bon week end de paques a toi aussi ! soleil et ......chocolat lol
voici le dernier rapport
"HP_Propri‚taire" - 07-04-07 18:57:51 Service Pack 2
ComboFix 07-04-05 - Running from: "C:\Documents and Settings\HP_Propri‚taire\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2007-03-07 to 2007-04-07 ))))))))))))))))))))))))))))))))))
2007-04-07 10:43 532,480 --a------ C:\Program Files\cwshredder.exe
2007-04-06 22:00 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-04-06 16:11 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-06 15:15 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Google
2007-04-06 15:10 427,520 --a------ C:\WINDOWS\WRServices.dll
2007-04-06 15:10 102,912 --a------ C:\WINDOWS\system32\islzma.dll
2007-04-06 15:10 <REP> d-------- C:\Program Files\Webroot
2007-04-06 15:10 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\Webroot
2007-04-06 12:48 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2007-04-05 10:12 <REP> d-------- C:\Program Files\Dofus
2007-03-26 12:11 <REP> d-------- C:\Program Files\RegCleaner
2007-03-24 16:05 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\EoRezo
2007-03-24 16:04 <REP> d-------- C:\Program Files\eoRezo
2007-03-24 13:07 <REP> d-------- C:\Program Files\fond-ecran-wallpaper
2007-03-23 21:03 3,876 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-23 20:59 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-23 20:59 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-23 20:59 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-23 20:59 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-23 20:59 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-23 18:37 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-17 20:54 24 -rah----- C:\WINDOWS\wcpx_.dat
2007-03-17 20:43 172,032 --a------ C:\WINDOWS\system32\cncs32.dll
2007-03-17 20:43 <REP> d-------- C:\WINDOWS\vocabulon
2007-03-16 22:07 <REP> d-------- C:\WINDOWS\system32\3-D_Dolphin_Reef_Demo dir
2007-03-15 18:00 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-03-14 13:19 <REP> d-------- C:\WINDOWS\system32\bfubackups
2007-03-14 12:12 899,960 --a------ C:\blbeta.exe
2007-03-13 11:56 <REP> d-------- C:\Program Files\CCleaner
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-07 10:54 -------- d-------- C:\Program Files\wanadoo
2007-04-07 10:54 -------- d-------- C:\Program Files\wanadoo
2007-04-07 02:08 -------- d-------- C:\Program Files\quicktime
2007-04-07 02:08 -------- d-------- C:\Program Files\quicktime
2007-04-07 02:04 -------- d-------- C:\Program Files\msn messenger
2007-04-07 02:04 -------- d-------- C:\Program Files\msn messenger
2007-04-07 00:48 -------- d-------- C:\Program Files\google
2007-04-07 00:48 -------- d-------- C:\Program Files\google
2007-04-04 15:20 913408 --a------ C:\WINDOWS\system32\xreglib.dll
2007-04-03 20:11 -------- d-------- C:\Program Files\java
2007-04-03 20:11 -------- d-------- C:\Program Files\java
2007-03-25 20:48 -------- d-------- C:\Program Files\emule
2007-03-25 20:48 -------- d-------- C:\Program Files\emule
2007-03-25 12:24 65362 --a------ C:\WINDOWS\system32\perfc00c.dat
2007-03-25 12:24 449322 --a------ C:\WINDOWS\system32\perfh00c.dat
2007-03-13 15:29 -------- d-------- C:\Program Files\ewido anti-malware
2007-03-13 15:29 -------- d-------- C:\Program Files\ewido anti-malware
2007-03-08 17:37 578560 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 17:37 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 17:37 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 17:33 1843712 --a------ C:\WINDOWS\system32\win32k.sys
2007-02-21 11:43 -------- d-------- C:\Program Files\orangehss
2007-02-21 11:43 -------- d-------- C:\Program Files\orangehss
2007-02-20 23:29 -------- d--h----- C:\Program Files\installshield installation information
2007-02-20 23:29 -------- d--h----- C:\Program Files\installshield installation information
2007-02-19 12:45 -------- d-------- C:\Program Files\photofiltre
2007-02-19 12:45 -------- d-------- C:\Program Files\photofiltre
2007-02-16 21:58 -------- d-------- C:\Program Files\orange hss
2007-02-16 21:58 -------- d-------- C:\Program Files\orange hss
2007-02-07 22:11 -------- d-------- C:\Program Files\limewire
2007-02-07 22:11 -------- d-------- C:\Program Files\limewire
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"IMOL"="C:\\Program Files\\IncrediMail\\bin\\IMOLApp.exe /c"
"Acme.PCHButton"="C:\\PROGRA~1\\HELPAN~1\\Pavilion\\XPHWWBF4\\plugin\\bin\\PCHButton.exe"
"WOOKIT"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM="
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
"HPHUPD06"="c:\\Program Files\\HP\\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\\hphupd06.exe"
"HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"WOOWATCH"="C:\\PROGRA~1\\Wanadoo\\Watch.exe"
"WOOTASKBARICON"="C:\\PROGRA~1\\Wanadoo\\GestMaj.exe TaskBarIcon.exe"
"KBD"="C:\\HP\\KBD\\KBD.EXE"
"BDMCon"="\"C:\\Program Files\\Softwin\\BitDefender10\\bdmcon.exe\" /reg"
"BDAgent"="\"C:\\Program Files\\Softwin\\BitDefender10\\bdagent.exe\""
"EoWeather"=""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /startintray"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SSS7"="\"C:\\Program Files\\Steganos Security Suite 7\\SSS7.exe\" -firstboot"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Maintenance en 1 clic.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-07 19:03:13
C:\ComboFix-quarantined-files.txt ... 07-04-07 19:03