ComboFix 08-07-31.06 - Utilisateur 2008-08-01 15:09:04.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.701 [GMT 2:00]
Endroit: C:\Documents and Settings\Utilisateur\Bureau\C-Fix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-01 to 2008-08-01 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 23:43 . 2008-07-31 23:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-31 23:43 . 2008-07-31 23:43 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Malwarebytes
2008-07-31 23:43 . 2008-07-31 23:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-31 23:43 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-31 23:43 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-31 20:12 . 2008-07-31 20:12 <REP> d-------- C:\Program Files\Trend Micro
2008-07-31 20:01 . 2008-07-31 20:01 49,810 --a------ C:\kaspersky.html
2008-07-31 18:01 . 2008-07-31 18:01 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-07-31 17:52 . 2008-07-31 17:52 11,374,088 --a------ C:\upload_moi_UTILISAT-294BC4.tar.gz
2008-07-31 17:42 . 2008-07-31 21:19 1,210 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-31 17:24 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-31 17:24 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-31 17:24 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-31 17:24 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-31 17:24 . 2008-07-02 15:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-31 17:24 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-31 17:24 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-31 17:24 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-31 17:24 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-31 16:41 . 2008-07-31 16:59 <REP> d-------- C:\Program Files\EsetOnlineScanner
2008-07-31 13:23 . 2008-07-31 13:23 86 --a------ C:\WINDOWS\wininit.ini
2008-07-31 13:06 . 2008-07-31 13:06 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-31 13:06 . 2008-07-31 20:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-29 14:03 . 2008-07-29 14:03 <REP> d-------- C:\Program Files\CCleaner
2008-07-27 23:40 . 1999-09-10 13:06 45,056 --a------ C:\WINDOWS\system32\wnaspi32.dll
2008-07-27 23:40 . 1999-09-10 13:06 25,244 --a------ C:\WINDOWS\system32\drivers\aspi32.sys
2008-07-27 23:40 . 1999-09-10 13:06 5,600 --a------ C:\WINDOWS\system\winaspi.dll
2008-07-27 23:40 . 1999-09-10 13:06 4,672 --a------ C:\WINDOWS\system\wowpost.exe
2008-07-27 23:32 . 2008-07-27 23:32 268 --ah----- C:\sqmdata17.sqm
2008-07-27 23:32 . 2008-07-27 23:32 244 --ah----- C:\sqmnoopt17.sqm
2008-07-16 16:45 . 2008-07-16 16:45 <REP> d-------- C:\Program Files\Lionhead Studios
2008-07-16 01:45 . 2008-07-16 01:45 268 --ah----- C:\sqmdata15.sqm
2008-07-16 01:45 . 2008-07-16 01:45 244 --ah----- C:\sqmnoopt15.sqm
2008-07-16 01:45 . 2008-07-16 01:45 172 --ah----- C:\sqmnoopt16.sqm
2008-07-16 01:45 . 2008-07-16 01:45 172 --ah----- C:\sqmdata16.sqm
2008-07-11 20:17 . 2002-04-16 16:18 151,552 --a------ C:\badboy.exe
2008-07-11 20:17 . 2002-02-24 11:50 125,440 --a------ C:\fmod.dll
2008-07-11 20:17 . 2000-07-27 02:13 53,760 --a------ C:\zlib.dll
2008-07-11 17:52 . 2006-03-17 13:29 <REP> d-------- C:\Legend of Zelda, The - Link's Awakening
2008-07-09 13:11 . 2008-07-09 13:11 <REP> d-------- C:\WINDOWS\$SQLUninstallSQL2000-KB948110-v8.00.2050-x86-ENU$
2008-07-06 11:51 . 2008-07-06 11:51 268 --ah----- C:\sqmdata14.sqm
2008-07-06 11:51 . 2008-07-06 11:51 244 --ah----- C:\sqmnoopt14.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 12:37 --------- d-----w C:\Program Files\eMule
2008-08-01 12:36 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 12:36 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\OpenOffice.org2
2008-07-31 11:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-28 23:12 --------- d-----w C:\Program Files\Java
2008-07-24 12:39 --------- d-----w C:\Program Files\DivX
2008-07-11 11:46 --------- d-----w C:\Program Files\WinamaxPoker
2008-06-30 22:38 --------- d-----w C:\Program Files\Imperial Casino
2008-06-25 18:25 --------- d-----w C:\Program Files\SAGEM WiFi manager
