ComboFix 08-07-30.02 - sylvia 2008-07-31 16:03:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.643 [GMT 2:00]
Endroit: C:\Documents and Settings\sylvia\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\sylvia\Local Settings\Application Data\gsjkltktr.dat
C:\Documents and Settings\sylvia\Local Settings\Application Data\gsjkltktr_nav.dat
C:\Documents and Settings\sylvia\Local Settings\Application Data\gsjkltktr_navps.dat
C:\Program Files\Adssite Games Collection
C:\Program Files\Adssite Games Collection\BattlesOfHelicopters.exe
C:\Program Files\Adssite Games Collection\BobAndBill.exe
C:\Program Files\Adssite Games Collection\CrazyBlocks.exe
C:\Program Files\Adssite Games Collection\Lines.exe
C:\Program Files\Adssite Games Collection\uninstall.exe
C:\Program Files\Adssite Games Collection\VideoPool.exe
C:\WINDOWS\system32\dcads-remove.exe
C:\WINDOWS\system32\superiorads-uninst.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 15:21 . 2008-07-31 15:21 <REP> d-------- C:\WINDOWS\LastGood
2008-07-31 15:05 . 2008-07-31 15:06 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-31 15:05 . 2008-07-31 15:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-31 15:05 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-31 15:05 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 14:39 . 2008-07-31 14:39 <REP> d-------- C:\Deckard
2008-07-31 14:16 . 2008-07-31 14:16 <REP> d-------- C:\Program Files\Trend Micro
2008-07-29 07:20 . 2008-07-29 07:20 <REP> d-------- C:\Program Files\Avira
2008-07-29 07:20 . 2008-07-29 07:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-26 23:08 . 2008-07-26 23:08 5,248 --a------ C:\WINDOWS\system32\giveio.sys
2008-07-26 22:43 . 2008-07-26 23:12 <REP> d-------- C:\Program Files\SSC Service Utility
2008-07-24 09:46 . 2008-07-24 09:46 <REP> d-------- C:\WINDOWS\system32\fr
2008-07-24 09:46 . 2008-07-24 09:46 <REP> d-------- C:\WINDOWS\system32\bits
2008-07-24 09:46 . 2008-07-24 09:46 <REP> d-------- C:\WINDOWS\l2schemas
2008-07-24 09:44 . 2008-07-24 09:46 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-07-24 09:39 . 2008-07-24 09:39 <REP> d-------- C:\WINDOWS\EHome
2008-07-24 09:30 . 2004-08-19 15:53 327,168 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-07-21 16:34 . 2008-07-21 16:34 244 --ah----- C:\sqmnoopt10.sqm
2008-07-21 16:34 . 2008-07-21 16:34 232 --ah----- C:\sqmdata10.sqm
2008-07-15 19:33 . 2008-07-15 19:33 <REP> d-------- C:\Program Files\VideoLAN
2008-07-09 11:36 . 2008-07-09 12:48 <REP> d-------- C:\Casino
2008-07-07 21:22 . 2008-07-07 21:22 <REP> d-------- C:\WINDOWS\system32\inook-v4-3 dir
2008-07-07 21:22 . 2008-07-07 21:22 201,728 --a------ C:\WINDOWS\system32\inook-v4-3.scr
2008-07-07 08:31 . 2008-07-07 08:31 244 --ah----- C:\sqmnoopt09.sqm
2008-07-07 08:31 . 2008-07-07 08:31 232 --ah----- C:\sqmdata09.sqm
2008-07-07 00:16 . 2008-07-07 00:16 244 --ah----- C:\sqmnoopt08.sqm
2008-07-07 00:16 . 2008-07-07 00:16 232 --ah----- C:\sqmdata08.sqm
2008-07-05 19:46 . 2008-07-05 19:46 <REP> d-------- C:\Documents and Settings\sylvia\Application Data\Talkback
2008-07-05 19:24 . 2008-07-05 19:24 1,160 --a------ C:\WINDOWS\mozver.dat
2008-07-05 19:22 . 2008-07-05 19:24 <REP> d-------- C:\Documents and Settings\sylvia\dwhelper
2008-07-05 19:17 . 2008-07-05 19:17 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-05 16:21 . 2008-07-05 16:21 <REP> d-------- C:\Program Files\Microsoft Works
2008-07-05 16:19 . 2008-07-05 16:19 <REP> d-------- C:\Program Files\Microsoft.NET
2008-07-05 16:17 . 2008-07-05 16:17 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-07-05 16:17 . 2008-07-05 16:17 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-07-05 16:16 . 2008-07-05 16:16 <REP> dr-h----- C:\MSOCache
2008-07-05 16:16 . 2008-07-29 13:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-25 20:13 . 2008-06-25 20:13 <REP> d-------- C:\Program Files\Corsair
