ComboFix 10-10-23.01 - mbultez 24/10/2010 13:30:46.1.2 - x86 DSREPAIR
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2038.1504 [GMT 2:00]
Lancé depuis: c:\documents and settings\mbultez\Bureau\ComboFix.exe
AV: Trend Micro Core Protection Module *On-access scanning enabled* (Updated) {4CA5B9AB-4295-4D4C-9664-0EBE85AE0525}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Flags.dtd
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Local.dtd
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\swUPdate.dll.tmp
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Ui.dtd
c:\documents and settings\mbultez\Application Data\mdbu.bin
c:\documents and settings\mbultez\Application Data\Microsoft\stor.cfg
c:\documents and settings\mbultez\Application Data\Microsoft\svchost.exe
c:\documents and settings\mbultez\Application Data\Microsoft\Windows\shell.exe
c:\documents and settings\mbultez\Application Data\Smart Engine
c:\documents and settings\mbultez\Local Settings\Application Data\36805276.exe
c:\documents and settings\mbultez\Recent\ANTIGEN.exe
c:\documents and settings\mbultez\Recent\cb.dll
c:\documents and settings\mbultez\Recent\cid.exe
c:\documents and settings\mbultez\Recent\CLSV.drv
c:\documents and settings\mbultez\Recent\CLSV.exe
c:\documents and settings\mbultez\Recent\CLSV.sys
c:\documents and settings\mbultez\Recent\ddv.exe
c:\documents and settings\mbultez\Recent\delfile.drv
c:\documents and settings\mbultez\Recent\eb.dll
c:\documents and settings\mbultez\Recent\eb.drv
c:\documents and settings\mbultez\Recent\eb.sys
c:\documents and settings\mbultez\Recent\energy.dll
c:\documents and settings\mbultez\Recent\energy.drv
c:\documents and settings\mbultez\Recent\exec.sys
c:\documents and settings\mbultez\Recent\fix.sys
c:\documents and settings\mbultez\Recent\hymt.exe
c:\documents and settings\mbultez\Recent\pal.exe
c:\documents and settings\mbultez\Recent\PE.exe
c:\documents and settings\mbultez\Recent\PE.tmp
c:\documents and settings\mbultez\Recent\ppal.drv
c:\documents and settings\mbultez\Recent\runddl.dll
c:\documents and settings\mbultez\Recent\runddlkey.tmp
c:\documents and settings\mbultez\Recent\tjd.dll
c:\documents and settings\mbultez\Recent\tjd.drv
c:\documents and settings\mbultez\Recent\tjd.sys
c:\windows\TEMP\pdk-SYSTEM\04a938823668c652aef77ba79a274400\Service.dll
c:\windows\TEMP\pdk-SYSTEM\d6fec475513d165261d38743a490dfc1\perl58.dll
c:\windows\TEMP\pdk-SYSTEM\e00cd61a82f12186df5e4de4b75a822d\Registry.dll
c:\windows\TEMP\pdk-SYSTEM\ea8ed9772b76a525d50cde8448090219\WinError.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SYSDRV32
((((((((((((((((((((((((((((( Fichiers créés du 2010-09-24 au 2010-10-24 ))))))))))))))))))))))))))))))))))))
.
