ComboFix 08-08-04.01 - Benoit 2008-08-05 9:42:54.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2586 [GMT 2:00]
Endroit: C:\Documents and Settings\Benoit\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Benoit\Application Data\macromedia\Flash Player\#SharedObjects\SMZTT6GF\iforex.com
C:\Documents and Settings\Benoit\Application Data\macromedia\Flash Player\#SharedObjects\SMZTT6GF\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Benoit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Benoit\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\codec.exe
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\bdvokybu.dll
C:\WINDOWS\system32\Ijklknpo.ini
C:\WINDOWS\system32\Ijklknpo.ini2
C:\WINDOWS\system32\opnklkjI.dll
C:\WINDOWS\system32\tuvUOFYq.dll
C:\WINDOWS\system32\WinCtrl32.dl_
C:\WINDOWS\system32\WinCtrl32.dll
C:\WINDOWS\system32\xedmsk.dll
C:\WINDOWS\system32\yiqopcvx.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-05 to 2008-08-05 ))))))))))))))))))))))))))))))))))))
.
2008-08-05 09:23 . 2008-08-05 09:23 99,200 --a------ C:\WINDOWS\system32\xvcpoqiy.dll
2008-08-04 13:35 . 2008-08-04 13:35 <REP> d-------- C:\Program Files\Trend Micro
2008-08-04 12:39 . 2008-08-04 12:39 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-04 12:39 . 2008-08-04 12:39 <REP> d-------- C:\Documents and Settings\Benoit\Application Data\Malwarebytes
2008-08-04 12:39 . 2008-08-04 12:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 12:39 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-04 12:39 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-04 08:52 . 2005-01-02 02:00 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-08-04 08:52 . 2004-11-24 03:37 <REP> d-------- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-08-04 08:52 . 2004-11-24 03:37 <REP> d-------- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-08-04 08:52 . 2007-04-19 23:43 <REP> d-------- C:\Documents and Settings\Administrateur\ModŠles
2008-08-04 08:52 . 2004-11-25 05:26 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-08-04 08:52 . 2004-11-25 05:26 <REP> d-------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-08-04 08:52 . 2007-04-19 15:59 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-08-04 08:52 . 2005-01-02 02:06 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-08-04 08:52 . 2005-01-02 02:18 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-08-04 08:52 . 2005-01-02 02:11 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2008-08-04 08:52 . 2005-01-02 02:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2008-08-04 08:52 . 2008-08-04 08:52 <REP> d-------- C:\Documents and Settings\Administrateur
2008-08-04 08:33 . 2008-08-04 08:33 130,432 --------- C:\WINDOWS\system32\jujmzg.dll
2008-08-04 08:27 . 2008-08-05 09:51 31,616 --a------ C:\WINDOWS\system32\drivers\Winyh42.sys
2008-07-24 13:02 . 2008-08-01 11:32 65,536 --a------ C:\WINDOWS\Setup_ver1.1394.0.exe
2008-07-21 08:46 . 2008-07-21 08:46 <REP> d-------- C:\Program Files\MIKSOFT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-05 07:53 --------- d-----w C:\Documents and Settings\Benoit\Application Data\Skype
2008-08-05 07:52 --------- d-----w C:\Documents and Settings\Benoit\Application Data\BitTorrent
2008-08-05 07:49 --------- d-----w C:\Documents and Settings\Benoit\Application Data\DNA
2008-08-04 07:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-29 11:47 --------- d-----w C:\Program Files\FlashFXP
2008-07-19 16:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-02-05 11:38 1,454 ----a-w C:\Program Files\log.txt
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:07 1289000]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29 165784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-07-02 17:10 23237416]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-18 20:08 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 20:00 15360]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"SeeUrank"="C:\Program Files\Yooda\SeeUrankV3\SeeUrank.exe" [2008-07-01 12:14 4620800]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-12 16:17 289088]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2008-05-12 16:18 587568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 21:02 61440]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2004-10-25 23:17 90112]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-04-19 16:30 949376]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"BigDog305"="C:\WINDOWS\VM305_STI.EXE" [2005-08-05 16:15 61440]
"ecd566f8"="C:\WINDOWS\system32\xvcpoqiy.dll" [2008-08-05 09:23 99200]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=jujmzg.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winyh42.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 Winyh42;Winyh42;C:\WINDOWS\system32\Drivers\Winyh42.sys [2008-08-05 09:51]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
R3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\WlanUIG.sys [2004-08-13 17:15]
R3 ZSMC0305;Look 316;C:\WINDOWS\system32\Drivers\usbVM305.sys [2006-08-02 19:20]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MsnMsgr - ~C:\Program Files\Windows Live\Messenger\msnmsgr.exe
HKCU-Run-AdobeUpdater - C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
HKLM-Run-Recguard - C:\WINDOWS\SMINST\RECGUARD.EXE
HKLM-Run-LSBWatcher - c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
Notify-WgaLogon - (no file)
Notify-WinCtrl32 - WinCtrl32.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Benoit\Application Data\Mozilla\Firefox\Profiles\1xz9xkxv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-05 09:52:41
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\WinCtrl32.dll
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-05 9:57:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-05 07:57:24
Pre-Run: 100,300,189,696 octets libres
Post-Run: 102,534,307,840 octets libres
161 --- E O F --- 2008-07-19 16:59:53