ComboFix 07-10-28.2 - Arthur et Catherine 2007-10-28 18:39:44.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.144 [GMT 1:00]Running from: C:\Documents and Settings\Arthur et Catherine\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\setup.exe
C:\WINDOWS\system32\nvrssk.dll
C:\WINDOWS\system32\nvrssl.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-28 to 2007-10-28 ))))))))))))))))))))))))))))))))))))
.
2007-10-28 18:39 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-28 16:38 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-10-28 16:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-10-28 16:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-10-28 16:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-10-28 16:02 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-10-28 16:02 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-10-28 16:02 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-10-28 16:02 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-10-28 14:24 <REP> d-------- C:\Program Files\Trend Micro
2007-10-28 14:18 <REP> d-------- C:\securité
2007-10-28 10:13 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-28 10:13 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-28 10:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-28 10:13 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-28 10:13 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-28 10:13 4,230 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-28 06:10 1,536 --a------ C:\WINDOWS\system32\Delete_Me_Dummy_sulimo.dat
2007-10-12 06:29 <REP> d-------- C:\Program Files\msncleaner_msncleaner_1.3.7_francais_43676
2007-10-12 06:29 <REP> d-------- C:\BackUpMSNCleaner
2007-10-12 06:28 344,502 --a------ C:\Program Files\msncleaner_msncleaner_1.3.7_francais_43676.zip
2007-10-12 06:05 <REP> d-------- C:\Program Files\MSN Messenger
2007-10-03 06:08 <REP> d-------- C:\Documents and Settings\Arthur et Catherine\Application Data\Talkback
2007-09-28 09:51 <REP> d-------- C:\Documents and Settings\Arthur et Catherine\Application Data\acccore
2007-09-28 09:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2007-09-28 09:48 <REP> d-------- C:\Program Files\AIM6
2007-09-28 09:48 335 --a------ C:\WINDOWS\nsreg.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-28 17:42 --------- d-----w C:\Program Files\SpeedFan
2007-10-28 13:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-24 16:24 --------- d-----w C:\Program Files\Google
2007-10-19 09:13 --------- d-----w C:\Program Files\Ludiclub
2007-10-03 05:07 --------- d-----w C:\Program Files\DivX
2007-09-29 13:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-28 08:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-09-26 15:33 --------- d-----w C:\Program Files\BoontyGames
2007-09-26 14:59 23,876,904 ----a-w C:\Program Files\SkypeSetup.exe
2007-09-21 07:36 --------- d-----w C:\Program Files\WinPerformance
2007-09-21 07:33 --------- d-----w C:\Program Files\PerfInfo
2007-09-17 16:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\JollyBear
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-05-18 04:21 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2007-05-13 07:15 262,032 ----a-w C:\Program Files\emoticones.exe
2007-05-12 11:26 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-04-08 09:45 14,993,976 ----a-w C:\Program Files\GoogleEarthWin.exe
2007-02-27 06:22 3,121,136 ----a-w C:\Program Files\50331-_umbro.mpg
2007-02-26 06:16 717,824 ----a-w C:\Program Files\Levieuxsage.pps
2007-02-19 08:28 1,892,654 ----a-w C:\Program Files\lcplugin22.exe
2007-02-13 09:31 358,400 ----a-w C:\Program Files\FLEURS~1.PPS
2007-02-10 11:57 4,003,432 ----a-w C:\Program Files\SweetImSetup.exe
2007-02-02 06:16 815,104 ----a-w C:\Program Files\100_au_compteur.pps
2007-01-14 17:09 1,527,829 ----a-w C:\Program Files\zp500std.exe
2007-01-14 16:52 9,453,630 ----a-w C:\Program Files\vlc-0.8.6a-win32.exe
2007-01-14 16:50 13,122,160 ----a-w C:\Program Files\MPSetup.exe
2006-11-13 11:45 55,960 ----a-w C:\Documents and Settings\Arthur et Catherine\Application Data\GDIPFONTCACHEV1.DAT
2006-10-20 14:41 4,772,352 ----a-w C:\Program Files\qi98_40.exe
