ComboFix 08-12-29.01 - Trapeur 2008-12-30 2:44:41.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.3071.2385 [GMT 1:00]
Lancé depuis: c:\documents and settings\Trapeur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Trapeur\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
- Un nouveau point de restauration a été créé
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\a.exe
C:\C.exe
c:\documents and settings\Trapeur\Application Data.#
c:\documents and settings\Trapeur\Application Data.#\MBX@B68@3839D0.###
c:\documents and settings\Trapeur\Application Data.#\MBX@B68@3839E0.###
c:\documents and settings\Trapeur\Application Data.#\MBX@DD0@3839D0.###
c:\documents and settings\Trapeur\Application Data.#\MBX@DD0@3839E0.###
C:\Documents
C:\f.exe
c:\windows\system32_003485_.tmp.dll
c:\windows\system32_003626_.tmp.dll
c:\windows\system32_003627_.tmp.dll
c:\windows\system32_003628_.tmp.dll
c:\windows\system32_003629_.tmp.dll
c:\windows\system32_003636_.tmp.dll
c:\windows\system32_003637_.tmp.dll
c:\windows\system32_003638_.tmp.dll
c:\windows\system32_003639_.tmp.dll
c:\windows\system32_003641_.tmp.dll
c:\windows\system32_003642_.tmp.dll
c:\windows\system32_003645_.tmp.dll
c:\windows\system32_003646_.tmp.dll
c:\windows\system32_003649_.tmp.dll
c:\windows\system32_003650_.tmp.dll
c:\windows\system32_003652_.tmp.dll
c:\windows\system32_003653_.tmp.dll
c:\windows\system32_003655_.tmp.dll
c:\windows\system32_003660_.tmp.dll
c:\windows\system32_003662_.tmp.dll
c:\windows\system32_003663_.tmp.dll
c:\windows\system32_003665_.tmp.dll
c:\windows\system32_003667_.tmp.dll
c:\windows\system32_003668_.tmp.dll
c:\windows\system32_003669_.tmp.dll
c:\windows\system32_003670_.tmp.dll
c:\windows\system32_003671_.tmp.dll
c:\windows\system32_003674_.tmp.dll
c:\windows\system32_003676_.tmp.dll
c:\windows\system32_003677_.tmp.dll
c:\windows\system32_003678_.tmp.dll
c:\windows\system32_003682_.tmp.dll
c:\windows\system32_003890_.tmp.dll
c:\windows\system32_004045_.tmp.dll
c:\windows\system32_004046_.tmp.dll
c:\windows\system32_004047_.tmp.dll
c:\windows\system32_004048_.tmp.dll
c:\windows\system32_004055_.tmp.dll
c:\windows\system32_004056_.tmp.dll
c:\windows\system32_004057_.tmp.dll
c:\windows\system32_004058_.tmp.dll
c:\windows\system32_004060_.tmp.dll
c:\windows\system32_004061_.tmp.dll
c:\windows\system32_004064_.tmp.dll
c:\windows\system32_004065_.tmp.dll
c:\windows\system32_004067_.tmp.dll
c:\windows\system32_004068_.tmp.dll
c:\windows\system32_004069_.tmp.dll
c:\windows\system32_004071_.tmp.dll
c:\windows\system32_004072_.tmp.dll
c:\windows\system32_004074_.tmp.dll
c:\windows\system32_004075_.tmp.dll
c:\windows\system32_004079_.tmp.dll
c:\windows\system32_004080_.tmp.dll
c:\windows\system32_004082_.tmp.dll
c:\windows\system32_004083_.tmp.dll
c:\windows\system32_004085_.tmp.dll
c:\windows\system32_004087_.tmp.dll
c:\windows\system32_004088_.tmp.dll
c:\windows\system32_004089_.tmp.dll
c:\windows\system32_004090_.tmp.dll
c:\windows\system32_004091_.tmp.dll
c:\windows\system32_004094_.tmp.dll
c:\windows\system32_004095_.tmp.dll
c:\windows\system32_004096_.tmp.dll
c:\windows\system32_004097_.tmp.dll
c:\windows\system32_004098_.tmp.dll
c:\windows\system32_004103_.tmp.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-28 au 2008-12-30 ))))))))))))))))))))))))))))))))))))
.
