Donc:
Le premier rapport:
ComboFix 08-04-15.8 - Mistral 2008-04-16 21:49:12.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.404 [GMT 2:00]
Endroit: C:\Documents and Settings\Mistral\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mistral\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE ::
C:\WINDOWS\bbdddd.ini2
C:\WINDOWS\system32\tphklock.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FixComponents.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixSchedule.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\grep.exe
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\HPFix5.reg
C:\SDFix\apps\HPFix6.reg
C:\SDFix\apps\HPFix7.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\regedit.exe
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\beep.sys
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\beep.sys
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\sed.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\srv2bk.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\vfind.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\winsec.reg
C:\SDFix\apps\zip.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\HOSTS
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\WINDOWS\bbdddd.ini2
C:\WINDOWS\system32\tphklock.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-16 to 2008-04-16 ))))))))))))))))))))))))))))))))))))
.
2008-04-16 21:34 . 2008-04-16 21:34 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 21:34 . 2008-04-16 21:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 18:07 . 2008-04-16 18:07 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-15 20:56 . 2008-04-15 20:56 <REP> d-------- C:\Program Files\AxBx
2008-04-14 15:15 . 2008-04-14 15:15 <REP> d-------- C:\Program Files\Lavasoft
2008-04-14 15:15 . 2008-04-14 15:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-14 15:01 . 2008-04-14 15:01 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-04-14 14:20 . 2008-04-14 14:20 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-14 13:43 . 2008-04-14 13:43 <REP> d-------- C:\Program Files\Trend Micro
2008-04-14 10:09 . 2008-04-14 10:09 <REP> d-------- C:\Documents and Settings\Mistral\Application Data\Grisoft
2008-04-14 10:09 . 2008-04-14 10:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-14 10:09 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-13 21:09 . 2004-08-04 00:54 116,736 --a------ C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-04-13 21:09 . 2001-08-23 17:47 99,865 --a------ C:\WINDOWS\system32\dllcache\xlog.exe
2008-04-13 21:09 . 2004-08-05 05:00 28,288 --a------ C:\WINDOWS\system32\dllcache\xjis.nls
2008-04-13 21:09 . 2001-08-23 17:47 27,648 --a------ C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-04-13 21:09 . 2001-08-23 17:47 23,040 --a------ C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-04-13 21:09 . 2004-08-03 22:29 19,455 --a------ C:\WINDOWS\system32\dllcache\wvchntxx.sys
2008-04-13 21:09 . 2001-08-23 17:47 17,408 --a------ C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-04-13 21:09 . 2001-08-17 20:11 16,970 --a------ C:\WINDOWS\system32\dllcache\xem336n5.sys
2008-04-13 21:09 . 2004-08-03 22:29 12,063 --a------ C:\WINDOWS\system32\dllcache\wsiintxx.sys
2008-04-13 21:09 . 2001-08-23 17:47 4,608 --a------ C:\WINDOWS\system32\dllcache\xrxflnch.exe
2008-04-13 21:08 . 2004-08-05 05:00 156,672 --a------ C:\WINDOWS\system32\dllcache\winzm.ime
2008-04-13 21:08 . 2004-08-05 05:00 156,672 --a------ C:\WINDOWS\system32\dllcache\winsp.ime
2008-04-13 21:08 . 2004-08-05 05:00 156,672 --a------ C:\WINDOWS\system32\dllcache\winpy.ime
2008-04-13 21:08 . 2004-08-03 22:31 154,624 --a------ C:\WINDOWS\system32\dllcache\wlluc48.sys
2008-04-13 21:08 . 2004-08-05 05:00 79,360 --a------ C:\WINDOWS\system32\dllcache\winar30.ime
2008-04-13 21:08 . 2004-08-05 05:00 69,120 --a------ C:\WINDOWS\system32\dllcache\wingb.ime
2008-04-13 21:08 . 2004-08-05 05:00 65,536 --a------ C:\WINDOWS\system32\dllcache\winime.ime
2008-04-13 21:08 . 2001-08-23 17:05 35,402 --a------ C:\WINDOWS\system32\dllcache\wlandrv2.sys
