ComboFix 11-05-02.02 - Administrateur 02/05/2011 21:05:26.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3327.2583 [GMT 2:00]
Lancé depuis: e:\documents and settings\Administrateur\Mes documents\Téléchargements\ComboFix.exe
Commutateurs utilisés :: e:\documents and settings\Administrateur\Bureau\CFScript.txt
AV: Lavasoft Ad-Watch Live! Antivirus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
FILE ::
"e:\documents and settings\Administrateur\binternet.jar"
"e:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\binternet.lnk"
"e:\windows\system32\hkasm.dll"
"e:\windows\system32\XDva383.sys"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
e:\documents and settings\Administrateur\binternet.jar
e:\windows\TEMP\logishrd\LVPrcInj01.dll
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_CMBQZTSR
-------\Legacy_UTSEXVGBV
-------\Legacy_XDVA383
-------\Service_cmbqztsr
-------\Service_utsexvgbv
-------\Service_XDva383
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-04-02 au 2011-05-02 ))))))))))))))))))))))))))))))))))))
.
.
2011-05-02 18:10 . 2011-05-02 18:10 -------- d-----w- E:\$AVG
2011-05-02 17:55 . 2011-05-02 17:55 -------- d-----w- e:\documents and settings\Administrateur\Application Data\AVG10
2011-05-02 17:45 . 2011-05-02 17:45 -------- d--h--w- e:\documents and settings\All Users\Application Data\Common Files
2011-05-02 17:45 . 2011-05-02 18:43 -------- d-----w- e:\documents and settings\All Users\Application Data\AVG10
2011-05-02 17:44 . 2011-05-02 17:44 -------- d-----w- e:\program files\AVG
2011-05-01 20:15 . 2011-05-02 18:41 -------- d-----w- e:\documents and settings\All Users\Application Data\MFAData
2011-05-01 09:49 . 2011-05-01 09:49 512 ----a-w- E:\PhysicalDisk0_MBR.bin
2011-05-01 09:49 . 2011-05-01 09:50 -------- d-----w- E:\rsit
2011-05-01 09:49 . 2011-05-01 09:50 -------- d-----w- e:\program files\trend micro
2011-05-01 09:48 . 2011-05-01 09:49 -------- d-----w- e:\program files\ZHPDiag
2011-05-01 09:37 . 2011-05-01 09:39 -------- d-----w- e:\program files\ZHPFix
2011-05-01 09:31 . 2011-05-01 09:31 -------- d-----w- E:\_OTM
2011-05-01 08:54 . 2011-05-01 08:10 16432 ----a-w- e:\windows\system32\lsdelete.exe
2011-05-01 08:10 . 2011-05-01 08:10 98392 ----a-w- e:\windows\system32\drivers\SBREDrv.sys
2011-05-01 08:05 . 2011-04-29 10:12 64512 ----a-w- e:\windows\system32\drivers\Lbd.sys
2011-05-01 08:05 . 2011-05-01 08:05 -------- d-----w- e:\documents and settings\All Users\Application Data\Lavasoft
2011-05-01 08:05 . 2011-05-01 08:05 -------- d-----w- e:\program files\Lavasoft
2011-04-30 21:11 . 2011-04-30 21:18 110 ----a-w- e:\documents and settings\Administrateur\errorlog.tmp
2011-04-30 21:11 . 2011-04-30 21:11 -------- d-----w- e:\documents and settings\Administrateur\historique_ChatLand
2011-04-20 07:28 . 2011-04-20 07:28 -------- d-----w- e:\documents and settings\Administrateur\Application Data\MP-Manager
2011-04-20 07:28 . 2011-04-20 07:28 -------- d-----w- e:\program files\MPMAN
2011-04-20 07:09 . 2011-04-20 07:09 -------- d-----w- e:\documents and settings\Administrateur\Local Settings\Application Data\Help
2011-04-18 16:02 . 2011-04-18 16:02 -------- d-----w- e:\program files\Combined Community Codec Pack
2011-04-18 15:29 . 2011-04-18 15:29 -------- d-----w- e:\documents and settings\All Users\Application Data\PSPVC
2011-04-18 15:21 . 2011-04-18 15:21 -------- d-----w- e:\windows\Logs
2011-04-18 15:19 . 2011-04-30 21:44 -------- d-----w- e:\program files\AviSynth 2.5
2011-04-18 15:19 . 2011-04-18 15:29 -------- d-----w- e:\program files\pspvc
2011-04-15 16:49 . 2011-04-15 16:49 -------- d-----w- e:\program files\Microsoft Silverlight
2011-04-07 21:21 . 2011-04-07 21:21 -------- d-----w- e:\documents and settings\Administrateur\Application Data\Mumble
2011-04-07 21:20 . 2011-04-07 21:20 -------- d-----w- e:\program files\Mumble
2011-04-03 14:22 . 2004-01-28 13:03 21456 ----a-w- e:\windows\system32\drivers\SilvrLnk.sys
2011-04-03 14:22 . 2004-02-04 08:27 49536 ----a-w- e:\windows\system32\drivers\tiehdusb.sys
2011-04-03 14:22 . 2011-04-03 14:22 -------- d-----w- e:\program files\TI Education
2011-04-03 14:22 . 2011-04-03 14:22 -------- d-----w- e:\program files\Fichiers communs\TI Shared