2008-12-30 01:59 . 2008-12-30 01:59 d-------- c:\program files\Trend Micro
2008-12-30 01:39 . 2008-12-30 01:39 d-------- C:_OTMoveIt
2008-12-30 01:11 . 2008-12-30 01:32 d-------- c:\program files\FindyKill
2008-12-29 22:21 . 2008-12-29 22:21 d-------- c:\program files\ToniArts
2008-12-29 21:20 . 2008-12-29 21:20 d-------- c:\program files\Panda Security
2008-12-29 21:11 . 2008-12-29 21:12 d-------- c:\program files\Spybot - Search & Destroy
2008-12-29 21:11 . 2008-12-29 21:11 d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-29 18:08 . 2008-12-29 18:08 d-------- c:\program files\Windows Live SkyDrive
2008-12-29 18:08 . 2008-12-29 18:08 d-------- c:\program files\Microsoft
2008-12-29 18:08 . 2008-12-29 18:08 d-------- c:\documents and settings\Trapeur\Application Data\SYSTRAN
2008-12-29 18:08 . 2008-12-29 18:08 d-------- c:\documents and settings\All Users\Application Data\InstallShield
2008-12-29 02:56 . 2008-12-29 19:56 d-------- c:\program files\Softick
2008-12-29 01:40 . 2008-12-29 19:44 98 --a------ c:\windows\WirelessFTP.INI
2008-12-28 12:45 . 2008-12-28 12:45 d-------- c:\program files\SYSTRAN
2008-12-28 12:45 . 2008-12-28 12:45 878,080 --a------ c:\windows\system32\iconv.dll
2008-12-28 12:45 . 2008-12-28 12:45 721,920 --a------ c:\windows\system32\libxml2.dll
2008-12-28 12:45 . 2008-12-28 12:45 170,432 --a------ c:\windows\system32\libsyslic1.pd
2008-12-28 12:45 . 2008-12-28 12:45 150,016 --a------ c:\windows\system32\libxslt.dll
2008-12-28 12:45 . 2008-12-28 12:45 51,200 --a------ c:\windows\system32\libexslt.dll
2008-12-28 12:45 . 2008-12-28 12:45 192 --a------ c:\windows\system32\libsyslic1.ls
2008-12-28 12:43 . 2007-03-14 00:57 144,896 -ra------ c:\windows\system32\libsyslic1.original.dll
2008-12-28 12:43 . 2007-03-24 11:45 57,344 -ra------ c:\windows\system32\libsyslic1.dll
2008-12-28 02:48 . 2008-12-28 02:48 d-------- c:\documents and settings\Trapeur\Application Data\Microsoft Office Mobile
2008-12-28 02:20 . 2008-12-29 19:57 d-------- c:\program files\eMule
2008-12-27 23:42 . 2006-01-05 17:52 90,112 --a------ c:\windows\RSetupCE.exe
2008-12-27 22:46 . 2008-12-27 22:46 d-------- C:\bb5_unlocker
2008-12-27 17:36 . 2008-12-27 17:36 0 --a------ c:\windows\tosOBEX.INI
2008-12-27 16:52 . 2008-12-27 16:52 d-------- c:\documents and settings\Trapeur\Application Data\Toshiba
2008-12-27 15:53 . 2008-12-29 20:12 d-------- c:\program files\RPN Calculator
2008-12-27 15:47 . 2001-08-06 21:58 163,599 --a------ c:\windows\psuninst2.exe
2008-12-27 15:45 . 2008-12-27 15:45 d-------- c:\program files\Calc98a
2008-12-27 14:21 . 2008-12-27 14:21 162,816 --a------ c:\windows\system32\fmod.dll
2008-12-27 14:18 . 2008-12-27 14:18 d-------- c:\program files\Wizcode
2008-12-27 00:53 . 2008-12-27 00:53 d-------- c:\documents and settings\Trapeur\Application Data\Jeyo
2008-12-25 14:31 . 2008-12-25 14:32 d-------- c:\documents and settings\Trapeur\Phone Browser
2008-12-25 14:25 . 2008-12-25 14:27 d-------- c:\documents and settings\All Users\Application Data\PC Suite
2008-12-25 14:24 . 2008-12-25 14:24 d-------- c:\program files\Fichiers communs\PCSuite
2008-12-25 14:24 . 2008-12-25 14:24 d-------- c:\program files\Fichiers communs\Nokia
2008-12-25 14:24 . 2008-12-25 14:33 d-------- c:\documents and settings\Trapeur\Application Data\Nokia
2008-12-25 14:23 . 2008-12-25 14:23 d-------- c:\program files\PC Connectivity Solution
2008-12-25 14:11 . 2008-12-25 14:24 d-------- c:\program files\Nokia
2008-12-25 14:11 . 2008-12-25 15:14 d-------- c:\documents and settings\Trapeur\Application Data\PC Suite
2008-12-25 14:11 . 2007-02-22 11:15 137,216 --a------ c:\windows\system32\drivers\nmwcd.sys
2008-12-25 14:11 . 2007-02-22 11:15 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-12-25 14:11 . 2007-02-22 11:15 65,536 --a------ c:\windows\system32\nmwcdcocls.dll
2008-12-25 14:11 . 2007-02-22 11:15 12,288 --a------ c:\windows\system32\drivers\nmwcdcm.sys
