bonsoir voila le rapport
ComboFix 09-11-11.02 - tibo 12/11/2009 0:06.2.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.767.573 [GMT 1:00]
Lancé depuis: c:\documents and settings\tibo\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\tibo\Bureau\CFscript.txt
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wmdrtc32.dl_
c:\windows\system32\wmdrtc32.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ABP470N5
-------\Legacy_NDISFILESERVICES32
-------\Service_abp470n5
-------\Service_NdisFileServices32
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-11 au 2009-11-11 ))))))))))))))))))))))))))))))))))))
.
2009-11-11 15:30 . 2009-11-11 15:30 -------- d-----w- c:\program files\NirSoft
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\documents and settings\tibo\Application Data\Talkback
2009-11-10 22:25 . 2009-11-10 22:25 0 ----a-w- c:\windows\nsreg.dat
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\documents and settings\tibo\Local Settings\Application Data\Mozilla
2009-11-06 14:52 . 2009-11-06 14:52 -------- d-----w- c:\program files\Trend Micro
2009-10-31 10:16 . 2009-10-31 10:16 -------- d-----w- c:\documents and settings\tibo\Application Data\dvdcss
2009-10-23 23:22 . 2009-11-11 20:31 -------- d-----w- c:\program files\Crawler
2009-10-22 21:03 . 2009-11-10 10:50 -------- d-----w- c:\program files\QuickMediaConverter
2009-10-22 16:37 . 2009-10-23 23:40 40960 ----a-w- c:\windows\system32\wmdrtc32.dll.ren
2009-10-22 15:07 . 2009-10-22 15:07 -------- d-----w- c:\documents and settings\tibo\Application Data\Malwarebytes
2009-10-22 15:07 . 2009-10-22 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-15 14:02 . 2009-10-15 14:02 -------- d-----w- c:\documents and settings\tibo\Local Settings\Application Data\WMTools Downloaded Files
2009-10-15 14:02 . 2009-10-15 14:02 -------- d-----w- c:\documents and settings\tibo\Application Data\Ahead
2009-10-15 13:42 . 2003-03-29 14:45 89184 ----a-w- c:\windows\system32\drivers\imagedrv.sys
2009-10-15 13:41 . 2001-07-06 16:24 283920 ----a-w- c:\windows\system32\ImagXpr5.dll
2009-10-15 13:41 . 2001-07-06 12:41 569344 ----a-w- c:\windows\system32\imagr5.dll
2009-10-15 13:41 . 2001-07-06 10:44 544768 ----a-w- c:\windows\system32\imagx5.dll
2009-10-15 13:41 . 2001-06-26 06:15 38912 ----a-w- c:\windows\system32\picn20.dll
2009-10-15 13:41 . 2009-10-15 13:41 -------- d-----w- c:\program files\Fichiers communs\Ahead
2009-10-15 13:41 . 2001-07-09 09:50 253952 ----a-w- c:\windows\system32\NeroCheck.exe
2009-10-15 13:41 . 2009-10-15 13:41 -------- d-----w- c:\program files\Ahead
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-11 23:13 . 2009-10-10 14:23 5477 ----a-w- c:\windows\system32\drivers\njjlmn.sys
2009-11-10 21:50 . 2009-10-11 00:59 -------- d-----w- c:\program files\PokerStars
2009-10-29 12:05 . 2001-08-28 12:00 48856 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-29 12:05 . 2001-08-28 12:00 368076 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-28 16:17 . 2009-10-09 22:32 -------- d-----w- c:\documents and settings\tibo\Application Data\Winamp
2009-10-09 23:48 . 2009-10-09 22:00 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-09 23:21 . 2009-10-09 23:00 -------- d-----w- c:\documents and settings\tibo\Application Data\vlc
2009-10-09 22:53 . 2009-10-09 22:53 -------- d-----w- c:\documents and settings\tibo\Application Data\Media Player Classic
2009-10-09 22:52 . 2009-10-09 22:21 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-10-09 22:34 . 2009-10-09 22:25 12912 ----a-w- c:\documents and settings\tibo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-09 22:33 . 2009-10-09 22:33 -------- d-----w- c:\program files\Microsoft
2009-10-09 22:33 . 2009-10-09 22:32 -------- d-----w- c:\program files\Windows Live
2009-10-09 22:33 . 2009-10-09 22:33 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-09 22:31 . 2009-10-09 22:31 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-10-09 22:27 . 2009-10-09 22:26 -------- d-----w- c:\program files\Wanadoo
2009-10-09 22:23 . 2009-10-09 22:23 -------- d-----w- c:\program files\Securitoo
2009-10-09 22:22 . 2009-10-09 22:22 -------- d-----w- c:\program files\Inventel
2009-10-09 22:03 . 2009-10-09 22:03 -------- d-----w- c:\program files\microsoft frontpage
2009-10-09 21:59 . 2009-10-09 21:59 -------- d-----w- c:\program files\Services en ligne
2009-10-09 21:57 . 2009-10-09 21:57 21892 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-09 21:57 . 2009-10-09 21:57 -------- d-----w- c:\program files\Windows Media Connect 2
2008-12-17 23:04 . 2009-11-10 22:24 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-17 23:04 . 2009-11-10 22:24 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-17 23:04 . 2009-11-10 22:24 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-17 23:04 . 2009-11-10 22:24 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-17 23:04 . 2009-11-10 22:24 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
[-] 2008-05-09 . 33578A738C564B4F84D906EFD91025E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-07_16.25.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-11 23:11 . 2009-11-11 23:11 16384 c:\windows\Temp\Perflib_Perfdata_644.dat
+ 2009-11-11 23:05 . 2009-11-11 23:05 16384 c:\windows\Temp\Perflib_Perfdata_258.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1900032]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3957584]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 253952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.exe \??\c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.dat
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\utiles\\winamp5541_full_emusic-7plus_fr-fr.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\eMule\\eMule.exe"=
"g:\\programmes\\Winamp\\winamp.exe"=
"e:\\utiles\\Nero 6.0.0.11 Full FR + Keygen + adon+ All plugin\\Nero60011.exe"=
"c:\\WINDOWS\\system32\\NeroCheck.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"c:\\Program Files\\Windows Live\\Contacts\\wlcomm.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\cmd.exe"=
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mbr
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/FF - ProfilePath - c:\documents and settings\tibo\Application Data\Mozilla\Firefox\Profiles\21vgznsa.default\
FF - prefs.js: browser.search.selectedEngine - Crawler Search
FF - prefs.js: keyword.URL -
hxxp://www.crawler.com/search/dispatche ... 60341&qkw=FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-12 00:11
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3060)
c:\windows\system32\wmdrtc32.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Heure de fin: 2009-11-11 0:14 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-11 23:14
ComboFix2.txt 2009-11-07 16:28
Avant-CF: 6 924 980 224 octets libres
Après-CF: 6 902 972 416 octets libres
- - End Of File - - 2CA96E8DEFF47B4DC629BD2E56D033E3