ComboFix 09-07-09.08 - isabelle 10/07/2009 17:07.2.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1589 [GMT 2:00]
Lancé depuis: c:documents and settingsisabelleBureauComboFix.exe
AV: Antivirus BitDefender *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Pare-feu BitDefender *enabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:documents and settingsAll UsersApplication Data98084836.ini
c:documents and settingsisabelleApplication Datawiaserva.log
c:windowsInstaller1d6a4f4.msp
c:windowsInstaller22cef.msi
c:windowssystem32\_003385_.tmp.dll
c:windowssystem32\_003386_.tmp.dll
c:windowssystem32\_003387_.tmp.dll
c:windowssystem32\_003388_.tmp.dll
c:windowssystem32\_003395_.tmp.dll
c:windowssystem32\_003396_.tmp.dll
c:windowssystem32\_003397_.tmp.dll
c:windowssystem32\_003399_.tmp.dll
c:windowssystem32\_003400_.tmp.dll
c:windowssystem32\_003403_.tmp.dll
c:windowssystem32\_003404_.tmp.dll
c:windowssystem32\_003406_.tmp.dll
c:windowssystem32\_003407_.tmp.dll
c:windowssystem32\_003408_.tmp.dll
c:windowssystem32\_003409_.tmp.dll
c:windowssystem32\_003410_.tmp.dll
c:windowssystem32\_003411_.tmp.dll
c:windowssystem32\_003412_.tmp.dll
c:windowssystem32\_003414_.tmp.dll
c:windowssystem32\_003416_.tmp.dll
c:windowssystem32\_003417_.tmp.dll
c:windowssystem32\_003418_.tmp.dll
c:windowssystem32\_003419_.tmp.dll
c:windowssystem32\_003420_.tmp.dll
c:windowssystem32\_003421_.tmp.dll
c:windowssystem32\_003423_.tmp.dll
c:windowssystem32\_003424_.tmp.dll
c:windowssystem32\_003427_.tmp.dll
c:windowssystem32\_003428_.tmp.dll
c:windowssystem32\_003429_.tmp.dll
c:windowssystem32\_003430_.tmp.dll
c:windowssystem32\_003431_.tmp.dll
c:windowssystem32\_003432_.tmp.dll
c:windowssystem32\_003433_.tmp.dll
c:windowssystem32\_003434_.tmp.dll
c:windowssystem32\_003436_.tmp.dll
c:windowssystem32\_003437_.tmp.dll
c:windowssystem32\_003438_.tmp.dll
c:windowssystem32\_003440_.tmp.dll
c:windowssystem32\_003441_.tmp.dll
c:windowssystem32\_003442_.tmp.dll
c:windowssystem32\_003443_.tmp.dll
c:windowssystem32\_003445_.tmp.dll
c:windowssystem32\_003446_.tmp.dll
c:windowssystem32\_003447_.tmp.dll
c:windowssystem32\_003448_.tmp.dll
c:windowssystem32\_003449_.tmp.dll
c:windowssystem32\_003450_.tmp.dll
c:windowssystem32\_003451_.tmp.dll
c:windowssystem32\_003452_.tmp.dll
c:windowssystem32\_003453_.tmp.dll
c:windowssystem32\_003454_.tmp.dll
c:windowssystem32\_003455_.tmp.dll
c:windowssystem32\_003456_.tmp.dll
c:windowssystem32\_003457_.tmp.dll
c:windowssystem32\_003458_.tmp.dll
c:windowssystem32\_003459_.tmp.dll
c:windowssystem32\_003460_.tmp.dll
c:windowssystem32\_003463_.tmp.dll
c:windowssystem32\_003464_.tmp.dll
c:windowssystem32\_003465_.tmp.dll
c:windowssystem32\_003466_.tmp.dll
c:windowssystem32\_003467_.tmp.dll
c:windowssystem32\_003468_.tmp.dll
c:windowssystem32\_003473_.tmp.dll
c:windowssystem32404Fix.exe
c:windowssystem32Agent.OMZ.Fix.exe
c:windowssystem32dumphive.exe
c:windowssystem32IEDFix.C.exe
c:windowssystem32IEDFix.exe
c:windowssystem32o4Patch.exe
c:windowssystem32Process.exe
c:windowssystem32qvyesqkd.ini
c:windowssystem32sqlite3.dll
c:windowssystem32SrchSTS.exe
c:windowssystem32 mp.reg
c:windowssystem32VACFix.exe
c:windowssystem32VCCLSID.exe
c:windowssystem32WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------Service_glaide32
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-10 au 2009-07-10 ))))))))))))))))))))))))))))))))))))
.
