Rapport Combofix
ComboFix 08-02.01.1 - Caroline 2008-02-01 7:40:39.4 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.806 [GMT 1:00]
Endroit: C:\Documents and Settings\Caroline\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\kavo.exe
C:\WINDOWS\system32\kavo0.dll
D:\Autorun.inf . . . . Echec de suppression
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-01 to 2008-02-01 ))))))))))))))))))))))))))))))))))))
.
2008-01-31 20:02 . 2008-01-31 20:02 <REP> d-------- C:\Program Files\Audacity
2008-01-31 18:58 . 2008-01-31 18:58 113,267 -r-hs---- C:\q83iwmgf.bat
2008-01-31 12:23 . 2008-01-23 18:40 115,564 -r-hs---- C:\um.cmd
2008-01-27 11:39 . 2008-01-27 11:44 <REP> d-------- C:\Program Files\XoftSpySE
2008-01-27 09:55 . 2008-02-01 07:37 121 --a------ C:\WINDOWS\bdagent.INI
2008-01-27 09:21 . 2008-01-31 18:59 10,624 --a------ C:\WINDOWS\system32\drivers\pxark.sys
2008-01-27 09:05 . 2008-01-27 09:05 <REP> d-------- C:\Program Files\PrevxCSI
2008-01-27 08:37 . 2008-01-27 08:37 <REP> d-------- C:\Program Files\Trend Micro
2008-01-27 08:02 . 2008-01-31 19:00 <REP> d-------- C:\Documents and Settings\Caroline\Application Data\PrevxCSI
2008-01-27 08:02 . 2008-01-27 08:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-27 00:28 . 2008-01-27 00:28 <REP> d-------- C:\Documents and Settings\Caroline\Application Data\Bitdefender
2008-01-27 00:27 . 2008-01-27 00:27 <REP> d-------- C:\Program Files\BitDefender
2008-01-27 00:27 . 2008-01-27 00:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
2008-01-27 00:26 . 2008-01-27 00:27 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-01-19 23:24 . 2008-01-26 14:00 <REP> d-------- C:\Documents and Settings\Caroline\Application Data\DMCache
2008-01-11 16:18 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-01-11 16:17 . 2004-08-04 00:55 91,648 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-01-07 15:21 . 2008-01-07 15:21 268 --ah----- C:\sqmdata05.sqm
2008-01-07 15:21 . 2008-01-07 15:21 244 --ah----- C:\sqmnoopt05.sqm
2008-01-03 23:33 . 2008-01-03 23:33 268 --ah----- C:\sqmdata04.sqm
2008-01-03 23:33 . 2008-01-03 23:33 244 --ah----- C:\sqmnoopt04.sqm
2008-01-03 02:37 . 2008-01-03 02:37 268 --ah----- C:\sqmdata03.sqm
2008-01-03 02:37 . 2008-01-03 02:37 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 06:38 137,048 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-01 06:38 11,513,888 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-31 15:04 --------- d-----w C:\Program Files\eMule
2008-01-19 21:59 --------- d-----w C:\Program Files\DivX
2007-12-25 17:18 --------- d-----w C:\Program Files\CyberFlix
2007-12-24 04:28 --------- d-----w C:\Program Files\Azureus
2007-12-16 20:57 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Azureus
2007-12-16 05:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2007-12-14 11:13 --------- d-----w C:\Program Files\Lavasoft
2007-12-14 11:13 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-12-14 11:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-09 16:21 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Media Player Classic
2007-12-09 08:52 --------- d-----w C:\Program Files\Real Alternative
2007-12-05 12:14 67,704 -c--a-w C:\Documents and Settings\Caroline\Application Data\GDIPFONTCACHEV1.DAT
2007-12-04 14:56 93,264 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-02 13:07 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Apple Computer
2007-12-02 11:58 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-02 10:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 10:18 --------- d-----w C:\Program Files\QuickTime
2007-12-02 10:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-02 10:17 --------- d-----w C:\Program Files\Apple Software Update
2007-12-02 10:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-02 09:56 --------- d-----w C:\Program Files\IncrediMail
2007-12-01 13:05 --------- d-----w C:\Program Files\Veoh Networks
2006-08-06 11:21 22 -csha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D0943516-5076-4020-A3B5-AEFAF26AB263}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 15:56 1957888]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-11-30 16:31 3461120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-11 09:04 761945]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42 32768]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23 1187840]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2005-12-12 11:39 94208]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2005-01-27 18:17 1381376]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 16:25 98304]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 16:26 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 16:22 77824]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 16:45 507904]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-11-08 16:35 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-07 10:56 409600]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-06-29 13:48 233534]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23 132624]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 20:54 919016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16 286720]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2007-11-16 16:37 319488]
"PrevxCSI"="C:\Program Files\PrevxCSI\prevxcsi.exe" [2008-01-27 08:02 92160]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-05 09:00 160768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 09:00 15360]
S1 bdftdif;bdftdif;C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys [2007-11-12 16:28]
S3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2007-08-02 16:03]
S3 BDSelfPr;BDSelfPr;C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-01-27 00:29]
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2007-08-28 07:48]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys []
S3 pxark;pxark;C:\WINDOWS\system32\drivers\pxark.sys [2008-01-31 18:59]
S3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2004-08-05 09:00]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 21:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\um.cmd
\Shell\explore\Command - H:\um.cmd
\Shell\open\Command - H:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73038399-968d-11dc-87b2-0013022ddbf2}]
\Shell\AutoRun\command - G:\q83iwmgf.bat
\Shell\explore\Command - G:\q83iwmgf.bat
\Shell\open\Command - G:\q83iwmgf.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{75878791-975b-11dc-87b4-0013022ddbf2}]
\Shell\AutoRun\command - F:\um.cmd
\Shell\explore\Command - F:\um.cmd
\Shell\open\Command - F:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9825d874-35f0-11dc-8cbb-0013022ddbf2}]
\Shell\AutoRun\command - F:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cee8da29-cb1c-11dc-8821-0013022ddbf2}]
\Shell\AutoRun\command - F:\um.cmd
\Shell\explore\Command - F:\um.cmd
\Shell\open\Command - F:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cee8da2c-cb1c-11dc-8821-0013022ddbf2}]
\Shell\AutoRun\command - H:\um.cmd
\Shell\explore\Command - H:\um.cmd
\Shell\open\Command - H:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cee8da2d-cb1c-11dc-8821-0013022ddbf2}]
\Shell\AutoRun\command - I:\um.cmd
\Shell\explore\Command - I:\um.cmd
\Shell\open\Command - I:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0d2ae24-c9b3-11dc-881e-0013022ddbf2}]
\Shell\AutoRun\command - F:\um.cmd
\Shell\explore\Command - F:\um.cmd
\Shell\open\Command - F:\um.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef3ef052-0f75-11db-8b2d-0013022ddbf2}]
\Shell\AutoRun\command - F:\q83iwmgf.bat
\Shell\explore\Command - F:\q83iwmgf.bat
\Shell\open\Command - F:\q83iwmgf.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0a5094e-943f-11dc-87ae-0013022ddbf2}]
\Shell\AutoRun\command - F:\um.cmd
\Shell\explore\Command - F:\um.cmd
\Shell\open\Command - F:\um.cmd
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-01-28 19:54:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-01 06:30:57 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-01-29 02:23:18 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-01 07:45:45
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-01 7:48:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 06:48:36
ComboFix2.txt 2008-01-29 16:37:00
ComboFix3.txt 2008-01-27 11:31:08
ComboFix4.txt 2008-01-27 09:22:27
.
2008-01-09 16:36:35 --- E O F ---