ComboFix 08-02-22.3 - utilisateur 2008-02-22 20:09:51.6 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.545 [GMT 1:00]
Endroit: C:\Documents and Settings\utilisateur\Bureau\Killbagle.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))))))))
.
2008-02-20 18:49 . 2008-02-20 18:51 900 --a------ C:\WINDOWS\Active Setup Log.BAK
2008-02-19 21:46 . 2008-02-19 21:46 1,782 --a------ C:\WINDOWS\system32\svchost.exe.virtual.lnk
2008-02-19 20:59 . 2008-02-20 19:45 <REP> d-------- C:\Program Files\AxBx
2008-02-19 20:24 . 2008-02-19 20:24 <REP> d-------- C:\WINDOWS\D1534F6AD2E14F278D266DEB9E095D39.TMP
2008-02-19 19:27 . 2008-02-19 19:27 <REP> d-------- C:\Program Files\Webroot
2008-02-19 19:27 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2008-02-19 19:27 . 2007-10-01 16:24 23,864 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-02-19 19:21 . 2008-02-19 19:21 164 --a------ C:\install.dat
2008-02-19 18:29 . 2008-02-19 18:29 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\ItsLabel
2008-02-19 18:25 . 2008-02-19 18:25 <REP> d-------- C:\Program Files\Alwil Software
2008-02-19 18:24 . 2008-02-19 19:22 <REP> d-------- C:\Program Files\EoRezo
2008-02-19 18:24 . 2008-02-19 19:22 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\EoRezo
2008-02-19 13:00 . 2008-02-20 19:42 31 --a------ C:\WINDOWS\warhead.ini
2008-02-18 21:06 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-02-18 21:06 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-02-18 21:06 . 2008-02-18 21:06 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-02-18 21:06 . 2008-02-18 21:06 3,120 --a------ C:\WINDOWS\118294.78
2008-02-18 21:06 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-02-18 20:05 . 2008-02-19 19:54 <REP> d-------- C:\Program Files\Panda Security
2008-02-17 19:40 . 2008-02-17 19:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-17 19:40 . 2008-02-17 19:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-17 17:41 . 2008-02-17 17:41 <REP> d-------- C:\Program Files\Picasa2
2008-02-17 17:40 . 2008-02-17 17:40 <REP> d-------- C:\WINDOWS\230C4A452586416184EF5C0D75D5B270.TMP
2008-02-17 17:40 . 2008-02-19 20:23 121,439 --a------ C:\WINDOWS\system32\63F15B6B14AF427FA17CCE7D54235929
2008-02-17 17:16 . 2008-02-17 17:16 35,363 --a------ C:\WINDOWS\system32\windrvNT.sys
2008-02-17 15:22 . 2008-02-19 19:47 <REP> d-------- C:\Program Files\Spyware Doctor
2008-02-17 15:22 . 2008-02-17 15:22 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\PC Tools
2008-02-17 15:22 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-17 15:22 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-17 15:22 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-17 15:22 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-02-16 22:02 . 2008-02-16 22:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-02-16 22:00 . 2008-02-16 22:00 <REP> d-------- C:\Program Files\GameHouse
2008-02-16 22:00 . 2008-02-16 22:00 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\GameHouse
2008-02-16 18:31 . 2008-02-16 21:55 <REP> d-------- C:\Program Files\Cake Mania 2
2008-02-16 11:34 . 2008-02-16 11:37 <REP> d-------- C:\Program Files\Fab Fashion
2008-02-16 10:39 . 2008-02-16 10:40 <REP> d-------- C:\Program Files\Cake Mania Back to the Bakery
2008-02-15 21:25 . 2008-02-16 21:56 <REP> d-------- C:\Program Files\Cake Mania
2008-02-15 21:24 . 2008-02-15 21:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-02-15 17:36 . 2008-02-16 10:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-02-15 09:49 . 2008-02-15 09:49 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\Fuzzy Games
2008-02-11 19:04 . 2008-02-11 19:10 <REP> d-------- C:\Program Files\Mozilla Thunderbird
2008-02-11 19:04 . 2008-02-11 19:04 <REP> d-------- C:\Documents and Settings\utilisateur\Application Data\Thunderbird
2008-02-08 17:40 . 2008-02-08 17:40 <REP> d-------- C:\WINDOWS\Build A Lot
2008-02-08 17:40 . 2008-02-08 17:40 <REP> d-------- C:\Program Files\Build A Lot
2008-02-08 17:31 . 2008-02-08 17:31 <REP> d-------- C:\Program Files\Build-a-lot
2008-02-06 18:04 . 2008-02-06 18:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\HipSoft
2008-02-04 20:01 . 2008-02-04 20:01 31 --a------ C:\WINDOWS\utpath.inf
2008-02-04 20:00 . 2008-02-05 13:15 <REP> d-------- C:\Program Files\Aquatic Tycoon