2008-12-25 14:11 . 2007-02-22 11:15 12,288 --a------ c:\windows\system32\drivers\nmwcdcj.sys
2008-12-25 14:11 . 2007-02-22 11:15 8,320 --a------ c:\windows\system32\drivers\nmwcdc.sys
2008-12-25 14:10 . 2008-12-25 14:11 d-------- c:\documents and settings\All Users\Application Data\Installations
2008-12-24 13:15 . 2008-12-29 20:15 d-------- c:\program files\Microsoft ActiveSync
2008-12-24 13:14 . 2008-12-24 13:14 d-------- c:\program files\ASUSTek
2008-12-24 13:13 . 2008-12-24 13:13 d-------- c:\program files\Windows Mobile Device Handbook
2008-12-16 22:28 . 2008-12-16 22:28 d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-16 20:21 . 2008-12-23 19:37 8 --a------ c:\windows\system32\nvModes.dat
2008-12-15 02:04 . 2008-12-15 02:04 dr-h----- c:\documents and settings\Trapeur\Application Data\SecuROM
2008-12-15 02:03 . 2008-12-15 02:09 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-15 01:58 . 2008-12-15 02:37 d-------- c:\program files\Microsoft Games for Windows - LIVE
2008-12-15 01:18 . 2008-12-15 01:18 d-------- c:\program files\SuperCopier2
2008-12-14 15:49 . 2008-12-14 15:49 d-------- c:\documents and settings\Trapeur\Application Data\WildPackets
2008-12-14 12:40 . 2008-12-15 00:14 d-------- c:\documents and settings\Trapeur.VirtualBox
2008-12-14 12:39 . 2008-12-14 12:39 d-------- c:\program files\Sun
2008-12-14 12:39 . 2008-11-21 21:10 93,776 --a------ c:\windows\system32\drivers\VBoxDrv.sys
2008-12-14 12:39 . 2008-11-21 21:10 41,744 --a------ c:\windows\system32\drivers\VBoxUSBMon.sys
2008-12-13 23:52 . 2008-12-13 23:52 d-------- c:\program files\Microsoft Virtual PC
2008-12-13 13:20 . 2008-12-13 13:20 d-------- C:\Ddos
2008-12-13 12:01 . 2008-12-13 11:56 68,224 --a------ c:\windows\system32\WanPacket2.dll
2008-12-12 21:26 . 2008-12-12 21:26 d-------- c:\program files\Bethesda Softworks
2008-12-12 21:26 . 2008-12-12 21:26 d-------- c:\documents and settings\All Users\Application Data\Fallout3
2008-12-12 21:26 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-12-12 21:26 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-12-12 21:26 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-12-12 21:26 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-12-12 21:26 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-12-12 21:26 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-12-12 21:26 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-12-12 21:23 . 2008-12-12 21:23 d-------- c:\windows\system32\xlive
2008-12-12 19:49 . 2008-12-12 19:49 d-------- c:\program files\PDFCreator
2008-12-12 19:49 . 1998-07-13 02:08 141,312 --a------ c:\windows\system32\MSCMCFR.DLL
2008-12-12 19:49 . 2001-10-28 17:42 116,224 --a------ c:\windows\system32\pdfcmnnt.dll
2008-12-12 19:49 . 1998-07-13 02:08 59,904 --a------ c:\windows\system32\MSCC2FR.DLL
2008-12-12 19:49 . 1998-07-06 01:00 23,552 --a------ c:\windows\system32\MSMPIDE.DLL
2008-12-10 23:49 . 2008-12-10 23:49 d-------- c:\documents and settings\LocalService\Bureau
2008-12-08 21:07 . 2008-12-12 00:16 d-------- c:\documents and settings\Trapeur\Application Data\gtk-2.0
2008-12-08 21:06 . 2008-12-08 21:06 d-------- c:\documents and settings\Trapeur.thumbnails
2008-12-08 21:06 . 2008-12-27 20:43 d-------- c:\documents and settings\Trapeur.gimp-2.4
2008-12-08 12:56 . 2008-12-08 12:56 d-------- c:\documents and settings\All Users\Application Data\2DBoy
2008-12-08 01:48 . 2008-12-08 01:48 d-------- c:\program files\PROnetworks
2008-12-08 00:39 . 2008-10-27 18:37 192,307 --a------ C:\wubildr
2008-12-08 00:39 . 2008-10-27 18:37 8,192 --a------ C:\wubildr.mbr
2008-12-08 00:38 . 2008-12-08 00:38 d-------- C:\ubuntu
2008-12-07 19:16 . 2008-12-07 22:22 d-------- c:\program files\JkDefrag
2008-12-07 19:16 . 2008-09-02 15:49 253,952 --a------ c:\windows\system32\JkDefragScreenSaver.exe
2008-12-07 19:16 . 2008-09-02 15:49 106,496 --a------ c:\windows\system32\JkDefragScreenSaver.scr
