Voici le rapport Combofix :
ComboFix 08-09-03.06 - Administrateur 2008-09-05 18:56:06.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.616 [GMT 2:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrateur\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\pure coal bone thunk
C:\Documents and Settings\All Users\Application Data\pure coal bone thunk\Hide Amen.exe
C:\Documents and Settings\Lotfi\Application Data\DATA ROAD NOUN
C:\Documents and Settings\Lotfi\Application Data\DATA ROAD NOUN\[u]0/u
C:\Program Files\DATA ROAD NOUN
C:\Program Files\SAV
C:\Program Files\SAV\sav.cpl
C:\Program Files\SAV\sav.exe
C:\Program Files\SAV\sav0.dat
C:\Program Files\SAV\sav1.dat
C:\WINDOWS\sxmaokgf.exe
C:\WINDOWS\system32\cepsetup.exe
C:\WINDOWS\system32\msxml71.dll
C:\WINDOWS\system32\sav.cpl
C:\WINDOWS\system32\zwbsxkhk.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-05 to 2008-09-05 ))))))))))))))))))))))))))))))))))))
.
2008-09-05 18:26 . 2008-09-05 18:44 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-05 18:21 . 2008-09-05 18:21 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-05 18:21 . 2008-09-05 18:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-05 18:21 . 2008-09-05 18:21 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-09-05 18:21 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-05 18:21 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-05 18:19 . 2008-09-05 18:19 <REP> d-------- C:\Program Files\Avira
2008-09-05 18:19 . 2008-09-05 18:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-09-01 20:26 . 2008-09-05 18:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\tctsdybq
2008-09-01 20:25 . 2008-09-01 20:25 <REP> d-------- C:\Documents and Settings\Lotfi\Application Data\TmpRecentIcons
2008-08-31 00:38 . 2008-05-01 16:31 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-31 00:30 . 2008-08-31 00:30 <REP> d-------- C:\Documents and Settings\Lotfi\Application Data\Syntrillium
2008-08-31 00:29 . 2001-10-19 14:40 1,683,792 --a------ C:\WINDOWS\system32\wmvcore2.dll
2008-08-31 00:29 . 2001-10-19 14:40 665,424 --a------ C:\WINDOWS\system32\wmv8dmoe.dll
2008-08-31 00:29 . 2001-10-19 14:39 572,752 --a------ C:\WINDOWS\system32\wmvdmoe.dll
2008-08-31 00:29 . 2001-10-19 14:40 438,608 --a------ C:\WINDOWS\system32\wmv8dmod.dll
2008-08-31 00:29 . 2001-10-19 02:05 285,184 --a------ C:\WINDOWS\system32\wmidx2.ocx
2008-08-31 00:29 . 2008-08-31 00:29 156,910 --a------ C:\WINDOWS\WMSysPr8.prx
2008-08-31 00:27 . 2008-08-31 00:29 <REP> d-------- C:\Program Files\coolpro2
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 16:11 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-05 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-31 13:24 --------- d-----w C:\Program Files\AIDA32 - Personal System Information
2008-08-30 13:48 --------- d-----w C:\Program Files\MSN Messenger
2008-08-30 13:48 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-03 18:51 --------- d-----w C:\Program Files\Guitar Pro 5
2008-08-03 18:46 --------- d-----w C:\Program Files\Windows Media Components
2008-08-03 18:42 --------- d-----w C:\Program Files\Kellogg's
2008-08-03 11:08 --------- d-----w C:\Documents and Settings\Lotfi\Application Data\FaxCtr
2008-08-03 10:29 --------- d-----w C:\Program Files\Lx_cats
2008-08-03 09:41 --------- d-----w C:\Program Files\Lexmark_P910 Series
2008-08-03 09:41 --------- d-----w C:\Program Files\Lexmark P910 Series
2008-08-03 09:40 --------- d-----w C:\Program Files\Lexmark Fax Solutions
2008-08-03 09:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-08-01 10:07 --------- d-----w C:\Documents and Settings\Lotfi\Application Data\dvdcss
2008-07-30 10:51 --------- d-----w C:\Program Files\Electronic Arts
2008-07-24 14:24 --------- d-----w C:\Documents and Settings\Lotfi\Application Data\LimeWire
2008-07-21 13:02 --------- d-----w C:\Program Files\Fichiers communs\SWF Studio
2008-07-16 11:56 --------- d-----w C:\Program Files\Common Files
2008-07-09 11:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\SimCity Societies
2007-12-19 14:48 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-05_17.58.47.62 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-18 14:32:57 450,560 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\SP2QFE\jscript.dll
+ 2007-12-18 14:32:57 417,792 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\SP2QFE\vbscript.dll
+ 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\spmsg.dll
+ 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\spuninst.exe
+ 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\update\spcustom.dll
+ 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\update\update.exe
