ComboFix 07-08-30.3 - "Benjamin" 2007-08-30 22:04:07.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.199 [GMT 2:00]
((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-30 )))))))))))))))))))))))))))))))
2007-08-30 22:03 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-29 19:34 <REP> d-------- C:\Program Files\RealMedia
2007-08-29 19:34 <REP> d-------- C:\Program Files\OpenSource Flash Video Splitter
2007-08-29 19:34 <REP> d-------- C:\Program Files\DScaler5
2007-08-29 19:34 <REP> d-------- C:\Program Files\CD Audio Reader Filter
2007-08-29 19:33 10,752 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-08-29 19:33 <REP> d-------- C:\Program Files\SHOUTcast Source
2007-08-29 19:33 <REP> d-------- C:\Program Files\ffdshow
2007-08-29 19:33 <REP> d-------- C:\Program Files\DS-MP3 Source
2007-08-29 19:32 <REP> d-------- C:\Program Files\Zoom Player
2007-08-29 19:32 <REP> d-------- C:\Program Files\DirectVobSub
2007-08-28 20:43 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-08-28 20:43 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-28 20:43 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-08-28 20:43 1,826 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-28 19:45 3,290 --a------ C:\WINDOWS\system32\gnc.exe
2007-08-28 00:22 <REP> d-------- C:\WINDOWS\system32\Rawflow
2007-08-28 00:22 <REP> d-------- C:\Program Files\RawFlow
2007-08-25 01:03 <REP> d-------- C:\Program Files\StuffPlug3
2007-08-24 01:43 <REP> dr------- D:\DOCUME~1\ADMINI~1.000\Mes documents
2007-08-24 01:43 <REP> dr------- D:\DOCUME~1\ADMINI~1.000\Menu D‚marrer
2007-08-24 01:43 <REP> dr------- D:\DOCUME~1\ADMINI~1.000\Favoris
2007-08-24 01:43 <REP> dr------- D:\DOCUME~1\ADMINI~1.000\Bureau
2007-08-24 01:43 <REP> d--h----- D:\DOCUME~1\ADMINI~1.000\Voisinage r‚seau
2007-08-24 01:43 <REP> d--h----- D:\DOCUME~1\ADMINI~1.000\Voisinage d'impression
2007-08-24 01:43 <REP> d--h----- D:\DOCUME~1\ADMINI~1.000\ModŠles
2007-08-23 21:44 <REP> d-------- C:\Program Files\KiddiesBarre
2007-08-20 14:00 <REP> d-------- C:\UT2004
2007-08-18 20:47 <REP> d-------- C:\Program Files\WowCartographe
2007-08-15 17:11 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\fretsonfire
2007-08-15 17:11 <REP> d-------- C:\Program Files\Frets on Fire
2007-08-14 22:17 <REP> d-------- C:\Program Files\Navilog1
2007-08-14 01:22 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-08-14 01:22 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-08-14 01:22 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-08-14 01:22 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-08-14 01:22 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-14 01:22 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-08-14 01:21 783,224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-08-12 17:28 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-08-11 23:55 4 --a------ C:\WINDOWS\info147.sys
2007-08-06 21:46 <REP> d-------- C:\WINDOWS\Darluok Patch World of Warcraft
2007-08-05 14:30 <REP> d-------- C:\Program Files\Fichiers communs\Blizzard Entertainment
2007-08-04 13:30 <REP> d-------- C:\WINDOWS\Club-Internet
2007-07-31 21:34 <REP> d-------- C:\Program Files\CpuZ
2007-07-31 02:14 <REP> d-------- C:\Program Files\a-squared Free
2007-07-29 23:12 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\BitTorrent
2007-07-27 01:06 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-07-27 01:06 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-07-27 01:06 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-07-27 01:06 144,704 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-07-27 01:06 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-07-27 00:12 <REP> d-------- C:\Program Files\ATITool
2007-07-26 15:19 <REP> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\POP3Profiles
2007-07-22 22:45 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-07-22 22:45 42,648 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2007-07-22 22:45 22,168 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2007-07-22 22:45 18,072 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2007-07-22 22:44 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-07-21 13:03 <REP> d--hs---- C:\found.001
2007-07-21 10:45 <REP> d-------- C:\Program Files\iTunes
2007-07-21 10:45 <REP> d-------- C:\Program Files\iPod
2007-07-21 10:40 <REP> d-------- C:\Program Files\QuickTime
2007-07-19 12:51 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\teamspeak2
2007-07-19 12:50 <REP> d-------- C:\Program Files\Teamspeak2_RC2
2007-07-17 21:05 <REP> d-------- D:\DOCUME~1\Laurent\APPLIC~1\vlc
2007-07-17 21:05 <REP> d-------- D:\DOCUME~1\Laurent\APPLIC~1\DivX
2007-07-17 21:02 <REP> d-------- D:\DOCUME~1\Laurent\APPLIC~1\MEGAUPLOADTOOLBAR
2007-07-16 15:52 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\WNR
2007-07-16 02:01 <REP> d-------- C:\Downloads
2007-07-16 00:59 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\Megaupload
2007-07-16 00:58 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\MegauploadToolbar
2007-07-16 00:58 <REP> d-------- C:\Program Files\Megaupload
2007-07-15 23:26 <REP> d--hs---- C:\found.000
2007-07-10 11:28 <REP> d-------- C:\Program Files\SpeedFan
2007-07-09 02:45 <REP> d-------- C:\Program Files\Ray Adams
2007-07-08 22:12 <REP> d-------- C:\Program Files\Hmonitor
2007-07-07 19:06 <REP> d-------- C:\Program Files\Rapidown
2007-07-07 16:03 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-07-07 15:47 <REP> d-------- C:\Program Files\ElcomSoft
2007-07-07 10:05 <REP> d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-07 10:05 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2007-07-06 02:36 54,784 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-07-06 02:33 6,128 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-07-06 02:32 <REP> d-------- C:\WINDOWS\BricoPacks
2007-07-02 02:35 20,992 --a------ C:\WINDOWS\jestertb.dll
2007-07-02 02:34 <REP> d-------- C:\Program Files\Primedius
2007-07-02 02:25 <REP> d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\Tor
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-30 22:06 --------- d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\Free Download Manager
2007-08-30 20:34 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-29 19:37 --------- d-------- C:\Program Files\DivX
2007-08-28 22:14 --------- d-------- C:\Program Files\AV Vcs 4.0 DIAMOND
2007-08-25 12:47 --------- d-------- C:\Program Files\Winamp
