Voila le rapport combofixComboFix 09-03-06.02 - Johan 2009-03-09 13:43:21.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2045.1299 [GMT 1:00]
Lancé depuis: c:\users\Johan\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\Johan\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Un nouveau point de restauration a été créé
FILE ::
c:\users\Johan\AppData\Local\Temp\csrssc.exe
c:\users\Johan\AppData\Local\Temp\winlognn.exe
c:\windows\System32\drivers\~GLH0014.TMP
c:\windows\system32\drivers\senekapjebqhgc.sys
c:\windows\System32\drivers\tcpsr.sys
c:\windows\system32\tmp.txt
E:\Install.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\drivers\~GLH0014.TMP
c:\windows\system32\tmp.txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-09 au 2009-03-09 ))))))))))))))))))))))))))))))))))))
.
2009-03-07 18:40 . 2009-03-07 18:40 <REP> d-------- c:\users\Johan\AppData\Roaming\TuneUp Software
2009-03-07 18:40 . 2009-03-07 18:40 603,904 --a------ c:\windows\System32\TUProgSt.exe
2009-03-07 18:40 . 2009-03-07 18:40 360,192 --a------ c:\windows\System32\TuneUpDefragService.exe
2009-03-07 18:40 . 2008-12-11 13:31 27,904 --a------ c:\windows\System32\uxtuneup.dll
2009-03-07 18:40 . 2008-12-11 13:31 17,152 --a------ c:\windows\System32\authuitu.dll
2009-03-07 18:38 . 2009-03-07 18:38 <REP> d-------- c:\users\All Users\TuneUp Software
2009-03-07 18:38 . 2009-03-07 18:38 <REP> d-------- c:\programdata\TuneUp Software
2009-03-07 18:38 . 2009-03-07 18:40 <REP> d-------- c:\program files\TuneUp Utilities 2009
2009-03-07 18:37 . 2009-03-07 18:37 <REP> d--hs---- c:\users\All Users\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 18:37 . 2009-03-07 18:37 <REP> d--hs---- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-07 10:19 . 2009-03-07 10:19 <REP> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-03-06 23:58 . 2009-03-06 23:58 <REP> d-------- c:\program files\DAEMON Tools Lite
2009-03-06 21:52 . 2009-03-06 21:52 <REP> d-------- c:\users\Johan\AppData\Roaming\Creative
2009-03-06 20:43 . 2009-03-06 20:43 <REP> d-------- c:\program files\Creative
2009-03-06 20:07 . 2009-03-06 20:07 <REP> d-------- c:\users\All Users\PY_Software
2009-03-06 20:07 . 2009-03-06 20:07 <REP> d-------- c:\programdata\PY_Software
2009-03-06 20:07 . 2009-03-06 20:09 <REP> d-------- c:\program files\Active WebCam
2009-03-06 20:07 . 2007-08-13 14:51 446,464 --a------ c:\windows\System32\wmvdmoe.dll
2009-03-06 19:04 . 2009-03-06 19:04 <REP> d-------- c:\program files\Phantombility
2009-03-04 20:31 . 2009-03-04 20:31 <REP> d-------- c:\windows\System32\Kaspersky Lab
2009-03-04 19:41 . 2009-03-05 16:47 <REP> d-------- C:\ToolBar SD
2009-03-04 18:47 . 2009-03-04 18:48 <REP> d-------- c:\program files\CCleaner
2009-03-04 15:42 . 2009-03-04 15:42 <REP> d-------- c:\users\Johan\AppData\Roaming\Malwarebytes
2009-03-04 15:42 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-03-04 15:41 . 2009-03-04 15:41 <REP> d-------- c:\users\All Users\Malwarebytes
2009-03-04 15:41 . 2009-03-04 15:41 <REP> d-------- c:\programdata\Malwarebytes
2009-03-04 15:41 . 2009-03-04 15:42 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-04 15:41 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-04 14:24 . 2009-03-04 14:25 <REP> d-------- C:\rsit
2009-03-04 14:24 . 2009-03-04 21:29 <REP> d-------- c:\program files\trend micro
