ComboFix 08-01-28.2 - Administrateur 2008-01-28 18:13:30.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1784 [GMT 1:00]
ˆÌÐÐλÖÃ: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
(((((((((((((((((((((((((((( 2007-12-28 - 2008-01-28 Ö®ég½¨Á¢µÄ™n°¸ )))))))))))))))))))))))))))))))))
.
2008-01-27 00:00 . 2008-01-27 00:00 250,368 --a------ C:\WINDOWS\system32\andt.sys
2008-01-27 00:00 . 2008-01-27 00:00 45,056 --a------ C:\WINDOWS\system32\Indt2.sys
2008-01-26 13:35 . 2008-01-26 13:41 208,876 --a------ C:\WINDOWS\system32\tmp0_571716599315.bk
2008-01-25 21:49 . 2008-01-25 21:49 <REP> d-------- C:\WINDOWS\ERUNT
2008-01-25 11:31 . 2008-01-25 11:31 208,876 --a------ C:\WINDOWS\system32\tmp0_82694680009.bk
2008-01-25 11:31 . 2008-01-25 11:31 15,810 --a------ C:\WINDOWS\system32\tmp0_636921397753.bk
2008-01-25 00:02 . 2008-01-25 00:02 10,280 --a------ C:\WINDOWS\system32\tmp0_877511465861.bk
2008-01-25 00:01 . 2008-01-25 00:02 208,988 --a------ C:\WINDOWS\system32\tmp0_402688320123.bk
2008-01-24 23:00 . 2008-01-24 23:00 207,461 --a------ C:\WINDOWS\system32\tmp0_558588276055.bk
2008-01-24 11:21 . 2008-01-24 11:21 <REP> d-------- C:\Program Files\Trend Micro
2008-01-23 19:20 . 2008-01-23 19:36 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-23 19:20 . 2008-01-23 19:36 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-23 19:19 . 2008-01-23 19:19 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-01-23 19:19 . 2008-01-28 17:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-23 19:19 . 2008-01-28 18:11 8,305,952 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-23 19:19 . 2008-01-28 18:11 112,316 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-23 19:19 . 2008-01-28 18:11 91,936 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-23 19:19 . 2008-01-28 18:11 9,692 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-23 13:11 . 2008-01-25 11:31 250,368 --a------ C:\WINDOWS\system32\ndt2.sys
2008-01-22 18:15 . 2008-01-27 11:14 1,050 --a------ C:\WINDOWS\eReg.dat
2008-01-22 18:07 . 2008-01-22 18:08 <REP> d-------- C:\Program Files\Maxis
2008-01-21 23:59 . 2008-01-22 00:06 2,740 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-21 21:33 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-21 21:33 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-21 21:33 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-21 21:33 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-16 22:51 . 2008-01-16 23:24 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Bioshock
2008-01-16 22:51 . 2008-01-16 22:51 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-01-16 22:47 . 2008-01-16 22:47 <REP> d-------- C:\Program Files\2K Games
2008-01-16 20:20 . 2008-01-16 20:20 <REP> d-------- C:\Program Files\Atari
2008-01-13 20:12 . 2008-01-25 08:53 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-13 20:12 . 2008-01-13 20:12 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-13 17:39 . 2008-01-13 17:39 <REP> d-------- C:\Program Files\AxBx
.
