re!
ComboFix 08-10-18.03 - hp 2008-10-19 17:27:24.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.697 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\hp\Bureau\ComboFix.exe
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\hp\Application Data\Adobe\crc.dat
C:\Documents and Settings\hp\Application Data\Adobe\Player.exe.bak
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdn.com
C:\WINDOWS\dispatcher.exe
C:\WINDOWS\eoke.exe
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\system32\akttzn.exe
C:\WINDOWS\system32\anticipator.dll
C:\WINDOWS\system32\awtoolb.dll
C:\WINDOWS\system32\BaKjPqru.ini
C:\WINDOWS\system32\BaKjPqru.ini2
C:\WINDOWS\system32\bdn.com
C:\WINDOWS\system32\bsva-egihsg52.exe
C:\WINDOWS\system32\bybqsi.dll
C:\WINDOWS\system32\dpcproxy.exe
C:\WINDOWS\system32\ebfyetso.dll
C:\WINDOWS\system32\emesx.dll
C:\WINDOWS\system32\fkrjesjt.dll
C:\WINDOWS\system32\geBronmm.dll
C:\WINDOWS\system32\hoproxy.dll
C:\WINDOWS\system32\hxiwlgpm.dat
C:\WINDOWS\system32\hxiwlgpm.exe
C:\WINDOWS\system32\iifdDTjH.dll
C:\WINDOWS\system32\j3YaFm82.exe.a_a
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\medup012.dll
C:\WINDOWS\system32\msgp.exe
C:\WINDOWS\system32\msnbho.dll
C:\WINDOWS\system32\mssecu.exe
C:\WINDOWS\system32\msvchost.exe
C:\WINDOWS\system32\mtr2.exe
C:\WINDOWS\system32\mwin32.exe
C:\WINDOWS\system32\netode.exe
C:\WINDOWS\system32\newsd32.exe
C:\WINDOWS\system32\osteyfbe.ini
C:\WINDOWS\system32\P4rk4lo5.exe.a_a
C:\WINDOWS\system32\ps1.exe
C:\WINDOWS\system32\psof1.exe
C:\WINDOWS\system32\psoft1.exe
C:\WINDOWS\system32\pwyidgak.dll
C:\WINDOWS\system32\regc64.dll
C:\WINDOWS\system32\regm64.dll
C:\WINDOWS\system32\Rundl1.exe
C:\WINDOWS\system32\smp
C:\WINDOWS\system32\smp\msrc.exe
C:\WINDOWS\system32\sncntr.exe
C:\WINDOWS\system32\snojhn.dll
C:\WINDOWS\system32\ssurf022.dll
C:\WINDOWS\system32\ssvchost.com
C:\WINDOWS\system32\ssvchost.exe
C:\WINDOWS\system32\sysreq.exe
C:\WINDOWS\system32\taack.dat
C:\WINDOWS\system32\taack.exe
C:\WINDOWS\system32\temp#01.exe
C:\WINDOWS\system32\thun.dll
C:\WINDOWS\system32\thun32.dll
C:\WINDOWS\system32\urqPjKaB.dll
C:\WINDOWS\system32\VBIEWER.OCX
C:\WINDOWS\system32\vbsys2.dll
C:\WINDOWS\system32\vcatchpi.dll
C:\WINDOWS\system32\winlogonpc.exe
C:\WINDOWS\system32\winsystem.exe
C:\WINDOWS\system32\WINWGPX.EXE
C:\WINDOWS\system32\ycpxtiug.ini
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\winsystem.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp
----- BITS: Il y a peut-être des sites infectés -----
hxxp://78.157.143.163
hxxp://78.157.143.198
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-19 au 2008-10-19 ))))))))))))))))))))))))))))))))))))
.