+ 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB944338-v2\update\updspapi.dll
+ 2008-07-07 20:28:20 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3GDR\es.dll
+ 2008-07-07 20:24:11 253,952 ----a-w C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll
+ 2007-11-30 12:39:29 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spmsg.dll
+ 2007-11-30 12:39:29 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB950974\spuninst.exe
+ 2007-11-30 12:39:29 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\spcustom.dll
+ 2007-11-30 12:39:26 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\update.exe
+ 2007-11-30 12:39:29 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB950974\update\updspapi.dll
+ 2008-07-14 11:03:00 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP2QFE\tzchange.exe
+ 2008-07-11 12:42:28 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3GDR\tzchange.exe
+ 2008-07-11 12:51:51 62,976 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe
+ 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spmsg.dll
+ 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\spuninst.exe
+ 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\spcustom.dll
+ 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\update.exe
+ 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB951072-v2\update\updspapi.dll
+ 2008-06-24 16:30:27 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP2QFE\mscms.dll
+ 2008-06-24 16:44:02 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3GDR\mscms.dll
+ 2008-06-24 16:53:52 74,240 ----a-w C:\WINDOWS\$hf_mig$\KB952954\SP3QFE\mscms.dll
+ 2007-11-30 11:19:06 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spmsg.dll
+ 2007-11-30 11:19:06 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB952954\spuninst.exe
+ 2007-11-30 11:19:06 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\spcustom.dll
+ 2007-11-30 12:39:29 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\update.exe
+ 2007-11-30 12:39:31 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB952954\update\updspapi.dll
+ 2008-06-23 15:10:27 3,088,384 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\mshtml.dll
+ 2008-06-26 08:13:32 1,499,648 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\shdocvw.dll
+ 2008-06-26 08:13:32 620,544 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\urlmon.dll
+ 2008-06-23 15:10:27 670,208 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3GDR\wininet.dll
+ 2008-06-25 04:26:28 3,088,896 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\mshtml.dll
+ 2008-06-26 08:00:28 1,499,648 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\shdocvw.dll
+ 2008-06-26 08:00:28 620,544 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\urlmon.dll
+ 2008-06-23 14:56:26 670,720 ----a-w C:\WINDOWS\$hf_mig$\KB953838\SP3QFE\wininet.dll
+ 2007-11-30 12:39:29 18,296 ----a-w C:\WINDOWS\$hf_mig$\KB953838\spmsg.dll
+ 2007-11-30 12:39:29 234,872 ----a-w C:\WINDOWS\$hf_mig$\KB953838\spuninst.exe
+ 2007-11-30 12:39:29 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB953838\update\spcustom.dll
+ 2007-11-30 12:39:26 767,352 ----a-w C:\WINDOWS\$hf_mig$\KB953838\update\update.exe
+ 2007-11-30 12:39:29 406,392 ----a-w C:\WINDOWS\$hf_mig$\KB953838\update\updspapi.dll
- 2007-06-12 10:15:57 248,632 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2008-09-05 16:00:09 250,928 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2007-06-12 10:15:57 248,632 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0/u0002105501100000000000000F01FEC\12.0.4518\PPTPIA.DLL
+ 2007-08-24 03:00:34 1,767,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0/u00021090200C0400000000000F01FEC\12.0.6215\PPCNV.DLL
+ 2007-08-24 03:00:48 72,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0/u00021090200C0400000000000F01FEC\12.0.6215\PXBCOM.EXE
+ 2006-10-27 13:04:06 465,200 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0/u0002119130000000000000000F01FEC\12.0.4518\POWERPNT.EXE
+ 2006-10-27 13:04:06 7,980,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\[u]0/u0002119130000000000000000F01FEC\12.0.4518\PPCORE.DLL
- 2007-06-12 10:23:20 217,864 ----a-r C:\WINDOWS\Installer\{50120000-1105-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-05 16:00:10 217,864 ----a-r C:\WINDOWS\Installer\{50120000-1105-0000-0000-0000000FF1CE}\misc.exe
