REBONJOUR,
VOICI LE RAPPORT DE CONBOFIX.
ComboFix 08-06-01.6 - unika 2008-06-02 21:21:32.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.408 [GMT 2:00]
Endroit: C:\Documents and Settings\unika\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM17f0d136.xml
C:\WINDOWS\msettings.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\edNpWvut.ini
C:\WINDOWS\system32\edNpWvut.ini2
C:\WINDOWS\system32\kmkwgxde.ini
C:\WINDOWS\system32\lkaxprhv.ini
C:\WINDOWS\system32\vlyfxlmo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-02 to 2008-06-02 ))))))))))))))))))))))))))))))))))))
.
2008-06-02 16:13 . 2008-06-02 16:13 3,874 --a------ C:\cc_20080602_1613.reg
2008-06-02 16:12 . 2008-06-02 16:13 1,835 --a------ C:\cc_20080602_1612.reg
2008-06-02 15:56 . 2008-06-02 15:56 266 --a------ C:\cc_20080602_1556.reg
2008-06-02 13:29 . <REP> C:\WINDOWS\LastGood.Tmp
2008-06-02 13:11 . 2008-06-02 13:11 <REP> d-------- C:\Deckard
2008-06-01 20:43 . 2008-06-01 20:43 1,152 --a------ C:\cc_20080601_2042.reg
2008-06-01 19:40 . 2008-06-01 19:40 812,344 --a------ C:\thejack.exe
2008-06-01 19:39 . 2008-06-01 19:39 <REP> d-------- C:\Program Files\Trend Micro
2008-06-01 18:00 . 2008-06-01 18:00 453 --a------ C:\cc_20080601_1800.reg
2008-06-01 17:34 . 2008-06-01 17:34 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-01 16:10 . 2008-06-02 19:57 <REP> d-------- C:\Program Files\Navilog1
2008-06-01 15:38 . 2008-06-02 13:32 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-06-01 14:57 . 2008-06-01 14:57 220,122 --a------ C:\cc_20080601_1457.reg
2008-06-01 14:52 . 2008-06-01 14:53 77,525 --a------ C:\cc_20080601_1452.reg
2008-06-01 13:16 . 2008-06-01 13:16 <REP> d-------- C:\VundoFix Backups
2008-06-01 11:53 . 2008-06-01 11:53 <REP> d-------- C:\Documents and Settings\unika\Application Data\Malwarebytes
2008-06-01 11:40 . 2008-06-01 11:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-01 11:36 . 2008-05-30 01:06 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-01 11:36 . 2008-05-30 01:06 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-01 11:33 . 2008-06-01 12:14 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-30 22:06 . 2008-05-30 22:07 97,839 --a------ C:\cc_20080530_2206.reg
2008-05-30 21:14 . 2008-05-30 21:14 <REP> d-------- C:\!KillBox
2008-05-30 19:15 . 2008-05-30 19:22 <REP> d-------- C:\Program Files\RegCleaner
2008-05-30 18:01 . 2004-08-20 00:09 116,736 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-05-30 18:01 . 2001-08-23 17:47 99,865 --a--c--- C:\WINDOWS\system32\dllcache\xlog.exe
2008-05-30 18:01 . 2001-08-28 14:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-05-30 18:01 . 2001-08-23 17:47 27,648 --a--c--- C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-05-30 18:01 . 2001-08-23 17:47 23,040 --a--c--- C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-05-30 18:01 . 2004-08-04 06:29 19,455 --a--c--- C:\WINDOWS\system32\dllcache\wvchntxx.sys
2008-05-30 18:01 . 2001-08-23 17:47 17,408 --a--c--- C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-05-30 18:01 . 2001-08-17 20:11 16,970 --a--c--- C:\WINDOWS\system32\dllcache\xem336n5.sys
2008-05-30 18:01 . 2001-08-23 17:47 4,608 --a--c--- C:\WINDOWS\system32\dllcache\xrxflnch.exe
2008-05-30 17:59 . 2001-08-23 17:47 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-05-30 17:58 . 2001-08-23 17:18 899,914 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-05-30 17:57 . 2001-08-17 22:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-05-30 17:56 . 2001-08-17 21:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-05-30 17:55 . 2004-08-20 00:09 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-05-30 17:54 . 2001-08-23 17:46 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-05-30 17:53 . 2001-08-23 17:04 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-05-30 17:52 . 2001-08-17 21:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-05-30 17:51 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-05-30 14:45 . 2008-05-30 14:45 61 --a------ C:\WINDOWS\wininit.ini
2008-05-30 14:17 . 1998-10-30 22:21 1,022,976 --------- C:\WINDOWS\system32\SierraNW.dll
2008-05-30 14:17 . 1998-10-30 22:21 231,936 --------- C:\WINDOWS\system32\SNWValid.dll