2008-04-13 21:08 . 2004-08-03 23:07 8,832 --a------ C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-04-13 21:06 . 2001-08-17 21:28 765,884 --a------ C:\WINDOWS\system32\dllcache\usrti.sys
2008-04-13 21:05 . 2001-08-17 21:28 794,654 --a------ C:\WINDOWS\system32\dllcache\usr1801.sys
2008-04-13 21:04 . 2001-08-23 17:47 525,568 --a------ C:\WINDOWS\system32\dllcache\tridxp.dll
2008-04-13 21:03 . 2004-08-05 05:00 571,392 --a------ C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-04-13 21:02 . 2004-08-03 23:00 149,376 --a------ C:\WINDOWS\system32\dllcache\tffsport.sys
2008-04-13 21:02 . 2001-08-23 17:46 81,408 --a------ C:\WINDOWS\system32\dllcache\tgiul50.dll
2008-04-13 21:02 . 2001-08-17 20:13 37,961 --a------ C:\WINDOWS\system32\dllcache\tdk100b.sys
2008-04-13 21:02 . 2001-08-17 20:50 36,640 --a------ C:\WINDOWS\system32\dllcache\t2r4mini.sys
2008-04-13 21:02 . 2001-08-17 21:49 30,464 --a------ C:\WINDOWS\system32\dllcache\tbatm155.sys
2008-04-13 21:02 . 2004-08-05 05:00 21,896 --a------ C:\WINDOWS\system32\dllcache\tdipx.sys
2008-04-13 21:02 . 2004-08-05 05:00 19,464 --a------ C:\WINDOWS\system32\dllcache\tdspx.sys
2008-04-13 21:02 . 2001-08-17 20:13 17,129 --a------ C:\WINDOWS\system32\dllcache\tdkcd31.sys
2008-04-13 21:02 . 2004-08-05 05:00 13,192 --a------ C:\WINDOWS\system32\dllcache\tdasync.sys
2008-04-13 21:02 . 2001-08-17 21:52 7,040 --a------ C:\WINDOWS\system32\dllcache\tandqic.sys
2008-04-13 21:01 . 2001-08-23 17:46 172,768 --a------ C:\WINDOWS\system32\dllcache\t2r4disp.dll
2008-04-13 21:01 . 2001-08-17 21:50 103,936 --a------ C:\WINDOWS\system32\dllcache\sx.sys
2008-04-13 21:01 . 2001-08-23 17:47 94,293 --a------ C:\WINDOWS\system32\dllcache\sxports.dll
2008-04-13 21:01 . 2001-08-23 17:47 53,760 --a------ C:\WINDOWS\system32\dllcache\sw_wheel.dll
2008-04-13 21:01 . 2001-08-23 17:47 41,472 --a------ C:\WINDOWS\system32\dllcache\sw_effct.dll
2008-04-13 21:01 . 2001-08-23 17:47 10,240 --a------ C:\WINDOWS\system32\dllcache\swpidflt.dll
2008-04-13 21:01 . 2001-08-23 17:47 10,240 --a------ C:\WINDOWS\system32\dllcache\swpdflt2.dll
2008-04-13 21:01 . 2001-08-17 22:02 3,968 --a------ C:\WINDOWS\system32\dllcache\swusbflt.sys
2008-04-13 20:59 . 2004-08-05 05:00 466,944 --a------ C:\WINDOWS\system32\dllcache\smtpsvc.dll
2008-04-13 20:58 . 2004-08-03 22:41 404,990 --a------ C:\WINDOWS\system32\dllcache\slntamr.sys
2008-04-13 20:57 . 2001-08-23 17:46 386,560 --a------ C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-04-13 20:57 . 2001-08-23 17:21 161,664 --a------ C:\WINDOWS\system32\dllcache\sgsmusb.sys
2008-04-13 20:57 . 2001-08-17 20:50 101,760 --a------ C:\WINDOWS\system32\dllcache\sis300ip.sys
2008-04-13 20:57 . 2001-08-17 20:51 98,080 --a------ C:\WINDOWS\system32\dllcache\sgiulnt5.sys
2008-04-13 20:57 . 2004-08-05 05:00 18,944 --a------ C:\WINDOWS\system32\dllcache\simptcp.dll
2008-04-13 20:57 . 2001-07-21 22:29 18,400 --a------ C:\WINDOWS\system32\dllcache\sgsmld.sys
2008-04-13 20:57 . 2004-08-04 00:54 3,901 --a------ C:\WINDOWS\system32\dllcache\siint5.dll
2008-04-13 20:56 . 2001-08-23 17:47 57,856 --a------ C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2008-04-13 20:56 . 2001-08-17 20:19 36,480 --a------ C:\WINDOWS\system32\dllcache\sfmanm.sys
2008-04-13 20:56 . 2001-08-23 17:47 26,112 --a------ C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2008-04-13 20:56 . 2001-08-23 17:20 18,432 --a------ C:\WINDOWS\system32\dllcache\sermouse.sys
2008-04-13 20:56 . 2001-08-17 21:52 11,648 --a------ C:\WINDOWS\system32\dllcache\scsiprnt.sys
2008-04-13 20:56 . 2001-08-17 21:53 10,880 --a------ C:\WINDOWS\system32\dllcache\scsiscan.sys
2008-04-13 20:56 . 2001-08-23 17:20 6,912 --a------ C:\WINDOWS\system32\dllcache\serscan.sys
2008-04-13 20:56 . 2001-08-17 21:53 6,912 --a------ C:\WINDOWS\system32\dllcache\seaddsmc.sys
2008-04-13 20:55 . 2001-08-23 17:47 495,616 --a------ C:\WINDOWS\system32\dllcache\sblfx.dll
2008-04-13 20:55 . 2001-08-17 20:50 75,392 --a------ C:\WINDOWS\system32\dllcache\s3savmxm.sys
