wizard
2008-12-24, 04:21
run spy bot scan, malware scan, combox fix and hijack, here all the result, please help me resolve this, i just want to be sure my computer is clean as i need to do accounting for the end of the year, so all youy help would be very appreciated ! thanks a lot.
COMBOFIX:
ComboFix 08-12-23.01 - Frank 2008-12-23 21:16:59.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.3070.2470 [GMT -5:00]
Lancé depuis: c:\documents and settings\Frank\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Frank\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\nmoWvGgh.ini2
c:\windows\system32\SrsvCMoq.ini2
F:\Autorun.inf
----- BITS: Il y a peut-être des sites infectés -----
hxxp://onestopstation.net
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-24 au 2008-12-24 ))))))))))))))))))))))))))))))))))))
.
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\documents and settings\Frank\Application Data\Malwarebytes
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-23 20:30 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-23 20:30 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-23 20:29 . 2008-12-23 20:29 95 --a------ c:\windows\wininit.ini
2008-12-23 20:08 . 2008-12-23 20:12 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-23 20:08 . 2008-12-23 21:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-22 22:38 . 2008-12-22 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-12-22 22:33 . 2008-12-22 22:33 <REP> d-------- c:\program files\Adobe Media Player
2008-12-22 22:31 . 2008-12-22 22:31 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2008-12-22 22:26 . 2008-12-22 22:26 <REP> d-------- c:\program files\Fichiers communs\Macrovision Shared
2008-12-22 13:05 . 2008-12-22 13:05 <REP> d-------- c:\program files\uTorrent
2008-12-22 13:05 . 2008-12-22 22:14 <REP> d-------- c:\documents and settings\Frank\Application Data\uTorrent
2008-12-21 18:06 . 2008-12-21 18:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Phase One
2008-12-21 18:06 . 2008-10-13 14:50 23,808 --a------ c:\windows\system32\drivers\p1c1394.sys
2008-12-21 18:05 . 2008-12-21 18:05 <REP> d-------- c:\program files\Phase One
2008-12-21 17:20 . 2008-12-21 17:20 <REP> d-------- c:\program files\Microsoft Pro Photo Tools
2008-12-21 17:16 . 2008-12-21 17:16 <REP> d-------- c:\program files\MSBuild
2008-12-21 17:15 . 2008-12-21 17:15 <REP> d-------- c:\program files\Canon
2008-12-21 17:12 . 2008-12-21 17:18 <REP> d-------- c:\windows\system32\XPSViewer
2008-12-21 17:11 . 2008-12-21 17:11 <REP> d-------- c:\program files\Reference Assemblies
2008-12-21 17:11 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-12-21 16:59 . 2008-12-21 17:15 <REP> d-------- c:\program files\Fichiers communs\Canon
2008-12-21 16:33 . 2008-12-21 16:33 <REP> d-------- c:\program files\Pro Imaging Powertoys
2008-12-21 16:33 . 2008-12-21 16:33 <REP> d-------- c:\program files\Fichiers communs\Nikon
2008-12-21 16:24 . 2008-12-21 16:25 <REP> d-------- c:\windows\system32\URTTemp
2008-12-21 15:38 . 2008-12-21 15:38 <REP> d-------- c:\temp\tmp
2008-12-21 15:38 . 2008-12-21 15:51 <REP> d-------- C:\Temp
2008-11-30 20:36 . 2001-08-17 21:56 7,552 --a------ c:\windows\system32\drivers\SONYPVU1.SYS
2008-11-30 20:36 . 2001-08-17 21:56 7,552 --a--c--- c:\windows\system32\dllcache\sonypvu1.sys
2008-11-30 16:34 . 2008-11-30 16:34 <REP> d-------- c:\documents and settings\Andree\.thumbnails
2008-11-30 16:34 . 2008-11-30 16:35 <REP> d-------- c:\documents and settings\Andree\.gimp-2.6
2008-11-30 16:33 . 2008-11-30 16:34 <REP> d-------- c:\documents and settings\Andree\.gegl-0.0
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 02:18 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2008-12-24 02:12 --------- d-----w c:\program files\Steam
2008-12-24 01:55 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-23 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-23 03:34 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-17 22:25 --------- d-----w c:\documents and settings\Frank\Application Data\Juniper Networks
2008-12-07 02:53 --------- d-----w c:\documents and settings\Frank\Application Data\mIRC
2008-12-05 22:23 --------- d-----w c:\program files\mIRC
2008-11-21 22:58 --------- d-----w c:\program files\eclipse
