ComboFix 07-11-07.3 - Administrateur 2007-11-07 13:37:29.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.451 [GMT 1:00]
Running from: D:\BASURA\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\auto.exe
C:\Autorun.inf
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\FD2389C2.EXE
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wpcap.dll
D:\auto.exe
D:\Autorun.inf
E:\auto.exe
E:\Autorun.inf
F:\auto.exe
F:\Autorun.inf
G:\auto.exe
G:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\NPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-07 to 2007-11-07 ))))))))))))))))))))))))))))))))))))
.
2007-11-07 13:38 40,960 --a------ C:\WINDOWS\system32\5C760F7C.DLL
2007-11-07 13:36 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 22:17 <REP> d-------- C:\Program Files\CCleaner
2007-11-02 23:56 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Trymedia
2007-11-02 23:54 <REP> d-------- C:\Program Files\ReflexiveArcade
2007-10-28 20:05 <REP> d-------- C:\Program Files\TVUPlayer
2007-10-28 20:05 <REP> d-------- C:\Documents and Settings\Administrateur.TITANIUM\Application Data\TVU Networks
2007-10-24 20:00 241,664 --a------ C:\WINDOWS\system32\UCLiveSocket.dll
2007-10-24 19:59 159,744 --a------ C:\WINDOWS\system32\UCLiveCore.dll
2007-10-24 19:59 153,088 --a------ C:\UNWISE.EXE
2007-10-23 20:44 <REP> d-------- C:\Program Files\PeerTV
2007-10-23 00:27 <REP> d--h----- C:\WINDOWS\PIF
2007-10-22 18:17 <REP> d-------- C:\Program Files\PartitionMagic8
2007-10-22 18:08 306,688 --a------ C:\WINDOWS\IsUn0411.exe
2007-10-20 04:21 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT\Application Data\AVG7
2007-10-20 04:05 <REP> d-------- C:\Documents and Settings\Administrateur.TITANIUM\Application Data\AVG7
2007-10-20 04:04 <REP> d-------- C:\Program Files\AVG7
2007-10-20 04:04 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-10-20 04:04 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-10-20 04:04 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2007-10-20 02:35 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2007-10-19 20:30 <REP> d-------- C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Skype
2007-10-19 20:29 <REP> d-------- C:\Program Files\Skype
2007-10-19 20:29 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2007-10-19 20:29 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
2007-10-18 23:51 <REP> d-------- C:\WINDOWS\system32\QuickTime
2007-10-18 23:51 <REP> d-------- C:\Program Files\TechSmith
2007-10-18 23:51 <REP> d-------- C:\Program Files\Fichiers communs\TechSmith Shared
2007-10-18 23:51 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\TechSmith
2007-10-18 23:51 107,864 --a------ C:\WINDOWS\system32\tsccvid.dll
2007-10-18 13:56 <REP> d-------- C:\Program Files\WinPcap
2007-10-18 13:56 56,320 --a------ C:\WINDOWS\system32\LM20.DLL
2007-10-18 04:06 <REP> d-------- C:\Documents and Settings\Administrateur.TITANIUM\amsn
2007-10-18 04:05 <REP> d-------- C:\Program Files\aMSN
2007-10-17 19:21 <REP> d-------- C:\Program Files\DITEL
2007-10-15 04:24 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2007-10-10 11:40 <REP> d-------- C:\Program Files\MultiTranse
2007-10-08 18:18 <REP> d-------- C:\WINDOWS\Downloaded Installations
2007-10-08 18:18 <REP> d-------- C:\Program Files\NETGEAR
2007-10-08 18:18 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-07 12:38 --------- d-----w C:\Documents and Settings\Administrateur.TITANIUM\Application Data\uTorrent
2007-10-31 16:57 --------- d-----w C:\Program Files\VoipStunt
2007-10-28 18:22 --------- d-----w C:\Program Files\PokerStars
2007-10-22 17:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-22 17:10 12,400 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-15 22:03 --------- d-----w C:\Program Files\Nokia
2007-10-15 03:23 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2007-10-03 18:50 --------- d-----w C:\Documents and Settings\Administrateur.TITANIUM\Application Data\SopCast
2007-10-03 18:46 --------- d-----w C:\Program Files\SopCast
2007-09-16 03:38 --------- d-----w C:\Program Files\Lame
2007-09-16 01:40 --------- d-----w C:\Program Files\Winamp
2007-09-16 01:05 --------- d-----w C:\Program Files\YouTube Downloader
2007-09-16 00:36 --------- d-----w C:\Documents and Settings\Administrateur.TITANIUM\Application Data\PC Suite
2007-09-16 00:21 --------- d-----w C:\Documents and Settings\Administrateur.TITANIUM\Application Data\Nokia
2007-09-16 00:17 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2007-09-16 00:16 --------- d-----w C:\Program Files\DIFX
2007-09-16 00:15 --------- d-----w C:\Program Files\PC Connectivity Solution
2007-09-16 00:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2007-09-15 23:26 --------- d-----w C:\Documents and Settings\Administrateur.TITANIUM\Application Data\DeepBurner Pro
2007-09-14 09:15 50,520 ----a-w C:\WINDOWS\system32\csvidcap.dll
2007-09-14 06:28 --------- d-----w C:\Program Files\PhotoDenoising
2007-09-10 22:14 --------- d-----w C:\Program Files\Alcohol Soft
2007-09-09 12:04 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-09-09 12:03 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-09-09 10:54 --------- d-----w C:\Program Files\Microsoft Silverlight
2007-09-08 19:11 --------- d-----w C:\Program Files\VLC
2007-09-07 04:40 --------- d-----w C:\Program Files\uTorrent
2007-08-30 23:44 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2007-08-27 06:54 434,252 ----a-w C:\WINDOWS\system32\MSVCRTD.DLL
2007-08-27 06:54 216,576 ----a-w C:\WINDOWS\system32\monln.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:55 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 16:22 C:\WINDOWS\system32\nvmctray.dll]
"AVG7_CC"="C:\PROGRA~1\AVG7\avgcc.exe" [2007-10-26 22:24]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:54]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"=C:\PROGRA~1\AVG7\avgw.exe /RUNONCE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RunDLL32.exe NvMCTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
S2 FA14F5FB;FA14F5FB;C:\WINDOWS\system32\FD2389C2.EXE -k
S3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7FDA5DA0-0C92-E780-F273-B9207984D491}]
C:\WINDOWS\system32:svchost.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-07 13:40:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32:svchost.exe 20480 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2007-11-07 13:41:26 - machine was rebooted
.
--- E O F ---
PS: Parfait ce combofix !!! je n'vait pas de cle usb mais c'est possible qu'un jour jen ai mise une. aparement tout parait clean. merci beaucoup !!!