2008-04-13 20:55 . 2004-08-03 22:59 43,136 --a------ C:\WINDOWS\system32\dllcache\sbp2port.sys
2008-04-13 20:55 . 2001-08-23 17:20 24,064 --a------ C:\WINDOWS\system32\dllcache\sccmn50m.sys
2008-04-13 20:55 . 2001-08-17 21:51 23,936 --a------ C:\WINDOWS\system32\dllcache\sccmusbm.sys
2008-04-13 20:55 . 2001-08-23 17:20 17,536 --a------ C:\WINDOWS\system32\dllcache\scr111.sys
2008-04-13 20:55 . 2001-08-23 17:20 16,768 --a------ C:\WINDOWS\system32\dllcache\scmstcs.sys
2008-04-13 20:53 . 2001-08-23 17:18 899,914 --a------ C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-04-13 20:52 . 2004-08-05 05:00 482,304 --a------ C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-04-13 20:51 . 2004-08-04 00:53 259,328 --a------ C:\WINDOWS\system32\dllcache\perm3dd.dll
2008-04-13 20:50 . 2001-08-17 22:05 351,616 --a------ C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-04-13 20:50 . 2001-08-23 17:47 116,736 --a------ C:\WINDOWS\system32\dllcache\ovcodec2.dll
2008-04-13 20:50 . 2001-08-23 17:15 54,954 --a------ C:\WINDOWS\system32\dllcache\otcsercb.sys
2008-04-13 20:50 . 2001-08-17 22:05 48,000 --a------ C:\WINDOWS\system32\dllcache\ovcam2.sys
2008-04-13 20:50 . 2001-08-23 17:47 39,424 --a------ C:\WINDOWS\system32\dllcache\ovcoms.exe
2008-04-13 20:50 . 2001-08-17 22:05 31,872 --a------ C:\WINDOWS\system32\dllcache\ovce.sys
2008-04-13 20:50 . 2001-08-17 22:05 28,032 --a------ C:\WINDOWS\system32\dllcache\ovcd.sys
2008-04-13 20:50 . 2001-08-17 22:05 25,088 --a------ C:\WINDOWS\system32\dllcache\ovca.sys
2008-04-13 20:50 . 2001-08-23 17:47 20,480 --a------ C:\WINDOWS\system32\dllcache\ovcomc.dll
2008-04-13 20:49 . 2001-08-17 20:50 198,144 --a------ C:\WINDOWS\system32\dllcache\nv3.sys
2008-04-13 20:49 . 2001-08-23 17:46 123,776 --a------ C:\WINDOWS\system32\dllcache\nv3.dll
2008-04-13 20:49 . 2001-08-17 20:20 54,528 --a------ C:\WINDOWS\system32\dllcache\opl3sax.sys
2008-04-13 20:49 . 2001-08-23 17:15 44,297 --a------ C:\WINDOWS\system32\dllcache\otceth5.sys
2008-04-13 20:49 . 2001-08-17 20:12 27,209 --a------ C:\WINDOWS\system32\dllcache\otc06x5.sys
2008-04-13 20:48 . 2004-08-03 22:41 180,360 --a------ C:\WINDOWS\system32\dllcache\ntmtlfax.sys
2008-04-13 20:48 . 2004-08-04 00:47 132,695 --a------ C:\WINDOWS\system32\dllcache\netwlan5.sys
2008-04-13 20:48 . 2001-08-17 20:20 126,080 --a------ C:\WINDOWS\system32\dllcache\nm5a2wdm.sys
2008-04-13 20:48 . 2001-08-17 20:20 87,040 --a------ C:\WINDOWS\system32\dllcache\nm6wdm.sys
2008-04-13 20:48 . 2001-08-23 17:10 66,302 --a------ C:\WINDOWS\system32\dllcache\netflx3.sys
2008-04-13 20:48 . 2001-08-17 20:49 51,552 --a------ C:\WINDOWS\system32\dllcache\ntgrip.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 19:56 179,828 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-16 19:56 15,274,016 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-15 16:39 --------- d-----w C:\Program Files\Conquer 2.0
2008-04-15 16:37 --------- d-----w C:\Program Files\RealVNC
2008-04-15 16:36 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-04-14 18:43 --------- d-----w C:\Documents and Settings\Mistral\Application Data\OpenOffice.org2
2008-04-14 13:13 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-13 08:10 5,427 ----a-w C:\WINDOWS\system32\EGATHDRV.SYS
2008-04-06 20:59 397,824 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp
2008-04-06 20:59 1,488,896 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp
2008-04-06 16:04 94,208 ----a-w C:\WINDOWS\DUMP69e5.tmp
2008-04-06 16:03 1,222,144 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp
2008-04-03 20:33 458,240 ----a-w C:\WINDOWS\Internet Logs\xDBA.tmp
2008-04-03 20:33 1,486,336 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp
2008-04-02 19:40 2,816,000 ----a-w C:\WINDOWS\Internet Logs\xDB9.tmp
2008-03-18 21:51 2,680,832 ----a-w C:\WINDOWS\Internet Logs\xDB7.tmp
2008-03-18 21:51 1,478,656 ----a-w C:\WINDOWS\Internet Logs\xDB8.tmp
2008-03-11 12:31 --------- d-----w C:\Program Files\CCleaner
