Le second
ComboFix 09-01-05.05 - Utilisateur 2009-01-06 12:52:56.9 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2047.1417 [GMT 1:00]
Lancé depuis: c:\documents and settings\Utilisateur\Bureau\killbagleexe.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 12:44 . 2009-01-06 12:47 <REP> d-------- c:\program files\UsbFix
2009-01-06 11:51 . 2009-01-06 11:53 <REP> d-------- c:\program files\SafeSoft
2009-01-05 13:39 . 2009-01-05 13:39 0 --a------ c:\windows\licview.INI
2009-01-05 13:28 . 2009-01-05 13:29 214,528 --a------ C:\[u]0/u9010500.lgh
2009-01-05 13:28 . 2009-01-05 13:29 30,720 --a------ C:\[u]0/u9010500.idx
2009-01-05 11:03 . 2009-01-05 11:38 <REP> d-------- c:\program files\a-squared Anti-Malware
2009-01-05 09:29 . 2009-01-05 09:30 <REP> d-------- c:\program files\TTERMPRO
2009-01-05 09:28 . 2009-01-05 09:29 43 --a------ c:\windows\iltwain.ini
2008-12-31 08:06 . 2008-12-31 08:06 <REP> d-------- c:\documents and settings\Utilisateur\Application Data\ArchestrA
2008-12-31 07:48 . 2008-12-31 07:48 0 --a------ c:\windows\aaLicView.INI
2008-12-31 07:38 . 2008-12-31 07:38 <REP> d-------- c:\program files\Wonderware
2008-12-31 07:38 . 2008-12-31 07:38 <REP> d-------- c:\program files\Rainbow Technologies
2008-12-31 07:38 . 2009-01-05 13:21 <REP> d-------- c:\program files\Fichiers communs\ArchestrA
2008-12-31 07:38 . 2008-12-31 07:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Wonderware
2008-12-31 07:38 . 2008-12-31 07:39 <REP> d-------- c:\documents and settings\All Users\Application Data\ArchestrA
2008-12-22 09:34 . 2008-12-22 09:34 <REP> d-------- c:\program files\Google
2008-12-17 13:06 . 2008-12-17 13:06 <REP> d-------- c:\program files\Microsoft
2008-12-17 13:05 . 2008-12-17 13:05 <REP> d-------- c:\program files\Windows Live SkyDrive
2008-12-11 07:27 . 2008-12-11 07:27 <REP> d-------- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-08 08:57 . 2008-12-15 08:17 593 --a------ c:\windows\imsins.BAK
2008-12-08 08:47 . 2008-10-16 14:08 27,672 --a------ c:\windows\system32\wuapi.dll.mui
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 07:17 --------- d-----w c:\program files\Advanced IP Scanner
2009-01-06 05:32 --------- d-----w c:\program files\LogMeIn
2008-12-31 10:53 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 10:33 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-30 10:57 --------- d-----w c:\program files\Siemens
2008-12-29 13:02 --------- d-----w c:\program files\CS6
2008-12-17 12:11 --------- d-----w c:\program files\Messenger Plus! Live
2008-12-17 12:05 --------- d-----w c:\program files\Windows Live
2008-12-08 13:42 --------- d-----w c:\documents and settings\Utilisateur\Application Data\U3
2008-12-05 12:41 --------- d-----w c:\program files\Java
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-02 21:37 49,480 ----a-w c:\windows\system32\sirenacm.dll
2008-11-25 08:03 --------- d-----w c:\documents and settings\Utilisateur\Application Data\TomTom
2008-11-25 08:03 --------- d-----w c:\documents and settings\All Users\Application Data\TomTom
2008-11-25 07:57 --------- d-----w c:\program files\TomTom DesktopSuite
2008-11-17 06:30 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-14 13:35 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-14 10:29 --------- d-----w c:\program files\Trend Micro
2008-11-14 07:44 --------- d-----w c:\documents and settings\Utilisateur\Application Data\Tyre
2008-11-13 15:18 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-13 08:49 --------- d-----w c:\program files\Fichiers communs\SWF Studio
2008-11-13 07:21 --------- d-----w c:\program files\PS-Wizard
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-11-07 13:08 --------- d-----w c:\program files\Avira
2008-11-07 13:08 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-11-06 07:06 --------- d-----w c:\program files\PDF Editeur 2
2008-11-06 07:06 --------- d-----w c:\program files\Fichiers communs\XPressUpdate
2008-10-18 05:34 87,352 ----a-w c:\windows\system32\LMIinit.dll