2010-10-24 08:28 . 2010-10-24 10:33 -------- d-----w- c:\program files\ZHPDiag
2010-10-24 07:13 . 2010-10-24 07:13 -------- d-----w- c:\documents and settings\mbultez\Application Data\Malwarebytes
2010-10-24 07:13 . 2010-10-24 07:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-23 19:50 . 2010-10-23 19:50 -------- d-----w- c:\program files\Enigma Software Group
2010-10-23 19:50 . 2010-10-23 20:13 -------- d-----w- c:\windows\9EFA732347A048E28F7735DB5EED500A.TMP
2010-10-23 18:42 . 2010-10-23 18:42 -------- d-sh--w- c:\documents and settings\All Users\Application Data\SMPYEVGSKVE
2010-10-23 18:41 . 2010-10-24 08:21 -------- d-sh--w- c:\documents and settings\All Users\Application Data\30094b
2010-10-20 18:29 . 2010-10-20 18:32 19657194 ----a-w- c:\temp\vlc-1.1.4-win32.exe
2010-10-06 06:43 . 2010-10-06 06:44 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-10-04 06:13 . 2010-10-04 06:13 -------- d-----w- C:\spoolerlogs
2010-09-28 16:40 . 2010-09-28 16:40 865008 ----a-w- c:\program files\Internet Explorer\minftnet.exe
2010-09-28 16:40 . 2010-09-28 16:40 -------- d-----w- c:\documents and settings\mbultez\Application Data\Icones
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-24 07:41 . 2010-08-19 13:28 0 ----a-w- c:\documents and settings\mbultez\Local Settings\Application Data\WavXMapDrive.bat
2010-09-08 09:17 . 2010-09-08 09:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 09:17 . 2010-09-08 09:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-08-19 14:52 . 2010-08-19 14:52 8464 ----a-w- c:\windows\system32\SpOrder.dll
2010-08-19 12:53 . 2010-08-19 09:37 0 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\WavXMapDrive.bat
2006-12-29 14:15 . 2009-12-16 19:27 3100672 ----a-w- c:\program files\Fichiers communs\sapxlhelper.dll
2006-12-29 14:15 . 2009-12-16 19:27 626688 ----a-w- c:\program files\Fichiers communs\sapconsaccess.dll
2006-12-29 14:15 . 2009-12-16 19:27 192512 ----a-w- c:\program files\Fichiers communs\sapconsr3.dll
2006-12-29 14:15 . 2009-12-16 19:27 40960 ----a-w- c:\program files\Fichiers communs\DigitalSignature.ocx
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OfficeScanNT Monitor"="c:\program files\Trend Micro\OfficeScan Client\pccntmon.exe" [2009-10-07 696320]
"SigmatelSysTrayApp"="stsystra.exe" [2007-09-14 405504]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-10 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-10 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-10 137752]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-10 159744]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2007-09-10 92160]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-09-14 218424]
"KADxMain"="c:\windows\system32\KADxMain.exe" [2006-11-02 282624]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-13 59392]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"SODCPreLoad"="c:\program files\Notes65\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090922-1655\preload.exe" [2009-12-17 40960]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2008-05-29 1085440]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-12-21 86016]
"AeXAgentLogon"="c:\program files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2010-03-28 204584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\mbultez\Menu D'marrer\Programmes\D'marrage\
chkntfs.exe [2008-4-13 91136]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-8-19 50688]
Post-it© Software Notes Lite.lnk - c:\program files\3M\PSNLite\PsnLite.exe [2004-10-15 2080768]
TAK-Reader.lnk - c:\program files\TAKReader\TAKReader.exe [2010-9-23 2759680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 13:20 73728 ----a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntivirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\cba\\pds.exe"=
"c:\\WINDOWS\\system32\\msgsys.exe"=
"c:\\Program Files\\LANDesk\\LDClient\\issuser.exe"=
"c:\\Program Files\\LANDesk\\LDClient\\tmcsvc.exe"=
"c:\\Program Files\\Notes65\\framework\\rcp\\eclipse\\plugins\\com.ibm.rcp.base_6.2.1.20090925-1604\\win32\\x86\\notes2.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LANDesk\\Shared Files\\residentagent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"52311:UDP"= 52311:UDP:BES Client
R0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [25/04/2009 01:40 218112]
R0 aac;PERC 320/DC SCSI RAID Miniport Driver;c:\windows\system32\drivers\aac.sys [25/04/2009 01:40 48140]
R0 aarich;aarich;c:\windows\system32\drivers\aarich.sys [25/04/2009 01:40 204800]
R0 megasas;DELL PERC RAID Driver;c:\windows\system32\drivers\megasas.sys [25/04/2009 01:41 19200]
R0 SiSRaid4;SiSRaid4;c:\windows\system32\drivers\sisraid4.sys [25/04/2009 01:41 63872]
R2 BESClientHelper;BESClientHelper;c:\program files\BigFix Enterprise\BES Client\BESClientHelper.exe [19/08/2010 11:47 737367]
R2 CBA8;LANDesk(R) Management Agent;c:\program files\LANDesk\Shared Files\residentAgent.exe [02/06/2008 10:42 155648]
R2 InfonetMonitor;Infonet Monitor Service;c:\program files\Infonet Services Corporation\infonet wireless\WENGINE\wmonitor.exe [23/12/2004 13:24 65604]
R2 JuniperAccessService;Juniper Unified Network Service;c:\program files\Fichiers communs\Juniper Networks\JUNS\dsAccessService.exe [17/03/2010 08:40 132464]
R2 LANDesk Policy Invoker;LANDesk Policy Invoker;c:\program files\LANDesk\LDClient\policy.client.invoker.exe [19/08/2010 16:43 118784]
R2 Lotus Notes Diagnostics;Diagnostics Lotus Notes ;c:\program files\Notes65\nsd.exe [29/09/2009 12:29 3397000]
R2 Softmon;LANDesk(R) Software Monitoring Service;c:\program files\LANDesk\LDClient\SoftMon.exe [19/08/2010 16:43 335872]
R2 TMAdptrSvr;Trend Micro Adapter Service;c:\program files\Trend Micro\Core Protection Module\TMCPMAdapter.exe [07/10/2009 17:56 671744]
R2 TmFilter;Trend Micro Filter;c:\program files\Trend Micro\OfficeScan Client\TmXPFlt.sys [09/02/2009 20:35 230928]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\Trend Micro\OfficeScan Client\tmpreflt.sys [09/02/2009 20:35 36368]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [02/03/2006 14:00 5120]
R3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [01/11/2004 15:16 17536]
R3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [02/11/2006 12:32 97536]
R3 ldblank;Screen Blanking driver for Remote Control;c:\windows\system32\drivers\ldblank.sys [19/08/2010 16:43 11904]
R3 ldmirror;ldmirror;c:\windows\system32\drivers\ldmirror.sys [19/08/2010 16:43 3328]
R3 mirrorflt;Mirror Filter Driver for Uninstall;c:\windows\system32\drivers\mirrorflt.sys [19/08/2010 16:43 3712]
S0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys --> c:\windows\system32\drivers\vmscsi.sys [?]
