ComboFix 08-09-01.05 - SAIDA 2008-09-05 19:04:11.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.449 [GMT 2:00]
Endroit: D:\Documents and Settings\SAIDA\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Documents and Settings\JAWAD\Local Settings\Application Data\inetinfo.exe
D:\Documents and Settings\JAWAD\Local Settings\Application Data\lsass.exe
D:\Documents and Settings\JAWAD\Local Settings\Application Data\services.exe
D:\Documents and Settings\JAWAD\Local Settings\Application Data\winlogon.exe
D:\Documents and Settings\SAIDA\Local Settings\Application Data\inetinfo.exe
D:\Documents and Settings\SAIDA\Local Settings\Application Data\lsass.exe
D:\Documents and Settings\SAIDA\Local Settings\Application Data\services.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-05 to 2008-09-05 ))))))))))))))))))))))))))))))))))))
.
2008-08-19 12:32 . 2008-08-19 12:32 <REP> d-------- C:\Program Files\Trend Micro
2008-08-19 11:48 . 2008-08-19 11:48 <REP> d-------- C:\upload_moi_115143250318
2008-08-19 09:02 . 2008-08-19 09:02 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-08-17 22:06 . 2008-08-17 22:06 10,850,756 --a------ C:\upload_moi_115143250318.tar.gz
2008-08-17 12:31 . 2008-08-17 12:31 <REP> d--hs---- D:\Documents and Settings\NetworkService.AUTORITE NT.008
2008-08-17 12:31 . 2008-08-17 12:31 <REP> d--hs---- D:\Documents and Settings\LocalService.AUTORITE NT.008
2008-08-13 11:28 . 2008-05-01 16:31 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-09 21:44 . 2008-08-09 21:44 <REP> d-------- D:\Documents and Settings\SAIDA\Application Data\TomTom
2008-08-08 22:48 . 2008-08-08 22:48 <REP> d-------- D:\Documents and Settings\JAWAD\Application Data\Malwarebytes
2008-08-06 14:54 . 2006-10-04 16:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-08-06 14:54 . 2006-10-04 16:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-08-06 14:54 . 2006-10-04 16:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-08-06 14:53 . 2008-08-19 09:00 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-08-06 14:52 . 2008-08-19 09:00 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-08-05 00:18 . 2008-08-05 00:18 <REP> d-------- D:\Documents and Settings\SAIDA\Application Data\Malwarebytes
2008-08-05 00:18 . 2008-08-05 00:18 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 00:18 . 2008-08-19 09:01 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-05 00:18 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-05 00:18 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-05 00:09 . 2008-08-05 00:09 <REP> d-------- D:\Documents and Settings\SAIDA\Application Data\Norman
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 17:06 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-08-20 20:02 --------- d-----w C:\Program Files\eMule
2008-08-11 07:11 45,417 ---h--w C:\WINDOWS\KesenjanganSosial.exe
2008-08-11 07:11 45,417 ----a-w C:\WINDOWS\system32\SAIDA's Setting.scr
2008-08-11 07:11 45,417 ----a-w C:\WINDOWS\system32\JAWAD's Setting.scr
2008-08-11 07:11 45,417 ----a-w C:\WINDOWS\system32\cmd-brontok.exe
2008-08-04 21:52 --------- d-----w D:\Documents and Settings\JAWAD\Application Data\Norman
2008-07-31 10:03 45,417 ----a-w C:\WINDOWS\system32\Administrateur.115143250318's Setting.scr
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\You've Got Pictures Screensaver
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\Viewpoint
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\VadeRetro
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\Symantec
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\Apple Computer
2008-07-28 10:03 --------- d-----w D:\Documents and Settings\SAIDA\Application Data\AdobeUM
2008-07-28 10:01 --------- d-----w C:\Program Files\Apple Software Update
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-15 14:52 --------- d---a-w D:\Documents and Settings\All Users\Application Data\TEMP
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock(2)(2).dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock(2)(2)(2).dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock(2)(2)(2)(2)(3).dll
2008-06-20 17:41 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dnsapi(2)(2).dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dnsapi(2)(2)(2).dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dnsapi(2)(2)(2)(2)(3).dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2004-08-05 13:00 1,392,671 --sh--r C:\WINDOWS\system32\msvbvm60.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-06-18 171448]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Tok-Cirrhatus-2355"="D:\Documents and Settings\SAIDA\Local Settings\Application Data\br5733on.exe" [2008-08-11 45417]
"AWMON"="C:\Program Files\Norman\Norman Ad-aware SE Plus\Ad-Watch.exe" [2005-06-27 516608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vade Retro Outlook Express"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe" [2004-10-04 310272]
"Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-03-03 180269]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 127118]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-08-02 86016]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-08-02 7110656]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-22 842584]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2004-09-07 58488]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-09-06 1003520]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2005-08-02 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
D:\Documents and Settings\Administrateur.115143250318\Menu D‚marrer\Programmes\D‚marrage\
Empty.pif [2008-08-13 45417]
D:\Documents and Settings\JAWAD\Menu D‚marrer\Programmes\D‚marrage\
Empty.pif [2008-08-11 45417]
D:\Documents and Settings\SAIDA\Menu D‚marrer\Programmes\D‚marrage\
Empty.pif [2008-08-11 45417]
D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
OFFICE One Clock v6.5.lnk - C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe [2007-06-14 257536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
hxxp://www.google.fr/
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
file:///C:/WINDOWS/Java/classes/xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-05 19:06:07
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-05 19:06:58
ComboFix-quarantined-files.txt 2008-09-05 17:06:55
Pre-Run: 8,652,636,160 octets libres
Post-Run: 8,678,752,256 octets libres
188 --- E O F --- 2008-08-18 09:01:06
desole pour mon retar j'etas pas chez moi merci encore j'en peu plu avec brontok on dirai qu'il se cache dés qu'il se sent menacé