ComboFix 09-08-24.06 - Odette 2009-08-25 12:32.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.2.1036.18.190.88 [GMT -4:00]
Running from: c:\documents and settings\Bureau\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\program files\SuperCopier2\SC2Hook.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\11632344
c:\documents and settings\All Users\Application Data\11632344\11632344
c:\documents and settings\All Users\Application Data\11632344\11632344.exe
c:\documents and settings\All Users\Application Data\11632344\pc11632344ins
c:\documents and settings\Application Data\Google
c:\recycler\S-1-5-21-2064928127-3868026699-604471969-8373
c:\recycler\S-1-5-21-2064928127-3868026699-604471969-8373\rundll32.exe
c:\windows\Installer\116844c.msp
c:\windows\Installer\11ccdd.msp
c:\windows\Installer\11cce1.msp
c:\windows\Installer\123af0b.msp
c:\windows\Installer\12522e.msp
c:\windows\Installer\125232.msp
c:\windows\Installer\125236.msp
c:\windows\Installer\12523a.msp
c:\windows\Installer\12523e.msp
c:\windows\Installer\125242.msp
c:\windows\Installer\125246.msp
c:\windows\Installer\12524a.msp
c:\windows\Installer\12524e.msp
c:\windows\Installer\125252.msp
c:\windows\Installer\125256.msp
c:\windows\Installer\12525a.msp
c:\windows\Installer\12525e.msp
c:\windows\Installer\125262.msp
c:\windows\Installer\125266.msp
c:\windows\Installer\12526a.msp
c:\windows\Installer\12526e.msp
c:\windows\Installer\12626f7.msp
c:\windows\Installer\12626fb.msp
c:\windows\Installer\12626ff.msp
c:\windows\Installer\1262703.msp
c:\windows\Installer\1262707.msp
c:\windows\Installer\126270b.msp
c:\windows\Installer\126270f.msp
c:\windows\Installer\1262713.msp
c:\windows\Installer\1262717.msp
c:\windows\Installer\126271b.msp
c:\windows\Installer\126271f.msp
c:\windows\Installer\1262723.msp
c:\windows\Installer\1262727.msp
c:\windows\Installer\1299589.msp
c:\windows\Installer\1357375.msp
c:\windows\Installer\14d8e4.msp
c:\windows\Installer\14d8e8.msp
c:\windows\Installer\14d8ec.msp
c:\windows\Installer\14d8f0.msp
c:\windows\Installer\14d8f4.msp
c:\windows\Installer\14d8f8.msp
c:\windows\Installer\14d8fc.msp
c:\windows\Installer\14d900.msp
c:\windows\Installer\14d904.msp
c:\windows\Installer\14d908.msp
c:\windows\Installer\16eb05d.msp
c:\windows\Installer\1a56d2.msp
c:\windows\Installer\23c6e9.msp
c:\windows\Installer\23c6ed.msp
c:\windows\Installer\23c6f1.msp
c:\windows\Installer\23c6f5.msp
c:\windows\Installer\240992.msp
c:\windows\Installer\240996.msp
c:\windows\Installer\24099a.msp
c:\windows\Installer\24099e.msp
c:\windows\Installer\2409a2.msp
c:\windows\Installer\2409a6.msp
c:\windows\Installer\2409aa.msp
c:\windows\Installer\2409ae.msp
c:\windows\Installer\2409b2.msp
c:\windows\Installer\2409b6.msp
c:\windows\Installer\2409ba.msp
c:\windows\Installer\2409be.msp
c:\windows\Installer\2409c2.msp
c:\windows\Installer\2409c6.msp
c:\windows\Installer\2409ca.msp
c:\windows\Installer\2409ce.msp
c:\windows\Installer\2409d2.msp
c:\windows\Installer\242f9a8.msp
c:\windows\Installer\2d3f966.msp
c:\windows\Installer\2d3f96a.msp
