ComboFix 08-07-27.6 - SYSTEM 2008-07-28 19:40:53.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2940 [GMT 2:00]
Endroit: C:\Windows\system32\config\systemprofile\Desktop\Killbagle.exe
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\drivers\downld
C:\Windows\system32\drivers\downld\150556.exe
C:\Windows\system32\drivers\downld\185875.exe
C:\Windows\system32\drivers\downld\192474.exe
C:\Windows\system32\drivers\downld\198854.exe
C:\Windows\system32\drivers\downld\200461.exe
C:\Windows\system32\drivers\downld\206966.exe
C:\Windows\system32\drivers\downld\262268.exe
C:\Windows\system32\drivers\downld\272658.exe
C:\Windows\system32\drivers\downld\58796.exe
C:\Windows\system32\drivers\downld\77735.exe
C:\Windows\system32\drivers\downld\88920.exe
C:\Windows\system32\drivers\downld\91151.exe
C:\Windows\system32\drivers\downld\97828.exe
C:\Windows\system32\drivers\hldrrr.exe
C:\Windows\system32\drivers\mdelk.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
-------\Service_srosa
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-28 to 2008-07-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-26 16:32 0 ----a-w C:\ntuser.dat
2008-07-25 16:19 --------- d-----w C:\Program Files\Common Files\LightScribe
2008-07-24 20:40 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-07-24 18:43 352,615 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
2008-07-24 18:35 --------- d-----w C:\Program Files\DAEMON Tools
2008-07-24 14:05 --------- d-----w C:\Program Files\antitrock
2008-07-19 12:28 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-19 12:28 --------- d-----w C:\Program Files\THQ
2008-07-18 06:04 3,650,560 ----a-w C:\Windows\Internet Logs\xDB9C4E.tmp
2008-07-17 21:16 --------- d-----w C:\PROGRA~2\NVIDIA
2008-07-17 01:44 --------- d-----w C:\PROGRA~2\media center programs
2008-07-17 01:01 --------- d-----w C:\Program Files\Funcom
2008-07-17 00:59 --------- d-----w C:\PROGRA~2\Funcom
2008-07-17 00:41 3,117,056 ----a-w C:\Windows\Internet Logs\xDBA8BC.tmp
2008-07-11 21:05 --------- d-----w C:\Program Files\Opera
2008-07-10 14:58 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 20:09 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-07-09 20:05 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-09 14:20 --------- d---a-w C:\Program Files\Furnish Pro
2008-07-09 14:20 --------- d-----w C:\Program Files\Pixie
2008-07-09 01:28 174 --sha-w C:\Program Files\desktop.ini
2008-07-09 01:00 --------- d-----w C:\Program Files\Windows Mail
2008-07-08 16:57 --------- d-----w C:\Program Files\Java
2008-07-08 16:56 --------- d-----w C:\Program Files\Common Files\Java
2008-07-03 22:20 429,568 ----a-w C:\Windows\Internet Logs\xDBB9FB.tmp
2008-07-03 22:04 --------- d-----w C:\Program Files\Real Alternative
2008-07-03 21:59 --------- d-----w C:\PROGRA~2\GRETECH
2008-07-03 21:57 --------- d-----w C:\Program Files\GRETECH
2008-07-03 13:45 --------- d-----w C:\Program Files\VSO
2008-06-29 02:11 --------- d-----w C:\Program Files\Windows Calendar
2008-06-29 01:04 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
2008-06-29 01:04 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
2008-06-29 01:04 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
2008-06-29 01:04 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
2008-06-29 01:04 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
2008-06-28 17:33 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-28 17:33 --------- d-----w C:\Program Files\Windows Live
2008-06-28 17:25 2,402,832 ----a-w C:\WLinstaller.exe
2008-06-28 17:25 --------- d-----w C:\PROGRA~2\WLInstaller
2008-06-24 13:01 --------- d-----w C:\Program Files\MSBuild
2008-06-24 13:01 --------- d-----w C:\Program Files\Microsoft Works
2008-06-24 13:00 --------- d-----w C:\Program Files\Microsoft.NET
2008-06-24 12:58 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-06-24 11:42 --------- d-----w C:\Program Files\SpeedFan
2008-06-24 10:14 --------- d-----w C:\Program Files\Electronic Arts
2008-06-24 02:39 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-24 02:39 --------- d-----w C:\Program Files\Windows Defender
2008-06-24 01:20 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-06-24 01:20 2,923,520 ----a-w C:\Windows\explorer.exe
