"C‚sa" - mer. 04/04/2007 17:04:04 Service Pack 4
ComboFix 07-04-04.5 - Running from: "C:\Documents and Settings\Isa\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINNT\system32\nfomon\License.txt
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\vidmon\vidmon.inf
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\keys.dat
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0104.dbd
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0106.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0204.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0315.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0412.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0504.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon0904.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon1204.ddx
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\mon1215.dbd
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo\arch\1001.dfn
C:\Program Files\pedevice\communication.xml
C:\Program Files\pedevice\Domain.Watchlist.txt
C:\Program Files\pedevice\Downloader.exe
C:\Program Files\pedevice\pae-options.xml
C:\Program Files\pedevice\pae_url.xml
C:\Program Files\pedevice\PeDev.exe
C:\Program Files\pedevice\pedevPS.dll
C:\Program Files\pedevice\Preparation.dll
C:\Program Files\pedevice\search.watchlist.txt
C:\Program Files\pedevice\statistic.xml
C:\Program Files\pedevice\watchlist.xml
C:\Program Files\pedevice\tmp\tmp.html
C:\WINNT\system32\unsvchosts.lzma
C:\lswmv.ini
C:\WINNT\system32\vidmon
C:\WINNT\system32\nfomon
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\vidmon
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nfo
C:\Program Files\Common Files\Uninstall Information
C:\Program Files\pedevice
C:\Program Files\Common Files\{D0169~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\Documents and Settings\Isa\My Documents\CROSOF~1.NET
C:\qoobox\purity\Documents and Settings\Isa\My Documents\CROSOF~1.NET\??crosoft.NET
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\nm
-------\LEGACY_COM+_MESSAGES
-------\LEGACY_MCHINJDRV
((((((((((((((((((((((((((((((( Files Created from 2007-03-04 to 2007-04-04 ))))))))))))))))))))))))))))))))))
2007-04-04 09:36 <DIR> d-------- C:\FILES
2007-04-03 11:13 178,408 --a------ C:\WINNT\system32\muweb.dll
2007-04-03 11:13 127,208 --a------ C:\WINNT\system32\mucltui.dll
2007-04-03 10:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
2007-04-03 10:12 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2007-04-03 08:00 <DIR> d--h-c--- C:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2007-04-03 07:59 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-04-03 07:59 <DIR> d-------- C:\f9e807517437e16bc238
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-03 10:12 -------- d-------- C:\Program Files\msn apps
2007-01-28 00:31 112798 --a------ C:\WINNT\hpoins07.dat
2007-01-18 12:19 6 --a------ C:\DOCUME~1\Isa\APPLIC~1\dm.ini
2007-01-18 12:19 1824 --a------ C:\DOCUME~1\Isa\APPLIC~1\adobedlm.log
2007-01-16 23:02 16384 --a----t- C:\WINNT\system32\perflib_perfdata_210.dat
2007-01-16 16:08 16384 --a----t- C:\WINNT\system32\perflib_perfdata_224.dat
2007-01-16 12:52 16384 --a----t- C:\WINNT\system32\perflib_perfdata_220.dat
2007-01-15 18:32 689280 --a------ C:\WINNT\system32\aswboot.exe
2007-01-15 18:23 90112 --a------ C:\WINNT\system32\avastss.scr
2007-01-14 13:55 16384 --a----t- C:\WINNT\system32\perflib_perfdata_21c.dat
2007-01-10 11:09 212992 --a------ C:\WINNT\system32\odbc32.dll
2007-01-05 08:49 22752 --a------ C:\WINNT\system32\spupdsvc.exe
2007-01-04 15:18 16384 --a----t- C:\WINNT\system32\perflib_perfdata_214.dat
2007-01-04 10:57 16384 --a----t- C:\WINNT\system32\perflib_perfdata_218.dat
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"internat.exe"="internat.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"="mobsync.exe /logon"
"AcroRead 5 SetLanguage"="wscript.exe \"c:\\program files\\adobe\\acrobat 5.0\\Reader\\Acrobat.vbs\""
"%FP%Friendly fts.exe"="\"C:\\Program Files\\Friendly Technologies\\BroadbandAccess\\fts.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Antivirus\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"UnlockerAssistant"="\"C:\\Program Files\\Antivirus\\Unlocker\\UnlockerAssistant.exe\""
"avast!"="C:\\PROGRA~1\\ANTIVI~1\\Avast\\ashDisp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"="C:\\Program Files\\Internet Explorer\\Connection Wizard\\icwconn1.exe /desktop"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
"Intec Services Driverrs"="winrvc.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"="internat.exe"
"Intec Services Driverrs"="winrvc.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
rpcss REG_MULTI_SZ RpcSs\0\0
wugroup REG_MULTI_SZ wuauserv\0\0
BITSgroup REG_MULTI_SZ BITS\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
CMD.EXE [2708]
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0
********************************************************************
Completion time: Wed 2007-04-04 17:13:23
C:\ComboFix-quarantined-files.txt ... 07-04-04 17:13
C:\ComboFix2.txt ... 06-12-30 15:51