Bon, bon, bon, excuse moi, j'ai des mèches blondes ...
ComboFix 08-01-23.1C - Propri‚taire 2008-01-29 20:00:28.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.33 [GMT 1:00]
Endroit: C:\Documents and Settings\Propri‚taire\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
.
The following files were disabled during the run:
C:\WINDOWS\system32\guard32.dll
((((((((((((((((((((((((((((( Fichiers créés 2007-12-28 to 2008-01-29 ))))))))))))))))))))))))))))))))))))
.
2008-01-29 19:58 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-26 19:40 . 2008-01-26 19:40 <REP> d-------- C:\bin
2008-01-26 19:38 . 2008-01-26 19:38 <REP> d-------- C:\Program Files\Fichiers communs\Sonic Shared
2008-01-26 18:29 . 2008-01-26 18:30 128,146 --------- C:\WINDOWS\hpoins11.dat.temp
2008-01-26 18:29 . 2006-05-06 00:21 11,634 --------- C:\WINDOWS\hpomdl11.dat.temp
2008-01-20 21:16 . 2008-01-20 21:16 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-19 12:35 . 2008-01-26 19:56 128,280 --a------ C:\WINDOWS\hpoins11.dat
2008-01-19 12:10 . 2006-12-30 15:49 117,760 --a------ C:\WINDOWS\system32\hpzll4v2.dll
2008-01-19 10:59 . 2008-01-19 12:01 148,088 --a------ C:\WINDOWS\hpoins12.dat
2008-01-19 10:59 . 2007-01-22 17:05 1,470 --------- C:\WINDOWS\hpomdl12.dat
2008-01-19 00:09 . 2006-01-04 10:12 77,824 -ra------ C:\WINDOWS\system32\HPZIDS01.dll
2008-01-19 00:09 . 2006-04-10 14:03 38,400 --a------ C:\WINDOWS\system32\hpz3l054.dll
2007-12-31 00:46 . 2007-12-31 00:46 <REP> d-------- C:\Program Files\Trend Micro
2007-12-31 00:23 . 2007-12-31 00:23 <REP> d-------- C:\Program Files\Yahoo!
2007-12-31 00:22 . 2007-12-31 00:25 <REP> d-------- C:\Program Files\CCleaner
2007-12-30 21:33 . 2007-12-30 21:33 <REP> d-------- C:\Program Files\AxBx
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 10:17 --------- d---a-w C:\Program Files\Hewlett-Packard
2008-01-19 10:17 --------- d---a-w C:\Program Files\Fichiers communs\HP
2008-01-19 10:13 --------- d---a-w C:\Program Files\HP
2007-12-21 14:31 --------- d---a-w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-21 14:00 --------- d-----w C:\Program Files\Norton Security Scan
2007-12-07 20:06 --------- d-----w C:\Program Files\Google
2007-12-07 19:34 --------- d-----w C:\Program Files\XOP Demo
2007-12-07 19:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-07 19:29 --------- d-----w C:\Program Files\Comodo
2007-12-07 19:18 --------- d-----w C:\Program Files\eMule
2007-12-07 19:15 --------- d-----w C:\Program Files\Ahead
2007-12-04 14:56 93,264 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2005-09-29 08:51 976,020 -c--a-w C:\Program Files\BDAXP.cab
2005-09-29 08:51 703,080 -c--a-w C:\Program Files\BDA.cab
2005-09-29 08:51 15,493,481 -c--a-w C:\Program Files\DirectX.cab
2005-09-29 08:51 1,156,363 -c--a-w C:\Program Files\BDANT.cab
2007-03-17 21:27 16,384 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2007-02-26 03:08 393,216 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007021920070226\index.dat
2007-03-05 19:32 131,072 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007022620070305\index.dat
2007-03-12 13:46 131,072 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007030520070312\index.dat
2007-03-12 20:52 49,152 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031220070313\index.dat
2007-03-13 20:27 65,536 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031320070314\index.dat
2007-03-14 17:55 65,536 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031420070315\index.dat
2007-03-15 22:39 49,152 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031520070316\index.dat
2007-03-16 20:00 49,152 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031620070317\index.dat
2007-03-17 21:27 32,768 -csha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007031720070318\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll" [2003-05-03 06:19 835654 C:\WINDOWS\system32\nview.dll]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 17:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04 52736]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 14:07 114688]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 14:23 90112]
"HPHUPD05"="c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 10:03 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-05-23 09:56 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 03:02 61440]
"StorageGuard"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-02-13 15:01 155648]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 04:42 212992]
"VTTimer"="VTTimer.exe" [2003-05-08 07:32 36864 C:\WINDOWS\system32\VTTimer.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-05-03 06:19 4640768]
"nwiz"="nwiz.exe" [2003-05-03 06:19 323584 C:\WINDOWS\system32\nwiz.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-19 21:10 335872]
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-08-09 11:27 139264]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 50176 C:\WINDOWS\ALCXMNTR.EXE]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-06-18 01:13 118784]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 23:57 81920]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-22 10:13 98304]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\cfp.exe" [2007-11-22 20:10 1481984]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-12-10 21:52 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2007-11-22 20:10]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2007-11-22 20:10]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 gtermddo;gtermddo;C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\gtermddo.sys []
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2005-08-18 20:56:23 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1103895704.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
"2007-12-21 17:36:04 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-29 20:21:40
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
.
Temps d'accomplissement: 2008-01-29 20:26:18
.
2008-01-09 19:14:09 --- E O F ---