2008-12-07 17:20 . 2008-12-07 17:20 d-------- c:\program files\Windows Media Connect 2
2008-12-07 17:20 . 2008-04-13 18:33 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-07 17:18 . 2008-12-25 14:27 d-------- c:\windows\system32\drivers\UMDF
2008-12-07 16:28 . 2008-12-07 16:28 d-------- c:\program files\SlySoft
2008-12-07 16:28 . 2008-12-07 16:28 d-------- c:\documents and settings\All Users\Application Data\SlySoft
2008-12-07 16:26 . 2008-12-07 16:26 d-------- c:\program files\eRightSoft
2008-12-07 16:26 . 2008-12-07 16:26 d-------- c:\program files\AviSynth 2.5
2008-12-07 16:18 . 2008-12-07 16:18 d-------- c:\windows\system32\Atheros_L1
2008-12-07 16:18 . 2007-11-01 08:56 36,864 --a------ c:\windows\system32\drivers\l151x86.sys
2008-12-07 16:03 . 2008-12-07 16:09 d-------- c:\program files\Folder Lock
2008-12-07 16:02 . 2008-12-07 16:09 d-------- c:\program files\Babylon(2)
2008-12-07 16:02 . 2008-12-07 16:09 d-------- c:\documents and settings\Trapeur\Application Data\Babylon
2008-12-07 16:02 . 2008-12-07 16:09 d-------- c:\documents and settings\All Users\Application Data\Babylon
2008-12-07 16:01 . 2008-12-07 16:09 d-------- c:\program files\Everest
2008-12-07 15:39 . 2007-02-24 14:42 39,936 --a------ c:\windows\system32\drivers\rimmptsk.sys
2008-12-07 15:22 . 2008-12-07 15:22 d–h----- c:\windows\Icons
2008-12-07 15:19 . 2008-12-07 15:19 2,287,104 --a------ c:\windows\system32\TUKernel.exe
2008-12-07 15:09 . 2008-12-07 15:09 d-------- c:\program files\Alcohol Soft
2008-12-07 14:47 . 2008-12-07 14:47 d-------- c:\program files\PixiePack Codec Pack
2008-12-07 14:44 . 2008-12-07 14:47 dr------- c:\documents and settings\Trapeur\Mes documents
2008-12-07 14:44 . 2008-12-22 14:23 d-------- c:\documents and settings\Trapeur\Application Data\Tunebite
2008-12-07 14:44 . 2007-12-11 09:52 26,784 --a------ c:\windows\system32\drivers\tbhsd.sys
2008-12-07 14:43 . 2008-12-07 14:43 d-------- c:\program files\RapidSolution
2008-12-07 14:43 . 2008-12-07 14:47 d-------- c:\documents and settings\All Users\Application Data\RapidSolution
2008-12-07 14:24 . 2008-12-07 14:24 d-------- C:\Fraps
2008-12-07 14:24 . 2008-12-10 21:46 d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-12-07 14:23 . 2008-12-07 14:23 d-------- C:\RDM
2008-12-07 14:15 . 2008-12-07 14:21 d-------- C:\rdm6
2008-12-07 04:46 . 2008-12-07 04:46 d-------- c:\program files\TuneUp Utilities 2009
2008-12-07 04:46 . 2008-12-07 04:46 d-------- c:\documents and settings\Trapeur\Application Data\TuneUp Software
2008-12-07 04:46 . 2008-12-07 04:46 d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-12-07 04:46 . 2008-12-07 04:46 d–hs---- c:\documents and settings\All Users\Application Data{55A29068-F2CE-456C-9148-C869879E2357}
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 01:32 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-29 23:36 --------- d-----w c:\documents and settings\Trapeur\Application Data\uTorrent
2008-12-29 21:21 --------- d–h--w c:\program files\InstallShield Installation Information
2008-12-29 15:46 --------- d-----w c:\documents and settings\Trapeur\Application Data\Skype
2008-12-29 11:13 --------- d-----w c:\documents and settings\Trapeur\Application Data\skypePM
2008-12-28 11:45 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-12-26 19:55 --------- d-----w c:\documents and settings\Trapeur\Application Data\teamspeak2
2008-12-20 22:19 --------- d-----w c:\program files\Dassault Systemes
2008-12-10 13:37 --------- d-----w c:\documents and settings\Trapeur\Application Data\Teeworlds
2008-12-07 15:35 --------- d-----w c:\program files\ma-config.com
2008-12-07 15:35 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
2008-11-09 16:34 --------- d-----w c:\program files\Windows Live
2008-11-07 18:20 --------- d-----w c:\program files\MSBuild
2008-11-07 18:14 --------- d-----w c:\program files\MSECache
2008-09-28 18:27 164 ----a-w C:\cc_20080928_202714.reg
