ComboFix 08-01-15.1 - GUILLARD 2008-01-14 22:32:59.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.236 [GMT 1:00]
Running from: C:\Documents and Settings\GUILLARD\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\GUILLARD\Application Data\ShoppingReport\cs\res2\WhiteList.dbs
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Bin\2.0.26\ShoppingReport.dll
C:\Program Files\ShoppingReport\Uninst.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-15 to 2008-01-15 ))))))))))))))))))))))))))))))))))))
.
2008-01-14 18:23 . 2008-01-14 18:23 <REP> d-------- C:\WINDOWS\LastGood
2007-12-26 18:34 . 2007-12-26 18:34 <REP> d-------- C:\Documents and Settings\GUILLARD\Phone Browser
2007-12-26 18:29 . 2007-12-26 19:58 <REP> d-------- C:\Documents and Settings\GUILLARD\Application Data\Nokia Multimedia Player
2007-12-26 18:09 . 2007-12-26 18:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-26 18:08 . 2007-12-26 19:58 <REP> d-------- C:\Documents and Settings\GUILLARD\Application Data\Nokia
2007-12-26 18:07 . 2007-12-26 18:07 <REP> d-------- C:\Program Files\PC Connectivity Solution
2007-12-26 18:07 . 2007-12-26 18:07 <REP> d-------- C:\Program Files\Fichiers communs\PCSuite
2007-12-26 18:07 . 2007-12-26 18:08 <REP> d-------- C:\Program Files\Fichiers communs\Nokia
2007-12-26 18:07 . 2007-12-26 18:07 <REP> d-------- C:\Program Files\DIFX
2007-12-26 18:07 . 2007-12-26 18:09 <REP> d-------- C:\Documents and Settings\GUILLARD\Application Data\PC Suite
2007-12-26 18:07 . 2007-02-22 11:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-12-26 18:07 . 2007-02-22 11:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-12-26 18:07 . 2007-02-22 11:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-12-26 18:07 . 2007-02-22 11:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-12-26 18:07 . 2007-02-22 11:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-12-26 18:06 . 2007-12-26 18:07 <REP> d-------- C:\Program Files\Nokia
2007-12-26 18:06 . 2007-02-22 11:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-12-26 18:04 . 2007-12-26 18:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Installations
2007-12-26 12:28 . 2007-12-26 12:28 <REP> d-------- C:\Documents and Settings\GUILLARD\Application Data\Application Data
2007-12-25 20:35 . 2008-01-14 21:48 <REP> d-------- C:\Documents and Settings\GUILLARD\Shared
2007-12-25 20:34 . 2007-12-25 20:34 <REP> d-------- C:\Program Files\LimeWire
2007-12-25 20:34 . 2008-01-14 21:49 <REP> d-------- C:\Documents and Settings\GUILLARD\Incomplete
2007-12-25 20:34 . 2008-01-14 20:00 <REP> d-------- C:\Documents and Settings\GUILLARD\Application Data\LimeWire
2007-12-18 19:30 . 2007-12-18 19:49 <REP> d-------- C:\Program Files\Project64 1.6
2007-12-16 16:02 . 2007-12-16 16:02 <REP> d--h----- C:\WINDOWS\PIF
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 17:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\NPF
2008-01-14 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZangoSA
2008-01-14 17:15 5 ----a-w C:\NPF_USER.DAT
2008-01-02 15:36 --------- d-----w C:\Documents and Settings\GUILLARD\Application Data\dvdcss
2007-12-30 21:09 --------- d-----w C:\Program Files\eMule
2007-12-23 15:52 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-19 15:38 --------- d-----w C:\Program Files\SPYWAREfighter
2007-12-18 19:10 --------- d-----w C:\Program Files\Windows Live
2007-12-18 19:09 --------- d-----w C:\Program Files\VirtualDJ
2007-12-18 19:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-18 19:08 --------- d-----w C:\Program Files\Ulead Systems
2007-12-18 19:07 --------- d-----w C:\Program Files\GIMP-2.0
2007-12-16 20:43 --------- d-----w C:\Documents and Settings\GUILLARD\Application Data\Skype
2007-12-08 12:48 --------- d-----w C:\Program Files\DivX
2007-12-07 13:06 --------- d-----w C:\Program Files\Veoh Networks
2007-12-01 12:05 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-30 11:48 --------- d-----w C:\Program Files\Picasa2
2007-11-22 08:08 --------- d-----w C:\Documents and Settings\GUILLARD\Application Data\Zango
2007-11-21 19:15 --------- d-----w C:\Program Files\Zango
2007-11-21 19:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-11-18 19:20 --------- d-----w C:\Program Files\Share_Accelerator_MM
2007-11-18 19:15 --------- d-----w C:\Program Files\Zapu
2007-11-16 11:13 --------- d-----w C:\Program Files\iTunes
2007-11-16 11:13 --------- d-----w C:\Program Files\iPod
2007-11-16 11:11 --------- d-----w C:\Program Files\QuickTime
2007-11-15 15:08 --------- d-----w C:\Documents and Settings\GUILLARD\Application Data\Canon
2007-11-15 09:11 --------- d-----w C:\Program Files\PhotoFiltre
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-02-17 16:40 54 -c--a-w C:\Program Files\delir.gio
