pour Arethusa
bonjour,
-voici le rapport combofix:
ComboFix 08-11-20.02 - monpc 2008-11-21 17:44:00.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6001.1.1252.1.1036.18.2624 [GMT 1:00]
Lancé depuis: c:usersmonpcLogicielsComboFix.exe
.
ADS - Windows: deleted 72 bytes in 1 streams.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-21 au 2008-11-21 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-21 16:38 45,056 ----a-w c:windowsSystem32acovcnt.exe
2008-11-21 16:38 352,615 ---ha-w c:windowssystem32driversvsconfig.xml
2008-11-21 16:24 --------- d-----w c:usersmonpcAppDataRoamingOpenOffice.org2
2008-11-20 18:44 1,753,600 ----a-w c:windowsInternet LogsxDB7F7B.tmp
2008-11-20 17:32 --------- d-----w c:program filesPanda Security
2008-11-20 17:30 1,310,720 --sha-w c:usersInvité
tuser.dat
2008-11-20 17:30 1,310,720 --sha-w c:usersInvité
tuser.dat
2008-11-20 17:21 69,689 ----a-w c:windowsUNZIP.DLL
2008-11-20 17:21 507,904 ----a-w c:windowsTMUPDATE.DLL
2008-11-20 17:21 286,720 ----a-w c:windowsPATCH.EXE
2008-11-20 16:53 --------- d-----w c:usersmonpcAppDataRoamingEoRezo
2008-11-20 13:52 --------- d-----w c:usersmonpcAppDataRoamingNikon
2008-11-20 13:52 --------- d-----w c:program filesCommon FilesNikon
2008-11-20 13:47 --------- d--h--w c:program filesInstallShield Installation Information
2008-11-20 13:46 --------- d-----w c:program filesNikon
2008-11-20 13:44 --------- d-----w c:program filesArcSoft
2008-11-19 17:42 --------- d-----w c:usersmonpcAppDataRoaming uxmath
2008-11-19 17:04 --------- d-----w c:program filesTuxMath
2008-11-19 10:36 --------- d-----w c:progra~2Microsoft Help
2008-11-18 18:40 --------- d-----w c:usersmonpcAppDataRoamingShareaza
2008-11-18 18:02 51,792 ----a-w c:windowssystem32driversaswMonFlt.sys
2008-11-18 17:11 --------- d-----w c:progra~2Spybot - Search & Destroy
2008-11-18 17:04 --------- d-----w c:program filesa-squared Free
2008-11-18 16:57 --------- d-----w c:program filesSpybot - Search & Destroy
2008-11-18 15:08 --------- d-----w c:program filesWindows Mail
2008-11-18 15:08 --------- d-----w c:progra~2P4G
2008-11-16 16:49 --------- d-----w c:usersmonpcAppDataRoamingCanon
2008-11-13 16:16 352,615 ---ha-w c:windowssystem32driversvsconfig(276).xml
2008-11-08 16:13 1,716,224 ----a-w c:windowsInternet LogsxDB76B4.tmp
2008-11-08 16:04 --------- d-----w c:program filesDivX
2008-11-08 16:04 --------- d-----w c:program filesCommon FilesPX Storage Engine
2008-11-08 16:03 --------- d-----w c:program filesMozilla Thunderbird
2008-11-07 14:36 --------- d-----w c:usersmonpcAppDataRoaminguTorrent
2008-11-07 14:17 --------- d-----w c:usersmonpcAppDataRoamingLimeWire
2008-11-05 17:21 --------- d-----w c:program filesCanon
2008-11-05 17:13 --------- d--h--w c:program filesCanonBJ
2008-10-31 16:31 --------- d-----w c:progra~2eMule
2008-10-31 16:30 --------- d-----w c:program fileseMule
2008-10-30 15:48 --------- d-----w c:program filesMicro Application
2008-10-30 15:48 --------- d-----w c:progra~2Micro Application
2008-10-29 19:04 --------- d-----w c:usersmonpcAppDataRoamingdvdcss
2008-10-25 15:21 --------- d-----w c:program filesCommon FilesScanSoft Shared
2008-10-25 11:57 352,615 ---ha-w c:windowssystem32driversvsconfig(527).xml
2008-10-25 11:25 29,186,387 ----a-w c:windowsInternet Logsvsmon_on_demand_2008_10_24_19_07_28_full.dmp.zip
2008-10-23 16:51 --------- d-----w c:usersmonpcAppDataRoamingvlc
2008-10-23 16:47 --------- d-----w c:program filesVideoLAN
2008-10-22 16:12 --------- d-----w c:program filesDVD Decrypter
2008-10-18 14:43 --------- d-----w c:program filesSlySoft
2008-10-18 14:43 --------- d-----w c:progra~2SlySoft
2008-10-18 14:42 --------- d-----w c:program filesElaborate Bytes
2008-10-17 14:37 27,839 ----a-w c:usersmonpcAppDataRoaming
vModes.dat
2008-10-11 16:06 --------- d-----w c:usersmonpcAppDataRoaminggtk-2.0
2008-10-10 16:22 --------- d-----w c:program filesGimp-2.0
2008-10-09 17:02 --------- d-----w c:program filesuTorrent
2008-10-09 15:45 --------- d-----w c:program filesMicrosoft IntelliPoint
2008-10-09 08:46 --------- d-----w c:progra~2SSScanAppDataDir
2008-10-09 08:43 --------- d-----w c:usersmonpcAppDataRoamingArcSoft
