Tien, j'avais prévenu, il est asser long !!!
ComboFix 08-05-15.3 - Mathieu 2008-05-18 19:15:01.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1035 [GMT 2:00]
Endroit: C:\Users\Mathieu\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\p4p
C:\Program Files\p4p\P4P.exe
C:\Program Files\p4p\RING.WAV
C:\Windows\system32\MSINET.oca
C:\Windows\system32\pac.txt
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-18 to 2008-05-18 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-18 16:52 45,056 ----a-w C:\Windows\System32\acovcnt.exe
2008-05-18 16:44 --------- d-----w C:\ProgramData\Avira
2008-05-18 16:44 --------- d-----w C:\Program Files\Avira
2008-05-18 15:54 --------- d-----w C:\Program Files\Trend Micro
2008-05-18 12:07 --------- d-----w C:\Users\Mathieu\AppData\Roaming\Grisoft
2008-05-18 12:07 --------- d-----w C:\ProgramData\Grisoft
2008-05-18 11:58 --------- d-----w C:\Program Files\CCleaner
2008-05-17 15:10 --------- d-----w C:\Program Files\Alwil Software
2008-05-17 13:25 --------- d-----w C:\ProgramData\TrackMania
2008-05-15 17:41 --------- d-----w C:\Program Files\Windows Mail
2008-05-15 17:40 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-11 22:31 --------- d-----w C:\Users\Mathieu\AppData\Roaming\LimeWire
2008-05-03 10:40 --------- d-----w C:\Program Files\LimeWire
2008-04-26 13:56 --------- d-----w C:\ProgramData\Symantec
2008-04-26 13:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-26 13:52 --------- d-----w C:\Program Files\Symantec
2008-04-16 16:36 --------- d-----w C:\Program Files\AC3Filter
2008-04-16 16:35 2,392,722 ----a-w C:\Users\Mathieu\ac3filter_1_46.exe
2008-04-09 22:51 --------- d-----w C:\Program Files\DivX
2008-04-09 17:26 944,184 ----a-w C:\Windows\System32\winload.exe
2008-04-09 17:26 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-04-09 17:26 620,088 ----a-w C:\Windows\System32\ci.dll
2008-04-09 17:26 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-04-09 17:26 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-04-09 17:26 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-04-09 17:26 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-04-09 17:26 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-04-09 17:26 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-04-09 17:24 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-04-09 17:23 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-04-09 17:20 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
2008-04-09 17:20 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
2008-04-09 16:30 148,992 ----a-w C:\Windows\system32\drivers\ks.sys
2008-04-09 14:46 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-09 14:46 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-09 14:46 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-09 14:46 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-03-31 21:25 831,488 ----a-w C:\Windows\System32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\Windows\System32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\Windows\System32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\Windows\System32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-03-21 20:30 524,288 ----a-w C:\Windows\System32\DivXsm.exe
2008-03-21 20:30 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-03-21 20:30 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\Windows\System32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\Windows\System32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\Windows\System32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\Windows\System32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\Windows\System32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\Windows\System32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\Windows\System32\DivXWMPExtType.dll
2008-03-11 13:08 1,048,576 ---h--r C:\F7SR.BIN
2008-02-18 10:22 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-02-08 16:53 4,499,000 ----a-w C:\Users\Mathieu\LimeWireWin.exe
2007-12-27 22:10 642,796 ----a-w C:\Users\Mathieu\XviD-1.1.3-28062007.exe
2007-12-26 12:13 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@={A8D448F4-0431-45AC-9F5E-E1B434AB2249}
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 02:08 143360 --a------ C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-25 19:58 171448]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-10-20 15:03 1006264]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 11:31 630784]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 21:12 161328]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-03-26 20:42 1057328]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 21:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 05:05 4669440 C:\Windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-06-15 10:44 1826816 C:\Windows\SkyTel.exe]
"JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 08:36 36864]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 15:24 857648]
"PowerForPhone"="C:\Program Files\P4P\P4P.exe" [ ]
"ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2007-10-20 16:14 33136]
"ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2007-10-20 16:15 37232]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-06-24 16:16 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-31 01:12 98304]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
C:\Users\Mathieu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 21:24:54 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{20D92B9C-1F13-4E63-BE73-7DB74DC45559}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{B4089F11-C171-4F4F-84C2-D633D41F36A2}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{00DA162F-8325-492D-A564-08A6ADB947FC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B49FFEDD-1240-4136-AF15-09E9281BE9B0}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CA17A02A-1E5F-4724-8600-149C9BEBF60B}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{90CFA857-A625-4B00-A246-40BA1CBC32F7}"= UDP:D:\jeux\aomx.exe:Age of Mythology - The Titans Expansion
"{FDF1D6FC-F663-440F-B48C-9810F41B6EAE}"= TCP:D:\jeux\aomx.exe:Age of Mythology - The Titans Expansion
"{DB774B5B-8604-4FE0-BDD3-51F9937443D5}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{4A3E6E42-377F-4B13-9588-5C8C8A8EBE2F}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{C2550113-88F4-411F-A059-43CF9079B60A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B6C32DBF-874E-46F8-80FC-B437548B55D6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{1A133813-4CC4-4B6A-AB9C-37BC50644542}D:\\jeux\\call of duty ii\\cod2mp_s.exe"= UDP:D:\jeux\call of duty ii\cod2mp_s.exe:CoD2MP_s
"UDP Query User{2D749D9B-1C1C-4D13-B5AD-A4F9A785B502}D:\\jeux\\call of duty ii\\cod2mp_s.exe"= TCP:D:\jeux\call of duty ii\cod2mp_s.exe:CoD2MP_s
"TCP Query User{35BB1EA3-948F-4D03-8BF8-C2611131008D}D:\\jeux\\call of duty 4 - modern warfare\\iw3mp.exe"= UDP:D:\jeux\call of duty 4 - modern warfare\iw3mp.exe:iw3mp
"UDP Query User{7A9BD9E8-446F-4717-92A2-66B61136D0FC}D:\\jeux\\call of duty 4 - modern warfare\\iw3mp.exe"= TCP:D:\jeux\call of duty 4 - modern warfare\iw3mp.exe:iw3mp
"TCP Query User{F815936A-5452-471F-A227-1CAF71409E9E}D:\\jeux\\call of duty 4 - modern warfare\\iw3mp.exe"= UDP:D:\jeux\call of duty 4 - modern warfare\iw3mp.exe:iw3mp
"UDP Query User{94B4F549-9850-414B-BC2D-A77610C67CF0}D:\\jeux\\call of duty 4 - modern warfare\\iw3mp.exe"= TCP:D:\jeux\call of duty 4 - modern warfare\iw3mp.exe:iw3mp
"TCP Query User{009A6105-C0F1-487A-8233-0F15D5183092}D:\\jeux\\call of duty ii\\cod2mp_s.exe"= UDP:D:\jeux\call of duty ii\cod2mp_s.exe:CoD2MP_s
"UDP Query User{3937F167-9B2D-4E04-8E88-7E26890B69B4}D:\\jeux\\call of duty ii\\cod2mp_s.exe"= TCP:D:\jeux\call of duty ii\cod2mp_s.exe:CoD2MP_s
"TCP Query User{9E5F84D7-B8A6-478B-9698-1643CAB6DB27}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{9027D2B6-4631-482E-995E-998727A9637C}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"TCP Query User{88314BB3-9639-4143-B0B7-1C05F00BB657}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{FD0D02D1-99D8-4AFF-BD7B-37EBEC9B16DC}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{4DBB474F-DCBA-4230-86F9-542B8BC9719F}C:\\users\\mathieu\\desktop\\tmnationsforever\\tmforever.exe"= UDP:C:\users\mathieu\desktop\tmnationsforever\tmforever.exe:tmforever.exe
"UDP Query User{B33BD468-F76D-4F36-8457-0E7510BBF48C}C:\\users\\mathieu\\desktop\\tmnationsforever\\tmforever.exe"= TCP:C:\users\mathieu\desktop\tmnationsforever\tmforever.exe:tmforever.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-13 09:28]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-05-24 04:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad385274-cb5a-11dc-97de-001b77a5e20c}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - AVIPBB
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 19:30:06
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
C:\ADSM_PData_0150
Scan terminé avec succès
Les fichiers cachés: 1
**************************************************************************
.
Temps d'accomplissement: 2008-05-18 19:31:01
ComboFix-quarantined-files.txt 2008-05-18 17:30:57
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
186 --- E O F --- 2008-05-17 15:24:39