ComboFix 09-05-14.02 - Ced 16/05/2009 0:36.2 - NTFSx86
Lancé depuis: c:\documents and settings\Ced\Bureau\bibite.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Exécution préalable -------
.
C:\
0bcobed.exe
C:\
0xuc.com
C:\1ogf.exe
C:\abk.bat
C:\Autorun.inf
C:\boyedt.com
C:\cqxj.exe
c:\documents and settings\Ced\Application Data\~tmp.html
c:\documents and settings\Ced\Application Data\config.cfg
c:\documents and settings\Ced\Bureau\System Security 2009.lnk
C:\e2.cmd
C:\ej10fkdo.bat
C:\em8tqm.cmd
C:\eyt.exe
C:\fbak.exe
C:\g1ljsm.com
C:\gyn.cmd
C:\hkn6k.bat
C:\jm3cx96.bat
C:\lc.exe
C:\luk1ylq.com
C:\minm.cmd
C:\npee.com
C:\nu.cmd
C:\o3n9k.com
c:\program files\Microsoft Office\WINWORD.EXE
c:\program files\newdotnet
c:\program files\newdotnet\nnrun.exe
c:\program files\newdotnet\readme.html
c:\program files\newdotnet\uninstall.exe
C:\q0dhfjf.exe
C:\qwtb.com
C:\rbj9jn1n.bat
C:\upw.bat
C:\uxkl0apt.bat
C:\vwewav8.com
C:\w2.com
c:\windows\alg.exe
c:\windows\ctfmon.exe
c:\windows\emMON.exe
c:\windows\lsass.exe
c:\windows\NDNuninstall6_38.exe
c:\windows\NDNuninstall7_48.exe
c:\windows\odb.exe
c:\windows\svc.exe
c:\windows\svw.exe
c:\windows\svx.exe
c:\windows\system32\gasretyw1.dll
c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds1.dll
c:\windows\system32\ntos.exe
c:\windows\system32\olhrwef.exe
c:\windows\system32\wsnpoem
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\audio.dll.cla
c:\windows\system32\wsnpoem\video.dll
c:\windows\vlc.exe
c:\windows\wdmon.exe
C:\xsia.bat
C:\ymxf2.exe
C:\ysep1.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NNSERV
-------\Service_NNServ
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-15 au 2009-05-15 ))))))))))))))))))))))))))))))))))))
.
2009-05-14 21:28 . 2009-05-15 22:34 -------- d-----w C:\rsit
2009-05-13 21:05 . 2009-05-13 21:05 -------- d-----w C:\Rooter$
2009-05-12 18:08 . 2009-05-12 18:08 -------- d-sh--w c:\windows\system32\config\systemprofile\IETldCache
2009-05-12 18:03 . 2009-05-12 18:02 281600 ----a-w c:\windows\servicelayer.exe
2009-05-12 18:03 . 2009-05-12 18:01 281600 ----a-w c:\windows\amoumain.exe
2009-05-12 17:58 . 2009-05-12 18:06 109 --sha-w c:\windows\system32\4174150470.dat
2009-05-12 17:57 . 2009-05-15 22:31 -------- d-----w c:\documents and settings\All Users\Application Data\16097344
2009-05-12 17:57 . 2009-05-12 17:57 41472 --sh--r c:\windows\system32\Adobev.exe
2009-05-09 21:59 . 2009-05-09 21:59 -------- d-sh--w c:\documents and settings\Ced\IECompatCache
2009-05-08 13:19 . 2009-05-08 13:19 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-08 12:49 . 2009-05-08 12:49 -------- d-sh--w c:\documents and settings\Ced\PrivacIE
2009-05-08 12:45 . 2009-05-08 12:45 -------- d-sh--w c:\documents and settings\Ced\IETldCache
2009-05-08 12:42 . 2009-05-08 12:42 -------- d--h--w c:\windows\msdownld.tmp
2009-05-08 12:42 . 2009-05-08 12:42 -------- d-----w c:\windows\ie8updates
2009-05-08 12:37 . 2009-05-08 12:39 -------- dc-h--w c:\windows\ie8
2009-05-08 12:34 . 2009-04-25 05:30 102400 ------w c:\windows\system32\dllcache\iecompat.dll
2009-05-08 11:27 . 2009-05-08 20:55 -------- d-----w c:\program files\Microsoft Silverlight
2009-05-08 11:23 . 2009-05-08 11:23 -------- d-----w c:\program files\Microsoft
2009-05-07 18:32 . 2009-05-07 18:32 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-06 19:56 . 2009-05-06 19:56 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 22:31 . 2006-10-01 21:16 -------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-05-12 21:39 . 2006-10-01 13:25 90112 ----a-w c:\windows\DUMP4f48.tmp
2009-05-08 13:10 . 2004-08-16 16:41 83760 ----a-w c:\windows\system32\perfc00C.dat
2009-05-08 13:10 . 2004-08-16 16:41 488658 ----a-w c:\windows\system32\perfh00C.dat
2009-05-08 12:56 . 2007-06-07 19:45 -------- d-----w c:\program files\Windows Live
2009-05-06 20:00 . 2006-10-02 17:52 -------- d-----w c:\program files\Google
2009-04-21 21:13 . 2009-03-12 07:31 -------- d-----w c:\program files\adslTV
2009-04-19 15:31 . 2006-10-01 21:16 -------- d-----w c:\program files\Norton Internet Security
2009-04-13 18:27 . 2006-10-01 21:16 -------- d-----w c:\program files\Java
2009-04-04 11:28 . 2006-10-01 21:16 -------- d-----w c:\program files\Fichiers communs\Nullsoft
2009-04-04 11:26 . 2006-10-01 21:16 -------- d-----w c:\program files\Fichiers communs\AOL
2009-03-21 09:11 . 2006-12-04 08:47 -------- d-----w c:\program files\eMule
2009-03-09 03:19 . 2009-03-14 18:20 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 02:34 . 2004-08-16 16:41 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2004-08-16 16:40 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2004-08-16 16:40 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2004-08-16 16:41 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2004-08-16 16:39 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2004-08-16 16:40 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2004-08-16 16:40 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2004-08-16 16:40 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2004-08-16 16:40 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2004-08-16 16:40 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2004-08-16 16:40 286720 ----a-w c:\windows\system32\pdh.dll
2009-02-22 08:09 . 2006-10-01 14:38 57032 ----a-w c:\documents and settings\Ced\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-11-08 08:29 . 2007-07-12 20:32 8192 --sha-w c:\program files\Thumbs.db
.
------- Sigcheck -------
