Voici les rapports demandés
boFix 08-08-03.03 - maurice2 2008-08-08 20:46:41.8 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.486 [GMT 2:00]
Endroit: C:\Documents and Settings\maurice2\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\maurice2\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_poof
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-08 to 2008-08-08 ))))))))))))))))))))))))))))))))))))
.
2008-08-08 16:20 . 2008-08-08 16:20 2,652 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-08 16:19 . 2008-08-08 16:20 <REP> d-------- C:\SmitfraudFix
2008-08-08 16:19 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-08 16:19 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-08 16:19 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-08 16:19 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-08 16:19 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-08 16:19 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-08 16:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-08 16:19 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-08 16:19 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-08 16:18 . 2008-08-08 16:18 1,479,127 --a------ C:\SmitfraudFix.exe
2008-08-08 15:29 . 2008-08-08 15:29 12,838,445 --a------ C:\upload_moi_MAURICE.tar.gz
2008-08-06 21:35 . 2008-08-08 20:55 3,374,222 --a------ C:\WINDOWS\{00000002-00000000-00000008-00001102-00000002-80651102}.BAK
2008-08-06 21:07 . 2008-08-06 21:07 <REP> d-------- C:\_OTMoveIt
2008-08-05 15:29 . 2008-08-05 15:37 <REP> d-------- C:\Documents and Settings\famille.MAURICE\Application Data\Studio-Scrap
2008-08-05 07:16 . 2008-08-05 07:16 <REP> d--h----- C:\WINDOWS\PIF
2008-08-04 18:50 . 2008-08-04 18:50 <REP> d-------- C:\Program Files\Trend Micro
2008-08-03 13:33 . 2008-08-03 13:33 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-02 15:46 . 2007-11-13 11:44 2,398,720 --a------ C:\WINDOWS\system32\WPTools5_BCB6.bpl
2008-07-28 10:53 . 2008-07-28 10:53 <REP> d-------- C:\Documents and Settings\jessie\Application Data\Malwarebytes
2008-07-26 11:39 . 2008-07-26 11:39 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Documents and Settings\maurice2\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-26 08:30 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-25 09:34 . 2008-07-25 09:34 <REP> d-------- C:\Documents and Settings\maurice2\Application Data\AVGTOOLBAR
2008-07-25 09:33 . 2008-07-25 09:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\Voisinage r‚seau
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\Voisinage d'impression
2008-07-23 08:36 . 2006-12-07 11:52 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\ModŠles
2008-07-23 08:36 . 2008-07-24 07:45 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Mes documents
2008-07-23 08:36 . 2006-12-07 12:37 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Menu D‚marrer
2008-07-23 08:36 . 2008-07-23 08:37 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Favoris
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001\Bureau
2008-07-23 08:36 . 2008-08-06 06:42 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001
2008-07-22 10:09 . 2008-07-22 10:09 <REP> d-------- C:\Program Files\CCleaner
2008-07-21 08:49 . 2008-07-23 08:35 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.000
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 18:41 --------- d-----w C:\Program Files\Wanadoo
2008-08-08 16:59 --------- d-----w C:\Documents and Settings\jessie\Application Data\Studio-Scrap
2008-08-05 13:31 --------- d-----w C:\Program Files\Studio-Scrap
2008-08-03 15:43 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-30 15:35 103,936 ----a-w C:\WINDOWS\system32\yvwyinx.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-04_20.36.31.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-07-19 14:43:08 1,163,960 ----a-w C:\WINDOWS\system32\aswBoot.exe
- 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
+ 2008-07-19 14:30:53 94,392 ----a-w C:\WINDOWS\system32\AVASTSS.scr