2008-09-28 18:27 1,414 ----a-w C:\cc_20080928_202702.reg
2008-09-28 18:26 30,356 ----a-w C:\cc_20080928_202642.reg
2008-09-28 18:05 315,392 ----a-w c:\windows\HideWin.exe
2008-09-28 17:46 21,361 ----a-w c:\windows\AegisP.sys
2006-05-03 09:06 163,328 --sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh–r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 --sh–r c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
@="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
[HKEY_CLASSES_ROOT\CLSID{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
2006-10-27 00:35 391168 -ra------ c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2008-04-13 15360]
“H/PC Connection Agent”=“c:\program files\Microsoft ActiveSync\wcescomm.exe” [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“IntelWireless”=“c:\program files\Intel\Wireless\Bin\ifrmewrk.exe” [2007-10-08 1101824]
“SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe” [2006-10-12 815104]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-12-03 136600]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2008-02-22 13508608]
“NvMediaCenter”=“c:\windows\system32\NvMcTray.dll” [2008-02-22 86016]
“nwiz”=“nwiz.exe” [2008-02-22 c:\windows\system32\nwiz.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\System32\CTFMON.EXE” [2008-04-13 15360]
“Nokia.PCSync”=“c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe” [2007-06-19 1241088]
c:\documents and settings\All Users\Menu D?marrer\Programmes\D?marrage
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2007-06-14 425984]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
“{56F9679E-7826-4C84-81F3-532071A8BCC5}”= “c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll” [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
“UIHost”=“c:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe”
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2007-02-07 01:30 74240 c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=APSHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.MJPG”= Pvmjpg30.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ ASWLNPkg
[HKLM~\startupfolder\C:^Documents and Settings^Trapeur^Menu Démarrer^Programmes^Démarrage^Moteur du Planificateur de tâches SolidWorks.lnk]
path=c:\documents and settings\Trapeur\Menu Démarrer\Programmes\Démarrage\Moteur du Planificateur de tâches SolidWorks.lnk
backup=c:\windows\pss\Moteur du Planificateur de tâches SolidWorks.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CognizanceTS]
-ra------ 2003-12-22 05:12 17920 c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a------ 2008-08-08 13:11 490952 c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
–a------ 2007-06-18 15:10 271360 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-08-11 16:46 21741864 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
–a------ 2007-08-28 10:48 655360 c:\program files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperCopier2.exe]
–a------ 2006-07-07 17:45 1052672 c:\program files\SuperCopier2\SuperCopier2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tunebite]
–a------ 2007-12-19 18:45 4961584 c:\program files\RapidSolution\Tunebite\Tunebite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console 2]
–a------ 2007-07-05 15:53 1040384 c:\program files\Wireless Console 2\wcourier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a------ 2008-06-19 16:20 57344 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a------ 2008-06-20 16:57 16872448 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
“WinVNC4”=2 (0x2)
“TapiSrv”=3 (0x3)
“maconfservice”=3 (0x3)
“BsMobileCS”=2 (0x2)
“BsHelpCS”=3 (0x3)
“BlueSoleilCS”=2 (0x2)
“BBDemon”=2 (0x2)
“WMPNetworkSvc”=3 (0x3)
“SolidWorks Licensing Service”=3 (0x3)
“ServiceLayer”=3 (0x3)
“PnkBstrB”=2 (0x2)
“PnkBstrA”=2 (0x2)
“ose”=3 (0x3)
“odserv”=3 (0x3)
“NMIndexingService”=3 (0x3)
“NBService”=3 (0x3)