2008-10-18 05:34 83,288 ----a-w c:\windows\system32\LMIRfsClientNP.dll
2008-10-18 05:34 28,984 ----a-w c:\windows\system32\LMIport.dll
2008-10-18 05:34 23,736 ----a-w c:\windows\system32\lmimirr.dll
2008-10-18 05:34 10,040 ----a-w c:\windows\system32\lmimirr2.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:07 208,744 ----a-w c:\windows\system32\muweb.dll
2008-04-10 12:54 88 --sh--r c:\documents and settings\All Users\Application Data\3B54EF5A91.sys
2008-04-10 12:54 2,516 --sha-w c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
1998-04-27 18:15 570,128 ------w c:\program files\Fichiers communs\dao350.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-06-11 163840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-07 827392]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 872448]
"WinVNC"="c:\program files\UltraVNC\WinVNC.exe" [2006-06-18 712704]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-09-12 63048]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"S7UB Start"="c:\program files\common files\Siemens\S7ubtoox\s7ubtstx.exe" [2008-07-14 102453]
"WinCC flexible Smart Start"="c:\program files\Siemens\SIMATIC WinCC flexible\WinCC flexible 2008\HmiSmartStart.exe" [2008-08-02 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Client Access Service"="c:\program files\IBM\Client Access\cwbsvstr.exe" [2005-06-09 20530]
"Client Access Help Update"="c:\program files\IBM\Client Access\cwbinhlp.exe" [2005-06-09 24626]
"Client Access Check Version"="c:\program files\IBM\Client Access\cwbckver.exe" [2005-06-09 45106]
"Client Access Express Welcome"="c:\program files\IBM\Client Access\cwbwlwiz.exe" [2005-06-09 20480]
"Client Access PC5250 Sound"="c:\program files\IBM\Client Access\Emulator\pcssnd.exe" [2005-06-09 40960]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
SyncBack.lnk - c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-07-08 2936064]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-06 561213]
start.bat [2008-11-06 226]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-18 06:34 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/u
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\Program Files\\Siemens\\Step7\\S7BIN\\S7tgtopx.exe"=
"c:\\Program Files\\Siemens\\Step7\\S7INF\\S7usiapx.exe"=
"c:\\WINDOWS\\system32\\s7otbxsx.exe"=
"c:\\Program Files\\common files\\Siemens\\ace\\bin\\CCAgent.exe"=
"c:\\Program Files\\common files\\Siemens\\ace\\bin\\CCEServer.exe"=
"c:\\Program Files\\common files\\Siemens\\ace\\bin\\RedundancyControl.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2008\\HmiES.exe"=
"c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2008\\TraceServer.exe"=
"c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2008 Runtime\\Miniweb.exe"=
"c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2008 Runtime\\SmartServer.exe"=
"c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2008 Runtime\\HmiLoad.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\ArchestrA\\aaLogger.exe"=
"c:\\Program Files\\Fichiers communs\\ArchestrA\\slssvc.exe"=
"c:\\Program Files\\Wonderware\\InTouch\\wm.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\OpcEnum.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"102:TCP"= 102:TCP:DAS SI 102
"135:TCP"= 135:TCP:DCOM 135
"502:TCP"= 502:TCP:Modicon 502
"1434:UDP"= 1434:UDP:SQL Server Browser 1434
"1433:TCP"= 1433:TCP:SQL TCP 1433
"2221:TCP"= 2221:TCP:DAS ABTCP 2221
"2222:TCP"= 2222:TCP:DAS ABTCP 2222
"2223:TCP"= 2223:TCP:DAS ABTCP 2223
"5413:TCP"= 5413:TCP:Port 5413
"80:TCP"= 80:TCP:SuiteVoyager 80
"443:TCP"= 443:TCP:SuiteVoyager 443
"9001:TCP"= 9001:TCP:vista 9001
"9002:TCP"= 9002:TCP:EnvMngr 9002
"9003:TCP"= 9003:TCP:MsgMngr 9003
"9004:TCP"= 9004:TCP:SecMngr 9004
"9006:TCP"= 9006:TCP:RedMngr 9006
"9007:TCP"= 9007:TCP:UnilinkMngr 9007
"9008:TCP"= 9008:TCP:BatchMngr 9008
"9011:TCP"= 9011:TCP:LogMngr 9011
"9012:TCP"= 9012:TCP:InfoMngr 9012
"9013:UDP"= 9013:UDP:RedMngrX 9013
"9014:UDP"= 9014:UDP:RedMngrX2 9014
"9015:TCP"= 9015:TCP:HistQMngrvista 9015