2009-03-03 18:16 . 2009-03-03 18:18 <REP> d-------- c:\users\All Users\Lavasoft
2009-03-03 18:16 . 2009-03-03 18:18 <REP> d-------- c:\programdata\Lavasoft
2009-03-03 18:16 . 2009-03-03 18:16 <REP> d-------- c:\program files\Lavasoft
2009-03-03 18:14 . 2009-03-03 18:14 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-03 12:19 . 2009-03-03 12:19 <REP> d-------- c:\program files\MSXML 4.0
2009-03-02 13:23 . 2009-03-02 13:26 <REP> d-------- c:\windows\System32\Samsung_USB_Drivers
2009-03-02 13:23 . 2005-08-28 20:51 766 --a------ c:\windows\System32\Uninstall.ico
2009-03-02 13:22 . 2009-03-02 13:22 <REP> d-------- c:\program files\Samsung
2009-03-02 13:22 . 2009-03-02 13:49 5,632 --a------ c:\windows\System32\drivers\StarOpen.sys
2009-03-02 02:20 . 2009-03-02 02:20 <REP> d-------- c:\program files\Microsoft Silverlight
2009-03-02 02:17 . 2008-12-16 04:29 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2009-03-02 02:17 . 2008-12-16 06:31 7,680 --a------ c:\windows\System32\spwmp.dll
2009-03-02 02:17 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\msdxm.ocx
2009-03-02 02:17 . 2008-12-16 06:31 4,096 --a------ c:\windows\System32\dxmasf.dll
2009-03-02 01:57 . 2009-03-02 02:15 <REP> d-------- c:\windows\System32\NtmsData
2009-03-01 22:52 . 2009-03-09 11:59 <REP> d-------- c:\users\Johan\AppData\Roaming\Azureus
2009-03-01 22:52 . 2009-03-01 22:52 <REP> d-------- c:\users\All Users\Azureus
2009-03-01 22:52 . 2009-03-01 22:52 <REP> d-------- c:\programdata\Azureus
2009-03-01 22:51 . 2009-03-01 22:52 <REP> d-------- c:\program files\Vuze
2009-03-01 21:41 . 2009-03-02 03:09 <REP> d-------- c:\users\Johan\AppData\Roaming\uTorrent
2009-03-01 19:45 . 2009-03-01 19:48 691 --a------ c:\users\Johan\AppData\Roaming\GetValue.vbs
2009-03-01 19:45 . 2009-03-01 19:48 35 --a------ c:\users\Johan\AppData\Roaming\SetValue.bat
2009-02-28 17:12 . 2009-02-28 17:12 <REP> d-------- c:\program files\DNA
2009-02-28 17:12 . 2009-02-28 17:12 <REP> d-------- c:\program files\BitTorrent
2009-02-27 18:39 . 2009-03-01 00:33 <REP> d-------- C:\Downloads
2009-02-27 16:33 . 2009-02-27 18:18 <REP> d-------- c:\users\All Users\Retrospect
2009-02-27 16:33 . 2009-02-27 18:18 <REP> d-------- c:\programdata\Retrospect
2009-02-27 15:15 . 2008-03-03 15:05 54,672 --a------ c:\windows\System32\vsutil_loc040c.dll
2009-02-27 15:15 . 2009-02-27 15:15 5,571 --a------ c:\windows\System32\vsconfig.xml
2009-02-27 15:14 . 2009-02-27 15:14 <REP> d-------- c:\users\All Users\CheckPoint
2009-02-27 15:14 . 2009-02-27 15:14 <REP> d-------- c:\programdata\CheckPoint
2009-02-27 15:14 . 2009-02-27 15:14 <REP> d-------- c:\program files\Zone Labs
2009-02-27 15:14 . 2008-03-03 15:05 1,086,952 --a------ c:\windows\System32\zpeng24.dll
2009-02-27 15:13 . 2009-02-27 15:15 <REP> d-------- c:\windows\System32\ZoneLabs
2009-02-27 15:13 . 2009-03-09 13:47 352,615 --ah----- c:\windows\System32\drivers\vsconfig.xml
2009-02-27 15:13 . 2008-03-03 15:06 279,440 --------- c:\windows\System32\drivers\vsdatant.sys
2009-02-27 15:11 . 2009-03-09 13:47 <REP> d-------- c:\windows\Internet Logs
2009-02-25 17:07 . 2009-02-25 17:07 0 --a------ c:\windows\nsreg.dat
2009-02-25 16:07 . 2009-02-25 16:07 <REP> d-------- c:\windows\System32\Dell
2009-02-25 16:01 . 2009-02-25 16:01 <REP> d-------- c:\windows\McAfee.com
2009-02-25 15:46 . 2009-02-25 15:48 <REP> d-------- c:\users\Johan\.housecall6.6
