ComboFix 08-11-21.05 - so 2008-11-22 14:40:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.633 [GMT 1:00]
Lancé depuis: c:\documents and settings\so\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\setup.exe
F:\Autorun.inf
F:\resycled
f:\resycled\boot.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-22 au 2008-11-22 ))))))))))))))))))))))))))))))))))))
.
2008-11-22 13:26 . 2008-11-22 13:26 244 --ah----- C:\sqmnoopt19.sqm
2008-11-22 13:26 . 2008-11-22 13:26 232 --ah----- C:\sqmdata19.sqm
2008-11-22 12:43 . 2008-11-22 12:43 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-22 12:43 . 2008-11-22 12:43 <REP> d-------- c:\documents and settings\so\Application Data\Malwarebytes
2008-11-22 12:43 . 2008-11-22 12:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-22 12:43 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-22 12:43 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-21 20:03 . 2008-11-21 20:03 244 --ah----- C:\sqmnoopt18.sqm
2008-11-21 20:03 . 2008-11-21 20:03 232 --ah----- C:\sqmdata18.sqm
2008-11-21 14:52 . 2008-11-21 20:00 <REP> d-------- c:\program files\UsbFix
2008-11-21 14:46 . 2008-11-21 14:46 244 --ah----- C:\sqmnoopt17.sqm
2008-11-21 14:46 . 2008-11-21 14:46 232 --ah----- C:\sqmdata17.sqm
2008-11-21 14:03 . 2008-11-21 14:03 <REP> d-------- C:\rsit
2008-11-21 14:03 . 2008-11-22 12:10 <REP> d-------- c:\program files\trend micro
2008-11-21 13:01 . 2008-11-21 13:01 <REP> d-------- c:\program files\AxBx
2008-11-21 12:27 . 2008-11-21 12:27 244 --ah----- C:\sqmnoopt16.sqm
2008-11-21 12:27 . 2008-11-21 12:27 232 --ah----- C:\sqmdata16.sqm
2008-11-21 11:57 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-11-21 11:57 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-11-21 11:57 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-11-21 11:57 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-11-21 11:57 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-11-21 11:57 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-11-21 11:57 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-11-21 11:57 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
2008-11-21 11:57 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-11-21 11:57 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-11-21 11:16 . 2008-11-21 11:16 27,904 --a------ c:\windows\system32\drivers\ndisprot.sys
2008-11-21 10:00 . 2008-11-21 10:01 <REP> d-------- c:\program files\Decoshow
2008-11-20 22:08 . 2008-11-20 22:08 244 --ah----- C:\sqmnoopt15.sqm
2008-11-20 22:08 . 2008-11-20 22:08 232 --ah----- C:\sqmdata15.sqm
2008-11-19 21:32 . 2008-11-19 21:32 244 --ah----- C:\sqmnoopt14.sqm
2008-11-19 21:32 . 2008-11-19 21:32 232 --ah----- C:\sqmdata14.sqm
2008-11-18 17:50 . 2008-11-18 17:50 151 --a------ c:\windows\PhotoSnapViewer.INI
2008-11-04 20:23 . 2008-11-04 20:23 244 --ah----- C:\sqmnoopt13.sqm
2008-11-04 20:23 . 2008-11-04 20:23 232 --ah----- C:\sqmdata13.sqm
2008-11-04 13:29 . 2008-11-04 13:29 244 --ah----- C:\sqmnoopt12.sqm
2008-11-04 13:29 . 2008-11-04 13:29 232 --ah----- C:\sqmdata12.sqm
2008-11-03 21:28 . 2008-11-03 21:28 244 --ah----- C:\sqmnoopt11.sqm
2008-11-03 21:28 . 2008-11-03 21:28 232 --ah----- C:\sqmdata11.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 13:37 --------- d-----w c:\program files\Wanadoo
2008-11-18 16:56 --------- d-----w c:\program files\EasyBeadPatterns
2008-10-24 16:07 --------- d-----w c:\documents and settings\so\Application Data\Media Player
2008-10-20 07:20 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-19 08:21 --------- d-----w c:\program files\MyDSC2
2008-10-18 21:05 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-18 21:05 --------- d-----w c:\documents and settings\so\Application Data\InstallShield
2008-10-18 17:38 --------- d-----w c:\program files\Inventel
2008-10-18 16:53 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-10-18 16:52 --------- d-----w c:\program files\OLITEC
2008-10-18 16:52 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-10-16 08:58 --------- d-----w c:\documents and settings\so\Application Data\AdobeUM
2008-10-01 08:26 --------- d-----w c:\program files\Fichiers communs\Adobe AIR
2008-10-01 07:05 --------- d-----w c:\program files\NOS
