Dominico
Inscrit le: 17 Juil 2007 Messages: 14
|
Posté le: Mar Juil 17, 2007 9:23 pm Sujet du message: |
|
|
SmitFraudFix v2.204
Rapport fait à 22:21:33,15, 17/07/2007
Executé à partir de D:\Documents and Settings\Dominico\Bureau\GIANG\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
C:\WINDOWS\RTHDCPL.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\YesMessenger\YesMessenger.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» D:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Dominico
»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Dominico\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\Dominico\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kditi.exe"
kditi.exe détecté !
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
xpdx détecté, utilisez un scanner de Rootkit
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Votre ordinateur est certainement victime d'un détournement de DNS: 85.255.x.x détecté !
Description: Palladia 300/400 Usb Adsl Modem #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 85.255.116.103
DNS Server Search Order: 85.255.112.185
Description: Palladia 300/400 Usb Adsl Modem #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{02E2B3B7-DC1F-4F8C-87D3-AEE2A62D0C66}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{155D5A1B-02EC-4F55-A1F4-9AFDE78D510E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B1BFA5EF-0493-4B56-86AD-9E4CB7E3DAB7}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CCS\Services\Tcpip\..\{E5ED37EE-63F9-4511-91CC-24F734EABD2A}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS1\Services\Tcpip\..\{02E2B3B7-DC1F-4F8C-87D3-AEE2A62D0C66}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS1\Services\Tcpip\..\{155D5A1B-02EC-4F55-A1F4-9AFDE78D510E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B1BFA5EF-0493-4B56-86AD-9E4CB7E3DAB7}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS1\Services\Tcpip\..\{E5ED37EE-63F9-4511-91CC-24F734EABD2A}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS2\Services\Tcpip\..\{02E2B3B7-DC1F-4F8C-87D3-AEE2A62D0C66}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS2\Services\Tcpip\..\{155D5A1B-02EC-4F55-A1F4-9AFDE78D510E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS2\Services\Tcpip\..\{B1BFA5EF-0493-4B56-86AD-9E4CB7E3DAB7}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS2\Services\Tcpip\..\{E5ED37EE-63F9-4511-91CC-24F734EABD2A}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS3\Services\Tcpip\..\{02E2B3B7-DC1F-4F8C-87D3-AEE2A62D0C66}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{155D5A1B-02EC-4F55-A1F4-9AFDE78D510E}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B1BFA5EF-0493-4B56-86AD-9E4CB7E3DAB7}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CS3\Services\Tcpip\..\{E5ED37EE-63F9-4511-91CC-24F734EABD2A}: DhcpNameServer=85.255.116.103,85.255.112.185
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.116.103 85.255.112.185
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Désolé je n'ai pas fait gaffe |
|
Dominico
Inscrit le: 17 Juil 2007 Messages: 14
|
Posté le: Dim Juil 22, 2007 11:28 pm Sujet du message: |
|
|
Merci et voilà le rapport .
