ComboFix 09-05-14.05 - Barranger 15/05/2009 13:38.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.515 [GMT 2:00]
Lancé depuis: c:\documents and settings\Barranger\Bureau\ComboFix.exe
AV: Antivirus BitDefender *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Pare-feu BitDefender *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\\setup.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-15 au 2009-05-15 ))))))))))))))))))))))))))))))))))))
.
2009-05-15 10:25 . 2009-05-15 10:40 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-15 10:17 . 2009-05-15 11:14 -------- d-----w C:\UsbFix
2009-05-15 08:51 . 2009-05-15 09:58 -------- d-----w c:\program files\Ad-remover
2009-05-15 08:44 . 2009-05-15 08:45 -------- d-----w c:\program files\trend micro
2009-05-15 08:44 . 2009-05-15 08:45 -------- d-----w C:\rsit
2009-05-15 08:29 . 2009-05-15 08:29 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-05-15 08:25 . 2009-05-15 08:25 -------- d-----w c:\program files\Microsoft Silverlight
2009-05-15 08:25 . 2009-05-15 08:25 -------- d-----w c:\documents and settings\Barranger\Application Data\Windows Desktop Search
2009-05-15 08:24 . 2009-05-15 08:24 -------- d-----w c:\program files\Windows Desktop Search
2009-05-15 08:24 . 2009-05-15 08:24 -------- d-----w c:\windows\system32\GroupPolicy
2009-05-15 08:24 . 2008-03-07 17:02 29696 -c----w c:\windows\system32\dllcache\mimefilt.dll
2009-05-15 08:24 . 2008-03-07 17:02 98304 -c----w c:\windows\system32\dllcache\nlhtml.dll
2009-05-15 08:24 . 2008-03-07 17:02 192000 -c----w c:\windows\system32\dllcache\offfilt.dll
2009-05-15 08:23 . 2009-05-15 08:23 -------- d-----w c:\program files\Windows Media Connect 2
2009-05-15 08:21 . 2009-05-15 08:22 -------- d-----w c:\windows\system32\drivers\UMDF
2009-05-15 08:18 . 2009-05-15 08:18 -------- d-----w c:\windows\system32\URTTEMP
2009-05-14 19:35 . 2009-05-14 19:37 -------- d-----w c:\windows\system32\NtmsData
2009-05-14 14:12 . 2009-05-14 14:12 -------- d-----w c:\documents and settings\Barranger\Application Data\True Sword
2009-05-14 14:10 . 2005-10-11 12:40 356352 ----a-w c:\windows\eSellerateEngine.dll
2009-05-14 14:10 . 2003-06-06 09:21 81920 ----a-w c:\windows\eSellerateControl350.dll
2009-05-14 14:10 . 2009-05-14 15:39 -------- d-----w c:\program files\True Sword 5
2009-05-14 12:48 . 2009-05-15 11:15 81984 ----a-w c:\windows\system32\bdod.bin
2009-05-14 12:08 . 2009-05-14 12:08 -------- d-----w c:\documents and settings\Barranger\Application Data\BitDefender
2009-05-14 12:07 . 2009-05-14 12:10 -------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-05-14 12:07 . 2009-05-14 12:07 -------- d-----w c:\program files\BitDefender
2009-05-14 11:58 . 2009-05-14 12:07 -------- d-----w c:\program files\Fichiers communs\BitDefender
2009-05-14 11:00 . 2009-05-14 11:01 -------- dc-h--w c:\windows\ie8
2009-05-13 21:48 . 2009-05-14 10:46 -------- d-----w c:\documents and settings\Barranger\.housecall6.6
2009-05-13 21:26 . 2009-05-13 21:26 -------- d-----w c:\program files\TightVNC
2009-05-13 20:05 . 2009-05-13 20:05 -------- d-----w c:\program files\Lavasoft
2009-05-13 20:05 . 2009-05-13 20:06 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-13 20:05 . 2009-05-13 20:05 -------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-05-13 08:07 . 2009-05-13 08:08 -------- d-----w c:\documents and settings\All Users\AdobeTemp
2009-05-08 18:54 . 2001-08-17 19:56 7552 -c--a-w c:\windows\system32\dllcache\sonypvu1.sys
2009-05-08 18:54 . 2001-08-17 19:56 7552 ----a-w c:\windows\system32\drivers\SONYPVU1.SYS
2009-05-04 14:27 . 2009-05-04 14:27 -------- d-----w c:\program files\Fichiers communs\DivX Shared
2009-05-02 15:43 . 2009-05-02 15:43 -------- d-----w c:\program files\BurnTool
2009-05-02 14:10 . 2009-05-02 14:10 1854 ----a-w c:\windows\system32\SpoonUninstall-Objectif Tarot.dat
2009-05-02 14:10 . 2009-05-02 14:10 131584 ----a-w c:\windows\system32\SpoonUninstall.exe
2009-05-02 14:10 . 2009-05-02 18:29 -------- d-----w c:\program files\Objective Tarot
2009-04-18 20:25 . 2009-05-15 10:56 -------- d-----w c:\documents and settings\Barranger\Tracing
2009-04-18 20:23 . 2009-05-15 08:25 -------- d-----w c:\program files\Microsoft
2009-04-18 20:23 . 2009-04-18 20:23 -------- d-----w c:\program files\Windows Live SkyDrive
2009-04-18 20:20 . 2009-04-18 20:20 -------- d-----w c:\program files\Fichiers communs\Windows Live
2009-04-16 16:42 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 16:42 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 16:42 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 16:42 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 16:42 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 16:42 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 16:42 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 16:42 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 16:42 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 16:42 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
2009-04-16 16:41 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-15 08:24 . 2006-03-02 12:00 94716 ----a-w c:\windows\system32\perfc00C.dat
2009-05-15 08:24 . 2006-03-02 12:00 535132 ----a-w c:\windows\system32\perfh00C.dat