2008-03-09 17:42 1,677,824 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-03-09 17:42 1,470,976 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-03-05 21:25 105,984 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-03-05 21:25 1,469,440 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-03-05 21:20 2,858,496 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-03-05 21:20 1,468,928 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-02-27 12:27 --------- d-----w C:\Program Files\DivX
2008-02-21 02:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-02-21 02:05 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-06-20 11:36 47,868 ----a-w C:\Program Files\unrar.exe
2005-05-11 21:36 12,288 ------w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-16_20.58.53.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-16 18:36:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 19:58:21 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-16 19:58:50 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_11c.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 307,200 2005-10-24 13:53:40 C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
------w 0 1601-01-01 00:00:00 C:\Program Files\Adobe\Photoshop Album Edition DÚcouverte\3.0\Apps\bak\
----a-w 344,064 2005-07-28 19:15:00 C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
----a-w 196,696 2005-09-26 14:11:04 C:\Program Files\Diskeeper Corporation\Diskeeper\bak\DkIcon.exe
----a-w 196,696 2005-09-26 14:11:04 C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe
----a-w 50,760 2006-05-25 14:35:42 C:\Program Files\Fichiers communs\AOL\1167670222\ee\bak\AOLSoftware.exe
----a-w 124,520 2006-02-17 16:59:46 C:\Program Files\Fichiers communs\AOL\IPHSend\bak\IPHSend.exe
----a-w 50,760 2006-05-25 14:35:40 C:\Program Files\Fichiers communs\AOL\Launch\bak\AOLLaunch.exe
----a-w 81,920 2004-07-27 14:50:18 C:\Program Files\Fichiers communs\InstallShield\UpdateService\bak\issch.exe
----a-w 221,184 2004-07-27 14:50:42 C:\Program Files\Fichiers communs\InstallShield\UpdateService\bak\ISUSPM.exe
----a-w 180,269 2006-05-24 15:18:49 C:\Program Files\Fichiers communs\Real\Update_OB\bak\realsched.exe
----a-w 48,752 2005-07-12 10:35:38 C:\Program Files\Fichiers communs\Symantec Shared\bak\ccApp.exe
----a-w 49,152 2005-05-11 21:12:54 C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe
----a-w 1,988,144 2005-08-02 16:52:40 C:\Program Files\IBM ThinkVantage\Client Security Solution\bak\cssauth.exe
----a-r 49,152 2005-07-07 13:22:54 C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\bak\pdservice.exe
----a-w 278,528 2006-06-14 14:24:14 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 36,975 2005-11-10 11:03:52 C:\Program Files\Java\jre1.5.0_06\bin\bak\jusched.exe
----a-w 94,208 2005-08-29 12:15:02 C:\Program Files\Lenovo\PkgMgr\HOTKEY\bak\TPHKMGR.exe
----a-w 282,624 2006-09-07 09:20:08 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 85,600 2005-08-25 15:59:18 C:\Program Files\Symantec Client Security\Symantec AntiVirus\bak\VPTray.exe
----a-w 512,000 2005-08-01 08:48:28 C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe
----a-w 110,592 2005-08-01 08:48:56 C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe
----a-w 409,600 2005-12-15 15:14:34 C:\Program Files\ThinkPad\ConnectUtilities\bak\ACTray.exe
----a-w 98,304 2005-12-15 15:14:14 C:\Program Files\ThinkPad\ConnectUtilities\bak\ACWLIcon.exe
----a-w 237,568 2005-08-31 00:20:00 C:\Program Files\ThinkPad\Utilities\bak\EzEjMnAp.Exe
----a-w 864,256 2005-08-23 16:23:20 C:\Program Files\ThinkPad\Utilities\bak\TpKmapAp.exe
----a-w 106,496 2005-11-23 23:02:00 C:\Program Files\ThinkVantage\PrdCtr\bak\LPMGR.exe
----a-w 40,960 2005-08-01 15:32:38 C:\Program Files\ThinkVantage\SystemUpdate\bak\UCLauncher.exe
----a-w 126,050 2005-07-12 07:00:30 C:\Program Files\ThinkVantage Fingerprint Software\bak\ctlcntr.exe
----a-w 15,360 2004-08-05 03:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-05 03:00:00 C:\WINDOWS\system32\ctfmon.exe