"Dominico" - 2007-07-23 0:16:51 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\b122.exe
C:\WINDOWS\b136.exe
C:\WINDOWS\system32\krgyvzuhvs.dat
C:\WINDOWS\system32\krgyvzuhvs_nav.dat
C:\WINDOWS\system32\krgyvzuhvs_navps.dat
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\pgzako.dat
C:\WINDOWS\system32\pgzako_nav.dat
C:\WINDOWS\system32\pgzako_navps.dat
C:\WINDOWS\system32\xpdx.sys
C:\WINDOWS\wr.txt
D:\DOCUME~1\Dominico\APPLIC~1\WinTouch
D:\DOCUME~1\Dominico\APPLIC~1\WinTouch\wintouch.cfg
D:\DOCUME~1\Dominico\APPLIC~1\WinTouch\WinTouch.rgn
D:\DOCUME~1\Dominico\APPLIC~1\WinTouch\WTUninstaller.exe
D:\DOCUME~1\Dominico\Bureau.\internet explorer.lnk
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_ASC3550U
-------\LEGACY_RUNTIME
-------\asc3550u
((((((((((((((((((((((((( Files Created from 2007-06-22 to 2007-07-22 )))))))))))))))))))))))))))))))
2007-07-23 00:14 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-17 21:11 4,234 --a------ C:\WINDOWS\system32\tmp.reg
2007-07-17 20:17 44,211 --a------ C:\WINDOWS\system32\16577962ld.exe
2007-07-17 16:56 44,211 --a------ C:\WINDOWS\system32\55593432ld.exe
2007-07-17 16:55 35,840 --a------ C:\WINDOWS\system32\55508752ld.exe
2007-07-17 15:38 44,219 --a------ C:\WINDOWS\system32\38123282ld.exe
2007-07-17 15:35 44,219 --a------ C:\WINDOWS\system32\354002ld.exe
2007-07-10 20:41 <REP> d-------- C:\Program Files\Prison Tycoon
2007-07-10 17:25 35,840 --a------ C:\WINDOWS\system32\msvcrtd.exe
2007-07-10 17:15 95,872 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-07-10 17:15 94,552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-10 17:15 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-10 17:15 745,600 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-10 17:15 71,328 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-10 17:15 43,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-10 17:15 26,888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-10 17:15 <REP> d-------- C:\Program Files\Alwil Software
2007-07-10 00:22 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-07-08 23:12 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-08 23:12 <REP> d-------- C:\Program Files\CCleaner
2007-07-08 22:58 <REP> d-------- C:\WINDOWS\system32\NtmsData
2007-07-08 18:45 2,432 --a------ C:\WINDOWS\wds.dat
2007-07-08 18:45 1,680 --a------ C:\WINDOWS\rmt.dat
2007-07-08 18:20 259,584 --a------ C:\WINDOWS\system32\thjqqdjo.exe
2007-07-08 18:05 259,584 --a------ C:\WINDOWS\system32\cewetjjme.exe
2007-07-08 17:54 258,048 --a------ C:\WINDOWS\system32\ixmbuaj.exe
2007-07-08 10:56 259,072 --a------ C:\WINDOWS\system32\xfrwev.exe
2007-07-08 10:23 92,160 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2007-07-08 10:12 262,656 --a------ C:\WINDOWS\system32\ryiznl.exe
2007-07-08 10:05 270,336 --a------ C:\WINDOWS\system32\pqepne.exe
2007-07-08 08:32 267,264 --a------ C:\WINDOWS\system32\xsotivrh.exe
2007-07-08 00:16 275,456 --a------ C:\WINDOWS\system32\zljgbtjixy.exe
2007-07-08 00:08 265,216 --a------ C:\WINDOWS\system32\irtffczgjb.exe