2009-05-14 08:53 . 2008-12-04 11:25 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-05-04 14:27 . 2008-12-20 12:59 -------- d-----w c:\program files\DivX
2009-04-18 20:24 . 2008-12-03 08:50 -------- d-----w c:\program files\Windows Live
2009-04-11 08:55 . 2009-03-12 20:41 85733 ----a-w c:\windows\system32\cbed3dc5-62b1-4984-953b-f46372532991.exe
2009-04-10 09:49 . 2009-04-10 09:49 717824 ----a-w c:\windows\system32\nshA.dll
2009-04-09 06:51 . 2008-08-14 06:57 73312 ----a-w c:\windows\system32\drivers\adfs.sys
2009-04-07 08:32 . 2009-04-07 08:32 -------- d-----w c:\program files\MSXML 4.0
2009-04-07 08:14 . 2008-12-04 13:29 -------- d-----w c:\program files\Java
2009-04-06 07:28 . 2009-04-06 07:26 -------- d-----w c:\program files\Fichiers communs\Ahead
2009-04-06 07:26 . 2009-04-06 07:26 -------- d-----w c:\program files\Nero 7
2009-03-17 09:02 . 2009-03-17 09:02 61224 ----a-w c:\documents and settings\Barranger\GoToAssistDownloadHelper.exe
2009-03-13 14:57 . 2008-12-03 21:35 73216 ----a-w c:\documents and settings\Barranger\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-09 03:19 . 2008-12-04 13:29 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 02:34 . 2006-03-02 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2006-03-02 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2006-03-02 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2006-03-02 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2006-03-02 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2006-03-02 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2006-03-02 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2006-03-02 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2006-03-02 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2006-03-02 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:20 . 2006-03-02 12:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-01-24 21:12 . 2009-01-21 18:44 1104 ----a-w c:\program files\bestsco0.ret
2009-01-21 17:57 . 2009-01-21 17:57 9 ----a-w c:\program files\lance.ret
2008-09-30 17:01 . 2008-09-30 17:01 123048501 ----a-w c:\program files\openofficeorg1.cab
2008-09-30 16:26 . 2008-09-30 16:26 217 ----a-w c:\program files\setup.ini
2008-09-30 16:26 . 2008-09-30 16:26 9775104 ----a-w c:\program files\openofficeorg30.msi
2007-03-07 20:10 . 2009-01-15 18:08 4308 ----a-w c:\program files\Setup.lst
2007-03-07 20:03 . 2009-01-15 18:08 982 ----a-w c:\program files\Readme.txt
2002-03-11 09:06 . 2002-03-11 09:06 1822520 ----a-w c:\program files\instmsiw.exe
2002-03-11 08:45 . 2002-03-11 08:45 1708856 ----a-w c:\program files\instmsia.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-10 39408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2009-03-11 611712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-10 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-03-19 778240]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-02-23 69632]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-08-03 1826816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Barranger\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\dwwin.exe]
"Debugger"=c:\windows\system32\win.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Data-Concept\\Cyberlux Serveur 7 Fusion\\Cyberlux.exe"=
"c:\\PVSW\\Bin\\w3dbsmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Data-Concept\\Cyberlux Serveur 7 Fusion\\ControlPc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\EBP\\Compta13.0\\compta.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\TightVNC\\WinVNC.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"5900:TCP"= 5900:TCP:VNP
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [06/10/2008 18:16 82696]
R2 EBP Pervasive.SQL;EBP Pervasive.SQL;c:\pvsw\Bin\WGE_SRV.exe [07/12/2006 17:08 32768]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [18/09/2008 12:09 111112]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [12/02/2009 16:52 104328]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [20/01/2009 19:16 172032]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [03/12/2008 10:56 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1baeb6a7-3e0a-11de-81da-001e8c6661c7}]
\Shell\AutoRun\command - E:\e2.cmd
\Shell\open\Command - E:\e2.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f6d7888-d3fd-11dd-b74c-001e8c6661c7}]
\Shell\AutoRun\command - E:\EmDesk.exe
\Shell\EmDesk\command - E:\EmDesk.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70f60364-3f9c-11de-81dc-001e8c6661c7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe /e:vbs winfile.jpg
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a229744b-28d2-11de-81c2-001e8c6661c7}]
\Shell\Auto\command - sxs.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe
.
Contenu du dossier 'Tâches planifiées'
2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {A06BE318-C096-11D4-964F-0010A4D06F69} - hxxps://tva.dgi.minefi.gouv.fr/activeX/TeleTVA.tva
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-15 13:40
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-05-15 13:41
ComboFix-quarantined-files.txt 2009-05-15 11:41
Avant-CF: 285 088 411 648 octets libres
Après-CF: 285 604 593 664 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
215 --- E O F --- 2009-05-13 08:10