ComboFix 08-04-15.4 - jimmy 2008-04-18 0:02:32.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.238 [GMT 2:00]
Endroit: C:\Documents and Settings\jimmy\Bureau\ComboFix.exe
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-17 to 2008-04-17 ))))))))))))))))))))))))))))))))))))
.
2008-04-17 00:56 . 2008-04-17 01:00 <REP> d-------- C:\Program Files\SpywareBlaster
2008-04-17 00:45 . 2006-11-22 12:35 42,496 --a------ C:\WINDOWS\system32\AdvUninstCPL.cpl
2008-04-17 00:40 . 2008-04-17 00:39 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-04-17 00:40 . 2008-04-17 00:39 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-04-17 00:40 . 2008-04-17 00:39 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-04-17 00:01 . 2008-04-17 00:01 250 --a------ C:\WINDOWS\gmer.ini
2008-04-16 13:23 . 2008-04-16 13:23 <REP> d-------- C:\Documents and Settings\jimmy\Application Data\Grisoft
2008-04-16 13:23 . 2008-04-16 13:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-16 13:23 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-16 13:01 . 2008-04-16 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-04-16 12:18 . 2008-04-16 12:18 268 --ah----- C:\sqmdata19.sqm
2008-04-16 12:18 . 2008-04-16 12:18 244 --ah----- C:\sqmnoopt19.sqm
2008-04-16 12:01 . 2008-04-16 12:01 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-04-16 11:59 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-16 11:58 . 2008-04-16 11:58 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-04-16 11:42 . 2008-04-16 11:42 <REP> d-------- C:\Program Files\Trend Micro
2008-04-16 03:10 . 2008-04-16 03:10 268 --ah----- C:\sqmdata18.sqm
2008-04-16 03:10 . 2008-04-16 03:10 244 --ah----- C:\sqmnoopt18.sqm
2008-04-16 03:06 . 2008-04-16 03:06 268 --ah----- C:\sqmdata17.sqm
2008-04-16 03:06 . 2008-04-16 03:06 244 --ah----- C:\sqmnoopt17.sqm
2008-04-16 02:17 . 2008-04-16 02:17 268 --ah----- C:\sqmdata16.sqm
2008-04-16 02:17 . 2008-04-16 02:17 244 --ah----- C:\sqmnoopt16.sqm
2008-04-16 02:10 . 2008-04-16 02:10 268 --ah----- C:\sqmdata15.sqm
2008-04-16 02:10 . 2008-04-16 02:10 244 --ah----- C:\sqmnoopt15.sqm
2008-04-16 02:04 . 2008-04-16 02:04 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-16 02:04 . 2008-04-16 02:04 <REP> d-------- C:\Documents and Settings\jimmy\Application Data\Malwarebytes
2008-04-16 02:04 . 2008-04-16 02:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-16 02:02 . 2008-04-16 02:02 268 --ah----- C:\sqmdata14.sqm
2008-04-16 02:02 . 2008-04-16 02:02 244 --ah----- C:\sqmnoopt14.sqm
2008-04-16 01:59 . 2008-04-16 01:59 268 --ah----- C:\sqmdata13.sqm
2008-04-16 01:59 . 2008-04-16 01:59 244 --ah----- C:\sqmnoopt13.sqm
2008-04-16 01:55 . 2008-04-16 01:55 268 --ah----- C:\sqmdata12.sqm
2008-04-16 01:55 . 2008-04-16 01:55 244 --ah----- C:\sqmnoopt12.sqm
2008-04-16 01:49 . 2008-04-16 01:49 268 --ah----- C:\sqmdata11.sqm
2008-04-16 01:49 . 2008-04-16 01:49 244 --ah----- C:\sqmnoopt11.sqm
2008-04-16 01:45 . 2008-04-16 01:45 268 --ah----- C:\sqmdata10.sqm
2008-04-16 01:45 . 2008-04-16 01:45 244 --ah----- C:\sqmnoopt10.sqm
2008-04-16 01:20 . 2008-04-16 12:29 <REP> d-------- C:\Muestras
2008-04-16 00:08 . 2008-04-16 00:08 244 --ah----- C:\sqmnoopt08.sqm
2008-04-16 00:08 . 2008-04-16 00:08 232 --ah----- C:\sqmdata08.sqm
2008-04-16 00:08 . 2008-04-16 00:08 172 --ah----- C:\sqmnoopt09.sqm
2008-04-16 00:08 . 2008-04-16 00:08 172 --ah----- C:\sqmdata09.sqm