2007-07-07 21:53 272,896 --a------ C:\WINDOWS\system32\xaddanu.exe
2007-07-07 09:41 266,240 --a------ C:\WINDOWS\system32\dcpnzzy.exe
2007-07-07 05:33 270,848 --a------ C:\WINDOWS\system32\atcjrapn.exe
2007-07-06 23:30 269,312 --a------ C:\WINDOWS\system32\ipoahsaix.exe
2007-07-06 22:28 12,516 --a------ D:\DOCUME~1\Dominico\lfoufp.exe
2007-07-06 00:18 <REP> d-------- C:\Program Files\YesMessenger
2007-07-06 00:06 261,632 --a------ C:\WINDOWS\system32\gijwxhbs.exe
2007-07-05 23:39 10,830 --a------ D:\DOCUME~1\Dominico\qtqodm.exe
2007-07-05 07:43 272,384 --a------ C:\WINDOWS\system32\cnbxtdfxq.exe
2007-07-04 23:33 257,536 --a------ C:\WINDOWS\system32\mjzmsi.exe
2007-07-04 12:55 256,512 --a------ C:\WINDOWS\system32\wghknowx.exe
2007-07-03 16:42 22,016 --a------ C:\WINDOWS\b138.exe
2007-07-03 10:04 124,756 --a------ D:\DOCUME~1\Dominico\eftzvq.exe
2007-07-03 10:04 10,830 --a------ D:\DOCUME~1\Dominico\llbsbj.exe
2007-07-03 07:53 254,976 --a------ C:\WINDOWS\system32\vsqxldpagc.exe
2007-07-02 23:33 256,000 --a------ C:\WINDOWS\system32\vpycfx.exe
2007-07-02 07:02 249,856 --a------ C:\WINDOWS\system32\hzdhscrgk.exe
2007-07-02 05:03 252,416 --a------ C:\WINDOWS\system32\yfzwygilq.exe
2007-07-01 19:07 41,482 --a------ D:\DOCUME~1\Dominico\tytavi.exe
2007-07-01 18:28 124,756 --a------ D:\DOCUME~1\Dominico\elbnhg.exe
2007-07-01 18:28 <REP> d-------- C:\install
2007-07-01 16:59 251,904 --a------ C:\WINDOWS\system32\lpkjbak.exe
2007-07-01 06:09 256,000 --a------ C:\WINDOWS\system32\wrjyiw.exe
2007-06-30 23:32 258,048 --a------ C:\WINDOWS\system32\thjiulpyl.exe
2007-06-30 22:51 <REP> d-------- C:\Program Files\Metin2_France
2007-06-30 19:09 272,896 --a------ C:\WINDOWS\system32\sksmhixkgn.exe
2007-06-30 06:52 279,552 --a------ C:\WINDOWS\system32\dibusbiak.exe
2007-06-28 23:32 278,528 --a------ C:\WINDOWS\system32\ttlhpu.exe
2007-06-28 17:50 270,848 --a------ C:\WINDOWS\system32\pqiwjear.exe
2007-06-28 08:38 277,504 --a------ C:\WINDOWS\system32\uvwdntlrjf.exe
2007-06-27 05:06 275,968 --a------ C:\WINDOWS\system32\dgyjfju.exe
2007-06-26 23:31 283,136 --a------ C:\WINDOWS\system32\unktly.exe
2007-06-26 06:02 275,456 --a------ C:\WINDOWS\system32\lnadzyducx.exe
2007-06-25 11:11 288,256 --a------ C:\WINDOWS\system32\pnckhwtfiq.exe
2007-06-24 23:31 284,160 --a------ C:\WINDOWS\system32\vnjitikh.exe
2007-06-24 05:48 278,016 --a------ C:\WINDOWS\system32\sosomumq.exe
2007-06-23 06:18 280,576 --a------ C:\WINDOWS\system32\uorbbitt.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-22 19:50:19 -------- d-----w D:\DOCUME~1\Dominico\APPLIC~1\Azureus
2007-07-10 23:05:19 75,506 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-07-10 23:05:19 468,490 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-07-10 15:24:40 -------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-07-10 15:18:48 -------- d-----w C:\Program Files\Symantec
2007-07-08 21:13:11 -------- d-----w C:\Program Files\Yahoo!
2007-07-08 08:46:34 -------- d-----w C:\Program Files\MagicDisc
2007-07-05 22:07:58 -------- d-----w C:\Program Files\Tokimeki Check in!