2008-06-25 20:13 . 2005-09-20 10:30 53,248 -ra------ C:\WINDOWS\system32\IoctlSvc.exe
2008-06-25 20:13 . 2004-02-16 15:09 45,056 -ra------ C:\WINDOWS\system32\HotFixQ0306270.exe
2008-06-25 20:13 . 2004-02-16 15:09 7,424 -ra------ C:\WINDOWS\system32\drivers\plff.sys
2008-06-20 19:47 . 2008-06-20 19:47 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 19:47 . 2008-06-20 19:47 147,968 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 13:51 . 2008-06-20 13:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 13:40 . 2008-06-20 13:40 138,496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 13:08 . 2008-06-20 13:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-11 09:01 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 09:01 . 2008-06-14 19:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 09:01 . 2008-05-08 16:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-07 14:41 . 2008-06-15 21:33 230,424 --a------ C:\snp2sxp-001.raw
2008-06-07 12:01 . 2008-06-07 12:01 244 --ah----- C:\sqmnoopt07.sqm
2008-06-07 12:01 . 2008-06-07 12:01 232 --ah----- C:\sqmdata07.sqm
2008-06-07 11:59 . 2008-06-07 11:59 244 --ah----- C:\sqmnoopt06.sqm
2008-06-07 11:59 . 2008-06-07 11:59 232 --ah----- C:\sqmdata06.sqm
2008-06-05 20:55 . 2008-06-05 21:00 921,624 --a------ C:\snp2sxp-002.raw
2008-06-05 14:52 . 2008-06-05 14:52 0 --a------ C:\CAPTURE.AVI
2008-06-05 14:44 . 2006-06-07 04:34 10,305,280 -ra------ C:\WINDOWS\system32\drivers\snp2sxp.sys
2008-06-05 14:44 . 2006-05-15 09:52 675,840 -ra------ C:\WINDOWS\vsnp2std.exe
2008-06-05 14:44 . 2006-05-04 05:14 61,440 -ra------ C:\WINDOWS\vsnp2std.dll
2008-06-05 14:44 . 2005-11-23 07:55 53,248 -ra------ C:\WINDOWS\system32\csnp2std.dll
2008-06-05 14:44 . 2006-04-27 14:43 24,832 -ra------ C:\WINDOWS\system32\drivers\sncamd.sys
2008-06-05 14:44 . 2004-12-09 11:23 15,497 -ra------ C:\WINDOWS\snp2std.ini
2008-06-05 14:44 . 2004-12-09 11:23 13,022 -ra------ C:\WINDOWS\snp2std.src
2008-06-05 14:39 . 2004-08-09 17:43 94,208 --a------ C:\WINDOWS\amcap.exe
2008-06-04 17:30 . 1999-05-26 09:46 212,480 --a------ C:\WINDOWS\pcdlib32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-30 04:17 --------- d-----w C:\Program Files\InstantTouch
2008-07-28 09:05 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-07-23 09:21 --------- d-----w C:\Program Files\DivX
2008-07-23 09:17 --------- d-----w C:\Documents and Settings\sylvia\Application Data\LimeWire
2008-07-19 18:19 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-07-15 17:34 --------- d-----w C:\Documents and Settings\sylvia\Application Data\vlc
2008-06-25 18:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-24 13:32 --------- d-----w C:\Program Files\LimeWire
2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 11:17 --------- d-----w C:\Program Files\Diner Dash
2008-05-31 20:02 --------- d-----w C:\Program Files\Lavasoft
2008-05-31 20:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-31 20:01 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-31 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-30 17:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-30 17:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-30 17:19 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-30 17:19 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-16 09:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 07:30 131,072 ----a-w C:\WINDOWS\system32\datestamp.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-14 02:50 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 02:37 332,800 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 02:33 98,816 ----a-w C:\WINDOWS\system32\psbase.dll
2008-04-14 02:32 764,416 ----a-w C:\WINDOWS\system32\winntbbu.dll
