ComboFix 09-04-30.02 - Administrateur 30/04/2009 22:47.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.479.178 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090429-0] *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-28 au 2009-04-30 ))))))))))))))))))))))))))))))))))))
.
2009-04-30 18:33 . 2009-04-30 18:59 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-04-30 16:47 . 2009-04-30 16:47 -------- d-----w c:\documents and settings\Administrateur\Application Data\Uniblue
2009-04-30 16:37 . 2009-04-30 20:39 -------- d-----w C:\FindyKill
2009-04-25 13:00 . 2009-04-25 13:00 -------- d-----w c:\documents and settings\LocalService\Bureau
2009-04-23 18:57 . 2009-04-23 18:57 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-04-23 11:20 . 2009-04-23 11:20 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-04-23 11:19 . 2009-04-23 11:27 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\Google
2009-04-23 11:18 . 2009-04-29 19:48 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-23 11:18 . 2009-04-23 11:21 -------- d-----w c:\program files\Google
2009-04-21 15:01 . 2008-04-13 18:45 60032 ----a-w c:\windows\system32\drivers\USBAUDIO.sys
2009-04-21 15:00 . 2007-04-10 21:46 116072 ----a-w c:\windows\VX1000.dll
2009-04-21 15:00 . 2007-04-10 21:46 185704 ----a-w c:\windows\system32\cVX1000.dll
2009-04-21 15:00 . 2007-04-10 21:46 476520 ----a-w c:\windows\vVX1000.dll
2009-04-21 15:00 . 2007-04-10 21:46 709992 ----a-w c:\windows\vVX1000.exe
2009-04-21 15:00 . 2007-04-10 21:46 1966312 ----a-w c:\windows\system32\drivers\VX1000.sys
2009-04-21 15:00 . 2007-04-10 21:46 202088 ----a-w c:\windows\system32\LCCoin14.dll
2009-04-21 14:57 . 2009-04-21 14:58 -------- d-----w c:\program files\Microsoft LifeCam
2009-04-17 20:21 . 2009-04-17 20:21 -------- d-----w c:\program files\Moleskinsoft Directory Size 2.3
2009-04-16 17:44 . 2009-04-16 17:44 -------- d-----w C:\OEMSettings
2009-04-16 17:43 . 2009-04-16 17:43 21035 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-16 17:43 . 2009-04-16 17:43 -------- d-----w c:\program files\NETGEAR
2009-04-15 19:32 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 19:32 . 2009-03-06 14:20 286720 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-15 19:32 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-15 19:32 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 19:32 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 19:32 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-15 19:32 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 19:32 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 19:32 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 19:32 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 19:24 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
2009-04-15 19:23 . 2008-04-21 21:15 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-06 14:13 . 2009-04-06 14:13 -------- d-----w c:\documents and settings\Administrateur\Local Settings\Application Data\WMTools Downloaded Files
2009-04-06 14:07 . 2009-04-06 14:07 -------- d-----w c:\program files\Defraggler
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-25 12:53 . 2009-03-09 14:29 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-25 12:52 . 2009-03-06 10:54 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-24 13:28 . 2002-09-06 23:00 82172 ----a-w c:\windows\system32\perfc00C.dat
2009-04-24 13:28 . 2002-09-06 23:00 504226 ----a-w c:\windows\system32\perfh00C.dat
2009-04-21 14:48 . 2008-03-11 15:52 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-13 19:10 . 2008-03-18 08:11 -------- d-----w c:\program files\Java
2009-04-06 13:56 . 2008-06-12 19:18 -------- d-----w c:\program files\HomePlayer
2009-03-27 12:16 . 2009-03-27 12:13 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-26 17:46 . 2008-03-11 15:29 -------- d-----w c:\program files\ma-config.com
