ComboFix 08-01-20.1 - julien 2008-01-21 22:41:31.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.256 [GMT 1:00]
Running from: C:\Users\julien\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1M2VX1NN\ComboFix[1].exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Invit‚\Desktop\internetgamebox.lnk
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-21 to 2008-01-21 ))))))))))))))))))))))))))))))))))))
.
2008-01-21 22:38 . 2000-08-31 08:00 51,200 --a------ C:\Windows\NirCmd.exe
2008-01-21 22:26 . 2008-01-21 22:26 <REP> d-------- C:\Program Files\Lopxp
2008-01-21 22:17 . 2008-01-21 22:17 <REP> d-------- C:\Program Files\Trend Micro
2008-01-16 11:25 . 2008-01-21 10:35 <REP> d-------- C:\Program Files\Navilog1
2008-01-15 13:45 . 2008-01-15 13:45 <REP> d-------- C:\Windows\Google Toolbar
2008-01-15 11:55 . 2005-09-23 07:29 626,688 --a------ C:\Windows\System32\msvcr80.dll
2008-01-15 11:28 . 2008-01-15 14:08 <REP> d-a------ C:\Users\All Users\TEMP
2008-01-15 11:28 . 2008-01-15 14:08 <REP> d-a------ C:\ProgramData\TEMP
2008-01-15 11:27 . 2008-01-15 14:06 <REP> d-------- C:\Users\All Users\Google
2008-01-15 11:27 . 2008-01-15 14:11 <REP> d-------- C:\Program Files\Google
2008-01-13 12:57 . 2008-01-14 13:12 <REP> d-------- C:\Users\julien\AppData\Roaming\Application Data
2008-01-13 12:57 . 2008-01-14 13:13 <REP> d-------- C:\Program Files\Spyware Terminator
2008-01-11 17:20 . 2008-01-13 12:40 <REP> d-------- C:\Users\All Users\Lavasoft
2008-01-11 17:20 . 2008-01-13 12:40 <REP> d-------- C:\ProgramData\Lavasoft
2008-01-11 16:21 . 2008-01-11 16:21 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-11 16:21 . 2008-01-11 16:21 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-11 16:21 . 2008-01-11 16:21 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-11 16:21 . 2008-01-11 16:21 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-11 16:21 . 2008-01-11 16:21 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-11 16:19 . 2008-01-11 16:19 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-11 16:19 . 2008-01-11 16:19 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-11 16:19 . 2008-01-11 16:19 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-11 16:19 . 2008-01-11 16:19 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-11 16:19 . 2008-01-11 16:19 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-11 16:19 . 2008-01-11 16:19 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-11 16:19 . 2008-01-11 16:19 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-11 16:19 . 2008-01-11 16:19 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-11 16:19 . 2008-01-11 16:19 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-01-11 16:18 . 2008-01-11 16:18 11,776 --a------ C:\Windows\System32\sbunattend.exe
2008-01-05 16:02 . 2008-01-05 16:02 <REP> d-------- C:\Users\julien\telechargement et videos
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 10:51 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-01-15 09:24 --------- d-----w C:\ProgramData\HECKMEALJUMP
2008-01-15 09:24 --------- d-----w C:\ProgramData\grey ante kind mess
2008-01-11 15:42 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-11 15:42 --------- d-----w C:\Program Files\Windows Mail
2008-01-11 15:19 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-11 15:19 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-11 15:19 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-11 15:19 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2007-12-28 17:36 --------- d-----w C:\ProgramData\Symantec
2007-12-28 17:36 --------- d-----w C:\Program Files\NewTech Infosystems
2007-12-28 17:36 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
2007-12-27 18:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-27 18:10 --------- d-----w C:\Program Files\LGGSM
2007-12-27 18:09 --------- d-----w C:\Program Files\Ulead Systems
2007-12-27 18:08 --------- d-----w C:\ProgramData\Ulead Systems
2007-12-20 20:23 --------- d-----w C:\ProgramData\NVIDIA
2007-12-19 11:17 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-18 17:04 --------- d-----w C:\Program Files\MSN Messenger
2007-12-18 17:04 --------- d-----w C:\Program Files\Circle Developement
2007-12-12 07:39 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-12 07:37 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-12 07:37 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-12 07:37 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-12 07:36 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-12 07:36 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-12 07:36 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-12 07:36 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-12 07:35 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-12 07:35 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-12 07:35 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-12 07:35 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-12 07:34 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-12 07:34 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-04 14:53 23,152 ----a-w C:\Windows\system32\drivers\aswRdr.sys
2007-12-04 14:52 45,648 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2007-12-04 13:04 837,496 ----a-w C:\Windows\System32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\Windows\System32\AvastSS.scr
2007-11-18 16:42 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-15 02:03 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-15 02:03 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-15 02:03 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-15 02:03 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-15 02:03 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-15 02:03 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-15 02:03 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-15 02:03 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-15 02:03 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-15 02:03 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-15 02:02 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-11-15 02:02 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-08-29 12:25 174 --sha-w C:\Program Files\desktop.ini
2007-08-02 14:55 2,922,848,256 ----a-w C:\Users\julien\Downloads.zip
2007-05-17 13:08 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-05-17 13:08 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-05-17 13:08 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-11 16:18 1232896]
"????r"="" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 14:30 249856]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"DEBUGNURB"="C:\ProgramData\logopenopen.ch42v" [2008-01-15 10:23 385040]
"Kind Mess Surf Settings"="C:\ProgramData\deaf boob bin.8xwl9" [2008-01-15 10:24 380944]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-05-09 17:41 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48 57344]
"eRecoveryService"="" []
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-19 10:45 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-19 10:39 217088]
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 14:15 61440]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-11-19 12:03 45056]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 05:28 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 05:28 8497696]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 05:28 81920]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-14 14:18:59 528384]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 15:52]
R2 int15;int15;C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 17:12]
R2 vnccom;vnccom;C:\Windows\system32\Drivers\vnccom.SYS [2004-06-26 12:22]
R3 vncdrv;vncdrv;C:\Windows\system32\DRIVERS\vncdrv.sys [2004-06-26 12:22]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-07-31 08:22]
R3 ZSMC0305;VIMICRO USB PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2005-11-30 11:50]
R3 ZY202_XP;ZyXEL 802.11g XG202 1211 Driver;C:\Windows\system32\DRIVERS\WlanUZXP.sys [2006-06-20 09:57]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-21 22:45:20
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog305 = C:\Windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????@?@??????????????????????????
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background?g
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-21 22:47:02
ComboFix-quarantined-files.txt 2008-01-21 21:46:55
.
2008-01-18 20:16:29 --- E O F ---