- 2008-07-20 01:01:54 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-09-05 16:03:30 1,165,584 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2008-07-20 01:01:54 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-09-05 16:03:31 20,240 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-07-20 01:01:54 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-09-05 16:03:30 159,504 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2008-07-20 01:01:54 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-05 16:03:31 217,864 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2008-07-20 01:01:54 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-09-05 16:03:31 18,704 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-07-20 01:01:54 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-09-05 16:03:31 35,088 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-07-20 01:01:54 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-09-05 16:03:30 845,584 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2008-07-20 01:01:54 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-09-05 16:03:31 922,384 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2008-07-20 01:01:54 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-09-05 16:03:31 272,648 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-07-20 01:01:54 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-09-05 16:03:31 888,080 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-07-20 01:01:54 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-09-05 16:03:30 1,172,240 ----a-r C:\WINDOWS\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-08-30 12:37:37 38,240 ----a-r C:\WINDOWS\Installer\{90120000-0020-040C-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2008-09-05 16:02:38 38,240 ----a-r C:\WINDOWS\Installer\{90120000-0020-040C-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-07-20 01:01:39 1,165,584 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-09-05 16:03:13 1,165,584 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\accicons.exe
- 2008-07-20 01:01:39 20,240 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-09-05 16:03:13 20,240 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-07-20 01:01:39 217,864 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\misc.exe
+ 2008-09-05 16:03:13 217,864 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\misc.exe
- 2008-07-20 01:01:39 18,704 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-09-05 16:03:13 18,704 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-07-20 01:01:39 35,088 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-09-05 16:03:13 35,088 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-07-20 01:01:39 845,584 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-09-05 16:03:13 845,584 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\outicon.exe
- 2008-07-20 01:01:39 922,384 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-09-05 16:03:13 922,384 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pptico.exe
- 2008-07-20 01:01:39 272,648 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-09-05 16:03:13 272,648 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\pubs.exe
- 2008-07-20 01:01:39 888,080 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-09-05 16:03:13 888,080 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-07-20 01:01:39 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-09-05 16:03:13 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-0031-0000-0000-0000000FF1CE}\xlicons.exe
- 2007-10-11 05:59:18 1,024,512 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2008-06-23 16:15:33 1,024,512 ----a-w C:\WINDOWS\system32\browseui.dll
- 2007-10-11 05:59:18 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
+ 2008-06-23 16:15:34 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
- 2007-10-11 05:59:21 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
+ 2008-06-23 16:15:35 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
- 2007-10-11 05:59:18 1,024,512 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
+ 2008-06-23 16:15:33 1,024,512 -c----w C:\WINDOWS\system32\dllcache\browseui.dll
- 2007-10-11 05:59:18 152,064 -c----w C:\WINDOWS\system32\dllcache\cdfview.dll
+ 2008-06-23 16:15:34 152,064 -c----w C:\WINDOWS\system32\dllcache\cdfview.dll
- 2007-10-11 05:59:21 1,056,768 -c----w C:\WINDOWS\system32\dllcache\danim.dll
+ 2008-06-23 16:15:35 1,056,768 -c----w C:\WINDOWS\system32\dllcache\danim.dll
- 2007-10-11 05:59:22 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-06-23 16:15:35 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-10-11 05:59:22 205,824 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-06-23 16:15:35 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-07-07 20:18:27 253,952 -c----w C:\WINDOWS\system32\dllcache\es.dll