2008-02-04 19:58 . 2008-02-04 19:58 <REP> d-------- C:\Program Files\Managed DirectX (0900)
2008-02-02 13:49 . 2008-02-02 13:49 0 --a------ C:\WINDOWS\system32\BufferZone.CSV
2008-01-26 13:51 . 2008-01-26 13:51 <REP> d-------- C:\Program Files\Codemasters
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 19:02 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\OpenOffice.org2
2008-02-22 19:01 --------- d-----w C:\Program Files\BufferZone
2008-02-22 11:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-19 19:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-19 19:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-02-19 19:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-19 18:31 --------- d-----w C:\Program Files\Web Hottest Videos Personal Player
2008-02-19 12:02 --------- d-----w C:\Program Files\Pack Securite
2008-02-18 20:31 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-18 20:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 20:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-18 17:57 --------- d-----w C:\Program Files\eMule
2008-02-17 12:11 --------- d-----w C:\Program Files\PC Tools AntiVirus
2008-02-16 21:00 --------- d-----w C:\Program Files\Zylom Games
2008-02-15 08:48 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Zylom
2008-02-14 17:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-13 17:03 30,016 ----a-w C:\WINDOWS\system32\drivers\fsndis5.sys
2008-02-11 18:22 --------- d-----w C:\Program Files\Google
2008-02-11 18:14 --------- d-----w C:\Program Files\GameSpy Arcade
2008-02-09 12:02 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\Azureus
2008-02-09 11:33 --------- d-----w C:\Program Files\Azureus
2008-02-03 08:57 --------- d-----w C:\Program Files\Secured eMule
2008-01-26 13:22 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-01-20 18:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2008-01-20 17:48 --------- d-----w C:\Program Files\Chocolatier Deluxe
2008-01-13 19:31 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-01-13 18:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\BufferZone
2008-01-13 18:34 --------- d-----w C:\Program Files\Secured_eMule
2008-01-11 16:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-01-11 16:54 --------- d-----w C:\Program Files\Delicious 2 Deluxe
2008-01-11 15:59 --------- d-----w C:\Program Files\FreshGames
2008-01-11 11:41 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\PlayFirst
2008-01-11 11:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-01-01 15:07 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-01-01 15:07 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-01-01 15:06 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-01-01 15:06 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-01-01 15:06 --------- d-----w C:\Program Files\Real
2007-12-31 15:42 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\AVG7
2007-12-30 17:34 --------- d---a-w C:\Program Files\Windows Live
2007-12-30 17:33 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-30 17:31 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-12-30 10:51 --------- d-----w C:\Program Files\Adobe Type Manager
2007-12-30 10:45 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\vlc
2007-12-27 18:19 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-26 17:24 --------- d-----w C:\Documents and Settings\utilisateur\Application Data\PCToolsFirewallPlus
2007-12-24 09:47 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-17 00:11 428,060 ----a-w C:\WINDOWS\system32\Ole2Plgin.dll
2007-12-17 00:11 1,212,928 ----a-w C:\WINDOWS\system32\RlShellExt.dll
2007-12-07 01:07 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
2008-01-13 19:34 1502232 --a------ C:\Program Files\Secured_eMule\tbSec1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{039036AA-7710-11D7-ACDA-00B0D094B576}
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{1D1B60FD-B21F-4B9A-8A5F-64E8544828D7}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{1D1B60FD-B21F-4B9A-8A5F-64E8544828D7}"= C:\Program Files\Secured_eMule\tbSec1.dll [2008-01-13 19:34 1502232]
[HKEY_CLASSES_ROOT\clsid\{1d1b60fd-b21f-4b9a-8a5f-64e8544828d7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzBufferZoneOverlay]
@={37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzConfidentialOverlay]