- 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-07-19 14:32:15 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
- 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-07-19 14:37:42 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
- 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-07-19 14:37:21 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
- 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-07-19 14:33:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
- 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-07-19 14:35:18 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
- 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-07-19 14:32:36 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
- 2008-08-04 18:25:08 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_4c4.dat
+ 2008-08-08 18:52:55 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_4c4.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A970955-A749-47F0-AD00-DD776594EDAC}]
2008-07-30 17:35 103936 --a------ c:\windows\system32\qdlzvsw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE59BEFC-0358-4F9A-A1F4-4738B60C68EF}]
C:\DOCUME~1\MAURIC~1.MAU\LOCALS~1\Temp\dm4.dll [BU]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 16:27 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]
"AdobeUpdater"="C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 02:00 28672]
"WooCnxMon"="C:\PROGRA~1\Wanadoo\CnxMon.exe" [2004-10-13 17:12 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 12:38 866816]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-10-13 17:12 24576]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 17:12 49152]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 12:00 49152]
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" [2003-07-07 10:30 729088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 18:56 24576 C:\WINDOWS\system32\CTHELPER.EXE]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 17:22 577536 C:\WINDOWS\soundman.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1504:UDP"= 1504:UDP:Windows Media Format SDK (iexplore.exe)
"1505:UDP"= 1505:UDP:Windows Media Format SDK (iexplore.exe)
"1506:UDP"= 1506:UDP:Windows Media Format SDK (iexplore.exe)
"2868:TCP"= 2868:TCP:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
"60541:TCP"= 60541:TCP:@xpsp2res.dll,-22009
"21792:TCP"= 21792:TCP:@xpsp2res.dll,-22009
"45332:TCP"= 45332:TCP:@xpsp2res.dll,-22009
"61312:TCP"= 61312:TCP:@xpsp2res.dll,-22009
"25417:TCP"= 25417:TCP:@xpsp2res.dll,-22009
"53370:TCP"= 53370:TCP:@xpsp2res.dll,-22009
"34321:TCP"= 34321:TCP:@xpsp2res.dll,-22009
"52336:TCP"= 52336:TCP:@xpsp2res.dll,-22009
"47238:TCP"= 47238:TCP:@xpsp2res.dll,-22009
"1559:TCP"= 1559:TCP:@xpsp2res.dll,-22009
"7774:TCP"= 7774:TCP:@xpsp2res.dll,-22009
"10014:TCP"= 10014:TCP:@xpsp2res.dll,-22009
"56959:TCP"= 56959:TCP:@xpsp2res.dll,-22009
"54907:TCP"= 54907:TCP:@xpsp2res.dll,-22009
"37495:TCP"= 37495:TCP:@xpsp2res.dll,-22009
"61063:TCP"= 61063:TCP:@xpsp2res.dll,-22009
"65117:TCP"= 65117:TCP:@xpsp2res.dll,-22009
"3847:TCP"= 3847:TCP:@xpsp2res.dll,-22009
"11842:TCP"= 11842:TCP:@xpsp2res.dll,-22009
"34501:TCP"= 34501:TCP:@xpsp2res.dll,-22009
"34246:TCP"= 34246:TCP:@xpsp2res.dll,-22009
"47053:TCP"= 47053:TCP:@xpsp2res.dll,-22009
"39449:TCP"= 39449:TCP:@xpsp2res.dll,-22009
"1314:TCP"= 1314:TCP:@xpsp2res.dll,-22009
"48839:TCP"= 48839:TCP:@xpsp2res.dll,-22009
"61046:TCP"= 61046:TCP:@xpsp2res.dll,-22009
"18127:TCP"= 18127:TCP:@xpsp2res.dll,-22009
"20818:TCP"= 20818:TCP:@xpsp2res.dll,-22009
"63583:TCP"= 63583:TCP:@xpsp2res.dll,-22009
"38488:TCP"= 38488:TCP:@xpsp2res.dll,-22009
"30344:TCP"= 30344:TCP:@xpsp2res.dll,-22009
"56342:TCP"= 56342:TCP:@xpsp2res.dll,-22009
"42107:TCP"= 42107:TCP:@xpsp2res.dll,-22009
"34150:TCP"= 34150:TCP:@xpsp2res.dll,-22009
"18229:TCP"= 18229:TCP:@xpsp2res.dll,-22009
"33806:TCP"= 33806:TCP:@xpsp2res.dll,-22009
"48692:TCP"= 48692:TCP:@xpsp2res.dll,-22009
"50279:TCP"= 50279:TCP:@xpsp2res.dll,-22009
"63542:TCP"= 63542:TCP:@xpsp2res.dll,-22009
"45636:TCP"= 45636:TCP:@xpsp2res.dll,-22009
"11088:TCP"= 11088:TCP:@xpsp2res.dll,-22009
