ComboFix 09-11-23.04 - Berny 24/11/2009 12:37.1.2 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1532 [GMT 1:00]
Lancé depuis: c:\documents and settings\Berny\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\fxavx.ini
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\comrepl.exe
c:\windows\kb913800.exe
c:\windows\system\cisvc.exe
c:\windows\system\mqtgsvc.exe
c:\windows\System\mstinit.exe
c:\windows\system\sessmgr.exe
c:\windows\system\spoolsv.exe
c:\windows\system32\drivers\esentutl.exe
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\rsvp.exe
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-24 au 2009-11-24 ))))))))))))))))))))))))))))))))))))
.
2009-11-23 15:20 . 2009-11-23 14:57 404737 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\update.exe
2009-11-23 15:20 . 2009-11-23 14:57 345345 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\update.dll
2009-11-22 14:55 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-11-22 14:55 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-11-22 14:55 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-11-22 14:55 . 2009-11-22 14:55 -------- d-----w- c:\program files\Avira
2009-11-22 14:55 . 2009-11-22 14:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-11-21 00:00 . 2009-11-21 00:00 -------- d-----w- c:\windows\avxoscan
2009-11-20 22:24 . 2009-11-20 22:24 -------- d-----w- c:\documents and settings\Berny\DoctorWeb
2009-11-20 22:06 . 2009-11-20 22:06 -------- d-----w- c:\windows\BDOSCAN8
2009-11-20 17:46 . 2009-11-20 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-11-14 10:55 . 2009-11-14 10:55 -------- d-----w- C:\FOUND.008
2009-11-08 20:43 . 2009-11-08 20:43 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-10-29 18:32 . 2009-10-29 18:35 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-24 11:43 . 2009-07-09 09:50 12 ----a-w- c:\windows\bthservsdp.dat
2009-11-23 15:20 . 2009-11-22 14:55 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-23 11:33 . 2009-11-23 11:33 -------- d-----w- c:\program files\trend micro
2009-11-23 09:39 . 2009-11-23 09:39 -------- d-----w- c:\documents and settings\LocalService\Application Data\IE7Pro
2009-11-21 19:29 . 2006-06-09 19:06 86182 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-21 19:29 . 2006-06-09 19:06 512862 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-21 15:59 . 2006-11-25 21:06 42104 ----a-w- c:\documents and settings\Berny\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-17 14:20 . 2009-10-17 14:20 -------- d-----w- c:\program files\LucasArts
2009-10-17 14:19 . 2009-10-17 14:19 -------- d-----w- c:\documents and settings\Berny\Application Data\InstallShield
2009-10-15 17:42 . 2008-09-16 23:24 1 ----a-w- c:\documents and settings\Berny\Application Data\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-10-09 12:46 . 2009-10-09 12:46 -------- d-----w- c:\program files\Alwil Software
2009-10-04 03:09 . 2009-10-04 03:09 152576 ----a-w- c:\documents and settings\Berny\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-09-29 22:58 . 2009-09-29 22:58 -------- d-----w- c:\program files\Fichiers communs\xing shared
2009-09-28 18:20 . 2009-09-28 18:20 89256 ------w- c:\windows\system32\ElbyCDIO.dll
2009-09-26 17:57 . 2009-09-26 17:57 25768 ------w- c:\windows\system32\drivers\ElbyCDIO.sys
2009-09-20 16:06 . 2006-11-25 21:01 90112 ----a-w- c:\windows\DUMP2431.tmp
2009-09-16 21:12 . 2006-11-25 21:01 90112 ----a-w- c:\windows\DUMP249f.tmp
2009-09-11 15:18 . 2004-08-10 04:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 22:04 . 2004-08-10 04:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:56 . 2006-01-09 19:02 916480 ----a-w- c:\windows\system32\wininet.dll
2006-11-26 14:26 . 2006-11-26 14:26 251 ----a-w- c:\program files\wt3d.ini
2008-02-10 15:36 . 2008-02-10 15:36 0 --sh--w- c:\windows\S9085C6AC.tmp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe 1" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"preload"="c:\windows\RUNXMLPL.exe" [2005-05-19 32768]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-19 7397376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-19 86016]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-04-19 69632]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-04-20 86016]
"ePower_DMC"="c:\acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-03-30 421888]
"Boot"="c:\acer\Empowering Technology\ePower\Boot.exe" [2006-03-15 579584]
"Acer ePresentation HPD"="c:\acer\Empowering Technology\ePresentation\ePresentation.exe" [2006-03-31 204800]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-04-28 401408]
"ImageItEncrypt"="c:\windows\system32\ImageItEncrypt.exe" [2005-12-30 40960]
"domino"="c:\windows\domino.exe" [2006-07-04 49152]
"VMSnap1"="c:\windows\VMSnap1.exe" [2006-07-17 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"CardDetectorHUAWEI"="c:\program files\CardDetector\HUAWEI\CardDetector.exe" [2008-12-01 274432]
"BEWINTERNET-FR-DMGP-V2SessionManager"="c:\program files\Orange\IEWInternet\SessionManager\SessionManager.exe" [2008-12-01 131824]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-09-29 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-12-12 88204]
"GSICONEXE"="GSICON.EXE" - c:\windows\system32\gsicon.exe [2001-09-10 90112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-12-19 16062464]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - c:\acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2006-11-25 45056]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\documents and settings\Berny\Application Data\iolo"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Securitoo.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Securitoo.lnk
backup=c:\windows\pss\Securitoo.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Fichiers communs\\NewTech Infosystems\\LiveUpdate\\LiveUpdate.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Orange\\IEWInternet\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\sweaw.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [22/11/2009 15:55 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [20/03/2009 11:47 54752]
S1 mailKmd;mailKmd; [x]
S2 gafwload;GlobeSpan Usb ADSL Loader;c:\windows\system32\drivers\gafwload.sys [13/12/2006 18:35 26985]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [23/07/2009 12:40 99840]
.
