tittuq
Newbie


Posts: 12
|
 |
Re: rb3-rb4.tmp in recycle bin.... ....again!!!
« Reply #10 on: Oct 18th, 2007, 1:33pm » |
Quote Modify
|
ComboFix 07-10-18.6 - David Lessard 2007-10-18 14:27:10.1 - NTFSx86 Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.165 [GMT -4:00] Running from: C:\Documents and Settings\David Lessard\Bureau\ComboFix.exe * Created a new restore point . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\David Lessard\Application Data\CROSOF~1 C:\Documents and Settings\David Lessard\Application Data\ICROSO~1 C:\Program Files\Fichiers communs\inetget C:\Program Files\outlook C:\Program Files\windows C:\WINDOWS\dobe~1 C:\WINDOWS\system32\f.exe C:\WINDOWS\system32\ppatch~1 C:\WINDOWS\system32\racle~1 C:\WINDOWS\system32\ssembl~1 C:\WINDOWS\wnsxs~1 C:\WINDOWS\ystem~1 . ((((((((((((((((((((((((((((( Fichiers créés 2007-09-18 to 2007-10-18 )))))))))))))))))))))))))))))))))))) . 2007-10-18 14:2651,200--a------C:\WINDOWS\NirCmd.exe 2007-10-18 13:51225,509--a------C:\WINDOWS\system32\bftm.exe 2007-10-18 12:08<REP>d--------C:\WINDOWS\BDOSCAN8 2007-10-18 11:38225,509--a------C:\WINDOWS\system32\jl.exe 2007-10-17 18:03<REP>d--------C:\WINDOWS\system32\fr-fr 2007-10-17 18:01225,509--a------C:\WINDOWS\system32\bwtsgwos.exe 2007-10-17 17:546,058,496-----c---C:\WINDOWS\system32\dllcache\ieframe.dll 2007-10-17 17:542,455,488-----c---C:\WINDOWS\system32\dllcache\ieapfltr.dat 2007-10-17 17:54459,264-----c---C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-10-17 17:54383,488-----c---C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-10-17 17:54267,776-----c---C:\WINDOWS\system32\dllcache\iertutil.dll 2007-10-17 17:5463,488-----c---C:\WINDOWS\system32\dllcache\icardie.dll 2007-10-17 17:5452,224-----c---C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-10-17 17:5413,824-----c---C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-10-17 15:58<REP>d--------C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2007-10-17 14:19<REP>d--------C:\Documents and Settings\David Lessard\Application Data\TrojanHunter 2007-10-17 13:30<REP>d--------C:\Program Files\SUPERAntiSpyware 2007-10-17 13:30<REP>d--------C:\Program Files\Fichiers communs\Wise Installation Wizard 2007-10-17 13:30<REP>d--------C:\Documents and Settings\David Lessard\Application Data\SUPERAntiSpyware.com 2007-10-17 13:27<REP>d--------C:\Program Files\TrojanHunter 5.0 2007-10-17 13:27<REP>d--------C:\Program Files\CCleaner 2007-10-17 13:07225,509--a------C:\WINDOWS\system32\ke.exe 2007-10-17 01:08225,509--a------C:\WINDOWS\system32\wqgkqoreffrp.exe 2007-10-16 23:28<REP>d--------C:\Program Files\Trend Micro 2007-10-16 16:25225,509--a------C:\WINDOWS\system32\kvifqrl.exe 2007-10-15 19:04225,509--a------C:\WINDOWS\system32\gakkkajsld.exe 2007-10-15 12:55225,509--a------C:\WINDOWS\system32\lhhtjee.exe 2007-10-14 20:26225,509--a------C:\WINDOWS\system32\myyhu.exe 2007-10-12 15:35224,655--a------C:\WINDOWS\system32\ugmqex.exe 2007-10-11 11:43226,914--a------C:\WINDOWS\system32\vguiayywhwgl.exe 2007-10-09 13:57584,192-----c---C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-07 17:26<REP>d--------C:\Program Files\LimeWire 2007-10-06 21:38<REP>d--------C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-10-03 15:12<REP>dr-------C:\Documents