ComboFix 09-03-18.01 - Florian 2009-03-19 10:48:21.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.159 [GMT 1:00]
Lancé depuis: c:\documents and settings\Florian\Mes documents\Document Flo\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090318-0] *On-access scanning disabled* (Updated)
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\SystemDoctor Free
c:\documents and settings\All Users\Application Data\SystemDoctor Free\Data\Abbr
c:\documents and settings\All Users\Application Data\SystemDoctor Free\Data\ActivationCode
c:\documents and settings\All Users\Application Data\SystemDoctor Free\Data\HOURS
c:\documents and settings\All Users\Application Data\SystemDoctor Free\Data\ProductCode
c:\documents and settings\Florian\err.log
c:\documents and settings\Florian\ResErrors.log
c:\documents and settings\joss-fred\Application Data\SystemDoctor Free
c:\documents and settings\joss-fred\Application Data\SystemDoctor Free\Logs\update.log
c:\documents and settings\joss-fred\err.log
c:\documents and settings\joss-fred\Local Settings\Application Data\aikwk.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\aikwk_nav.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\aikwk_navps.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\ciiie_navfx.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\diees.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\diees_nav.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\diees_navps.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\oauqics_navfx.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\qikiawc.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\qikiawc_nav.dat
c:\documents and settings\joss-fred\Local Settings\Application Data\qikiawc_navps.dat
c:\documents and settings\joss-fred\ResErrors.log
c:\program files\Fichiers communs\SystemDoctor
c:\program files\Fichiers communs\SystemDoctor\err.log
c:\windows\Bhonoxevu.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\303369.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\ahtn.htm
c:\windows\system32\dumphive.exe
c:\windows\system32\frmwrk32.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\init32.exe
c:\windows\system32\ntdll64.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\ovfsthbwimainljjbleuxakdrxwhyutkixexwk.dll
c:\windows\system32\ovfstheymfbdibmlwmkloodqpuxxyvjoowweqv.dll
c:\windows\system32\ovfsthftutctrnvmswhyxrdmuytbcvcfxetoof.dll
c:\windows\system32\ovfsthlharbwsnmdmeblwipgopicgbqiovydrw.dll
c:\windows\system32\ovfsthoqmgieifybgphagbguwxnkylttxvsbse.dll
c:\windows\system32\ovfsthuckkyfydsxlvedvvgvmncrmttiltvenb.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\uniq.tll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\WS2Fix.exe
----- BITS: Il y a peut-être des sites infectés -----
hxxp://sunmicro.ht.rd.llnw.net
[color=blue]Une copie infectée de c:\windows\system32\userinit.exe a été trouvée et désinfectée
opie restaurée à partir de - c:\qoobox\Quarantine\C\WINDOWS\system32\userinit.exe.vir/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ovfsthrrpdqvdnostypasikltfqppjwswwkmos
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-19 au 2009-03-19 ))))))))))))))))))))))))))))))))))))
.
2009-03-19 10:39 . 2009-03-19 10:40 <REP> d----c--- C:\32788R22FWJFW
2009-03-19 10:08 . 2009-03-19 10:23 <REP> d----c--- C:\ToolBar SD
2009-03-19 09:58 . 2009-03-19 09:58 <REP> d----c--- C:\rsit
2009-03-19 09:04 . 2009-03-19 10:34 112,640 --a--c--- C:\gtb.exe
2009-03-19 08:22 . 2009-03-19 08:55 43 --a------ c:\windows\system32\ovfsthxeaufkqpypikkiqjdvwpqyrtfwffkqsd.dat
2009-03-19 08:16 . 2009-03-19 08:16 71,680 --a------ c:\windows\system32\drivers\xtfdtipymstporen.sys
2009-03-19 08:16 . 2009-03-19 10:22 3,353 --a------ c:\windows\system32\ovfsthalvsptvbmycbpjbchpfohajikgskueav.dat
2009-03-18 19:55 . 2009-03-18 20:35 <REP> d-------- c:\program files\FindyKill
2009-03-18 19:49 . 2009-03-18 19:49 <REP> d-------- c:\program files\Trend Micro
2009-03-18 19:41 . 2009-03-18 19:41 <REP> d-------- c:\documents and settings\Florian\Application Data\Talkback
2009-03-18 15:57 . 2009-03-18 15:57 40,448 --a------ c:\windows\system32\KuzSmall.exe
2009-03-18 15:41 . 2009-03-18 15:41 <REP> d-------- c:\windows\system32\config\systemprofile\Application Data\Talkback
2009-03-18 15:34 . 2009-03-18 16:00 43 --a------ c:\windows\system32\ovfsthsfvpyurbqbwulqeetagwrrvicykvdnos.dat
2009-03-18 15:31 . 2009-03-18 15:57 1,516 --a--c--- C:\br.exe
2009-03-18 15:27 . 2009-03-18 16:00 5,865 --a------ c:\windows\system32\ovfsthlqcwyexyjaotmdcxxdnteppjxcbsitcp.dat
2009-03-18 13:53 . 2009-03-17 20:13 48,690 -r-hs---- c:\windows\fxsteller.exe
2009-03-05 18:48 . 2009-03-05 18:48 <REP> d-------- c:\program files\Safari
2009-03-05 18:44 . 2009-03-05 18:44 <REP> d-------- c:\program files\iPod
2009-03-05 18:43 . 2009-03-05 18:44 <REP> d-------- c:\program files\iTunes
