ComboFix 08-10-11.02 - Acer 2008-10-12 14:20:42.5 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.586 [GMT -12:00]
Lancé depuis: C:\Documents and Settings\Acer\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-13 au 2008-10-13 ))))))))))))))))))))))))))))))))))))
.
2008-10-12 13:09 . 2008-10-12 13:09 <REP> d-------- C:\Documents and Settings\Acer\Application Data\Malwarebytes
2008-10-12 13:08 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-12 13:08 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-12 12:48 . 2008-10-12 12:48 <REP> d-------- C:\_OTMoveIt
2008-10-12 11:57 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-12 11:57 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-12 11:57 . 2008-10-01 15:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-10-12 11:57 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-10-12 11:57 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-12 11:57 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-10-12 11:57 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-10-12 11:57 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-12 11:28 . 2001-08-28 14:00 4,224 --a------ C:\WINDOWS\system32\drivers\beep.sys
2008-10-12 10:57 . 2008-10-12 10:57 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-12 10:57 . 2008-10-12 10:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-12 10:29 . 2008-10-12 10:29 <REP> d-------- C:\Lop SD
2008-10-12 07:50 . 2008-10-12 07:50 <REP> d--hs---- C:\FOUND.049
2008-10-10 12:48 . 2008-10-10 12:48 <REP> d-------- C:\abzpaie
2008-10-09 22:36 . 2008-10-09 22:36 <REP> d-------- C:\Assigest
2008-10-09 11:13 . 2008-10-09 11:13 19,615 --a------ C:\WINDOWS\yxekuli.ban
2008-10-09 11:13 . 2008-10-09 11:13 19,611 --a------ C:\Program Files\Fichiers communs\cijybyhe.sys
2008-10-09 11:13 . 2008-10-09 11:13 18,299 --a------ C:\WINDOWS\system32\liviqimo.reg
2008-10-09 11:13 . 2008-10-09 11:13 17,740 --a------ C:\Program Files\Fichiers communs\woqe.reg
2008-10-09 11:13 . 2008-10-09 11:13 15,696 --a------ C:\WINDOWS\ihadaji.pif
2008-10-09 11:13 . 2008-10-09 11:13 15,685 --a------ C:\WINDOWS\pahep.dl
2008-10-09 11:13 . 2008-10-09 11:13 14,516 --a------ C:\Documents and Settings\All Users\Application Data\okusiliq.sys
2008-10-09 11:13 . 2008-10-09 11:13 14,492 --a------ C:\WINDOWS\system32\byduwuxa.inf
2008-10-09 11:13 . 2008-10-09 11:13 13,777 --a------ C:\WINDOWS\system32\kunygol.sys
2008-10-09 11:13 . 2008-10-09 11:13 12,449 --a------ C:\Documents and Settings\All Users\Application Data\sejan.pif
2008-10-09 11:13 . 2008-10-09 11:13 12,174 --a------ C:\WINDOWS\akac.exe
2008-10-09 11:13 . 2008-10-09 11:13 11,258 --a------ C:\WINDOWS\odutel.dat
2008-10-08 20:35 . 2008-10-08 20:35 <REP> d-------- C:\Program Files\dhahmac
2008-10-08 20:35 . 2008-10-08 20:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nwnyxkbo
2008-10-07 17:26 . 2008-10-07 17:26 <REP> d-------- C:\Documents and Settings\Acer\Application Data\OpenOffice.org2
2008-10-07 17:07 . 2008-10-07 17:07 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-10-02 03:01 . 2008-10-02 03:01 <REP> d-------- C:\Program Files\Tempstrav
2008-09-29 05:57 . 2008-09-29 05:57 <REP> d-------- C:\Program Files\Google
2008-09-16 06:46 . 2008-09-16 06:46 <REP> d-------- C:\Documents and Settings\Acer\Application Data\Apple Computer
2008-09-16 06:38 . 2008-09-16 06:38 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-16 06:38 . 2008-09-16 06:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-13 02:30 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-10-13 00:32 3,392 ----a-w C:\WINDOWS\system32\tmp.reg
2008-10-13 00:21 43,099 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-10-12 04:05 21,916 ----a-w C:\Documents and Settings\Acer\Application Data\wklnhst.dat
2008-10-09 23:13 18,097 ----a-w C:\Program Files\Fichiers communs\arihodese.ban
2008-09-12 13:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-12 13:34 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-07 07:30 --------- d-----w C:\Program Files\WordBiz
2008-08-28 05:21 --------- d-----w C:\Program Files\Interstem
2008-08-19 21:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
2008-08-19 21:47 --------- d-----w C:\Program Files\Elaborate Bytes
2008-08-18 21:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Micro Application
2008-07-19 10:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-19 10:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 10:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 10:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-19 10:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 10:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 10:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-19 10:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 10:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-19 10:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 10:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-19 10:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 10:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-19 10:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-19 10:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-19 10:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-19 10:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2007-11-07 04:28 78,568 ----a-w C:\Documents and Settings\Acer\Application Data\GDIPFONTCACHEV1.DAT
2007-05-25 05:21 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
1998-04-28 11:00 570,128 ----a-w C:\Program Files\Fichiers communs\DAO350.DLL
.