2009-02-25 15:38 . 2009-02-25 15:38 <REP> d-------- c:\program files\Java
2009-02-23 22:22 . 2009-02-23 22:22 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-02-23 18:05 . 2009-02-23 18:05 1,409 --a------ c:\windows\System32\tmp6AF68.FOT
2009-02-23 18:05 . 2009-02-23 18:05 1,409 --a------ c:\windows\System32\tmp32078.FOT
2009-02-23 14:27 . 2009-02-23 14:27 <REP> d-------- c:\users\Johan\AppData\Roaming\Leadertech
2009-02-23 14:27 . 2009-02-23 14:27 <REP> d-------- c:\program files\Iomega
2009-02-19 19:01 . 2008-06-20 02:14 781,344 --a------ c:\windows\System32\PresentationNative_v0300.dll
2009-02-19 19:01 . 2008-06-20 02:14 622,080 --a------ c:\windows\System32\icardagt.exe
2009-02-19 19:01 . 2008-06-20 02:14 326,160 --a------ c:\windows\System32\PresentationHost.exe
2009-02-19 19:01 . 2008-06-20 02:14 105,016 --a------ c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-02-19 19:01 . 2008-06-20 02:14 97,800 --a------ c:\windows\System32\infocardapi.dll
2009-02-19 19:01 . 2008-06-20 02:14 43,544 --a------ c:\windows\System32\PresentationHostProxy.dll
2009-02-19 19:01 . 2008-06-20 02:14 37,384 --a------ c:\windows\System32\infocardcpl.cpl
2009-02-19 19:01 . 2008-06-20 02:14 11,264 --a------ c:\windows\System32\icardres.dll
2009-02-19 18:52 . 2008-07-27 19:03 282,112 --a------ c:\windows\System32\mscoree.dll
2009-02-19 18:52 . 2008-07-27 19:03 96,760 --a------ c:\windows\System32\dfshim.dll
2009-02-19 18:52 . 2008-07-27 19:03 41,984 --a------ c:\windows\System32\netfxperf.dll
2009-02-19 18:51 . 2008-07-27 19:03 158,720 --a------ c:\windows\System32\mscorier.dll
2009-02-19 18:51 . 2008-07-27 19:03 83,968 --a------ c:\windows\System32\mscories.dll
2009-02-19 18:40 . 2009-02-19 19:17 196,608 --a------ c:\windows\SPInstall.etl
2009-02-19 13:17 . 2009-03-01 19:47 <REP> d-------- c:\program files\Windows Live Safety Center
2009-02-19 12:43 . 2009-02-19 12:43 <REP> d-------- C:\inetpub
2009-02-17 22:11 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2009-02-17 22:02 . 2009-02-17 22:02 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-17 19:57 . 2009-02-17 19:57 <REP> d-------- C:\PerfLogs
2009-02-17 15:08 . 2009-01-23 21:20 9,728 --a------ c:\users\Johan\AppData\Roaming\auserv.exe
2009-02-17 15:08 . 2009-02-17 15:08 74 --a------ c:\program files\inc1.bat
2009-02-17 15:08 . 2009-02-17 15:08 41 --a------ c:\program files\sleep.bat
2009-02-17 12:38 . 2009-02-20 00:10 <REP> d-------- c:\users\Johan\AppData\Roaming\com.zipeg
2009-02-17 12:38 . 2009-02-17 12:38 <REP> d-------- c:\program files\Zipeg
2009-02-15 00:41 . 2009-03-07 00:47 <REP> d-------- c:\users\All Users\eMule
2009-02-15 00:41 . 2009-03-07 00:47 <REP> d-------- c:\programdata\eMule
2009-02-11 23:01 . 2008-12-05 05:32 428,544 --a------ c:\windows\System32\EncDec.dll
2009-02-11 23:01 . 2008-12-05 05:32 293,376 --a------ c:\windows\System32\psisdecd.dll
2009-02-11 23:01 . 2008-12-05 05:31 217,088 --a------ c:\windows\System32\psisrndr.ax
2009-02-11 23:01 . 2008-12-05 05:31 177,664 --a------ c:\windows\System32\mpg2splt.ax
2009-02-11 23:01 . 2008-12-05 05:31 80,896 --a------ c:\windows\System32\MSNP.ax
2009-02-11 03:48 . 2009-01-15 04:36 1,383,424 --a------ c:\windows\System32\mshtml.tlb
2009-02-11 03:48 . 2009-01-15 07:11 827,392 --a------ c:\windows\System32\wininet.dll
2009-02-09 12:36 . 2009-02-09 12:36 <REP> d-------- c:\program files\Microsoft Works
