التقرير
كود:
ComboFix 09-03-23.01 - kawim 2009-03-24 15:27:18.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.223.141 [GMT 0:00]
Lancé depuis: c:\documents and settings\kawim\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated)
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-24 au 2009-03-24 ))))))))))))))))))))))))))))))))))))
.
2009-03-24 10:12 . 2009-03-24 10:12 <REP> d-------- c:\program files\MSXML 4.0
2009-03-23 16:29 . 2009-03-23 23:01 <REP> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-23 16:22 . 2009-03-23 16:22 <REP> d-------- c:\program files\WinASO
2009-03-23 16:16 . 2009-03-23 16:16 <REP> d-------- c:\program files\Ares
2009-03-23 16:07 . 2009-03-23 16:07 <REP> d-------- c:\program files\Messenger Plus! Live
2009-03-23 16:07 . 2009-03-23 16:07 <REP> d-------- c:\program files\Circle Developement
2009-03-23 15:56 . 2009-03-23 15:59 <REP> d-------- c:\program files\Free Window Sweeper
2009-03-23 14:48 . 2009-03-24 12:11 <REP> d-------- c:\windows\system32\CatRoot_bak
2009-03-23 14:35 . 2008-08-14 13:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-23 14:35 . 2008-08-14 13:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-23 14:35 . 2008-08-14 13:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-23 14:35 . 2008-08-14 13:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-23 14:34 . 2008-10-24 11:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-23 14:10 . 2009-03-24 10:19 <REP> d--h----- c:\windows\$hf_mig$
2009-03-23 14:10 . 2005-02-25 03:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2009-03-22 13:37 . 2009-03-22 13:37 <REP> d-------- c:\program files\Atomic Alarm Clock
2009-03-22 13:23 . 2009-03-22 13:23 <REP> d-------- c:\windows\Sun
2009-03-22 13:22 . 2009-03-22 13:21 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-22 13:22 . 2009-03-22 13:21 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-22 13:21 . 2009-03-22 13:21 <REP> d-------- c:\program files\Java
2009-03-22 13:11 . 2009-03-22 13:11 <REP> d-------- c:\program files\Fichiers communs\Adobe
2009-03-22 13:00 . 2009-03-22 13:00 <REP> d-------- c:\program files\Eazel-FR
2009-03-22 13:00 . 2009-03-22 13:00 <REP> d-------- c:\program files\Conduit
2009-03-22 11:00 . 2009-03-22 11:00 <REP> d-------- c:\program files\ADSL Autoconnect
2009-03-21 20:31 . 2009-03-21 20:31 <REP> d---s---- c:\documents and settings\kawim\UserData
2009-03-21 20:18 . 2009-03-21 20:18 64,868 --a------ c:\windows\BricoPackUninst.cmd
2009-03-21 20:18 . 2009-03-21 20:18 268 --ah----- C:\sqmdata01.sqm
2009-03-21 20:18 . 2009-03-21 20:18 244 --ah----- C:\sqmnoopt01.sqm
2009-03-21 20:17 . 2009-03-21 20:17 2,359,350 --a------ c:\windows\BricoPack Wallpaper.bmp
2009-03-21 20:13 . 2009-03-21 20:18 5,997 --a------ c:\windows\BricoPackFoldersDelete.cmd
2009-03-21 19:58 . 2009-03-21 20:08 <REP> d-------- c:\windows\BricoPacks
2009-03-21 19:42 . 2009-03-21 19:42 <REP> d-------- c:\program files\LG Electronics
2009-03-21 19:42 . 2009-03-21 19:42 <REP> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-03-21 19:42 . 2007-08-28 15:17 21,632 --a------ c:\windows\system32\drivers\lgevdomodem.sys
2009-03-21 19:42 . 2007-08-28 15:17 19,840 --a------ c:\windows\system32\drivers\lgevdodiag.sys
2009-03-21 19:42 . 2007-08-28 15:17 19,840 --a------ c:\windows\system32\drivers\lgevdoatc.sys
2009-03-21 19:42 . 2007-08-28 15:17 12,800 --a------ c:\windows\system32\drivers\lgevdobus.sys
2009-03-21 19:17 . 2009-03-21 19:17 <REP> d-------- c:\program files\Avira
2009-03-21 19:17 . 2009-03-21 19:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-21 19:11 . 2009-03-21 19:11 268 --ah----- C:\sqmdata00.sqm
2009-03-21 19:11 . 2009-03-21 19:11 244 --ah----- C:\sqmnoopt00.sqm
2009-03-21 19:00 . 2008-01-24 16:36 4,127,488 -ra------ c:\windows\system32\drivers\alcxwdm.sys
2009-03-21 18:59 . 2009-03-21 19:00 <REP> d-------- c:\program files\Realtek AC97
2009-03-21 18:59 . 2006-11-17 05:40 18,804,736 --a------ c:\windows\system32\alsndmgr.cpl
2009-03-21 18:59 . 2006-12-08 15:20 10,528,768 --a------ c:\windows\system32\RTLCPL.exe
2009-03-21 18:59 . 2007-04-16 15:28 577,536 --a------ c:\windows\soundman.exe
2009-03-21 18:59 . 2006-07-31 11:19 315,392 --a------ c:\windows\alcupd.exe
2009-03-21 18:59 . 2006-07-31 11:27 217,088 --a------ c:\windows\Alcrmv.exe
2009-03-21 18:59 . 2006-10-18 02:53 147,456 --a------ c:\windows\system32\RtlCPAPI.dll