@={F594B094-8768-4632-8143-12852EBBD688}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzForbiddenOverlay]
@={F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SxBzUnknownOverlay]
@={E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}
[HKEY_CLASSES_ROOT\CLSID\{37ADBD0B-11EC-4A2C-9F93-5C3ACC7994DF}]
2007-12-17 01:11 1212928 --a------ C:\WINDOWS\system32\RlShellExt.dll
[HKEY_CLASSES_ROOT\CLSID\{F594B094-8768-4632-8143-12852EBBD688}]
2007-12-17 01:11 1212928 --a------ C:\WINDOWS\system32\RlShellExt.dll
[HKEY_CLASSES_ROOT\CLSID\{F1A1DA12-E651-4AD0-A1A0-6214546B2F9D}]
2007-12-17 01:11 1212928 --a------ C:\WINDOWS\system32\RlShellExt.dll
[HKEY_CLASSES_ROOT\CLSID\{E4FC4B31-8A4F-45E6-BDAC-28F612371FE3}]
2007-12-17 01:11 1212928 --a------ C:\WINDOWS\system32\RlShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-27 15:19 4670704]
"ProtectionDeDriver"="C:\Program Files\ProtectionDeDriver\GDC.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"BufferZone"="C:\Program Files\BufferZone\CLIENTGUI.exe" [2007-12-17 01:11 3250912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [ ]
C:\Documents and Settings\utilisateur\Menu D‚marrer\Programmes\D‚marrage\
Hotkeys.lnk - C:\Documents and Settings\utilisateur\Application Data\Microsoft\Installer\{C1D1E3E7-0A50-426D-8FAD-64112F6C7184}\_4d064db7.exe [2007-09-16 10:28:43 25214]
OpenOffice.org 2.2.lnk - C:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 16:54:56 393216]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-08-25 14:29:28 131584]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-08-25 19:01:37 124912]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWinKeys"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"= %windir%\\system32\\sessmgr.exe:@xpsp2res.dll,-22019
"C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
R0 REDLIGHT;REDLIGHT;C:\WINDOWS\system32\drivers\REDLIGHT.SYS [2007-12-17 01:05]
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\Pack Securite\HIPS\fshs.sys [2008-02-13 18:02]
R2 BufferZoneSvc;BufferZone Service;C:\Program Files\BufferZone\CLNTSVC.EXE [2007-12-17 01:11]
R2 BZDcomLaunch;BufferZone DCOM Helper;C:\Program Files\BufferZone\BZDCOMLAUNCH.EXE [2007-11-08 11:48]
R2 BZRpcSs;BufferZone RPC Helper;C:\Program Files\BufferZone\BZRPCSS.EXE [2007-11-08 11:48]
R2 SENS_Untrusted_BZ;Notification d'événement système_Untrusted_BZ;C:\Virtual\Untrusted\C_\WINDOWS\system32\svchost.exe [2004-08-05 13:00]
R3 EventSystem_Untrusted_BZ;Système d'événements de COM+_Untrusted_BZ;C:\Virtual\Untrusted\C_\WINDOWS\system32\svchost.exe [2004-08-05 13:00]
S2 winmgmt_Untrusted_BZ;Infrastructure de gestion Windows_Untrusted_BZ;C:\Virtual\Untrusted\C_\WINDOWS\system32\svchost.exe [2004-08-05 13:00]
S3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\Pack Securite\Anti-Virus\minifilter\fsgk.sys [2007-04-26 18:07]
S3 usnjsvc_Untrusted_BZ;Service Messenger Sharing Folders USN Journal Reader_Untrusted_BZ;"C:\Virtual\Untrusted\C_\Program Files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 11:31]
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\Pack Securite\Anti-Virus\Win2K\FSfilter.sys [2007-04-26 18:08]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\Pack Securite\Anti-Virus\Win2K\FSrec.sys [2007-04-26 18:08]
S4 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2007-04-26 18:09]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-18 20:37:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-22 19:02:02 C:\WINDOWS\Tasks\Restauration du système.job"
- C:\WINDOWS\system32\Restore\rstrui.exe
"2008-02-22 19:02:03 C:\WINDOWS\Tasks\Vérifier les mises à jour du kit.job"
- C:\PROGRA~1\Neuf\Kit\9launch.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-22 20:12:06
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Program Files\BufferZone\WINBORDER.DLL
.
Temps d'accomplissement: 2008-02-22 20:12:46
ComboFix-quarantined-files.txt 2008-02-22 19:12:44
ComboFix2.txt 2008-02-22 18:58:48
ComboFix3.txt 2008-02-22 18:52:57
ComboFix4.txt 2008-02-22 18:43:15
.
2008-02-14 13:13:34 --- E O F ---
enfin trouver le rapport mais je crois devenir fou!
cette ordi est une vraie machine a gaz, morzilla et internet explorer en parallele et je ne sais combien d'anti virus , anti spam, anti je ne sais quoi et cela passe toujours! au secours a l'aide