2008-10-19 15:34 . 2008-10-19 16:48 3,786 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-19 15:21 . 2008-10-19 15:21 <REP> d-------- C:\Program Files\Avira
2008-10-19 15:21 . 2008-10-19 15:21 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Avira
2008-10-19 10:09 . 2008-10-19 10:08 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-10-19 10:08 . 2008-10-19 10:10 <REP> d-------- C:\Documents and Settings\hp\.housecall6.6
2008-10-18 23:33 . 2008-10-18 23:33 <REP> d-------- C:\Program Files\Panda Security
2008-10-18 23:24 . 2008-10-18 23:24 77,824 --a------ C:\WINDOWS\system32\atsvwrsd.exe
2008-10-18 13:40 . 2008-10-18 13:40 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\kjqxcngr
2008-10-09 16:05 . 2008-10-09 16:05 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-10-09 16:05 . 2004-02-22 10:11 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-10-09 16:05 . 2006-10-07 17:43 502,784 --a------ C:\WINDOWS\x2.64.exe
2008-10-09 16:05 . 2007-05-17 17:30 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2008-10-09 16:05 . 2005-02-28 13:16 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2008-10-09 16:05 . 2006-04-12 09:47 217,073 --a------ C:\WINDOWS\meta4.exe
2008-10-09 16:05 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-10-09 16:05 . 2004-01-25 00:00 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2008-10-09 16:05 . 2006-04-05 08:09 66,560 --a------ C:\WINDOWS\MOTA113.exe
2008-10-09 16:05 . 2005-07-14 12:31 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-10-09 16:04 . 2008-10-09 16:04 <REP> d-------- C:\Program Files\eRightSoft
2008-10-09 16:04 . 2005-02-13 00:00 186,880 -r-hs---- C:\WINDOWS\system32\RLOgg.ax
2008-10-09 16:04 . 2005-01-18 00:26 179,200 -r-hs---- C:\WINDOWS\system32\DiracSplitter.ax
2008-10-09 16:04 . 2006-08-16 15:53 175,104 -r-hs---- C:\WINDOWS\system32\CoreAAC.ax
2008-10-09 16:04 . 2005-02-06 00:00 92,672 -r-hs---- C:\WINDOWS\system32\RLVorbisDec.ax
2008-10-09 16:04 . 2005-02-22 17:55 81,920 -r-hs---- C:\WINDOWS\system32\aac_parser.ax
2008-10-09 16:04 . 2005-02-13 00:00 67,584 -r-hs---- C:\WINDOWS\system32\RLTheoraDec.ax
2008-10-09 16:04 . 2005-02-13 00:00 51,712 -r-hs---- C:\WINDOWS\system32\RLSpeexDec.ax
2008-09-23 00:03 . 2008-09-23 00:03 <REP> d-------- C:\Program Files\Fichiers communs\Windows Media Metering
2008-09-23 00:03 . 2008-10-01 01:21 <REP> d-------- C:\Documents and Settings\hp\Application Data\Windows Media Metering
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 14:58 --------- d-----w C:\Program Files\Mozilla Firefox 2 Beta 2
2008-10-18 11:50 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-10-18 11:30 --------- d-----w C:\Documents and Settings\hp\Application Data\BitTorrent
2008-10-11 20:50 --------- d-----w C:\Documents and Settings\hp\Application Data\Skype
2008-10-11 14:09 --------- d-----w C:\Documents and Settings\hp\Application Data\skypePM
2008-09-27 10:36 --------- d-----w C:\Program Files\LimeWire
2008-09-15 21:27 --------- dc----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-14 10:53 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-10 17:23 --------- d-----w C:\Documents and Settings\hp\Application Data\Viewpoint
2008-09-08 10:18 --------- d-----w C:\Program Files\Neuf
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2007-12-04 21:35 32 -c--a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2006-12-27 18:03 1,882 -c--a-w C:\Documents and Settings\hp\Application Data\wklnhst.dat
2006-11-29 19:59 0 -c--a-w C:\Documents and Settings\Invité\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"StrCfgWin"="C:\WINDOWS\system32\atsvwrsd.exe" [2008-10-18 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-10-31 180269]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-05 160768]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"Autoconfigurateur WiFi Neuf"="C:\Program Files\Neuf\Kit\WiFi\9wifi.exe" [2008-06-09 287984]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"PTxTqYcDMu"="C:\Documents and Settings\All Users\Application Data\kjqxcngr\kjstytyn.exe" [2008-10-18 61440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=bybqsi.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk
backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^hp^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
path=C:\Documents and Settings\hp\Menu Démarrer\Programmes\Démarrage\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^hp^Menu Démarrer^Programmes^Démarrage^Mon agenda personnel Etam.lnk]
path=C:\Documents and Settings\hp\Menu Démarrer\Programmes\Démarrage\Mon agenda personnel Etam.lnk
backup=C:\WINDOWS\pss\Mon agenda personnel Etam.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2007-12-26 03:08 286016 C:\Program Files\BitTorrent_DNA\dna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eabconfg.cpl]
--a------ 2005-12-22 08:57 405504 C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-11-06 16:03 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
-----c--- 2005-02-10 18:00 1937408 C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-11-12 16:48 21760296 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-10-31 16:26 180269 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\adslTV\\adsltv.exe"=
"C:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"28087:TCP"= 28087:TCP:LIME