2008-04-14 02:32 61,471 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 02:32 5,632 ----a-w C:\WINDOWS\system32\wmi.dll
2008-04-14 02:07 2,147,328 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-14 02:07 2,025,984 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-14 02:06 4,096 ----a-w C:\WINDOWS\system32\dsprpres.dll
2008-04-14 02:04 93,184 ----a-w C:\WINDOWS\system32\msxml6r.dll
2008-04-14 02:03 81,920 ------w C:\WINDOWS\system32\msshavmsg.dll
2008-04-14 02:02 50,688 ----a-w C:\WINDOWS\system32\inetres.dll
2008-04-14 02:00 572,416 ----a-w C:\WINDOWS\system32\shdoclc.dll
2008-04-14 01:59 10,240 ----a-w C:\WINDOWS\system32\gpkrsrc.dll
2008-04-14 01:58 1,845,760 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-14 01:58 1,647,616 ----a-w C:\WINDOWS\system32\winbrand.dll
2008-04-14 01:57 70,144 ----a-w C:\WINDOWS\system32\browselc.dll
2008-04-14 01:54 103,936 ----a-w C:\WINDOWS\system32\dpcdll.dll
2008-04-13 18:44 17,664 ----a-w C:\WINDOWS\system32\watchdog.sys
2008-04-13 18:40 445,440 ----a-w C:\WINDOWS\system32\xpob2res.dll
2008-04-13 18:36 2,986,496 ----a-w C:\WINDOWS\system32\xpsp2res.dll
2008-04-13 18:35 24,064 ----a-w C:\WINDOWS\system32\pidgen.dll
2008-04-13 18:35 197,632 ----a-w C:\WINDOWS\system32\xpsp1res.dll
2008-04-13 18:31 7,424 ----a-w C:\WINDOWS\system32\kd1394.dll
2008-04-13 18:30 61,440 ----a-w C:\WINDOWS\system32\msvcrt40.dll
2008-04-13 17:37 208,384 ----a-w C:\WINDOWS\system32\rsaenh.dll
2008-04-13 17:37 138,752 ----a-w C:\WINDOWS\system32\dssenh.dll
2008-04-13 17:34 11,264 ----a-w C:\WINDOWS\system32\spnpinst.exe
2008-04-13 17:33 424,960 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-13 17:33 1,005,056 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\odbcp32r.dll
2008-04-13 17:26 12,288 ----a-w C:\WINDOWS\system32\mscpx32r.dll
2008-04-13 17:21 733,696 ----a-w C:\WINDOWS\system32\qedwipes.dll
2008-04-13 16:45 216,064 ----a-w C:\WINDOWS\system32\moricons.dll
2008-04-13 16:23 48,128 ----a-w C:\WINDOWS\system32\msprivs.dll
2008-04-13 15:39 884,736 ----a-w C:\WINDOWS\system32\msimsg.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-04-21 18:03 94208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 11:58 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2006-05-15 09:52 675840]
"CORSAIR_PLUtil"="C:\Program Files\Corsair\Corsair Flash Voyager Utility\PLBkMon.exe" [2005-11-28 16:11 94208]
"PLFFAP"="C:\WINDOWS\system32\HotfixQ0306270.exe" [2004-02-16 15:09 45056]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"SkyTel"="SkyTel.EXE" [2007-04-04 11:22 1822720 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 09:28 16126464 C:\WINDOWS\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:33 15360]
"EPSON Stylus DX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 08:01 180736]
"EPSON Stylus DX4400 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 08:01 180736]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-31 11:58 68856]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-01-03 00:48:28 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l251x86.sys [2007-06-21 04:44]
R3 PLFF;USB Flash Disk Driver;C:\WINDOWS\system32\Drivers\PLFF.sys [2004-02-16 15:09]
S1 hidfltr;HID Filter Driver;C:\WINDOWS\system32\drivers\MWhid.sys [2006-02-03 12:15]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2006-06-07 04:34]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\sylvia\Application Data\Mozilla\Firefox\Profiles\pea8jlzt.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.ffsearch.net/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-31 16:05:57
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-31 16:06:57
ComboFix-quarantined-files.txt 2008-07-31 14:06:54
Pre-Run: 276,660,703,232 octets libres
Post-Run: 276,977,876,992 octets libres
226 --- E O F --- 2008-07-29 11:05:01