[code]<pre>
----a-w 524,288 2007-06-19 13:24:54 C:\Program Files\Thoosje Sidebar V2.0\Thoosje Sidebar .exe
</pre>/code
((((((((((((((((((((((((((((( snapshot@2008-10-09_12.33.21.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-02-06 20:25:38 340,564 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-10-12 23:12:24 529,804 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 40960]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" [X]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
"SiS Windows KeyHook"="C:\WINDOWS\system32\keyhook.exe" [2005-03-04 32768]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"zzzHPSETUP"="E:\Setup.exe" [N/A]
"Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 49152]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-03 2629632]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-08-19 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-07 C:\WINDOWS\AGRSMMSG.exe]
"SiSPower"="SiSPower.dll" [2005-02-25 C:\WINDOWS\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
C:\Documents and Settings\Acer\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 65536]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-20 180224]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-05-20 155648]
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
Yahoo! Widgets.lnk - C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= C:\Program Files\ffdshow\ffdshow.ax
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"D:\\World of Warcraft\\WoW-1.12.0-frFR-downloader.exe"=
"C:\\Program Files\\Sunbelt Software\\Personal Firewall\\KPF4GUI.EXE"=
"D:\\gnucash\\bin\\gnucash-bin.exe"=
"D:\\gnucash\\bin\\gconfd-2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 pnpshark;pnpshark;C:\WINDOWS\system32\DRIVERS\pnpshark.sys [2003-10-02 119552]
R0 st3shark;st3shark;C:\WINDOWS\system32\DRIVERS\st3shark.sys [2003-09-27 5504]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 302000]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 72624]
R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 43816]
R2 fsssvc;Windows Live OneCare Contrôle parental;C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe [2007-12-17 523816]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-03-04 8704]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 4010]
R2 SPF4;Sunbelt Personal Firewall 4;C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe [2007-04-26 1234480]
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 32768]
S2 EAPPkt;Realtek EAPPkt Protocol;C:\WINDOWS\system32\DRIVERS\EAPPkt.sys [ ]
S3 A4501A;802.11g Wireless USB Adapter Driver;C:\WINDOWS\system32\DRIVERS\A4501A.sys [2005-06-19 349728]
S3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 69632]
S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;C:\WINDOWS\system32\DRIVERS\libusb0.sys [2006-04-22 29184]
S3 ovt530;Webcam Deluxe;C:\WINDOWS\system32\Drivers\ov530vid.sys [ ]
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cf47fe3-50d6-11dc-bcbd-00c09fbc7e3b}]
\Shell\AutoRun\command - Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61b330f8-10a4-11dd-be20-00c09fbc7e3b}]
\Shell\AutoRun\command - F:\
\Shell\explore\Command - RECYCLED\INFO.exe
\Shell\open\Command - RECYCLED\INFO.exe
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Acer\Application Data\Mozilla\Firefox\Profiles\vmxclutg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q=
FF -: plugin - C:\Documents and Settings\Acer\Application Data\Mozilla\Firefox\Profiles\vmxclutg.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npyaxmpb.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 14:30:26
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\SYSTEM32\WLTRYSVC.EXE
C:\WINDOWS\SYSTEM32\BCMWLTRY.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\WLTRAY.EXE
C:\ACER\EMANAGER\ANBMSERV.EXE
C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\GUARD.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\SEARCHINDEXER.EXE
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSCORSVW.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SYSTEM32\IMAPI.EXE
.
**************************************************************************
.
Heure de fin: 2008-10-12 14:35:27 - La machine a redémarré [Acer]
ComboFix-quarantined-files.txt 2008-10-13 02:35:16
ComboFix3.txt 2008-10-10 00:35:12
ComboFix2.txt 2008-10-12 09:48:42
Avant-CF: 347,832,320 octets libres
Après-CF: 325,664,768 octets libres
237 --- E O F --- 2008-09-10 15:07:53