2008-06-24 01:20 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-06-24 01:18 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-06-24 01:18 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-06-24 01:15 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-06-24 01:15 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-06-24 01:15 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-06-24 01:14 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-06-24 01:14 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-06-24 01:14 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-06-24 01:14 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-06-24 01:14 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-06-24 01:14 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-06-24 01:13 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-06-24 01:13 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-06-24 01:10 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-06-24 01:10 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-06-24 01:10 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-06-24 01:10 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-06-24 01:10 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-06-24 01:10 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-06-24 01:10 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-06-24 01:07 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-06-24 01:06 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-24 01:06 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-06-24 01:06 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-06-24 01:06 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-06-24 01:06 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-06-24 01:05 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-06-24 01:05 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-06-24 01:05 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-06-24 01:05 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-06-24 01:05 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-06-24 01:04 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
2008-06-24 01:02 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-06-24 00:55 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-24 00:36 691,545 ----a-w C:\Windows\unins000.exe
2008-06-23 20:16 --------- d-----w C:\Program Files\Activision
2008-06-23 20:05 685,816 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-06-23 15:17 --------- d-----w C:\Program Files\VideoLAN
2008-06-23 14:48 --------- d-----w C:\Program Files\Zone Labs
2008-06-23 14:48 --------- d-----w C:\PROGRA~2\CheckPoint
2008-06-23 14:28 --------- d-----w C:\Program Files\WinTV
2008-06-23 14:26 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-06-23 14:26 --------- d-----w C:\Program Files\Realtek
2008-06-23 14:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-23 14:26 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-23 14:25 --------- d-----w C:\Program Files\Nero
2008-06-23 14:25 --------- d-----w C:\PROGRA~2\Nero
2008-06-23 14:19 --------- d-----w C:\Program Files\Alwil Software
2008-06-23 13:44 --------- d-sh--w C:\Program Files\Fichiers communs
2008-06-23 13:44 --------- d-sh--w C:\PROGRA~2\Modèles
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-06-24 03:06 1232896]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-26 19:22 2097488]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\WINDOWS\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-28 18:53 959976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 14:01 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 14:01 92704]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-29 20:11 4317184 C:\WINDOWS\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-940212003-742955070-3152845943-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EEAA6ACC-3F76-4C04-8700-81398A89C986}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{ADC6821B-AC70-47B9-B00A-A79AEFEDCD18}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{45FC8FE2-351E-4161-9EA8-E9F0A49F1B12}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{CE94B7E8-2AC8-4DDA-977A-AFD0F5565640}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{23D31F51-5F6D-4D31-9025-81468DC8B064}"= UDP:C:\Program Files\eMule\emule.exe:eMuleMorphXT
"{D6551345-EE6E-4E7B-8E4F-962D40F7C00C}"= TCP:C:\Program Files\eMule\emule.exe:eMuleMorphXT
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-16 01:18]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2006-11-16 07:24]
R3 Hauppauge WinTV-HVR;Hauppauge WinTV-HVR 713X PCI Card;C:\Windows\system32\DRIVERS\HCW713x.sys [2006-07-07 16:36]
S3 Ph3xIB32;Philips 713x VU PCI TV Card;C:\Windows\system32\DRIVERS\Ph3xIB32.sys [2006-11-02 10:27]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\AutoRun\command - J:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1aa9e439-4160-11dd-b533-001d600d9880}]
\shell\AutoRun\command - L:\Autorun.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NeroFilterCheck - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-28 19:45:58
Windows 6.0.6000 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\nvvsvc.exe
C:\WINDOWS\System32\audiodg.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\WUDFHost.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-28 19:47:37 - machine was rebooted [jules]
ComboFix-quarantined-files.txt 2008-07-28 17:47:26
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 331,557,474,304 octets libres
224 --- E O F --- 2008-07-22 20:25:45