"37179:TCP"= 37179:TCP:@xpsp2res.dll,-22009
"39770:TCP"= 39770:TCP:@xpsp2res.dll,-22009
"1395:TCP"= 1395:TCP:@xpsp2res.dll,-22009
"49171:TCP"= 49171:TCP:@xpsp2res.dll,-22009
"55075:TCP"= 55075:TCP:@xpsp2res.dll,-22009
"44601:TCP"= 44601:TCP:@xpsp2res.dll,-22009
"57884:TCP"= 57884:TCP:@xpsp2res.dll,-22009
"4097:TCP"= 4097:TCP:@xpsp2res.dll,-22009
"2617:TCP"= 2617:TCP:@xpsp2res.dll,-22009
"63624:TCP"= 63624:TCP:@xpsp2res.dll,-22009
"41270:TCP"= 41270:TCP:@xpsp2res.dll,-22009
"20293:TCP"= 20293:TCP:@xpsp2res.dll,-22009
"19074:TCP"= 19074:TCP:@xpsp2res.dll,-22009
"7484:TCP"= 7484:TCP:@xpsp2res.dll,-22009
"47496:TCP"= 47496:TCP:@xpsp2res.dll,-22009
"62521:TCP"= 62521:TCP:@xpsp2res.dll,-22009
"19576:TCP"= 19576:TCP:@xpsp2res.dll,-22009
"18775:TCP"= 18775:TCP:@xpsp2res.dll,-22009
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 18:07]
R0 mfchtxkj;mfchtxkj;C:\WINDOWS\system32\drivers\mfchtxkj.sys [2006-03-02 14:00]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
S3 FXDRV;FXDRV;D:\Fxdrv.sys []
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-08-09 06:00]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-05-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 15:21]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-08 20:53:42
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\DOCUME~1\maurice2\LOCALS~1\Temp\RGI1.tmp 7136 bytes
C:\Documents and Settings\maurice2\Application Data\Microsoft\Modèles\~$Normal.dot
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-08 20:58:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 18:58:39
ComboFix2.txt 2008-08-06 05:23:05
ComboFix3.txt 2008-08-04 18:37:09
ComboFix4.txt 2008-08-03 08:35:03
Pre-Run: 35,693,510,656 octets libres
Post-Run: 35,754,213,376 octets libres
233 --- E O F --- 2008-07-09 07:08:11
Rapport hijackthis
LogboFix 08-08-03.03 - maurice2 2008-08-08 20:46:41.8 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.486 [GMT 2:00]
Endroit: C:\Documents and Settings\maurice2\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\maurice2\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_poof
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-08 to 2008-08-08 ))))))))))))))))))))))))))))))))))))
.
2008-08-08 16:20 . 2008-08-08 16:20 2,652 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-08 16:19 . 2008-08-08 16:20 <REP> d-------- C:\SmitfraudFix
2008-08-08 16:19 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-08 16:19 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-08 16:19 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-08 16:19 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-08 16:19 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-08 16:19 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-08 16:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-08 16:19 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-08 16:19 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-08 16:18 . 2008-08-08 16:18 1,479,127 --a------ C:\SmitfraudFix.exe
2008-08-08 15:29 . 2008-08-08 15:29 12,838,445 --a------ C:\upload_moi_MAURICE.tar.gz
2008-08-06 21:35 . 2008-08-08 20:55 3,374,222 --a------ C:\WINDOWS\{00000002-00000000-00000008-00001102-00000002-80651102}.BAK
2008-08-06 21:07 . 2008-08-06 21:07 <REP> d-------- C:\_OTMoveIt
2008-08-05 15:29 . 2008-08-05 15:37 <REP> d-------- C:\Documents and Settings\famille.MAURICE\Application Data\Studio-Scrap
2008-08-05 07:16 . 2008-08-05 07:16 <REP> d--h----- C:\WINDOWS\PIF
2008-08-04 18:50 . 2008-08-04 18:50 <REP> d-------- C:\Program Files\Trend Micro
2008-08-03 13:33 . 2008-08-03 13:33 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-02 15:46 . 2007-11-13 11:44 2,398,720 --a------ C:\WINDOWS\system32\WPTools5_BCB6.bpl
2008-07-28 10:53 . 2008-07-28 10:53 <REP> d-------- C:\Documents and Settings\jessie\Application Data\Malwarebytes