c:\windows\Installer\2d3f96e.msp
c:\windows\Installer\2d3f972.msp
c:\windows\Installer\2d3f976.msp
c:\windows\Installer\2d3f97a.msp
c:\windows\Installer\2d3f97e.msp
c:\windows\Installer\2d3f997.msp
c:\windows\Installer\2d3f99b.msp
c:\windows\Installer\2d3f99f.msp
c:\windows\Installer\2d3f9a3.msp
c:\windows\Installer\2d3f9a7.msp
c:\windows\Installer\2d3f9ab.msp
c:\windows\Installer\2d3f9af.msp
c:\windows\Installer\2d3f9b3.msp
c:\windows\Installer\2d3f9b7.msp
c:\windows\Installer\2d3f9bb.msp
c:\windows\Installer\3af8b5.msp
c:\windows\Installer\3af8b9.msp
c:\windows\Installer\3af8bd.msp
c:\windows\Installer\3af8c1.msp
c:\windows\Installer\488cfe.msp
c:\windows\Installer\59a5e0.msp
c:\windows\Installer\59a5e1.msp
c:\windows\Installer\59a5e5.msp
c:\windows\Installer\5b9257.msp
c:\windows\Installer\5b925b.msp
c:\windows\Installer\5b925f.msp
c:\windows\Installer\5b9263.msp
c:\windows\Installer\5b9267.msp
c:\windows\Installer\5b926b.msp
c:\windows\Installer\5b926f.msp
c:\windows\Installer\5b9273.msp
c:\windows\Installer\5b9277.msp
c:\windows\Installer\5b927b.msp
c:\windows\Installer\5b927f.msp
c:\windows\Installer\5b9283.msp
c:\windows\Installer\5b9287.msp
c:\windows\Installer\5b928b.msp
c:\windows\Installer\5b928f.msp
c:\windows\Installer\5b9293.msp
c:\windows\Installer\5b9297.msp
c:\windows\Installer\69821.msp
c:\windows\Installer\69825.msp
c:\windows\Installer\69829.msp
c:\windows\Installer\71e76.msp
c:\windows\Installer\71e7a.msp
c:\windows\Installer\71e7e.msp
c:\windows\Installer\71e82.msp
c:\windows\Installer\71e86.msp
c:\windows\Installer\71e8a.msp
c:\windows\Installer\71e8e.msp
c:\windows\Installer\71e92.msp
c:\windows\Installer\71e96.msp
c:\windows\Installer\71e9a.msp
c:\windows\Installer\71e9e.msp
c:\windows\Installer\71ea2.msp
c:\windows\Installer\71ea6.msp
c:\windows\Installer\71eaa.msp
c:\windows\Installer\71eae.msp
c:\windows\Installer\71eb2.msp
c:\windows\Installer\71eb6.msp
c:\windows\Installer\7971b.msp
c:\windows\Installer\7971f.msp
c:\windows\Installer\79723.msp
c:\windows\Installer\79727.msp
c:\windows\Installer\7972b.msp
c:\windows\Installer\7972f.msp
c:\windows\Installer\79733.msp
c:\windows\Installer\79737.msp
c:\windows\Installer\7973b.msp
c:\windows\Installer\7973f.msp
c:\windows\Installer\79743.msp
c:\windows\Installer\79747.msp
c:\windows\Installer\7974b.msp
c:\windows\Installer\7974f.msp
c:\windows\Installer\79753.msp
c:\windows\Installer\79757.msp
c:\windows\Installer\7975b.msp
c:\windows\Installer\7c761.msp
c:\windows\Installer\7c765.msp
c:\windows\Installer\7c769.msp
c:\windows\Installer\7c76d.msp
c:\windows\Installer\7c771.msp
c:\windows\Installer\81b230c.msp
c:\windows\Installer\81b2310.msp
c:\windows\Installer\8d090a.msi
c:\windows\Installer\8d090b.msp
c:\windows\Installer\8d090c.msp
c:\windows\Installer\8d090d.msp
c:\windows\Installer\8d090e.msp
c:\windows\Installer\8d090f.msp
c:\windows\Installer\8d0910.msp
c:\windows\Installer\8d0911.msp
c:\windows\Installer\8d0912.msp
c:\windows\Installer\8d0913.msp
c:\windows\Installer\8d0914.msp
c:\windows\system32\setting.ini
.
