ComboFix 08-02-25.3 - home 2008-02-28 18:52:25.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.84 [GMT 1:00]
Endroit: D:\Documents and Settings\home\Bureau\Combo-Fix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\pskill.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-28 to 2008-02-28 ))))))))))))))))))))))))))))))))))))
.
2008-02-27 19:30 . 2008-02-27 19:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-27 06:07 . 2008-02-27 06:07 35,151,825 --a------ C:\WINDOWS\VPTNFILE.125
2008-02-27 06:07 . 2008-02-27 06:07 35,151,825 --a------ C:\WINDOWS\LPT$VPN.125
2008-02-27 06:06 . 2008-02-27 06:07 <REP> d-------- C:\WINDOWS\AU_Temp
2008-02-26 19:46 . 2008-02-26 19:46 <REP> d-------- C:\Program Files\CCleaner
2008-02-26 17:01 . 2008-02-26 17:10 <REP> d-------- D:\Documents and Settings\home\Application Data\1ClickDVDCopy
2008-02-26 05:27 . 2008-02-26 23:52 <REP> d-------- D:\Documents and Settings\home\.housecall6.6
2008-02-24 11:04 . 2008-02-26 19:46 <REP> d-------- D:\Documents and Settings\home\Application Data\uTorrent
2008-02-24 11:04 . 2008-02-24 11:18 <REP> d-------- C:\Program Files\uTorrent
2008-02-23 16:23 . 2008-02-26 19:15 <REP> d-------- D:\Documents and Settings\home\Application Data\BitTorrent
2008-02-22 21:44 . 2008-02-22 21:44 <REP> d-------- C:\Program Files\kemule
2008-02-22 21:44 . 2008-02-22 21:44 <REP> d-------- C:\Program Files\Conduit
2008-02-20 20:11 . 2008-02-20 20:11 <REP> d-------- C:\WINDOWS\system32\VIRepair
2008-02-20 20:05 . 2004-08-05 13:00 221,696 --a------ C:\WINDOWS\system32\logon.scr
2008-02-20 20:05 . 2004-08-05 13:00 221,696 --a------ C:\WINDOWS\system32\dllcache\logon.scr
2008-02-19 22:55 . 2008-02-19 22:55 63,735 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-02-19 22:51 . 2008-02-19 22:55 6,112 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-02-19 22:50 . 2008-02-19 22:50 <REP> d-------- C:\WINDOWS\BricoPacks
2008-02-19 22:30 . 2008-02-19 22:55 3,932,214 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-02-19 22:28 . 2008-02-19 22:28 <REP> d-------- C:\WINDOWS\Packs
2008-02-19 20:35 . 2008-02-19 20:35 78,942 --a------ C:\WINDOWS\Icon_2.ico
2008-02-19 20:32 . 2008-02-19 20:32 <REP> d-------- D:\Documents and Settings\home\Application Data\Styler
2008-02-19 20:32 . 2008-02-19 20:39 <REP> d-------- C:\Program Files\WinFlip
2008-02-19 20:32 . 2008-02-19 20:39 <REP> d-------- C:\Program Files\TrueTransparency
2008-02-19 20:27 . 2008-02-20 20:24 <REP> d-------- C:\WINDOWS\system32\VITrans
2008-02-19 20:27 . 2008-02-20 20:05 <REP> d-------- C:\VTPFiles
2008-02-19 20:27 . 2006-12-03 17:15 111,104 --a------ C:\WINDOWS\system32\Uharc.exe
2008-02-19 20:27 . 2008-02-19 20:27 78,942 --a------ C:\WINDOWS\Icon_1.ico
2008-02-19 20:27 . 2006-12-03 17:15 19,968 --a------ C:\WINDOWS\system32\reico.exe
2008-02-19 20:27 . 2006-12-03 17:14 8,636 --a------ C:\WINDOWS\system32\modifype.exe
2008-02-17 22:33 . 2008-02-17 22:33 32 --a------ C:\WINDOWS\go
2008-02-16 13:35 . 2008-02-25 05:51 <REP> d-------- C:\Program Files\Invisible IP Map
2008-02-14 19:31 . 2008-02-14 19:31 28 --a------ C:\WINDOWS\DVDFabGold.INI
2008-02-01 21:25 . 2008-02-02 17:53 <REP> d-------- C:\Program Files\Lavasoft
2008-02-01 11:17 . 2008-02-01 11:17 587,264 --a------ C:\WINDOWS\WLXPGSS.SCR