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-09 12:46 27,839 ----a-w c:\users\All Users\nvModes.dat
2009-03-09 12:46 27,839 ----a-w c:\programdata\nvModes.dat
2009-03-09 12:45 4,412,648 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-09 12:45 332,389,152 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-09 12:31 --------- d-----w c:\programdata\Kaspersky Lab
2009-03-09 00:02 --------- d-----w c:\program files\Steam
2009-03-07 21:40 --------- d-----w c:\program files\Common Files\Steam
2009-03-06 23:47 --------- d-----w c:\program files\eMule
2009-03-06 23:43 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-06 23:43 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-06 22:42 --------- d-----w c:\program files\Ubisoft
2009-03-06 19:43 --------- d-----w c:\program files\Dell
2009-03-06 08:40 316,882,976 --sha-w c:\windows\system32\drivers\fidbox(40).dat
2009-03-02 12:20 --------- d-----w c:\program files\Common Files\Adobe
2009-03-01 21:45 --------- d-----w c:\program files\BitComet
2009-02-28 15:49 --------- d-----w c:\programdata\Apple Computer
2009-02-28 15:49 --------- d-----w c:\program files\iTunes
2009-02-28 15:49 --------- d-----w c:\program files\iPod
2009-02-28 10:42 101,654 ----a-w c:\windows\Internet Logs\vsmon_2nd_2009_02_28_06_41_10_small.dmp.zip
2009-02-28 10:37 173,034 ----a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-25 17:48 --------- d-----w c:\program files\TF1Vision
2009-02-25 17:47 --------- d-----w c:\program files\CDBurnerXP
2009-02-25 17:46 --------- d-----w c:\programdata\Droppix
2009-02-25 14:38 410,984 ----a-w c:\windows\System32\deploytk.dll
2009-02-19 10:36 --------- d-----w c:\program files\Windows Sidebar
2009-02-19 10:36 --------- d-----w c:\program files\Windows Photo Gallery
2009-02-19 10:36 --------- d-----w c:\program files\Windows Mail
2009-02-19 10:36 --------- d-----w c:\program files\Windows Journal
2009-02-19 10:36 --------- d-----w c:\program files\Windows Defender
2009-02-19 10:36 --------- d-----w c:\program files\Windows Collaboration
2009-02-19 10:36 --------- d-----w c:\program files\Windows Calendar
2009-02-19 10:36 --------- d-----w c:\program files\DellTPad
2009-02-17 19:16 174 --sha-w c:\program files\desktop.ini
2009-02-17 18:41 82,432 ----a-w c:\windows\System32\axaltocm.dll
2009-02-17 18:41 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2009-02-13 10:10 --------- d-----w c:\users\Johan\AppData\Roaming\U3
2009-02-06 20:59 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-06 20:59 22,328 ----a-w c:\users\Johan\AppData\Roaming\PnkBstrK.sys
2009-02-06 20:59 107,832 ----a-w c:\windows\System32\PnkBstrB.exe
2009-02-06 20:58 66,872 ----a-w c:\windows\System32\PnkBstrA.exe
2009-02-06 20:58 2,250,024 ----a-w c:\windows\System32\pbsvc.exe
2009-02-06 17:52 49,504 ----a-w c:\windows\System32\sirenacm.dll
2009-02-05 16:22 --------- d-----w c:\program files\Electronic Arts
2009-02-04 20:28 107,888 ----a-w c:\windows\System32\CmdLineExt.dll
2009-02-03 17:18 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 17:18 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-01-26 14:28 --------- d-----w c:\users\Johan\AppData\Roaming\LimeWire
2009-01-11 18:06 --------- d---a-w c:\programdata\TEMP
2009-01-11 11:17 --------- d--h--r c:\users\Johan\AppData\Roaming\SecuROM
2009-01-10 15:51 --------- d-----w c:\users\Johan\AppData\Roaming\TigerPlayer