----a-w 127,037 2005-05-19 03:33:00 C:\WINDOWS\system32\dla\bak\tfswctrl.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-13 14:59 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-13 14:59 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-04-13 14:59 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:07 1667584]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 05:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TpShocks"="TpShocks.exe" [2005-08-22 19:29 86016 C:\WINDOWS\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2005-08-24 01:10 40960 C:\WINDOWS\system32\TP4EX.exe]
"PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-08-31 01:10 139264]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-08-31 01:10 208896]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 20:27 919016]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-13 14:59 1177368]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-09-26 16:11 196696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55 5674352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
C:\Program Files\ThinkVantage Fingerprint Software\psfus.dll 2005-07-12 09:06 110688 C:\Program Files\ThinkVantage Fingerprint Software\psfus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
notifyf2.dll 2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\ThinkVantage\\SystemUpdate\\jre\\bin\\javaw.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\1167670222\\ee\\aim6.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-04-13 15:00]
R0 Shockprf;Shockprf;C:\WINDOWS\system32\drivers\Shockprf.sys [2005-06-06 11:59]
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2005-11-08 09:27]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-13 14:59]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2005-11-08 09:27]
R1 ShockMgr;ShockMgr;C:\WINDOWS\system32\drivers\ShockMgr.sys [2005-06-06 11:59]
R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\Tppwrif.sys [2005-08-31 01:10]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-13 14:59]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-13 14:59]
R2 ibmfilter;ibmfilter;C:\WINDOWS\system32\drivers\ibmfilter.sys [2005-08-02 18:15]
R2 PrivateDisk;PrivateDisk;C:\Program Files\IBM ThinkVantage\SafeGuard PrivateDisk\PrivateDiskM.sys [2005-06-28 08:26]
R2 smi2;smi2;C:\Program Files\SMI2\smi2.sys [2005-08-02 17:47]
R2 SmiHlp;SMI helper driver;C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2005-07-12 08:57]
R3 TcUsb;TC USB Kernel Driver;C:\WINDOWS\system32\Drivers\tcusb.sys [2005-07-12 09:07]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-06-14 12:03]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-14 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 07:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 08:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 16:00:01 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-14 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-14 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-14 22:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-14 23:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 00:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 01:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 02:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 03:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 04:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 05:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 06:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 07:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 08:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 09:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 10:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 11:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 12:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 13:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 14:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 15:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 16:00:01 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 17:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 18:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 19:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-16 20:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-14 21:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\JliqKp50.exe