((((((((((((((((((((((((( Files Created from 2009-07-25 to 2009-08-25 )))))))))))))))))))))))))))))))
.
2009-08-25 03:23 . 2009-08-25 04:31 -------- d-----w- C:\Lop SD
2009-08-25 03:10 . 2009-08-25 03:11 -------- d-----w- c:\program files\trend micro
2009-08-25 03:10 . 2009-08-25 03:11 -------- d-----w- C:\rsit
2009-08-24 23:33 . 2009-08-24 23:33 -------- d-----w- c:\documents and settings\Application Data\Malwarebytes
2009-08-24 23:33 . 2009-08-24 23:33 -------- d-----w- c:\documents and settings\Application Data\Malwarebytes
2009-08-24 23:32 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-24 23:32 . 2009-08-24 23:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-24 23:32 . 2009-08-24 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-24 23:32 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-24 23:16 . 2009-08-24 23:16 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Apple Computer
2009-08-24 23:16 . 2009-08-24 23:16 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Apple Computer
2009-08-22 06:48 . 2009-08-22 06:49 -------- d-----w- C:\97eee50456ab8a2fd4adb80732a569b0
2009-08-22 06:38 . 2009-08-22 06:38 -------- d-----w- C:\f421059c2cfb97d794a2e85004
2009-08-22 06:37 . 2009-08-22 06:38 -------- d-----w- C:\f9065e9131f354747af6
2009-08-22 04:42 . 2009-08-25 16:29 -------- d-----w- c:\windows\system\spool
2009-08-22 04:14 . 2009-08-22 04:14 -------- d-----w- C:\046e36b332192a63f1bfd4684a
2009-08-22 04:13 . 2009-08-22 04:14 -------- d-----w- C:\b05de0705b2cea75d1
2009-08-18 03:44 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-18 03:37 . 2009-08-25 16:19 753664 ----a-w- c:\documents and settings\All Users\Application Data\One idol win data\safe trust.exe
2009-08-18 03:37 . 2009-08-18 03:37 753664 ----a-w- c:\documents and settings\Application Data\Closeinfo\xpjmnpgs.exe
2009-08-18 03:36 . 2009-08-18 03:36 -------- d-----w- c:\program files\Closeinfo
2009-08-18 03:34 . 2009-08-18 03:34 315392 ----a-w- c:\documents and settings\Application Data\Closeinfo\smawkgdy.exe
2009-08-09 16:04 . 2009-08-09 16:04 -------- d-----w- c:\documents and settings\Odette\Local Settings\Application Data\ESET
2009-08-05 09:00 . 2009-08-05 09:00 205312 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-26 19:22 . 2009-07-26 19:22 757760 ----a-w- c:\documents and settings\Application Data\Closeinfo\igsrwrnm.exe
2009-07-26 19:19 . 2009-07-26 19:19 303104 ----a-w- c:\documents and settings\Application Data\Closeinfo\matamkme.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 16:29 . 2009-01-28 00:54 -------- d-----w- c:\program files\SuperCopier2
2009-08-25 16:24 . 2009-08-25 16:28 3184368 ----a-r- c:\documents and settings\Bureau\ComboFix.exe
2009-08-25 03:04 . 2009-04-06 15:44 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-08-25 01:32 . 2008-04-14 11:00 85078 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-25 01:32 . 2008-04-14 11:00 510986 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-25 00:06 . 2009-04-12 00:50 42752 ----a-w- c:\documents and settings\Odette\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 03:38 . 2009-07-11 01:16 -------- d-----w- c:\documents and settings\Application Data\Closeinfo
2009-08-18 03:37 . 2009-07-11 01:17 270336 ----a-w- c:\documents and settings\Application Data\Closeinfo\Blah multi mode.exe
2009-08-18 03:37 . 2009-07-11 01:17 315392 ----a-w- c:\documents and settings\Application Data\Closeinfo\Ooze Two Grid 01.exe
2009-08-18 03:37 . 2009-07-11 01:17 -------- d-----w- c:\documents and settings\All Users\Application Data\One idol win data
2009-08-18 03:35 . 2009-07-11 01:16 516096 ----a-w- c:\documents and settings\Application Data\Closeinfo\Wipe Aim Dale.exe
2009-08-11 23:30 . 2009-02-27 01:38 -------- d-----w- c:\documents and settings\Application Data\LimeWire