2009-03-21 18:59 . 2002-02-05 13:54 141,016 --a------ c:\windows\system32\alsndmgr.wav
2009-03-21 18:56 . 2009-03-23 23:32 <REP> d-------- c:\documents and settings\kawim\Contacts
2009-03-21 18:54 . 2009-03-21 19:03 <REP> d-------- c:\windows\SxsCaPendDel
2009-03-21 18:46 . 2009-02-13 11:31 55,640 --a------ c:\windows\system32\drivers\avgntflt.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-21 20:18 219,648 ----a-w c:\windows\system32\uxtheme.dll
2009-03-21 19:42 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-21 19:42 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-03-21 17:46 --------- d-----w c:\program files\Menara
2009-03-21 17:38 --------- d-----w c:\program files\Windows Live
2009-03-21 17:34 --------- d-----w c:\documents and settings\kawim\Application Data\ESET
2009-03-21 17:31 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-03-21 17:17 --------- d-----w c:\program files\microsoft frontpage
2009-03-21 17:13 --------- d-----w c:\program files\Services en ligne
2009-02-09 14:17 1,846,400 ----a-w c:\windows\system32\win32k.sys
.
------- Sigcheck -------
2008-04-14 02:34 14336 e4bdf223cd75478bf44567b4d5c2634d c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\svchost.exe
2004-08-04 04:55 14336 1bd6c2f707a275cb7c16fd99fe0f31ca c:\windows\system32\svchost.exe
2004-08-04 04:55 14336 1bd6c2f707a275cb7c16fd99fe0f31ca c:\windows\system32\dllcache\svchost.exe
2008-04-14 02:33 579584 e853f84d3ce2faa2a802e33cf89ac023 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\user32.dll
2004-08-04 04:54 578048 e46fb493e3b33704f0715020cf52106b c:\windows\system32\user32.dll
2004-08-04 04:54 578048 e46fb493e3b33704f0715020cf52106b c:\windows\system32\dllcache\user32.dll
2008-04-14 02:33 82432 fb836f9e62d82904c983ad21296a5d9c c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ws2_32.dll
2004-08-04 04:54 82944 bc41f51a39d3b255805fdb759b7814ae c:\windows\system32\ws2_32.dll
2004-08-04 04:54 82944 bc41f51a39d3b255805fdb759b7814ae c:\windows\system32\dllcache\ws2_32.dll
2008-10-16 10:38 663552 4bad064ed3fb5008af94d427dd77fddd c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP2GDR\wininet.dll
2008-10-16 10:23 671744 f9ae6dbb4ec5b4d1a82bf2f0cb7ee200 c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP2QFE\wininet.dll
2008-10-16 01:01 670208 05033943ff61abd13b93c00337d04e92 c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP3GDR\wininet.dll
2008-10-16 01:04 671232 1c6e9fdab1f4cb983a39efba6f131acc c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP3QFE\wininet.dll
2008-04-14 02:33 670208 4a6e04ea20f48d750d9bfed8600d516b c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\wininet.dll
2004-08-04 04:54 694784 f6ad4c0f992b3b51c044ad74d9e2e854 c:\windows\system32\wininet.dll
2004-08-04 04:54 694784 f6ad4c0f992b3b51c044ad74d9e2e854 c:\windows\system32\dllcache\wininet.dll
2008-04-14 02:34 512000 dd73d6b9f6b4cb630cf35b438b540174 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\winlogon.exe
2004-08-04 04:55 506368 d2de785aeab0bb8ca4c14a8a199dbe4e c:\windows\system32\winlogon.exe
2004-08-04 04:55 506368 d2de785aeab0bb8ca4c14a8a199dbe4e c:\windows\system32\dllcache\winlogon.exe
2008-04-13 19:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ndis.sys
2004-08-04 03:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\dllcache\ndis.sys
2004-08-04 03:14 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 18:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ip6fw.sys
2004-08-04 03:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\dllcache\ip6fw.sys
2004-08-04 03:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2004-08-04 04:54 978432 9f3b76c8cf787449a47f05abab4e13e6 c:\windows\explorer.exe
2008-04-14 02:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\explorer.exe
2004-08-04 04:54 978432 9f3b76c8cf787449a47f05abab4e13e6 c:\windows\system32\dllcache\explorer.exe
2008-04-14 02:34 109056 54cb50058851d95e56ec70d09f70857f c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\services.exe
2004-08-04 04:55 108544 732e0b1abaace15d80ec19056b0a2af9 c:\windows\system32\services.exe
2004-08-04 04:55 108544 732e0b1abaace15d80ec19056b0a2af9 c:\windows\system32\dllcache\services.exe
2008-04-14 02:34 13312 91e6024d6d4dcdecdb36c43ecf9bbecb c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\lsass.exe
2004-08-04 04:54 13312 9f3744a5c6f49291a7a685040a013399 c:\windows\system32\lsass.exe
2004-08-04 04:54 13312 9f3744a5c6f49291a7a685040a013399 c:\windows\system32\dllcache\lsass.exe
