ComboFix 09-11-20.02 - tibo 21/11/2009 10:21.4.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.767.526 [GMT 1:00]
Lancé depuis: c:\documents and settings\tibo\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\tibo\Bureau\CFscript.txt
* Un nouveau point de restauration a été créé
FILE ::
"c:\windows\system32\drivers\fipjkj.sys"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\pciide.sys
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ABP470N5
-------\Service_abp470n5
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-21 au 2009-11-21 ))))))))))))))))))))))))))))))))))))
.
2009-11-19 15:41 . 2009-11-19 15:44 -------- d-----w- c:\program files\eMule
2009-11-16 23:37 . 2009-11-16 23:37 -------- d-----w- c:\documents and settings\tibo\DoctorWeb
2009-11-14 22:28 . 2009-11-14 22:28 -------- d--h--w- c:\windows\PIF
2009-11-13 16:35 . 2009-11-13 16:37 -------- d-----w- C:\Fichiers Internet temporaires
2009-11-11 23:18 . 2009-11-11 23:18 1174 ----a-w- c:\windows\mozver.dat
2009-11-11 15:30 . 2009-11-11 15:30 -------- d-----w- c:\program files\NirSoft
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\documents and settings\tibo\Application Data\Talkback
2009-11-10 22:25 . 2009-11-10 22:25 0 ----a-w- c:\windows\nsreg.dat
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\documents and settings\tibo\Local Settings\Application Data\Mozilla
2009-11-06 14:52 . 2009-11-06 14:52 -------- d-----w- c:\program files\Trend Micro
2009-10-31 10:16 . 2009-10-31 10:16 -------- d-----w- c:\documents and settings\tibo\Application Data\dvdcss
2009-10-22 21:03 . 2009-11-14 14:48 -------- d-----w- c:\program files\QuickMediaConverter
2009-10-22 15:07 . 2009-10-22 15:07 -------- d-----w- c:\documents and settings\tibo\Application Data\Malwarebytes
2009-10-22 15:07 . 2009-10-22 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-20 23:00 . 2009-10-11 00:59 -------- d-----w- c:\program files\PokerStars
2009-10-29 12:05 . 2001-08-28 12:00 48856 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-29 12:05 . 2001-08-28 12:00 368076 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-28 16:17 . 2009-10-09 22:32 -------- d-----w- c:\documents and settings\tibo\Application Data\Winamp
2009-10-15 14:02 . 2009-10-15 14:02 -------- d-----w- c:\documents and settings\tibo\Application Data\Ahead
2009-10-15 13:41 . 2009-10-15 13:41 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-10-15 13:41 . 2009-10-15 13:41 -------- d-----w- c:\program files\Ahead
2009-10-09 23:48 . 2009-10-09 22:00 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-09 23:21 . 2009-10-09 23:00 -------- d-----w- c:\documents and settings\tibo\Application Data\vlc
2009-10-09 22:53 . 2009-10-09 22:53 -------- d-----w- c:\documents and settings\tibo\Application Data\Media Player Classic
2009-10-09 22:52 . 2009-10-09 22:21 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-09 22:34 . 2009-10-09 22:25 12912 ----a-w- c:\documents and settings\tibo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-09 22:33 . 2009-10-09 22:33 -------- d-----w- c:\program files\Microsoft
2009-10-09 22:33 . 2009-10-09 22:32 -------- d-----w- c:\program files\Windows Live
2009-10-09 22:33 . 2009-10-09 22:33 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-09 22:31 . 2009-10-09 22:31 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-10-09 22:27 . 2009-10-09 22:26 -------- d-----w- c:\program files\Wanadoo
2009-10-09 22:23 . 2009-10-09 22:23 -------- d-----w- c:\program files\Securitoo
2009-10-09 22:22 . 2009-10-09 22:22 -------- d-----w- c:\program files\Inventel
2009-10-09 22:03 . 2009-10-09 22:03 -------- d-----w- c:\program files\microsoft frontpage
2009-10-09 21:59 . 2009-10-09 21:59 -------- d-----w- c:\program files\Services en ligne
2009-10-09 21:57 . 2009-10-09 21:57 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-09 21:57 . 2009-10-09 21:57 -------- d-----w- c:\program files\Windows Media Connect 2
.
------- Sigcheck -------
[-] 2008-05-09 . 33578A738C564B4F84D906EFD91025E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-07_16.25.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-21 09:27 . 2009-11-21 09:27 16384 c:\windows\temp\Perflib_Perfdata_f8.dat
+ 2009-11-21 09:22 . 2009-11-21 09:22 16384 c:\windows\temp\Perflib_Perfdata_1560.dat
+ 2001-08-28 12:00 . 2001-08-23 16:15 3328 c:\windows\system32\dllcache\pciide.sys
+ 2009-10-15 13:41 . 2001-07-09 09:50 233472 c:\windows\system32\NeroCheck.exe
+ 2009-11-11 23:18 . 2009-07-17 19:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2008-04-13 09:53 . 2008-04-13 09:53 558080 c:\windows\Network Diagnostic\xpnetdiag.exe
+ 2009-11-11 23:18 . 2009-07-17 19:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1900032]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 4031312]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2009-02-22 5668864]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 233472]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ a\0u\0t\0o\0c\0h\0e\0c\0k\0 \0a\0u\0t\0o\0c\0h\0k\0 \0*\0\0\0
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\utiles\\winamp5541_full_emusic-7plus_fr-fr.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\eMule\\eMule.exe"=
"g:\\programmes\\Winamp\\winamp.exe"=
"e:\\utiles\\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\\Nero60011.exe"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"c:\\Program Files\\Windows Live\\Contacts\\wlcomm.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\cmd.exe"=
"e:\\utiles\\eMule0.47a-Installer.exe"=
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - ABP470N5
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/FF - ProfilePath - c:\documents and settings\tibo\Application Data\Mozilla\Firefox\Profiles\21vgznsa.default\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-21 10:27
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1444)
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\docume~1\tibo\LOCALS~1\Temp\tscm.exe
.
**************************************************************************
.
Heure de fin: 2009-11-21 10:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-21 09:30
ComboFix2.txt 2009-11-19 15:34
ComboFix3.txt 2009-11-11 23:14
ComboFix4.txt 2009-11-07 16:28
Avant-CF: 7 081 328 640 octets libres
Après-CF: 7 029 452 800 octets libres
- - End Of File - - BAE3216118FEFECDA3EE43C1BE175407