et voilà !
ComboFix 08-03-17.1 - enzo 2008-03-17 22:59:33.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.710 [GMT 1:00]
Endroit: C:\Users\enzo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2SOCASAR\ComboFix[1].exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\AutoRun.inf
C:\Windows\system32\jusched.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-17 to 2008-03-17 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 21:48 --------- d-----w C:\Program Files\EasyBits For Kids
2008-03-14 14:45 --------- d-----w C:\Program Files\Services en ligne
2008-03-12 02:30 --------- d-----w C:\Program Files\Windows Mail
2008-03-12 02:24 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-11 21:20 --------- d---a-w C:\ProgramData\TEMP
2008-03-11 17:27 --------- d-----w C:\Users\enzo\AppData\Roaming\PlayFirst
2008-03-11 17:27 --------- d-----w C:\ProgramData\PlayFirst
2008-03-05 09:28 --------- d-----w C:\Users\enzo\AppData\Roaming\Roxio
2008-03-01 14:21 --------- d-----w C:\ProgramData\HipSoft
2008-02-28 12:20 --------- d-----w C:\Users\enzo\AppData\Roaming\FloodLightGames
2008-02-28 12:20 --------- d-----w C:\ProgramData\FloodLightGames
2008-02-28 09:27 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-28 08:57 --------- d-----w C:\ProgramData\HPSSUPPLY
2008-02-28 08:57 --------- d-----w C:\Program Files\HP
2008-02-28 02:04 --------- d-----w C:\Program Files\Windows Live
2008-02-23 16:56 --------- d-----w C:\ProgramData\AWEM
2008-02-20 07:25 --------- d-----w C:\Program Files\Securitoo
2008-02-19 13:47 30,016 ----a-w C:\Windows\system32\drivers\fsndis5.sys
2008-02-16 16:43 --------- d-----w C:\ProgramData\Go Go Gourmet
2008-02-14 02:12 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 02:12 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 02:06 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 02:06 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-14 02:06 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 02:06 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 02:06 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 02:06 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 02:06 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 02:06 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 02:06 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 02:06 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 02:06 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-14 02:06 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 02:05 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 02:05 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 02:05 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 02:05 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 02:05 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 02:05 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 02:02 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 02:02 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 02:02 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 02:02 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-13 20:22 --------- d-----w C:\Program Files\Google
2008-02-12 21:18 --------- d-----w C:\Users\enzo\AppData\Roaming\ScreenSeven
2008-02-12 16:46 --------- d-----w C:\ProgramData\Oberon Games
2008-02-12 16:46 --------- d-----w C:\Program Files\Orange
2008-02-12 16:46 --------- d-----w C:\Program Files\GamesBar
2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
2008-01-31 10:14 --------- d-----w C:\ProgramData\HP
2008-01-22 20:02 --------- d-----w C:\Program Files\MSECache
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-01-09 07:25 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-07 15:39 81,984 ----a-w C:\Windows\System32\bdod.bin
2008-01-02 13:26 301,568 ----a-w C:\Windows\System32\rrhqquj.exe
2007-11-09 08:26 174 --sha-w C:\Program Files\desktop.ini
2007-12-05 18:17 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-05 18:17 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-05 18:17 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 08:25 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 13:34 2159104 C:\Windows\System32\oobefldr.dll]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-06-01 12:40 1783400]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2007-01-17 15:10 4938016]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-13 21:22 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-04 07:12 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 16:01 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 17:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 12:59 118784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 12:06 4669440 C:\Windows\RtHDVCpl.exe]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 12:13 71176]
"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2007-04-07 01:56 54936]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 20:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 20:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 20:15 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-11-14 23:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]
"F-Secure Manager"="C:\Program Files\Securitoo\Common\FSM32.exe" [2007-06-13 14:58 176177]
"F-Secure TNB"="C:\Program Files\Securitoo\FSGUI\TNBUtil.exe" [2007-06-13 14:57 733184]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2007-11-03 12:28:49 57344]
WiFi Station pour Livebox.lnk - C:\Program Files\Hercules\WiFi Station pour Livebox\WiFiLB.exe [2007-11-03 18:58:29 102400]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1B3AD448-BE5A-4790-8A80-7E3254F72F21}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0FB5F214-D970-4FAE-9DB5-039811DFE0E1}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{5E591280-E657-4D0E-928C-DE0BB1765D89}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{E6ECDFED-1D58-4324-8CB4-500491AAA6F2}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{289B13A4-8611-4964-B0F4-A00EA3183F2C}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{12967359-27D7-4493-9D0B-A2EDCF69CF36}"= UDP:C:\Users\enzo\AppData\Local\Zylom Games\Diner Dash 2 Deluxe\wrapper.exe:Diner Dash 2 Deluxe
"{DBCECD3C-8588-40F5-AA2C-167B15AB72D1}"= TCP:C:\Users\enzo\AppData\Local\Zylom Games\Diner Dash 2 Deluxe\wrapper.exe:Diner Dash 2 Deluxe
"{2624EA7F-4822-4849-811E-0BA90C982FB3}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{10DC5902-F1C5-4EA3-A6C1-B7613F673116}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{1A55F9E9-7252-42A6-962C-BDD2E80D900F}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{082D2037-924B-4E72-827C-F902084127A0}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{AD39CD84-2EDF-462A-B461-FA3111EDF4D5}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{AE46E2C9-A405-46E5-8487-A28A38BBADF3}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{6C0A22C9-2BC7-4383-ACBB-E17949E9C2D8}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{D1901AC5-62F0-4DE0-B915-0ACB93D9392F}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 F-Secure HIPS;F-Secure HIPS;C:\Program Files\Securitoo\HIPS\fshs.sys [2008-02-19 14:46]
R1 FSES;F-Secure Email Scanning Driver;C:\Windows\system32\drivers\fses.sys [2007-06-13 14:58]
R1 FSFW;F-Secure Firewall Driver;C:\Windows\system32\drivers\fsdfw.sys [2007-06-13 14:58]
R1 fsvista;F-Secure Vista Support Driver;C:\Program Files\Securitoo\Anti-Virus\minifilter\fsvista.sys [2007-06-13 14:58]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\Securitoo\Anti-Virus\minifilter\fsgk.sys [2007-06-13 14:58]
R3 netr73;Hercules Wireless USB Dongle Driver for Vista;C:\Windows\system32\DRIVERS\netr73.sys [2007-01-31 17:01]
R4 ezntsvc;EasyBits Magic Desktop Services for Windows NT;C:\Windows\system32\ezNTSvc.exe [2007-11-02 21:39]
S3 PCD5SRVC{BD6912E3-AC9D80E8-05020000};PCD5SRVC{BD6912E3-AC9D80E8-05020000} - PCDR Kernel Mode Service Helper Driver;C:\PROGRA~1\PC-DOC~1\PCD5SRVC.pkms [2007-05-16 01:47]
S4 F-Secure Filter;F-Secure File System Filter;C:\Program Files\Securitoo\Anti-Virus\Win2K\FSfilter.sys [2007-06-13 14:58]
S4 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\Securitoo\Anti-Virus\Win2K\FSrec.sys [2007-06-13 14:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-17 01:09:26 C:\Windows\Tasks\User_Feed_Synchronization-{D05B4C55-1DFA-4310-B73F-F6BFB0593E2D}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-03-17 21:57:02 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-17 23:05:24
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-17 23:06:14
ComboFix-quarantined-files.txt 2008-03-17 22:06:11
.
2008-03-14 13:22:30 --- E O F ---