2008-04-14 02:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ctfmon.exe
2004-08-04 04:54 15360 5584247b568c2e53934873f4b655fe6a c:\windows\system32\ctfmon.exe
2004-08-04 04:54 15360 5584247b568c2e53934873f4b655fe6a c:\windows\system32\dllcache\ctfmon.exe
2008-04-14 02:34 57856 460e4ce148bd07218da0b6a3d31885a9 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\spoolsv.exe
2004-08-04 04:55 57856 b4ef928e4fad79364a80acba6d999934 c:\windows\system32\spoolsv.exe
2004-08-04 04:55 57856 b4ef928e4fad79364a80acba6d999934 c:\windows\system32\dllcache\spoolsv.exe
2008-04-14 02:34 112640 7e3defe771cb451b0ff630bfa435417e c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\wuauclt.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\system32\wuauclt.exe
2008-10-16 14:09 66584 2275f45e257d46e6500558b2930cb9a4 c:\windows\system32\dllcache\wuauclt.exe
2008-04-14 02:34 26624 e74ddb12188c2ff57a78624dbf7332fc c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\userinit.exe
2004-08-04 04:55 25088 d6d65ea32b190401b57edb6706f29669 c:\windows\system32\userinit.exe
2004-08-04 04:55 25088 d6d65ea32b190401b57edb6706f29669 c:\windows\system32\dllcache\userinit.exe
2008-04-14 02:33 297984 710bc85a8c22626ee094439e3ea0d38c c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\termsrv.dll
2004-08-04 04:54 297984 7d521b8cf926459e270d18c559323815 c:\windows\system32\termsrv.dll
2004-08-04 04:54 297984 7d521b8cf926459e270d18c559323815 c:\windows\system32\dllcache\termsrv.dll
2008-04-14 02:33 1054720 3ac8886dfa5ab641417df4d3b7f5512e c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\kernel32.dll
2004-08-04 04:54 1048576 7830e20c74611281b1bdae5888cd50f5 c:\windows\system32\kernel32.dll
2004-08-04 04:54 1048576 7830e20c74611281b1bdae5888cd50f5 c:\windows\system32\dllcache\kernel32.dll
2008-04-14 02:33 17408 9f2c862e39bf8e8fc51c3f6a6bceb415 c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\powrprof.dll
2004-08-04 04:54 17408 b02e4ddbe0e98f42f3b61292ddb3a104 c:\windows\system32\powrprof.dll
2004-08-04 04:54 17408 b02e4ddbe0e98f42f3b61292ddb3a104 c:\windows\system32\dllcache\powrprof.dll
2008-04-14 02:33 110080 0469b73db32e5520f342c5e163aa3cca c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\imm32.dll
2004-08-04 04:54 110080 39ee5faf56260ebb8d77a08f525ebbb4 c:\windows\system32\imm32.dll
2004-08-04 04:54 110080 39ee5faf56260ebb8d77a08f525ebbb4 c:\windows\system32\dllcache\imm32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]
[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
2009-02-16 15:44 1882136 --a------ c:\program files\Eazel-FR\tbEaze.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]
[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A8F9752D-E2B8-4E7A-86B5-499F4330E2FE}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]
[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"UMService"="c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe" [2008-05-09 28672]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2007-10-31 1707008]
"ares"="c:\program files\Ares\Ares.exe" [2008-11-23 880640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\kawim\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-03-21 839680]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
S2 ADSLAutoconnect;ADSLAutoconnect;c:\program files\ADSL Autoconnect\ADSL Autoconnect.exe [2009-03-22 446464]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-21 108289]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2009-03-21 63555]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2009-03-21 114616]
S3 UsbEvdoAtc;LGE EVDO USB Serial Port;c:\windows\system32\drivers\lgevdoatc.sys [2009-03-21 19840]
S3 usbevdobus;LGE EVDO Composite USB Device;c:\windows\system32\drivers\lgevdobus.sys [2009-03-21 12800]
S3 UsbEvdoDiag;LGE EVDO USB Serial DM Port;c:\windows\system32\drivers\lgevdodiag.sys [2009-03-21 19840]
S3 USBEVDOModem;LGE EVDO USB Modem;c:\windows\system32\drivers\lgevdomodem.sys [2009-03-21 21632]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - IKANLOADER2
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.menara.ma/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-24 15:29:48
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-03-24 15:31:51
ComboFix-quarantined-files.txt 2009-03-24 15:31:49
Avant-CF: 16****256****856****064 octets libres
Après-CF: 16,437,088,256 octets libres
205 --- E O F --- 2009-03-23 14:18:11