2009-01-10 15:49 --------- d-----w c:\program files\MpcStar
2009-01-09 18:35 --------- d-----w c:\program files\LucasArts
2008-12-19 23:40 61,440 ----a-w c:\windows\System32\winipsec.dll
2008-12-19 23:40 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2008-12-19 23:40 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2008-12-19 23:40 272,896 ----a-w c:\windows\System32\polstore.dll
2008-12-19 23:39 94,720 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-12-19 23:39 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-12-19 23:39 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-12-19 23:31 269,312 ----a-w c:\windows\System32\es.dll
2008-12-19 23:27 988,216 ----a-w c:\windows\System32\winload.exe
2008-12-19 23:27 927,288 ----a-w c:\windows\System32\winresume.exe
2008-12-19 23:27 615,992 ----a-w c:\windows\System32\ci.dll
2008-12-19 23:27 6,656 ----a-w c:\windows\System32\kbd106n.dll
2008-12-19 23:27 46,592 ----a-w c:\windows\System32\setbcdlocale.dll
2008-12-19 23:27 40,960 ----a-w c:\windows\System32\srclient.dll
2008-12-19 23:27 378,368 ----a-w c:\windows\System32\srcore.dll
2008-12-19 23:27 318,464 ----a-w c:\windows\System32\rstrui.exe
2008-12-19 23:27 19,000 ----a-w c:\windows\System32\kd1394.dll
2008-12-19 23:27 14,848 ----a-w c:\windows\System32\srdelayed.exe
2008-12-18 23:09 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-12-18 23:04 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-12-18 23:04 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-12-18 23:04 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-18 23:04 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-18 23:04 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-12-18 23:04 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-12-18 23:04 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-12-18 23:04 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-18 23:04 1,695,744 ----a-w c:\windows\System32\gameux.dll
2008-12-18 23:03 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2008-12-18 23:02 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-12-18 23:01 2,048 ----a-w c:\windows\System32\msxml3r.dll
2008-12-18 23:01 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-12-18 22:57 2,048 ----a-w c:\windows\System32\tzres.dll
2008-12-18 22:51 2,927,104 ----a-w c:\windows\explorer.exe
2008-12-18 22:44 9,892,864 ----a-w c:\windows\System32\NlsLexicons000a.dll
2008-12-18 22:43 181,760 ----a-w c:\windows\System32\fsquirt.exe
2008-12-18 22:39 712,704 ----a-w c:\windows\System32\WindowsCodecs.dll
2008-12-18 22:39 425,472 ----a-w c:\windows\System32\PhotoMetadataHandler.dll
2008-12-18 22:39 347,136 ----a-w c:\windows\System32\WindowsCodecsExt.dll
2008-12-18 22:37 443,392 ----a-w c:\windows\System32\win32spl.dll
2008-12-18 22:37 37,888 ----a-w c:\windows\System32\printcom.dll
2008-12-18 22:36 14,848 ----a-w c:\windows\System32\wshrm.dll
2008-12-18 22:35 996,352 ----a-w c:\windows\System32\WMNetMgr.dll
2008-12-18 22:35 98,816 ----a-w c:\windows\System32\mfps.dll
2008-12-18 22:35 94,720 ----a-w c:\windows\System32\logagent.exe
2008-12-18 22:35 53,248 ----a-w c:\windows\System32\rrinstaller.exe
2008-12-18 22:35 24,576 ----a-w c:\windows\System32\mfpmp.exe
2008-12-18 22:35 2,868,736 ----a-w c:\windows\System32\mf.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\inc1.bat -- Not a PE file.