2009-07-10 15:15 . 2004-08-05 11:00 2944 ----a-w- c:windowssystem32drivers
ull.sys
2009-07-10 15:15 . 2004-08-05 11:00 4224 ----a-w- c:windowssystem32driverseep.sys
2009-07-10 14:35 . 2009-07-10 14:56 -------- d-----w- C:FindyKill
2009-07-10 14:03 . 2009-07-10 14:05 -------- d-----w- C:Lop SD
2009-07-10 13:43 . 2009-07-10 14:31 -------- d-----w- c:program filesNavilog1
2009-07-10 13:38 . 2009-07-10 13:51 -------- d-----w- C:ToolBar SD
2009-07-10 13:33 . 2004-08-05 11:00 4224 ----a-w- c:windowssystem32dllcacheeep.sys
2009-07-09 07:20 . 2009-06-17 09:27 38160 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2009-07-09 07:20 . 2009-07-09 07:20 -------- d-----w- c:program filesMalwarebytes' Anti-Malware
2009-07-09 07:20 . 2009-06-17 09:27 19096 ----a-w- c:windowssystem32driversmbam.sys
2009-07-02 11:47 . 2009-07-02 11:47 -------- d-----w- c:documents and settingsAdministrateurApplication DataBitDefender
2009-07-01 17:27 . 2009-07-09 06:19 -------- d-----w- c:documents and settingsAll UsersApplication Data18074844
2009-06-21 10:19 . 2009-06-21 10:19 815 ----a-w- C:
tsr_eml_sr.dat
2009-06-21 10:19 . 2009-06-21 10:19 141 ----a-w- C:dwl.dat
2009-06-21 10:19 . 2009-06-21 10:19 132 ----a-w- C:httpdwl.dat
2009-06-21 10:13 . 2009-06-21 10:13 16 ----a-w- C:asdict.dat
2009-06-19 10:26 . 2009-06-19 10:26 -------- d-----w- c:documents and settingsisabelleApplication DataBitDefender
2009-06-19 10:25 . 2009-06-19 10:27 -------- d-----w- c:documents and settingsAll UsersApplication DataBitDefender
2009-06-19 10:25 . 2009-06-19 10:25 -------- d-----w- c:program filesBitDefender
2009-06-19 10:25 . 2009-06-19 10:26 -------- d-----w- c:program filesFichiers communsBitDefender
2009-06-14 15:21 . 2009-06-14 15:21 152576 ----a-w- c:documents and settingsisabelleApplication DataSunJavajre1.6.0_13lzma.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 15:13 . 2007-06-18 07:50 81984 ----a-w- c:windowssystem32dod.bin
2009-07-10 07:53 . 2007-04-26 10:37 -------- d-----w- c:documents and settingsisabelleApplication DataVadeRetro
2009-07-02 11:51 . 2009-04-20 13:50 -------- d---a-w- c:documents and settingsAll UsersApplication DataTEMP
2009-07-01 17:27 . 2009-02-19 14:26 109 --sha-w- c:windowssystem3272406528.dat
2009-07-01 16:40 . 2007-04-26 11:00 -------- d-----w- c:program filesPowerArchiver
2009-06-17 06:02 . 2007-04-26 10:36 -------- d-----w- c:documents and settingsAll UsersApplication DataVadeRetro
2009-06-14 15:23 . 2007-04-21 11:25 -------- d-----w- c:program filesJava
2009-05-07 15:33 . 2009-02-27 15:32 348672 ----a-w- c:windowssystem32localspl.dll
2009-04-29 04:45 . 2004-08-19 12:03 827392 ----a-w- c:windowssystem32wininet.dll
2009-04-29 04:45 . 2004-08-19 12:03 78336 ----a-w- c:windowssystem32ieencode.dll
2009-04-23 18:55 . 2004-08-19 12:03 85688 ----a-w- c:windowssystem32perfc00C.dat
2009-04-23 18:55 . 2004-08-19 12:03 512286 ----a-w- c:windowssystem32perfh00C.dat
2009-04-19 19:50 . 2009-02-27 15:32 1847296 ----a-w- c:windowssystem32win32k.sys
2009-04-15 14:53 . 2004-08-19 12:03 585216 ----a-w- c:windowssystem32
pcrt4.dll
.