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-28 17:33 --------- d-----w D:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-28 12:36 --------- d-----w C:\Program Files\eMule
2008-02-28 05:05 --------- d-----w C:\Program Files\Regclean
2008-02-27 19:04 --------- d-----w C:\Program Files\Trend Micro
2008-02-27 18:59 --------- d-----w C:\Program Files\Windows Live
2008-02-27 18:54 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-27 17:00 --------- d-----w C:\Program Files\ADSL Autoconnect
2008-02-27 05:07 86,094 ----a-w C:\WINDOWS\BPMNT.dll
2008-02-27 05:07 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-02-27 05:07 267,845 ----a-w C:\WINDOWS\tsc.exe
2008-02-27 05:07 1,163,344 ----a-w C:\WINDOWS\vsapi32.dll
2008-02-26 18:15 --------- d-----w D:\Documents and Settings\home\Application Data\Azureus
2008-02-26 16:16 98,232,352 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-26 16:16 1,155,368 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-25 05:00 --------- d-----w D:\Documents and Settings\home\Application Data\dvdcss
2008-02-23 11:23 --------- d-----w C:\Program Files\Live Billiards
2008-02-18 20:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-18 20:55 --------- d-----w C:\Program Files\Navman
2008-02-18 17:37 --------- d-----w C:\Program Files\Lexmark X1100 Series
2008-02-18 17:06 --------- d-----w D:\Documents and Settings\home\Application Data\Vso
2008-02-14 20:21 --------- d-----w C:\Program Files\Dvd-cloner
2008-02-13 19:29 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-03 21:18 --------- d-----w D:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-02 16:59 --------- d-----w D:\Documents and Settings\home\Application Data\Lavasoft
2008-02-01 20:32 --------- d-----w C:\Program Files\Fraction
2008-02-01 20:31 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-27 16:20 --------- d-----w D:\Documents and Settings\home\Application Data\COWON
2008-01-24 22:11 23 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-01-24 22:11 --------- d-----w C:\Program Files\SAGEM
2008-01-20 12:13 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-01-20 12:12 --------- d-----w C:\Program Files\MSN Messenger
2008-01-17 20:32 --------- d-----w C:\Program Files\iKoneStudio
2008-01-17 20:21 --------- d-----w C:\Program Files\ImTOO
2008-01-16 21:23 --------- d-----w C:\Program Files\Macrogaming
2008-01-16 05:24 --------- d-----w C:\Program Files\AliveMedia
2008-01-15 19:56 --------- d-----w C:\Program Files\Astonsoft
2008-01-14 05:29 --------- d-----w D:\Documents and Settings\home\Application Data\Nero
2008-01-14 05:27 --------- d-----w C:\Program Files\Fichiers communs\Nero
2008-01-14 05:21 --------- d-----w D:\Documents and Settings\All Users\Application Data\Nero
2008-01-14 05:21 --------- d-----w C:\Program Files\Nero
2008-01-14 05:21 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-01-12 16:01 --------- d-----w C:\Program Files\QuickTime
2008-01-12 15:56 --------- d-----w C:\Program Files\DK
2008-01-12 15:53 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-01-10 20:23 --------- d-----w D:\Documents and Settings\All Users\Application Data\4D
2008-01-08 18:20 --------- d-----w D:\Documents and Settings\home\Application Data\DeepBurner
2008-01-07 17:47 --------- d-----w C:\Program Files\Yahoo!
