voici le rapport combofixComboFix 08-08-01.04 - HERSE 2008-08-02 14:49:24.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.499 [GMT 2:00]
Endroit: C:\Documents and Settings\HERSE\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bnstllxk.ini
C:\WINDOWS\system32\dcjbysvy.ini
C:\WINDOWS\system32\ejmzjc.dll
C:\WINDOWS\system32\erfpgwed.dll
C:\WINDOWS\system32\olgxfjdr.ini
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-02 to 2008-08-02 ))))))))))))))))))))))))))))))))))))
.
2008-08-02 14:42 . 2008-08-02 14:45 <REP> d-------- C:\Program Files\Navilog1
2008-08-02 03:53 . 2008-08-02 03:53 <REP> d-------- C:\Nouveau dossier
2008-08-02 03:11 . 2008-08-02 14:33 <REP> d-------- C:\Program Files\Spyware Terminator
2008-08-02 03:11 . 2008-08-02 03:35 <REP> d-------- C:\Program Files\Crawler
2008-08-02 03:11 . 2008-08-02 14:33 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\Spyware Terminator
2008-08-02 03:11 . 2008-08-02 14:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-08-02 03:11 . 2008-08-02 03:11 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-08-02 00:09 . 2008-05-15 17:51 322 --a------ C:\boot.ini.comodofirewall
2008-07-31 00:37 . 2008-07-31 00:44 <REP> d-------- C:\Program Files\Glary Utilities
2008-07-28 06:42 . 2002-01-05 20:48 974,848 --a------ C:\WINDOWS\mfc70.dll
2008-07-28 06:42 . 2002-01-05 20:36 964,608 --a------ C:\WINDOWS\mfc70u.dll
2008-07-28 06:42 . 2002-01-05 19:40 487,424 --a------ C:\WINDOWS\msvcp70.dll
2008-07-28 06:42 . 2003-02-21 20:42 348,160 --a------ C:\WINDOWS\msvcr71.dll
2008-07-28 06:42 . 2002-01-05 19:37 344,064 --a------ C:\WINDOWS\msvcr70.dll
2008-07-28 06:42 . 2002-09-10 06:53 323,072 --a------ C:\WINDOWS\msvcrt.dll
2008-07-27 17:03 . 2008-07-27 17:03 <REP> d-------- C:\Program Files\Avira
2008-07-27 17:03 . 2008-07-27 17:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-27 15:26 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-27 15:21 . 2008-07-27 15:21 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\Malwarebytes
2008-07-27 15:20 . 2008-07-27 15:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 15:18 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-27 15:16 . 2008-07-31 00:47 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 14:59 . 2008-07-27 17:13 <REP> d-------- C:\Program Files\Ascentive
2008-07-27 14:58 . 2007-10-17 10:19 1,066,176 --a------ C:\WINDOWS\system32\mscomctl.ocx
2008-07-27 14:58 . 2007-10-17 10:19 20,480 --a------ C:\WINDOWS\system32\SysRestore.dll
2008-07-27 14:57 . 2008-04-17 16:22 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-07-26 01:58 . 2008-07-26 01:58 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\TuneUp Software
2008-07-26 01:57 . 2008-07-26 01:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-07-26 01:54 . 2008-07-26 01:54 424 --a------ C:\WINDOWS\zipgenius.xml
2008-07-25 21:19 . 2008-07-25 21:19 244 --ah----- C:\sqmnoopt00.sqm
2008-07-25 21:19 . 2008-07-25 21:19 232 --ah----- C:\sqmdata00.sqm
2008-07-24 05:25 . 2008-07-24 05:31 2,632 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-24 05:24 . 2008-07-31 00:14 <REP> d-------- C:\Documents and Settings\HERSE\SmitfraudFix
