ComboFix 08-06-10.5 - Admin 2008-06-11 16:08:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.558 [GMT -4:00]
Endroit: C:\Documents and Settings\Admin\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\tmpvc14
C:\WINDOWS\BM2750db57.xml
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\dorfnpgh.ini
C:\WINDOWS\system32\iPsrYJlm.ini
C:\WINDOWS\system32\iPsrYJlm.ini2
C:\WINDOWS\system32\iyfaooaa.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\tkfwordx.dll
C:\WINDOWS\system32\yayvWqnl.dll
C:\WINDOWS\system32\ygolixwp.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-11 to 2008-06-11 ))))))))))))))))))))))))))))))))))))
.
2008-06-11 15:28 . 2008-06-11 15:28 1,453,438 --a------ C:\upload_moi_ACER-9604116340.tar.gz
2008-06-11 13:22 . 2008-06-11 13:22 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-11 13:22 . 2008-06-11 13:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-11 13:22 . 2008-06-11 13:22 <REP> d-------- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-06-11 13:22 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-11 13:22 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 12:18 . 2008-06-11 12:46 4,390 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-11 12:17 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-06-11 12:17 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-06-11 12:17 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-06-11 12:17 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-06-11 12:17 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-06-11 12:17 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-06-11 12:17 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-06-11 12:17 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-06-10 17:35 . 2008-06-11 14:17 91,136 --------- C:\WINDOWS\system32\rvifybry.dll
2008-06-09 21:48 . 2008-06-09 21:48 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-09 21:48 . 2008-06-09 22:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-09 21:01 . 2008-06-09 21:01 <REP> d-------- C:\Program Files\Ratajik Software
2008-06-09 20:28 . 2008-06-09 20:38 <REP> d-------- C:\Program Files\Nexus Radio
2008-06-09 19:28 . 2008-06-09 19:28 <REP> d-------- C:\Archivos de programa
2008-06-09 19:26 . 2008-05-16 12:00 <REP> d-------- C:\Program Files\Serials 2000 7.1.5 Plus
2008-06-09 16:16 . 2008-06-09 17:03 <REP> d-------- C:\Program Files\Virtual Piano
2008-06-09 00:25 . 2008-06-11 14:17 281,088 --------- C:\WINDOWS\system32\mlJYrsPi.dll
2008-06-09 00:02 . 2008-06-09 00:03 <REP> d-------- C:\Program Files\Hide My IP 2007
2008-06-09 00:02 . 2007-12-03 03:13 888,832 --a------ C:\WINDOWS\system32\securenet.dll
2008-06-08 22:53 . 2008-06-08 22:53 32 --a------ C:\WINDOWS\go
2008-06-08 20:54 . 2008-06-08 21:41 143 --a------ C:\rapidhacker.dll
2008-05-17 09:58 . 2008-05-17 09:58 <REP> d-------- C:\Program Files\My Downloaded Games
2008-05-17 09:58 . 2008-05-17 09:58 <REP> d-------- C:\Program Files\BoontyGames
2008-05-17 08:42 . 2003-06-12 23:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd
2008-05-16 15:55 . 2008-05-16 15:55 <REP> d-------- C:\Program Files\Microsoft Works
2008-05-16 15:54 . 2008-05-16 15:54 <REP> d-------- C:\Program Files\Microsoft.NET
2008-05-16 15:51 . 2008-05-16 15:55 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-05-16 15:47 . 2008-05-16 15:47 <REP> dr-h----- C:\MSOCache
2008-05-15 22:33 . 2008-05-15 22:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-05-15 22:25 . 2008-05-17 02:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-15 20:34 . 2008-05-15 20:34 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-05-12 09:56 . 2008-05-12 09:56 1,160 --a------ C:\WINDOWS\mozver.dat
2008-05-12 08:26 . 2008-06-11 16:08 <REP> d-------- C:\Temp
2008-05-12 08:08 . 2008-05-12 08:08 0 --a------ C:\WINDOWS\sms.INI
2008-05-12 08:07 . 2008-05-12 08:07 <REP> d-------- C:\My Music
2008-05-11 21:21 . 2008-06-05 12:58 <REP> d-------- C:\Program Files\FrostWire
2008-05-11 21:21 . 2008-06-08 21:12 <REP> d-------- C:\Documents and Settings\Admin\Shared
2008-05-11 21:21 . 2008-06-08 22:15 <REP> d-------- C:\Documents and Settings\Admin\Incomplete
2008-05-11 21:21 . 2008-05-15 22:26 <REP> d-------- C:\Documents and Settings\Admin\Application Data\FrostWire
2008-05-11 20:41 . 2008-05-11 20:42 <REP> d-------- C:\Program Files\Samsung
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 01:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-17 12:41 --------- d-----w C:\Program Files\Creative
2008-05-12 01:21 --------- d-----w C:\Program Files\LimeWire
2008-05-12 00:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-10 15:05 --------- d-----w C:\Documents and Settings\Admin\Application Data\LimeWire
2008-05-10 15:02 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-10 15:00 --------- d-----w C:\Documents and Settings\Admin\Application Data\AdobeUM
2008-05-10 06:44 --------- d-----w C:\Program Files\silence on tourne
2008-05-10 06:19 --------- d-----w C:\Documents and Settings\Admin\Application Data\Creative
2008-05-10 06:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Creative
2008-05-10 05:39 --------- d--h--w C:\Program Files\Creative Installation Information
2008-05-10 05:37 --------- d-----w C:\Program Files\Fichiers communs\Creative
2008-05-10 04:43 --------- d-----w C:\Documents and Settings\Admin\Application Data\Kazaa Lite
