ComboFix 08-06-01.6 - moreau 2008-06-02 20:24:18.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.707 [GMT 2:00]
Endroit: C:\Documents and Settings\moreau\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\xtcvfhvp.dll
.
---- Previous Run -------
.
C:\WINDOWS\qrkverwh.exe
C:\WINDOWS\system32\kgkeidfe.exe
C:\WINDOWS\system32\mvohembf.dll
C:\WINDOWS\system32\nqvssuhy.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-02 to 2008-06-02 ))))))))))))))))))))))))))))))))))))
.
2008-06-02 15:58 . 2008-06-02 15:59 <REP> d-------- C:\Program Files\uTorrent
2008-06-02 15:58 . 2008-06-02 15:59 <REP> d-------- C:\Documents and Settings\moreau\Application Data\uTorrent
2008-06-02 15:08 . 2008-06-02 15:33 <REP> d-------- C:\Program Files\Navilog1
2008-06-02 15:06 . 2008-06-02 15:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-06-02 15:06 . 2008-06-02 15:16 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-06-02 15:05 . 2004-04-27 05:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-06-02 15:04 . 2008-06-02 15:32 <REP> d-------- C:\WINDOWS\Internet Logs
2008-06-02 12:30 . 2008-06-02 12:30 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-02 12:30 . 2008-06-02 12:30 <REP> d-------- C:\_OTMoveIt
2008-06-02 12:23 . 2008-06-02 12:23 <REP> d-------- C:\Program Files\Trend Micro
2008-05-31 18:48 . 2008-05-31 18:48 <REP> d-------- C:\Program Files\PSCS2Updater
2008-05-31 14:21 . 2008-05-31 14:21 <REP> d-------- C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-05-31 14:21 . 2008-05-31 14:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-05-24 18:27 . 2001-08-17 22:02 8,576 --a------ C:\WINDOWS\system32\drivers\hidgame.sys
2008-05-14 22:18 . 2008-05-14 22:18 <REP> d-------- C:\Program Files\Multiquence
2008-05-10 18:50 . 2008-05-10 18:51 <REP> d-------- C:\WINDOWS\system32\URTTemp
2008-05-10 18:48 . 2008-05-10 18:48 <REP> d-------- C:\WINDOWS\San Andreas Mod Installer
2008-05-10 00:37 . 2008-05-10 00:37 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-05-09 23:58 . 2008-05-09 23:58 <REP> d-------- C:\Program Files\Rockstar Games
2008-05-09 11:39 . 1999-12-13 09:01 44,032 --------- C:\WINDOWS\system32\CTSVCCDA.EXE
2008-05-09 11:39 . 1999-11-18 09:00 25,088 --------- C:\WINDOWS\system32\CTSVCCTL.EXE
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 16:24 --------- d-----w C:\Program Files\eMule
2008-06-01 17:42 --------- d-----w C:\Program Files\EA SPORTS
2008-06-01 17:42 --------- d-----w C:\Program Files\DVDVIDEOSOFT
2008-06-01 13:35 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-01 09:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-31 17:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-15 17:10 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-05-15 06:51 --------- d-----w C:\Program Files\Yetisports
2008-05-11 08:31 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-09 16:01 --------- d-----w C:\Program Files\Spyware Doctor
2008-05-09 09:40 --------- d--h--w C:\Program Files\Creative Installation Information
2008-05-09 09:40 --------- d-----w C:\Program Files\Creative
2008-05-01 19:14 --------- d-----w C:\Documents and Settings\moreau\Application Data\PC Tools
2008-05-01 17:55 --------- d-----w C:\Program Files\WinAVI MP4 Converter
2008-04-28 20:03 --------- d-----w C:\Documents and Settings\moreau\Application Data\LimeWire
2008-04-28 17:41 --------- d-----w C:\Documents and Settings\moreau\Application Data\Teleca
2008-04-28 17:40 --------- d-----w C:\Documents and Settings\moreau\Application Data\Sony Ericsson
2008-04-28 17:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
2008-04-28 17:34 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-04-28 17:34 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
2008-04-28 17:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-04-28 17:33 --------- d-----w C:\Program Files\Sony Ericsson
2008-04-26 18:49 --------- d-----w C:\Documents and Settings\moreau\Application Data\Talkback
2008-04-20 13:44 --------- d-----w C:\Program Files\MediaCoder
2008-04-19 11:13 --------- d-----w C:\Program Files\XVideoConverter
2008-04-18 18:09 --------- d-----w C:\Documents and Settings\moreau\Application Data\vlc
2008-04-18 18:06 --------- d-----w C:\Program Files\VideoLAN
2008-04-16 14:13 --------- d-----w C:\Program Files\Fichiers communs\DVDVIDEOSOFT
2008-04-14 16:40 --------- d-----w C:\Program Files\Ulead Systems
2008-04-14 16:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-04-14 16:36 495 ---ha-w C:\os357577.bin
2008-04-13 18:16 --------- d-----w C:\Program Files\EPSON
2008-04-10 17:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-04-10 16:46 --------- d-----w C:\Program Files\Windows Live
2008-04-10 08:26 --------- d-----w C:\Documents and Settings\moreau\Application Data\Malwarebytes
2008-04-10 08:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-09 15:24 2,814 ----a-w C:\WINDOWS\system32\tmp.reg
2008-04-08 20:44 82,432 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-04-07 15:46 --------- d-----w C:\Program Files\Fichiers communs\Nero
2008-04-07 15:42 --------- d-----w C:\Program Files\Nero
2008-04-07 15:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-07 15:36 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-04-07 09:02 --------- d-----w C:\Documents and Settings\moreau\Application Data\Ahead
2008-03-28 22:19 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-03-27 18:15 37,888 ----a-w C:\WINDOWS\system32\rar.exe
2008-03-16 12:15 304,160 ----a-w C:\StiImg.dat
2001-11-23 12:08 712,704 ----a-r C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:54 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-12 14:57 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 11:03 868352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update"="uiojvcj.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft Update"="uiojvcj.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 06:54 15360]
C:\Documents and Settings\moreau\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Icatch(VI) SnapDetect.lnk - C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe [2008-03-02 21:42:56 65536]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 PAC207;SoC PC-Camer@;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-05-27 15:57]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 18:23]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-30 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-02 20:26:13
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-02 20:27:09
ComboFix-quarantined-files.txt 2008-06-02 18:27:06
ComboFix2.txt 2008-04-09 21:56:36
Pre-Run: 31,167,541,248 octets libres
Post-Run: 31,209,242,624 octets libres
145 --- E O F --- 2008-04-10 12:00:44