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-05 13:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"ATIPTA"="c:\ati technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-04-04 71304]
"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2004-01-27 70760]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2004-10-08 81920]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2003-11-10 406016]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2006-10-12 100056]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-02-22 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"amoumain"="c:\windows\amoumain.exe" [2009-05-12 281600]
"servicelayer"="c:\windows\servicelayer.exe" [2009-05-12 281600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave2"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\Inventime\\my.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\adslTV\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:emule tcp entrant
"4672:UDP"= 4672:UDP:emule udp entrant
R2 gupdate1c9ce84bad357ec;Service Google Update (gupdate1c9ce84bad357ec);c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 133104]
R3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);c:\windows\system32\DRIVERS\v800bus.sys [2004-08-09 52416]
R3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;c:\windows\system32\DRIVERS\v800mdfl.sys [2004-08-09 6160]
R3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;c:\windows\system32\DRIVERS\v800mdm.sys [2004-08-09 84544]
R3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\v800mgmt.sys [2004-08-09 77760]
R3 v800obex;Sony Ericsson V800-Vodafone 802SE USB WMC OBEX Interface;c:\windows\system32\DRIVERS\v800obex.sys [2004-08-09 75584]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - ALG
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - AOL ACS
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - cbidf
*Deregistered* - ccEvtMgr
*Deregistered* - ccProxy
*Deregistered* - ccSetMgr
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CmdIde
*Deregistered* - Cpqarray
*Deregistered* - CryptSvc
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - dpti2o
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - gagp30kx
*Deregistered* - Gpc
*Deregistered* - gupdate1c9ce84bad357ec
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - hpn
*Deregistered* - HTTP
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - LVUSBSta
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - mraid35x
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - navapsvc
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - PCIIde
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - Pml Driver HPZ12
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RecAgent
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - SAVRT
*Deregistered* - SAVRTPEL
*Deregistered* - SAVScan
*Deregistered* - SBService
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SLService
*Deregistered* - SlWdmSup
*Deregistered* - SNDSrvc
*Deregistered* - Sparrow
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - SymWSC
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TosIde
*Deregistered* - TrkWks
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - wanatw
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WmiApSrv
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WudfPf
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0709fa7a-33bc-11de-9c77-00038a000015}]
\Shell\AutoRun\command - J:\fbak.exe
\Shell\open\Command - J:\fbak.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14edbdec-4049-11dc-991a-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a9bcb96-d510-11dd-9be7-00038a000015}]
\Shell\AutoRun\command - J:\abk.bat
\Shell\explore\Command - J:\abk.bat
\Shell\open\Command - J:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a9bcb97-d510-11dd-9be7-00038a000015}]
\Shell\AutoRun\command - K:\abk.bat
\Shell\explore\Command - K:\abk.bat
\Shell\open\Command - K:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2539bb6b-16cb-11de-9c43-00038a000015}]
\Shell\AutoRun\command - I:\jm3cx96.bat
\Shell\open\Command - I:\jm3cx96.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3ee8fffc-7866-11dd-9b48-00038a000015}]
\Shell\AutoRun\command - iqe68o.bat
\Shell\explore\Command - iqe68o.bat
\Shell\open\Command - iqe68o.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5de01077-147e-11de-9c3e-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f6e5000-b665-11dd-9bbc-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6d59de66-e13d-11dd-9bf3-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9b1543ee-f86d-11dd-9c0b-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce336cc2-515f-11db-970b-00038a000015}]
\Shell\AutoRun\command - J:\abk.bat
\Shell\explore\Command - J:\abk.bat
\Shell\open\Command - J:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d79ce97d-bcb6-11dd-9bc6-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc2e6e4b-9d33-11dd-9b8d-00038a000015}]
\Shell\AutoRun\command - J:\abk.bat
\Shell\explore\Command - J:\abk.bat
\Shell\open\Command - J:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f67651ac-247c-11de-9c5b-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6d6e693-8183-11dc-998f-00038a000015}]
\Shell\AutoRun\command - I:\abk.bat
\Shell\explore\Command - I:\abk.bat
\Shell\open\Command - I:\abk.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f74bfa7e-c22e-11dd-9bcf-00038a000015}]
\Shell\AutoRun\command - K:\abk.bat
\Shell\explore\Command - K:\abk.bat
\Shell\open\Command - K:\abk.bat
.
