ComboFix 08-10-30.13 - gerard 2008-10-31 17:49:35.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.625 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\gerard\Bureau\C-Fix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MICROSOFT_WINDOWS_TCP_PROTOCOL
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-28 au 2008-10-31 ))))))))))))))))))))))))))))))))))))
.
2008-10-31 16:33 . 2008-10-31 16:33 <REP> d-------- C:\Program Files\Real
2008-10-31 16:33 . 2008-10-31 16:33 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-10-31 16:33 . 2008-10-31 16:33 <REP> d-------- C:\Program Files\Fichiers communs\Real
2008-10-31 16:33 . 2008-10-31 16:33 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-10-31 16:24 . 2008-10-31 16:24 <REP> d-------- C:\Documents and Settings\gerard\Application Data\vlc
2008-10-31 16:23 . 2008-10-31 16:23 <REP> d-------- C:\Program Files\VideoLAN
2008-10-31 11:19 . 2008-10-31 11:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-31 11:19 . 2008-10-31 11:19 <REP> d-------- C:\Documents and Settings\gerard\Application Data\Malwarebytes
2008-10-31 11:19 . 2008-10-31 11:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-31 11:19 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-31 11:19 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-30 18:49 . 2008-10-30 18:49 <REP> d-------- C:\Program Files\Auslogics
2008-10-30 18:49 . 2008-10-30 18:49 <REP> d-------- C:\Documents and Settings\gerard\Application Data\Auslogics
2008-10-30 15:37 . 2008-10-31 13:35 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-30 15:05 . 2008-10-31 11:19 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-30 15:05 . 2008-10-30 15:05 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-30 15:05 . 2008-10-30 15:05 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-10-30 15:05 . 2008-10-30 15:05 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-30 15:04 . 2008-10-30 15:04 <REP> d-------- C:\Program Files\AVG
2008-10-30 15:04 . 2008-10-30 15:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-30 14:03 . 2008-10-30 15:05 8,192 --a------ C:\Documents and Settings\ADMINI~1
2008-10-30 13:09 . 2008-10-30 13:13 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-10-30 13:09 . 2008-04-13 19:33 33,792 -----c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-10-30 13:04 . 2008-04-13 11:23 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2008-10-30 12:19 . 2008-10-30 12:19 <REP> d-------- C:\WINDOWS\ERUNT
2008-10-30 12:15 . 2008-10-30 12:25 <REP> d-------- C:\SDFix
2008-10-29 19:14 . 2008-10-29 19:14 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2008-10-29 19:04 . 2008-10-30 13:27 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-10-29 19:04 . 2008-04-13 19:33 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-29 19:03 . 2008-10-29 19:03 <REP> d-------- C:\WINDOWS\provisioning
2008-10-29 19:03 . 2008-10-30 13:12 <REP> d-------- C:\WINDOWS\peernet
2008-10-29 18:50 . 2008-10-30 13:13 <REP> d-------- C:\WINDOWS\EHome
2008-10-29 18:47 . 2008-10-29 18:49 <REP> d-------- C:\Program Files\Unlocker
2008-10-29 18:47 . 2008-10-31 13:05 <REP> d-------- C:\Documents and Settings\gerard\Application Data\Desktopicon
2008-10-29 17:40 . 2008-10-29 17:40 <REP> d-------- C:\Program Files\Glary Utilities
2008-10-29 17:40 . 2008-10-29 17:40 <REP> d-------- C:\Documents and Settings\gerard\Application Data\GlarySoft
2008-10-29 17:07 . 2004-03-10 19:01 608,256 -----c--- C:\WINDOWS\system32\dllcache\xpsp2res.dll
2008-10-29 17:07 . 2004-01-10 06:11 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2008-10-29 16:54 . 2008-10-29 16:54 <REP> d-------- C:\WINDOWS\report
2008-10-29 16:54 . 2008-10-29 16:51 20,682,137 --a------ C:\WINDOWS\LPT$VPN.627
2008-10-29 16:51 . 2008-10-29 16:51 <REP> d-------- C:\WINDOWS\AU_Backup
2008-10-29 16:51 . 2008-10-29 16:51 20,682,137 --a------ C:\WINDOWS\VPTNFILE.627
2008-10-29 16:51 . 2008-10-29 16:51 1,960,798 --a------ C:\WINDOWS\tsc.ptn
2008-10-29 16:51 . 2008-10-29 16:51 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
2008-10-29 16:51 . 2008-10-29 16:51 348,229 --a------ C:\WINDOWS\tsc.exe
2008-10-29 16:51 . 2008-10-29 16:51 91,744 --a------ C:\WINDOWS\BPMNT.dll
2008-10-29 16:51 . 2008-10-29 16:51 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2008-10-29 16:51 . 2008-10-29 17:13 823 --a------ C:\WINDOWS\tsc.ini
2008-10-29 16:42 . 2008-10-29 16:51 <REP> d-------- C:\WINDOWS\AU_Temp
2008-10-29 16:42 . 2008-10-29 16:42 <REP> d-------- C:\WINDOWS\AU_Log
2008-10-29 16:42 . 2008-10-29 16:42 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-10-29 16:42 . 2008-10-29 16:42 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-10-29 16:42 . 2008-10-29 16:42 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-10-29 16:42 . 2008-10-29 16:42 170 --a------ C:\WINDOWS\GetServer.ini
2008-10-29 16:12 . 2008-10-29 16:12 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-29 16:12 . 2008-10-30 20:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-29 12:17 . 2008-10-29 12:17 <REP> d-------- C:\WINDOWS\Sun
2008-10-29 09:50 . 2008-10-29 09:51 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-10-28 20:58 . 2008-10-28 20:58 <REP> d-------- C:\Program Files\ma-config.com
