ComboFix 08-11-18.A2 - Grisselin-Van Stalle 2008-11-19 23:35:14.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1558 [GMT 1:00]
Lancé depuis: c:documents and settingsGrisselin-Van StalleBureaufix.exe
Commutateurs utilisés :: c:documents and settingsGrisselin-Van StalleBureauCFScript.txt
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
FILE ::
c:windowsprefetch161328.EXE-1761EBD1.pf
c:windowsprefetch166953.EXE-3AA5AA62.pf
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:windowsprefetch161328.EXE-1761EBD1.pf
c:windowsprefetch166953.EXE-3AA5AA62.pf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-19 au 2008-11-19 ))))))))))))))))))))))))))))))))))))
.
2008-11-19 21:57 . 2008-11-19 21:57 200 --a------ C:sqmnoopt10.sqm
2008-11-19 21:57 . 2008-11-19 21:57 200 --a------ C:sqmdata10.sqm
2008-11-19 13:50 . 2008-11-19 13:50 200 --a------ C:sqmnoopt09.sqm
2008-11-19 13:50 . 2008-11-19 13:50 200 --a------ C:sqmdata09.sqm
2008-11-19 07:50 . 2008-11-19 07:50 236 --a------ C:sqmdata08.sqm
2008-11-19 07:50 . 2008-11-19 07:50 200 --a------ C:sqmnoopt08.sqm
2008-11-18 23:25 . 2008-11-18 23:25 <REP> d-------- c:documents and settingsGrisselin-Van StalleApplication DataWindows Live Writer
2008-11-18 23:20 . 2008-11-18 23:20 200 --a------ C:sqmnoopt07.sqm
2008-11-18 23:20 . 2008-11-18 23:20 200 --a------ C:sqmdata07.sqm
2008-11-18 23:13 . 2008-11-18 23:13 236 --a------ C:sqmdata06.sqm
2008-11-18 23:13 . 2008-11-18 23:13 200 --a------ C:sqmnoopt06.sqm
2008-11-18 22:12 . 2008-11-18 22:12 200 --a------ C:sqmnoopt05.sqm
2008-11-18 22:12 . 2008-11-18 22:12 200 --a------ C:sqmdata05.sqm
2008-11-18 21:52 . 2008-11-18 22:10 <REP> d-------- C:SDFix
2008-11-18 21:48 . 2008-11-19 22:43 <REP> d-------- C:ToolBar SD
2008-11-18 21:42 . 2008-11-19 14:09 <REP> d-------- c:program filesFindyKill
2008-11-18 21:31 . 2008-11-18 21:31 200 --a------ C:sqmnoopt04.sqm
2008-11-18 21:31 . 2008-11-18 21:31 200 --a------ C:sqmdata04.sqm
2008-11-18 20:05 . 2008-11-18 20:05 <REP> d-------- c:program filesMalwarebytes' Anti-Malware
2008-11-18 20:05 . 2008-11-18 20:05 <REP> d-------- c:documents and settingsGrisselin-Van StalleApplication DataMalwarebytes
2008-11-18 20:05 . 2008-11-18 20:05 <REP> d-------- c:documents and settingsAll UsersApplication DataMalwarebytes
2008-11-18 20:05 . 2008-10-22 16:10 38,496 --a------ c:windowssystem32driversmbamswissarmy.sys
2008-11-18 20:05 . 2008-10-22 16:10 15,504 --a------ c:windowssystem32driversmbam.sys
2008-11-18 19:03 . 2008-11-18 19:03 200 --a------ C:sqmnoopt03.sqm
2008-11-18 19:03 . 2008-11-18 19:03 200 --a------ C:sqmdata03.sqm
2008-11-18 05:26 . 2008-11-18 05:26 54,156 --ah----- c:windowsQTFont.qfn
2008-11-18 05:26 . 2008-11-18 05:26 1,409 --a------ c:windowsQTFont.for
2008-11-17 18:42 . 2008-11-17 18:42 200 --a------ C:sqmnoopt02.sqm
2008-11-17 18:42 . 2008-11-17 18:42 200 --a------ C:sqmdata02.sqm
2008-11-17 18:27 . 2008-11-17 18:27 200 --a------ C:sqmnoopt01.sqm
2008-11-17 18:27 . 2008-11-17 18:27 200 --a------ C:sqmdata01.sqm
2008-11-17 05:33 . 2008-11-17 05:33 200 --a------ C:sqmnoopt00.sqm
2008-11-17 05:33 . 2008-11-17 05:33 200 --a------ C:sqmdata00.sqm
2008-11-16 23:35 . 2008-11-16 23:35 <REP> d-------- c:program filesTrend Micro
2008-11-16 20:38 . 2008-11-16 20:38 81,465 --a------ c:windowssystem32driversklif.cab
2008-11-16 20:34 . 2008-11-16 20:34 <REP> d-------- c:documents and settingsAll UsersApplication DataKaspersky Lab Setup Files
2008-11-16 13:57 . 2008-11-16 14:29 <REP> d-------- c:program filesRegCleaner
2008-11-13 19:52 . 2008-11-13 19:52 <REP> d-------- c:program filesSelor
2008-11-13 19:52 . 2008-11-13 19:52 <REP> d-------- c:documents and settingsGrisselin-Van StalleWINDOWS
