ComboFix 08-04-13.3 - achour 2008-04-15 15:00:08.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.467 [GMT 2:00]
Endroit: C:\Documents and Settings\Administrator\My Documents\Downloads\My Downloads\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-15 to 2008-04-15 ))))))))))))))))))))))))))))))))))))
.
2008-04-14 08:54 . 2008-04-14 08:55 <REP> d-------- D:\Program Files\Maxthon2
2008-04-14 08:48 . 2008-04-14 08:48 <REP> d-------- D:\Program Files\MSXML 6.0
2008-04-14 08:47 . 2005-06-28 10:21 22,752 --a------ D:\WINDOWS\system32\spupdsvc.exe
2008-04-13 23:21 . 2008-04-14 08:41 <REP> d-------- D:\Program Files\WolFBox(2)
2008-04-13 19:05 . 2008-04-14 08:43 <REP> d-------- D:\Temp\flashgot.profile
2008-04-13 08:51 . 2008-04-14 08:41 <REP> d-------- D:\Program Files\Duplicate Hunter
2008-04-12 23:44 . 2008-04-12 23:44 <REP> d-------- D:\Documents and Settings\picard2\Application Data\vlc
2008-04-12 23:42 . 2008-04-12 23:42 <REP> d-------- D:\Program Files\VideoLAN
2008-04-12 23:41 . 2008-04-12 23:41 <REP> d-------- D:\Program Files\Xilisoft
2008-04-12 23:40 . 2008-04-12 23:43 <REP> d-------- D:\Documents and Settings\picard2\G-Force
2008-04-12 15:38 . 2008-04-12 15:38 <REP> d-------- D:\WINDOWS\system32\QuickTime
2008-04-12 15:38 . 2008-04-12 15:38 <REP> d-------- D:\Program Files\3ivx
2008-04-12 15:31 . 2008-03-01 14:58 6,066,176 -----c--- D:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-12 15:31 . 2007-04-17 11:32 2,455,488 -----c--- D:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-12 15:31 . 2007-03-08 07:10 1,048,576 -----c--- D:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-12 15:31 . 2008-03-01 14:58 459,264 -----c--- D:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-12 15:31 . 2008-03-01 14:58 383,488 -----c--- D:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-12 15:31 . 2008-03-01 14:58 267,776 -----c--- D:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-12 15:31 . 2008-03-01 14:58 102,912 -----c--- D:\WINDOWS\system32\dllcache\occache.dll
2008-04-12 15:31 . 2008-03-01 14:58 63,488 -----c--- D:\WINDOWS\system32\dllcache\icardie.dll
2008-04-12 15:31 . 2008-03-01 14:58 52,224 -----c--- D:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-12 15:31 . 2008-02-22 12:00 13,824 -----c--- D:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-12 15:24 . 2008-04-12 15:41 <REP> d-------- D:\Program Files\WMV9_VCM
2008-04-12 15:18 . 2008-04-12 15:18 <REP> d-------- D:\Program Files\SoundSpectrum
2008-04-12 15:08 . 2007-10-25 18:43 8,516,608 -----c--- D:\WINDOWS\system32\dllcache\****l32.dll
2008-04-12 15:03 . 2004-08-19 18:09 21,504 --a------ D:\WINDOWS\system32\hidserv.dll
2008-04-12 15:03 . 2001-08-17 23:59 3,072 --a------ D:\WINDOWS\system32\drivers\audstub.sys
2008-04-12 15:02 . 2004-08-19 18:09 4,274,816 --a------ D:\WINDOWS\system32\nv4_disp.dll
2008-04-12 15:02 . 2004-08-04 00:29 1,897,408 --a------ D:\WINDOWS\system32\drivers\nv4_mini.sys
2008-04-12 15:02 . 2004-08-19 17:54 58,496 --a------ D:\WINDOWS\system32\drivers\redbook.sys
