اهلا وسهلا كونغ
التقرير
ComboFix 08-09-15.02 - Administrateur 09/16/2008 3:29:22.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1256.966.1036.18.284 [GMT 0:00]
Lancé depuis: C:\Documents and Settings\Administrateur\UserData\Mes documents\Downloads\Programs\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RةCUPةRATION N'EST PAS INSTALLةE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-16 au 2008-09-16 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 03:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-16 03:45 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\DMCache
2008-09-16 03:35 565,280 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-16 03:35 5,108 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-16 03:35 2,003,488 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-16 03:35 19,876 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-16 03:21 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\SiteAdvisor
2008-09-16 03:14 --------- d-----w C:\Program Files\Startup Manager
2008-09-16 03:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Startup Manager
2008-09-15 21:51 --------- d-----w C:\Program Files\Internet Download Manager
2008-09-15 21:41 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\IDM
2008-09-15 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-15 13:31 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-15 13:09 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2008-09-15 11:18 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-15 10:51 --------- d-----w C:\Program Files\IEPro
2008-09-15 10:50 --------- d-----w C:\Program Files\UltraISO
2008-09-15 02:16 87,855 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-15 02:14 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-15 02:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-09-14 22:41 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\cleaner
2008-09-14 18:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-14 17:25 --------- d-----w C:\Program Files\TaskSwitchXP
2008-09-14 17:25 --------- d-----w C:\Program Files\SuperCopier
2008-09-14 17:25 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-14 17:25 --------- d-----w C:\Program Files\SeePassword
2008-09-14 17:25 --------- d-----w C:\Program Files\Microsoft Bootvis
2008-09-14 17:25 --------- d-----w C:\Program Files\Folderico
2008-09-14 17:25 --------- d-----w C:\Program Files\Desktop Icon Toy
2008-09-14 17:25 --------- d-----w C:\Program Files\Desktop
2008-09-14 17:25 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\zyzprivacy
2008-09-14 17:25 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\iolo
2008-09-14 16:42 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\PrevxCSI
2008-09-14 16:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Prevx
2008-09-14 08:12 --------- d-----w C:\Program Files\Foxit Software
2008-09-14 07:30 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Ashampoo
2008-09-14 06:23 --------- d-----w C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-09-13 20:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-12 03:45 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-09-12 03:13 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-11 19:46 --------- d-----w C:\Program Files\Java
2008-09-11 13:16 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Downloaded Installations
2008-09-11 12:42 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Thinstall
2008-09-08 21:25 --------- d-----w C:\Program Files\Siber Systems
2008-09-08 03:23 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\VSRevoGroup
2008-09-08 02:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Blueberry
2008-09-08 02:40 2,944 ----a-w C:\WINDOWS\system32\drivers\bbcap.sys
2008-09-08 02:40 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Blueberry
2008-09-08 02:39 --------- d-----w C:\Program Files\Fichiers communs\Blueberry Software
2008-09-08 02:39 --------- d-----w C:\Program Files\Blueberry Software
2008-09-08 02:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\{F9228DAD-21AA-4BC3-8B63-E19AA9EEA5F8}
2008-09-07 15:07 --------- d-----w C:\Program Files\Fichiers communs\DVDVideoSoft
2008-09-07 15:07 --------- d-----w C:\Program Files\DVDVideoSoft
2008-09-05 19:58 --------- d-----w C:\Program Files\Fichiers communs\Scanner
2008-09-04 22:06 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-09-04 19:44 --------- d-----w C:\Program Files\MSXML 6.0
2008-09-03 22:30 --------- d-----w C:\Program Files\Driver-Soft
2008-09-03 21:06 --------- d-----w C:\Program Files\KingoOo_Upload
2008-09-02 18:47 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-09-02 09:04 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-09-02 09:03 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\SystemRequirementsLab
2008-09-01 22:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-08-30 14:51 --------- d-----w C:\Program Files\Project1
2008-08-30 14:48 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-30 14:48 286,720 ------w C:\WINDOWS\Setup1.exe
2008-08-30 13:37 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\IEPro
2008-08-30 10:51 --------- d-----w C:\Program Files\Fichiers communs\Borland Shared
2008-08-29 19:07 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-29 02:45 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Free Download Manager
2008-08-28 19:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\iolo
2008-08-28 13:22 --------- d-----w C:\Program Files\Fichiers communs\Adobe AIR
2008-08-28 13:07 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-08-26 21:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2008-08-26 14:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-26 05:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-26 02:58 --------- d-----w C:\Program Files\Google
2008-08-25 22:53 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\FastStone
2008-08-25 02:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\JH Software
2008-08-24 19:29 --------- d-----w C:\Program Files\Conduit
2008-08-24 08:16 --------- d-----w C:\Program Files\Secunia
2008-08-24 07:58 --------- d-----w C:\Program Files\Windows Desktop Search
2008-08-24 06:34 --------- d-----w C:\Program Files\MSBuild
2008-08-24 06:23 --------- d-----w C:\Program Files\Reference Assemblies
2008-08-24 02:17 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-23 21:41 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\CyberScrub
2008-08-22 23:50 --------- d-----w C:\Program Files\MpcStar
2008-08-22 10:39 --------- d-----w C:\Program Files\MSECache
2008-08-22 09:36 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-08-21 23:26 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2008-08-21 17:44 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\elefundesktops
2008-08-21 00:00 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\ESET
2008-08-20 23:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-08-20 02:20 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Adblock Pro
2008-08-18 17:34 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\URSoft
2008-08-11 04:20 --------- d-----w C:\Program Files\Broadcom
2008-08-11 03:42 --------- d-----w C:\Program Files\Fichiers communs\PAC207
2008-08-11 03:23 --------- d-----w C:\Program Files\PC Camera
2008-08-11 03:23 --------- d-----w C:\Program Files\Micro Innovations
2008-08-11 02:30 --------- d-----w C:\Program Files\ORITE
2008-08-11 02:21 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
.