2008-11-06 11:40 . 2008-11-06 11:40 <REP> d-------- c:program filesWestern Digital
2008-11-06 11:40 . 2008-11-06 11:40 <REP> d-------- c:program filesFichiers communseSellerate
2008-11-06 11:39 . 2008-11-06 11:39 <REP> d-------- c:program filesWestern Digital Technologies
2008-11-06 11:39 . 2008-11-06 11:40 <REP> d---s---- c:documents and settingsAll UsersApplication DataMemeo
2008-11-03 17:53 . 2008-11-03 17:53 <REP> d-------- c:program filesCommon Files
2008-11-03 09:23 . 2008-11-03 09:23 <REP> d-------- c:program filesFichiers communsArcSoft
2008-11-03 09:22 . 2003-09-19 15:45 21,248 --a------ c:windowssystem32driverspfc.sys
2008-10-28 22:58 . 2008-11-19 23:31 <REP> d-------- c:documents and settingsGrisselin-Van StalleTracing
2008-10-28 22:57 . 2008-10-28 22:57 <REP> d-------- c:program filesMicrosoft Office Outlook Connector
2008-10-28 22:55 . 2008-09-04 22:03 56,344 --a------ c:windowssystem32driversfssfltr.sys
2008-10-28 22:47 . 2008-10-28 22:47 <REP> d-------- c:program filesMicrosoft
2008-10-28 22:37 . 2008-10-28 22:37 <REP> d-------- c:program filesFichiers communsWindows Live
2008-10-28 08:42 . 2008-10-28 08:42 371 --a------ c:windowsJMC_1000_V0601.INI
2008-10-28 08:41 . 2008-10-28 08:42 <REP> d-------- C:educampa
2008-10-26 14:21 . 2008-10-26 14:22 25,992 --a------ c:windowssystem32pgdfgsvc.exe
2008-10-23 19:19 . 2008-11-08 22:33 <REP> d-------- c:program filesvanBasco's Karaoke Player
2008-10-19 17:02 . 2008-10-19 17:02 <REP> d-------- c:program filesUBISOFT
2008-10-19 16:49 . 2008-10-19 16:49 <REP> d-------- c:documents and settingsGrisselin-Van StalleApplication DataEncyclopedie Hachette
2008-10-19 16:47 . 2008-10-19 16:47 <REP> d-------- c:documents and settingsGrisselin-Van StalleApplication Dataubi.com
2008-10-19 16:47 . 2001-07-30 17:03 185,344 --a------ c:windowspatchw32.dll
2008-10-19 16:46 . 2008-10-19 16:46 <REP> d-------- c:program filesubi.com
2008-10-19 16:46 . 2008-10-19 16:46 <REP> d-------- c:program filesFichiers communsPocketSoft
2008-10-19 16:35 . 2008-10-19 16:35 <REP> d-------- c:documents and settingsAll UsersApplication DataQuickTime
2008-10-19 16:30 . 2008-10-19 16:30 <REP> d-------- c:program filesHachette
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 21:58 7,168 -csha-w c:program filesThumbs.db
2008-11-19 20:38 --------- d-----w c:program filesSPAMfighter
2008-11-18 18:03 --------- d-----w c:program filesBearShare Applications
2008-11-17 17:31 --------- d-----w c:program filesAlwil Software
2008-11-16 23:33 --------- d-----w c:program fileseMule
2008-11-16 22:30 --------- d-----w c:documents and settingsAll UsersApplication Dataavg7
2008-11-16 13:47 --------- d-----w c:program filesGoogle
2008-11-08 22:26 --------- d-----w c:program filesAbbyy FineReader 6.0 Sprint
2008-11-06 10:40 --------- d--h--w c:program filesInstallShield Installation Information
2008-11-03 08:25 --------- d-----w c:documents and settingsGrisselin-Van StalleApplication DataArcSoft
2008-11-03 08:19 --------- d-----w c:program filesArcSoft
2008-10-28 21:55 --------- d-----w c:program filesWindows Live
2008-10-28 21:51 --------- d-----w c:program filesWindows Live Toolbar
2008-10-26 08:45 --------- d-----w c:documents and settingsGrisselin-Van StalleApplication DataBearShare
2008-10-25 17:58 --------- d-----w c:documents and settingsAll UsersApplication DataMicrosoft Help
2008-10-15 19:41 --------- d-----w c:documents and settingsGrisselin-Van StalleApplication DataU3
2008-10-11 11:45 --------- d-----w c:program filesPopCap Games
2008-10-05 13:58 --------- d-----w c:documents and settingsGrisselin-Van StalleApplication DataFaxCtr
2008-09-05 15:04 288,768 ----a-w c:windowsWLXPGSS.SCR