2008-10-28 20:58 . 2008-10-28 20:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-10-28 20:24 . 2008-10-28 20:24 <REP> d-------- C:\Program Files\CCleaner
2008-10-28 20:12 . 2008-10-28 20:12 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-10-28 20:04 . 2008-10-30 12:37 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-10-28 20:01 . 2008-10-30 13:12 <REP> d-------- C:\WINDOWS\system32\bits
2008-10-28 20:00 . 2008-10-28 20:00 <REP> d-------- C:\Documents and Settings\gerard\Application Data\OpenOffice.org
2008-10-28 19:56 . 2008-10-28 19:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
2008-10-28 19:48 . 2008-10-28 19:48 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-28 19:45 . 2008-10-28 19:45 <REP> d-------- C:\Program Files\OpenOffice.org 3
2008-10-28 19:45 . 2008-10-28 19:45 <REP> d-------- C:\Program Files\JRE
2008-10-28 19:45 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-10-28 19:45 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-10-28 19:45 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-10-28 19:45 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-10-28 19:45 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-10-28 19:45 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-10-28 19:45 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-10-28 19:45 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-10-28 19:45 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-28 19:44 . 2008-10-28 19:44 <REP> d-------- C:\Program Files\Java
2008-10-28 19:44 . 2008-10-28 19:44 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-10-28 19:44 . 2008-10-28 19:44 <REP> d---s---- C:\Documents and Settings\gerard\UserData
2008-10-28 19:44 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-28 19:42 . 2008-10-28 19:42 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-10-28 19:36 . 2001-09-12 16:21 114,744 --a------ C:\WINDOWS\system32\hpzlnt04.dll
2008-10-28 19:36 . 2008-10-28 19:36 800 --a------ C:\WINDOWS\hpinfo.lnk
2008-10-28 19:35 . 2008-10-28 19:35 376 --a------ C:\WINDOWS\mozregistry.dat
2008-10-28 19:33 . 2008-10-28 19:36 <REP> d-------- C:\Program Files\hp deskjet 845c series
2008-10-28 19:33 . 2008-10-28 19:34 <REP> d-------- C:\Program Files\Hewlett-Packard
2008-10-28 19:30 . 2004-10-20 14:23 21,344 -ra------ C:\WINDOWS\system32\drivers\fbxusb32.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 17:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-28 17:15 --------- d-----w C:\Program Files\AMD
2008-10-28 17:12 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-10-28 17:12 --------- d-----w C:\Program Files\Realtek
2008-10-28 17:12 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-10-28 17:05 --------- d-----w C:\Documents and Settings\gerard\Application Data\InstallShield
2008-10-28 16:59 558,142 ----a-w C:\WINDOWS\java\Packages\jlrnzv5b.zip
2008-10-28 16:59 155,995 ----a-w C:\WINDOWS\java\Packages\r1vrxjlv.zip
2008-10-28 16:59 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-28 16:55 --------- d-----w C:\Program Files\Services en ligne
2008-09-16 00:14 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-09-16 00:11 683,520 ----a-w C:\WINDOWS\system32\divx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="C:\Documents and Settings\gerard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-30 133104]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-12 196608]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-30 7634944]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-30 1234712]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-13 19:34 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-10-30 23:35 7634944 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-10-30 23:35 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-10-30 23:35 1622016 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2008-02-19 08:34 16858112 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"winlogon.exe"=C:\WINDOWS\system32\drivers\winlogon.exe
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-30 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-30 875288]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-30 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-10-30 76040]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-10-28 195752]
.
Contenu du dossier 'Tâches planifiées'
2008-10-31 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Program Files\Glary Utilities\initialize.exe [2008-09-17 16:35]
2008-10-31 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
- C:\Documents and Settings\gerard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-30 18:54]
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-winlogon - C:\WINDOWS\system32\drivers\winlogon.exe
MSConfigStartUp-VTkMgr - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\gerard\Application Data\Mozilla\Firefox\Profiles\tr0khyrj.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-31 17:55:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Heure de fin: 2008-10-31 18:00:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-31 17:00:14
Avant-CF: 28 833 820 672 octets libres
Après-CF: 28,803,653,632 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
212