2008-10-04 08:38 --------- d-----w c:program filesAudacity
2008-10-04 08:31 --------- d-----w c:program filesLavasoft
2008-10-04 08:30 --------- d-----w c:program filesCommon FilesWise Installation Wizard
2008-10-02 03:49 827,392 ----a-w c:windowsSystem32wininet.dll
2008-10-01 16:06 --------- d-----w c:program filesTomb Raider - Anniversary Demo
2008-10-01 16:06 --------- d-----w c:progra~2Media Center Programs
2008-09-30 15:43 1,286,152 ----a-w c:windowsSystem32msxml4.dll
2008-09-23 15:01 --------- d-----w c:program filesSkyline
2008-09-23 15:01 --------- d-----w c:progra~2Skyline
2008-09-18 05:09 3,601,464 ----a-w c:windowsSystem32
tkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:windowsSystem32
toskrnl.exe
2008-09-18 04:56 147,456 ----a-w c:windowsSystem32Faultrep.dll
2008-09-18 04:56 125,952 ----a-w c:windowsSystem32wersvc.dll
2008-09-18 02:16 2,032,640 ----a-w c:windowsSystem32win32k.sys
2008-09-10 03:40 1,334,272 ----a-w c:windowsSystem32msxml6.dll
2008-09-10 03:40 1,334,272 ----a-w c:windowsSystem32msxml6(243).dll
2008-09-05 05:14 1,191,936 ----a-w c:windowsSystem32msxml3.dll
2008-09-05 05:14 1,191,936 ----a-w c:windowsSystem32msxml3(241).dll
2008-08-25 18:48 1,524,736 ----a-w c:windowsInternet LogsxDB8574.tmp
2008-08-22 15:50 1,513,984 ----a-w c:windowsInternet LogsxDB7E24.tmp
2008-06-28 16:28 174 --sha-w c:program filesdesktop.ini
2008-08-06 15:13 16,384 --sha-w c:windowsServiceProfilesLocalServiceAppDataLocalMicrosoftWindowsHistoryHistory.IE5index.dat
2008-08-06 15:13 32,768 --sha-w c:windowsServiceProfilesLocalServiceAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.IE5index.dat
2008-08-06 15:13 16,384 --sha-w c:windowsServiceProfilesLocalServiceAppDataRoamingMicrosoftWindowsCookiesindex.dat
2008-01-19 07:33 397,312 --sha-w c:windowswinsxsx86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6001.18000_none_f1582d884fb532fbWinMail.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiersADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOTCLSID{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 01:08 143360 --a------ c:program filesASUSASUS Data Security ManagerOverlayIconShlExt1.dll
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"Sidebar"="c:program filesWindows Sidebarsidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:windowsehomeehTray.exe" [2008-01-19 125952]
"SpybotSD TeaTimer"="c:program filesSpybot - Search & DestroyTeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="c:program filesWindows Media PlayerWMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"SMSERIAL"="c:program filesMotorolaSMSERIALsm56hlpr.exe" [2006-11-22 630784]
"ATKMEDIA"="c:program filesASUSATK MediaDMEDIA.EXE" [2006-11-02 61440]
"avast!"="c:progra~1ALWILS~1Avast4ashDisp.exe" [2008-11-18 81000]
"ZoneAlarm Client"="c:program filesone LabsoneAlarmzlclient.exe" [2008-03-03 959976]
"NvSvc"="c:windowssystem32
vsvc.dll" [2007-12-05 86016]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2007-12-05 8534560]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2007-12-05 81920]
"SunJavaUpdateSched"="c:program filesJavajre1.6.0_07injusched.exe" [2008-06-10 144784]
"PowerForPhone"="c:program filesP4PP4P.exe" [2007-08-03 778240]
"JMB36X IDE Setup"="c:windowsRaidToolxInsIDE.exe" [2007-03-20 36864]
"ASUS Screen Saver Protector"="c:windowsASScrPro.exe" [2008-04-15 33136]
"ASUS Camera ScreenSaver"="c:windowsASScrProlog.exe" [2008-04-15 37232]
"IntelliPoint"="c:program filesMicrosoft IntelliPointipoint.exe" [2008-06-10 1406024]
"SynTPEnh"="c:program filesSynapticsSynTPSynTPEnh.exe" [2007-12-06 1029416]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 c:windowsRtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-03-16 c:windowsSkyTel.exe]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunOnce]
"GrpConv"="grpconv -o" [X]
c:usersmonpcAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupFoxit Reader
Foxit Reader.lnk - c:program filesFoxit SoftwareFoxit ReaderFoxit Reader.exe [2008-06-27 6794496]
Uninstall.lnk - c:program filesFoxit SoftwareFoxit ReaderUninstall.exe [2008-06-27 89344]