2008-04-12 15:02 . 2004-08-19 17:56 54,400 --a------ D:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-12 15:02 . 2004-08-04 01:08 10,624 --a------ D:\WINDOWS\system32\drivers\gameenum.sys
2008-04-12 15:01 . 2004-08-19 18:09 77,312 --a------ D:\WINDOWS\system32\usbui.dll
2008-04-12 15:01 . 2004-08-04 01:07 44,672 --a------ D:\WINDOWS\system32\drivers\UAGP35.SYS
2008-04-12 15:01 . 2002-07-10 17:39 32,256 -ra------ D:\WINDOWS\system32\drivers\sisnic.sys
2008-04-12 15:01 . 2002-07-10 17:39 32,256 --a--c--- D:\WINDOWS\system32\dllcache\sisnic.sys
2008-04-12 15:01 . 2008-04-12 15:01 4,128 --a------ D:\INFCACHE.1
2008-04-12 15:00 . 2008-09-15 15:25 <REP> d--hs---- D:\WINDOWS\Installer
2008-04-12 15:00 . 2008-09-15 13:23 1,033,152 --a------ D:\WINDOWS\system32\PerfStringBackup.INI
2008-04-12 15:00 . 2002-09-06 22:59 77,824 --a--c--- D:\WINDOWS\system32\dllcache\spcommon.dll
2008-04-12 15:00 . 2002-09-06 22:59 65,536 --a--c--- D:\WINDOWS\system32\dllcache\spcplui.dll
2008-04-12 15:00 . 2008-04-12 13:26 4,205 --a------ D:\WINDOWS\ODBCINST.INI
2008-04-12 15:00 . 2008-04-14 09:32 1,374 --a------ D:\WINDOWS\imsins.BAK
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-15 13:33 --------- d-----w D:\Program Files\TunisiaForum.com Gbox
2008-09-15 12:05 --------- d-----w D:\Documents and Settings\picard2\Application Data\Thinstall
2008-09-15 09:03 --------- d-----w D:\Program Files\ESET
2008-09-15 09:02 --------- d-----w D:\Documents and Settings\picard2\Application Data\ESET
2008-09-15 09:01 --------- d-----w D:\Documents and Settings\All Users\Application Data\ESET
2008-09-15 08:20 --------- d-----w D:\Program Files\Windows Live
2008-04-12 12:06 --------- d-----w D:\Program Files\ADSL Autoconnect
2008-04-12 11:58 4,608 ----a-w D:\WINDOWS\system32\bbchlp.dll
2008-04-12 11:58 27,776 ----a-w D:\WINDOWS\system32\bbcap.dll
2008-04-12 11:58 2,944 ----a-w D:\WINDOWS\system32\drivers\bbcap.sys
2008-04-12 11:58 --------- d-----w D:\Documents and Settings\picard2\Application Data\LogSys
2008-04-12 11:58 --------- d-----w D:\Documents and Settings\picard2\Application Data\Blueberry
2008-04-12 11:58 --------- d-----w D:\Documents and Settings\All Users\Application Data\Blueberry
2008-04-12 11:57 --------- d--h--w D:\Documents and Settings\All Users\Application Data\{3A7FD077-F0B4-4276-BE42-175DEF23CA39}
2008-04-12 11:57 --------- d-----w D:\Program Files\Fichiers communs\Blueberry Software
2008-04-12 11:57 --------- d-----w D:\Program Files\Blueberry Software
2008-04-12 11:57 --------- d-----w D:\Documents and Settings\All Users\Application Data\LogSys
2008-04-12 11:54 --------- d-----w D:\Program Files\Firefox 2.0.0.13 by aLkEmMa
2008-04-12 11:48 --------- d-----w D:\Program Files\No-IP
2008-04-12 11:46 --------- d-----w D:\Program Files\TechSmith
2008-04-12 11:46 --------- d-----w D:\Documents and Settings\All Users\Application Data\TechSmith
2008-04-12 11:43 23 ----a-w D:\WINDOWS\system32\drivers\adidsl.cfg
2008-04-12 11:43 --------- d-----w D:\Program Files\Ororea
2008-04-12 11:43 --------- d-----w D:\Program Files\Fichiers communs\Wise Installation Wizard