2009-03-05 18:43 . 2009-03-05 18:44 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-21 15:53 . 2002-01-05 14:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2009-02-21 15:52 . 2009-02-21 15:53 <REP> d-------- c:\program files\Fichiers communs\DVDVideoSoft
2009-02-21 15:52 . 2009-02-21 15:52 <REP> d-------- c:\program files\DVDVideoSoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 10:01 --------- d-----w c:\program files\Steam
2009-03-18 16:56 --------- d-----w c:\program files\Circle Developement
2009-03-18 16:39 --------- d-----w c:\documents and settings\joss-fred\Application Data\REAL SIZE DELETE
2009-03-18 16:24 --------- d-----w c:\documents and settings\Florian\Application Data\REAL SIZE DELETE
2009-03-18 14:53 --------- d-----w c:\documents and settings\All Users\Application Data\Proxy Long Chin Ping
2009-03-18 13:32 140,216 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-03-14 10:10 --------- d-----w c:\documents and settings\Fiona\Application Data\Apple Computer
2009-03-13 19:09 --------- d-----w c:\program files\Microsoft Games
2009-03-11 21:18 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-05 17:44 --------- d-----w c:\program files\Fichiers communs\Apple
2009-02-27 12:53 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-18 10:13 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-14 19:33 --------- d-----w c:\program files\QuickTime
2009-02-14 19:25 --------- d-----w c:\program files\Bonjour
2009-01-15 21:07 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2009-01-15 21:07 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-15 21:07 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2009-01-15 21:07 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2009-01-15 21:07 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-09-27 18:37 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008092720080928\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Steam"="c:\program files\Steam\Steam.exe" [2008-10-08 1410296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"VX3000"="c:\windows\vVX3000.exe" [2006-06-30 707376]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"OPTENET_GUI"="c:\program files\Telecom Italia France\Securite Enfants\bin\OPTGui.exe" [2007-10-17 397352]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SoundMan"="SOUNDMAN.EXE" [2005-06-14 c:\windows\SOUNDMAN.EXE]
"C-Media Mixer"="Mixer.exe" [2003-04-06 c:\windows\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\Fiona\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Florian\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-06-19 152616]
c:\documents and settings\Florian\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\Florian\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-06-19 152616]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 16423]
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 176128]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-02 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-02 20560]
R2 OPTENET_FILTER;Sécurité Enfants;c:\program files\Telecom Italia France\Securite Enfants\bin\optproxy.exe [2007-10-17 608744]
S3 SE2Fbus;Sony Ericsson Device 047 Driver driver (WDM);c:\windows\system32\drivers\SE2Fbus.sys [2008-02-09 61600]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0d8f050a-77f8-11dc-9d88-0013d4f70cd6}]
\Shell\Auto\command - cmd /C launch.bat
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b24b5f1-27c9-11dc-9c78-021122338171}]
\Shell\AutoRun\command - E:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee5e64d4-ed2b-11dc-9eee-0013d4f70cd6}]
\Shell\AutoRun\command - h0s2.bat
\Shell\explore\Command - h0s2.bat
\Shell\open\Command - h0s2.bat
.
Contenu du dossier 'Tâches planifiées'
2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-19 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
HKCU-Run-memo soap - c:\docume~1\Florian\APPLIC~1\REALSI~1\mess beep.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Telecom Italia France\Securite Enfants\bin\lsp.dll
TCP: {FFB7AE95-D1AD-455D-80A4-90722910EB3E} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Florian\Application Data\Mozilla\Firefox\Profiles\[u]0/uc4wh6e7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=13166&l=dis
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=
FF - component: c:\progra~1\MOZILL~1\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
---- PARAMETRES FIREFOX ----
pref(dom.disable_open_during_load, true);.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-19 11:01:28
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\searchindexer.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\documents and settings\Florian\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Heure de fin: 2009-03-19 11:06:16 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-19 10:06:11
Avant-CF: 88,717,967,360 octets libres
Après-CF: 91,389,239,296 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
262 --- E O F --- 2009-03-15 21:37:07