- Code: Tout sélectionner
ComboFix 09-12-29.03 - christophe amouroux 29/12/2009 23:15:01.3.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1007.604 [GMT 1:00]
Lancé depuis: c:\documents and settings\christophe amouroux\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\christophe amouroux\Bureau\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
Les fichiers ci-dessous ont été désactivés pendant l'exécution:
c:\program files\SuperCopier2\SC2Hook.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\appmgmts.dll --> c:\windows\system32\appmgmts.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-28 au 2009-12-29 ))))))))))))))))))))))))))))))))))))
.
2009-12-29 19:31 . 2009-12-29 18:53 167936 ------w- C:\appmgmts.dll
2009-12-29 12:00 . 2009-12-29 12:28 -------- d-----w- C:\Schnoqueur
2009-12-29 11:23 . 2009-12-29 11:24 -------- d-----w- C:\tdsskiller
2009-12-29 11:07 . 2009-12-29 11:09 -------- d-----w- C:\rsit
2009-12-29 11:01 . 2009-12-29 11:01 -------- d-----w- c:\program files\Trend Micro
2009-12-29 10:02 . 2009-12-29 10:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 22:25 . 2001-08-28 12:00 94078 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-29 22:25 . 2001-08-28 12:00 532794 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-29 22:20 . 2009-03-01 23:50 -------- d-----w- c:\program files\SuperCopier2
2009-12-29 21:32 . 2008-12-22 17:23 -------- d-----w- c:\program files\Java
2009-12-29 21:30 . 2009-12-29 21:22 152576 ----a-w- c:\documents and settings\christophe amouroux\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-29 21:30 . 2009-11-25 09:10 79488 ----a-w- c:\documents and settings\christophe amouroux\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-29 19:32 . 2009-04-10 17:17 -------- d-----w- c:\documents and settings\christophe amouroux\Application Data\foobar2000
2009-12-29 18:53 . 2009-01-10 15:18 167936 ----a-w- c:\windows\system32\appmgmts.dll
2009-12-29 17:09 . 2008-12-21 22:56 -------- d-----w- c:\documents and settings\christophe amouroux\Application Data\uTorrent
2009-12-29 16:52 . 2009-01-06 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-29 12:18 . 2009-11-13 08:20 -------- d-----w- c:\program files\Cheat Engine
2009-12-29 12:12 . 2008-12-21 19:41 -------- d-----w- c:\program files\Google
2009-12-29 11:04 . 2009-03-25 15:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 02:07 . 2009-03-11 10:22 -------- d-----w- c:\program files\a-squared Free
2009-12-29 00:34 . 2008-12-23 14:51 1 ----a-w- c:\documents and settings\christophe amouroux\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-28 18:48 . 2008-12-23 10:22 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-12-28 17:20 . 2009-02-03 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-27 18:38 . 2009-01-20 17:27 -------- d-----w- c:\documents and settings\christophe amouroux\Application Data\dvdcss
2009-12-10 22:44 . 2009-06-27 15:00 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-04 12:37 . 2009-02-24 22:30 -------- d-----w- c:\program files\Mp3tag
2009-12-03 15:14 . 2009-03-25 15:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 15:13 . 2009-03-25 15:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-12 19:08 . 2009-11-12 17:46 -------- d-----w- c:\documents and settings\christophe amouroux\Application Data\MSN6
2009-11-12 17:58 . 2008-12-21 13:48 22536 ----a-w- c:\documents and settings\christophe amouroux\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-12 17:54 . 2009-11-12 17:54 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-12 17:52 . 2009-11-12 17:52 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-11-12 17:46 . 2009-11-12 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
2009-11-10 01:20 . 2009-09-30 01:44 75680 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-11-08 23:57 . 2009-03-09 07:48 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-05 08:53 . 2009-11-05 08:53 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-29 07:42 . 2001-08-28 12:00 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:39 . 2008-12-21 13:42 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-21 05:39 . 2008-12-21 13:42 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-20 16:20 . 2008-12-21 13:42 265728 ------w- c:\windows\system32\drivers\http.sys
2009-10-13 10:33 . 2001-08-28 12:00 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2001-08-28 12:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2001-08-28 12:00 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 03:17 . 2008-12-23 10:06 411368 ----a-w- c:\windows\system32\deploytk.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\documents and settings\christophe amouroux\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 7680
Created time: 2008-12-21 13:48
Modified time: 2009-12-28 21:58
MD5: BA61DD752BE99502EE2453B9315A6742
SHA1: 5B5C70E6B79C918D9978C59F80C526682D1DB33C
------- Sigcheck -------
[-] 2009-12-29 . 9C3C12975C97119412802B181FBEEFFE . 167936 . . [5.1.2600.2180] . . c:\windows\system32\appmgmts.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"nwiz"="nwiz.exe" [2008-09-17 1657376]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-12-12 196608]
"P17Helper"="P17.dll" [2005-05-03 64512]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"M-Audio Taskbar Icon"="c:\windows\System32\DeltaIITray.exe" [2008-03-03 236040]
"DeltaIITaskbarApp"="c:\windows\system32\DeltaIITray.exe" [2008-03-03 236040]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"DT PHL"="c:\program files\Philips Display\SmartControl II\DTHtml.exe" [2007-07-27 292352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\fsproflt]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [11/03/2009 11:22 1858144]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [27/06/2009 16:00 108289]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\deltaII.sys [10/05/2009 00:25 302728]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 17:13 234864]
S3 sbext;Sound Blaster Extigy Audio Driver;c:\windows\system32\DRIVERS\sbext.sys --> c:\windows\system32\DRIVERS\sbext.sys [?]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mchInjDrv
.
Contenu du dossier 'Tâches planifiées'
.
.
------- Examen supplémentaire -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\christophe amouroux\Application Data\Mozilla\Firefox\Profiles\avnzrt03.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/webhp?hl=fr&safe=off&client=firefox-a&rls=org.mozilla:fr:official&hs=ekH&btnG=Rechercher
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\christophe amouroux\Application Data\Mozilla\Firefox\Profiles\avnzrt03.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 23:22
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\CHRIST~1\LOCALS~1\Temp\mc24.tmp"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2608)
c:\program files\SuperCopier2\SC2Hook.dll
c:\program files\RocketDock\RocketDock.dll
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\windows\system32\ZiepodOneClicker.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Portrait Displays\Shared\DTSRVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\Rundll32.exe
c:\program files\Fichiers communs\Portrait Displays\Shared\HookManager.exe
.
**************************************************************************
.
Heure de fin: 2009-12-29 23:27:38 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-12-29 22:27
ComboFix2.txt 2009-12-29 12:28
Avant-CF: 12 865 433 600 octets libres
Après-CF: 12 839 972 864 octets libres
- - End Of File - - E7F3FBDB09D691F4B9A5BFE4BE2BABE6
Edit AtOM: rapport "balisé" [code]