2008-07-24 01:19 . 2008-07-24 06:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-07-23 22:56 . 2008-07-31 00:52 <REP> d-------- C:\Documents and Settings\HERSE\.housecall6.6
2008-07-23 22:47 . 2008-07-23 22:47 40 --a------ C:\WINDOWS\TSC.INI
2008-07-23 22:40 . 2008-07-23 22:44 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-07-23 22:39 . 2008-07-23 22:44 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-07-23 22:39 . 2008-07-23 22:44 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-07-22 03:08 . 2008-07-23 22:07 44,061 ---hs---- C:\WINDOWS\system32\iqswoptv.ini
2008-07-22 03:02 . 2008-07-22 03:02 <REP> d-------- C:\Program Files\Spamihilator
2008-07-22 02:59 . 2008-07-26 05:07 <REP> d-------- C:\Program Files\a-squared Free
2008-07-21 17:39 . 2008-07-21 18:41 1,712 --a------ C:\WINDOWS\wininit.ini
2008-07-21 17:17 . 2008-07-22 02:25 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-21 17:17 . 2008-07-22 02:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-21 16:58 . 2008-07-22 02:24 43,701 ---hs---- C:\WINDOWS\system32\kwtsqanq.ini
2008-07-20 02:14 . 2008-07-31 00:52 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\dvdcss
2008-07-18 00:37 . 2008-07-22 05:40 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\Player Orange
2008-07-16 21:03 . 2008-07-16 21:03 <REP> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-15 06:40 . 2008-07-15 07:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\VirtualFarm
2008-07-15 05:57 . 2008-07-15 05:57 <REP> d-------- C:\Program Files\Fichiers communs\Oberon Media
2008-07-10 23:56 . 2008-07-10 23:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2008-07-10 23:51 . 2008-07-22 03:52 <REP> d-------- C:\Program Files\Panda Security
2008-07-10 23:47 . 2008-07-10 23:47 227 --a------ C:\WINDOWS\AvDetected.ini
2008-07-10 22:31 . 2008-07-10 22:31 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\agi
2008-07-10 22:30 . 2008-07-10 22:30 <REP> d-------- C:\Documents and Settings\HERSE\Application Data\agi
2008-07-10 22:30 . 2008-07-10 22:30 2,113,536 --a------ C:\WINDOWS\system32\python25.dll
2008-07-10 22:30 . 2008-07-10 22:30 327,680 --a------ C:\WINDOWS\system32\pythoncom25.dll
2008-07-10 22:30 . 2008-07-10 22:30 102,400 --a------ C:\WINDOWS\system32\pywintypes25.dll
2008-07-08 19:54 . 2008-07-12 18:42 <REP> d-------- C:\Program Files\CIMW
2008-07-04 13:50 . 2008-07-20 17:49 <REP> d-------- C:\Program Files\YesMessenger
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-02 05:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-02 04:59 --------- d-----w C:\Documents and Settings\HERSE\Application Data\LimeWire
2008-07-30 22:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-30 22:52 --------- d-----w C:\Program Files\Orange
2008-07-30 22:52 --------- d-----w C:\Program Files\eMule
2008-07-30 22:52 --------- d-----w C:\Program Files\AskTBar
2008-07-30 22:47 --------- d-----w C:\Program Files\LimeWire
2008-07-24 04:37 --------- d-----w C:\Documents and Settings\HERSE\Application Data\New4manager
2008-07-24 04:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\File dvd base road
2008-07-10 21:38 --------- d-----w C:\Program Files\MSN Messenger
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 23:56 --------- d-----w C:\Program Files\Yahoo!
