ComboFix 09-01-05.05 - gege 2009-01-06 17:53:35.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.447.198 [GMT 1:00]
Lancé depuis: c:\documents and settings\gege\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\mpg4c32.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 17:50 . 2009-01-06 17:51 <REP> d-------- C:\32788R22FWJFW
2009-01-06 16:23 . 2009-01-06 16:23 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-01-06 16:23 . 2009-01-06 16:23 <REP> d-------- c:\windows\LastGood
2009-01-06 15:05 . 2009-01-06 15:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-06 15:05 . 2009-01-06 15:05 <REP> d-------- c:\documents and settings\gege\Application Data\Malwarebytes
2009-01-06 15:05 . 2009-01-06 15:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-06 15:05 . 2009-01-04 18:39 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-06 15:05 . 2009-01-04 18:39 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-06 14:39 . 2009-01-06 14:39 <REP> d-------- c:\program files\CCleaner
2009-01-06 14:31 . 2009-01-06 17:43 <REP> d-------- c:\program files\Ad-remover
2009-01-06 13:58 . 2009-01-06 14:06 <REP> d-------- c:\program files\UsbFix
2009-01-04 13:54 . 2009-01-04 13:55 <REP> d-------- C:\rsit
2009-01-04 13:54 . 2009-01-05 18:29 <REP> d-------- c:\program files\trend micro
2008-12-30 10:56 . 2008-12-30 10:56 <REP> d-------- c:\program files\Auslogics
2008-12-30 10:56 . 2008-12-30 10:56 <REP> d-------- c:\documents and settings\gege\Application Data\Auslogics
2008-12-28 18:02 . 2008-12-29 17:56 <REP> d-------- c:\program files\Dofus
2008-12-26 19:56 . 2008-12-26 19:56 <REP> d-------- c:\program files\AVIConverter
2008-12-26 19:03 . 2007-09-27 15:22 261,632 --a------ c:\windows\system32\mcdvd_32.dll
2008-12-26 19:03 . 2003-05-22 13:26 221,215 --a------ c:\windows\system32\divxdec.ax
2008-12-26 19:03 . 2003-05-22 00:50 156,910 --a------ c:\windows\WMSysPr8.prx
2008-12-26 19:03 . 2003-05-22 00:50 82,944 --a------ c:\windows\system32\vct3216.acm
2008-12-26 19:03 . 2004-09-06 17:06 53,248 --a------ c:\windows\system32\xvid.ax
2008-12-26 19:03 . 2003-05-22 00:50 38,912 --a------ c:\windows\system32\alf2cd.acm
2008-12-26 19:03 . 2000-03-14 21:55 13,239 --a------ c:\windows\system32\Scg726.acm
2008-12-26 16:37 . 2008-12-26 16:37 <REP> d-------- c:\documents and settings\gege\Application Data\AVS4YOU
2008-12-26 16:37 . 2008-12-26 16:37 <REP> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU
2008-12-26 16:36 . 2008-12-26 19:04 <REP> d-------- c:\program files\Fichiers communs\AVSMedia
2008-12-26 16:36 . 2008-12-26 19:18 <REP> d-------- c:\program files\AVS4YOU
2008-12-26 16:36 . 2007-02-27 18:36 1,700,352 --a------ c:\windows\system32\GdiPlus.dll
2008-12-26 16:36 . 2007-02-27 18:36 974,848 --a------ c:\windows\system32\mfc70.dll
2008-12-26 16:36 . 2007-02-27 18:36 487,424 --a------ c:\windows\system32\msvcp70.dll
2008-12-26 16:36 . 2007-02-27 18:36 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-12-20 18:45 . 2008-12-20 18:53 <REP> d-------- c:\program files\Pochette Express 2
2008-12-11 15:23 . 2008-10-03 11:03 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2008-12-08 19:05 . 2008-12-08 19:05 <REP> d-------- c:\program files\Audacity
2008-12-08 19:04 . 2008-12-08 19:04 <REP> d-------- c:\program files\EoRezo
2008-12-08 19:04 . 2009-01-06 15:57 <REP> d-------- c:\documents and settings\gege\Application Data\EoRezo
2008-12-06 10:54 . 2008-12-06 10:54 <REP> d-------- c:\program files\Fichiers communs\Adobe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-02 18:55 --------- d-----w c:\program files\eMule
2008-12-26 15:17 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-26 15:14 --------- d-----w c:\program files\Google
2008-12-21 10:50 --------- d-----w c:\program files\EPSON Print CD
2008-12-02 16:36 --------- d-----w c:\documents and settings\gege\Application Data\Ahead
2008-11-25 17:10 --------- d-----w c:\documents and settings\gege\Application Data\Creative
2008-11-20 08:08 --------- d-----w c:\program files\Picasa2
2008-11-17 19:28 --------- d-----w c:\documents and settings\All Users\Application Data\Creative
2008-11-17 18:39 --------- d-----w c:\documents and settings\gege\Application Data\EPSON
2008-11-17 18:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-17 18:24 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-11-17 18:22 --------- d-----w c:\program files\epson
2008-11-17 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\UDL
2008-11-11 19:03 44,984 -c--a-w c:\documents and settings\gege\Application Data\GDIPFONTCACHEV1.DAT
2008-11-01 09:27 558,142 -c--a-w c:\windows\java\Packages\7L7PFVVP.ZIP
2008-11-01 09:27 155,995 -c--a-w c:\windows\java\Packages\EV9JVVVN.ZIP
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX560 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIBPE.EXE" [2006-05-23 139264]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"V0420Mon.exe"="c:\windows\V0420Mon.exe" [2007-04-30 32768]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"c:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Microsoft Games\\Motocross Madness\\mcm.exe"=
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2008-11-01 21656]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-01 111184]
R3 V0420VID;Live! Cam Vista IM (VF0420);c:\windows\system32\drivers\V0420Vid.sys [2008-11-02 99648]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-27 20560]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-10-28 195752]
.
.
------- Examen supplémentaire -------
.
uDefault_Search_URL =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext =
hxxp://google.fr/
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {9C4AFC47-FF1E-49F2-BEFB-E1D5A106118C} = 192.168.1.1
O16 -: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
hxxp://ma-config.com/activex/hardwaredetection_3_0_3_4.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-06 17:54:34
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-06 17:55:57
ComboFix-quarantined-files.txt 2009-01-06 16:55:43
Avant-CF: 105 596 018 688 octets libres
Après-CF: 105,596,334,080 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
147 --- E O F --- 2008-12-18 10:26:05