ComboFix 07-08-14.4 - "utilisation" 2007-08-19 17:30:20.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.1479 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((( Files Created from 2007-07-19 to 2007-08-19 )))))))))))))))))))))))))))))))
2007-08-19 17:29 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-19 17:02 <REP> d-------- C:\WINDOWS\ERUNT
2007-08-19 16:23 3,804 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-19 16:22 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-08-19 16:22 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-19 16:22 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-08-19 15:58 3,290 --a------ C:\WINDOWS\system32\gnc.exe
2007-08-19 14:39 <REP> d-------- C:\hijackthis
2007-08-19 14:23 <REP> d-------- C:\VundoFix Backups
2007-08-19 10:31 <REP> d-------- C:\Program Files\Navilog1
2007-08-19 09:21 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-19 09:06 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-19 09:05 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-08-19 09:05 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-08-19 09:05 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-08-19 09:05 54,672 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-08-19 09:05 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2007-08-19 09:05 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-08-19 09:05 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2007-08-19 09:05 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2007-08-19 09:05 143,392 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-19 09:05 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys
2007-08-19 09:05 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-08-19 09:05 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-08-19 09:05 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-08-19 09:03 <REP> d-------- C:\WINDOWS\Internet Logs
2007-08-04 18:52 <REP> d-------- C:\Program Files\MSXML 6.0
2007-08-04 18:50 <REP> d-------- C:\Program Files\MSBuild
2007-08-04 18:47 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2007-08-04 18:46 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-08-04 18:46 <REP> d-------- C:\Program Files\Reference Assemblies
2007-08-04 18:46 <REP> d-------- C:\9cb816daf0c1aeeefe38bcc82b
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-19 11:15 2756 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a--c--- C:\WINDOWS\system32\AVASTSS.scr
2007-07-18 06:18 --------- d-------- C:\DOCUME~1\UTILIS~1\APPLIC~1\U3
2007-07-16 17:55 65024 --a------ C:\WINDOWS\IFinst26.exe
2007-07-16 17:55 --------- d-------- C:\Program Files\Lame MP3 Codec
2007-07-16 17:54 --------- d-------- C:\Program Files\Samsung
2007-07-16 17:54 --------- d-------- C:\Program Files\MarkAny
2007-07-16 17:54 --------- d-------- C:\DOCUME~1\UTILIS~1\APPLIC~1\DataCast
2007-07-16 17:53 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-16 17:53 --------- d-------- C:\DOCUME~1\UTILIS~1\APPLIC~1\InstallShield
2007-07-13 22:52 --------- d-------- C:\Program Files\eMule
2007-07-12 09:41 --------- d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-06-28 17:11 267776 --a------ C:\WINDOWS\system32\uulnno.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 17:07 C:\WINDOWS\system32\HdAShCut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-25 16:25]
"RTHDCPL"="RTHDCPL.EXE" [2006-02-27 18:28 C:\WINDOWS\RTHDCPL.EXE]
"Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2002-07-18 18:36]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-12-02 08:38]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2007-07-28 00:03]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-02-23 16:32]
"MAAgent"="C:\Program Files\MarkAny\ContentSafer\MAAgent.exe" [2007-01-30 20:36]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]
C:\Documents and Settings\utilisation\Menu D‚marrer\Programmes\D‚marrage\
Moniteur & Configuration.lnk - C:\Program Files\802.11 Wireless LAN\WlanMonitor.exe [2003-10-01 15:27:44]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - C:\Program Files\Belkin\Bluetooth Software\BTTray.exe [2006-06-07 18:05:38]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
WinManager.lnk - C:\Program Files\Fujitsu Siemens\WinManager\WinManager.exe [2007-01-16 14:00:27]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\ContentSafer\MACSMANAGER.dll [2004-11-23 16:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Firefox]
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
R0 SiSRaid2;SiSRaid2;C:\WINDOWS\system32\drivers\SiSRaid2.sys
R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys
S3 ATMELFVNETusb(AR)(R);ATMEL FVNETusb(AR)(R) Service for ATMEL USB FastVNET (AR);C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S3 MOD3700;XM400I Analog/DVB-T;C:\WINDOWS\system32\Drivers\xm400i.sys
S3 UDTT2BDA;DTV-DVB USB2 DVB-T receiver;C:\WINDOWS\system32\Drivers\UDTT2BDA.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7fc1c8f3-cc83-11db-9a0b-00030d4280f4}]
AutoRun\command- E:\instapls.exe /AUTORUN
configure\command- E:\instapls.exe
install\command- E:\instapls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d03c5a6b-1fa0-11db-9d25-00030d4280f4}]
AutoRun\command- E:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d03c5a6c-1fa0-11db-9d25-00030d4280f4}]
AutoRun\command- G:\setupSNK.exe
Contents of the 'Scheduled Tasks' folder
2007-07-13 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job - C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
2007-08-19 15:28:59 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-19 17:32:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-19 17:32:54
--- E O F ---