2008-06-25 18:23 --------- d-----w C:\Program Files\SAGEM
2008-06-25 18:14 --------- d-----w C:\Program Files\Services en ligne
2008-06-25 09:49 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\DeepBurner
2008-06-25 09:38 --------- d-----w C:\Program Files\Astonsoft
2008-06-22 12:14 --------- d-----w C:\Program Files\Monte Cristo
2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 11:55 --------- d-----w C:\Program Files\PC Tools Firewall Plus
2008-06-19 11:39 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\PCToolsFirewallPlus
2008-06-18 19:52 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-06-18 14:24 --------- d-----w C:\Program Files\Fichiers communs\PC Tools
2008-06-17 14:22 --------- d-----w C:\Program Files\PKR
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 12:04 --------- d-----w C:\Program Files\Axon Data
2008-06-11 00:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-06-11 00:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-06-11 00:04 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-06-11 00:04 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-06-10 21:16 --------- d-----w C:\Program Files\SopCast
2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
2005-03-08 21:48 4,311,301 ----a-w C:\Program Files\setup-2.3.0.1.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
"PMCRemote"="C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe" [2007-09-18 13:00 257096]
"PMCLoader"="C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe" [2007-09-27 08:15 109640]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2008-05-14 13:00 5423104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 17:29 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 17:29 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2003-11-10 17:06 406016]
"DXM6Patch_981116"="C:\WINDOWS\p_981116.exe" [1998-11-30 18:04 497376]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2008-03-28 14:37 2598808]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 11:42 90112 C:\WINDOWS\soundman.exe]
"nwiz"="nwiz.exe" [2006-03-09 17:29 1519616 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:33 15360]
C:\Documents and Settings\Utilisateur\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56 393216]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
Utilitaire r‚seau pour SAGEM Wi-Fi 11g USB adapter.lnk - C:\Program Files\SAGEM WiFi manager\WLANUTL.exe [2008-06-25 20:25:49 925696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Fichiers communs\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys [2005-12-06 17:11]
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-03-12 09:30]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\WINDOWS\system32\drivers\pctmp.sys [2008-02-21 08:56]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\WINDOWS\system32\drivers\pctssipc.sys [2008-02-21 08:56]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-04-14 04:34]
R3 3xHybrid;Pinnacle PCTV 100i-110i-300i-310i-MCE;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-11-22 08:53]
R3 PctvVirtualNdis;Pinnacle Virtual Miniport;C:\WINDOWS\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 17:30]
R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2006-01-18 14:08]
S3 ProtoWall;ProtoWall Defender;C:\WINDOWS\system32\DRIVERS\ProtoWall.sys []
S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-04-20 19:36]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-07-25 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:39]
.
- - - - ORPHANS REMOVED - - - -
BHO-{28030FA8-2428-4DE6-B0F3-CE9494E1A412} - (no file)
BHO-{E6A4AE92-D45B-46A0-A96C-F874A1F88E39} - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_2_0_4_13.cab
C:\WINDOWS\Downloaded Program Files\hardwaredetection.inf
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-01 15:10:52
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-01 15:11:50
ComboFix-quarantined-files.txt 2008-08-01 13:11:46
Pre-Run: 192,821,407,744 octets libres
Post-Run: 192,884,461,568 octets libres
182 --- E O F --- 2008-07-09 11:11:50