"9016:TCP"= 9016:TCP:HistQReader 9016
"44818:TCP"= 44818:TCP:Logix 44818
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\RemoteAdminSettings]
"Enabled"= 0 (0x0)
R3 fwkbdrtm;fwkbdrtm;c:\windows\system32\drivers\fwkbdrtm.sys [2008-08-01 5632]
R4 almservice;Automation License Manager Service;c:\program files\common files\Siemens\SWS\almsrv\almsrvx.exe [2008-05-20 1146880]
R4 CCAgent;CCAgent;c:\program files\common files\Siemens\ace\bin\CCAgent.exe [2007-06-28 266307]
R4 CCEServer;CCEServer;c:\program files\common files\Siemens\ace\bin\CCEServer.exe [2007-06-28 192581]
R4 Dpmtrcdd;Dpmtrcdd;c:\windows\system32\drivers\dpmtrcdd.sys [2007-06-25 28363]
R4 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2007-09-12 12856]
R4 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-11-19 47640]
R4 MSSQL$WINCCFLEXEXPRESS;SQL Server (WINCCFLEXEXPRESS);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 29183504]
R4 Peakcan;Peakcan;c:\windows\system32\drivers\PEAKCAN.SYS [2007-12-03 177296]
R4 RedundancyControl;RedundancyControl;c:\program files\common files\Siemens\ace\bin\RedundancyControl.exe [2007-06-28 331853]
R4 RedundancyState;RedundancyState;c:\program files\common files\Siemens\ace\bin\RedundancyState.exe [2007-06-28 110667]
R4 s7asysvx;S7 Global Services;c:\program files\Siemens\Step7\S7BIN\s7asysvx.exe [2008-07-14 69685]
R4 s7odpx2x;SIMATIC MPI/PROFIBUS DPX2 Driver;c:\windows\system32\drivers\s7odpx2x.sys [2008-07-03 77312]
R4 s7oiehsx;SIMATIC IEPG Help Service;c:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe [2008-07-03 1571912]
R4 S7opcsrtx;PROFINET IO RT-Protocol (LLDP);c:\windows\system32\drivers\s7opcsrtx.sys [2008-07-03 31232]
R4 s7osmcax;s7osmcax;c:\windows\system32\drivers\s7osmcax.sys [2008-07-03 173568]
R4 s7snsrtx;PROFINET IO RT-Protocol;c:\windows\system32\drivers\s7snsrtx.sys [2007-07-30 71168]
R4 S7TraceServiceX;S7TraceServiceX;c:\program files\Fichiers communs\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [2008-07-03 240712]
R4 SCSMonitor;SCSMonitor;c:\program files\common files\Siemens\ace\bin\SCSMX.exe [2007-06-28 122945]
S3 CCEClient;CCEClient;c:\program files\common files\Siemens\ace\bin\CCEClient.exe [2007-06-28 225349]
S3 dpmcslv;dpmcslv;c:\windows\system32\drivers\dpmcslv.sys [2005-07-04 68280]
S3 S5S7DRV;S5S7DRV;c:\s5w\s5s7drv.sys [2008-04-24 51640]
S3 s7oefs_x;SIMATIC MPI/EFS Driver;c:\windows\system32\drivers\s7oefs_x.sys [2002-10-18 30512]
S3 s7oppinx;s7oppinx;c:\windows\system32\drivers\s7oppinx.sys [2008-07-03 124928]
S3 S7OUPC2X;SIMATIC PC Adapter USB Driver;c:\windows\system32\drivers\s7oupc2x.sys [2007-11-19 21536]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
S4 SsfdcPp;Parallel Port Ssfdc Programmer Driver;c:\windows\system32\drivers\SsfdcPp.sys [2007-12-12 12583]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contenu du dossier 'Tâches planifiées'
2009-01-06 c:\windows\Tasks\SyncBack Pc Vers H.job
- c:\program files\2BrightSparks\SyncBack\SyncBack.exe [2008-02-12 10:19]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyServer = 192.168.1.2:8080
uInternet Settings,ProxyOverride = <local>
Trusted Zone: chat.tchatche.com
Trusted Zone: fr.mg40.mail.yahoo.com
c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe
c:\windows\Downloaded Program Files\live.ini
c:\windows\Downloaded Program Files\scanoptions.tsi
c:\windows\Downloaded Program Files\lang.ini
c:\windows\Downloaded Program Files\ipsupd.dll
c:\windows\Downloaded Program Files\bdupd.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\oscan8.ocx
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
c:\windows\Downloaded Program Files\oscan8.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 12:54:58
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*NULL*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Heure de fin: 2009-01-06 12:56:12
ComboFix-quarantined-files.txt 2009-01-06 11:56:10
Avant-CF: 5 990 608 896 octets libres
Après-CF: 6,035,177,472 octets libres
264 --- E O F --- 2008-12-08 11:00:12