2008-04-16 00:00 . 2008-04-16 00:00 268 --ah----- C:\sqmdata07.sqm
2008-04-16 00:00 . 2008-04-16 00:00 244 --ah----- C:\sqmnoopt07.sqm
2008-04-15 14:28 . 2008-04-16 12:26 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-04-15 13:02 . 2008-04-15 13:02 244 --ah----- C:\sqmnoopt06.sqm
2008-04-15 13:02 . 2008-04-15 13:02 232 --ah----- C:\sqmdata06.sqm
2008-04-15 12:58 . 2008-04-17 15:07 244 --ah----- C:\sqmnoopt05.sqm
2008-04-15 12:58 . 2008-04-17 15:07 232 --ah----- C:\sqmdata05.sqm
2008-04-15 00:07 . 2008-04-15 00:07 <REP> d-------- C:\Documents and Settings\jimmy\Application Data\FaxCtr
2008-04-14 17:18 . 2008-04-14 17:18 <REP> d-------- C:\Program Files\GamesBar
2008-04-14 17:18 . 2008-04-14 17:18 <REP> d-------- C:\Documents and Settings\jimmy\Application Data\Valusoft
2008-04-14 17:18 . 2008-04-14 17:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Valusoft
2008-04-14 17:17 . 2008-04-14 17:17 <REP> d-------- C:\Program Files\orange
2008-04-14 17:17 . 2008-04-14 17:17 <REP> d-------- C:\Program Files\Fichiers communs\Oberon Media
2008-04-14 11:22 . 2008-04-14 11:22 <REP> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-04-14 11:21 . 2003-03-12 00:26 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2008-04-14 11:21 . 2003-03-12 00:26 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2008-04-14 11:21 . 2003-03-12 00:26 98,304 --a------ C:\WINDOWS\system32\IM31XPNG.DEL
2008-04-14 11:21 . 2003-03-12 00:26 69,632 --a------ C:\WINDOWS\system32\IM31XTIF.DEL
2008-04-14 11:21 . 2003-03-12 00:26 49,152 --a------ C:\WINDOWS\system32\IM31IMG.DIL
2008-04-14 11:21 . 2005-07-12 15:33 32,768 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2008-04-14 11:21 . 2005-07-12 15:33 20,480 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2008-04-14 11:21 . 2005-07-12 15:36 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2008-04-14 11:20 . 2008-04-14 11:21 <REP> d-------- C:\Program Files\Lexmark Fax Solutions
2008-04-14 11:20 . 2008-04-14 11:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-04-14 11:20 . 2008-04-14 11:22 23,099 --a------ C:\WINDOWS\system32\LexFiles.ulf
2008-04-14 11:19 . 2008-04-16 13:41 <REP> d-------- C:\Program Files\Lx_cats
2008-04-14 11:19 . 2008-04-15 00:07 <REP> d-------- C:\Program Files\Lexmark 2300 Series
2008-04-14 11:18 . 2008-04-15 00:07 <REP> d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2008-04-14 11:18 . 2008-04-14 11:18 <REP> d-------- C:\Temp
2008-04-14 11:18 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-14 11:18 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-14 11:18 . 2008-04-14 11:18 0 --a------ C:\lxcgfire.csv
2008-04-11 20:16 . 2008-04-17 15:07 244 --ah----- C:\sqmnoopt04.sqm
2008-04-11 20:16 . 2008-04-17 15:07 232 --ah----- C:\sqmdata04.sqm
2008-04-11 15:08 . 2008-04-17 12:39 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-11 15:07 . 2008-04-11 15:07 <REP> d-------- C:\Documents and Settings\jimmy\Application Data\Media Player Classic
2008-04-11 15:04 . 2008-04-11 15:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-04-11 14:46 . 2008-04-11 14:46 <REP> d-------- C:\Program Files\Windows Live
2008-04-11 14:46 . 2008-04-11 14:46 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-04-11 12:23 . 2008-04-11 12:23 <REP> d--hs---- C:\Documents and Settings\jimmy\UserData
2008-04-11 12:20 . 2008-04-17 15:07 244 --ah----- C:\sqmnoopt03.sqm
2008-04-11 12:20 . 2008-04-17 15:07 232 --ah----- C:\sqmdata03.sqm