S3 AltirisAgentProvider;AltirisAgentProvider;c:\program files\Altiris\Altiris Agent\Agents\WMIProviderAgent\AltirisAgentProvider.exe [31/08/2010 19:54 614400]
S3 esgiguard;esgiguard;\??\c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys --> c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [?]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [19/08/2010 11:39 45534]
S3 TAK2PL;Pilote Puits de déchargement TakFlash;c:\windows\system32\drivers\TAK2PL.sys [23/09/2010 08:03 42752]
S3 TmProxy;OfficeScan NT Proxy Service;c:\program files\Trend Micro\OfficeScan Client\TmProxy.exe [09/02/2009 20:34 689416]
S3 USB TAKCardReader;USB TAKCardReader;c:\windows\system32\drivers\TAKCR2K.sys [23/09/2010 08:03 47215]
.
Contenu du dossier 'Tâches planifiées'
2010-10-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/portail
uInternet Settings,ProxyServer = http=127.0.0.1:50370
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
.
.
------- Associations de fichier -------
.
.scr=DWGTrueViewScriptFile
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-10-24 13:38
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(1120)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
- - - - - - - > 'explorer.exe'(3704)
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
c:\windows\system32\wpdshext.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\SCardSvr.exe
c:\program files\Altiris\Altiris Agent\aexnsagent.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\BigFix Enterprise\BES Client\BESClient.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\LANDesk\LDClient\LocalSch.EXE
c:\windows\system32\CBA\pds.exe
c:\program files\LANDesk\LDClient\tmcsvc.exe
c:\program files\LANDesk\LDClient\policy.sync.exe
c:\program files\LANDesk\LDClient\vulScan.exe
c:\program files\LANDesk\LDClient\LDIScn32.EXE
c:\progra~1\LANDesk\LDClient\collector.exe
c:\progra~1\LANDesk\LDClient\issuser.exe
c:\program files\LANDesk\Shared Files\serviceHost.exe
c:\program files\LANDesk\LDClient\ldapplpcgi.exe
c:\program files\LANDesk\LDClient\ldiscnupdate.exe
c:\program files\Notes65\ntmulti.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Trend Micro\OfficeScan Client\ntrtscan.exe
c:\windows\system32\StacSV.exe
c:\program files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
c:\program files\BigFix Enterprise\BES Client\BESClientUI.exe
c:\program files\Trend Micro\OfficeScan Client\tmlisten.exe
c:\progra~1\LANDesk\LDClient\rcgui.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Altiris\Altiris Agent\AeXAgentUIHost.exe
c:\windows\TEMP\PH6DDB.EXE
c:\program files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe
c:\program files\LANDesk\Shared Files\proxyhost.exe
c:\program files\LANDesk\Shared Files\proxyhost.exe
c:\program files\LANDesk\Shared Files\proxyhost.exe
c:\program files\LANDesk\Shared Files\proxyhost.exe
.
**************************************************************************
.
Heure de fin: 2010-10-24 13:43:23 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-10-24 11:43
Avant-CF: 43 608 686 592 octets libres
Après-CF: 44 006 629 376 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect /safeboot:dsrepair /noguiboot /bootlog
- - End Of File - - 87DAE744F400BEC2E339F96AB6CA1669