2007-08-25 12:45 --------- d-------- C:\Program Files\Windows Live Safety Center
2007-08-25 01:03 --------- d-------- C:\Program Files\MSN Messenger
2007-08-14 01:15 --------- d-------- C:\Program Files\Lavasoft
2007-08-14 01:15 --------- d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-27 01:06 43528 --------- C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-07-27 01:06 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-07-27 01:06 120056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-07-27 01:06 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-07-27 01:03 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-07-27 01:03 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-07-27 01:03 81920 --a------ C:\WINDOWS\system32\dpl100.dll
2007-07-27 01:03 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-07-27 01:03 740442 --a------ C:\WINDOWS\system32\DivX.dll
2007-07-27 01:03 593920 --a------ C:\WINDOWS\system32\dpuGUI11.dll
2007-07-27 01:03 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-07-27 01:03 53248 --a------ C:\WINDOWS\system32\dpuGUI10.dll
2007-07-27 01:03 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-07-27 01:03 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-07-27 01:03 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-07-27 01:03 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-07-27 01:03 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-26 15:16 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-23 12:49 --------- d-------- D:\DOCUME~1\ALLUSE~1\APPLIC~1\Chintransregsglobal
2007-07-19 08:58 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-14 19:46 --------- d-------- C:\Program Files\RamBoost XP
2007-07-13 01:30 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-12 21:59 --------- d-------- D:\DOCUME~1\BENJAM~1.000\APPLIC~1\DivX
2007-07-07 16:12 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2007-07-06 02:36 219648 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-06-30 20:09 --------- d-------- C:\Program Files\Realtek AC97
2007-06-30 13:48 33952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-06-29 13:19 74752 --a------ C:\WINDOWS\ST6UNST.EXE
2007-06-29 13:19 253952 --------- C:\WINDOWS\Setup1.exe
2007-06-27 15:24 823808 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 15:24 671232 --------- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 15:24 477696 --------- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 15:24 232960 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 15:24 193024 --------- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 15:24 1152000 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 15:24 105984 --a------ C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 15:24 102400 --a------ C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 15:23 6058496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 15:23 52224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 15:23 459264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 15:23 44544 --------- C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 15:23 27648 --------- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 15:23 267776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 15:22 384512 --------- C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 15:22 383488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 15:22 230400 --------- C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 15:22 153088 --------- C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 15:22 132608 --------- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 15:22 124928 --------- C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 10:28 625152 --------- C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 10:27 63488 --------- C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 10:27 13824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 09:00 161792 --------- C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 08:09 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:09 1104896 --------- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 15:32 282112 --------- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-17 14:48 108144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-06-13 15:22 1037312 --a------ C:\WINDOWS\explorer.exe
2007-06-13 15:22 1037312 --------- C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-11 23:51 10834944 --a------ C:\WINDOWS\system32\dllcache\wmp.dll
2007-02-24 22:31 47360 --a------ D:\DOCUME~1\BENJAM~1.000\APPLIC~1\pcouffin.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 15:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 15:00]
"NECHotkey"="mHotkey.exe" [2006-01-11 11:29 C:\WINDOWS\mHotkey.exe]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Detect"=C:\Program Files\iNTERNET Turbo\iDetect.exe /auto
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R0 SI3112r;ATI-437A Serial ATA Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys
R1 ATITool;ATITool Overclocking Utility;C:\WINDOWS\system32\DRIVERS\ATITool.sys
R1 oreans32;oreans32;\??\C:\WINDOWS\system32\drivers\oreans32.sys
R3 ovt519;Eye Toy;C:\WINDOWS\system32\Drivers\ov519vid.sys
S1 atitray;atitray;\??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys
S1 hmonitor;hmonitor;\??\C:\WINDOWS\system32\drivers\hmonitor.sys
S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
S3 AEXPAM;Philips SmartManage Service;C:\WINDOWS\system32\Drivers\aexpamdrv.sys
S3 AMDPCI;AMDPCI;\??\D:\DOCUME~1\BENJAM~1.000\LOCALS~1\Temp\AMDPCI.sys
S3 driverhardwarev2;driverhardwarev2;\??\C:\Program Files\HardwareDetection\driverhardwarev2.sys
S3 krn32;krn32;\??\C:\Downloads\krn32.sys
S3 nocashio;nocashio;C:\WINDOWS\system32\drivers\nocashio.sys
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys
S3 RaBiT;RaBiT;\??\C:\Downloads\RaBiT.v2.0a\RaBiT.sys
S3 SANDRA;SANDRA;\??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP2\Sandra.sys
*Newly Created Service* - CATCHME
Contents of the 'Scheduled Tasks' folder
2007-08-18 06:30:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-30 17:30:00 C:\WINDOWS\Tasks\Configurer mon PC.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-30 22:06:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-30 22:07:41
C:\ComboFix-quarantined-files.txt ... 2007-08-30 22:07
--- E O F ---
merci duflox de ton aide
Configuration: Windows XP
Firefox 2.0.0.4