Contenu du dossier 'Tâches planifiées'
2009-11-24 c:\windows\Tasks\User_Feed_Synchronization-{983E89B4-EF27-4374-A776-B0CE220B6AE9}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Connection Wizard,ShellNext = hxxp://www.aceradvantage.com/stdreg
IE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://195.101.52.0/activex/AMC.cab
FF - ProfilePath - c:\documents and settings\Berny\Application Data\Mozilla\Firefox\Profiles\b3hjb370.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Explorer_Run-Logman - c:\docume~1\Berny\APPLIC~1\logman.exe
HKLM-Explorer_Run-ClipSrv - c:\docume~1\Berny\LOCALS~1\APPLIC~1\clipsrv.exe
HKLM-Explorer_Run-Cisvc - c:\docume~1\Berny\LOCALS~1\APPLIC~1\cisvc.exe
HKLM-Explorer_Run-DllHst - c:\windows\System\dllhst3g.exe
HKLM-Explorer_Run-Esent Utl - c:\docume~1\Berny\APPLIC~1\esentutl.exe
HKLM-Explorer_Run-ComRepl - c:\windows\System32\drivers\comrepl.exe
HKLM-Explorer_Run-IEudinit - c:\windows\System\ieudinit.exe
HKLM-Explorer_Run-Mstsc - c:\windows\mstsc.exe
HKLM-Explorer_Run-CmSTP - c:\docume~1\Berny\APPLIC~1\cmstp.exe
HKLM-Explorer_Run-rsvp - c:\docume~1\Berny\LOCALS~1\APPLIC~1\MICROS~1\rsvp.exe
HKLM-Explorer_Run-SessMgr - c:\docume~1\Berny\LOCALS~1\APPLIC~1\sessmgr.exe
HKCU-Explorer_Run-MstInit - c:\docume~1\Berny\APPLIC~1\mstinit.exe
HKCU-Explorer_Run-IEudinit - c:\docume~1\Berny\LOCALS~1\APPLIC~1\ieudinit.exe
HKCU-Explorer_Run-Logman - c:\docume~1\Berny\LOCALS~1\APPLIC~1\logman.exe
HKCU-Explorer_Run-Spool - c:\windows\System32\drivers\spoolsv.exe
HKCU-Explorer_Run-ClipSrv - c:\windows\System\clipsrv.exe
HKCU-Explorer_Run-SessMgr - c:\docume~1\Berny\APPLIC~1\MICROS~1\sessmgr.exe
HKCU-Explorer_Run-ComRepl - c:\docume~1\Berny\LOCALS~1\APPLIC~1\comrepl.exe
HKCU-Explorer_Run-Cisvc - c:\windows\System32\drivers\cisvc.exe
HKCU-Explorer_Run-DllHst - c:\docume~1\Berny\LOCALS~1\APPLIC~1\dllhst3g.exe
HKCU-Explorer_Run-rsvp - c:\docume~1\Berny\APPLIC~1\rsvp.exe
HKU-Default-Explorer_Run-Spool - c:\docume~1\Berny\LOCALS~1\APPLIC~1\spoolsv.exe
HKU-Default-Explorer_Run-rsvp - c:\docume~1\Berny\LOCALS~1\APPLIC~1\MICROS~1\rsvp.exe
HKU-Default-Explorer_Run-SessMgr - c:\docume~1\Berny\LOCALS~1\APPLIC~1\sessmgr.exe
HKU-Default-Explorer_Run-ClipSrv - c:\docume~1\Berny\APPLIC~1\clipsrv.exe
HKU-Default-Explorer_Run-Cisvc - c:\windows\System32\drivers\cisvc.exe
HKU-Default-Explorer_Run-MstInit - c:\windows\mstinit.exe
HKU-Default-Explorer_Run-Logman - c:\windows\System32\drivers\logman.exe
AddRemove-GridVista - c:\windows\UnInst32.exe GridV.UNI
AddRemove-HTML Help Workshop - c:\program files\HTML Help Workshop\setup.exe Uninstall
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealPlayer 12.0 - c:\program files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|12.0
AddRemove-{4AD13F68-CADA-4C6B-9759-C33753F89908} - c:\acer\Empowering Technology\eDataSecurity\eDStbmngr.exe UNINSTALL 1
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-24 12:47
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2264)
c:\windows\system32\MSNCHATHOOK.DLL
c:\windows\system32\sysenv.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\MFC71U.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
c:\program files\iolo\Common\Lib\ioloDMVSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\eHome\ehmsas.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Heure de fin: 2009-11-24 12:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-11-24 11:49
Avant-CF: 32 806 699 008 octets libres
Après-CF: 32 679 067 648 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 50FE27A1CAC0146D0F1FBCA005737254