ComboFix 08-11-01.04 - MAES 2008-11-02 12:12:27.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.438 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\MAES\Bureau\C-Fix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\kavo0.dll
C:\WINDOWS\system32\kavo1.dll
C:\yjkjfuo.cmd
D:\Autorun.inf
D:\yjkjfuo.cmd
G:\Autorun.inf
G:\yjkjfuo.cmd
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-02 au 2008-11-02 ))))))))))))))))))))))))))))))))))))
.
2008-11-02 11:49 . 2008-11-02 11:49 <REP> d-------- C:\Program Files\Trend Micro
2008-11-01 17:11 . 2008-04-13 19:33 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-11-01 17:11 . 2001-08-23 17:47 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-11-01 15:18 . 2008-11-01 15:18 <REP> d-------- C:\Documents and Settings\MAES\Application Data\DivX
2008-11-01 15:10 . 2008-11-01 15:12 <REP> d-------- C:\Program Files\DivX
2008-11-01 14:18 . 2008-11-01 14:18 <REP> d-------- C:\Documents and Settings\MAES\Application Data\HP
2008-11-01 13:05 . 2008-11-01 13:05 <REP> d-------- C:\Documents and Settings\MAES\Application Data\Apple Computer
2008-11-01 13:05 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-11-01 13:05 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-11-01 13:04 . 2008-11-01 13:04 <REP> d-------- C:\Program Files\iPod
2008-11-01 13:03 . 2008-11-01 13:05 <REP> d-------- C:\Program Files\iTunes
2008-11-01 13:03 . 2008-11-01 13:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-01 13:02 . 2008-11-01 13:02 <REP> d-------- C:\Program Files\Bonjour
2008-11-01 12:58 . 2008-11-01 13:01 <REP> d-------- C:\Program Files\QuickTime
2008-11-01 12:58 . 2008-11-01 13:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-11-01 12:57 . 2008-11-01 13:05 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-11-01 12:57 . 2008-11-01 12:57 <REP> d-------- C:\Program Files\Apple Software Update
2008-11-01 12:55 . 2008-11-01 12:59 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-11-01 12:55 . 2008-11-01 12:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-11-01 09:14 . 2008-11-01 09:14 <REP> d-------- C:\Program Files\MSXML 4.0
2008-10-31 18:30 . 2008-10-31 18:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-10-31 18:28 . 2008-10-31 18:28 <REP> d-------- C:\Program Files\Fichiers communs\Sonic Shared
2008-10-31 18:28 . 2008-10-31 18:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-10-31 18:27 . 2008-10-31 18:28 <REP> d-------- C:\Program Files\Fichiers communs\HP
2008-10-31 18:25 . 2008-10-31 18:25 <REP> d-------- C:\Program Files\Hewlett-Packard
2008-10-31 18:23 . 2008-10-31 18:24 <REP> d-------- C:\WINDOWS\system32\URTTemp
2008-10-31 18:22 . 2008-10-31 18:22 <REP> d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2008-10-31 18:21 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-10-31 18:21 . 2004-09-29 12:12 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2008-10-31 18:21 . 2004-09-29 12:15 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2008-10-31 18:21 . 2004-09-29 12:09 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2008-10-31 18:21 . 2004-09-29 12:14 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2008-10-31 18:21 . 2004-09-29 12:08 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2008-10-31 18:21 . 2004-09-29 12:09 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2008-10-31 18:17 . 2008-10-31 18:30 <REP> d-------- C:\Program Files\HP
2008-10-31 18:16 . 2005-03-08 06:52 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-10-31 18:15 . 2008-10-31 18:32 90,399 --a------ C:\WINDOWS\hpoins06.dat
