ComboFix 08-09-05.12 - Nicolas 2008-09-20 8:24:21.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1717 [GMT 2:00]
Endroit: C:\Users\Nicolas\Downloads\ComboFix.exe
.
- FONCTIONNALITES REDUITES -
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\actskn43.ocx
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-20 to 2008-09-20 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-20 06:10 352,615 —ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-09-20 06:10 --------- d-----w C:\Users\Nicolas\AppData\Roaming\OpenOffice.org2
2008-09-20 06:10 --------- d-----w C:\Program Files\Steam
2008-09-19 17:34 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-09-19 16:48 --------- d-----w C:\Users\Nicolas\AppData\Roaming\Pro Cycling Manager 2008
2008-09-19 05:13 --------- d-----w C:\Program Files\Common Files\Steam
2008-09-18 17:28 --------- d-----w C:\Program Files\Electronic Arts
2008-09-18 17:02 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-09-18 17:02 --------- d-----w C:\Program Files\Codemasters
2008-09-18 16:59 --------- d-----w C:\PROGRA~2\Codemasters
2008-09-18 14:49 --------- d-----w C:\PROGRA~2\Google Updater
2008-09-17 19:31 --------- d-----w C:\Users\Nicolas\AppData\Roaming\LimeWire
2008-09-14 16:34 --------- d-----w C:\PROGRA~2\Test Drive Unlimited
2008-09-13 16:47 139,120 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-09-13 16:47 111,928 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-09-13 09:25 --------- d-----w C:\Users\Nicolas\AppData\Roaming\Xfire
2008-09-12 18:11 --------- d-----w C:\Program Files\Nicolas MERLET
2008-09-11 15:48 --------- d-----w C:\PROGRA~2\Xfire
2008-09-10 15:21 --------- d-----w C:\Users\Nicolas\AppData\Roaming\vlc
2008-09-10 15:14 --------- d-----w C:\Program Files\VideoLAN
2008-09-08 17:21 --------- d-----w C:\PROGRA~2\Media Center Programs
2008-09-08 14:12 --------- d-----w C:\Program Files\Secunia
2008-09-08 12:41 --------- d-----w C:\Program Files\Enigma Software Group
2008-09-07 17:00 --------- d-----w C:\Users\Nicolas\AppData\Roaming\Malwarebytes
2008-09-07 17:00 --------- d-----w C:\Program Files\Malwarebytes’ Anti-Malware
2008-09-07 17:00 --------- d-----w C:\PROGRA~2\Malwarebytes
2008-09-06 09:01 2,755,359 ----a-w C:\Windows\Internet Logs\tvDebug.zip
2008-09-03 16:52 --------- d-----w C:\Program Files\Xfire
2008-09-01 22:16 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-09-01 22:16 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-09-01 14:35 --------- d-----w C:\Program Files\UltimateContext
2008-09-01 12:15 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-31 05:50 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-31 05:45 --------- d-----w C:\Program Files\Azureus
2008-08-30 18:54 --------- d-----w C:\Program Files\LimeWire
2008-08-30 18:13 --------- d-----w C:\Program Files\AGEIA Technologies
2008-08-30 18:12 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-30 17:56 --------- d-----w C:\Users\Nicolas\AppData\Roaming\Azureus
2008-08-30 12:28 --------- d-----w C:\PROGRA~2\Azureus
2008-08-30 11:44 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-27 21:03 42,320 ----a-w C:\Windows\System32\xfcodec.dll
2008-08-13 09:15 --------- d-----w C:\Program Files\Windows Mail
2008-08-10 17:44 1,666,560 ----a-w C:\Windows\Internet Logs\xDBB3A5.tmp
2008-08-08 15:30 --------- d-----w C:\PROGRA~2\TrackMania
2008-08-08 09:03 --------- d-----w C:\Program Files\Google
2008-08-06 15:20 --------- d-----w C:\Program Files\Game Cam V2
2008-08-05 12:14 --------- d-----w C:\Program Files\ModernRcon
2008-08-03 10:37 22,328 ----a-w C:\Users\Nicolas\AppData\Roaming\PnkBstrK.sys
2008-08-03 10:36 669,184 ----a-w C:\Windows\System32\pbsvc.exe
