ComboFix 07-11-19.4 - ANNA 2007-11-27 0:28:51.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.237 [GMT 1:00]
Running from: C:\Documents and Settings\ANNA\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-26 to 2007-11-26 ))))))))))))))))))))))))))))))))))))
.
2007-11-26 23:29 467,632 --a------ C:\WINDOWS\system32\perfh040.dat
2007-11-26 23:29 74,326 --a------ C:\WINDOWS\system32\perfc040.dat
2007-11-26 21:40 <REP> d-------- C:\VundoFix Backups
2007-11-26 20:39 <REP> d-------- C:\Program Files\Trend Micro
2007-11-26 17:09 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-26 17:09 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-26 17:09 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-26 17:09 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-11-26 17:08 <REP> d-------- C:\Program Files\Spyware Doctor
2007-11-26 13:06 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-11-26 11:12 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-11-26 08:10 1,168,955 ---hs---- C:\WINDOWS\system32\yehctblc.ini
2007-11-26 08:07 <REP> d-------- C:\WINDOWS\system32\tnrtmwuk
2007-11-25 00:47 <REP> d-------- C:\WINDOWS\AU_Temp
2007-11-24 14:01 1,352,957 ---hs---- C:\WINDOWS\system32\hnhkavvt.ini
2007-11-24 13:58 81,472 --a------ C:\WINDOWS\system32\ilsqvvyi.dll
2007-11-22 17:22 79,936 --a------ C:\WINDOWS\system32\murnqpsp.dll
2007-11-22 17:18 1,004,368 ---hs---- C:\WINDOWS\system32\pgykbnbu.ini
2007-11-22 17:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-18 18:58 79,424 --a------ C:\WINDOWS\system32\ydsrbxvb.dll
2007-11-18 18:55 737,138 ---hs---- C:\WINDOWS\system32\niojyxbp.ini
2007-11-12 18:21 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-11-12 18:21 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-11-12 18:21 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-11-12 18:21 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-11-12 18:21 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-11-12 18:21 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-11-12 18:21 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-11-12 14:51 582,995 ---hs---- C:\WINDOWS\system32\qkbqbdcs.ini
2007-11-12 14:44 81,472 --a------ C:\WINDOWS\system32\soxeqqrx.dll
2007-11-12 13:54 <REP> d-------- C:\Program Files\Runtime Software
2007-11-12 10:56 1,024 --a------ C:\WINDOWS\system32\drivers\DCF1518D-AE04-44E5-A398-2B2579435BD4.cxv
2007-11-12 10:38 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-11-12 10:22 10,240 --a------ C:\WINDOWS\system32\drivers\63C1D9DE-045B-4F3E-A220-8CAB6453DA8F.cxv
2007-11-12 10:18 <REP> d-------- C:\Program Files\STOPzilla!
2007-11-12 10:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\STOPzilla!
2007-11-12 02:34 2,432 --a------ C:\WINDOWS\system32\unpr.sys
2007-11-12 02:34 353 ---hs---- C:\WINDOWS\system32\xxyxx.ini
2007-11-12 02:29 <REP> d-------- C:\WINDOWS\system32\bfeguufo
2007-11-12 02:29 <REP> d-------- C:\Program Files\rexunuxy
2007-11-12 02:21 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-11-12 01:39 <REP> d-------- C:\Documents and Settings\ANNA\Application Data\PC Tools
2007-11-10 02:36 <REP> d-------- C:\Program Files\RegCleaner
2007-11-10 02:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-11-10 01:22 <REP> d-------- C:\Documents and Settings\ANNA\Application Data\MSNInstaller
2007-11-10 01:14 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-11-10 01:03 <REP> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-11-10 00:39 <REP> d-------- C:\Program Files\Windows Live
2007-11-10 00:39 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-10 00:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-09 01:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-09 00:32 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-11-09 00:32 267,845 --a------ C:\WINDOWS\tsc.exe
2007-11-09 00:32 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-11-09 00:32 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-11-09 00:31 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-11-09 00:31 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-11-09 00:31 69,689 --a------ C:\WINDOWS\UNZIP.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-26 23:21 --------- d-----w C:\Program Files\PestPatrol
2007-11-26 23:20 --------- d-----w C:\Program Files\Wanadoo
2007-11-26 19:31 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-26 16:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-26 16:01 --------- d-----w C:\Program Files\Google
2007-11-26 07:26 --------- d-----w C:\Program Files\Hijackthis Version Française
2007-11-22 15:59 --------- d-----w C:\Documents and Settings\ANNA\Application Data\uTorrent
2007-11-22 15:48 --------- d-----w C:\Program Files\LogProtect
2007-11-12 21:35 --------- d-----w C:\Program Files\eMule
2007-11-12 20:56 --------- d-----w C:\Program Files\a-squared Free
2007-11-12 18:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-12 18:26 --------- d-----w C:\Program Files\Ontrack
2007-11-12 12:54 --------- d-----w C:\Program Files\PowerArchiver
2007-11-12 11:06 --------- d-----w C:\Program Files\Ahead
2007-11-12 11:06 --------- d-----w C:\Documents and Settings\ANNA\Application Data\Ahead