2006-12-03 21:39 3,382,784 -csha-w c:program filesehthumbs.db
2006-11-30 21:01 0 -c----w c:documents and settingsGrisselin-Van StalleApplication Datawklnhst.dat
2006-11-14 16:36 774,144 -c--a-w c:program filesRngInterstitial.dll
2006-11-11 16:52 49 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb7428.dat
2006-11-11 16:52 337 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb1942.dat
2006-11-11 15:26 76 -c--a-w c:program files
etopts
2006-11-11 15:26 32 -c--a-w c:program filesSpecSelection.bin
2006-11-10 20:12 6,144 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb1125.dat
2006-11-08 21:23 987,056 -c--a-w c:program filesOPTIONS
2006-11-08 21:23 6,336 -c--a-w c:program filesBESTTIMES_GHOSTS
2006-11-08 21:23 49,264 -c--a-w c:program filesCHAMPIONSHIP_SLOT_3
2006-11-08 07:36 9,216 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb7804.dat
2006-11-08 07:36 20,480 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb5257.dat
2006-11-08 07:36 0 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb9527.dat
2006-11-08 07:25 0 -c--a-w c:documents and settingsgilles Van stalleApplication Datainternaldb41.dat
2006-11-06 20:42 41,306 -c--a-w c:program filesGhostReplay40
2006-11-06 20:36 24,452 -c--a-w c:program filesGhostReplay66
2006-11-06 20:30 35,204 -c--a-w c:program filesGhostReplay61
2006-11-06 20:26 38,420 -c--a-w c:program filesGhostReplay75
2006-11-06 20:22 31,834 -c--a-w c:program filesGhostReplay74
2006-11-06 20:13 38,234 -c--a-w c:program filesGhostReplay00
2006-11-06 19:03 34,990 -c--a-w c:program filesGhostReplay32
2006-11-04 06:48 35,702 -c--a-w c:program filesGhostReplay20
2006-11-03 20:10 40,366 -c--a-w c:program filesGhostReplay60
2006-11-03 20:05 17,042 -c--a-w c:program filesGhostReplay36
2006-11-03 20:02 32,728 -c--a-w c:program filesGhostReplay70
2006-11-03 11:13 30,838 -c--a-w c:program filesGhostReplay50
2006-11-01 09:24 49,264 -c--a-w c:program filesCHAMPIONSHIP_SLOT_2
2006-11-01 05:27 49,264 -c--a-w c:program filesCHAMPIONSHIP_SLOT_1
2006-10-31 21:21 251 -c--a-w c:program fileswt3d.ini
2006-10-31 21:10 0 -c--a-w c:documents and settingsgilles Van stalleApplication Datawklnhst.dat
2004-03-22 13:01 1,892,352 -c--a-w c:program filescmr4.exe
2004-03-02 13:46 793 -c--a-w c:program files
etwork.cfg
2003-12-01 15:39 2,998 -c--a-w c:program filesCMR4.ico
2003-09-02 15:28 53,248 -c--a-r c:program filesMathPIII.dll
2003-09-02 15:28 53,248 -c--a-r c:program filesMathCPU.dll
2003-09-02 15:28 53,248 -c--a-r c:program filesMath3dNow.dll
2003-09-02 15:28 208,896 -c--a-r c:program filesMathPIIId.dll
2003-09-02 15:28 200,704 -c--a-r c:program filesMathCPUd.dll
2003-09-02 15:28 188,416 -c--a-r c:program filesMath3dNowd.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32ctfmon.exe" [2006-03-25 15360]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"ehTray"="c:windowsehomeehtray.exe" [2005-08-05 64512]
"hpWirelessAssistant"="c:program fileshpqHP Wireless AssistantHP Wireless Assistant.exe" [2006-05-03 458752]
"igfxtray"="c:windowssystem32igfxtray.exe" [2006-03-22 94208]
"igfxhkcmd"="c:windowssystem32hkcmd.exe" [2006-03-22 77824]
"igfxpers"="c:windowssystem32igfxpers.exe" [2006-03-22 118784]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2006-06-17 794713]
"RecGuard"="c:windowsSMINSTRecGuard.exe" [2005-10-11 1187840]
"Reminder"="c:windowsCREATORRemind_XP.exe" [2006-02-09 643072]
"QuickTime Task"="c:program filesQuickTimeqttask.exe" [2008-03-28 413696]
"Adobe Reader Speed Launcher"="c:program filesAdobeReader 8.0ReaderReader_sl.exe" [2008-10-15 39792]