and Settings\LocalService\Mes documents 2007-10-03 14:5255,296--a------C:\WINDOWS\system32\drivers\rp_skt32.sys 2007-10-03 14:51<REP>d--------C:\Program Files\Raxco 2007-10-03 14:51<REP>d--------C:\Program Files\Fichiers communs\Scanner 2007-10-03 14:51<REP>d--------C:\Program Files\Fichiers communs\Authentium 2007-10-03 14:51<REP>d--------C:\Program Files\CA 2007-10-03 14:51<REP>d--------C:\Documents and Settings\All Users\Application Data\Raxco 2007-10-03 14:5148,384--a------C:\WINDOWS\system32\drivers\rp_pkt32.sys 2007-10-03 14:50<REP>d--------C:\Program Files\Bell 2007-10-03 14:50<REP>d--------C:\Documents and Settings\David Lessard\Application Data\Bell 2007-10-03 14:50<REP>d--------C:\Documents and Settings\All Users\Application Data\Bell 2007-10-03 14:49<REP>d--------C:\Documents and Settings\David Lessard\Application Data\InstallShield 2007-10-02 23:1360,928---hs----C:\WINDOWS\system32\wscsvc.exe 2007-09-25 13:13129,784---------C:\WINDOWS\system32\pxafs.dll 2007-09-19 19:4581,920-ra------C:\WINDOWS\system32\drivers\InfReg.exe 2007-09-19 19:4528,005-ra------C:\WINDOWS\system32\drivers\enethusb.sys 2007-09-19 19:39<REP>d--------C:\WINDOWS\system32\CodeBaby 2007-09-19 19:38<REP>d--------C:\Program Files\Fichiers communs\Motive 2007-09-19 19:38<REP>d--------C:\Documents and Settings\All Users\Application Data\Motive 2007-09-19 19:3869,632--a------C:\WINDOWS\system32\MCCDevice.dll 2007-09-19 19:386,048--a------C:\WINDOWS\system32\MCC16.dll . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-17 05:27---------d-----wC:\Documents and Settings\David Lessard\Application Data\Lavasoft 2007-10-14 00:19---------d-----wC:\Documents and Settings\David Lessard\Application Data\Azureus 2007-10-11 04:12---------d-----wC:\Program Files\Winamp 2007-10-07 22:25---------d-----wC:\Program Files\DivX 2007-10-03 18:50---------d--h--wC:\Program Files\InstallShield Installation Information 2007-09-23 18:00---------d-----wC:\Program Files\Azureus 2007-09-21 20:281,882----a-wC:\Program Files\INSTALL.LOG 2007-09-19 23:38---------d-----wC:\Program Files\Common Files 2007-08-21 06:17683,520----a-wC:\WINDOWS\system32\inetcomm.dll 2007-08-13 22:54413,696----a-wC:\WINDOWS\system32\vbscript.dll 2007-08-13 22:54156,160----a-wC:\WINDOWS\system32\msls31.dll 2007-08-13 22:4578,336----a-wC:\WINDOWS\system32\ieencode.dll 2007-08-13 22:4440,960----a-wC:\WINDOWS\system32\licmgr10.dll 2007-08-13 22:3971,680----a-wC:\WINDOWS\system32\admparse.dll 2007-08-13 22:3955,296----a-wC:\WINDOWS\system32\iesetup.dll 2007-08-13 22:3636,352----a-wC:\WINDOWS\system32\imgutil.dll 2007-08-13 22:3245,568----a-wC:\WINDOWS\system32\mshta.exe 2007-08-13 22:0148,128----a-wC:\WINDOWS\system32\mshtmler.dll 2007-07-30 23:1992,504----a-wC:\WINDOWS\system32\cdm.dll 2007-07-30 23:19549,720----a-wC:\WINDOWS\system32\wuapi.dll 2007-07-30 23:1953,080----a-wC:\WINDOWS\system32\wuauclt.exe 2007-07-30 23:1943,352----a-wC:\WINDOWS\system32\wups2.dll 2007-07-30 23:19325,976----a-wC:\WINDOWS\system32\wucltui.dll 2007-07-30 23:19271,224----a-wC:\WINDOWS\system32\mucltui.dll 2007-07-30 23:19207,736----a-wC:\WINDOWS\system32\muweb.dll 2007-07-30 23:19203,096----a-wC:\WINDOWS\system32\wuweb.dll 2007-07-30 23:191,712,984----a-wC:\WINDOWS\system32\wuaueng.dll 2007-07-30 