ComboFix 11-10-03.01 - Mr OZCAN 03/10/2011 17:08:43.3.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.958.583 [GMT 2:00]
Lancé depuis: c:\documents and settings\Mr OZCAN\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Mr OZCAN\Bureau\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\SET167.tmp"
"c:\windows\SET16A.tmp"
"c:\windows\SET176.tmp"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\ab05cc
c:\documents and settings\All Users\ab05cc\RTab0_5608.exe
c:\documents and settings\All Users\Application Data\iC04902KiFbH04902
c:\documents and settings\All Users\Application Data\iC04902KiFbH04902\iC04902KiFbH04902
c:\documents and settings\All Users\Application Data\nL04903JhMbD04903
c:\documents and settings\All Users\Application Data\nL04903JhMbD04903\nL04903JhMbD04903
c:\windows\SET167.tmp
c:\windows\SET16A.tmp
c:\windows\SET176.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_bqlrssbz
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-09-03 au 2011-10-03 ))))))))))))))))))))))))))))))))))))
.
.
2011-10-02 09:57 . 2011-10-02 09:57 -------- d-----w- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\PCHealth
2011-09-30 23:13 . 2011-09-30 23:13 -------- d-----w- c:\program files\Ad-Remover
2011-09-30 22:08 . 2011-10-02 18:02 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-09-30 22:05 . 2011-10-02 18:02 -------- d-----w- C:\ZHP
2011-09-30 22:05 . 2011-10-02 18:02 -------- d-----w- c:\program files\ZHPDiag
2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\PC Tools Security
2011-09-30 17:08 . 2011-09-30 18:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2011-09-30 17:08 . 2011-09-30 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-09-30 17:02 . 2011-09-30 18:24 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2011-09-30 16:32 . 2011-09-30 16:32 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-09-29 16:56 . 2007-03-08 04:20 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2011-09-29 16:56 . 2007-03-08 04:20 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2011-09-29 14:13 . 2011-09-29 14:13 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\offreg.dll
2011-09-25 07:04 . 2011-09-12 23:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{39E1CE63-7175-4AB1-A8D3-8049F714EDEA}\mpengine.dll
2011-09-16 14:17 . 2007-03-08 04:20 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2011-09-13 16:31 . 2011-09-13 16:31 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2011-09-09 08:12 . 2011-06-23 18:31 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-09-09 08:12 . 2011-06-23 18:31 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-09-09 08:12 . 2011-06-23 18:31 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-09-09 08:12 . 2011-06-23 18:31 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-09-09 08:12 . 2011-06-23 18:31 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-09-09 08:12 . 2011-06-23 18:31 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-09-09 08:12 . 2011-06-23 18:31 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-09-09 07:47 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-09-09 07:46 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-09-09 07:40 . 2010-12-09 15:14 2194816 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-09-09 07:40 . 2010-12-09 15:14 2029056 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-09-09 07:40 . 2010-12-09 15:14 2150912 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-09-09 07:40 . 2010-12-09 15:14 2071424 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-09-08 15:01 . 2008-04-14 12:00 101888 -c--a-w- c:\windows\system32\dllcache\srusbusd.dll
2011-09-08 15:00 . 2008-04-14 12:00 59392 -c--a-w- c:\windows\system32\dllcache\imscinst.exe
2011-09-08 14:59 . 2003-03-24 13:52 20538 -c--a-w- c:\windows\system32\dllcache\fpremadm.exe
2011-09-08 14:39 . 2001-08-17 18:13 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2011-09-08 14:35 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-09-08 14:35 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-09-08 14:35 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-09-08 14:35 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-09-07 12:55 . 2011-09-07 12:55 -------- d-----r- c:\documents and settings\LocalService\Favoris
2011-09-07 11:04 . 2011-09-07 11:05 -------- d-----w- c:\documents and settings\Administrateur.OZCAN-61D1365FC
2011-09-07 10:04 . 2011-09-07 10:04 -------- d-----r- c:\documents and settings\NetworkService\Favoris
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
2011-09-04 21:16 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-09-03 17:31 . 2011-08-11 17:44 7152464 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-30 23:00 . 2008-04-14 12:00 66048 ----a-w- c:\windows\system32\drivers\serial.sys
2011-09-17 10:12 . 2011-06-29 09:44 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-09 09:12 . 2008-04-14 12:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-08-31 15:00 . 2010-11-23 16:15 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-15 13:29 . 2008-04-14 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2008-04-14 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-09-13 16:55 . 2011-04-06 13:41 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-02_09.48.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-03 15:16 . 2011-10-03 15:16 16384 c:\windows\temp\Perflib_Perfdata_e0.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"VX3000"="c:\windows\vVX3000.exe" [2006-12-05 707360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mr OZCAN^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
path=c:\documents and settings\Mr OZCAN\Menu Démarrer\Programmes\Démarrage\Notification de cadeaux MSN.lnk
backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-06-06 10:55 937920 ----a-w- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2006-11-16 17:04 139264 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-06 15:45 136176 ----atw- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 19:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-01-12 15:48 275800 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ------w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 13:40 155648 ----a-w- c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-05-09 14:50 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 21:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2011-03-09 12:30 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2010-02-18 15:19 53248 ----a-w- c:\windows\system32\VTTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
2010-02-18 15:19 176128 ----a-w- c:\windows\system32\VTTrayp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
2006-12-05 13:39 707360 ----a-w- c:\windows\vVX3000.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
.
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [09/03/2011 14:30 92592]
S0 jekfznca;jekfznca; [x]
S1 MpKsl3ebe2020;MpKsl3ebe2020;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{11661DA5-5298-4FC1-972A-2BCCA90CD684}\MpKsl3ebe2020.sys [?]
S1 MpKslc6572dfc;MpKslc6572dfc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{667BFE0C-2F90-45D0-AE20-FFD3301F595B}\MpKslc6572dfc.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 14:16 130384]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [06/03/2011 13:25 36608]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/12/2009 20:11 135664]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [26/01/2010 18:45 243056]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 14:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
.
2011-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
.
2011-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-10 18:11]
.
2011-09-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004Core.job
- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
.
2011-10-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-746137067-842925246-839522115-1004UA.job
- c:\documents and settings\Mr OZCAN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-08 15:45]
.
2011-10-01 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 13:39]
.
2011-10-03 c:\windows\Tasks\User_Feed_Synchronization-{8C734E8D-32B6-4C0C-999B-5C999564264D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyServer = hxxp://127.0.0.1:8080
uInternet Settings,ProxyOverride = *.local
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Mr OZCAN\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 212.27.40.240 212.27.40.241
FF - ProfilePath - c:\documents and settings\Mr OZCAN\Application Data\Mozilla\Firefox\Profiles\to310717.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-03 17:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(3884)
c:\program files\QuickTime\QTPlugin.ocx
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Heure de fin: 2011-10-03 17:19:32 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-10-03 15:19
ComboFix2.txt 2011-10-02 09:51
ComboFix3.txt 2011-09-08 16:01
.
Avant-CF: 215 688 171 520 octets libres
Après-CF: 215 583 313 920 octets libres
.
- - End Of File - - 1F9861C846BDB72F0B3BA0191A5B1E61