2008-08-02 09:59 --------- d-----w C:\Program Files\RconMax(MW)
2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
2008-08-02 01:01 625,152 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-31 01:13 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-07-24 16:17 --------- d-----w C:\Program Files\AdvancedTool
2008-07-24 14:27 304,528 ----a-w C:\Windows\System32\appdrvrem01.exe
2008-07-24 14:27 2,915,944 ----a-w C:\Windows\system32\drivers\appdrv01.sys
2008-07-24 11:25 --------- d-----w C:\Program Files\Cyanide
2008-07-24 09:29 --------- d-----w C:\Program Files\Nouveau dossier
2008-07-23 21:53 --------- d-----w C:\Users\Nicolas\AppData\Roaming\Pro Cycling Manager 2008 - Demo
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-06-26 03:29 801,280 ----a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 03:29 565,248 ----a-w C:\Windows\System32\emdmgmt.dll
2008-06-26 03:29 45,056 ----a-w C:\Windows\System32\dataclen.dll
2008-06-26 03:29 303,616 ----a-w C:\Windows\System32\wmpeffects.dll
2008-06-26 01:45 2,644,480 ----a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 ----a-w C:\Windows\System32\NlsLexicons0007.dll
2008-04-02 17:12 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“MsnMsgr”=“C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” [2007-10-18 5724184]
“ehTray.exe”=“C:\Windows\ehome\ehTray.exe” [2008-01-18 125952]
“Steam”=“c:\program files\steam\steam.exe” [2008-04-07 1271032]
“Sidebar”=“C:\Program Files\Windows Sidebar\sidebar.exe” [2008-01-18 1233920]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“avgnt”=“C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe” [2008-07-18 266497]
“LifeCam”=“C:\Program Files\Microsoft LifeCam\LifeExp.exe” [2007-05-17 279912]
“VX6000”=“C:\Windows\vVX6000.exe” [2007-04-10 996712]
“Start WingMan Profiler”=“C:\Program Files\Logitech\Gaming Software\LWEMon.exe” [2007-09-25 93208]
“SoundMAXPnP”=“C:\Program Files\Analog Devices\Core\smax4pnp.exe” [2006-12-18 868352]
“ZoneAlarm Client”=“C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe” [2008-03-03 959976]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe” [2008-06-10 144784]
“NvSvc”=“C:\Windows\system32\nvsvc.dll” [2007-11-06 86016]
“NvCplDaemon”=“C:\Windows\system32\NvCpl.dll” [2007-11-06 8530464]
“NvMediaCenter”=“C:\Windows\system32\NvMcTray.dll” [2007-11-06 81920]
“WireLessMouse”=“C:\Program Files\Lightmouse II\StartAutorun.exe” [2005-11-30 94208]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2008-06-12 34672]
“Kernel and Hardware Abstraction Layer”=“KHALMNPR.EXE” [2007-11-29 C:\Windows\KHALMNPR.Exe]
C:\Users\Nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
Secunia PSI (RC3).lnk - C:\Program Files\Secunia\PSI (RC3)\psi.exe [2008-06-16 663552]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup
Outil de mise
jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-17 124400]
C:\Users\Nicolas\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
Secunia PSI (RC3).lnk - C:\Program Files\Secunia\PSI (RC3)\psi.exe [2008-06-16 663552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.XFR1”= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
“{C7670340-25B7-4D1E-8A10-544721A96139}”= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
“{E165C582-D7A5-4ED8-A683-BA920827C36A}”= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
“{5AA0FFE9-731A-42FB-B33B-38E4B642C4C4}”= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
“{87E7E6BF-8406-4FD7-B682-E846EBB8020E}”= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
“{3D4E5354-90E4-4E60-A4CE-E0BCB173D4B5}”= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