(((((((((((((((((((((((((((((((((((( ½üÈý‚€Ôƒȸü„ӵęn°¸ )))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 17:09 --------- d-----w C:\Program Files\Wanadoo
2008-01-28 16:52 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Skype
2008-01-27 22:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-27 10:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 21:49 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-26 21:48 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-01-26 15:09 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-24 10:19 --------- d-----w C:\Program Files\Google
2008-01-21 20:08 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-20 17:32 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\SopCast
2008-01-20 17:01 --------- d-----w C:\Program Files\TVAnts
2008-01-08 07:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-16 17:42 --------- d-----w C:\Program Files\Zylom Games
2007-12-16 17:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-12-16 17:42 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Zylom
2007-12-16 09:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2007-12-16 08:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\NannyMania
2007-12-16 08:19 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\MysteryStudio
2007-12-13 23:01 32,768 ----a-w C:\WINDOWS\system32\routing.exe
2007-12-12 16:59 --------- d-----w C:\Program Files\Barbie(TM)
2007-12-12 02:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-10 18:24 --------- d-----w C:\Program Files\Alwil Software
2007-12-10 18:22 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2007-12-07 17:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-12-07 17:30 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\PlayFirst
2007-12-07 17:29 --------- d-----w C:\Program Files\Gamenext
2007-12-05 07:30 --------- d-----w C:\Program Files\Microsoft Works
2007-12-03 18:16 --------- d-----w C:\Program Files\SpywareBlaster
2007-12-02 22:08 --------- d-----w C:\Program Files\Java
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-09-13 21:06 22,328 ----a-w C:\Documents and Settings\Administrateur\Application Data\PnkBstrK.sys
2003-12-14 06:39 974,848 ----a-w C:\Program Files\Vide Fichiers Temporaires.exe
2003-02-17 10:26 139 ----a-w C:\Program Files\CleanTmp.reg
2003-02-10 11:20 409 ----a-w C:\Program Files\CleanTempFiles.bat
.
(((((((((((((((((((((((((((((((((((((((((( ÖØÒªµÇä›™n )))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*×¢Òâ* ¿Õ°×»òºÏ•¨µÄµÇä›ÖµŒ¢²»•þï@ʾ.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2006-10-31 14:06 204843]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-08-22 23:19 23120680]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-31 11:29 68856]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTDCPL"="RTDCPL.EXE" [2005-07-08 13:16 12298240 C:\WINDOWS\system32\RTDCPL.EXE]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2005-07-22 16:02 126464]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Tweak UI"="TWEAKUI.CPL" [2000-11-12 22:35 103424 C:\WINDOWS\system32\TWEAKUI.CPL]
"CleanTempFiles"="C:\Program Files\CleanTempFiles.bat" [2003-02-10 12:20 409]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 03:12 98304]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-11-07 05:20 122940]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-05-16 15:58 213936]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-05-16 15:58 86960]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-11-17 17:29 7700480]
"nwiz"="nwiz.exe" [2006-11-17 17:29 1622016 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-11-17 17:29 86016]
"ISUSPM"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2006-05-16 15:58 213936]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 22:46 57344]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-13 22:26 185632]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Festoon]
--a------ 2005-12-22 15:30 548864 C:\Program Files\Santa Cruz Networks\Festoon\Festoon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2006-07-29 19:34 5354792 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSStartup]
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orange Desktop Search]
C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-03-31 11:29 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystrayORAHSS]
C:\Program Files\OrangeHSS\Systray\SystrayApp.exe
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 13:00]
S2 perfmons;perfmons Service;C:\WINDOWS\system32\perfs.exe [2004-08-05 13:00]
S2 Routing;Routing Service;C:\WINDOWS\system32\routing.exe [2007-12-14 00:01]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 Moufiltr;Mouse Test Driver;C:\WINDOWS\system32\DRIVERS\Moufiltr.sys [2005-08-06 14:13]
S3 MouseCap;MouseCapture Driver;C:\WINDOWS\system32\Drivers\MouseCap.sys [2005-08-08 13:44]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\Autorun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-28 18:16:04
Windows 5.1.2600 Service Pack 2 NTFS
’ßÃèë[²ØµÄ³ÌÐò ...
’ßÃèë[²ØµÄßM³Ì ...
’ßÃèë[²ØµÄ™n°¸ ...
’ßÃèÍê³É
ë[²Ø™n°¸: 0
**************************************************************************
.
Íê³É•rég: 2008-01-28 18:16:35
ComboFix2.txt 2008-01-28 16:21:57
.
2008-01-09 22:08:35 --- E O F ---