2009-03-26 17:46 . 2009-02-24 11:11 -------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-03-19 07:33 . 2008-03-13 22:24 74888 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-17 15:41 . 2008-03-26 12:34 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-03-09 03:19 . 2008-12-01 12:53 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:20 . 2004-08-03 21:54 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-04 09:50 . 2009-03-04 09:50 -------- d-----w c:\program files\Fichiers communs\Java
2009-03-03 00:13 . 2004-08-03 21:54 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-02 20:08 . 2008-03-14 15:31 -------- d-----w c:\program files\eChanblard
2009-02-24 17:48 . 2009-02-24 17:48 0 ----a-w c:\windows\nsreg.dat
2009-02-20 17:10 . 2009-03-14 11:55 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-14 13:49 . 2008-03-21 11:16 10 ----a-w c:\windows\popcinfo.dat
2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 14:05 . 2004-08-03 21:45 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:24 . 2004-08-03 21:49 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:23 . 2004-08-03 21:55 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2004-08-03 21:54 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2004-08-03 21:54 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:53 . 2004-08-03 21:54 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2004-08-03 21:54 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-06 18:39 . 2009-02-06 18:39 308600 ----a-w c:\windows\WLXPGSS.SCR
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2009-02-06 10:39 . 2002-09-06 23:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:58 . 2004-08-03 21:54 56832 ----a-w c:\windows\system32\secur32.dll
2009-02-01 16:04 . 2009-02-01 15:25 81920 ----a-w c:\windows\system32\W32N50.dll
2009-02-01 16:04 . 2009-02-01 15:25 17134 ----a-w c:\windows\system32\PCANDIS5.sys
2003-04-22 18:24 . 2003-04-22 18:24 2736128 ------w c:\program files\aiodrv.msi
2003-04-22 18:20 . 2003-04-22 18:20 2605056 ------w c:\program files\aiosw.msi
2003-04-22 18:01 . 2003-04-22 18:01 16606 ----a-w c:\program files\hpomdl01.dat
2003-04-22 18:01 . 2003-04-22 18:01 241 ----a-w c:\program files\readme.html
2003-04-09 17:19 . 2003-04-09 17:19 2848 ----a-w c:\program files\hpound08.inf
2003-04-09 17:19 . 2003-04-09 17:19 14157 ----a-w c:\program files\hpousc08.inf
2003-04-09 17:00 . 2003-04-09 17:00 2889 ----a-w c:\program files\hpousb08.inf
2003-04-09 17:00 . 2003-04-09 17:00 4715 ----a-w c:\program files\hpoglu08.inf
2003-03-20 15:20 . 2003-03-20 15:20 22523 ----a-w c:\program files\HPZius12.cat
2003-03-20 15:20 . 2003-03-20 15:20 22082 ----a-w c:\program files\hpzist12.cat
2003-03-20 15:20 . 2003-03-20 15:20 24728 ----a-w c:\program files\HPZipr12.cat
2003-03-20 15:20 . 2003-03-20 15:20 22082 ----a-w c:\program files\HPZid412.cat
2003-03-20 15:20 . 2003-03-20 15:20 21641 ----a-w c:\program files\HPOunp08.cat
2003-03-20 15:20 . 2003-03-20 15:20 24285 ----a-w c:\program files\hposcu08.cat
2003-03-20 15:20 . 2003-03-20 15:20 205503 ----a-w c:\program files\hpoprn08.cat
2003-03-09 20:30 . 2003-03-09 20:30 3667 ----a-w c:\program files\hpzist12.inf
2003-03-09 20:30 . 2003-03-09 20:30 184320 ----a-w c:\program files\hpzscr07.dll
2003-03-09 20:30 . 2003-03-09 20:30 14285 ----a-w c:\program files\hpzius12.inf
2003-03-09 20:30 . 2003-03-09 20:30 10325 ----a-w c:\program files\hpzipr12.inf
2003-03-09 20:30 . 2003-03-09 20:30 63562 ----a-w c:\program files\hposcu08.inf
2003-03-09 20:30 . 2003-03-09 20:30 51266 ----a-w c:\program files\hpoprn08.inf
2003-03-09 20:30 . 2003-03-09 20:30 3898 ----a-w c:\program files\hpounp08.inf
2003-03-09 20:30 . 2003-03-09 20:30 33952 ----a-w c:\program files\hpzid412.inf
2003-03-09 20:30 . 2003-03-09 20:30 274432 ----a-w c:\program files\hpzglu07.exe
2003-03-09 20:30 . 2003-03-09 20:30 237568 ----a-w c:\program files\hpzc3212.dll
