe" [2008-05-27 10:50 413696]
"avgnt"="D:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" [2008-07-17 20:41 266497]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 D:WINDOWSsystem32
wiz.exe]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="D:WINDOWSsystem32CTFMON.EXE" [2004-08-05 14:00 15360]
"PcSync"="D:Program FilesNokiaNokia PC Suite 6PcSync2.exe" [2006-11-09 17:15 1634304]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.divxa32"= msaud32_divx.acm
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAcrobat Assistant 8.0]
--a------ 2006-10-22 23:24 620152 D:Program FilesAdobeAcrobat 8.0Acrobatacrotray.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 D:Program FilesAdobeReader 8.0Reader
eader_sl.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe_ID0EYTHM]
--a------ 2007-03-20 16:40 1884160 D:PROGRA~1FICHIE~1AdobeADOBEV~1ServerinVERSIO~2.EXE
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
--a------ 2004-08-05 14:00 15360 D:WINDOWSsystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechSoftwareUpdate]
--a------ 2005-06-08 14:44 196608 D:Program FilesLogitechVideoManifestEngine.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoRepair]
--a------ 2005-06-08 15:24 458752 D:Program FilesLogitechVideoISStart.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLogitechVideoTray]
--a------ 2005-06-08 15:14 217088 D:Program FilesLogitechVideoLogiTray.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMSMSGS]
--a------ 2004-10-13 18:24 1694208 D:Program FilesMessengermsmsgs.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
--a------ 2006-01-12 16:40 155648 D:Program FilesFichiers communsAheadLibNeroCheck.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
--a--c--- 2007-12-05 01:41 81920 D:WINDOWSsystem32
vmctray.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
--a------ 2008-05-27 10:50 413696 D:Program FilesQuickTimeQTTask.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRemoteControl]
--a------ 2004-11-02 20:24 32768 D:Program FilesCyberLinkPowerDVDPDVDServ.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSkype]
-ra------ 2008-05-30 15:54 21718312 D:Program FilesSkypePhoneSkype.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoundMan]
--a--c--- 2007-04-16 15:28 577536 D:WINDOWSsoundman.exe
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"D:\Program Files\MSN Messenger\msnmsgr.exe"=
"D:\Program Files\MSN Messenger\livecall.exe"=
"D:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"=
"D:\Program Files\Azureus\Azureus.exe"=
"D:\Program Files\LimeWire\LimeWire.exe"=
"D:\Program Files\Bonjour\mDNSResponder.exe"=
"D:\Program Files\Fichiers communs\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe"=
"D:\Program Files\Skype\Phone\Skype.exe"=
"D:\Program Files\Codemasters\GRID\GRID.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
.
Contenu du dossier 'Scheduled Tasks/Tches planifi,es'
2008-07-24 D:WINDOWSTasksAppleSoftwareUpdate.job
- D:Program FilesApple Software UpdateSoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-BitTorrent - D:Program FilesBitTorrentittorrent.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.fr/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Ajouter au fichier PDF existant - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convertir en Adobe PDF - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 -: Convertir la cible du lien en Adobe PDF - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 -: Convertir la cible du lien en un fichier PDF existant - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convertir la sélection en Adobe PDF - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
O8 -: Convertir la sélection en un fichier PDF existant - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convertir les liens sélectionnés en fichier Adobe PDF - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convertir les liens sélectionnés en un fichier PDF existant - D:Program FilesAdobeAcrobat 8.0AcrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: E&xporter vers Microsoft Excel - D:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-28 16:50:31
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
Balayage des fichiers cach,s ...
D:Documents and SettingsLuLuLocal SettingsApplication DataMicrosoftWindowsGameExplorer{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}PlayTasks1Les Sims™ 2 :
Boit@Look.lnk 1095 bytes hidden from API
Scan termin, avec succSs
Les fichiers cach,s: 1
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicesmchInjDrv]
"ImagePath"="??D:DOCUME~1LuLuLOCALS~1Tempmc22.tmp"
[HKEY_LOCAL_MACHINESystemControlSet001Servicesvsdatant]
"ImagePath"=""
.
------------------------ Other Running Processes ------------------------
.
D:Program FilesSygateSPFSmc.exe
D:Program FilesLavasoftAd-Awareaawservice.exe
D:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
D:Program Filesa-squared Freea2service.exe
D:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
D:Program FilesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
D:Program FilesBonjourmDNSResponder.exe
D:WINDOWSsystem32
vsvc32.exe
D:WINDOWSsystem32
undll32.exe
D:Program FilesBelkinUSB F5D7050Wireless UtilityBelkinwcui.exe
D:Program FilesPC Connectivity SolutionServiceLayer.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-28 16:56:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-28 14:56:01
Pre-Run: 31,196,454,912 octets libres
Post-Run: 31,939,538,944 octets libres
235 --- E O F --- 2008-07-09 10:51:46