ComboFix 09-10-04.01 - administrateur 04/10/2009 21:31.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.32.1033.18.479.222 [GMT 2:00]
Lancé depuis: c:\documents and settings\administrateur\Desktop\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide4.dll
c:\documents and settings\administrateur\Local Settings\Temp\IadHide4.dll
c:\windows\4ff345dfbh521
c:\windows\Installer\1b30570.msi
c:\windows\Installer\1b30571.msp
c:\windows\Installer\1b30572.msp
c:\windows\Installer\1b30573.msp
c:\windows\Installer\1b30574.msp
c:\windows\Installer\1b30575.msp
c:\windows\Installer\1b30576.msp
c:\windows\Installer\1b30577.msp
c:\windows\Installer\1b30578.msp
c:\windows\Installer\1b30579.msp
c:\windows\Installer\423d66.msp
c:\windows\Installer\423d67.msp
c:\windows\Installer\423d68.msp
c:\windows\Installer\423d69.msp
c:\windows\Installer\423d6a.msp
c:\windows\Installer\423d6b.msp
c:\windows\Installer\423d6c.msp
c:\windows\Installer\423d6d.msp
c:\windows\Installer\423d6e.msp
c:\windows\Installer\423d6f.msp
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Legacy_BROWSERCTL
-------\Legacy_BROWSERCTLDRV
-------\Service_Boonty Games
-------\Service_SfX
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-04 au 2009-10-04 ))))))))))))))))))))))))))))))))))))
.
2009-10-04 18:57 . 2009-10-04 19:14 -------- d-----w- C:\FindyKill
2009-10-04 18:30 . 2009-09-15 10:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-10-04 18:30 . 2009-09-15 10:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-10-04 18:29 . 2009-09-15 10:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-10-04 18:29 . 2009-10-04 18:29 -------- d-----w- c:\program files\Alwil Software
2009-10-04 18:07 . 2009-10-04 18:09 -------- d-----w- c:\temp\_ISTMP1.DIR
2009-10-04 15:55 . 2009-10-04 17:20 -------- d-----w- c:\program files\Dekovir.com
2009-10-04 15:39 . 2009-10-04 15:39 -------- d-----w- c:\program files\NFO viewer
2009-10-03 19:40 . 2009-10-03 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\BOONTY
2009-10-03 19:39 . 2009-10-03 19:39 -------- d-----w- c:\program files\Common Files\BOONTY Shared
2009-10-03 17:46 . 2009-10-03 22:08 -------- d-----w- c:\program files\Alpha Ball
2009-10-03 17:46 . 2009-10-03 17:46 -------- d-----w- c:\program files\ReflexiveArcade
2009-10-01 20:29 . 2009-10-01 20:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-10-01 20:18 . 2009-10-01 20:18 -------- d-----w- c:\documents and settings\administrateur\Application Data\Office Genuine Advantage
2009-09-12 18:20 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 19:17 . 2008-12-06 12:34 39400 ----a-w- c:\documents and settings\administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-04 18:26 . 2008-12-13 11:24 -------- d-----w- c:\program files\F-Secure
2009-10-04 15:57 . 2008-12-07 01:43 -------- d-----w- c:\program files\eMule
2009-10-04 15:41 . 2009-03-01 15:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-13 21:53 . 2009-08-18 20:17 -------- d-----w- c:\documents and settings\administrateur\Application Data\Skype
2009-09-12 20:56 . 2009-06-22 20:20 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-18 20:19 . 2009-08-18 20:19 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-08-18 20:19 . 2009-08-18 20:19 -------- d-----w- c:\documents and settings\administrateur\Application Data\skypePM
2009-08-18 20:17 . 2009-08-18 20:16 -------- d-----r- c:\program files\Skype
2009-08-18 20:16 . 2009-08-18 20:16 -------- d-----w- c:\program files\Common Files\Skype
2009-08-18 20:16 . 2009-08-18 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-13 17:38 . 2009-08-12 20:13 1945 ----a-w- c:\windows\th1234.dat
2009-08-12 20:35 . 2009-08-12 20:35 -------- d-----w- c:\documents and settings\administrateur\Application Data\Malwarebytes
2009-08-12 20:35 . 2009-08-12 20:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-12 20:35 . 2009-08-12 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-12 20:13 . 2009-08-12 20:13 1 ----a-w- c:\windows\ectbbyn.dat
2009-08-06 20:12 . 2008-12-07 02:43 -------- d-----w- c:\program files\Java
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 13:07 . 2009-08-03 13:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 13:07 . 2009-08-03 13:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 13:07 . 2009-08-03 13:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-08-03 11:36 . 2009-08-12 20:35 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 11:36 . 2009-08-12 20:35 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-25 03:23 . 2008-12-07 02:43 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 15:16 . 2009-07-12 15:16 81920 ------r- c:\windows\bwUnin-6.1.4.68-8876480L.exe
2009-03-19 20:42 . 2009-03-19 20:42 31015 ----a-w- c:\program files\jo.rar
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2009-07-12 20480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2009-10-04 106571]
"ResModify"="c:\program files\USBToolbox\ResModify.EXE" [2003-12-24 65536]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-04 77824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-05-21 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-06-01 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-06-01 217088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-10-04 81000]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-27 110592]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-7-12 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\fredastra\\condition zero\\hl.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"53:TCP"= 53:TCP:websrvx
R2 FSpm;F-Secure Policy Manager;c:\program files\F-Secure\Common\FSpm.sys [13/12/2008 13:24 65328]
R2 Fswsclds;F-Secure Windows Security Center Legacy Detection Service;c:\program files\F-Secure\fswsclds.exe [13/12/2008 22:35 40960]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys --> c:\windows\system32\DRIVERS\aswFsBlk.sys [?]
S2 F-Secure Filter;F-Secure File System Filter;\??\c:\program files\F-Secure\Common\FSfilter.sys --> c:\program files\F-Secure\Common\FSfilter.sys [?]
S2 F-Secure Gatekeeper;F-Secure Gatekeeper;\??\c:\program files\F-Secure\Common\fsgk.sys --> c:\program files\F-Secure\Common\fsgk.sys [?]
S2 F-Secure Recognizer;F-Secure File System Recognizer;\??\c:\program files\F-Secure\Common\FSrec.sys --> c:\program files\F-Secure\Common\FSrec.sys [?]
S2 gupdate1c99a802c360940;Service Google Update (gupdate1c99a802c360940);c:\program files\Google\Update\GoogleUpdate.exe [1/03/2009 17:12 133104]
S4 BackWeb Client - 7681197;F-Secure BackWeb;c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE --> c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-10-04 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-01 15:20]
2009-10-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 15:12]
2009-10-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 15:12]
2009-10-04 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 13:07]
2009-10-04 c:\windows\Tasks\User_Feed_Synchronization-{FBA41A23-D08E-4EB3-A794-E1B2216EFBF5}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.be/
uInternet Settings,ProxyOverride = localhost
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {C94FA56C-3836-4110-AE41-67789723B6AF} = 192.168.1.254
DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} -
hxxp://www.tele2.be/mailconfig/config/bin/AccountHelper.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKCU-Run-LogitechSoftwareUpdate - c:\program files\Logitech\Video\ManifestEngine.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-04 21:36
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3876)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\Video\FxSvr2.exe
.
**************************************************************************
.
Heure de fin: 2009-10-04 21:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-04 19:39
Avant-CF: 11.697.827.840 bytes free
Après-CF: 12.160.475.136 bytes free
197 --- E O F --- 2009-09-22 19:51