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 20096]
S3 RSPSC;RSPSC;C:\WINDOWS\system32\drivers\rspsc.sys [ ]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59cce907-7fcc-11db-bdec-0014a5b73cc0}]
\Shell\AutoRun\command - E:\setupSNK.exe
.
Contenu du dossier 'Tâches planifiées'
2008-10-19 C:\WINDOWS\Tasks\At100.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At101.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At102.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At103.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At104.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At105.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At106.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At107.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At108.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At109.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At110.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At111.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At112.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At113.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At114.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At115.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At116.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At117.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At118.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At119.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At120.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At121.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At122.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At123.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At124.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At125.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At126.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At127.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At128.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At129.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At130.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At131.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At132.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At133.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At134.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At135.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At136.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At137.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-19 C:\WINDOWS\Tasks\At138.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At139.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At140.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At141.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At142.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At143.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
2008-10-18 C:\WINDOWS\Tasks\At144.job
- C:\WINDOWS\system32\j3YaFm82.exe [2008-08-10 19:32]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{343C2D3D-295E-4256-A18F-C0204F026CE5} - C:\WINDOWS\grfxbanofek.dll
BHO-{3A28E93D-6636-4BF3-BDD5-4EFBC81A7AC1} - C:\WINDOWS\system32\urqPjKaB.dll
BHO-{758F6D53-DCC7-4CCF-9080-4B6F9389F641} - C:\WINDOWS\system32\geBronmm.dll
BHO-{a61ec8ea-20d8-4b93-b51d-ebe12fa27e71} - C:\WINDOWS\system32\bybqsi.dll
ShellExecuteHooks-{758F6D53-DCC7-4CCF-9080-4B6F9389F641} - C:\WINDOWS\system32\geBronmm.dll
MSConfigStartUp-DAEMON Tools - C:\Program Files\DAEMON Tools\daemon.exe
MSConfigStartUp-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-WinMsg - C:\WINDOWS\winmsgr.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\hp\Application Data\Mozilla\Firefox\Profiles\xe0s6p9l.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&SearchSource=3&a(...)
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.facebook.com/home.php
FF -: plugin - C:\Program Files\BitTorrent_DNA\npbtdna.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\np32dsw.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npdivx32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npnul32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\NPOFFICE.DLL
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\nppdf32.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin3.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin4.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin5.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin6.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\npqtplugin7.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\nprjplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox 2 Beta 2\plugins\NPSWF32.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-19 17:45:38
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????e????|?????? ???B?????????????hLC? ??????
Recherche de fichiers cachés ...
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\HPQ\shared\HPQTOA~1.EXE
.
**************************************************************************
.
Heure de fin: 2008-10-19 18:00:26 - La machine a redémarré [hp]
ComboFix-quarantined-files.txt 2008-10-19 15:59:15
Avant-CF: 82,919,481,344 octets libres
Après-CF: 82,124,017,664 octets libres
398 --- E O F --- 2008-10-16 01:21:07