"Pierrot" - 07-04-06 11:45:37 Service Pack 2
ComboFix 07-04-05 - Running from: "C:\Documents and Settings\Pierrot\Bureau"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\b.exe
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
-------\LEGACY_MCHINJDRV
((((((((((((((((((((((((((((((( Files Created from 2007-03-06 to 2007-04-06 ))))))))))))))))))))))))))))))))))
2007-04-06 11:04 <REP> d-------- C:\Program Files\SDFix
2007-04-05 20:04 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-04-04 18:01 79,360 --a------ C:\WINDOWS\SYSTEM32\swxcacls.exe
2007-04-04 18:01 51,200 --a------ C:\WINDOWS\SYSTEM32\dumphive.exe
2007-04-04 18:01 40,960 --a------ C:\WINDOWS\SYSTEM32\swsc.exe
2007-04-04 18:01 288,417 --a------ C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-04-04 18:01 2,874 --a------ C:\WINDOWS\SYSTEM32\tmp.reg
2007-04-04 18:01 135,168 --a------ C:\WINDOWS\SYSTEM32\swreg.exe
2007-04-04 17:04 <REP> dr------- C:\DOCUME~1\NETWOR~1\Favoris
2007-04-04 17:03 427,520 --a------ C:\WINDOWS\WRServices.dll
2007-04-04 17:03 102,912 --a------ C:\WINDOWS\SYSTEM32\islzma.dll
2007-04-04 17:03 <REP> d-------- C:\Program Files\Webroot
2007-04-04 17:03 <REP> d-------- C:\DOCUME~1\Pierrot\APPLIC~1\Webroot
2007-04-04 15:26 53,248 --a------ C:\WINDOWS\SYSTEM32\Process.exe
2007-04-03 18:14 <REP> d--hs---- C:\WINDOWS\CSC
2007-04-03 15:19 <REP> d-------- C:\DOCUME~1\Pierrot\APPLIC~1\SystemDoctor 2006 Free
2007-04-03 15:02 8,448 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\vspf_hk5.sys
2007-04-03 15:02 41,984 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\FOPN.sys
2007-04-03 15:02 21,888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\vspf5.sys
2007-04-03 15:02 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiVirus Pro 2006
2007-04-02 08:40 <REP> d-------- C:\Program Files\Atari
2007-04-01 19:11 <REP> d-------- C:\WINDOWS\SYSTEM32\ActiveScan
2007-04-01 19:05 <REP> d-------- C:\Program Files\Webshots
2007-04-01 19:05 <REP> d-------- C:\DOCUME~1\Pierrot\APPLIC~1\Webshots
2007-04-01 15:30 <REP> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-04-01 15:30 <REP> d-------- C:\Program Files\SH.zip
2007-03-30 22:58 <REP> d-------- C:\Program Files\DAEMON Tools
2007-03-30 17:50 <REP> d-------- C:\Program Files\TryMedia
2007-03-30 17:49 <REP> d-------- C:\Program Files\ValuSoft
2007-03-27 18:25 223,128 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\dtscsi.sys
2007-03-27 18:24 96,256 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sptd5421.sys
2007-03-27 18:24 642,560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\sptd.sys
2007-03-26 17:39 <REP> d-------- C:\Program Files\Alwil Software
2007-03-20 13:26 <REP> d-------- C:\Program Files\THQ
2007-03-18 21:03 <REP> d-------- C:\GFactory
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-06 11:01 73292 --a------ C:\WINDOWS\SYSTEM32\perfc00c.dat
2007-04-06 11:01 464106 --a------ C:\WINDOWS\SYSTEM32\perfh00c.dat
2007-04-04 18:53 -------- d-------- C:\Program Files\mozilla thunderbird
2007-04-03 10:06 -------- d-------- C:\Program Files\emule
2007-04-02 15:57 -------- d-------- C:\Program Files\trackmania nations eswc
2007-04-02 14:01 -------- d-------- C:\Program Files\mortyr 2 demo
2007-04-02 10:21 -------- d-------- C:\Program Files\warrock
2007-03-30 16:07 -------- d-------- C:\Program Files\call of duty single player demo
2007-03-26 10:38 -------- d-------- C:\Program Files\jowood
2007-03-20 13:26 -------- d--h----- C:\Program Files\installshield installation information
2007-03-18 16:25 -------- d-------- C:\Program Files\ea games
2007-03-18 11:17 -------- d-------- C:\Program Files\gamespy arcade
2007-03-13 21:07 -------- d-------- C:\Program Files\call of duty dawnville demo
2007-03-12 21:54 -------- d-------- C:\Program Files\call of duty united offensive single player demo
2007-03-08 17:37 578560 --a------ C:\WINDOWS\SYSTEM32\user32.dll
2007-03-08 17:37 40960 --a------ C:\WINDOWS\SYSTEM32\mf3216.dll
2007-03-08 17:37 281600 --a------ C:\WINDOWS\SYSTEM32\gdi32.dll
2007-03-08 17:33 1843712 --a------ C:\WINDOWS\SYSTEM32\win32k.sys
2007-02-28 19:52 -------- d-------- C:\Program Files\zelda return of the hylian
2007-02-19 12:41 -------- d-------- C:\Program Files\wesnoth
2007-02-19 01:58 -------- d-------- C:\Program Files\windows defender
2007-02-12 12:43 -------- d-------- C:\Program Files\the mark demo
2007-01-28 11:35 108144 --a------ C:\WINDOWS\SYSTEM32\cmdlineext.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -masquer"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
"cmonitor"=""
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe\" /startintray"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"C-Media Mixer"="Mixer.exe /startup"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
@=""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime"
"DWQueuedReporting"="\"C:\\PROGRA~1\\FICHIE~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\df_kmd.sys
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
hklm\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
UxTuneUp
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Maintenance en 1 clic.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-06 11:51:25
C:\ComboFix-quarantined-files.txt ... 07-04-06 11:51