2006-10-20 14:25 28,994,783 ----a-w C:\Program Files\InstallPacklang_GVAPD.exe
2006-05-11 11:39 11,132,160 ----a-w C:\Program Files\setupfre.exe
2006-05-11 08:17 1,724,160 ----a-w C:\Program Files\XoftSpy422_179.exe
2006-05-11 08:15 2,713,880 ----a-w C:\Program Files\WindowsXP-KB835732-x86-FRA.EXE
2006-05-11 08:14 2,710,296 ----a-w C:\Program Files\WindowsXP-KB835732-x86-ENU.EXE
2006-05-10 11:01 183,169 ----a-w C:\Program Files\hijackthis.zip
2006-05-10 10:47 5,037,072 ----a-w C:\Program Files\spybotsd14.exe
2006-05-10 10:19 1,455,784 ----a-w C:\Program Files\ccsetup129.exe
2006-04-11 08:14 533,574 ----a-w C:\Program Files\pllangs.exe
2006-04-11 08:14 2,855,080 ----a-w C:\Program Files\aawsepersonal.exe
2006-02-18 07:39 12,814,336 ----a-w C:\Program Files\media player version 10.exe
2006-02-09 17:06 4,096 ----a-w C:\Documents and Settings\Arthur et Catherine\log.dat
2005-09-06 06:27 4,577,316 ----a-w C:\Program Files\eMule0.46c-Installer.exe
2005-05-09 05:29 680,660 ----a-w C:\Program Files\VirtualDub-1.5.10.zip
2005-03-06 11:34 7,123,600 ----a-w C:\Program Files\Nimo50Build8.exe
2005-02-28 19:27 4,257,229 ----a-w C:\Program Files\sld.codec.pack.basic.2.1.exe
2005-02-28 19:26 9,430,768 ----a-w C:\Program Files\klcodec236f.exe
2005-02-28 10:48 12,814,336 ----a-w C:\Program Files\mp10setup.exe
1998-08-24 11:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-02-09 13:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"SpeedFan"="C:\Program Files\SpeedFan\Speedfan.exe" [2003-03-11 12:29]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-01-10 07:32]
"nwiz"="nwiz.exe" [2004-03-24 09:04 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-24 09:04]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-24 09:04]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"MSctlWin"="c:\windows\system32\MsCtlWin60\MSctlWin.exed" []
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-06-01 10:03]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-06-01 10:09]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2004-03-25 13:14]
"AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-06-21 11:01]
"HostManager"="C:\Program Files\Fichiers communs\AOL\1144675721\ee\AOLSoftware.exe" [2006-11-17 14:16]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
"PivotSoftware"="C:\Program Files\WinPortrait\wpctrl.exe" [2005-01-26 11:57]
"DT Task"="C:\Program Files\Portrait Displays\forteManager\DTHtml.exe" [2005-10-14 17:41]
"AOLSAV"="C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe" [2004-03-15 11:39]
"WinPerformance"="C:\Program Files\WinPerformance\WinPerformance.lnk" [2007-09-21 08:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-06-01 09:46]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 07:18]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
"Symantec NetDriver Warning"=C:\PROGRA~1\SYMNET~1\SNDWarn.exe
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
AOL 9.0 Icône AOL.lnk - C:\Program Files\AOL 9.0b\aoltray.exe [2007-05-18 06:01:56]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
LG SyncManager.lnk - C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe [2007-02-02 17:32:22]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 08:01:04]
R1 crlscsi;crlscsi;C:\WINDOWS\system32\drivers\crlscsi.sys
R1 pivot;pivot;C:\WINDOWS\system32\drivers\pivot.sys
S2 ERBNRRKQ;ERBNRRKQ;\??\C:\WINDOWS\system32\erbnrrkq.tqw
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);C:\WINDOWS\system32\DRIVERS\alcan5ln.sys
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe"
S3 optousb;OPTO ELECTRONICS optousb;C:\WINDOWS\system32\DRIVERS\optousb.sys
S3 optovcm;OPTO ELECTRONICS optovcm;C:\WINDOWS\system32\DRIVERS\optovcm.sys
S3 pivotmou;Pivot Mouse/Pointers Filter Driver;\??\C:\WINDOWS\system32\drivers\pivotmou.sys
S3 RescueDrv;Inventel Access Point USB Rescue Driver;C:\WINDOWS\system32\Drivers\resc_dwb.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
*Newly Created Service* - ATWPKT2
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2006-05-11 08:18:00 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-28 18:43:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-28 18:44:32 - machine was rebooted
.
--- E O F ---