Rapport combofix
ComboFix 07-11-08.1 - Biketo 2007-11-17 8:31:30.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.215 [GMT 1:00]
Running from: C:\Documents and Settings\Biketo\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Biketo\Bureau\CFScript.txt
* Created a new restore point
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iFinger\iFinger.exe
C:\Program Files\Softissimo\Lexibase Pro\exe\L-Express.exe
C:\Program Files\Softissimo\Lexibase Pro\exe\lexibase.exe
C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr. ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\System32\drivers\lsccvtum.dat
C:\WINDOWS\System32\drivers\yqofbcyz.dat
C:\WINDOWS\System32\ext.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_VZOPEWPY
-------\poof
-------\vzopewpy
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-17 to 2007-11-17 ))))))))))))))))))))))))))))))))))))
.
2007-11-17 08:13 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-15 16:58 <REP> d-------- C:\b8148bc99d63bd38e4
2007-10-28 11:27 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-10-28 08:51 <REP> d-------- C:\Program Files\Trend Micro
2007-10-27 21:00 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-27 18:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-10-27 18:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-10-27 18:38 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-10-27 18:38 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-10-27 18:38 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-10-27 18:38 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-10-27 18:38 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
2007-10-27 18:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\InterTrust
2007-10-27 17:49 <REP> d-------- C:\BFU
2007-10-27 08:22 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-10-27 08:22 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-10-27 08:22 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-10-27 08:19 <REP> d-------- C:\Program Files\MSXML 4.0
2007-10-21 21:30 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-21 17:00 <REP> d-------- C:\WINDOWS\system32\LogFiles
2007-10-21 16:15 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2007-10-21 15:17 <REP> d-------- C:\WINDOWS\provisioning
2007-10-21 15:17 <REP> d-------- C:\WINDOWS\peernet
2007-10-21 15:11 <REP> d-------- C:\WINDOWS\ServicePackFiles
2007-10-21 14:59 <REP> d-------- C:\WINDOWS\EHome
2007-10-21 12:10 35 --a------ C:\WINDOWS\system32\lister.bat
2007-10-21 10:56 210,432 --a------ C:\Program Files\OTMoveIt.exe
2007-10-20 23:29 14,603,672 --a------ C:\Program Files\jre-6u3-windows-i586-p-s.exe
2007-10-20 08:46 <REP> d-------- C:\Program Files\7-Zip
2007-10-20 08:46 836,783 --a------ C:\Program Files\dezipeur7z442.exe
2007-10-20 00:21 <REP> d-------- C:\Program Files\DiagHelp
2007-10-20 00:16 <REP> d-------- C:\DiagHelp
2007-10-17 07:30 <REP> d-------- C:\Documents and Settings\Thierrette\Application Data\Grisoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 18:51 45,064 ----a-w C:\Documents and Settings\Biketo\Application Data\GDIPFONTCACHEV1.DAT
2007-10-21 13:01 --------- d-----w C:\Program Files\a2 Free
2007-10-16 12:44 --------- d-----w C:\Program Files\Fichiers communs\Scanner
2007-10-16 12:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-10-15 08:31 --------- d-----w C:\Documents and Settings\Biketo\Application Data\Grisoft
2007-10-15 08:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-14 23:43 --------- d-----w C:\Program Files\Lexmark X1100 Series
2007-10-14 18:21 --------- d-----w C:\Program Files\Avira
2007-10-14 18:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2007-10-14 18:19 17,788,920 ----a-w C:\Program Files\antivir_workstation_win7u_en_h.exe
2007-10-14 08:59 --------- d-----w C:\Program Files\Alwil Software
2007-10-14 08:29 1,035,316 ----a-w C:\Program Files\SmitfraudFix.exe
2007-10-13 22:36 --------- d-----w C:\Program Files\PrintKey 2000 Fr
2007-10-13 22:32 --------- d-----w C:\Program Files\iFinger
2007-10-13 07:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-13 07:16 --------- d-----w C:\Program Files\Kit ADSL
2007-10-08 05:06 --------- d-----w C:\Program Files\Tunebite
2007-10-08 05:00 --------- d-----w C:\Documents and Settings\Biketo\Application Data\tunebite
2007-10-07 19:05 --------- d-----w C:\Documents and Settings\Biketo\Application Data\AccurateRip
2007-10-07 19:04 --------- d-----w C:\Program Files\Illustrate
2007-10-05 20:45 --------- d-----w C:\Program Files\QuickTime
2007-10-05 20:42 --------- d-----w C:\Program Files\Apple Software Update
2007-10-05 20:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" []
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" []
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" []
"WooCnxMon"="C:\PROGRA~1\Wanadoo\CnxMon.exe" []
"VCSPlayer"="C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-10-14 19:53]
"SoundMan"="SOUNDMAN.EXE" [2003-04-24 15:53 C:\WINDOWS\SOUNDMAN.EXE]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-14 19:54]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2003-07-28 14:12]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NISUM"=2 (0x2)
"ccPxySvc"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\DRIVERS\avgntmgr.sys
R0 vburner;vburner;C:\WINDOWS\system32\DRIVERS\vburner.sys
R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys
R1 SSHDRV84;SSHDRV84;\??\C:\WINDOWS\System32\drivers\SSHDRV84.sys
R1 vcsmpdrv;vcsmpdrv;C:\WINDOWS\system32\DRIVERS\vcsmpdrv.sys
R3 ENE;ENE;C:\WINDOWS\system32\DRIVERS\EMCR7SK.sys
S2 MTC0003_STDSB;Scroll Bar Driver;C:\WINDOWS\system32\STDSB.sys
S2 VCSSecS;Virtual CD v4 Security service (SDK - Version);C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
S3 DrmRDriverV32;DrmRDriverV32;C:\WINDOWS\system32\drivers\DrmRDriverV32.sys
S3 DrmRVideo32;DrmRVideo32;C:\WINDOWS\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-17 08:42:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2007-11-17 8:44:52 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-27 20:00
.
--- E O F --