2008-07-26 11:39 . 2008-07-26 11:39 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Documents and Settings\maurice2\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-26 08:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-26 08:30 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-26 08:30 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-25 09:34 . 2008-07-25 09:34 <REP> d-------- C:\Documents and Settings\maurice2\Application Data\AVGTOOLBAR
2008-07-25 09:33 . 2008-07-25 09:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\Voisinage r‚seau
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\Voisinage d'impression
2008-07-23 08:36 . 2006-12-07 11:52 <REP> d--h----- C:\Documents and Settings\maurice2_2.MAURICE.001\ModŠles
2008-07-23 08:36 . 2008-07-24 07:45 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Mes documents
2008-07-23 08:36 . 2006-12-07 12:37 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Menu D‚marrer
2008-07-23 08:36 . 2008-07-23 08:37 <REP> dr------- C:\Documents and Settings\maurice2_2.MAURICE.001\Favoris
2008-07-23 08:36 . 2006-12-07 12:37 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001\Bureau
2008-07-23 08:36 . 2008-08-06 06:42 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.001
2008-07-22 10:09 . 2008-07-22 10:09 <REP> d-------- C:\Program Files\CCleaner
2008-07-21 08:49 . 2008-07-23 08:35 <REP> d-------- C:\Documents and Settings\maurice2_2.MAURICE.000
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 18:41 --------- d-----w C:\Program Files\Wanadoo
2008-08-08 16:59 --------- d-----w C:\Documents and Settings\jessie\Application Data\Studio-Scrap
2008-08-05 13:31 --------- d-----w C:\Program Files\Studio-Scrap
2008-08-03 15:43 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-30 15:35 103,936 ----a-w C:\WINDOWS\system32\yvwyinx.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-04_20.36.31.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-07-19 14:43:08 1,163,960 ----a-w C:\WINDOWS\system32\aswBoot.exe
- 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
+ 2008-07-19 14:30:53 94,392 ----a-w C:\WINDOWS\system32\AVASTSS.scr
- 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-07-19 14:32:15 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
- 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-07-19 14:37:42 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
- 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-07-19 14:37:21 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
- 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-07-19 14:33:42 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
- 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-07-19 14:35:18 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
- 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-07-19 14:32:36 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
- 2008-08-04 18:25:08 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_4c4.dat
+ 2008-08-08 18:52:55 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_4c4.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A970955-A749-47F0-AD00-DD776594EDAC}]
2008-07-30 17:35 103936 --a------ c:\windows\system32\qdlzvsw.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE59BEFC-0358-4F9A-A1F4-4738B60C68EF}]
C:\DOCUME~1\MAURIC~1.MAU\LOCALS~1\Temp\dm4.dll [BU]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-20 16:27 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]
"AdobeUpdater"="C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 10:37 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00 90112]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 02:00 28672]
"WooCnxMon"="C:\PROGRA~1\Wanadoo\CnxMon.exe" [2004-10-13 17:12 24576]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 12:38 866816]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-10-13 17:12 24576]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 17:12 49152]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 12:00 49152]
"OPSE reminder"="C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" [2003-07-07 10:30 729088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 18:56 24576 C:\WINDOWS\system32\CTHELPER.EXE]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 17:22 577536 C:\WINDOWS\soundman.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\msncall.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1504:UDP"= 1504:UDP:Windows Media Format SDK (iexplore.exe)