c:usersmonpcAppDataRoamingMICROS~1WindowsSTARTM~1ProgramsStartupFoxit Reader
Foxit Reader.lnk - c:program filesFoxit SoftwareFoxit ReaderFoxit Reader.exe [2008-06-27 6794496]
Uninstall.lnk - c:program filesFoxit SoftwareFoxit ReaderUninstall.exe [2008-06-27 89344]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
[HKLM~startupfolderC:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NkbMonitor.exe.lnk]
path=c:programdataMicrosoftWindowsStart MenuProgramsStartupNkbMonitor.exe.lnk
backup=c:windowspssNkbMonitor.exe.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM~startupfolderC:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^StupAssist.lnk]
path=c:programdataMicrosoftWindowsStart MenuProgramsStartupStupAssist.lnk
backup=c:windowspssStupAssist.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM~startupfolderC:^Users^monpc^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice 2.4.lnk]
path=c:usersmonpcAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupOpenOffice 2.4.lnk
backup=c:windowspssOpenOffice 2.4.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregLightScribe Control Panel]
--a------ 2007-06-20 11:49 451872 c:program filesCommon FilesLightScribeLightScribeControlPanel.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregOPSE reminder]
--a------ 2003-07-07 08:30 729088 c:program filesScanSoftOmniPageSE2.0EregFreEreg.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregOpwareSE2]
--a------ 2003-05-08 10:00 49152 c:program filesScanSoftOmniPageSE2.0opwareSE2.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicyDomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyFirewallRules]
"{9AE33D4F-A886-420F-B510-565B93D26C72}"= TCP:6004|c:program filesMicrosoft OfficeOffice12outlook.exe:Microsoft Office Outlook
"{4C26850A-A100-4EB0-9E92-53E84C26755C}"= UDP:c:program filesuTorrentuTorrent.exe:µTorrent (TCP-In)
"{8B08FDB5-05C8-42DB-A10C-72A2E6ADC4A7}"= TCP:c:program filesuTorrentuTorrent.exe:µTorrent (UDP-In)
[HKLM~servicessharedaccessparametersfirewallpolicyPublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicyStandardProfile]
"EnableFirewall"= 0 (0x0)
R3 itecir;ITECIR Infrared Receiver;c:windowssystem32DRIVERSitecir.sys [2008-04-15 47616]
S0 pavboot;pavboot;c:windowssystem32driverspavboot.sys [2008-11-20 28544]
S1 aswSP;avast! Self Protection;c:windowssystem32driversaswSP.sys [2008-06-22 110160]
S2 aswFsBlk;aswFsBlk;c:windowssystem32DRIVERSaswFsBlk.sys [2008-06-22 20560]
S2 aswMonFlt;aswMonFlt;c:windowssystem32DRIVERSaswMonFlt.sys [2008-06-22 51792]
S2 SBSDWSCService;SBSD Security Center Service;c:program filesSpybot - Search & DestroySDWinSec.exe [2008-06-29 809296]
S2 StkSSrv;Syntek AVStream USB2.0 WebCam Service;c:windowsSystem32StkCSrv.exe [2007-04-19 24576]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:windowssystem32DRIVERSatl01v32.sys [2007-03-15 48128]
S3 StkCMini;Syntek AVStream USB2.0 1.3M WebCam;c:windowssystem32DriversStkCMini.sys [2007-05-30 1260672]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionsvchost]
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - ECACHE
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:program filesCommon FilesLightScribeLSRunOnce.exe"
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
HKLM-Run-EoEngine - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
MSConfigStartUp-EoEngine - c:program filesEoRezoEoEngine.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:usersmonpcAppDataRoamingMozillaFirefoxProfilessx3mamf5.default
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.orange.fr
FF -: plugin - c:program filesYahoo!Common
pyaxmpb.dll
FF -: plugin - c:windowsMicrosoft.NETFrameworkv3.5Windows Presentation FoundationNPWPF.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-21 17:52:23
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
C:ADSM_PData_0150
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
Heure de fin: 2008-11-21 17:53:14
ComboFix-quarantined-files.txt 2008-11-21 16:53:11
Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Après-CF: 109,447,712,768 octets libres
217 --- E O F --- 2008-11-19 10:36:48