2008-04-12 11:41 --------- d--h--w D:\Program Files\InstallShield Installation Information
2008-04-12 11:41 --------- d-----w D:\Program Files\SAGEM
2008-04-12 11:41 --------- d-----w D:\Program Files\Fichiers communs\InstallShield
2008-04-12 11:39 --------- d-----w D:\Program Files\SiSLan
2008-04-12 11:38 --------- d-----w D:\Program Files\C-Media 3D Audio
2008-04-12 11:34 --------- d-----w D:\Program Files\MSXML 4.0
2008-04-12 11:33 --------- d-----w D:\Program Files\WSTARTUP
2008-04-12 11:33 --------- d-----w D:\Program Files\UTILS
2008-04-12 11:33 --------- d-----w D:\Program Files\JEUX
2008-04-12 11:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\gtopala
2008-04-12 11:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\aignes
2008-04-12 11:27 --------- d-----w D:\Program Files\microsoft frontpage
2008-04-12 11:25 --------- d-----w D:\Program Files\Services en ligne
2008-03-20 07:56 1,846,016 ----a-w D:\WINDOWS\system32\win32k.sys
2008-03-13 14:52 71,176 ----a-w D:\WINDOWS\system32\drivers\epfw.sys
2008-03-13 14:52 54,280 ----a-w D:\WINDOWS\system32\drivers\epfwtdi.sys
2008-03-13 14:52 30,728 ----a-w D:\WINDOWS\system32\drivers\epfwndis.sys
2008-03-13 14:44 29,704 ----a-w D:\WINDOWS\system32\drivers\easdrv.sys
2008-03-13 14:43 40,456 ----a-w D:\WINDOWS\system32\drivers\eamon.sys
2008-03-01 12:58 826,368 ----a-w D:\WINDOWS\system32\wininet.dll
2008-02-20 18:50 45,568 ----a-w D:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 06:52 282,624 ----a-w D:\WINDOWS\system32\gdi32.dll
2008-02-04 15:23 693,792 ----a-w D:\WINDOWS\system32\OGACheckControl.DLL
2006-12-14 19:26 16,239,227 ----a-r D:\Program Files\****morphose.ccp
2001-11-23 04:08 712,704 ----a-w D:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-19 19:09 15360]
"MsnMsgr"="D:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-11-07 15:34 3739672]
"DWQueuedReporting"="d:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 14:38 39264]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSUSBRG"="D:\WINDOWS\SiSUSBrg.exe" [2002-07-12 12:15 106496]
"Cmaudio"="cmicnfg.cpl" []
"egui"="D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 19:09 15360]
D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - D:\Program Files\SAGEM\SAGEM
F@st 900-908\dslmon.exe [2008-04-12 13:41:55 962661]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"D:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"D:\\Program Files\\TunisiaForum.com Gbox\\SSSp.exe"=
R1 bbcap;bbcap;D:\WINDOWS\system32\DRIVERS\bbcap.sys [2008-04-12 13:58]
R2 ADSLAutoconnect;ADSLAutoconnect;"D:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z []
S3 usbstor;Pilote de stockage de masse USB;D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 02:08]
*Newly Created Service* - BTNETFILTER
*Newly Created Service* - CATCHME
*Newly Created Service* - USNJSVC
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-15 15:01:33
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-15 15:01:58
ComboFix-quarantined-files.txt 2008-04-15 13:01:50
Pre-Run: 54,121,013,248 octets libres
Post-Run: 54,112,632,832 octets libres
.
2008-09-15 13:18:43 --- E O F ---