Contenu du dossier 'Tâches planifiées'
2009-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-05-15 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 19:56]
2009-05-13 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur - Ced.job
- c:\progra~1\NORTON~1\NORTON~1\NAVW32.EXE [2003-08-22 18:06]
2009-05-15 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2003-08-22 18:06]
2009-04-20 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-02-12 12:39]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-16097344 - c:\documents and settings\All Users\Application Data\16097344\16097344.exe
HKLM-Run-odby - c:\windows\odb.exe
HKLM-Run-ctfmon - c:\windows\ctfmon.exe
HKLM-Run-alg - c:\windows\alg.exe
SharedTaskScheduler-IPC Configuration Utility - (no file)
Notify-WgaLogon - (no file)
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.ozap.com/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-16 00:40
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,fd,4f,af,bf,34,
5a,87,ae,e2,63,26,f1,3f,c8,ff,68,20,53,0f,11,19,04,65,e9,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,52,b3,01,4d,dd,
bb,96,52,6a,9c,d6,61,af,45,84,18,2e,68,8c,43,99,91,d2,c3,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,32,45,47,7f,8c,
1c,db,0c,ff,7c,85,e0,43,d4,0e,fe,aa,1d,64,ae,53,ff,61,f4,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,a3,da,98,41,f1,
21,48,aa,86,8c,21,01,be,91,eb,e7,3f,68,9b,b4,d2,b6,cf,4b,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,85,9f,31,06,2a,
f3,73,b8,f5,1d,4d,73,a8,13,5c,05,96,a6,7d,73,4e,44,b7,cc,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,03,ee,5b,d3,65,
af,65,11,df,20,58,62,78,6b,cf,c8,dc,44,ca,3e,fb,4d,9e,94,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,36,f3,8d,02,ab,
86,c1,b3,fb,a7,78,e6,12,2f,9a,ea,14,d4,94,77,44,84,4f,8b,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:aa,52,c6,00,84,3c,26,64,7f,0b,35,a4,99,
93,eb,47,01,3a,48,fc,e8,04,4a,f1,62,37,bb,59,4a,50,4b,b9,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c0,57,b5,ad,81,
ae,ee,80,f6,0f,4e,58,98,5b,89,c9,03,4c,38,72,d2,16,6b,38,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,3b,7f,fd,d6,00,
18,3b,43,3d,ce,ea,26,2d,45,aa,78,16,4e,ff,12,4a,f4,c2,ca,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,c2,2d,45,9d,01,
e2,57,24,2a,b7,cc,b5,b9,7f,41,e7,73,7c,8f,71,5b,69,03,70,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,26,b9,ba,d9,12,
15,56,14,6c,43,2d,1e,aa,22,2f,9c,88,f8,42,16,6b,73,a8,de,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2324)
c:\progra~1\FICHIE~1\SYMANT~1\ANTISPAM\asOEHook.dll
c:\program files\CyberLink\Shared Files\CLRCEngine.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\program files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
c:\program files\Logitech\Video\Namespc2.dll
c:\program files\Logitech\Video\AlbuDBps.dll
c:\windows\Twain_32\QuickCam\lvWIAext.dll
.
Heure de fin: 2009-05-15 0:43
ComboFix-quarantined-files.txt 2009-05-15 22:43
Avant-CF: 21 639 012 352 octets libres
Après-CF: 21 701 398 528 octets libres
561 --- E O F --- 2009-05-13 12:38