2011-04-03 14:21 . 2011-04-03 14:21 -------- d-----w- e:\program files\Fichiers communs\Wise Installation Wizard
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-09 21:41 . 2011-02-09 21:41 86576 ----a-w- e:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
2011-02-09 21:41 . 2011-02-09 21:41 392728 ----a-w- e:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
2011-02-09 21:41 . 2011-02-09 21:41 132672 ----a-w- e:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
2011-02-02 20:40 . 2011-01-19 15:20 472808 ----a-w- e:\windows\system32\deployJava1.dll
2011-02-02 18:19 . 2010-09-13 13:33 73728 ----a-w- e:\windows\system32\javacpl.cpl
2011-04-14 16:47 . 2011-05-01 09:02 142296 ----a-w- e:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((
SnapShot@2011-05-02_17.26.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-06 17:24 . 2009-08-06 17:24 44768 e:\windows\system32\wups2.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 35552 e:\windows\system32\wups.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 53472 e:\windows\system32\wuauclt.exe
+ 2011-05-02 18:38 . 2009-08-06 17:24 35552 e:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 35552 e:\windows\system32\dllcache\wups.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 53472 e:\windows\system32\dllcache\wuauclt.exe
+ 2008-04-14 12:00 . 2009-08-06 17:24 96480 e:\windows\system32\dllcache\cdm.dll
+ 2008-04-14 12:00 . 2009-08-06 17:24 96480 e:\windows\system32\cdm.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 209632 e:\windows\system32\wuweb.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 327896 e:\windows\system32\wucltui.dll
+ 2010-09-13 13:00 . 2009-08-06 17:23 575704 e:\windows\system32\wuapi.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 209632 e:\windows\system32\dllcache\wuweb.dll
+ 2010-09-13 13:00 . 2009-08-06 17:24 327896 e:\windows\system32\dllcache\wucltui.dll
+ 2010-09-13 13:00 . 2009-08-06 17:23 575704 e:\windows\system32\dllcache\wuapi.dll
+ 2010-09-13 13:00 . 2009-08-06 17:23 1929952 e:\windows\system32\wuaueng.dll
+ 2010-09-13 13:00 . 2009-08-06 17:23 1929952 e:\windows\system32\dllcache\wuaueng.dll
+ 2011-05-02 17:45 . 2011-05-02 17:45 3446272 e:\windows\Installer\2a00f5.msi
+ 2011-05-02 17:44 . 2011-05-02 17:44 1611776 e:\windows\Installer\2a00f1.msi
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="e:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2009-08-20 2363392]
"uTorrent"="e:\program files\uTorrent\uTorrent.exe" [2011-04-09 399736]
"msnmsgr"="e:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Skype"="e:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
"Logitech Vid"="e:\program files\Logitech\Logitech Vid\vid.exe" [2009-07-16 5458704]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="e:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-08-03 98304]
"ATICustomerCare"="e:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]
"M-Audio Taskbar Icon"="e:\windows\system32\M-AudioTaskBarIcon.exe" [2009-11-09 643592]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="e:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"RTHDCPL"="RTHDCPL.EXE" [2010-11-16 19722344]
"H2O"="e:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-22 385024]
"SunJavaUpdateSched"="e:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-10-29 249064]
"LogitechQuickCamRibbon"="e:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
e:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
binternet.lnk - e:\documents and settings\Administrateur\binternet.jar [N/A]
Logitech . Enregistrement du produit.lnk - e:\program files\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
OpenOffice.org 3.1.lnk - e:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
e:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
binternet.lnk - e:\documents and settings\Administrateur\binternet.jar [N/A]
Logitech . Enregistrement du produit.lnk - e:\program files\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
OpenOffice.org 3.1.lnk - e:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
e:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