2008-10-31 18:15 . 2005-03-15 21:36 77,824 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-10-31 18:15 . 2005-03-08 06:52 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-10-31 18:15 . 2005-06-03 06:53 5,389 --------- C:\WINDOWS\hpomdl06.dat
2008-10-31 18:14 . 2005-05-05 08:51 37,376 --a------ C:\WINDOWS\system32\hpz3l3xu.dll
2008-10-31 18:14 . 2008-04-13 11:47 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-10-31 18:14 . 2008-04-13 11:47 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-10-31 18:14 . 2005-03-08 06:52 21,744 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-10-31 18:12 . 2008-11-02 09:38 <REP> d-------- C:\Program Files\Mozilla Thunderbird
2008-10-31 18:12 . 2005-04-08 04:50 827,392 -ra------ C:\WINDOWS\system32\hpotiop2.dll
2008-10-31 18:12 . 2005-04-08 04:50 278,528 -ra------ C:\WINDOWS\system32\hpowiamd.dll
2008-10-31 18:12 . 2005-03-08 06:49 274,432 -ra------ C:\WINDOWS\system32\HPZc3212.dll
2008-10-31 18:12 . 2005-04-08 04:50 258,122 -ra------ C:\WINDOWS\system32\hpovst09.dll
2008-10-31 18:12 . 2008-04-13 11:45 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-10-31 18:12 . 2008-04-13 11:45 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-10-31 17:54 . 2008-10-31 17:54 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-10-31 17:38 . 2008-10-31 17:38 <REP> d-------- C:\Documents and Settings\MAES\Application Data\FileMaker
2008-10-29 14:48 . 2008-10-29 14:48 <REP> d-------- C:\Documents and Settings\MAES\Application Data\Talkback
2008-10-28 10:00 . 2008-04-13 19:34 92,160 --a------ C:\WINDOWS\system32\kswdmcap.ax
2008-10-28 10:00 . 2008-04-13 19:34 92,160 --a--c--- C:\WINDOWS\system32\dllcache\kswdmcap.ax
2008-10-28 10:00 . 2008-04-13 19:34 61,952 --a------ C:\WINDOWS\system32\kstvtune.ax
2008-10-28 10:00 . 2008-04-13 19:34 61,952 --a--c--- C:\WINDOWS\system32\dllcache\kstvtune.ax
2008-10-28 10:00 . 2008-04-13 19:33 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-28 10:00 . 2008-04-13 19:33 54,784 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2008-10-28 10:00 . 2008-04-13 19:34 43,008 --a------ C:\WINDOWS\system32\ksxbar.ax
2008-10-28 10:00 . 2008-04-13 19:34 43,008 --a--c--- C:\WINDOWS\system32\dllcache\ksxbar.ax
2008-10-28 10:00 . 2008-04-13 19:34 28,672 --a------ C:\WINDOWS\system32\vidcap.ax
2008-10-28 10:00 . 2008-04-13 19:34 28,672 --a--c--- C:\WINDOWS\system32\dllcache\vidcap.ax
2008-10-28 10:00 . 2008-04-13 19:34 20,992 --a------ C:\WINDOWS\system32\dshowext.ax
2008-10-28 10:00 . 2008-04-13 19:34 20,992 --a--c--- C:\WINDOWS\system32\dllcache\dshowext.ax
2008-10-25 15:18 . 2008-10-25 15:18 <REP> d-------- C:\Program Files\Picasa2
2008-10-25 15:18 . 2008-10-25 15:18 <REP> d-------- C:\Program Files\Google
2008-10-25 15:18 . 2006-10-05 03:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-25 15:18 . 2006-10-05 03:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-25 14:48 . 2008-11-02 09:25 <REP> d-------- C:\Documents and Settings\MAES\Application Data\skypePM
2008-10-25 14:48 . 2008-10-25 14:48 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-25 14:46 . 2008-10-25 14:46 <REP> d-------- C:\Program Files\Skype
2008-10-25 14:46 . 2008-10-25 14:46 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2008-10-25 14:46 . 2008-11-02 12:11 <REP> d-------- C:\Documents and Settings\MAES\Application Data\Skype
2008-10-25 14:46 . 2008-10-25 14:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-10-25 12:49 . 2008-10-29 14:48 <REP> d-------- C:\Documents and Settings\MAES\Application Data\Thunderbird
2008-10-25 12:27 . 2008-10-25 12:27 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-25 12:25 . 2008-10-25 12:25 7,606,832 --a------ C:\Firefox Setup 3.0.3.exe
2008-10-25 10:50 . 2008-10-25 10:50 <REP> d-------- C:\Program Files\Alwil Software
