بسم الله الرحمان الرحيم
هذا هو التقرير
ComboFix 08-07-24.3 - adel magroud 2008-07-25 16:28:12.6 -
FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.2.1256.213.1036.18.59 [GMT 2:00]
Endroit: C:\Documents and Settings\adel magroud\Bureau\ComboFix.exe
* Resident AV is active
AVERTISSEMENT - LA CONSOLE DE RةCUPةRATION N'EST PAS INSTALLةE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-25 to 2008-07-25 ))))))))))))))))))))))))))))))))))))
.
2008-07-25 17:32 . 2008-07-25 17:32 <REP> d--hs---- C:\FOUND.000
2008-07-25 17:25 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-25 17:23 . 2008-07-25 17:23 58,848 --a------ C:\2008-07-25_172325.png
2008-07-25 17:19 . 2008-07-25 17:19 <REP> dr-hs---- C:\Program Files\tuEagles
2008-07-25 17:19 . 2008-07-25 17:19 107,520 --a------ C:\WINDOWS\Netfathr.exe
2008-07-25 17:19 . 2008-07-25 17:20 9,522 --a------ C:\WINDOWS\Eleather.bmp
2008-07-25 17:07 . 2008-07-25 17:07 9,522 --a------ C:\WINDOWS\Retaften.bmp
2008-07-25 17:07 . 2008-07-25 16:22 0 --a------ C:\WINDOWS\system32\drivers\IsPubDrv.sys
2008-07-25 17:07 . 2008-07-25 16:22 0 --a------ C:\WINDOWS\system32\drivers\IsDrv118.sys
2008-07-25 16:52 . 2008-07-25 16:52 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-07-25 16:52 . 2008-07-25 16:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-25 16:52 . 2008-07-25 17:30 96,559 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-07-25 16:52 . 2008-07-25 17:30 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-07-25 16:52 . 2008-07-25 15:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-07-25 16:52 . 2008-07-25 15:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-07-25 15:32 . 2008-07-25 15:32 <REP> d-------- C:\Documents and Settings\adel magroud\Application Data\IDM
2008-07-25 15:03 . 2008-07-25 15:04 <REP> d--hs---- C:\Recycled
2008-07-25 13:15 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\58151912.sys
2008-07-25 13:11 . 2008-03-05 11:41 148,496 --a------ C:\WINDOWS\system32\drivers\
07128066.sys
2008-07-25 13:11 . 2008-07-25 15:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-25 13:11 . 2008-07-25 15:28 32 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-25 11:57 . 2008-07-25 11:57 <REP> d-------- C:\Documents and Settings\adel magroud\Application Data\FastStone
2008-07-25 08:57 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-07-25 08:57 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys
2008-07-25 01:33 . 2008-07-25 01:33 <REP> d--hs---- C:\FOUND.001
2008-07-24 22:58 . 2008-07-24 22:58 <REP> d-------- C:\WINDOWS\system32\MsDtc
2008-07-24 22:57 . 2004-08-03 23:01 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-07-24 22:57 . 2004-08-19 16:10 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-07-24 21:29 . 2004-08-19 16:09 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-24 21:29 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-07-24 21:29 . 2001-08-23 17:47 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-24 18:36 . 2008-07-24 18:36 0 --a------ C:\osy3.sys
2008-07-14 12:37 . 2008-07-09 16:34 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-25 15:30 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-07-24 21:46 --------- d-----w C:\Documents and Settings\adel magroud\Application Data\DMCache
2008-07-24 21:29 --------- d-----w C:\Documents and Settings\adel magroud\Application Data\skypePM
2008-07-24 21:20 --------- d-----w C:\Documents and Settings\adel magroud\Application Data\Skype
2008-07-24 21:17 --------- d-----w C:\Program Files\Skype
2008-07-24 21:17 --------- d-----w C:\Program Files\Google
2008-07-24 21:17 --------- d-----w C:\Program Files\Fichiers communs\Skype
2008-07-24 21:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-07-24 21:02 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-24 21:00 --------- d-----w C:\Program Files\Services en ligne
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 21:09 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-07-24 23:17 171448]
"SuperCopier2.exe"="e:\Program Files\SuperCopier2\SuperCopier2.exe" [2005-03-14 01:37 1057280]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-19 16:22 1667584]
"IDMan"="E:\Program Files\ade\Internet Download Manager\IDMan.exe" [2008-07-14 16:42 2606512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 05:32 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:31 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:32 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 05:32 455168]
"is-C4F0E"="e:\Documents and Settings\All Users\Bureau\Kaspersky Lab Tool\is-C4F0E\is-C4F0E.exe" [2008-06-07 15:26 217088]
"eagleeye"="C:\Program Files\tuEagles\EagleSvr.exe" [2006-09-24 09:03 1348608]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 15:42 77824 C:\WINDOWS\SOUNDMAN.EXE]
"VTTimer"="VTTimer.exe" [2005-03-07 21:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-11 11:33 147456 C:\WINDOWS\system32\VTTrayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 21:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
R1 is-C4F0Edrv;is-C4F0Edrv;C:\WINDOWS\system32\drivers\
07128066.sys [2008-03-05 11:41]
R1 is-HJI24drv;is-HJI24drv;C:\WINDOWS\system32\drivers\58151912.sys [2008-03-05 11:41]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S2 is-C4F0E;is-C4F0E;e:\Documents and Settings\All Users\Bureau\Kaspersky Lab Tool\is-C4F0E\is-C4F0E.exe [2008-06-07 15:26]
S2 is-HJI24;is-HJI24;C:\Documents and Settings\All Users\Bureau\Kaspersky Lab Tool\is-HJI24\is-HJI24.exe []
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E???? ??E?? ??I?? (??.??.??) EU ??E??E IC????I ?C????
O8 -: E???? C??? EU ??E??E IC????I ?C????
O8 -: E???? EU ??E??E IC????I ?C????
O8 -: E???? ??E?? ??I?? (??.??.??) EU ??E??E IC????I ?C???? - C:\Documents and Settings\adel magroud\Local Settings\Temp\Rar$EX00.063\IEGetVL.htm
O8 -: E???? C??? EU ??E??E IC????I ?C???? - C:\Documents and Settings\adel magroud\Local Settings\Temp\Rar$EX00.063\IEGetAll.htm
O8 -: E???? EU ??E??E IC????I ?C???? - C:\Documents and Settings\adel magroud\Local Settings\Temp\Rar$EX00.063\IEExt.htm
O8 -: تحميل الكل بـ إنترنت داونلود مانيجر - E:\Program Files\ade\Internet Download Manager\IEGetAll.htm
O8 -: تحميل بـ إنترنت داونلود مانيجر - E:\Program Files\ade\Internet Download Manager\IEExt.htm
O8 -: تحميل محتوى فيديو (إف.إل.في) بـ إنترنت داونلود مانيجر - E:\Program Files\ade\Internet Download Manager\IEGetVL.htm
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-07-25 16:50:59
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cachés ...
C:\PROGRAM FILES\TUEAGLES\EAGLESVR.EXE [468] 0x81C42020
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\DOCUME~1\ADELMA~1\LOCALS~1\Temp\mc21.tmp"
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\tuEagles\gphook.dll
-> C:\Program Files\tuEagles\EagleH.dll
-> C:\Program Files\tuEagles\EagleRes.dll
.
Temps d'accomplissement: 2008-07-25 16:57:38
ComboFix-quarantined-files.txt 2008-07-25 14:56:42
ComboFix2.txt 2008-07-25 11:54:18
Pre-Run: 9,744,113,664 octets libres
Post-Run: 9,487,982,592 octets libres
132