Merci.
Rapport combofix
ComboFix 08-08-18.05 - Karine 2008-08-19 16:32:47.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1240 [GMT 2:00]
Endroit: C:\Users\Karine\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Karine\AppData\Roaming\inst.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-19 to 2008-08-19 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 14:25 --------- d-----w C:\Program Files\MSN Messenger
2008-08-19 14:23 352,615 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-08-18 22:50 27,430 ----a-w C:\Users\Karine\AppData\Roaming\nvModes.dat
2008-08-18 19:40 --------- d-----w C:\Users\Karine\AppData\Roaming\Malwarebytes
2008-08-18 19:40 --------- d-----w C:\ProgramData\Malwarebytes
2008-08-18 19:40 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-08-18 15:43 --------- d-----w C:\Users\Karine\AppData\Roaming\Grisoft
2008-08-18 15:38 --------- d-----w C:\Program Files\Zone Labs
2008-08-18 08:42 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-18 08:15 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-18 07:34 --------- d-----w C:\ProgramData\eMule
2008-08-17 19:38 --------- d-----w C:\Program Files\a-squared Free
2008-08-17 13:01 38,472 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-08-17 13:01 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-08-17 07:25 --------- d-----w C:\Program Files\The Cleaner Free
2008-08-16 09:12 --------- d-----w C:\Users\Karine\AppData\Roaming\Canon
2008-08-15 08:22 --------- d-----w C:\Program Files\Windows Mail
2008-08-07 16:31 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-08-06 08:26 --------- d-----w C:\ProgramData\Roxio
2008-08-03 18:13 47,360 ----a-w C:\Users\Karine\AppData\Roaming\pcouffin.sys
2008-08-03 18:13 --------- d-----w C:\Program Files\vso
2008-07-31 12:03 --------- d-----w C:\ProgramData\NOS
2008-07-31 12:03 --------- d-----w C:\Program Files\NOS
2008-07-30 18:33 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 06:24 --------- d-----w C:\ProgramData\Lavasoft
2008-07-16 06:23 --------- d-----w C:\Program Files\Lavasoft
2008-07-16 06:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-13 16:50 --------- d-----w C:\Program Files\Java
2008-07-12 19:15 --------- d-----w C:\ProgramData\vsosdk
2008-07-12 16:47 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-07-12 16:45 --------- d-----w C:\ProgramData\DVD Shrink
2008-07-11 12:25 --------- d-----w C:\Users\Karine\AppData\Roaming\Roxio
2008-07-11 12:11 --------- d-----w C:\Program Files\VideoLAN
2008-07-11 11:56 --------- d-----w C:\Program Files\QuickTime
2008-07-10 08:26 --------- d--h--w C:\ProgramData\CanonBJ
2008-07-09 16:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-09 16:23 --------- d-----w C:\Program Files\Microsoft Games
2008-07-09 16:05 --------- d-----w C:\ProgramData\Microsoft Help
2008-07-09 16:04 --------- d-----w C:\Program Files\Microsoft Works
2008-07-08 13:01 --------- d-----w C:\Users\Karine\AppData\Roaming\ArcSoft
2008-07-07 15:14 --------- d-----w C:\Program Files\Canon
2008-07-07 14:49 --------- d-----w C:\Users\Karine\AppData\Roaming\My Games
2008-07-07 14:28 --------- d-----w C:\Program Files\ArcSoft
2008-07-04 06:54 96,520 ----a-w C:\Windows\system32\drivers\avgldx86.sys
2008-07-04 06:54 10,520 ----a-w C:\Windows\System32\avgrsstx.dll
2008-07-02 06:23 --------- d-----w C:\ProgramData\Symantec
2008-06-27 11:48 --------- d-----w C:\ProgramData\WLInstaller
2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-21 07:38 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-21 06:34 174 --sha-w C:\Program Files\desktop.ini
2008-06-20 22:28 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-20 22:28 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-20 22:28 --------- d-----w C:\Program Files\Windows Journal
2008-06-20 22:28 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-20 22:28 --------- d-----w C:\Program Files\Windows Calendar
2008-06-20 22:27 --------- d-----w C:\Program Files\Windows Defender
2008-06-20 09:51 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-20 09:51 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-19 10:46 --------- d-----w C:\ProgramData\avg8
2008-06-19 10:46 --------- d-----w C:\Program Files\AVG
2008-06-19 10:14 --------- d-----w C:\ProgramData\Grisoft
