ComboFix 09-09-23.02 - mustapha 24/09/2009 13:11.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.383.187 [GMT 1:00]
Lancé depuis: c:\documents and settings\mustapha\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090923-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\mustapha\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\mustapha\Application Data\addons.dat
c:\documents and settings\mustapha\Cookies\mustapha@managerzone.bbgames[2].txt
c:\program files\bifrost
c:\program files\bifrost\logg.dat
C:\test.txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-24 au 2009-09-24 ))))))))))))))))))))))))))))))))))))
.
2009-09-24 11:15 . 2009-09-24 11:15 -------- d-----w- c:\documents and settings\mustapha\Application Data\Leadertech
2009-09-17 11:48 . 2009-09-17 11:48 -------- d-----w- c:\windows\Downloaded Installations
2009-09-17 09:37 . 2009-09-17 09:37 -------- d-----w- c:\program files\CDROM
2009-09-14 19:26 . 2009-09-14 19:26 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-09-14 19:25 . 2009-09-23 09:19 -------- d-----w- c:\documents and settings\mustapha\Application Data\skypePM
2009-09-14 17:57 . 2009-09-23 09:27 -------- d-----w- c:\documents and settings\mustapha\Application Data\Skype
2009-09-14 17:57 . 2009-09-14 17:57 -------- d-----w- c:\program files\Fichiers communs\Skype
2009-09-14 17:57 . 2009-09-14 17:57 -------- d-----r- c:\program files\Skype
2009-09-14 17:57 . 2009-09-14 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-09-04 21:01 . 2009-09-17 11:50 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-09-04 20:57 . 2009-09-22 08:27 -------- d-----w- c:\documents and settings\mustapha\Local Settings\Application Data\Adobe
2009-09-03 01:59 . 2004-08-04 04:54 221184 ----a-w- c:\windows\system32\wmpns.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 11:39 . 2009-07-11 08:33 -------- d-----w- c:\documents and settings\mustapha\Application Data\Orbit
2009-09-21 16:26 . 2009-07-09 09:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-19 12:39 . 2009-07-09 11:57 69544 ----a-w- c:\documents and settings\mustapha\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-19 08:28 . 2009-07-11 08:33 -------- d-----w- c:\program files\Orbitdownloader
2009-09-16 18:16 . 2009-07-11 17:07 -------- d-----w- c:\documents and settings\mustapha\Application Data\EoRezo
2009-09-14 13:05 . 2009-08-21 23:19 0 ----a-w- c:\documents and settings\mustapha\errorlog.tmp
2009-09-01 14:08 . 2009-08-17 09:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-21 23:15 . 2009-08-21 23:16 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-21 23:15 . 2009-08-21 23:15 -------- d-----w- c:\program files\Java
2009-08-17 16:10 . 2009-07-09 14:11 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-07-09 14:11 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-07-09 14:11 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-07-09 14:11 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-07-09 14:11 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-07-09 14:11 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-07-09 14:11 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-07-09 14:11 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-07-09 14:11 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-17 09:26 . 2009-07-10 15:51 -------- d-----w- c:\program files\Google
2009-08-16 23:34 . 2009-08-16 23:34 -------- d-----w- c:\program files\Fichiers communs\DirectX
2009-08-15 23:24 . 2009-08-15 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2009-08-15 21:44 . 2009-08-15 21:44 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2009-08-14 22:32 . 2009-08-14 15:53 -------- d-----w- c:\program files\vcmm
2009-08-13 15:56 . 2009-08-13 15:56 -------- d-----w- c:\program files\GTA4MODS.com
2009-08-12 19:32 . 2009-08-12 19:32 131 ----a-w- c:\documents and settings\mustapha\Local Settings\Application Data\fusioncache.dat
2009-08-12 19:24 . 2002-09-07 00:00 70216 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-12 19:24 . 2002-09-07 00:00 504540 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-10 10:59 . 2009-08-10 10:59 -------- d-----w- c:\program files\Fichiers communs\xing shared
2009-08-10 10:59 . 2009-07-10 15:55 -------- d-----w- c:\program files\Fichiers communs\Real
2009-08-08 17:34 . 2009-07-31 13:01 -------- d-----w- c:\documents and settings\mustapha\Application Data\U3
2009-07-09 09:04 . 2009-07-09 09:04 21892 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-10 39408]
"Google Update"="c:\documents and settings\mustapha\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-15 133104]
"c:\program files\CDROM\CDROM.exe"="c:\program files\CDROM\CDROM.exe" [2007-06-13 828928]
"d:\logiciel\super.exe"="d:\logiciel\super.exe" [2007-06-13 828928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"SoftwareHelper"="c:\documents and settings\mustapha\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe" [2008-12-09 368224]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-08-10 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-21 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Orbit.lnk - c:\program files\Orbitdownloader\orbitdm.exe [2009-7-11 1719496]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [09/07/2009 15:11 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/07/2009 15:11 20560]
S2 gupdate1ca1f1cc18d6cc0;Service Google Update (gupdate1ca1f1cc18d6cc0);c:\program files\Google\Update\GoogleUpdate.exe [17/08/2009 10:26 133104]
.
Contenu du dossier 'Tâches planifiées'
2009-09-24 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-10 09:18]
2009-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-17 09:25]
2009-09-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-17 09:25]
2009-09-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1935655697-1957994488-1003Core.job
- c:\documents and settings\mustapha\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 22:28]
2009-09-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2000478354-1935655697-1957994488-1003UA.job
- c:\documents and settings\mustapha\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-15 22:28]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://y.lo.st
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.cherche.us/keyword/%s
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.cherche.us/keyword/%s
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: chat-land.org
TCP: {6DB68334-3E1E-487A-BE34-6A7CDC3AF982} = 41.221.20.4 213.140.2.12
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-EoEngine - (no file)
HKLM-Run-EoSudoku - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-24 13:16
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-09-24 13:18
ComboFix-quarantined-files.txt 2009-09-24 12:18
Avant-CF: 5 885 886 464 octets libres
Après-CF: 6 470 508 544 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
158