23:1833,624----a-wC:\WINDOWS\system32\wups.dll 2007-07-26 23:06200,704----a-wC:\WINDOWS\system32\ssldivx.dll 2007-07-26 23:061,044,480----a-wC:\WINDOWS\system32\libdivx.dll . ((((((((((((((((((((((((((((((((( Point de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-03-11 09:24] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-03-11 09:11] "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-03-20 15:05] "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2003-03-20 13:13] "NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 06:50] "eMusicClient"="C:\Program Files\Winamp\eMusic\eMusicClient.exe" [] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 14:03] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57] "yozemruA"="C:\WINDOWS\yozemruA.exe" [] "win32085114836881"="C:\WINDOWS\win32085114836881.exe" [] "sys014836881511"="C:\WINDOWS\sys014836881511.exe" [] "ms068151148368"="C:\WINDOWS\ms068151148368.exe" [] "MotiveReportAgent"="C:\Program Files\Fichiers communs\Motive\McciBootStrapper.exe" [] "Windows Security Center"="wscsvc.exe" [2007-10-03 03:03 C:\WINDOWS\system32\wscsvc.exe] "SSA.exe"="C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" [2007-03-27 10:33] "Gestionnaire de sécurité Sympatico"="C:\Program Files\Bell\Gestionnaire de securite\Rps.exe" [2007-05-09 12:35] "-FreedomNeedsReboot"="C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe" [2007-05-09 12:35] "THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2007-09-09 09:31] "gakkkajsld"="C:\WINDOWS\system32\gakkkajsld.exe" [2007-10-15 19:04] "bwtsgwos"="C:\WINDOWS\system32\bwtsgwos.exe" [2007-10-17 18:01] "jl"="C:\WINDOWS\system32\jl.exe" [2007-10-18 11:38] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Ahsc"="C:\DOCUME~1\DAVIDL~1\APPLIC~1\CROSOF~1\services.exe" [] "Xsovk"="C:\WINDOWS\system32\?racle\m?iexec.exe" [] "Ad Arrest"="C:\Program Files\Ad Arrest IE Popup Killer\adarrest.exe" [] "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 19:09] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce] "IndexCleaner"="C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] "IndexCleaner"="C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] "gakkkajsld"=C:\WINDOWS\system32\gakkkajsld.exe "bwtsgwos"=C:\WINDOWS\system32\bwtsgwos.exe "f"=C:\WINDOWS\system32\f.exe "jl"=C:\WINDOWS\system32\jl.exe [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "Ahsc"="C:\PROGRA~1\SMBOLS~1\winspool.exe" -vt ndrv "Ndsnu"=C:\WINDOWS\system32\?ssembly\r?gedit.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll S2 ey0ztun6ieniaozu;Print Spooler Service;C:\WINDOWS\system32\bftm.exe /service S3 Radialpoint Security Services;Gestionnaire de sécurité Sympatico;C:\WINDOWS\system32\dllhost.exe /Processid:{80098F68-1220-4F43-80A8-15C7395B8874} *Newly Created Service* - CATCHME . Contenu du dossier 'Scheduled Tasks/Tâches planifiées' "2007-09-23 14:42:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" "2007-10-18 18:02:05 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job" . ************************************************************************ ** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-18 14:29:15 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . Completion time: 2007-10-18 14:30:12 . --- E O F ---
|
|
IP Logged |
|
|
|