- 2007-10-11 05:59:22 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-06-23 16:15:35 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-10-10 10:48:23 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2008-06-23 09:53:58 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2007-10-11 05:59:22 251,904 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2008-06-23 16:15:36 251,904 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2007-08-21 06:17:23 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:51:06 683,520 -c----w C:\WINDOWS\system32\dllcache\inetcomm.dll
- 2007-10-11 05:59:22 96,768 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2008-06-23 16:15:36 96,768 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2007-11-14 07:28:02 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2007-12-18 14:41:58 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
- 2007-10-11 05:59:22 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-23 16:15:36 16,384 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-24 16:23:56 74,240 -c----w C:\WINDOWS\system32\dllcache\mscms.dll
- 2007-10-30 14:27:56 3,086,848 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-06-23 16:15:39 3,088,384 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-10-11 05:59:26 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-06-23 16:15:40 449,024 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-10-11 05:59:26 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-06-23 16:15:40 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-10-11 05:59:27 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-06-23 16:15:41 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2007-10-11 05:59:27 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-06-23 16:15:41 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-11 05:59:28 1,498,624 -c----w C:\WINDOWS\system32\dllcache\shdocvw.dll
+ 2008-06-23 16:15:42 1,499,648 -c----w C:\WINDOWS\system32\dllcache\shdocvw.dll
- 2007-10-11 05:59:28 474,624 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
+ 2008-06-23 16:15:43 474,624 -c--a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
- 2007-10-11 05:59:29 620,032 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-06-23 16:15:43 620,544 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2007-12-18 14:41:59 417,792 -c----w C:\WINDOWS\system32\dllcache\vbscript.dll
- 2007-10-11 05:59:29 670,208 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-06-23 16:15:44 671,232 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-05-09 11:15:51 45,376 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 16:11:28 22,336 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-06-27 13:03:55 75,072 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 08:34:22 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
- 2007-10-11 05:59:22 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-06-23 16:15:35 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-10-11 05:59:22 205,824 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-06-23 16:15:35 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2005-07-26 04:29:28 243,200 ----a-w C:\WINDOWS\system32\es.dll
+ 2008-07-07 20:18:27 253,952 ----a-w C:\WINDOWS\system32\es.dll
- 2007-10-11 05:59:22 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-06-23 16:15:35 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2007-10-11 05:59:22 251,904 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2008-06-23 16:15:36 251,904 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2007-08-21 06:17:23 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:51:06 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
- 2007-10-11 05:59:22 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2008-06-23 16:15:36 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
- 2007-11-14 07:28:02 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2007-12-18 14:41:58 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
- 2007-10-11 05:59:22 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-06-23 16:15:36 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2005-06-29 01:49:41 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:23:56 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
- 2007-10-30 14:27:56 3,086,848 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-06-23 16:15:39 3,088,384 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-10-11 05:59:26 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-06-23 16:15:40 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-10-11 05:59:26 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-06-23 16:15:40 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2007-10-11 05:59:27 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-06-23 16:15:41 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2007-10-11 05:59:27 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-06-23 16:15:41 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2007-10-11 05:59:28 1,498,624 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2008-06-23 16:15:42 1,499,648 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2007-10-11 05:59:28 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-06-23 16:15:43 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