2007-07-02 22:50:54 -------- d-----w C:\Program Files\mIRC
2007-06-24 15:57:44 -------- d-----w D:\DOCUME~1\Dominico\APPLIC~1\dvdcss
2007-06-22 21:30:48 270,848 ----a-w C:\WINDOWS\system32\wopnlgcoz.exe
2007-06-22 04:11:18 277,504 ----a-w C:\WINDOWS\system32\vwsjcf.exe
2007-06-20 04:35:16 460,288 ----a-w C:\WINDOWS\system32\ktybag.exe
2007-06-19 06:22:08 449,024 ----a-w C:\WINDOWS\system32\aydatlevk.exe
2007-06-17 22:40:17 446,464 ----a-w C:\WINDOWS\system32\djwjzvsv.exe
2007-06-17 19:38:29 451,072 ----a-w C:\WINDOWS\system32\bqmdtvb.exe
2007-06-17 15:40:28 448,000 ----a-w C:\WINDOWS\system32\nhovbkipgl.exe
2007-06-17 06:07:41 446,464 ----a-w C:\WINDOWS\system32\jopklnv.exe
2007-06-15 13:55:17 -------- d-----w C:\Program Files\MSN Messenger
2007-06-15 13:05:35 402,432 ----a-w C:\WINDOWS\system32\gzmfefhuhh.exe
2007-06-10 21:28:14 404,480 ----a-w C:\WINDOWS\system32\adphyfl.exe
2007-06-10 18:50:23 405,504 ----a-w C:\WINDOWS\system32\effpthd.exe
2007-06-10 08:06:35 394,240 ----a-w C:\WINDOWS\system32\pzascsvgu.exe
2007-06-09 07:33:40 401,920 ----a-w C:\WINDOWS\system32\wwfvfb.exe
2007-06-09 03:45:46 406,016 ----a-w C:\WINDOWS\system32\xfqrbiq.exe
2007-06-06 20:16:43 -------- d-----w C:\Program Files\DO
2007-06-05 21:38:27 -------- d-----w C:\Program Files\ZyX
2007-06-05 21:38:11 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll
2007-06-05 21:38:11 2,272 ----a-w C:\WINDOWS\system32\w95inf16.dll
2007-06-05 05:48:49 337,408 ----a-w C:\WINDOWS\system32\jgbaujxs.exe
2007-06-04 18:26:16 337,408 ----a-w C:\WINDOWS\system32\wntqltpdob.exe
2007-06-02 20:13:47 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-06-02 03:07:07 334,848 ----a-w C:\WINDOWS\system32\vymvxj.exe
2007-06-01 04:50:08 333,312 ----a-w C:\WINDOWS\system32\kjujcblatb.exe
2007-05-31 18:32:29 337,920 ----a-w C:\WINDOWS\system32\xtiiimejjx.exe
2007-05-30 17:10:17 329,216 ----a-w C:\WINDOWS\system32\khmnxnkwi.exe
2007-05-30 06:26:06 336,896 ----a-w C:\WINDOWS\system32\frvxqx.exe
2007-05-29 20:50:11 336,384 ----a-w C:\WINDOWS\system32\ulekeg.exe
2007-05-26 12:22:49 354,816 ----a-w C:\WINDOWS\system32\hhxriy.exe
2007-05-25 19:39:08 350,208 ----a-w C:\WINDOWS\system32\bbydvqxfol.exe
2007-05-25 18:56:57 351,744 ----a-w C:\WINDOWS\system32\wfewoxin.exe
2007-05-25 15:56:39 -------- d-----w C:\Program Files\Jasc Software Inc
2007-05-25 07:21:34 359,936 ----a-w C:\WINDOWS\system32\dsumus.exe
2007-05-24 21:19:32 360,960 ----a-w C:\WINDOWS\system32\kisaswx.exe
2007-05-24 18:31:35 356,352 ----a-w C:\WINDOWS\system32\uwhfsku.exe
2007-05-24 09:25:56 359,936 ----a-w C:\WINDOWS\system32\cigimofi.exe
2007-05-24 05:44:59 367,616 ----a-w C:\WINDOWS\system32\oafzrgihwa.exe
2007-05-23 19:45:14 361,472 ----a-w C:\WINDOWS\system32\tqledjwap.exe
2007-05-23 10:34:19 358,912 ----a-w C:\WINDOWS\system32\decbkhekyf.exe
2007-05-23 04:41:59 363,008 ----a-w C:\WINDOWS\system32\sykbwdvumv.exe
2007-05-22 14:08:21 -------- d-----w C:\Program Files\AskTBar
2007-05-22 06:53:16 364,032 ----a-w C:\WINDOWS\system32\pxusfjc.exe