MD5: d6bd77b8c8e3f9900019d9538227e49c
c:\program files\sleep.bat -- Not a PE file.
MD5: 0b22ec6148da4513163adcc22cf26390
---- c:\users\Johan\AppData\Roaming\auserv.exe ----
Company:
File Description: Fmcq Application
File Version: 2, 3, 3, 4
Product Name: Fmcq Application
Copyright: Copyright (C) 2008
Original file name: Fmcq.exe
MD5: 3bc286690ee9f2ac532c93672a866bb7
c:\windows\System32\tmp32078.FOT -- 16-bit executable. Not a PE file.
MD5: fb3cfa71eb5e4e29d7d3e90fbefa567d
c:\windows\System32\tmp6AF68.FOT -- 16-bit executable. Not a PE file.
MD5: be6427c5b3b616495dd972c11580a7dc
---- Directory of C:\Downloads ----
2009-03-01 00:33 22180 --a------ c:\downloads\Billy Talent 3 Albums.torrent
---- Directory of C:\inetpub ----
2009-03-09 13:30 15938 --a------ c:\inetpub\temp\appPools\APCBF19.tmp
2009-03-09 02:09 15938 --a------ c:\inetpub\temp\appPools\APCD883.tmp
2009-03-07 20:49 15938 --a------ c:\inetpub\temp\appPools\APCFED7.tmp
2009-03-06 21:51 15938 --a------ c:\inetpub\temp\appPools\APCCBB7.tmp
2009-03-06 14:50 15938 --a------ c:\inetpub\temp\appPools\APCC8F9.tmp
2009-03-05 11:54 15938 --a------ c:\inetpub\temp\appPools\APCB4EC.tmp
2009-03-04 20:24 15938 --a------ c:\inetpub\temp\appPools\APCECBE.tmp
2009-03-04 19:22 15938 --a------ c:\inetpub\temp\appPools\APCBA68.tmp
2009-03-01 12:41 15938 --a------ c:\inetpub\temp\appPools\APCCA9E.tmp
2009-02-28 11:38 15938 --a------ c:\inetpub\temp\appPools\APC298F.tmp
2009-02-19 12:45 16538 --a------ c:\inetpub\history\CFGHISTORY_0000000003\applicationHost.config
2009-02-19 12:45 16538 --a------ c:\inetpub\history\CFGHISTORY_0000000002\applicationHost.config
2009-02-19 12:44 10065 --a------ c:\inetpub\history\CFGHISTORY_0000000001\applicationHost.config
2009-02-19 12:43 689 --a------ c:\inetpub\wwwroot\iisstart.htm
2009-02-19 12:43 184946 --a------ c:\inetpub\wwwroot\welcome.png
---- Directory of C:\PerfLogs ----
---- Directory of c:\windows\system32\manifeststore ----
2008-01-19 07:16 453570 --a------ c:\windows\system32\manifeststore\advapi32.amx
2008-01-19 06:36 386164 --a------ c:\windows\system32\manifeststore\gdi32.amx
2008-01-19 06:36 350726 --a------ c:\windows\system32\manifeststore\user32.amx
2008-01-19 06:31 534104 --a------ c:\windows\system32\manifeststore\kernel32.amx
---- Directory of c:\windows\system32\migration ----
2008-12-18 23:47 64512 --a------ c:\windows\system32\migration\WininetPlugin.dll
2008-01-19 08:37 161280 --a------ c:\windows\system32\migration\WsUpgrade.dll
2008-01-19 08:36 96256 --a------ c:\windows\system32\migration\PlaMig.dll
2008-01-19 08:36 89088 --a------ c:\windows\system32\migration\nlscoremig.dll
2008-01-19 08:36 79872 --a------ c:\windows\system32\migration\shmig.dll
2008-01-19 08:36 72704 --a------ c:\windows\system32\migration\SxsMigPlugin.dll
2008-01-19 08:36 539136 --a------ c:\windows\system32\migration\MediaPlayer-DLMigPlugin.dll
2008-01-19 08:36 43520 --a------ c:\windows\system32\migration\SCGMigPlugin.dll
2008-01-19 08:36 372224 --a------ c:\windows\system32\migration\WMIMigrationPlugin.dll
2008-01-19 08:36 31232 --a------ c:\windows\system32\migration\TableTextServiceMig.dll
2008-01-19 08:36 209408 --a------ c:\windows\system32\migration\iismig.dll
2008-01-19 08:36 201216 --a------ c:\windows\system32\migration\StorMigPlugin.dll
2008-01-19 08:36 120832 --a------ c:\windows\system32\migration\CntrtextMig.dll
2008-01-19 08:35 49664 --a------ c:\windows\system32\migration\netiomig.dll
