ComboFix 08-07-25.6 - Agnès 2008-07-28 14:59:09.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1193 [GMT 2:00]
Endroit: C:\Users\Agnès\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-28 13:05 3,932,160 --sha-w C:\Users\Agnès\NTUSER.DAT
2008-07-28 13:05 3,932,160 --sha-w C:\Users\Agnès\NTUSER.DAT
2008-07-28 12:58 --------- d-----w C:\Users\Agnès\AppData\Roaming\uTorrent
2008-07-28 10:38 --------- d-----w C:\Program Files\SopCast
2008-07-27 22:28 --------- d-----w C:\Users\Agnès\AppData\Roaming\VMNTOOLBAR
2008-07-23 21:29 --------- d-----w C:\Program Files\Secured IE
2008-07-23 21:28 --------- d-----w C:\Program Files\securedie
2008-07-23 21:26 --------- d-----w C:\Program Files\Multi_Media_France
2008-07-22 20:02 --------- d-----w C:\Users\Agnès\AppData\Roaming\Malwarebytes
2008-07-22 20:02 --------- d-----w C:\ProgramData\Malwarebytes
2008-07-22 20:02 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-07-20 18:21 38,472 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-07-20 18:21 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-07-19 20:44 743 ---ha-w C:\os264931.bin
2008-07-19 11:30 --------- d-----w C:\Program Files\PhotoScape
2008-07-19 01:20 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-12 09:56 --------- d-----w C:\ProgramData\Downloaded Installations
2008-07-12 09:56 --------- d-----w C:\Program Files\VirginMega
2008-07-09 01:11 174 --sha-w C:\Program Files\desktop.ini
2008-07-09 01:02 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-09 01:01 --------- d-----w C:\Program Files\Windows Mail
2008-07-04 07:58 27,335 ----a-w C:\Users\Agnès\AppData\Roaming\nvModes.dat
2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
2008-06-25 22:39 81,920 ----a-w C:\Windows\System32\W32N50.dll
2008-06-25 22:39 17,134 ----a-w C:\Windows\System32\PCANDIS5.sys
2008-05-31 21:35 --------- d-----w C:\Program Files\uTorrent
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-04-15 00:18 84 ----a-w C:\Users\Agnès\AppData\Roaming\wklnhst.dat
2008-01-04 16:23 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-01-04 16:23 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-01-04 16:23 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
2007-09-06 12:28 1453080 --a------ C:\Program Files\securedie\tbsecu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 04:01 1232896]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 22:43 729088]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 02:05 1045800]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 16:37 174872]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-04-23 18:11 176128]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-01 12:27 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-01 12:27 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-01 12:27 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-06-25 23:26 77824]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 12:43 90112]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"mobiswing"="C:\PROGRA~1\SECURE~1\secp.exe" [2008-05-20 01:01 61952]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-11 12:38:39 110592]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 22:40:10 210520]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{63E473AA-F42E-438A-967D-10594C088465}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{385886E8-F959-405D-AEA8-53E522F0198F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7F62BBC5-75E4-4939-B914-21991D03E0E3}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{77BE45C3-9CE5-46CF-866A-F628CA4E7CF2}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{57F8BBBF-005C-4CAD-94DA-B7C508017205}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"TCP Query User{A0656E1A-D235-4124-BFD9-D057861C6B57}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{3B5B59AF-1852-4A8C-AD80-805D82628C92}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{9432F638-C6A4-49D4-B1AB-339C5BD368DA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{53B4D946-DAB3-4332-BBBF-E041127A4280}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5D686B3D-85A6-4F99-9980-091A3F3D6FCC}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{72461AEA-F49E-43FC-AFB3-B9E9194E836A}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{056FE5F8-8F8D-4E1F-A694-9F9469E3D6B5}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{ABFE8B72-B49C-4820-B672-5DFFDCF45B49}C:\\program files\\bluetoothpcdialer\\bluetoothpcdialer.exe"= UDP:C:\program files\bluetoothpcdialer\bluetoothpcdialer.exe:BluetoothPCDialer
"UDP Query User{F15B83FC-3D79-49C7-9775-1C455781056F}C:\\program files\\bluetoothpcdialer\\bluetoothpcdialer.exe"= TCP:C:\program files\bluetoothpcdialer\bluetoothpcdialer.exe:BluetoothPCDialer
"TCP Query User{A4EACCB0-318C-40B7-AC6A-EAA6E7D68FF4}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{023DB3B3-8EE8-4650-987E-10BD3FA060D0}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{B43C25E6-2F0D-460E-A8FD-9DD95C90E479}C:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{965D1EB2-5100-4A4C-8B0E-4B17B0B3ACF7}C:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:C:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{C675EBFD-96B1-4481-B82F-F6472ABDFAF2}C:\\program files\\sopcast\\sopcast.exe"= UDP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{877FB448-F5A3-4ABB-903D-14B87388A06B}C:\\program files\\sopcast\\sopcast.exe"= TCP:C:\program files\sopcast\sopcast.exe:SopCast Main Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-07-27 C:\Windows\Tasks\User_Feed_Synchronization-{938B4E0B-3B20-46D5-9B07-602BED779000}.job - C:\Windows\system32\msfeedssync.exe [2006-11-02 11:45]
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=73&bd=Pavilion&pf=laptop
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 15:04:58
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-28 15:06:42
ComboFix-quarantined-files.txt 2008-07-28 13:06:34
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 8,453,664,768 octets libres
162 --- E O F --- 2008-07-24 01:03:09
ca me donne ça !! je fais quoi après ?