“JavaQuickStarterService”=2 (0x2)
“idsvc”=3 (0x3)
“IDriverT”=3 (0x3)
“HidServ”=2 (0x2)
“getPlus® Helper”=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
“ManyCam”=“c:\program files\ManyCam 2.3\ManyCam.exe”
“LaunchList”=c:\program files\Pinnacle\Studio 11\LaunchList2.exe
“Tunebite”=c:\program files\RapidSolution\Tunebite\Tunebite.exe -tray
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
“NeroFilterCheck”=c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
“PWRISOVM.EXE”=c:\program files\PowerISO\PWRISOVM.EXE
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“%windir%\system32\sessmgr.exe”=
“c:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“c:\Program Files\Dassault Systemes\B16\intel_a\code\bin\orbixd.exe”=
“c:\Program Files\uTorrent\uTorrent.exe”=
“c:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CNEXT.exe”=
“c:\WINDOWS\system32\PnkBstrA.exe”=
“c:\WINDOWS\system32\PnkBstrB.exe”=
“c:\Program Files\Ubisoft\Tom Clancy’s Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe”=
“c:\Program Files\Ubisoft\Tom Clancy’s Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe”=
“c:\Program Files\Ubisoft\Tom Clancy’s Rainbow Six Vegas 2\Binaries\RainbowSixVegas2_SADS.exe”=
“c:\Program Files\Postal2STP\System\Postal2.exe”=
“c:\Program Files\Pinnacle\Studio 11\programs\RM.exe”=
“c:\Program Files\Pinnacle\Studio 11\programs\Studio.exe”=
“c:\Program Files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe”=
“c:\Program Files\Pinnacle\Studio 11\programs\umi.exe”=
“c:\Documents and Settings\Trapeur\Bureau\CryptLoad_1.1.4\RouterClient.exe”=
“c:\Program Files\Dassault Systemes\B14\intel_a\code\bin\orbixd.exe”=
“c:\Program Files\Dassault Systemes\B14\intel_a\code\bin\CNEXT.exe”=
“e:\Program Files\Rockstar Games\Grand Theft Auto IV\GTAIV.exe”=
“c:\program files\Microsoft ActiveSync\rapimgr.exe”= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
“c:\program files\Microsoft ActiveSync\wcescomm.exe”= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
“c:\program files\Microsoft ActiveSync\WCESMgr.exe”= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
“c:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“26675:TCP”= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\Drivers\BtHidBus.sys [2008-07-31 20616]
R1 ItSDisk;ItSDisk;c:\windows\system32\Drivers\ItSDisk.sys [2006-05-17 23232]
R1 LUMDriver;LUMDriver;??\c:\windows\system32\drivers\LUMDriver.sys [2003-07-11 14912]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2008-12-14 93776]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2008-12-14 41744]
R2 ASBroker;Courtier de session de connexion;c:\windows\System32\svchost.exe -k Cognizance [2008-09-27 14336]
R2 ASChannel;Canal de communication local;c:\windows\System32\svchost.exe -k Cognizance [2008-09-27 14336]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2008-12-07 603904]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;c:\windows\system32\DRIVERS\l151x86.sys [2008-12-07 36864]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\Drivers\IvtBtBus.sys [2008-07-02 26248]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\DRIVERS\ManyCam.sys [2008-01-14 21632]
R3 phil2vid;Appareil photo VGA USB Philips PCVC690;c:\windows\system32\DRIVERS\philcam2.sys [2008-10-07 173696]
R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2006-09-26 21920]
S3 SinoTPM;Driver For SINOSUN Trusted Platform Module;c:\windows\system32\DRIVERS\SinoTpm.sys [2008-12-03 34048]
S4 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B14\intel_a\code\bin\CATSysDemon.exe -service []
S4 BsMobileCS;BsMobileCS;c:\program files\IVT Corporation\BlueSoleil\BsMobileCS.exe []
S4 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-07 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{0c17a8e8-ca35-11dd-9023-001fc62c3ead}]
\Shell\AutoRun\command - J:\EmDesk.exe