"2008-04-15 02:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 03:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-15 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\6eYpAf55.exe
"2008-04-16 20:11:26 C:\WINDOWS\Tasks\PMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
"2006-05-10 21:41:57 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 22:10:17
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 182
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fichiers communs\Virtual Token\vtserver.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSvc.exe
C:\Program Files\IBM ThinkVantage\Client Security Solution\ibmtcsd.exe
C:\Program Files\IBM ThinkVantage\Rescue and Recovery\rrservice.exe
C:\Program Files\IBM ThinkVantage\Common\Scheduler\tvtsched.exe
C:\Program Files\ThinkVantage\SystemUpdate\UCLauncherService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcMurocHlpr.exe
C:\Program Files\IBM ThinkVantage\Common\Logger\logmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-16 22:18:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-16 20:18:02
ComboFix2.txt 2008-04-16 19:01:24
Pre-Run: 20,499,546,112 octets libres
Post-Run: 20,513,595,392 octets libres
Et le deuxième:
Fichier notifyf2.dll_ reçu le 2008.04.16 22:22:53 (CET)
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.4.17.0 2008.04.16 -
AntiVir 7.6.0.85 2008.04.16 -
Authentium 4.93.8 2008.04.16 -
Avast 4.8.1169.0 2008.04.16 -
AVG 7.5.0.516 2008.04.16 -
BitDefender 7.2 2008.04.16 -
CAT-QuickHeal 9.50 2008.04.16 -
ClamAV 0.92.1 2008.04.16 -
DrWeb 4.44.0.09170 2008.04.16 -
eSafe 7.0.15.0 2008.04.16 -
eTrust-Vet 31.3.5703 2008.04.16 -
Ewido 4.0 2008.04.16 -
F-Prot 4.4.2.54 2008.04.16 -
F-Secure 6.70.13260.0 2008.04.16 -
FileAdvisor 1 2008.04.16 -
Fortinet 3.14.0.0 2008.04.16 -
Ikarus T3.1.1.26 2008.04.16 -
Kaspersky 7.0.0.125 2008.04.16 -
McAfee 5275 2008.04.16 -
Microsoft 1.3408 2008.04.14 -
NOD32v2 3031 2008.04.16 -
Norman 5.80.02 2008.04.16 -
Panda 9.0.0.4 2008.04.16 -
Prevx1 V2 2008.04.16 -
Rising 20.40.22.00 2008.04.16 -
Sophos 4.28.0 2008.04.16 -
Sunbelt 3.0.1041.0 2008.04.12 -
Symantec 10 2008.04.16 -
TheHacker 6.2.92.280 2008.04.16 -
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.16 -
Webwasher-Gateway 6.6.2 2008.04.16 -
Information additionnelle
File size: 28672 bytes
MD5...: 3c21a62642bea691b588f69e8d11b374
SHA1..: b1d5a7de24dc9a99222b779ebe009bc72ac7061d
SHA256: 0bb739e9a64ccd7de0a10c6f5c9e68d6e780038382fdea4e1bb330bf2b8377d3
SHA512: 34b91c1a8955633fabe9eba2105268f8bd3468c9b1c7132e7c38c06c056ae0d9<br>4ef8aa713221ef77151c203abb8748cd0cc54ca4f94c155160e9489cb7b69086
PEiD..: Armadillo v1.xx - v2.xx
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x10001239<br>timedatestamp.....: 0x42cb4cbb (Wed Jul 06 03:15:07 2005)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x2c06 0x3000 6.24 8a4d9af50258f0f2bd9dbdfcb617a18d<br>.rdata 0x4000 0x92d 0x1000 3.62 ccf6ac4ae170676db9631eabf3abe931<br>.data 0x5000 0x920 0x1000 0.79 aedff4daee985da031662563e4fda493<br>.reloc 0x6000 0x4a0 0x1000 2.24 d6f9102cdf5f099305cf69b0a25e0139<br><br>( 2 imports ) <br>> KERNEL32.dll: CloseHandle, GetCommandLineA, GetVersion, ExitProcess, TerminateProcess, GetCurrentProcess, GetCurrentThreadId, TlsSetValue, TlsAlloc, TlsFree, TlsGetValue, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, DeleteCriticalSection, GetModuleFileNameA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, HeapFree, WriteFile, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapAlloc, GetCPInfo, GetACP, GetOEMCP, VirtualAlloc, HeapReAlloc, GetProcAddress, LoadLibraryA, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, RtlUnwind<br>> ADVAPI32.dll: RegOpenKeyExA, CreateProcessAsUserA, RegCloseKey, RegQueryValueExA<br><br>( 3 exports ) <br>__0CNotifyfnf2@@QAE@XZ, __4CNotifyfnf2@@QAEAAV0@ABV0@@Z, Unlock_Notify_fnf2<br>
A+