ComboFix 08-03-01.3 - Catherine 2008-03-02 15:49:52.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.205 [GMT 1:00]
Endroit: C:\Documents and Settings\Catherine\Bureau\Eradication Virus Février 2008\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Catherine\Application Data\DriveCleaner 2006 Free
C:\Documents and Settings\Catherine\Application Data\DriveCleaner 2006 Free\Logs\update.log
C:\Documents and Settings\Catherine\Application Data\macromedia\Flash Player\#SharedObjects\F8VNAVQE\www.broadcaster.com
C:\Documents and Settings\Catherine\Application Data\macromedia\Flash Player\#SharedObjects\F8VNAVQE\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Catherine\Application Data\macromedia\Flash Player\#SharedObjects\F8VNAVQE\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Catherine\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Catherine\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Catherine\err.log
C:\Documents and Settings\Catherine\Menu Démarrer\Programmes\Démarrage\TA_Start.lnk
C:\Documents and Settings\Catherine\Menu Démarrer\Programmes\Démarrage\think-adz.lnk
C:\WA6P
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\zxdnt3d.cfg
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FOPN
-------\LEGACY_VSPF
-------\LEGACY_VSPF_HK
((((((((((((((((((((((((((((( Fichiers créés 2008-02-02 to 2008-03-02 ))))))))))))))))))))))))))))))))))))
.
2008-02-28 00:32 . 2008-02-28 00:58 <REP> d-------- C:\Program Files\Navilog1
2008-02-28 00:13 . 2008-02-28 00:13 <REP> d-------- C:\Program Files\Trend Micro
2008-02-18 22:06 . 2008-02-18 22:06 <REP> d-------- C:\Program Files\Songbeat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-02 14:59 --------- d-----w C:\Documents and Settings\Catherine\Application Data\AVG7
2008-03-02 14:26 --------- d-----w C:\Documents and Settings\Catherine\Application Data\vmntoolbar
2008-02-28 00:17 90,112 ----a-w C:\WINDOWS\DUMP7f80.tmp
2008-02-27 22:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 14:08 --------- d-----w C:\Program Files\Conquete 2.0
2008-01-06 11:47 --------- d-----w C:\Program Files\GameSpy Arcade
2008-01-05 20:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-05 19:30 --------- d-----w C:\Documents and Settings\Catherine\Application Data\MSN6
2008-01-05 18:44 --------- d-----w C:\Program Files\Intel Desktop Board
2008-01-04 11:29 --------- d-----w C:\Program Files\Dofus
2008-01-04 09:05 --------- d-----w C:\Program Files\LucasArts
2007-09-08 15:09 2,154,496 ----a-w C:\Documents and Settings\Catherine\Application Data\sa3125_02_fus_eng.exe
2007-03-08 17:23 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-02-27 17:00 382 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb1942.dat
2007-02-27 16:32 49 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb41.dat
2007-02-26 20:58 20,480 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb4827.dat
2007-01-28 14:55 9,216 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb8467.dat
2007-01-28 14:55 0 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb6334.dat
2007-01-28 14:55 0 ----a-w C:\Documents and Settings\Catherine\Application Data\internaldb5436.dat
2006-10-05 18:49 3,601,656 ----a-w C:\Program Files\vmnstorage.exe
2006-09-20 09:49 23,488,648 ----a-w C:\Program Files\AdbeRdr708_fr_FR.exe
2006-09-20 09:47 762,512 ----a-w C:\Program Files\ytb612_efgsip.exe
2006-09-20 09:47 7,218,088 ----a-w C:\Program Files\psa30se_fr_fr.exe
.
[code]<pre>
----a-w 7,240,936 2000-09-14 16:20:44 C:\Documents and Settings\Catherine\Mes documents\Jeux\Casse Brique .exe
</pre>/code
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5ED7D3DE-6DBE-4516-8712-436325722327}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C07F60AC-688D-4F3E-89EC-30B281BDD2CC}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 12:32 94208]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55 5674352]
"EPSON Stylus C66 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.exe" [2003-11-26 14:00 99840]
"Nero PhotoShow Media Manager"="C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe" [2006-01-13 22:22 249856]
"neufbox_reminder"="C:\Program Files\Kit ADSL\Wizard\PostInstall_Checker.exe" [2004-09-14 19:45 444416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 07:57 143360]
"ASUS Probe"="C:\Program Files\ASUS\Probe\AsusProb.exe" [2002-12-06 15:07 617984]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 20:43 7630848]
"nwiz"="nwiz.exe" [2006-08-11 20:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 20:43 86016]
"EPSON Stylus C66 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.exe" [2003-11-26 14:00 99840]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 16:32 221184]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23 75520]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-12-30 11:36 579072]
"Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2004-08-27 19:22 90112]
"NWEReboot"="" []
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-25 16:15 454656]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-25 16:06 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 15:51 257088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [ ]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 14:28 219136]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Electronic Arts\\La Bataille pour la Terre du Milieu II\\game.dat"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Dofus-Arena\\Dofus-Arena.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Metin2_France\\metin2.bin"=
"C:\\Program Files\\Kazaa\\kazaa.exe"=
"C:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 10:38]
R2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys [1999-04-18 22:00]
R3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\system32\DRIVERS\usbiad.sys [2004-07-14 18:52]
S1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys []
S3 oflpydin;oflpydin;C:\DOCUME~1\CATHER~1\LOCALS~1\Temp\oflpydin.sys [2001-04-04 13:46]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-09-28 05:42:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-02 15:59:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-02 16:05:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-02 15:05:17
.
2008-02-17 10:35:07 --- E O F ---