2008-10-25 10:44 . 2008-10-25 10:44 27,582,248 --a------ C:\setupfre.exe
2008-10-25 08:38 . 2008-10-25 08:38 <REP> d-------- C:\Program Files\Securitoo
2008-10-25 08:38 . 2008-10-25 08:55 <REP> d-------- C:\Program Files\OrangeHSS
2008-10-25 08:38 . 2006-03-01 17:53 94,208 --a------ C:\WINDOWS\system32\w32n50.dll
2008-10-25 08:38 . 2007-12-11 19:22 65,536 --a------ C:\WINDOWS\system32\Autodial2000.dll
2008-10-25 08:38 . 2003-09-23 09:38 34,688 --a------ C:\WINDOWS\system32\pcampr5.sys
2008-10-25 08:38 . 2006-03-01 17:53 32,128 --a------ C:\WINDOWS\system32\pcandis5.sys
2008-10-25 08:37 . 2008-10-25 08:37 <REP> d-------- C:\Program Files\Fichiers communs\France Telecom
2008-10-25 08:37 . 2003-03-19 04:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-10-25 08:37 . 2003-09-16 07:07 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-10-25 08:37 . 2003-02-21 11:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-10-25 08:37 . 2003-03-19 02:05 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-10-25 08:21 . 2008-04-13 10:45 32,128 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-25 08:21 . 2008-04-13 10:45 32,128 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-15 21:03 . 2008-10-15 21:03 5,208 --a------ C:\WINDOWS\system32\pid.PNF
2008-10-15 21:01 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-02 10:22 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs
2008-10-15 18:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-15 18:24 --------- d-----w C:\Program Files\Realtek AC97
2008-10-15 18:23 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-10-15 18:12 --------- d-----w C:\Program Files\microsoft frontpage
2008-10-15 18:11 --------- d-----w C:\Program Files\Services en ligne
2008-09-16 00:14 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-09-16 00:14 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-09-16 00:12 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-09-16 00:11 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-09-16 00:11 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-09-16 00:11 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-09-16 00:11 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-09-16 00:11 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-09-16 00:11 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-09-16 00:11 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-29 09:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:23 2,191,232 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ORAHSSSessionManager"="C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\yjkjfuo.cmd
\Shell\explore\Command - K:\yjkjfuo.cmd
\Shell\open\Command - K:\yjkjfuo.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{779f3bf4-a7ff-11dd-8a0f-0010dcc624f3}]
\Shell\AutoRun\command - K:\yjkjfuo.cmd
\Shell\explore\Command - K:\yjkjfuo.cmd
\Shell\open\Command - K:\yjkjfuo.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{779f3bf8-a7ff-11dd-8a0f-0010dcc624f3}]
\Shell\AutoRun\command - K:\yjkjfuo.cmd
\Shell\explore\Command - K:\yjkjfuo.cmd
\Shell\open\Command - K:\yjkjfuo.cmd
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\MAES\Application Data\Mozilla\Firefox\Profiles\636z1jle.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.orange.fr/
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Picasa2\npPicasa2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-02 12:13:53
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-02 12:15:27
ComboFix-quarantined-files.txt 2008-11-02 11:15:12
Avant-CF: 142 835 720 192 octets libres
Après-CF: 142,896,275,456 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
245 --- E O F --- 2008-11-02 08:40:31