2008-05-10 03:51 --------- d-----w C:\Documents and Settings\Admin\Application Data\DivX
2008-05-09 23:41 --------- d-----w C:\Documents and Settings\Admin\Application Data\Apple Computer
2008-05-09 15:29 --------- d-----w C:\Documents and Settings\Admin\Application Data\Sony Corporation
2008-05-08 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
2008-05-08 16:00 314 ----a-w C:\Program Files\INSTALL.LOG
2008-05-08 02:58 --------- d-----w C:\Program Files\Common Files
2008-05-08 02:58 --------- d-----w C:\Documents and Settings\Admin\Application Data\Nexon
2008-05-08 02:56 --------- d-----w C:\Program Files\DivX
2008-05-08 01:00 --------- d-----w C:\Program Files\Fichiers communs\Motive
2008-05-08 01:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-04-25 22:03 --------- d-----w C:\Program Files\Google
2008-04-16 21:05 --------- d-----w C:\Program Files\Xmots98
2008-04-16 21:05 --------- d-----w C:\Program Files\Myst III Exile
2008-04-16 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Corel
2008-04-16 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Borland
2008-04-16 20:59 --------- d-----w C:\Program Files\WordPerfect OfficeReady 1.5
2008-04-16 20:56 --------- d-----w C:\Program Files\OpenOffice.org 2.0
2008-04-16 20:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-04-16 20:38 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-16 20:38 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-04-16 20:37 --------- d-----w C:\Program Files\Windows Live
2008-04-16 19:57 --------- d-----w C:\Documents and Settings\Admin\Application Data\MSNInstaller
2008-04-16 19:48 --------- d-----w C:\Program Files\L'Amerzone
2008-04-16 19:47 --------- d-----w C:\Program Files\Jeune Styliste 2
2008-04-16 19:46 --------- d-----w C:\Program Files\Jeune Styliste
2008-04-16 19:46 --------- d-----w C:\Program Files\Canon
2008-04-16 19:45 --------- d-----w C:\Documents and Settings\k\Application Data\Canon
2008-04-16 19:16 --------- d-----w C:\Documents and Settings\k\Application Data\OpenOffice.org2
2008-04-14 13:09 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-02-06 23:42 1,398,352 ----a-w C:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2007-02-02 04:52 80 --sh--r C:\WINDOWS\system32\870D8849F9.dll
2007-10-28 22:36 168 --sh--r C:\WINDOWS\system32\F949880D87.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2fb5b67a-05e1-4cb5-997d-55f1ef650fe6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CC068A5-8E60-4D5A-99EC-44A60E7CBD13}]
2008-06-11 14:17 281088 --------- C:\WINDOWS\system32\mlJYrsPi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7F7DAAD8-D1A0-46C3-8134-7FAAE453D4A4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0B4FFEA-D466-49A8-9BB0-B7BBD2FCB449}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 01:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 11:03 868352]
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-06-05 10:48 2113360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" []
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 10:11 1388544]
"ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 19:15 45056]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 01:00 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 01:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 01:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 01:00 455168]
"SiSPower"="SiSPower.dll" [2005-08-25 19:05 49152 C:\WINDOWS\system32\SiSPower.dll]
"SMSERIAL"="sm56hlpr.exe" [2005-06-06 13:40 544768 C:\WINDOWS\sm56hlpr.exe]
"AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 16:07 114688]
"MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 13:48 425984]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 17:00 397312]
"ISUSPM Startup"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
"UniMessenger"="" []
"MotiveReportAgent"="C:\Program Files\Fichiers communs\Motive\McciBootStrapper.exe" [ ]
"CTCheck"="C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 11:08 397312]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-09-13 22:10 180269]
"BM2750db57"="C:\WINDOWS\system32\rvifybry.dll" [2008-06-11 14:17 91136]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-09-23 13:41 860160]
"2463e8cb"="C:\WINDOWS\system32\ygolixwp.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 01:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayvWqnl]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 14:47]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2004-07-06 17:06]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2004-06-01 12:41]
R3 SecureSrv;SecureSrv;C:\Program Files\Hide My IP 2007\SecureSrv.exe [2007-12-18 11:22]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 01:00]
S3 PortlUSB;PortlUSB;C:\WINDOWS\system32\DRIVERS\YH-925.sys [2004-06-24 13:52]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-12 11:42:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-11 20:10:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{4E30322B-F709-43A0-9587-596D13591BCF}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-11 16:11:55
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\securenet.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-11 16:14:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-11 20:14:28
Pre-Run: 47,025,160,192 octets libres
Post-Run: 47,745,122,304 octets libres
229 --- E O F --- 2008-06-06 04:49:17