- 2007-11-30 12:39:29 18,296 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:19:06 18,296 ------w C:\WINDOWS\system32\spmsg.dll
- 2007-11-13 11:31:11 60,416 ------w C:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 ------w C:\WINDOWS\system32\tzchange.exe
- 2007-10-11 05:59:29 620,032 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-06-23 16:15:43 620,544 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2004-08-05 10:00:00 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2007-12-18 14:41:59 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2007-10-11 05:59:29 670,208 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-06-23 16:15:44 671,232 ----a-w C:\WINDOWS\system32\wininet.dll
- 2007-10-29 15:07:16 369,152 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2008-07-03 09:42:35 370,176 ----a-w C:\WINDOWS\system32\xpsp3res.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-09 191552]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-05 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Bluetooth Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Bluetooth Monitor.lnk
backup=C:\WINDOWS\pss\Bluetooth Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NOAHlinkInstaller.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\NOAHlinkInstaller.lnk
backup=C:\WINDOWS\pss\NOAHlinkInstaller.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^StartSHS6DBs.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\StartSHS6DBs.lnk
backup=C:\WINDOWS\pss\StartSHS6DBs.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^StartSHSDBs.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\StartSHSDBs.lnk
backup=C:\WINDOWS\pss\StartSHSDBs.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2008-03-25 08:38 2196280 C:\Program Files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--------- 2007-01-09 23:23 191552 C:\Program Files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2007-12-12 16:20 21686568 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SharedAccess"=2 (0x2)
"McAfeeFramework"=2 (0x2)
"btwdins"=2 (0x2)
"BthServ"=2 (0x2)
"AVP"=2 (0x2)
"AgereModemAudio"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2638:TCP"= 2638:TCP:ASA_DBE
"2638:UDP"= 2638:UDP:ASA_DBE
"49152:TCP"= 49152:TCP:ASA_DBE
"49152:UDP"= 49152:UDP:ASA_DBE
"7715:TCP"= 7715:TCP:BitComet 7715 TCP
"7715:UDP"= 7715:UDP:BitComet 7715 UDP
"49153:TCP"= 49153:TCP:ASA_DBE
"49153:UDP"= 49153:UDP:ASA_DBE
"20559:TCP"= 20559:TCP:BitComet 20559 TCP
"20559:UDP"= 20559:UDP:BitComet 20559 UDP
R0 tffsport;M-Systems DiskOnChip 2000;C:\WINDOWS\system32\DRIVERS\tffsport.sys [2004-08-03 149376]
R0 Thpdrv;TOSHIBA HDD Protection Driver;C:\WINDOWS\system32\DRIVERS\thpdrv.sys [2007-04-27 21120]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;C:\WINDOWS\system32\DRIVERS\Thpevm.SYS [2007-03-09 6528]
R1 TMEI3E;TMEI3E;C:\WINDOWS\system32\Drivers\TMEI3E.SYS [2004-06-16 5888]
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 30312]
R2 tdudf;TOSHIBA UDF File System Driver;C:\WINDOWS\system32\DRIVERS\tdudf.sys [2007-03-26 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;C:\WINDOWS\system32\DRIVERS\trudf.sys [2007-02-19 134016]
R2 WinRT;WinRT Toolkit Generic Driver;C:\WINDOWS\system32\drivers\WinRT.sys [2000-06-20 100560]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-06-10 35968]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
S3 snpstd2;USB PC Camera (SN9C103);C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-12-16 347264]
S3 TEchoCan;Toshiba Audio Effect;C:\WINDOWS\system32\DRIVERS\TEchoCan.sys [2007-02-21 435072]
*Newly Created Service* - SSMDRV
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-05 19:02:52
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Borland\Interbase\bin\ibguard.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\Program Files\TOSHIBA\TME3\TMESRV31.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\TME3\TMEEJME.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Borland\Interbase\bin\ibserver.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-05 19:07:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-05 17:07:15
ComboFix2.txt 2008-09-05 15:59:43
Pre-Run: 34,732,589,056 octets libres
Post-Run: 34,704,519,168 octets libres
409 --- E O F --- 2008-09-05 16:03:57
:)