2009-08-07 03:13 . 2009-02-22 01:38 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-05 09:00 . 2008-04-14 11:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:03 . 2008-04-14 11:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2008-10-01 11:47 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 00:32 . 2009-07-12 00:23 -------- d-----w- c:\documents and settings\Application Data\XLink Kai
2009-07-12 00:23 . 2009-07-12 00:23 36928 ----a-w- c:\windows\system32\drivers\pssdk41.sys
2009-07-11 01:17 . 2009-07-11 01:17 880640 ----a-w- c:\documents and settings\Application Data\Closeinfo\lsdvciwp.exe
2009-07-11 01:15 . 2009-07-11 01:15 -------- d-----w- c:\program files\Crcle Developement
2009-07-11 01:15 . 2009-06-15 01:49 -------- d-----w- c:\program files\Messenger Plus! Live
2009-07-02 21:20 . 2009-01-28 00:57 -------- d-----w- c:\program files\Windows Live
2009-07-01 03:40 . 2009-06-15 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-06-29 15:57 . 2008-08-26 07:11 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:57 . 2008-10-01 11:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:57 . 2008-10-01 11:57 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-18 00:40 . 2009-06-18 00:40 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-16 14:40 . 2008-04-14 11:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2008-04-14 11:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 00:06 . 2009-06-16 00:05 1161576 ----a-w- c:\documents and settings\Mes documents\wlsetup-web.exe
2009-06-15 10:44 . 2008-04-14 11:00 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:44 . 2008-04-14 11:00 82944 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-15 01:49 . 2009-06-15 01:49 5167952 ----a-w- c:\documents and settings\Mes documents\MsgPlusLive-481.exe
2009-06-10 14:14 . 2008-04-14 11:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:21 . 2009-01-28 00:08 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2008-04-14 11:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:12 . 2008-10-30 13:58 1297408 ----a-w- c:\windows\system32\quartz.dll
.
------- Sigcheck -------
[-] 2008-10-30 13:59 361600 E248A8391D7388A0A3679D1FB33E003D c:\windows\system32\drivers\tcpip.sys
[-] 2008-10-01 11:57 1571840 33578A738C564B4F84D906EFD91025E5 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"balm cash"="c:\docume~1\APPLIC~1\CLOSEI~1\Wipe Aim Dale.exe" [2009-08-18 516096]
"Windows Print Spooler"="c:\windows\system\spool\spoolsv.exe" [2009-08-22 365577]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-01-30 1443072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2002-09-12 1101824]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"Win Data Book Sect"="c:\documents and settings\All Users\Application Data\One idol win data\safe trust.exe" [2009-08-25 753664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-06-29 124928]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMMyDocs"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoNetworkConnections"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2009-04-12 9344]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-01-30 34312]
R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2009-04-12 448640]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-01-30 468224]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-07-02 55152]
S3 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [2009-07-11 36928]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-08-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-11632344 - c:\documents and settings\All Users\Application Data\11632344\11632344.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-25 12:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Odette\LOCALS~1\Temp\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'csrss.exe'(3220)
c:\program files\SuperCopier2\SC2Hook.dll
.
Completion time: 2009-08-25 12:46
ComboFix-quarantined-files.txt 2009-08-25 16:46
Pre-Run: 7 646 715 904 octets libres
Post-Run: 8 025 055 232 octets libres
357 --- E O F --- 2009-08-22 19:42