2008-11-09 18:28 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-10-29 22:01 --------- d-----w c:\program files\MSECache
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 01:01 670,208 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2008-10-10 1410296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-08-04 32768]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-24 714608]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-08-04 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-04 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=iwxwji.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 NEOFLTR_600_12507;Juniper Networks TDI Filter Driver (NEOFLTR_600_12507);\??\c:\windows\system32\Drivers\NEOFLTR_600_12507.SYS [2007-12-27 64160]
R2 AppServer9PE;SunJavaSystemAppserver9PE;c:\sun\SDK\lib\appservService.exe "\"c:\sun\SDK\bin\asadmin.bat\" start-domain --user Francis domain1" "\"c:\sun\SDK\bin\asadmin.bat\" stop-domain domain1\" []
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon [2007-08-24 149352]
R3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-09 99376]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2008-12-23 c:\windows\Tasks\Norton Internet Security - Effectuer une analyse complète du système - Andree.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 12:19]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{566499cf-4f13-4257-9d8e-1450d0a16403} - (no file)
BHO-{E2FE6244-D999-4A6B-8F99-AF782305BA1A} - (no file)
HKLM-Run-HPUsageTracking - c:\program files\HP\HP UT\bin\hppusg.exe
Notify-vtUnoOHa - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.canoe.qc.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Frank\Application Data\Mozilla\Firefox\Profiles\2d2a42a4.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-23 21:18:29
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(948)
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Heure de fin: 2008-12-23 21:19:12
ComboFix-quarantined-files.txt 2008-12-24 02:19:09
Avant-CF: 289,461,530,624 octets libres
Après-CF: 289,583,337,472 octets libres
180 --- E O F --- 2008-12-19 08:00:29
COMBOFIX:
ComboFix 08-12-23.01 - Frank 2008-12-23 21:16:59.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.3070.2470 [GMT -5:00]
Lancé depuis: c:\documents and settings\Frank\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Frank\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\nmoWvGgh.ini2
c:\windows\system32\SrsvCMoq.ini2
F:\Autorun.inf
----- BITS: Il y a peut-être des sites infectés -----
hxxp://onestopstation.net
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-24 au 2008-12-24 ))))))))))))))))))))))))))))))))))))
.
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\documents and settings\Frank\Application Data\Malwarebytes
2008-12-23 20:30 . 2008-12-23 20:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-23 20:30 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-23 20:30 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-23 20:29 . 2008-12-23 20:29 95 --a------ c:\windows\wininit.ini
2008-12-23 20:08 . 2008-12-23 20:12 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-23 20:08 . 2008-12-23 21:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-22 22:38 . 2008-12-22 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-12-22 22:33 . 2008-12-22 22:33 <REP> d-------- c:\program files\Adobe Media Player
2008-12-22 22:31 . 2008-12-22 22:31 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2008-12-22 22:26 . 2008-12-22 22:26 <REP> d-------- c:\program files\Fichiers communs\Macrovision Shared
2008-12-22 13:05 . 2008-12-22 13:05 <REP> d-------- c:\program files\uTorrent
2008-12-22 13:05 . 2008-12-22 22:14 <REP> d-------- c:\documents and settings\Frank\Application Data\uTorrent
2008-12-21 18:06 . 2008-12-21 18:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Phase One
2008-12-21 18:06 . 2008-10-13 14:50 23,808 --a------ c:\windows\system32\drivers\p1c1394.sys
2008-12-21 18:05 . 2008-12-21 18:05 <REP> d-------- c:\program files\Phase One
2008-12-21 17:20 . 2008-12-21 17:20 <REP> d-------- c:\program files\Microsoft Pro Photo Tools
2008-12-21 17:16 . 2008-12-21 17:16 <REP> d-------- c:\program files\MSBuild
2008-12-21 17:15 . 2008-12-21 17:15 <REP> d-------- c:\program files\Canon