------- Sigcheck -------
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:windows$hf_mig$KB917953SP2QFE cpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:windows$hf_mig$KB941644SP2QFE cpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:windows$hf_mig$KB951748SP2QFE cpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:windows$hf_mig$KB951748SP3GDR cpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:windows$hf_mig$KB951748SP3QFE cpip.sys
[-] 2008-06-20 10:45 360320 1CC09561E21A48A7F649A40F18235860 c:windows$NtServicePackUninstall$ cpip.sys
[7] 2004-08-05 11:00 359040 9F4B36614A0FC234525BA224957DE55C c:windows$NtUninstallKB917953$ cpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:windows$NtUninstallKB941644$ cpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:windows$NtUninstallKB951748$ cpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:windows$NtUninstallKB951748_0$ cpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:windowsServicePackFilesi386 cpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:windowsSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865af cpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:windowssystem32dllcache cpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:windowssystem32drivers cpip.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32ctfmon.exe" [2008-04-14 15360]
"PowerArchiver Tray"="c:program filesPowerArchiverPASTARTER.EXE" [2007-03-20 141352]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2006-03-21 7204864]
"IAAnotif"="c:program filesIntelIntel Matrix Storage Manageriaanotif.exe" [2006-04-26 143360]
"DVDLauncher"="c:program filesCyberLinkPowerDVDDVDLauncher.exe" [2005-12-09 49152]
"DLA"="c:windowsSystem32DLADLACTRLW.EXE" [2005-09-08 122940]
"MoneyStartUp10.0"="c:program filesMicrosoft MoneySystemActivation.exe" [2001-07-25 245810]
"VadeRetro Desktop"="c:program filesGoto SoftwareVade RetroVaderetro_Mgr.exe" [2008-05-26 1078272]
"BDAgent"="c:program filesBitDefenderBitDefender 2009dagent.exe" [2009-03-19 778240]
"BitDefender Antiphishing Helper"="c:program filesBitDefenderBitDefender 2009IEShow.exe" [2009-02-23 69632]
"SigmatelSysTrayApp"="stsystra.exe" - c:windowsstsystra.exe [2006-03-20 282624]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
c:documents and settingsisabelleMenu D,marrerProgrammesD,marrage
rncsys32.exe [2008-4-14 20992]
c:documents and settingsisabelleMenu D,marrerProgrammesD,marrage
rncsys32.exe [2008-4-14 20992]
c:documents and settingsisabelleMenu D,marrerProgrammesD,marrage
rncsys32.exe [2008-4-14 20992]
c:documents and settingsAll UsersMenu D,marrerProgrammesD,marrage
D,marrage d'Office.lnk - c:program filesMicrosoft OfficeOfficeOSA.EXE [1997-8-29 51984]
Microsoft Office.lnk - c:program filesMicrosoft OfficeOfficeOSA9.EXE [1999-2-17 65588]
Microsoft Recherche acc,l,r,e.lnk - c:program filesMicrosoft OfficeOfficeFINDFAST.EXE [1997-8-29 111376]
c:documents and settingsisabelleMenu D,marrerProgrammesD,marrage
rncsys32.exe [2008-4-14 20992]
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 ASFIPmon;Broadcom ASF IP Monitor;c:program filesBroadcomASFIPMonAsfIpMon.exe [17/03/2006 18:25 65536]
R2 BDVEDISK;BDVEDISK;c:program filesBitDefenderBitDefender 2009BDVEDISK.sys [06/10/2008 18:16 82696]
R3 bdfm;BDFM;c:windowssystem32driversdfm.sys [18/09/2008 12:09 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:windowssystem32driversdfndisf.sys [12/02/2009 16:52 104328]
S1 glaide32;glaide32;??c:windowssystem32driversglaide32.sys --> c:windowssystem32driversglaide32.sys [?]
S3 Arrakis3;BitDefender Arrakis Server;c:program filesFichiers communsBitDefenderBitDefender Arrakis ServerinArrakis3.exe [20/01/2009 19:16 172032]
S3 MBAMSwissArmy;MBAMSwissArmy;c:windowssystem32driversmbamswissarmy.sys [09/07/2009 09:20 38160]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
bdx REG_MULTI_SZ scan
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.com
mStart Page =
hxxp://www.google.com
TCP: {E396DADF-478E-43B8-94F6-5228AE293B91} = 80.10.246.2,80.10.246.129
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-10 17:14
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1404)
c:windowssystem32WPDShServiceObj.dll
c:windowssystem32PortableDeviceTypes.dll
c:windowssystem32PortableDeviceApi.dll
c:windowssystem32eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:program filesFichiers communsBitDefenderBitDefender Update Servicelivesrv.exe
c:program filesBitDefenderBitDefender 2009vsserv.exe
c:program filesIntelIntel Matrix Storage ManagerIAANTmon.exe
c:program filesJavajre6injqs.exe
c:windowssystem32
vsvc32.exe
.
**************************************************************************
.
Heure de fin: 2009-07-10 17:22 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-10 15:22
Avant-CF: 66 456 858 624 octets libres
Après-CF: 66 539 692 032 octets libres
241 --- E O F --- 2009-06-12 15:04