2008-01-06 19:18 --------- d-----w C:\Program Files\IncrediMail
2008-01-06 11:18 --------- d-----w D:\Documents and Settings\home\Application Data\Uniblue
2008-01-06 09:05 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-01-05 19:25 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-01-05 11:43 --------- d-----w C:\Program Files\Google
2008-01-03 16:56 --------- d-----w C:\Program Files\TuxPaint
2008-01-02 20:23 --------- d-----w D:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-01-01 21:50 --------- d-----w C:\Program Files\Micro Application
2008-01-01 08:44 --------- d-----w C:\Program Files\MSBuild
2008-01-01 08:44 --------- d-----w C:\Program Files\Microsoft Works
2008-01-01 08:43 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-28 22:02 --------- d-----w C:\Program Files\Common files
2007-11-25 10:27 752,436,294 ----a-w D:\Documents and Settings\DVD A GRAVER\Prog - Micro Application - Faire part - Fr.zip
2007-08-27 19:42 87,608 ----a-w D:\Documents and Settings\home\Application Data\ezpinst.exe
2007-08-27 19:42 47,360 ----a-w D:\Documents and Settings\home\Application Data\pcouffin.sys
2007-03-16 21:45 480,848 ----a-w D:\Documents and Settings\All Users\Application Data\pswi_preloaded.exe
2004-08-05 12:00 60,416 --sha-w C:\WINDOWS\BricoPacks\SysFiles\80_msimn.exe
2007-08-25 05:15 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2007-08-24 20:38 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007082420070825\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c102601d-ee8b-470d-a3dc-0577ce604a23}]
2008-02-14 14:54 1555480 --a------ C:\Program Files\kemule\tbkemu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938}
{C102601D-EE8B-470D-A3DC-0577CE604A23}
[HKEY_CLASSES_ROOT\clsid\{c102601d-ee8b-470d-a3dc-0577ce604a23}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{C102601D-EE8B-470D-A3DC-0577CE604A23}"= C:\Program Files\kemule\tbkemu.dll [2008-02-14 14:54 1555480]
[HKEY_CLASSES_ROOT\clsid\{c102601d-ee8b-470d-a3dc-0577ce604a23}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkwatAutoconnect"="C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" [2008-02-27 18:00 446464]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-27 18:11 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-02-27 17:21 919016]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 14:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2007-12-04 14:00 79224 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-05 13:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2008-01-01 19:41 214456 C:\PROGRA~1\INCRED~1\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
---hs---- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkwatAutoconnect]
--a------ 2008-02-27 18:00 446464 C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-08-27 18:11 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-08-25 15:43 180269 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
--a------ 2008-02-27 17:21 919016 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3 (0x3)
"WZCSVC"=2 (0x2)
"WudfSvc"=3 (0x3)
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WmiApSrv"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"W32Time"=2 (0x2)
"VSS"=3 (0x3)
"vsmon"=2 (0x2)
"UxTuneUp"=2 (0x2)
"usnjsvc"=3 (0x3)
"UPS"=3 (0x3)
"TrkWks"=2 (0x2)
"Themes"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"SwPrv"=3 (0x3)
"stisvc"=2 (0x2)
"srservice"=2 (0x2)
"Spooler"=2 (0x2)
"ShellHWDetection"=2 (0x2)
"SharedAccess"=2 (0x2)
"SENS"=2 (0x2)
"seclogon"=2 (0x2)
"Schedule"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RSVP"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"ProtectedStorage"=2 (0x2)
"PolicyAgent"=2 (0x2)
"PlugPlay"=2 (0x2)
"PDSched"=2 (0x2)
"PDEngine"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"Nla"=3 (0x3)
"Netman"=3 (0x3)
"Netlogon"=3 (0x3)
"MysqlInventime"=3 (0x3)
"MSIServer"=3 (0x3)
"MSDTC"=3 (0x3)
"mnmsrvc"=3 (0x3)
"LmHosts"=2 (0x2)
"LexBceS"=2 (0x2)
"lanmanworkstation"=2 (0x2)
"lanmanserver"=2 (0x2)
"ImapiService"=3 (0x3)
"IDriverT"=3 (0x3)
"HTTPFilter"=3 (0x3)
"HidServ"=2 (0x2)
"helpsvc"=2 (0x2)
"gusvc"=2 (0x2)
"GenericHidService"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"EventSystem"=3 (0x3)
"Eventlog"=2 (0x2)
"ERSvc"=2 (0x2)
"dmserver"=3 (0x3)
"dmadmin"=3 (0x3)
"Dhcp"=2 (0x2)
"CyberLink Media Library Service"=2 (0x2)
"CryptSvc"=2 (0x2)
"COMSysApp"=3 (0x3)
"CLSched"=2 (0x2)
"CLCapSvc"=2 (0x2)
"CiSvc"=3 (0x3)
"Browser"=2 (0x2)
"BITS"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"AudioSrv"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"aswUpdSv"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"AOL ACS"=2 (0x2)
"ALG"=3 (0x3)
"ADSLAutoconnect"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58368:TCP"= 58368:TCP:Pando P2P TCP Listening Port
"58368:UDP"= 58368:UDP:Pando P2P UDP Listening Port
"58217:TCP"= 58217:TCP:Pando P2P TCP Listening Port
"58217:UDP"= 58217:UDP:Pando P2P UDP Listening Port
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-02-22 16:40:10 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 18:56:21
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-28 18:58:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-28 17:58:47
ComboFix2.txt 2007-12-22 10:57:54
.
2008-02-27 18:59:18 --- E O F ---