ComboFix 08-05-29.1 - JACQUELINE 2008-06-01 10:37:17.1 - NTFSx86
Endroit: C:\Documents and Settings\JACQUELINE\Mes documents\nathalie\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-01 to 2008-06-01 ))))))))))))))))))))))))))))))))))))
.
2008-05-29 20:10 . 2008-05-29 20:10 <REP> d-------- C:\WINDOWS\ERUNT
2008-05-29 20:09 . 2008-05-29 20:29 <REP> d-------- C:\SDFix
2008-05-24 20:28 . 2008-05-24 20:28 <REP> d-------- C:\Program Files\Avira
2008-05-24 20:28 . 2008-05-24 20:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-24 09:40 . 2008-05-24 09:40 <REP> d-------- C:\Documents and Settings\JACQUELINE\Application Data\Grisoft
2008-05-24 09:38 . 2008-05-24 09:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-24 09:38 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-21 09:47 . 2008-05-21 09:47 <REP> d-------- C:\Documents and Settings\JACQUELINE\Application Data\AXPFixer
2008-05-21 09:45 . 2008-05-21 09:45 73,728 --a------ C:\WINDOWS\system32\aspimgr.exe_
2008-05-19 18:03 . 2008-05-19 18:03 <REP> d-------- C:\Program Files\MSN Messenger
2008-05-18 17:34 . 2008-05-19 07:57 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-05-18 11:12 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-05-18 11:03 . 2008-05-18 11:03 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-18 10:16 . 2008-05-18 17:35 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-05-18 10:15 . 2008-05-18 10:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-17 17:06 . 2008-05-21 09:43 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-17 17:06 . 2008-05-17 17:06 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-16 19:22 . 2003-04-05 14:33 20,369 --------- C:\WINDOWS\hpoins01.dat.temp
2008-05-16 19:22 . 2003-04-05 14:33 16,622 --------- C:\WINDOWS\hpomdl01.dat.temp
2008-05-16 19:19 . 2008-05-16 20:01 20,458 --a------ C:\WINDOWS\hpoins01.dat
2008-05-16 19:19 . 2003-04-05 14:33 16,622 --------- C:\WINDOWS\hpomdl01.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-01 08:19 --------- d-----w C:\Program Files\Wanadoo
2008-05-24 19:42 --------- d-----w C:\Program Files\Symantec
2008-05-24 19:42 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-24 19:19 --------- d-----w C:\Program Files\Norton AntiVirus
2008-05-24 19:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-19 16:05 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-18 15:35 --------- d-----w C:\Program Files\Fichiers communs\AOL
2008-05-16 18:01 82,380 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-05-16 07:11 522 ---ha-w C:\hpothb07.dat
2008-05-13 09:43 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-13 09:40 --------- d-----w C:\Documents and Settings\JACQUELINE\Application Data\AdobeUM
2008-04-23 16:01 905 ---ha-w C:\Documents and Settings\JACQUELINE\hpothb07.dat
2008-04-22 16:45 --------- d-----w C:\Program Files\GpsPrevent
2008-04-20 13:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-08-09 07:01 164 ---ha-w C:\Documents and Settings\All Users\hpothb07.dat
2006-09-15 15:51 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
------- Sigcheck -------
2003-04-24 14:00 12800 333a4db8410d8e24db06d6aebecdc7c2 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-20 01:10 14336 2979b03d5382a602623c0535b16ab9c0 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2004-08-20 01:10 17408 16ac63960d80ba4789a30216b26d7587 C:\WINDOWS\system32\svchost.exe
2004-06-17 02:08 487424 f5d97f77ac97b244ff33280154186065 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2003-04-24 14:00 520704 71820bc9ee6653c8748922459dfc384d C:\WINDOWS\$NtUninstallKB841533$\winlogon.exe
2004-08-20 01:10 506368 123eea158f74d0f67a51dcdf065d1091 C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-20 01:10 510464 ed6e4e656e8df8c8150381bf6959434b C:\WINDOWS\system32\winlogon.exe
2003-04-24 14:00 101888 fc0691097471ee374907e1024edcbd43 C:\WINDOWS\$NtServicePackUninstall$\services.exe
2004-08-20 01:10 108544 63dcde1a0d86eeb8924d6738ff616ead C:\WINDOWS\ServicePackFiles\i386\services.exe
2004-08-20 01:10 110592 db73c55454ce2a12b3230d3e4b2dad2a C:\WINDOWS\system32\services.exe
2003-04-24 14:00 11776 b7b1c150aff59455db4df082815f88f5 C:\WINDOWS\$NtServicePackUninstall$\lsass.exe
2004-08-20 01:09 13312 259af82a0932eea4f316f92db94707b6 C:\WINDOWS\ServicePackFiles\i386\lsass.exe
2004-08-20 01:09 14848 9560ee136029e224ff27c172ecb88bc9 C:\WINDOWS\system32\lsass.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\taskbaricon.exe" [2004-10-05 17:00 61440]
"SoundMan"="SOUNDMAN.EXE" [2004-04-22 18:04 57344 C:\WINDOWS\SOUNDMAN.EXE]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-10-23 13:58 98304]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-04-22 18:05 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-04-22 18:05 118784]
"Camera Detector"="C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.exe" [2003-11-17 10:52 208896]
"AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [ ]
"AntivirusRegistration"="C:\Program Files\Excid.com Aps\eTrust Antivirus Registration\EzAntivirusRegistrationCheck.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R2 LogWatch;Event Log Watch;C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2002-09-20 17:29]
R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-11-02 12:53]
S3 CA_LIC_CLNT;Client de licence CA;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe [2002-09-20 17:27]
S3 CA_LIC_SRVR;Serveur de licence CA;C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe [2002-09-20 17:41]
S3 lredbooo;lredbooo;C:\DOCUME~1\JACQUE~1\LOCALS~1\Temp\lredbooo.sys []
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-16 18:05:59 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1210960889.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-05-31 16:11:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-01 10:42:27
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-01 10:47:02
ComboFix-quarantined-files.txt 2008-06-01 08:46:46
Pre-Run: 9,080,377,344 octets libres
Post-Run: 9,124,012,032 octets libres
121 --- E O F --- 2008-05-29 16:56:48