\Shell\EmDesk\command - J:\EmDesk.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{a65e3b02-b1d7-11dd-9921-001fc62c3ead}]
\Shell\AutoRun\command - J:\e.cmd
\Shell\explore\Command - J:\e.cmd
\Shell\open\Command - J:\e.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{db319d4a-c20a-11dd-994b-001fc62c3ead}]
\Shell\AutoRun\command - L:\ReadMe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier ‘Tâches planifiées’
2008-12-30 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 12:14]
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
BHO-{4B0FAF5A-67C4-4625-AE07-B0DBADA16EBF} - (no file)
SafeBoot-sglfb.sys
SafeBoot-tga.sys
SafeBoot-wd.sys
SafeBoot-sacsvr
MSConfigStartUp-MsnMsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-RGSC - h:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
.
------- Examen supplémentaire -------
.
uStart Page = www.emule-france.com…
IE: Consulter les dictionnaires (SYSTRAN) - c:\program files\SYSTRAN\6\GUIres.dll/lookup.js
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer via Bluetooth - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tsinfo.htm
IE: Envoyer via message(&M)… - c:\program files\IVT Corporation\BlueSoleil\TransSend\IE\tssms.htm
IE: Traduire (SYSTRAN) - c:\program files\SYSTRAN\6\GUIres.dll/translate.js
TCP: {E62BDD37-A43A-478A-8981-6738BA50FEBE} = 192.168.0.1,192.168.0.2
O16 -: DirectAnimation Java Classes - [c:\windows\Java\classes\dajava.cab…](file://c:\windows\Java\classes\dajava.cab)
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - [c:\windows\Java\classes\xmldso.cab…](file://c:\windows\Java\classes\xmldso.cab)
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
FF - ProfilePath - c:\documents and settings\Trapeur\Application Data\Mozilla\Firefox\Profiles\l36v4dbr.default
FF - component: c:\program files\Mozilla Firefox\extensions{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Trapeur\Application Data\Mozilla\Firefox\Profiles\l36v4dbr.default\extensions{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
ATTENTION: FIREFOX POLICES IS IN FORCE
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-12-30 02:47:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
--------------------- DLLs chargées dans les processus actifs ---------------------
-
-
-
-
-
-
-
‘winlogon.exe’(1396)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\TrayIcon.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\brand.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\FRA\brand.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\FRA\ItMsg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItDAC.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItReports.DLL
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\BioAuth.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\FRA\BioAuth.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASBioAT.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItVCClient.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AuthWiz.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\FRA\AuthWiz.dll
-
-
-
-
-
-
-
‘lsass.exe’(1548)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\rundll32.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtBty.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\windows\system32\wbem\wmiadap.exe
.
.
Heure de fin: 2008-12-30 2:51:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-30 01:51:48
Avant-CF: 15 746 428 928 octets libres
Après-CF: 15,564,562,432 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
;
;Warning: Boot.ini is used on Windows XP and earlier operating systems.
;Warning: Use BCDEDIT.exe to modify Windows Vista boot options.
;
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Professionnel” /FASTDETECT /NoExecute=OptIn /TUTag=1HBIB9 /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP Professionnel (TuneUp Backup)” /FASTDETECT /NoExecute=OptIn /TUTag=1HBIB9-BAK
c:\wubildr.mbr=“Ubuntu”
504 — E O F — 2008-12-20 23:56:52