2008-10-01 07:05 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-09-30 08:12 --------- d-----w c:\program files\iTunes
2008-09-30 08:12 --------- d-----w c:\program files\iPod
2008-09-30 08:12 --------- d-----w c:\documents and settings\so\Application Data\Apple Computer
2008-09-30 08:12 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-09-30 08:12 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-30 08:11 --------- d-----w c:\program files\QuickTime
2008-09-30 08:11 --------- d-----w c:\program files\Fichiers communs\Apple
2008-09-30 08:11 --------- d-----w c:\program files\Bonjour
2008-09-30 08:10 --------- d-----w c:\program files\Apple Software Update
2008-09-30 08:09 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-08-29 08:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-03-05 10:16 31,808 ----a-w c:\documents and settings\so\Application Data\GDIPFONTCACHEV1.DAT
2007-10-02 17:32 21,964 ----a-w c:\program files\dancestep.ttf
2007-09-09 21:00 858,554 ----a-w c:\program files\Drop Plus.zip
2007-09-09 20:59 12,120 ----a-w c:\program files\Little Brown Cat.zip
2007-09-09 20:58 2,350,296 ----a-w c:\program files\cursorxp_free.zip
2007-05-09 19:49 4,437,401 ----a-w c:\program files\eMule-NG-0[1].47c-Installer.rar
2007-03-30 20:13 16,277,288 ----a-w c:\program files\Install_Messenger.exe
2007-03-30 19:38 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
"OrangePlayer"="c:\program files\orange\media player\Media Player.exe" [2008-06-05 319488]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WellPhone DirectSync - ScheduleSync"="c:\progra~1\WELLPH~1\SCHEDU~1.EXE" [2005-12-20 45056]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-06 849280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"ISUSPM Startup"="c:\program files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 c:\windows\system32\ptipbmf.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"OrangePlayer"="c:\program files\orange\media player\Media Player.exe" [2008-06-05 319488]
c:\documents and settings\so\Menu D‚marrer\Programmes\D‚marrage\
Gestionnaire Internet.lnk - c:\program files\Wanadoo\GestMAJ.exe [2008-10-19 32768]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Assistant d'Acrobat.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 217193]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-03-28 122880]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel de Synchronisation Orange.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logiciel de Synchronisation Orange.lnk
backup=c:\windows\pss\Logiciel de Synchronisation Orange.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Moniteur WiFi OLITEC.exe.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Moniteur WiFi OLITEC.exe.lnk
backup=c:\windows\pss\Moniteur WiFi OLITEC.exe.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-06-20 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-06-20 20560]
R3 MRVW225;802.11g/b Wireless LAN Dirver for Windows XP;c:\windows\system32\DRIVERS\MRVW225.sys [2008-10-18 299904]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-10-01 33752]
S3 Ndisprot;ArcNet NDIS Protocol Driver;\??\c:\windows\system32\drivers\Ndisprot.sys [2008-11-21 27904]
S3 UsbSagCom;SAGEM Full USB Driver;c:\windows\system32\DRIVERS\UsbSagCom.sys [2007-09-16 51456]
S4 hpt3xx;hpt3xx; []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5d14da40-5189-11dd-b453-0018f6e740c3}]
\Shell\Auto\command - pdtytcnvh.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-22 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 14:54]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-c:\windows\system32\kdzqc.exe - c:\windows\system32\kdzqc.exe
MSConfigStartUp-PlatriumWeather - c:\program files\Platrium\bin\1.2.103.0\Weather.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\so\Application Data\Mozilla\Firefox\Profiles\ydezgxog.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-22 14:43:52
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-22 14:44:44
ComboFix-quarantined-files.txt 2008-11-22 13:44:27
Avant-CF: 92 707 983 360 octets libres
Après-CF: 95,241,998,336 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
196 --- E O F --- 2008-10-09 14:02:16