"MsmqIntCert"="mqrt.dll" [2007-07-06 c:windowssystem32mqrt.dll]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-02 c:windowssystem32CHDAudPropShortcut.exe]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2006-03-25 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.MJPG"= mtkjpeg.dll
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetcontrollsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"c:\Program Files\Messenger\msmsgs.exe"=
"c:\WINDOWS\system32\mqsvc.exe"=
"c:\Program Files\IncrediMail\bin\IMApp.exe"=
"c:\Program Files\IncrediMail\bin\ImpCnt.exe"=
"c:\Program Files\IncrediMail\bin\IncMail.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"=
"c:\WINDOWS\system32\spool\drivers\w32x86\3\lxdipswx.exe"=
"c:\WINDOWS\system32\lxdicoms.exe"=
"c:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"=
"c:\Program Files\Lexmark 3500-4500 Series\App4r.exe"=
"c:\Program Files\Abbyy FineReader 6.0 Sprint\scan\scanman6.exe"=
"c:\Program Files\Lexmark Fax Solutions\FaxCtr.exe"=
"c:\WINDOWS\system32\lxdicfg.exe"=
"c:\WINDOWS\system32\spool\drivers\w32x86\3\lxditime.exe"=
"c:\WINDOWS\system32\spool\drivers\w32x86\3\lxdiwbgw.exe"=
"c:\WINDOWS\system32\spool\drivers\w32x86\3\lxdijswx.exe"=
"c:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"=
"c:\Program Files\Microsoft Office\Office12\GROOVE.EXE"=
"c:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"=
"c:\Program Files\iTunes\iTunes.exe"=
"c:\WINDOWS\system32\lxdiih.exe"=
"c:\Program Files\Windows Live\Messenger\wlcsdk.exe"=
"c:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
R2 fssfltr;FssFltr;c:windowssystem32DRIVERSfssfltr.sys [2008-10-28 56344]
R2 lxdi_device;lxdi_device;c:windowssystem32lxdicoms.exe -service []
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:windowsSystem32spoolDRIVERSW32X863\lxdiserv.exe [2008-01-03 99248]
R2 SPAMfighter Update Service;SPAMfighter Update Service;"c:program filesSPAMfightersfus.exe" [2008-07-29 184968]
R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:windowssystem32Drivers5U870CAP.sys [2006-06-06 61952]
S3 AF15BDA;AF9015 BDA Filter;c:windowssystem32DriversAF15BDA.sys [2008-02-21 264448]
S3 fsssvc;Windows Live Contrôle parental;"c:program filesWindows LiveFamily Safetyfsssvc.exe" [2008-09-04 512536]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{1da20a5c-9af1-11dd-8939-0018de344e65}]
ShellAutoRuncommand - F:LaunchU3.exe
.
Contenu du dossier 'Tâches planifiées'
2008-11-15 c:windowsTasksAppleSoftwareUpdate.job
- c:program filesApple Software UpdateSoftwareUpdate.exe [2008-04-11 16:57]
2007-01-14 c:windowsTasksConnexion facile à Internet.job
- c:program filesHewlett-PackardSDPHPSdpApp.exe [2005-11-16 09:55]
2007-01-06 c:windowsTasksHP Service Delivery.job
- c:program filesHewlett-PackardSDPHPSdpApp.exe [2005-11-16 09:55]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-19 23:38:24
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:windowssystem32msdtc.exe
c:program filesFichiers communsAppleMobile Device SupportinAppleMobileDeviceService.exe
c:windowsehomeehrecvr.exe
c:windowsehomeehSched.exe
c:program filesFichiers communsLightScribeLSSrvc.exe
c:windowssystem32spooldriversw32x863lxdiserv.exe
c:windowssystem32lxdicoms.exe
c:windowsehomemcrdsvc.exe
c:program filesHewlett-PackardSharedhpqwmiex.exe
c:program filesWindows Media Playerwmpnetwk.exe
c:windowssystem32mqsvc.exe
c:windowssystem32mqtgsvc.exe
c:windowssystem32dllhost.exe
c:windowsehomeehmsas.exe
c:progra~1HPQSharedHPQTOA~1.EXE
c:windowssystem32wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-11-19 23:42:21 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-19 22:42:17
ComboFix2.txt 2008-11-19 22:29:31
Avant-CF: 46.273.839.104 octets libres
Après-CF: 46,259,621,888 octets libres
258 --- E O F --- 2008-09-15 16:19:49