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-12-21 19:26 190024]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 07:18 307200]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-07-25 17:04 171448]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 17:45 1052672]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2007-12-03 13:21 3461120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 13:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [ ]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [ ]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-10 17:44 98394]
"WLAN"="C:\WINDOWS\system32\WLan.exe" [2005-11-25 07:52 221184]
"Norman ZANDA"="C:\Norman\Npm\bin\ZLH.exe" [2007-04-27 12:59 183352]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-10 17:43 688218]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-05-17 14:11 26112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
"spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52 115608]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36 267048]
"ZangoOE"="C:\Program Files\Zango\bin\10.0.370.0\OEAddOn.exe" [2007-10-03 04:21 91400]
"ZangoSA"="C:\Program Files\Zango\bin\10.0.370.0\ZangoSA.exe" [2007-11-14 22:36 771336]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 15:10 271360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17 1241088]
C:\Documents and Settings\GUILLARD\Mes documents\Menu D‚marrer\Programmes\D‚marrage\
Groom Agent.lnk - C:\Program Files\TooX\Groom\GroomAgent.exe [2007-02-17 17:40:07]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide du logiciel HP Image Zone.lnk
backup=C:\WINDOWS\pss\Démarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VProperty.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\VProperty.lnk
backup=C:\WINDOWS\pss\VProperty.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-05 13:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 14:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2005-11-28 12:52 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2005-11-28 12:55 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2005-11-28 12:55 98304 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-02 18:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2006-12-21 19:26 190024 C:\Program Files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--a------ 2005-05-11 12:48 127118 c:\Apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
--a------ 2007-10-23 22:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-10-19 20:16 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raccourci vers la page des propriétés de High Definition Audio]
--a------ 2005-01-07 16:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2006-05-17 14:11 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-12-19 14:52 15797248 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys]
--a------ 2005-11-17 08:51 975360 C:\APPS\SMP\SmpSys.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u
R0 NDIS_RD;Firewall Engine Type-R2;C:\WINDOWS\system32\drivers\NDIS_RD.sys [2004-12-06 11:18]
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2006-02-27 14:00]
R0 O2SDRDR;O2SDRDR;C:\WINDOWS\system32\DRIVERS\o2sd.sys [2006-02-20 15:01]
R1 kioport;kioport Library Driver;C:\WINDOWS\system32\drivers\kioport.sys [2005-04-29 13:02]
R1 TDI_RD;Firewall Engine Type-R;C:\WINDOWS\system32\drivers\tdi_rd.sys [2004-10-13 23:01]
R2 Ndiskio;Ndiskio;C:\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 09:55]
R3 CIR;Hid Device;C:\WINDOWS\system32\DRIVERS\CIR.sys [2005-09-30 10:37]
R3 kbd;Keyboard;C:\WINDOWS\system32\DRIVERS\kbd.sys [2005-09-30 10:36]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-05-31 13:51]
R3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe [2007-05-24 12:32]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Norman\Nvc\BIN\NVCSCHED.EXE [2007-03-15 10:48]
R3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys [2007-06-08 11:52]
R3 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe" [2007-06-08 11:52]
S3 nvcfsr;nvcfsr;C:\Norman\Nvc\bin\nvcfsr.sys [2007-01-09 13:25]
S3 nvcoafl51;nvcoafl51;C:\Norman\Nvc\bin\nvcoafl51.sys [2007-01-09 13:25]
S3 nvcoaft51;nvcoaft51;C:\Norman\Nvc\bin\nvcoaft51.sys [2007-01-09 13:25]
S3 nvcoarc51;nvcoarc51;C:\Norman\Nvc\bin\nvcoarc51.sys [2007-01-09 13:25]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2005-12-22 13:45]
S3 SPC610NC;SPC 610NC Laptop Camera;C:\WINDOWS\system32\DRIVERS\SPC610NC.SYS [2005-09-07 20:39]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4447474-60e3-11db-bb1a-001302332c2a}]
\Shell\AutoRun\command - setupSNK.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-20 09:55:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-14 18:30:00 C:\WINDOWS\Tasks\Extension de garantie.job"
- C:\APPS\SMP\PBCARNOT.EXE
"2008-01-14 18:30:00 C:\WINDOWS\Tasks\Master CD_DVD Creator.job"
- C:\Apps\SMP\MCDCHECK.EXE
"2008-01-14 21:29:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-15 22:38:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-15 22:38:54
ComboFix-quarantined-files.txt 2008-01-15 21:38:51
ComboFix2.txt 2007-08-09 19:56:56
ComboFix3.txt 2007-08-08 21:13:14
.
2008-01-10 09:57:00 --- E O F ---
Voilà mon rapport...
Je n'ai pas très bien compris la fin... que dois-je supprimer ?