ComboFix 08-01-03.3 - mickael morin 2008-01-02 22:10:26.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.61 [GMT 1:00]
Running from: C:\Documents and Settings\mickael morin\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\WINDOWS\pack.epk
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-03 to 2008-01-03 ))))))))))))))))))))))))))))))))))))
.
2008-01-01 21:44 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-01 21:44 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-01 21:44 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-01 21:44 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-01 21:44 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-01 21:44 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-01 21:44 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-01 21:44 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-01 21:13 . 2008-01-01 21:13 <REP> d-------- C:\Program Files\Yahoo!
2008-01-01 21:11 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-28 22:29 . 2007-12-28 22:29 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-28 17:32 . 2007-12-28 17:32 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2007-12-28 17:18 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-28 16:32 . 2007-12-28 16:32 <REP> d-------- C:\VundoFix Backups
2007-12-28 16:04 . 2007-12-28 16:07 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2007-12-28 15:09 . 2007-12-28 15:09 <REP> d-------- C:\Program Files\DivX
2007-12-28 11:42 . 2007-12-28 11:42 <REP> d-------- C:\Program Files\Trend Micro
2007-12-16 19:10 . 2007-12-16 19:10 <REP> d-------- C:\WINDOWS\system32\PC Booster 5
2007-12-16 12:16 . 2007-12-16 12:16 <REP> d-------- C:\Documents and Settings\mickael morin\Application Data\Internet Download Accelerator
2007-12-16 12:15 . 2007-12-16 17:04 <REP> d-------- C:\Program Files\IDA
2007-12-16 11:38 . 2007-12-16 11:38 <REP> d-------- C:\WINDOWS\Sun
2007-12-08 23:56 . 2007-12-09 00:04 <REP> d-------- C:\tmpDownload
2007-12-08 23:56 . 2007-12-09 00:07 <REP> d-------- C:\Program Files\YoutubeGet
2007-12-08 23:56 . 2007-12-09 00:03 5 --a------ C:\WINDOWS\youtubex.dll
2007-12-06 22:44 . 2007-12-06 22:57 <REP> d-------- C:\Documents and Settings\mickael morin\Application Data\SecondLife
2007-12-03 12:32 . 2007-12-03 12:32 <REP> d-------- C:\WINDOWS\system32\Viewers
2007-12-03 12:31 . 2007-12-03 12:32 <REP> d-------- C:\Program Files\MSWorks
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-01 17:04 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\LimeWire
2008-01-01 08:02 --------- d-----w C:\Program Files\Google
2007-12-18 15:19 80,097 ----a-w C:\WINDOWS\system32\dcads-remove.exe
2007-12-16 18:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-16 18:19 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-12-09 20:31 19,456 ----a-w C:\WINDOWS\system32\drivers\jnhliqdo.dat
2007-12-08 21:56 --------- d-----w C:\Program Files\eMule
2007-12-01 22:17 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\DefenseNetSurfage
2007-12-01 22:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\DefenseNetSurfage
2007-11-30 21:54 --------- d-----w C:\Program Files\Morpheus
2007-11-30 05:24 --------- d-----w C:\Program Files\Fichiers communs\DefenseNetSurfage
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-25 05:43 --------- d-----w C:\Program Files\RegistrySmart
2007-11-25 05:19 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\RegistrySmart
2007-11-24 17:27 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\MSN6
2007-11-24 16:52 --------- d-----w C:\Program Files\ReparateurDeSysteme
2007-11-24 15:15 --------- d-----w C:\Program Files\Fichiers communs\ReparateurDeSysteme
2007-11-24 15:15 --------- d-----r C:\Documents and Settings\All Users\Application Data\reparateurdesysteme
2007-11-23 09:56 40,731 ----a-w C:\WINDOWS\system32\superiorads-uninst.exe
2007-11-23 09:55 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\Dcads Advanced Toolbar
2007-11-23 09:35 --------- d-----w C:\Program Files\Dcads Advanced Toolbar
2007-11-22 11:57 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-11-21 21:00 --------- d-----w C:\Program Files\Alwil Software
2007-11-17 17:03 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\TeamViewer
2007-11-17 13:49 --------- d-----w C:\Program Files\MorpheusBar
2007-11-17 13:30 --------- d-----w C:\Program Files\LimeWire
2007-11-17 13:30 --------- d-----w C:\Program Files\Java
2007-11-17 13:29 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-11-17 12:57 --------- d-----w C:\Program Files\MSN Messenger
2007-11-17 12:54 --------- d-----w C:\Program Files\VideoLAN
2007-11-17 12:54 --------- d-----w C:\Documents and Settings\mickael morin\Application Data\vlc
2007-11-17 12:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSN6
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 09:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-17 17:23 10,752 ----a-w C:\WINDOWS\system32\WhoisCL.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C62C5E2-CFBF-4E9E-8ECF-FDFA81B9A927}]
2004-08-19 15:09 93952 --a------ C:\WINDOWS\system32\dinpu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F173E53F-E042-49b6-BD46-983E93DA1B17}]
C:\WINDOWS\system32\nse376.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{41C29B07-6F91-4966-91BE-2E2841643C83}
{DB87BFA2-A2E3-451E-8E5A-C89982D87CBF}
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[HKEY_CLASSES_ROOT\clsid\{41c29b07-6f91-4966-91be-2e2841643c83}]
[HKEY_CLASSES_ROOT\CoolToolBar.IEBarLogic.1]
[HKEY_CLASSES_ROOT\TypeLib\{6B4FA1DD-A353-49F8-A650-79C21D6B4824}]
[HKEY_CLASSES_ROOT\CoolToolBar.IEBarLogic]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-01-31 15:49 98304]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 15:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-01-24 20:00 315392]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 10:59 88107 C:\WINDOWS\AGRSMMSG.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"Salestart"="C:\Program Files\Fichiers communs\ReparateurDeSysteme\strpmon.exe" [2007-11-12 19:44 424960]
"Salestart(1)"="C:\Program Files\Fichiers communs\DefenseNetSurfage\mc.exe" [2007-11-07 18:12 429056]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Run Google Web Accelerator.lnk - C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 22:24:38]
R0 udzdqlog;udzdqlog;C:\WINDOWS\system32\drivers\jnhliqdo.dat []
R1 MFKGTKEY;MFKGTKEY;C:\WINDOWS\system32\drivers\mfkgtkey.sys [2003-03-26 13:29]
S3 ALiIRDA;Pilote de périphérique infrarouge ALi;C:\WINDOWS\system32\DRIVERS\alifir.sys [2001-08-17 21:49]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-25 05:19:31 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
- C:\Program Files\RegistrySmart\RegistrySmart.exe
- C:\Program Files\RegistrySmart
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-03 22:15:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-03 22:16:57
ComboFix-quarantined-files.txt 2008-01-03 21:16:24
.
2007-12-21 16:34:34 --- E O F ---