2008-01-19 08:35 129024 --a------ c:\windows\system32\migration\ndismigplugin.dll
2008-01-19 08:34 38912 --a------ c:\windows\system32\migration\imkrmig.dll
2008-01-19 08:34 35328 --a------ c:\windows\system32\migration\imjpmig.dll
2008-01-19 08:34 31744 --a------ c:\windows\system32\migration\imscmig.dll
2008-01-19 08:34 22528 --a------ c:\windows\system32\migration\imtcmig.dll
2008-01-19 08:34 153600 --a------ c:\windows\system32\migration\msctfmig.dll
2008-01-19 08:34 143872 --a------ c:\windows\system32\migration\modemmigplugin.dll
2008-01-19 08:33 73216 --a------ c:\windows\system32\migration\bthmigplugin.dll
2008-01-19 08:33 61952 --a------ c:\windows\system32\migration\bridgemigplugin.dll
2008-01-19 08:33 55808 --a------ c:\windows\system32\migration\commig.dll
2006-11-02 16:43 4096 --a------ c:\windows\system32\migration\fr-FR\ShMig.dll.mui
2006-11-02 16:43 2560 --a------ c:\windows\system32\migration\fr-FR\WsUpgrade.dll.mui
2006-11-02 16:42 2560 --a------ c:\windows\system32\migration\fr-FR\SxsMigPlugin.dll.mui
2006-11-02 13:34 16384 --a------ c:\windows\system32\migration\gameuxmig.dll
((((((((((((((((((((((((((((( SnapShot@2009-03-04_14.53.39.20 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-04 13:46:38 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-09 12:47:23 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-09 12:47:23 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-04 13:47:27 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-09 12:47:23 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-09 12:47:23 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-04 13:45:51 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-09 12:46:44 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-04 13:45:51 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-09 12:46:44 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-04 13:45:51 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-09 12:46:44 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-04 13:41:27 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-09 12:08:49 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-08-13 14:03:26 65,536 ----a-w c:\windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
- 2007-04-30 15:50:50 903,072 ----a-w c:\windows\System32\msidcrl40.dll
+ 2007-08-27 14:41:22 1,089,440 ----a-w c:\windows\System32\msidcrl40.dll
- 2009-03-04 00:13:57 120,728 ----a-w c:\windows\System32\perfc009.dat
+ 2009-03-07 08:18:05 120,728 ----a-w c:\windows\System32\perfc009.dat
- 2009-03-04 00:13:57 148,708 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-03-07 08:18:05 148,708 ----a-w c:\windows\System32\perfc00C.dat
- 2009-03-04 00:13:57 645,374 ----a-w c:\windows\System32\perfh009.dat
+ 2009-03-07 08:18:05 645,374 ----a-w c:\windows\System32\perfh009.dat
- 2009-03-04 00:13:57 737,474 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-03-07 08:18:05 737,474 ----a-w c:\windows\System32\perfh00C.dat
- 2009-03-04 13:48:10 7,790 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1835943604-59562121-35127351-1000_UserData.bin
+ 2009-03-09 12:32:47 9,074 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1835943604-59562121-35127351-1000_UserData.bin
