"Yan" - 2007-07-08 16:16:32 - ComboFix 07-07-07.3 - Service Pack 2
Command switches used :: C:\home\Yan\Bureau\ComboFix-Do.txt
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\aom.sys
C:\WINDOWS\system32\drivers\egl.sys
((((((((((((((((((((((((( Files Created from 2007-06-08 to 2007-07-08 )))))))))))))))))))))))))))))))
2007-07-08 11:42 55 --a------ C:\home\Carlos\msn.bat
2007-07-07 15:56 <REP> d-------- C:\Deckard
2007-07-03 22:36 <REP> d-------- C:\Program Files\ScanSpyware v3.8.0.4
2007-07-03 22:16 <REP> d-------- C:\Program Files\Diskeeper Lite Setup
2007-07-02 14:17 <REP> d-------- C:\home\Yan\.housecall6.6
2007-07-02 13:41 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-01 13:29 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-07-01 12:32 241,904 --a------ C:\WINDOWS\UNBOC.EXE
2007-07-01 12:32 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2007-07-01 12:31 <REP> d-------- C:\Program Files\CBOClean
2007-06-29 19:16 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2007-06-29 19:16 <REP> d-------- C:\home\ALLUSE~1\APPLIC~1\Apple
2007-06-24 13:45 <REP> d-------- C:\home\ADMINI~1\APPLIC~1\Help
2007-06-24 11:44 <REP> d-------- C:\WINDOWS\system32\NtmsData
2007-06-23 19:58 <REP> d-------- C:\Program Files\LIVEUPDATE
2007-06-16 17:43 <REP> d-------- C:\home\Yan\APPLIC~1\RipIt4Me
2007-06-13 23:24 <REP> d-------- C:\home\Yan\APPLIC~1\VanDyke
2007-06-13 23:23 <REP> d-------- C:\Program Files\CRT
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-08 19:14:07 24 ----a-w C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-0000000D-00001102-00000002-80271102}.dat
2007-07-08 19:14:07 24 ----a-w C:\WINDOWS\system32\DVCState-{00000000-00000000-0000000D-00001102-00000002-80271102}.dat
2007-07-08 18:57:33 -------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-07-08 18:57:32 -------- d-----w C:\Program Files\LittleWriter
2007-07-08 15:39:45 -------- d-s---w C:\Program Files\Xfire
2007-07-08 13:35:51 -------- d-----w C:\home\Yan\APPLIC~1\.gaim
2007-07-07 20:18:53 -------- d-----w C:\home\Yan\APPLIC~1\uTorrent
2007-07-07 20:17:23 -------- d-----w C:\Program Files\eMule
2007-07-04 20:35:51 -------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-07-04 16:19:24 22,584 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-07-04 16:19:18 99,904 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-07-04 03:25:27 -------- d-----w C:\home\Yan\APPLIC~1\foobar2000
2007-07-02 22:20:58 -------- d-----w C:\Program Files\Documents To Go
2007-06-29 23:21:04 -------- d-----w C:\Program Files\iTunes
2007-06-29 03:06:40 -------- d-----w C:\Program Files\PowerPro
2007-06-24 17:45:34 -------- d-----w C:\Program Files\totalcmd
2007-06-16 21:06:15 -------- d-----w C:\home\Yan\APPLIC~1\ZoomBrowser EX
2007-06-05 02:37:58 -------- d-----w C:\Program Files\palmOne
2007-06-02 14:50:40 -------- d-----w C:\Program Files\DAEMON Tools
2007-06-02 14:21:10 682,232 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-06-02 05:20:48 -------- d--h--r C:\home\Yan\APPLIC~1\SecuROM
2007-06-02 05:20:47 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-06-02 04:55:51 -------- d-----w C:\Program Files\UbiSoft
2007-06-02 03:41:27 -------- d-----w C:\Program Files\QuickTime
2007-05-28 03:00:58 -------- d-----w C:\Program Files\Plucker
2007-05-08 02:56:25 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-09 01:01:29 72,968 ----a-w C:\WINDOWS\War3Unin.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
2006-10-26 11:28 440384 --a------ C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 02:04 853672 --a------ C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
2006-12-18 05:18 231160 --a------ C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 14:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 18:56 C:\WINDOWS\system32\CTHELPER.EXE]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 02:00]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 20:52]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-20 17:01]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-12-11 20:36]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"Openwares LiveUpdate"="C:\Program Files\LiveUpdate\LiveUpdate.exe" [2003-12-13 13:17]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-09-08 12:06]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 18:29]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
"DisableRegistryTools"=0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService Alerter WebClient LmHosts upnphost SSDPSRV
Contents of the 'Scheduled Tasks' folder
2007-05-26 10:53:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-08 16:21:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
C:\WINDOWS\system32\cmd.exe [14948] 0xFC49D2E8
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-08 16:22:23
C:\ComboFix-quarantined-files.txt ... 2007-07-08 16:22
--- E O F ---