2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-06-12 05:28 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 34,816 ----a-w C:\Windows\System32\msscb.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 11,776 ----a-w C:\Windows\System32\msshooks.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-27 04:59 18,904 ----a-w C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-05-27 04:59 106,605 ----a-w C:\Windows\System32\StructuredQuerySchema.bin
2007-12-15 18:36 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
- Code:
-
<pre>
----a-w 325,204 2006-12-21 18:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 22:43 729088]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 05:36 827392]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 16:37 174872]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-04-23 18:11 176128]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 11:54 50696]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-04 08:54 1232152]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-05-01 12:27 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-01 12:27 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-01 12:27 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 15:05 959976]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1D536503-4C27-4389-8972-3D83BF6ABC2B}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{0B467C74-96CA-47CA-BD31-D644154EE19A}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{19E766DC-93D2-4FB6-BDDC-64EDE3600842}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"TCP Query User{365922B3-7C93-47B2-BC19-04CC7C4FB9FD}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{FAD7ED5C-7012-4885-BB89-D6165A7F8BF0}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{7DFD98CB-F7C5-4747-BF4B-7588FD007615}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{DA628DBF-E451-4A66-B45C-47DF7FC83783}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{A8E0909B-850A-412C-BC1F-8837279496E4}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{E1A46FA5-5C48-46A9-A4FD-8CA10B91D96D}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{985D9A84-4ED1-4CDB-B0E2-E3911A18449F}C:\\users\\karine\\downloads\\wow-frfr-installer-downloader.exe"= UDP:C:\users\karine\downloads\wow-frfr-installer-downloader.exe:wow-frfr-installer-downloader.exe
"UDP Query User{200E8C81-B393-4B64-994A-C894E5D63316}C:\\users\\karine\\downloads\\wow-frfr-installer-downloader.exe"= TCP:C:\users\karine\downloads\wow-frfr-installer-downloader.exe:wow-frfr-installer-downloader.exe
"{D25362C3-B0DD-4E21-A43B-ADD8BD2D7C3B}"= UDP:C:\Program Files\World of Warcraft\WoW-2.3.0-frFR-downloader.exe:Blizzard Downloader
"{06F06773-90EE-4CBE-8D7D-1079AA981ADC}"= TCP:C:\Program Files\World of Warcraft\WoW-2.3.0-frFR-downloader.exe:Blizzard Downloader
"{98CD4471-6698-49F7-9EF0-532945ACBB40}"= UDP:6881:Blizzard Downloader: 6881
"{C4BFCFD4-38DA-401B-AD5F-32DFD19BD7FF}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{4ABBE4F1-5BAE-4EE1-8E9F-31AFA93312B6}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{C168DCA3-EF4F-4765-87BD-928FF2CF5216}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{952D2C1C-8D03-431A-87AC-977084C1C22C}C:\\kav\\kav8.0\\french\\setup.exe"= UDP:C:\kav\kav8.0\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009
"UDP Query User{5C6F9BAA-3A27-4E14-90D2-1C4E2DB703E5}C:\\kav\\kav8.0\\french\\setup.exe"= TCP:C:\kav\kav8.0\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009
"{AAA72DB4-B0EE-42BF-9D5F-8279F2D435C6}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\system32\Drivers\avgldx86.sys [2008-07-04 08:54]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-04 08:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52be117d-ab5d-11dc-900c-806e6f6e6963}]
\shell\AutoRun\command - E:\Installer.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.fr/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
.
.
------- File Associations (Beta) -------
.
VBEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
VBSFile="%SystemRoot%\System32\WScript.exe" "%1" %*
vbefile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
vbsfile\shell\open\command="%SystemRoot%\System32\WScript.exe" "%1" %*
jsefile\shell\open\command=%SystemRoot%\System32\WScript.exe "%1" %*
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-19 16:36:32
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-19 16:39:06
ComboFix-quarantined-files.txt 2008-08-19 14:39:00
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 97,428,971,520 octets libres
220 --- E O F --- 2008-08-15 08:12:19