ComboFix 08-10-16.08 - Mehdi 2008-10-18 4:44:03.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.692 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Mehdi\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\MSINET.oca
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-18 au 2008-10-18 ))))))))))))))))))))))))))))))))))))
.
2008-10-18 04:29 . 2007-12-16 17:49 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-10-18 04:29 . 2007-12-16 17:49 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-10-18 04:29 . 2007-12-16 17:57 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-10-18 04:29 . 2007-12-16 17:49 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-10-18 04:29 . 2007-12-16 17:49 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-10-18 04:29 . 2007-12-16 17:49 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-10-18 04:29 . 2008-01-12 04:46 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-10-18 04:29 . 2008-10-18 04:29 <REP> d-------- C:\Documents and Settings\Administrateur
2008-10-18 04:19 . 2008-10-18 04:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-18 04:19 . 2008-10-18 04:19 <REP> d-------- C:\Documents and Settings\Mehdi\Application Data\Malwarebytes
2008-10-18 04:19 . 2008-10-18 04:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-18 04:19 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-18 04:19 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-18 04:01 . 2008-10-18 04:01 <REP> d-------- C:\Program Files\Trend Micro
2008-10-06 03:53 . 2008-10-06 03:53 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-06 03:52 . 2008-10-06 03:52 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-10-02 09:14 . 2008-10-02 09:14 371 --a------ C:\WINDOWS\kaillera.ini
2008-09-30 20:30 . 2008-09-30 20:30 <REP> d-------- C:\Program Files\RAR Password Cracker
2008-09-23 15:36 . 2008-09-23 15:36 <REP> d-------- C:\Program Files\Cyberflix
2008-09-23 15:36 . 2008-09-23 15:36 <REP> d-------- C:\Documents and Settings\Mehdi\WINDOWS
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 02:33 --------- d-----w C:\Program Files\Medor
2008-10-18 02:33 --------- d-----w C:\Program Files\eMule
2008-10-13 19:14 --------- d-----w C:\Documents and Settings\Mehdi\Application Data\OpenOffice.org2
2008-10-07 12:17 --------- d-----w C:\Documents and Settings\Mehdi\Application Data\Skype
2008-10-07 03:17 --------- d-----w C:\Documents and Settings\Mehdi\Application Data\skypePM
2008-10-06 01:52 --------- d-----w C:\Program Files\Skype
2008-09-17 22:00 --------- d-----w C:\Documents and Settings\Mehdi\Application Data\BitTorrent
2008-09-17 16:34 74,752 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-09-17 16:34 290,816 ------w C:\WINDOWS\Setup1.exe
2008-09-15 15:39 1,846,144 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-11 22:28 --------- d-----w C:\Program Files\PokerStars
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-20 05:37 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:44 2,182,400 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:44 2,059,776 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-04-20 00:43 19,896 ----a-w C:\Documents and Settings\Mehdi\Application Data\GDIPFONTCACHEV1.DAT
2008-01-21 19:59 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-15 482760]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-12-01 344064]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-15 185896]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]
C:\Documents and Settings\Mehdi\Menu D‚marrer\Programmes\D‚marrage\
Service Medor.lnk - C:\Program Files\Medor\medor.exe [2007-09-07 2311682]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe [2005-08-16 577597]
Stickies Startup.lnk - C:\Program Files\Stickies\stickies.exe [2008-02-03 593920]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=C:\WINDOWS\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mehdi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\Mehdi\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 20:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-09-20 16:35 202024 C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-02-12 20:10 287040 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2007-05-13 16:57 5308416 C:\Program Files\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileZilla Server Interface]
--a------ 2007-02-27 16:55 937984 C:\Program Files\FileZilla Server\FileZilla Server Interface.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 10:51 1836328 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 16:57 153136 C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-09-23 14:17 21755688 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-01-15 23:34 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a------ 2008-02-07 11:47 361832 C:\Program Files\TomTom HOME 2\HOMERunner.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Medor\\medor.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\WinSCP\\WinSCP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Casino\\bwin Casino\\casino.exe"=
"C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Microsoft Visual Studio\\VB98\\VB6.EXE"=
"C:\\Documents and Settings\\Mehdi\\Bureau\\wazabi\\client\\Wazabi-client.exe"=
"C:\\Documents and Settings\\Mehdi\\Bureau\\wazabi\\serveur\\Wazabi.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14963:TCP"= 14963:TCP:NortonAV
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-10-16 38496]
S3 PEEK5;PEEK5 Protocol Driver;C:\DOCUME~1\Mehdi\Bureau\WINAIR~1\WINAIR~1\PEEK5.SYS [2005-11-12 13184]
S3 WZCOOK;WEP/WPA-PMK key recovery service;C:\Documents and Settings\Mehdi\Bureau\WinAircrack\WinAircrackPack\wzcook.exe [2005-11-12 40960]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f9b2be9-8015-11dd-92f0-0014a5ac1c6e}]
\Shell\AutoRun\command - xvlyb.exe
\Shell\explore\Command - xvlyb.exe
\Shell\open\Command - xvlyb.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b71f5c9e-d82c-11dc-9255-0016d4438700}]
\Shell\AutoRun\command - F:\InstallTomTomHOME.exe
*Newly Created Service* - PROCEXP90
.
- - - - ORPHELINS SUPPRIMES - - - -
Notify-WgaLogon - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Mehdi\Application Data\Mozilla\Firefox\Profiles\uxomocid.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxps://www.etud.insa-toulouse.fr/webmail/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-18 04:48:48
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-18 4:53:05
ComboFix-quarantined-files.txt 2008-10-18 02:52:54
Avant-CF: 17 920 819 200 octets libres
Après-CF: 20,606,861,312 octets libres
183 --- E O F --- 2008-10-15 01:02:03