2008-04-11 12:14 . 2008-04-11 12:14 1,160 --a------ C:\WINDOWS\mozver.dat
2008-04-11 11:56 . 2008-04-17 15:17 <REP> d-------- C:\Documents and Settings\jimmy\Contacts
2008-04-11 10:36 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-04-11 10:36 . 2004-08-03 23:07 59,264 --a--c--- C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-04-11 10:35 . 2008-04-11 10:35 <REP> d-------- C:\WINDOWS\system32\Lang
2008-04-11 10:35 . 2008-04-11 10:35 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-04-11 10:35 . 2008-04-11 10:35 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-04-11 10:35 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-11 10:35 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-10 14:11 . 2008-04-17 15:06 268 --ah----- C:\sqmdata02.sqm
2008-04-10 14:11 . 2008-04-17 15:06 244 --ah----- C:\sqmnoopt02.sqm
2008-04-10 14:05 . 2008-04-14 13:04 169 --a------ C:\WINDOWS\RtlRack.ini
2008-04-10 13:58 . 2008-04-10 13:59 <REP> d-a------ C:\Utilitaires
2008-04-10 13:56 . 2008-04-10 13:56 <REP> d-------- C:\Program Files\Godlike Developers
2008-04-10 13:48 . 2008-04-10 13:48 <REP> d-------- C:\Program Files\Lavasoft
2008-04-10 13:48 . 2008-04-10 13:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 22:00 --------- d-----w C:\Program Files\ESET
2008-04-12 23:22 --------- d-----w C:\Program Files\PhotoFiltre
2008-04-09 09:33 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-09 09:31 --------- d-----w C:\Program Files\Services en ligne
2008-03-04 10:33 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
.
((((((((((((((((((((((((((((( snapshot@2008-04-16_13.17.58.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-16 11:17:02 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-17 21:34:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-03-24 17:33:02 1,527,056 ----a-w C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
+ 2008-04-16 22:01:02 819,200 ----a-w C:\WINDOWS\gmer.dll
+ 2008-04-16 22:01:02 86,097 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
+ 2008-03-25 02:32:44 218,496 ----a-r C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
+ 2008-04-16 11:26:13 74,649 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RAMSaverPro"="" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:07 1667584]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 77824 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43 8466432]
"nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43 81920]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 19:48 73728]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 08:07 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 14:05 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 15:36 299008]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-04-17 00:39 949376]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"D:\\Program Files\\eMule\\emule.exe"=
S4 Dnscache;Client DNS;C:\WINDOWS\system32\svchost.exe [2004-08-04 00:55]
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 00:03:35
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 1
**************************************************************************
.
Temps d'accomplissement: 2008-04-18 0:04:03
ComboFix-quarantined-files.txt 2008-04-17 22:03:59
ComboFix2.txt 2008-04-16 11:48:19
ComboFix3.txt 2008-04-16 11:18:07
Pre-Run: 16,468,815,872 octets libres
Post-Run: 16,460,472,320 octets libres