2008-06-15 23:54 --------- d-----w C:\Documents and Settings\HERSE\Application Data\OpenOffice.org2
2008-06-15 23:41 --------- d-----w C:\Program Files\DNA
2008-06-15 23:41 --------- d-----w C:\Documents and Settings\HERSE\Application Data\GrabIt
2008-06-15 23:41 --------- d-----w C:\Documents and Settings\HERSE\Application Data\Azureus
2008-06-15 23:41 --------- d-----w C:\Documents and Settings\HERSE\Application Data\.ABC
2008-06-15 23:38 --------- d-----w C:\Program Files\FrostWire
2008-06-14 22:17 --------- d-----w C:\Documents and Settings\HERSE\Application Data\FrostWire
2008-06-14 21:36 --------- d-----w C:\Program Files\Azureus
2008-06-14 20:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 18:28 --------- d-----w C:\Program Files\Fichiers communs\logishrd
2008-06-11 23:17 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-06-09 22:42 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-06-09 22:41 --------- d-----w C:\Program Files\Java
2008-06-08 22:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-06-08 21:29 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-06-08 20:46 --------- d-----w C:\Documents and Settings\HERSE\Application Data\vlc
2008-06-08 20:45 --------- d-----w C:\Program Files\VideoLAN
2008-06-08 19:39 --------- d-----w C:\Program Files\Windows Live
2008-06-08 19:26 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-06-08 19:26 --------- d-----w C:\Program Files\Windows Live Favorites
2008-06-08 19:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-06-08 18:59 --------- d-----w C:\Program Files\iOpus
2008-06-06 13:40 --------- d-----w C:\Documents and Settings\HERSE\Application Data\InfraRecorder
2008-06-06 13:32 --------- d-----w C:\Program Files\InfraRecorder
2008-06-06 13:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logishrd
2008-06-06 13:13 --------- d-----w C:\Program Files\Logitech
2008-06-06 13:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Logitech
2008-06-06 11:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-06-06 10:48 --------- d-----w C:\Documents and Settings\HERSE\Application Data\MSNInstaller
2008-06-06 00:16 --------- d-----w C:\Documents and Settings\HERSE\Application Data\GlarySoft
2008-06-06 00:04 58,952 ----a-w C:\WINDOWS\system32\MsgPlusLoader.dll
2008-06-06 00:04 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-06-05 23:40 --------- d-----w C:\Program Files\Fichiers communs\France Telecom
2008-06-05 23:36 --------- d-----w C:\Program Files\SAGEM
2008-06-05 23:35 --------- d-----w C:\Program Files\Securitoo
2008-06-05 21:47 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"helpmeal"="C:\DOCUME~1\HERSE\APPLIC~1\NEW4MA~1\bird anti heck.exe" [2008-07-24 06:34 513536]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 06:11 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 06:13 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 06:10 94208]
"SystrayORAHSS"="C:\Program Files\Orange\Systray\SystrayApp.exe" [2007-09-25 20:08 94208]
"ORAHSSSessionManager"="C:\Program Files\Orange\SessionManager\SessionManager.exe" [2007-09-25 19:10 102400]
"Base road long save"="C:\Documents and Settings\All Users\Application Data\File dvd base road\name mp3.exe" [2008-08-02 03:10 3815936]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 12:25 249896]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-08-02 03:11 1783808]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 10:58 16264192 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=MsgPlusLoader.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\kav\\kis8.0\\french\\setup.exe"=
"C:\\Program Files\\CIMW\\CIMW.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-08-02 03:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f7c9333-2274-11dd-98f2-8db3afff1b03}]
\Shell\AutoRun\command - EXPLORER.EXE
\Shell\explore\Command - EXPLORER.EXE
\Shell\open\Command - EXPLORER.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f7c9334-2274-11dd-98f2-8db3afff1b03}]
\Shell\AutoRun\command - I:\EXPLORER.EXE
\Shell\explore\Command - I:\EXPLORER.EXE
\Shell\open\Command - I:\EXPLORER.EXE
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
*Newly Created Service* - SP_RSDRV2
*Newly Created Service* - SP_RSSRV
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-02 C:\WINDOWS\Tasks\AA3051EF919BC75B.job
- c:\docume~1\herse\applic~1\new4ma~1\Sect Four Mode.exe [2008-07-24 06:37]
2008-08-01 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Program Files\Glary Utilities\initialize.exe [2008-07-18 11:08]
2008-08-01 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe []
2008-08-02 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\HERSE\Application Data\Mozilla\Firefox\Profiles\
01alkuaf.default\
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjava11.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjava12.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjava13.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjava14.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjava32.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll
FF -: plugin - C:\Program Files\Java\jre1.6.0_06\bin\npoji610.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
www.gmer.net...
Rootkit scan 2008-08-02 14:50:31
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-02 14:51:18
ComboFix-quarantined-files.txt 2008-08-02 12:51:15
Pre-Run: 133,511,311,360 octets libres
Post-Run: 133,544,394,752 octets libres
232 --- E O F --- 2008-07-18 14:16:09