“{9978D988-A413-4F5A-8DA9-92CC77F82072}”= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
“{BAC91697-4D3C-4CA5-9F73-6DA5E81CED29}”= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
“{A58A619B-27DA-4304-ADE5-BA769F1EBF77}”= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
“{5FABBAFB-7DA6-4234-B89E-FCD08D3B25F2}”= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
“{C59082D9-1621-4DE1-8F6F-F2AEB788954D}”= UDP:D:\Jeux\COD4\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
“{77C3D386-837E-4A69-953B-51ACD3AF9DAD}”= TCP:D:\Jeux\COD4\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
“{9C75A874-B688-4F87-BC3C-111423BB2B83}”= UDP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
“{376BC8E9-6234-4C4C-AE5B-577E931BDDB1}”= TCP:C:\Program Files\Cyanide\GameCenter\GameCenter.exe:GameCenter
“{2A576138-2286-4E23-9237-765798FEB453}”= UDP:C:\Program Files\Cyanide\Pro Cycling Manager - Season 2008\PCM.exe:Pro Cycling Manager - Season 2008
“{39AEC6BF-F662-4720-8ED2-260D2679951B}”= TCP:C:\Program Files\Cyanide\Pro Cycling Manager - Season 2008\PCM.exe:Pro Cycling Manager - Season 2008
“{E48196D9-6D5F-4F9D-90EA-FBACFCAB9B17}”= UDP:C:\Program Files\Cyanide\Pro Cycling Manager - Season 2008\Autorun\Exe\Autorun.exe:Pro Cycling Manager - Season 2008 - AutoRun
“{39B4689D-999A-4F4E-B08F-F0028B4A3709}”= TCP:C:\Program Files\Cyanide\Pro Cycling Manager - Season 2008\Autorun\Exe\Autorun.exe:Pro Cycling Manager - Season 2008 - AutoRun
“{0C3BBBE5-B31D-40CC-8607-1C1E22B75BDE}”= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
“{C277E714-4E36-4652-A7B5-14E5054381CA}”= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
“{A8C93584-2702-4B7B-9DB0-5EAC016AC52B}”= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
“{11209661-B94E-4DD4-9CB8-B2B50F9BD742}”= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
“{C63444B5-41F4-4987-AAF4-44DDA386FF3F}”= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
“{F4E81A84-BB2A-451E-8164-23A0AFFB007B}”= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
[HKLM~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
“EnableFirewall”= 0 (0x0)
S1 appdrv01;Application Driver (01);C:\Windows\system32\Drivers\appdrv01.sys [2008-07-24 2915944]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2006-11-15 48128]
S3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys [2008-06-16 7808]
S3 VX6000;Microsoft LifeCam VX-6000;C:\Windows\system32\DRIVERS\VX6000Xp.sys [2007-04-10 2385896]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{4de615f7-000f-11dd-8e59-806e6f6e6963}]
\shell\AutoRun\command - E:\AutoRunCD.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{7c57d22c-383f-11dd-a05e-001a92b6e459}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\demarrer.html
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{e62a88e0-49a7-11dd-b086-001a92b6e459}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\demarrer.html
Newly Created Service - CATCHME
Newly Created Service - ECACHE
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Nicolas\AppData\Roaming\Mozilla\Firefox\Profiles\9bln5e7f.default
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.fr…
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1172.2021\npCIDetect11.dll
.
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-09-20 08:35:23
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés …
Balayage caché autostart entries …
Balayage des fichiers cachés …
Scan terminé avec succès
Les fichiers cachés: 0
.
Temps d’accomplissement: 2008-09-20 8:38:13
ComboFix-quarantined-files.txt 2008-09-20 06:37:55
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 53,447,372,800 octets libres
202 — E O F — 2008-09-19 19:55:06