2008-05-30 14:01 . 2008-05-30 15:23 420 --a------ C:\WINDOWS\SIERRA.INI
2008-05-19 15:32 . 2008-05-19 15:32 <REP> d-------- C:\Documents and Settings\unika\Application Data\CVitae
2008-05-18 13:50 . 2008-05-21 15:35 <REP> d-------- C:\Program Files\CVitae
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 19:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-02 15:26 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-30 22:05 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-05-30 22:05 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-05-30 22:05 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-05-30 22:05 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-05-30 22:05 --------- d-----w C:\Program Files\Symantec
2008-05-30 18:02 --------- d-----w C:\Documents and Settings\unika\Application Data\Azureus
2008-05-16 19:10 --------- d-----w C:\Program Files\TeamViewer3
2008-05-09 15:24 --------- d-----w C:\Documents and Settings\unika\Application Data\AdobeUM
2008-04-27 17:14 --------- d-----w C:\Program Files\RamBoost XP
2008-04-27 17:14 --------- d-----w C:\Program Files\CDImage GUI
2008-04-27 08:12 --------- d-----w C:\Program Files\Azureus
2008-04-25 18:32 91,744 ----a-w C:\WINDOWS\BPMNT.dll
2008-04-25 18:32 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-04-25 18:32 333,576 ----a-w C:\WINDOWS\TSC.exe
2008-04-25 18:32 1,213,784 ----a-w C:\WINDOWS\vsapi32.dll
2008-04-25 18:30 69,689 ----a-w C:\WINDOWS\UNZIP.DLL
2008-04-25 18:30 507,904 ----a-w C:\WINDOWS\TMUPDATE.DLL
2008-04-25 18:30 286,720 ----a-w C:\WINDOWS\PATCH.EXE
2008-04-23 11:31 --------- d-----w C:\Program Files\Yahoo!
2008-04-23 11:31 --------- d-----w C:\Documents and Settings\unika\Application Data\Grisoft
2008-04-23 11:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-11 10:18 720,896 ----a-w C:\WINDOWS\iun6002.exe
2008-04-07 10:22 --------- d-----w C:\Documents and Settings\LocalService\Application Data\TeamViewer
2008-04-06 11:59 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\TeamViewer
2008-04-06 11:59 --------- d-----w C:\Documents and Settings\unika\Application Data\TeamViewer
2008-04-05 19:21 --------- d-----w C:\Program Files\Fichiers communs\NSV
2008-04-05 19:07 --------- d-----w C:\Program Files\Fichiers communs\Nullsoft
2008-04-02 15:54 130,048 -c--a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ------w C:\WINDOWS\system32\win32k.sys
2008-03-18 16:08 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-03-18 16:08 249,856 ------w C:\WINDOWS\Setup1.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WD Button Manager"="WDBtnMgr.exe" [2007-07-30 19:34 364544 C:\WINDOWS\system32\WDBtnMgr.exe]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43 45056]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-03-14 20:10 116328]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.3ivx"= 3ivxVfWCodec.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-20 01:09 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R2 TeamViewer;TeamViewer 3;"C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service []
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-30 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 07:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-01 08:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-01 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-01 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-30 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-06-02 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 20:01:12 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-30 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 02:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 03:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\System32\hR7us76q.exe
"2008-05-31 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\System32\hR7us76q.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-02 21:25:26
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPROXY.EXE
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-02 21:29:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-02 19:29:33
Pre-Run: 114,098,003,968 octets libres
Post-Run: 114,084,986,880 octets libres
229 --- E O F --- 2008-05-29 01:09:14