2008-12-21 17:12 . 2008-12-21 17:18 <REP> d-------- c:\windows\system32\XPSViewer
2008-12-21 17:11 . 2008-12-21 17:11 <REP> d-------- c:\program files\Reference Assemblies
2008-12-21 17:11 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-12-21 16:59 . 2008-12-21 17:15 <REP> d-------- c:\program files\Fichiers communs\Canon
2008-12-21 16:33 . 2008-12-21 16:33 <REP> d-------- c:\program files\Pro Imaging Powertoys
2008-12-21 16:33 . 2008-12-21 16:33 <REP> d-------- c:\program files\Fichiers communs\Nikon
2008-12-21 16:24 . 2008-12-21 16:25 <REP> d-------- c:\windows\system32\URTTemp
2008-12-21 15:38 . 2008-12-21 15:38 <REP> d-------- c:\temp\tmp
2008-12-21 15:38 . 2008-12-21 15:51 <REP> d-------- C:\Temp
2008-11-30 20:36 . 2001-08-17 21:56 7,552 --a------ c:\windows\system32\drivers\SONYPVU1.SYS
2008-11-30 20:36 . 2001-08-17 21:56 7,552 --a--c--- c:\windows\system32\dllcache\sonypvu1.sys
2008-11-30 16:34 . 2008-11-30 16:34 <REP> d-------- c:\documents and settings\Andree\.thumbnails
2008-11-30 16:34 . 2008-11-30 16:35 <REP> d-------- c:\documents and settings\Andree\.gimp-2.6
2008-11-30 16:33 . 2008-11-30 16:34 <REP> d-------- c:\documents and settings\Andree\.gegl-0.0
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 02:18 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2008-12-24 02:12 --------- d-----w c:\program files\Steam
2008-12-24 01:55 --------- d-----w c:\program files\Windows Media Connect 2
2008-12-23 18:56 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-23 03:34 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-17 22:25 --------- d-----w c:\documents and settings\Frank\Application Data\Juniper Networks
2008-12-07 02:53 --------- d-----w c:\documents and settings\Frank\Application Data\mIRC
2008-12-05 22:23 --------- d-----w c:\program files\mIRC
2008-11-21 22:58 --------- d-----w c:\program files\eclipse
2008-11-09 18:28 --------- d-----w c:\documents and settings\All Users\Application Data\WinZip
2008-10-29 22:01 --------- d-----w c:\program files\MSECache
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 01:01 670,208 ----a-w c:\windows\system32\wininet.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2008-10-10 1410296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-08-04 32768]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2007-08-24 714608]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"nwiz"="nwiz.exe" [2008-05-16 c:\windows\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-08-04 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-04 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=iwxwji.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\HP1006MC.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 NEOFLTR_600_12507;Juniper Networks TDI Filter Driver (NEOFLTR_600_12507);\??\c:\windows\system32\Drivers\NEOFLTR_600_12507.SYS [2007-12-27 64160]
R2 AppServer9PE;SunJavaSystemAppserver9PE;c:\sun\SDK\lib\appservService.exe "\"c:\sun\SDK\bin\asadmin.bat\" start-domain --user Francis domain1" "\"c:\sun\SDK\bin\asadmin.bat\" stop-domain domain1\" []
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon [2007-08-24 149352]
R3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2007-05-29 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-09 99376]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
2008-12-23 c:\windows\Tasks\Norton Internet Security - Effectuer une analyse complète du système - Andree.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-08-26 12:19]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{566499cf-4f13-4257-9d8e-1450d0a16403} - (no file)
BHO-{E2FE6244-D999-4A6B-8F99-AF782305BA1A} - (no file)
HKLM-Run-HPUsageTracking - c:\program files\HP\HP UT\bin\hppusg.exe
Notify-vtUnoOHa - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.canoe.qc.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Frank\Application Data\Mozilla\Firefox\Profiles\2d2a42a4.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-23 21:18:29
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(948)
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Heure de fin: 2008-12-23 21:19:12
ComboFix-quarantined-files.txt 2008-12-24 02:19:09
Avant-CF: 289,461,530,624 octets libres
Après-CF: 289,583,337,472 octets libres
180 --- E O F --- 2008-12-19 08:00:29