ComboFix 08-08-06.02 - Jacardi 2008-08-07 14:55:03.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1586 [GMT 2:00]
Endroit: C:\Documents and Settings\Jacardi\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jacardi\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Création d'un nouveau point de restauration
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-07 to 2008-08-07 ))))))))))))))))))))))))))))))))))))
.
2008-08-05 19:22 . 2008-08-05 19:22 <REP> d--h----- C:\Documents and Settings\Jonathan Jaccard\Voisinage réseau
2008-08-05 16:04 . 2008-08-05 16:04 <REP> d-------- C:\_OTMoveIt
2008-08-05 16:01 . 2008-08-05 16:01 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Application Data\Malwarebytes
2008-08-05 13:50 . 2008-08-05 13:50 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-08-05 13:12 . 2008-08-05 13:12 <REP> d-------- C:\Program Files\Avira
2008-08-05 13:12 . 2008-08-05 13:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-05 12:53 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-05 12:53 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-04 21:33 . 2008-08-04 21:33 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-08-04 21:28 . 2008-08-05 13:32 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Incomplete
2008-08-04 21:28 . 2008-08-05 00:10 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Application Data\LimeWire
2008-08-04 19:58 . 2008-08-06 20:05 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Application Data\Apple Computer
2008-08-04 19:47 . 2008-08-04 19:50 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Contacts
2008-08-04 19:06 . 2008-08-06 19:55 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Mes documents
2008-08-04 19:06 . 2004-08-20 12:30 <REP> dr------- C:\Documents and Settings\Jonathan Jaccard\Menu Démarrer
2008-08-04 19:06 . 2008-08-04 23:09 <REP> dr------- C:\Documents and Settings\Jonathan Jaccard\Favoris
2008-08-04 19:06 . 2008-08-07 14:37 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Bureau
2008-08-04 19:06 . 2007-01-10 01:44 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard\Application Data\Symantec
2008-08-04 19:06 . 2007-01-10 01:45 <REP> d--h----- C:\Documents and Settings\Jonathan Jaccard\Application Data\Gtek
2008-08-04 19:06 . 2008-08-07 13:42 <REP> d-------- C:\Documents and Settings\Jonathan Jaccard
2008-08-04 17:35 . 2008-08-04 17:35 <REP> d-------- C:\Program Files\ANI
2008-08-04 15:07 . 2008-08-04 15:07 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-08-04 14:55 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-04 14:20 . 2008-08-05 17:58 <REP> d-------- C:\Program Files\Navilog1
2008-08-04 13:19 . 2008-08-04 13:19 <REP> d-------- C:\Documents and Settings\Nicole\Application Data\Malwarebytes
2008-08-04 13:19 . 2008-08-04 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 13:04 . 2008-08-04 13:04 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-04 13:00 . 2008-08-03 04:12 <REP> d-------- C:\SDFix
2008-08-04 12:43 . 2008-08-04 12:43 <REP> d-------- C:\Deckard
2008-07-28 10:27 . 2008-07-28 10:27 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-28 10:20 . 2008-07-29 00:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-27 00:16 . 2008-07-27 00:16 58 --a------ C:\WINDOWS\yesmessenger.ini
2008-07-18 13:29 . 2008-07-18 13:29 <REP> d-------- C:\Program Files\Aglare 3GP MP4 to AVI WMV MPEG MOV iPod Converter
2008-07-18 13:29 . 2008-07-18 13:29 34 --ah----- C:\WINDOWS\system32\VideoConverter_sysquict.dat
2008-07-11 22:43 . 2008-07-11 22:44 463 --a------ C:\WINDOWS\pirchutl.ini
2008-07-11 22:43 . 2008-07-11 22:44 60 --a------ C:\WINDOWS\pident.ini
2008-07-09 18:42 . 2008-07-09 18:42 <REP> d-------- C:\WINDOWS\SQLTools9_KB948109_ENU
2008-07-09 18:40 . 2008-07-09 18:40 <REP> d-------- C:\WINDOWS\SQL9_KB948109_ENU
2008-07-07 18:29 . 2008-07-07 18:29 <REP> d-------- C:\Program Files\iPod
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 10:53 1,914 ----a-w C:\WINDOWS\system32\tmp.reg
2008-08-04 21:33 --------- d-----w C:\Program Files\eMule
2008-08-04 19:33 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-04 19:32 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-04 19:27 --------- d-----w C:\Program Files\LimeWire
2008-08-04 16:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-04 16:33 --------- d-----w C:\Program Files\Google
2008-08-04 16:33 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-08-04 16:33 --------- d-----w C:\Program Files\Dell
2008-08-04 10:46 --------- d-----w C:\Program Files\Trend Micro
2008-08-04 09:55 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-08-03 18:10 --------- d-----w C:\Program Files\TI Education
2008-08-03 18:07 --------- d-----w C:\Program Files\Corel
2008-07-09 16:42 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-07-07 19:02 --------- d-----w C:\Program Files\Apple Software Update
2008-07-07 16:29 --------- d-----w C:\Program Files\iTunes
2008-07-07 16:27 --------- d-----w C:\Program Files\QuickTime
2008-06-25 12:38 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-06-25 11:33 --------- d-----w C:\Program Files\CFWebAdvancedU
2008-06-25 10:39 --------- d-----w C:\Program Files\PacificPoker4
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-19 08:31 5,330 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-06-18 17:25 --------- d-----w C:\Program Files\MSECache
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-07 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-07 07:56 --------- d-----w C:\Program Files\Alwil Software
2008-06-07 07:30 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-03-03 15:25 88 --sh--r C:\WINDOWS\system32\326AFA93A6.sys
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 18:19 49152]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-23 15:04 1544192]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-04 21:32 185896]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide du logiciel HP Image Zone.lnk
backup=C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jacardi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
path=C:\Documents and Settings\Jacardi\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.4.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-05-08 17:23 289088 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-05 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-05-11 23:12 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-06-02 11:13 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-08-04 21:32 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-04-01 18:35 3587120 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SharedAccess"=2 (0x2)
"Autodesk Licensing Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT);C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 22:08]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 05:39]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S4 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-02-23 19:42]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-07-22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-07-04 C:\WINDOWS\Tasks\Recherche de virus de McAfee.com - Mon ordinateur (JONATHAN-Jacardi).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Jacardi\Application Data\Mozilla\Firefox\Profiles\k2khfl96.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.google.ch/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-07 14:55:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-07 14:56:44
ComboFix-quarantined-files.txt 2008-08-07 12:56:30
ComboFix2.txt 2008-08-07 12:46:31
Pre-Run: 92,203,868,160 octets libres
Post-Run: 92,200,456,192 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
212 --- E O F --- 2008-08-07 08:45:52