ComboFix 09-03-29.04 - cédric 2009-03-30 23:49:06.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1022.474 [GMT 2:00]
Lancé depuis: c:\documents and settings\cédric\Bureau\ComboFix.exe
AV: BitDefender Internet Security v10 *On-access scanning enabled* (Updated)
AV: Kaspersky Internet Security *On-access scanning enabled* (Updated)
AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated)
FW: BitDefender Internet Security v10 *enabled*
FW: Kaspersky Internet Security *enabled*
FW: Norton Internet Security 2006 *enabled*
FW: Norton Internet Worm Protection *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\corinne\Application Data\MessengerSkinner
c:\documents and settings\corinne\Application Data\MessengerSkinner\Userdata\defaultPack.cab
c:\documents and settings\corinne\Application Data\MessengerSkinner\Userdata\languages.xml
c:\documents and settings\corinne\Application Data\MessengerSkinner\Userdata\pack1.cab
c:\documents and settings\cédric\Application Data\wiaserva.log
c:\program files\FunWebProducts
c:\windows\pack.epk
c:\windows\system32\aompcenth.dat
c:\windows\system32\aompcenth_nav.dat
c:\windows\system32\aompcenth_navps.dat
c:\windows\system32\begkai.dat
c:\windows\system32\begkai_navps.dat
c:\windows\system32\begkai_navup.dat
c:\windows\system32\cvyrxz.dat
c:\windows\system32\cvyrxz_navps.dat
c:\windows\system32\cvyrxz_navup.dat
c:\windows\system32\cxsgfdtv.dat
c:\windows\system32\cxsgfdtv_nav.dat
c:\windows\system32\cxsgfdtv_navps.dat
c:\windows\system32\ecqkdx.dat
c:\windows\system32\ecqkdx_nav.dat
c:\windows\system32\ecqkdx_navps.dat
c:\windows\system32\havzpwugq.dat
c:\windows\system32\havzpwugq_nav.dat
c:\windows\system32\havzpwugq_navps.dat
c:\windows\system32\hgjfheltub.dat
c:\windows\system32\higeniraur.dat
c:\windows\system32\higeniraur_navps.dat
c:\windows\system32\icyrnx.dat
c:\windows\system32\icyrnx_nav.dat
c:\windows\system32\icyrnx_navps.dat
c:\windows\system32\lmvnvjwsk_navtmp.dat
c:\windows\system32\mpgakld.dat
c:\windows\system32\mpgakld_nav.dat
c:\windows\system32\mpgakld_navps.dat
c:\windows\system32\mwvhrzdjgq.dat
c:\windows\system32\mwvhrzdjgq_nav.dat
c:\windows\system32\mwvhrzdjgq_navps.dat
c:\windows\system32\nvs2.inf
c:\windows\system32\oyldnc.dat
c:\windows\system32\oyldnc_nav.dat
c:\windows\system32\oyldnc_navps.dat
c:\windows\system32\qmwscatgzc.dat
c:\windows\system32\qmwscatgzc_nav.dat
c:\windows\system32\qmwscatgzc_navps.dat
c:\windows\system32\qmwscatgzc_navup.dat
c:\windows\system32\svktlksij.dat
c:\windows\system32\svktlksij_navps.dat
c:\windows\system32\svktlksij_navup.dat
c:\windows\system32\ypxbiyc.dat
c:\windows\system32\ypxbiyc_nav.dat
c:\windows\system32\ypxbiyc_navps.dat
c:\windows\system32\zdlxykatb.dat
c:\windows\system32\zdlxykatb_navps.dat
c:\windows\system32\zdlxykatb_navtmp.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RKHIT
-------\Service_RkHit
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-30 ))))))))))))))))))))))))))))))))))))
.