2007-11-12 10:10 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2007-11-11 23:53 46,080 ----a-w C:\WINDOWS\system32\ftp.exe
2007-11-10 00:55 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-11-10 00:43 --------- d-----w C:\Program Files\MSN Messenger
2007-11-09 23:33 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-08 17:00 --------- d-----w C:\Program Files\Macrogaming
2007-11-08 15:09 --------- d-----w C:\Program Files\Fichiers communs\Sandlot Shared
2007-10-25 17:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 17:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 17:01 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 16:58 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-25 16:24 815,480 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-10-25 16:14 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-08 20:52 --------- d-----w C:\Program Files\Wizards of the Coast
2007-09-14 08:37 45,192 ----a-w C:\WINDOWS\system32\MsgPlusLoader.dll
2006-04-19 21:41 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((( snapshot@2007-11-26_23.23.53,98 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-26 16:10:28 61,476 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-26 23:25:12 61,476 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-26 16:10:28 401,932 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-26 23:25:12 401,932 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-11-26 21:06:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_534.dat
+ 2007-11-26 23:19:39 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_534.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{22b86299-7d7b-42fa-915c-3aa7dd2914ed}]
C:\WINDOWS\system32\jxcbeynb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2C45DAA2-2ABF-4D05-A606-D4A85AE2074E}]
C:\WINDOWS\system32\efecd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7690710C-1A33-4D05-B860-1730FE652B77}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B83082CA-29DB-4B4D-BA3A-E2BD0902DA7A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B98B4120-018E-4C17-9496-7705DE0F1216}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="C:\Program Files\ATI Multimedia\main\LaunchPd.exe" [2002-05-02 09:57]
"EPSON Stylus Photo R300 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.exe" [2003-09-11 04:00]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 13:50]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:54]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 21:41]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"WINSOS VERIFY"="C:\Program Files\Winsos\WINSOS.exe" []
"Ptei"="C:\PROGRA~1\SMANTE~1\attrib.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-03-23 17:06]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"C-Media Mixer"="Mixer.exe" [2001-12-07 16:24 C:\WINDOWS\Mixer.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-08-14 17:29]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54]
"EPSON Stylus Photo R300 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.exe" [2003-09-11 04:00]
"PPMemCheck"="C:\PROGRA~1\PESTPA~1\PPMemCheck.exe" [2003-08-05 09:11]
"PestPatrol Control Center"="C:\Program Files\PESTPA~1\PPControl.exe" [2003-08-05 09:11]
"CookiePatrol"="C:\PROGRA~1\PESTPA~1\CookiePatrol.exe" [2003-08-05 09:11]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 03:10]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2006-06-09 01:17]
C:\Documents and Settings\ANNA\Menu D‚marrer\Programmes\D‚marrage\
PPControl.lnk - C:\Documents and Settings\ANNA\Application Data\Microsoft\Installer\{FA1B3B7A-98D0-4F54-B555-7711A6E54544}\IconFA1B3B7A.exe [2005-03-23 00:49:53]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-13 01:44:38]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\guscwddl]
guscwddl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qhrwmgwr]
qhrwmgwr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyawvu]
xxyawvu.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWA6PV_0001_N91M2107]
C:\DOCUME~1\ANNA\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\O9GJSB8B\WinAntiVirusPro2006FreeInstall_fr
[1].exe -nag
R0 UNPR;UNPR;C:\WINDOWS\system32\unpr.sys
R1 VIAPFD;VIAPFD;C:\WINDOWS\system32\Drivers\VIAPFD.SYS
R3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys
S2 CINEMSUP;Software Cinemaster NT4.0 Driver;C:\WINDOWS\system32\DRIVERS\CINEMSUP.SYS
S3 AX88172;ASIX AX88172 USB2 to Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\ax88172.sys
S3 oUltraf;oUltraf;\??\C:\DOCUME~1\ANNA\LOCALS~1\Temp\oUltraf.sys
S3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys
S3 RescueDrv;Inventel Access Point USB Rescue Driver;C:\WINDOWS\system32\Drivers\resc_dwb.sys
S3 USBSHGX;SHARP GSM GPRS USB Driver 2.1.0;C:\WINDOWS\system32\DRIVERS\usbgx_2.sys
S3 viafilter;VIA USB Filter;C:\WINDOWS\system32\Drivers\viausb1.sys
S3 wanusb;ECI Telecom USB ADSL WAN Modem;C:\WINDOWS\system32\DRIVERS\gwausb.sys
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-26 23:00:00 C:\WINDOWS\Tasks\AF9263E490021B9C.job"
- c:\docume~1\anna\applic~1\inside~1\meow 4 view.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-27 00:32:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-11-27 0:33:44
.
--- E O F ---