2007-05-21 19:41:11 364,032 ----a-w C:\WINDOWS\system32\lsfrfuf.exe
2007-05-21 16:51:25 361,472 ----a-w C:\WINDOWS\system32\muxjdmqjt.exe
2007-05-21 09:51:47 358,400 ----a-w C:\WINDOWS\system32\qzoxfckx.exe
2007-05-21 07:29:12 358,400 ----a-w C:\WINDOWS\system32\rbsmqul.exe
2007-05-20 23:45:07 360,448 ----a-w C:\WINDOWS\system32\bykatbwc.exe
2007-05-20 08:18:25 361,472 ----a-w C:\WINDOWS\system32\nixzcxs.exe
2007-05-19 18:55:05 361,472 ----a-w C:\WINDOWS\system32\lpvstwc.exe
2007-05-19 08:37:25 358,912 ----a-w C:\WINDOWS\system32\xxyhuxfzgz.exe
2007-05-19 07:15:43 357,888 ----a-w C:\WINDOWS\system32\kldexoz.exe
2007-05-18 18:22:10 359,936 ----a-w C:\WINDOWS\system32\joluuq.exe
2007-05-18 17:19:28 362,496 ----a-w C:\WINDOWS\system32\jxutmbheu.exe
2007-05-18 12:37:43 355,328 ----a-w C:\WINDOWS\system32\hpuunl.exe
2007-05-18 11:52:32 363,008 ----a-w C:\WINDOWS\system32\qodowal.exe
2007-05-18 07:15:09 353,792 ----a-w C:\WINDOWS\system32\fiwhxaa.exe
2007-05-17 23:12:02 352,256 ----a-w C:\WINDOWS\system32\rcvbou.exe
2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 04:35:15 359,424 ----a-w C:\WINDOWS\system32\oqncptyvq.exe
2007-05-15 20:32:25 360,448 ----a-w C:\WINDOWS\system32\kkjkezmnj.exe
2007-05-15 12:39:10 360,960 ----a-w C:\WINDOWS\system32\vvjvzt.exe
2007-05-15 05:24:09 357,376 ----a-w C:\WINDOWS\system32\jssybb.exe
2007-05-12 06:47:24 356,352 ----a-w C:\WINDOWS\system32\ukaumymjc.exe
2007-05-12 04:01:37 354,816 ----a-w C:\WINDOWS\system32\ksouzf.exe
2007-05-11 08:48:12 355,840 ----a-w C:\WINDOWS\system32\edhrgc.exe
2007-05-11 07:43:11 358,912 ----a-w C:\WINDOWS\system32\nbgxwsbbl.exe
2007-05-11 05:02:38 362,496 ----a-w C:\WINDOWS\system32\qenqwkilf.exe
2007-05-10 19:41:10 359,424 ----a-w C:\WINDOWS\system32\rwdspovim.exe
2007-05-10 02:01:28 354,816 ----a-w C:\WINDOWS\system32\tslbrbobi.exe
2007-05-09 03:38:53 370,176 ----a-w C:\WINDOWS\system32\ltdmtl.exe
2007-05-08 04:57:54 360,960 ----a-w C:\WINDOWS\system32\dkkxjw.exe
2007-05-06 15:03:27 355,840 ----a-w C:\WINDOWS\system32\ocwgel.exe
2007-05-06 06:34:32 359,936 ----a-w C:\WINDOWS\system32\hvkamkd.exe
2007-05-05 08:18:35 362,496 ----a-w C:\WINDOWS\system32\tvpvrsf.exe
2007-05-04 04:55:59 386,560 ----a-w C:\WINDOWS\system32\xuekmmglc.exe
2007-05-03 09:54:53 384,512 ----a-w C:\WINDOWS\system32\oxqbphdxb.exe
2007-05-03 04:58:50 392,704 ----a-w C:\WINDOWS\system32\wblausvxm.exe
2007-05-03 00:45:15 388,608 ----a-w C:\WINDOWS\system32\ekbfritl.exe
2007-05-02 16:58:48 384,000 ----a-w C:\WINDOWS\system32\xdsfbthge.exe
2007-05-02 04:28:44 393,216 ----a-w C:\WINDOWS\system32\bfahnxk.exe
2007-05-01 17:53:40 392,704 ----a-w C:\WINDOWS\system32\dvdqnfqvu.exe
2007-05-01 13:00:32 386,560 ----a-w C:\WINDOWS\system32\jbrdjhqztj.exe
2007-05-01 04:25:04 392,704 ----a-w C:\WINDOWS\system32\plrqnpe.exe
2007-04-30 20:15:46 393,216 ----a-w C:\WINDOWS\system32\mranxiacj.exe
2007-04-30 06:37:47 384,512 ----a-w C:\WINDOWS\system32\wgsjzcyvy.exe