2009-03-31 00:02 . 2009-03-31 00:02 <REP> d-------- c:\windows\LastGood
2009-03-30 23:12 . 2009-03-30 23:12 <REP> d-------- C:\rsit
2009-03-30 23:12 . 2009-03-30 23:12 <REP> d-------- c:\program files\trend micro
2009-03-18 00:56 . 2009-03-28 13:52 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-18 00:56 . 2009-03-18 00:56 1,409 --a------ c:\windows\QTFont.for
2009-03-03 18:20 . 2009-03-03 23:49 <REP> d-------- c:\program files\Kyodai Mahjongg 2006
2009-02-24 10:36 . 2006-04-29 15:25 40,960 --a------ c:\windows\system32\psfind.dll
2009-02-24 10:27 . 2009-02-24 10:27 <REP> d-------- c:\program files\THQ
2009-02-23 22:57 . 2009-02-23 22:57 57,344 --a------ c:\windows\system32\apache.dll
2009-02-09 19:46 . 2009-02-09 19:46 45 ---h----- c:\windows\dhdd8187.dat
2009-02-08 20:25 . 2009-02-08 20:25 <REP> d-------- c:\program files\Axon Data
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-30 22:03 3,307,296 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-30 22:03 --------- d-----w c:\program files\Steam
2009-03-30 22:03 --------- d-----w c:\documents and settings\cédric\Application Data\OpenOffice.org2
2009-03-30 22:02 138,288,672 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-30 21:59 312,080 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-30 21:59 1,854,104 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-30 12:49 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-30 12:39 --------- d-----w c:\documents and settings\cédric\Application Data\Audacity
2009-03-26 00:10 --------- d-----w c:\documents and settings\corinne\Application Data\OpenOffice.org2
2009-02-26 18:06 32,549 ----a-w c:\windows\king-uninstall.exe
2009-02-24 08:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-03 19:25 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 19:25 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2006-11-14 10:52 5 --sha-w c:\windows\system32\fdcdcabdcf_d.dll
2008-11-20 22:52 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008112020081121\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\apps\SMP\SmpSys.exe" [2005-11-17 975360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Steam"="c:\program files\steam\steam.exe" [2008-10-09 1410296]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"Packard Bell Software Suite"="c:\program files\Packard Bell\Packard Bell Software Suite\Launcher.exe" [2008-08-28 1934144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Vade Retro Outlook Express"="c:\progra~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe" [2004-10-04 310272]
"DetectorApp"="c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe" [2005-10-20 102400]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-10-13 26112]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\corinne\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 393216]
c:\documents and settings\c‚dric\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.0.lnk - c:\program files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 393216]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-11-18 110592]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\SteamApps\\elladan246\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\elladan246\\source sdk base\\hl2.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\French\\setup.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [2007-12-13 78848]
R2 Cepstral License Server;Cepstral License Server;c:\program files\Cepstral\bin\CepstralLicSrv.exe [2008-06-24 57344]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2006-10-13 7040]
S3 zlportio;zlportio;\??\c:\program files\UltraStar Deluxe\zlportio.sys --> c:\program files\UltraStar Deluxe\zlportio.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12a8c037-c489-11dd-b08f-00038a000015}]
\Shell\AutoRun\command - J:\ClickMe.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-cédric - c:\documents and settings\cédric\cédric.exe
HKLM-Run-ISUSPM Startup - c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe
HKLM-Run-ISUSScheduler - c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe
HKLM-Run-ccApp - c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
HKLM-Run-BDAgent - c:\program files\Softwin\BitDefender10\bdagent.exe
HKLM-Run-BDMCon - c:\program files\Softwin\BitDefender10\bdmcon.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext = hxxp://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=6&key=BM2
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
IE: Add to AMV Converter... - c:\program files\MP3 Player Utilities 4.18\AMVConverter\grab.html
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/2.0.2.23/cfweb_activex.camfrogweb.com-advanced-2.0.2.23_instmodule.exe
FF - ProfilePath - c:\documents and settings\cédric\Application Data\Mozilla\Firefox\Profiles\zbxwlat6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://french.eazel.com/index.php?rvs=hompag
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-31 00:05:31
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-4266511436-4083242982-2466632262-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:0e,bc,22,45,da,d8,7b,f4,ef,28,0d,9b,5f,a0,25,7c,eb,a4,32,78,1d,09,32,
be,64,a2,78,c0,ac,21,cd,d5,2f,f9,b1,f1,62,01,1c,bc,cf,7f,65,61,bb,2b,c5,83,\
"??"=hex:8b,7f,4a,a7,43,86,e7,f3,36,69,4e,d7,80,e2,17,17
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(700)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\klogon.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\adialhk.dll
- - - - - - - > 'lsass.exe'(756)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Packard Bell\Packard Bell Software Suite\PowerSave\HDPBSSS.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
c:\progra~1\COMMON~1\X10\Common\X10nets.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\apps\ABOARD\AOSD.EXE
c:\windows\ehome\ehmsas.exe
c:\program files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
c:\program files\OpenOffice.org 2.0\program\soffice.exe
c:\program files\OpenOffice.org 2.0\program\soffice.bin
c:\program files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
.
**************************************************************************
.
Heure de fin: 2009-03-31 0:09:09 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-30 22:09:05
Avant-CF: 51 023 486 976 octets libres
Après-CF: 56,063,598,592 octets libres
270 --- E O F --- 2009-03-30 22:03:46