كود:
<pre>
----a-w 384,512 2008-04-13 19:34:20 C:\WINDOWS\system32\Restore\old-System Volume .exe
</pre>
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:34 PM 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [09/12/2008 10:44 AM 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" [11/03/2007 04:50 AM 6731312]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [07/29/2008 08:20 PM 206088]
"SystemInit"="" [N/A]
"Karen"="" [N/A]
"raVe"="" [N/A]
"Win32BaseServiceMOD"="" [N/A]
"startIE"="" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"raVe"="" [N/A]
"Driver32"="" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [04/13/2008 07:34 PM 15360]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoClose"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iPMS.exe]
"Debugger"=dummy.dat
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iPMS20.exe]
"Debugger"=dummy.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\AV-CLS\\WGET.EXE"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [01/29/2008 06:29 PM 32784]
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [09/08/2008 02:40 AM 2944]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [04/13/2008 07:34 PM 14336]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\WINDOWS\system32\DRIVERS\klfltdev.sys [03/13/2008 07:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [04/30/2008 06:06 PM 24592]
R3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [05/14/2007 10:26 AM 508288]
R3 UsbEvdoAtc;LGE EVDO USB Serial Port;C:\WINDOWS\system32\DRIVERS\lgevdoatc.sys [08/28/2007 03:17 PM 19840]
R3 usbevdobus;LGE EVDO Composite USB Device;C:\WINDOWS\system32\DRIVERS\lgevdobus.sys [08/28/2007 03:17 PM 12800]
R3 UsbEvdoDiag;LGE EVDO USB Serial DM Port;C:\WINDOWS\system32\DRIVERS\lgevdodiag.sys [08/28/2007 03:17 PM 19840]
R3 USBEVDOModem;LGE EVDO USB Modem;C:\WINDOWS\system32\DRIVERS\lgevdomodem.sys [08/28/2007 03:17 PM 21632]
S3 10e14;10e14;C:\WINDOWS\system32\10e14.sys [ ]
S3 13e18;13e18;C:\WINDOWS\system32\13e18.sys [ ]
S3 231F;231F;C:\WINDOWS\system32\231F.sys [ ]
S3 3428;3428;C:\WINDOWS\system32\3428.sys [ ]
S3 34aC;34aC;C:\WINDOWS\system32\34aC.sys [ ]
S3 38b10;38b10;C:\WINDOWS\system32\38b10.sys [ ]
S3 47419;47419;C:\WINDOWS\system32\47419.sys [ ]
S3 5103;5103;C:\WINDOWS\system32\5103.sys [ ]
S3 5ecB;5ecB;C:\WINDOWS\system32\5ecB.sys [ ]
S3 65e13;65e13;C:\WINDOWS\system32\65e13.sys [ ]
S3 6ac15;6ac15;C:\WINDOWS\system32\6ac15.sys [ ]
S3 9505;9505;C:\WINDOWS\system32\9505.sys [ ]
S3 b1517;b1517;C:\WINDOWS\system32\b1517.sys [ ]
S3 f2c4;f2c4;C:\WINDOWS\system32\f2c4.sys [ ]
S3 f3b7;f3b7;C:\WINDOWS\system32\f3b7.sys [ ]
S3 f3c8D;f3c8D;C:\WINDOWS\system32\f3c8D.sys [08/27/2008 12:51 PM 54624]
S3 f91D;f91D;C:\WINDOWS\system32\f91D.sys [ ]
S3 fcf9;fcf9;C:\WINDOWS\system32\fcf9.sys [ ]
S3 fd211;fd211;C:\WINDOWS\system32\fd211.sys [ ]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [07/25/2008 08:57 PM 191656]
S3 PSI;PSI;C:\WINDOWS\system32\DRIVERS\psi_mf.sys [06/16/2008 08:31 AM 7808]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [09/12/2008 03:39 AM 355584]
S4 QSIVLZLG;QSIVLZLG;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\QSIVLZLG.exe [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tƒches planifi‚es'
.
.
------- Examen suppl‚mentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\xeqjftza.default\
FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
txtfile=NOTEPAD %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
vbefile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
vbsfile\shell\edit\command=C:\WINDOWS\Notepad.exe %1
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-09-16 03:46:05
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cach‚s ...
Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...
Recherche de fichiers cach‚s ...
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Crypserv.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Heure de fin: 09/16/2008 3:53:14 - La machine a red‚marr‚
ComboFix-quarantined-files.txt 2008-09-16 03:53:11
ComboFix2.txt 2008-08-26 00:06:54
Avant-CF: 29,217,316,864 octets libres
Aprٹs-CF: 29,210,832,896 octets libres
251 --- E O F --- 2008-09-14 18:26:00
الكل تمام ما بقي الا مشكل الذي برقم 3 و الصورة للتوضيح
و انت ماشي و انا وراك