2003-03-09 20:30 . 2003-03-09 20:30 23186 ----a-w c:\program files\hpzcin06.ex_
2002-09-09 17:48 . 2002-09-09 17:48 22608 ----a-w c:\program files\usbprint.sys
2002-09-09 17:48 . 2002-09-09 17:48 12288 ----a-w c:\program files\usbmon.dll
2002-09-09 17:47 . 2002-09-09 17:47 254005 ----a-w c:\program files\msvcrt.dll
2002-09-09 17:47 . 2002-09-09 17:47 70656 ----a-w c:\program files\msvcirt.dll
2002-09-09 17:47 . 2002-09-09 17:47 55155 ----a-w c:\program files\hpzusb00.sy_
2002-09-09 17:47 . 2002-09-09 17:47 5705 ----a-w c:\program files\hpzuci02.dl_
2002-09-09 17:47 . 2002-09-09 17:47 25639 ----a-w c:\program files\hpzpom04.dl_
2002-09-09 17:47 . 2002-09-09 17:47 212992 ----a-w c:\program files\hpzpnp07.dll
2002-09-09 17:46 . 2002-09-09 17:46 49212 ----a-w c:\program files\hpzjvp01.dll
2002-09-09 17:46 . 2002-09-09 17:46 249913 ----a-w c:\program files\hpzjut01.dll
2002-09-09 17:46 . 2002-09-09 17:46 417849 ----a-w c:\program files\hpzjpp01.dll
2002-09-09 17:46 . 2002-09-09 17:46 28722 ----a-w c:\program files\hpzjlog.dll
2002-09-09 17:46 . 2002-09-09 17:46 52552 ----a-w c:\program files\hpziou01.dl_
2002-09-09 17:46 . 2002-09-09 17:46 46017 ----a-w c:\program files\hpzion00.sy_
2002-09-06 09:54 . 2002-09-06 09:54 995383 ----a-w c:\program files\MFC42.DLL
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-04-25 516440]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"VTPreset"="VTPreset.exe" - c:\windows\system32\VTPreset.exe [2004-02-24 45056]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Assistant Smart Wizard NETGEAR pour WG311v3.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 1929216]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 1929216]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\HomePlayer\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
R2 gupdate1c9c40571393e20;Service Google Update (gupdate1c9c40571393e20);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-23 133104]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-03-15 216232]
R3 MEMSWEEP2;MEMSWEEP2; [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-25 64160]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [2007-10-09 38144]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2008-12-08 55136]
S2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-25 953168]
S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S3 HSFHWVIA;HSFHWVIA;c:\windows\system32\DRIVERS\HSFHWVIA.sys [2008-03-11 159616]
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys [2007-12-28 287232]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{85f183c0-887c-11dd-9c02-0040d0587e97}]
\Shell\AutoRun\command - F:\AutoTransfer.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 12:52]
2008-06-26 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2170 series272A572217594EBCF1CEE215E352B92AD073FDE4206113274.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 16:56]
2009-04-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-23 11:18]
2009-04-30 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-23 11:19]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = hxxp://www.01net.com/telecharger/
IE: { - c:\program files\Messenger\msmsgs.exe
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\9vi5a7tr.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\9vi5a7tr.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-30 22:49
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-725345543-436374069-1060284298-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,20,95,ec,3e,76,af,7a,4d,ab,d6,52,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,20,95,ec,3e,76,af,7a,4d,ab,d6,52,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(580)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2009-04-30 22:52
ComboFix-quarantined-files.txt 2009-04-30 20:52
Avant-CF: 3 653 844 992 octets libres
Après-CF: 3 661 606 912 octets libres
239 --- E O F --- 2009-04-29 17:06