- Code: Tout sélectionner
ComboFix 10-11-18.04 - Propriétaire 19/11/2010 14:19:04.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.533 [GMT 1:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\cla.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\ResultBar
c:\documents and settings\All Users\Application Data\ResultBar\resultbar113.exe
c:\documents and settings\Propriétaire\Application Data\OfferBox
c:\documents and settings\Propriétaire\Application Data\OfferBox\config.dat
c:\documents and settings\Propriétaire\Application Data\OfferBox\config.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Propriétaire\Application Data\PriceGong\Data\z.xml
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\chrome\resultbar.jar
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\defaults\preferences\prefs.js
c:\program files\Mozilla Firefox\extensions\{34EFA911-B536-4C08-BECE-CD5E55C875B0}\install.rdf
c:\program files\OfferBox
c:\program files\OfferBox\OfferBox.exe
c:\program files\OfferBox\OfferBoxBHO.dll
c:\program files\OfferBox\OfferBoxChromeExtension.crx
c:\program files\OfferBox\OfferBoxEngine.dll
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome.manifest
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome\content\events.js
c:\program files\OfferBox\offerboxffx@offerbox.com\chrome\content\overlay.xul
c:\program files\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll
c:\program files\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.xpt
c:\program files\OfferBox\offerboxffx@offerbox.com\install.rdf
c:\program files\OfferBox\OfferBoxLauncher.exe
c:\program files\OfferBox\res\language.xml
c:\program files\OfferBox\res\loader.gif
c:\program files\OfferBox\uninst.exe
c:\program files\ResultBar
c:\program files\ResultBar\resultbar.dll
c:\program files\ResultBar\resultbar.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RESULTBAR_SERVICE
-------\Service_ResultBar Service
((((((((((((((((((((((((((((( Fichiers créés du 2010-10-19 au 2010-11-19 ))))))))))))))))))))))))))))))))))))
.
2010-11-17 18:00 . 2010-11-17 18:00 -------- d-----w- C:\_OTM
2010-11-14 21:31 . 2010-11-14 21:32 -------- d-----w- c:\documents and settings\Propriétaire\Application Data\vlc
2010-11-12 19:30 . 2010-11-15 21:39 -------- d-----w- c:\program files\ZHPDiag
2010-11-07 11:59 . 2010-11-19 10:39 -------- d-----w- c:\windows\system32\NtmsData
2010-11-07 11:45 . 2010-11-07 11:45 -------- d-----w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-23 15:47 . 2010-11-14 21:36 -------- d-----w- C:\Temp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 11:23 . 2008-01-07 16:56 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-01-07 16:56 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-01-07 16:56 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-01-07 16:56 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2008-01-07 16:58 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2008-01-07 16:56 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2008-01-07 16:55 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-09-08 10:17 . 2010-09-08 10:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17 . 2010-09-08 10:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-09-01 11:51 . 2008-01-07 16:54 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2008-01-07 16:58 1852928 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2008-01-07 16:58 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2008-01-07 16:57 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-01-07 16:57 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2008-01-07 16:54 617472 ----a-w- c:\windows\system32\comctl32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\program files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe" [2003-06-22 24576]
"NVIEW"="nview.dll" [2003-05-02 835654]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 90112]
"HPHUPD05"="c:\program files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-05-23 49152]
"HPHmon05"="c:\windows\System32\hphmon05.exe" [2003-05-23 483328]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"StorageGuard"="c:\program files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-02 4640768]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-08-09 139264]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"HomePlayer"="c:\program files\HomePlayer\HomePlayer.exe" [2007-11-06 294912]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
c:\documents and settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\HomePlayer\\VLC\\vlc.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [24/04/2010 15:43 135336]
R3 HPCFILT;Alcor Micro Corp - 9361;c:\windows\system32\drivers\HPCfilt.sys [11/08/2003 08:46 29812]
.
Contenu du dossier 'Tâches planifiées'
2010-11-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
2010-08-28 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8272956724.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
2010-04-23 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-08-06 21:07]
2010-11-19 c:\windows\Tasks\User_Feed_Synchronization-{60AB1693-9954-4378-B59A-7581477FC1D0}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://srch-fr9.hpwis.com/
mSearch Bar = hxxp://srch-fr9.hpwis.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\gmgv4n2i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2207610&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Softonic France FF Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/firefox
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-OfferBox - c:\program files\OfferBox\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-19 14:26
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1528)
c:\windows\system32\nView.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\rundll32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2010-11-19 14:32:55 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-11-19 13:32
Avant-CF: 23 710 785 536 octets libres
Après-CF: 23 635 574 784 octets libres
- - End Of File - - 75850C169C364128EA635068300CD001