- 2009-03-04 13:48:08 61,294 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-09 12:32:47 62,484 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-04 13:44:33 5,684 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-03-09 01:07:45 5,880 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-03-04 11:17:10 40,482 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-09 01:12:18 42,956 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2007-11-26 20:56:20 10,155,840 ----a-w c:\windows\System32\xlive.dll
+ 2008-10-22 04:29:02 14,303,392 ----a-w c:\windows\System32\xlive.dll
- 2007-11-26 20:56:20 13,653,824 ----a-w c:\windows\System32\xlivefnt.dll
+ 2008-10-22 04:29:02 13,643,936 ----a-w c:\windows\System32\xlivefnt.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-30 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-07-02 159744]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13543968]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2008-06-09 96800]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-25 148888]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 227856]
c:\users\Johan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Iomega Product Registration.lnk - c:\program files\Iomega\Registration\Register.exe [2004-02-12 16175104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.tscc"= c:\progra~1\MpcStar\Codecs\tscc\tsccvid.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" /AUTO
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"OEM02Mon.exe"=c:\windows\OEM02Mon.exe
"AppleSyncNotifier"=c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"="0x00000000"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{B21ECF25-9E87-4945-B649-86A87E3C461B}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{94A04448-BF53-432C-9FC9-2F03548BB360}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{172AD385-E06E-4BC1-A048-B5BEEF3C93EA}"= UDP:c:\program files\Steam\Steam.exe:Steam
"{11361498-AFAE-4A5D-9235-8055E29E482C}"= TCP:c:\program files\Steam\Steam.exe:Steam
"{43FDD0F7-F764-4141-B085-E903C749DCF6}"= UDP:c:\program files\Steam\steamapps\common\rainbow six vegas\Binaries\runme.exe:Rainbow Six Vegas
"{1E51BBB3-CED8-4EE1-987E-2A5B2F9900B0}"= TCP:c:\program files\Steam\steamapps\common\rainbow six vegas\Binaries\runme.exe:Rainbow Six Vegas
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [2007-10-16 20496]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-03-07 603904]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2008-12-11 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2008-12-11 7424]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
rsmsvcs REG_MULTI_SZ ntmssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0eda1c0-d519-11dd-b77b-0019b97ea2c9}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contenu du dossier 'Tâches planifiées'
2009-03-09 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-12 15:04]
.
.
------- Examen supplémentaire -------
.
mWindow Title =
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Johan\AppData\Roaming\Mozilla\Firefox\Profiles\jonrxt9w.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-09 13:47:33
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\System32\PnkBstrB.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\DellTPad\ApntEx.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-09 13:54:04 - La machine a redémarré [Johan]
ComboFix-quarantined-files.txt 2009-03-09 12:53:31
Avant-CF: 65,589,657,600 octets libres
Après-CF: 65,457,344,512 octets libres
466 --- E O F --- 2009-03-07 05:26:02