2007-04-28 19:47:33 388,096 ----a-w C:\WINDOWS\system32\bzeqqrv.exe
2007-04-28 09:00:24 393,728 ----a-w C:\WINDOWS\system32\vekldohj.exe
2007-04-27 08:10:15 387,072 ----a-w C:\WINDOWS\system32\hmuktonelp.exe
2007-04-26 07:38:08 389,632 ----a-w C:\WINDOWS\system32\mbhgkengx.exe
2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2004-12-14 02:56 63136 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A}]
C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}]
2006-10-31 08:55 1803720 --a------ C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2006-12-15 04:23 440056 --a------ C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
2006-07-07 13:29 324416 --a------ C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
2007-02-12 15:56 546672 --a------ C:\Program Files\Windows Live Toolbar\msntb.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bf00e119-21a3-4fd1-b178-3b8537e75c92}]
2007-02-15 20:25 110592 --a------ C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 C:\WINDOWS\system32\HdAShCut.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-08 17:55]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 14:25 C:\WINDOWS\RTHDCPL.EXE]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 19:43 C:\WINDOWS\Alcmtr.exe]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05]
"Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2005-05-23 09:57]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 14:48]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-11-04 17:40]
"NI.UERSV_0001_N86M1107"="D:\Documents and Settings\Dominico\Bureau\ErrorSafeScannerInstall_fr.exe" []
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-12-23 21:53]
"Ulead AutoDetector"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\Monitor.exe" [2005-05-23 09:57]
"Ulead Calendar Checker"="C:\Program Files\Ulead Systems\Ulead Photo Express 6\CalCheck.exe" [2005-08-22 09:10]
"Picasa Media Detector"="D:\Documents and Settings\Dominico\Mes documents\Anne-Marie\Picasa2\PicasaMediaDetector.exe" []
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 22:09]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 04:23]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
"Skype"="C:\APPS\skype\phone\Skype.exe" []
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-12-23 21:53]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"{90F36890-6D13-49AC-8317-6C4BC5DAA45D}"="syshelps.dll" []
"{C585C8D8-FCD5-4B3A-97CA-D4CFEDC428CA}"="sysprinters.dll" []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8583acd6-dcbc-11da-a986-0016ce120287}]
AutoRun\command- F:\Autorun.exe
Contents of the 'Scheduled Tasks' folder
2007-07-22 18:00:00 C:\WINDOWS\tasks\AA67A93091205350.job
2007-07-22 18:29:03 C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-23 00:23:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\MysqlInventime]
"ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
Completion time: 2007-07-23 0:24:48 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-23 00:24
--- E O F --- |
|