binternet.lnk - e:\documents and settings\Administrateur\binternet.jar [N/A]
Logitech . Enregistrement du produit.lnk - e:\program files\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
OpenOffice.org 3.1.lnk - e:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
e:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
binternet.lnk - e:\documents and settings\Administrateur\binternet.jar [N/A]
Logitech . Enregistrement du produit.lnk - e:\program files\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]
OpenOffice.org 3.1.lnk - e:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"e:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1130:TCP"= 1130:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 Lbd;Lbd;e:\windows\system32\drivers\Lbd.sys [01/05/2011 10:05 64512]
R0 mrdd;Marvell Removable Disk Control Driver;e:\windows\system32\drivers\mrdd.sys [13/09/2010 15:39 18984]
R0 mv61xx;mv61xx;e:\windows\system32\drivers\mv61xx.sys [09/02/2009 04:30 152616]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;e:\program files\Lavasoft\Ad-Aware\AAWService.exe [29/04/2011 12:11 2146496]
R3 CLEDX;Team H2O CLEDX service;e:\windows\system32\drivers\cledx.sys [19/01/2011 16:13 33792]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [13/09/2010 15:26 1691480]
S3 L6PODX3Pro;POD X3 Pro Service;e:\windows\system32\drivers\L6PODX3Pro.sys [31/01/2011 19:50 579456]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;e:\program files\Lavasoft\Ad-Aware\kernexplorer.sys [29/04/2011 12:11 15232]
S3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;e:\windows\system32\drivers\MAudioFastTrackPro.sys [09/11/2009 13:56 158600]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- e:\program files\Fichiers communs\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
.
2011-05-02 e:\windows\Tasks\Ad-Aware Update (Weekly).job
- e:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-29 10:11]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.search-web.netuDefault_Search_URL =
hxxp://www.search-web.net/keyword/uSearchMigratedDefaultURL =
hxxp://search-web.net/results.php?cx=partner-pub-0420647136319153%3A5n6ugpjrdrh&cof=GIMP%3ACCCCCC%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A10%3BDIV%3A%23FFFFF0%3B&ie=iso-8859-1&oe=iso-8859-1&sa=Rechercher&lang=en&q={searchTerms}Trusted Zone: line6.net
TCP: {1561DE3A-9877-4C4B-9FC7-1D9923D821B3} = 208.67.222.222,208.67.222.220
TCP: {9A25643A-5EB6-409F-BF6C-AD365DC22FA7} = 208.67.222.222,208.67.222.220
FF - ProfilePath - e:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\bcmdifjy.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.enabled - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-02 21:10
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="e:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(772)
e:\windows\system32\Ati2evxx.dll
e:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(5360)
e:\windows\TEMP\logishrd\LVPrcInj01.dll
e:\windows\system32\eappprxy.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
e:\windows\system32\Ati2evxx.exe
e:\windows\system32\Ati2evxx.exe
e:\windows\RTHDCPL.EXE
e:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
e:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
e:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
e:\program files\OpenOffice.org 3\program\soffice.exe
e:\program files\OpenOffice.org 3\program\soffice.bin
e:\program files\Skype\Plugin Manager\skypePM.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\program files\Fichiers communs\LightScribe\LSSrvc.exe
e:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
e:\program files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
e:\windows\system32\wbem\unsecapp.exe
e:\windows\system32\wbem\wmiapsrv.exe
e:\program files\Lavasoft\Ad-Aware\AAWTray.exe
e:\program files\Windows Live\Contacts\wlcomm.exe
e:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-05-02 21:11:21 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-05-02 19:11
ComboFix2.txt 2011-05-02 17:26
.
Avant-CF: 107 708 149 760 octets libres
Après-CF: 107 796 312 064 octets libres
.
- - End Of File - - 6C3DCE3C33A4D1CC4048AD068FDB21D0