"1505:UDP"= 1505:UDP:Windows Media Format SDK (iexplore.exe)
"1506:UDP"= 1506:UDP:Windows Media Format SDK (iexplore.exe)
"2868:TCP"= 2868:TCP:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:@xpsp2res.dll,-22009
"60541:TCP"= 60541:TCP:@xpsp2res.dll,-22009
"21792:TCP"= 21792:TCP:@xpsp2res.dll,-22009
"45332:TCP"= 45332:TCP:@xpsp2res.dll,-22009
"61312:TCP"= 61312:TCP:@xpsp2res.dll,-22009
"25417:TCP"= 25417:TCP:@xpsp2res.dll,-22009
"53370:TCP"= 53370:TCP:@xpsp2res.dll,-22009
"34321:TCP"= 34321:TCP:@xpsp2res.dll,-22009
"52336:TCP"= 52336:TCP:@xpsp2res.dll,-22009
"47238:TCP"= 47238:TCP:@xpsp2res.dll,-22009
"1559:TCP"= 1559:TCP:@xpsp2res.dll,-22009
"7774:TCP"= 7774:TCP:@xpsp2res.dll,-22009
"10014:TCP"= 10014:TCP:@xpsp2res.dll,-22009
"56959:TCP"= 56959:TCP:@xpsp2res.dll,-22009
"54907:TCP"= 54907:TCP:@xpsp2res.dll,-22009
"37495:TCP"= 37495:TCP:@xpsp2res.dll,-22009
"61063:TCP"= 61063:TCP:@xpsp2res.dll,-22009
"65117:TCP"= 65117:TCP:@xpsp2res.dll,-22009
"3847:TCP"= 3847:TCP:@xpsp2res.dll,-22009
"11842:TCP"= 11842:TCP:@xpsp2res.dll,-22009
"34501:TCP"= 34501:TCP:@xpsp2res.dll,-22009
"34246:TCP"= 34246:TCP:@xpsp2res.dll,-22009
"47053:TCP"= 47053:TCP:@xpsp2res.dll,-22009
"39449:TCP"= 39449:TCP:@xpsp2res.dll,-22009
"1314:TCP"= 1314:TCP:@xpsp2res.dll,-22009
"48839:TCP"= 48839:TCP:@xpsp2res.dll,-22009
"61046:TCP"= 61046:TCP:@xpsp2res.dll,-22009
"18127:TCP"= 18127:TCP:@xpsp2res.dll,-22009
"20818:TCP"= 20818:TCP:@xpsp2res.dll,-22009
"63583:TCP"= 63583:TCP:@xpsp2res.dll,-22009
"38488:TCP"= 38488:TCP:@xpsp2res.dll,-22009
"30344:TCP"= 30344:TCP:@xpsp2res.dll,-22009
"56342:TCP"= 56342:TCP:@xpsp2res.dll,-22009
"42107:TCP"= 42107:TCP:@xpsp2res.dll,-22009
"34150:TCP"= 34150:TCP:@xpsp2res.dll,-22009
"18229:TCP"= 18229:TCP:@xpsp2res.dll,-22009
"33806:TCP"= 33806:TCP:@xpsp2res.dll,-22009
"48692:TCP"= 48692:TCP:@xpsp2res.dll,-22009
"50279:TCP"= 50279:TCP:@xpsp2res.dll,-22009
"63542:TCP"= 63542:TCP:@xpsp2res.dll,-22009
"45636:TCP"= 45636:TCP:@xpsp2res.dll,-22009
"11088:TCP"= 11088:TCP:@xpsp2res.dll,-22009
"37179:TCP"= 37179:TCP:@xpsp2res.dll,-22009
"39770:TCP"= 39770:TCP:@xpsp2res.dll,-22009
"1395:TCP"= 1395:TCP:@xpsp2res.dll,-22009
"49171:TCP"= 49171:TCP:@xpsp2res.dll,-22009
"55075:TCP"= 55075:TCP:@xpsp2res.dll,-22009
"44601:TCP"= 44601:TCP:@xpsp2res.dll,-22009
"57884:TCP"= 57884:TCP:@xpsp2res.dll,-22009
"4097:TCP"= 4097:TCP:@xpsp2res.dll,-22009
"2617:TCP"= 2617:TCP:@xpsp2res.dll,-22009
"63624:TCP"= 63624:TCP:@xpsp2res.dll,-22009
"41270:TCP"= 41270:TCP:@xpsp2res.dll,-22009
"20293:TCP"= 20293:TCP:@xpsp2res.dll,-22009
"19074:TCP"= 19074:TCP:@xpsp2res.dll,-22009
"7484:TCP"= 7484:TCP:@xpsp2res.dll,-22009
"47496:TCP"= 47496:TCP:@xpsp2res.dll,-22009
"62521:TCP"= 62521:TCP:@xpsp2res.dll,-22009
"19576:TCP"= 19576:TCP:@xpsp2res.dll,-22009
"18775:TCP"= 18775:TCP:@xpsp2res.dll,-22009
R0 BsStor;InCD Storage Helper Driver;C:\WINDOWS\system32\DRIVERS\bsstor.sys [2002-06-05 18:07]
R0 mfchtxkj;mfchtxkj;C:\WINDOWS\system32\drivers\mfchtxkj.sys [2006-03-02 14:00]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
S3 FXDRV;FXDRV;D:\Fxdrv.sys []
S4 BsUDF;InCD UDF Driver;C:\WINDOWS\system32\drivers\BsUDF.sys [2002-08-09 06:00]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-05-06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 15:21]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-08 20:53:42
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\DOCUME~1\maurice2\LOCALS~1\Temp\RGI1.tmp 7136 bytes
C:\Documents and Settings\maurice2\Application Data\Microsoft\Modèles\~$Normal.dot
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-08 20:58:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 18:58:39
ComboFix2.txt 2008-08-06 05:23:05
ComboFix3.txt 2008-08-04 18:37:09
ComboFix4.txt 2008-08-03 08:35:03
Pre-Run: 35,693,510,656 octets libres
Post-Run: 35,754,213,376 octets libres
233 --- E O F --- 2008-07-09 07:08:11