ComboFix 08-08-27.06 - Chou 2008-08-28 20:58:09.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.539 [GMT 2:00]
Endroit: C:\Documents and Settings\Chou\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Chou\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE ::
C:\Temp\mn60te.exe
C:\WINDOWS\faceback.exe
C:\WINDOWS\meane.exe
C:\WINDOWS\system32\tguugtdd.tmp
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\Temp\epr1
C:\Temp\epr1\K19i.log
C:\Temp\mn60te.exe
C:\WINDOWS\faceback.exe
C:\WINDOWS\meane.exe
C:\WINDOWS\system32\az1
C:\WINDOWS\system32\tguugtdd.tmp
C:\WINDOWS\system32\ye2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
2008-08-31 16:23 . 2003-03-18 22:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-08-31 16:23 . 2003-03-18 21:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-08-31 16:23 . 2003-02-21 05:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-08-31 16:22 . 2008-08-31 16:22 <REP> d-------- C:\Program Files\Alwil Software
2008-08-28 20:21 . 2008-08-28 20:21 262,144 --a------ C:\WINDOWS\system32\default_user_class.dat
2008-08-28 20:04 . 2008-08-28 20:04 <REP> d-------- C:\Program Files\Avira
2008-08-28 20:04 . 2008-08-28 20:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-28 18:09 . 2008-08-28 18:36 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-28 18:09 . 2008-08-28 18:09 <REP> d-------- C:\Documents and Settings\Chou\Application Data\Malwarebytes
2008-08-28 18:09 . 2008-08-28 18:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-28 18:09 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-28 18:09 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-28 17:16 . 2008-08-28 17:37 1,940 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-28 16:55 . 2008-08-28 20:22 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-08-28 15:53 . 2008-08-28 15:54 <REP> d-------- C:\WINDOWS\system32\NtmsData
2008-08-27 13:56 . 2008-08-27 13:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CA
2008-08-26 21:05 . 2008-08-28 20:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-26 17:31 . 2008-08-26 17:32 118 --a------ C:\tmp2.reg
2008-08-24 17:28 . 2008-08-24 17:28 <REP> d-------- C:\Program Files\Trend Micro
2008-08-12 11:08 . 2001-08-28 14:00 18,688 --a------ C:\WINDOWS\system32\drivers\cdaudio.sys
2008-08-12 11:08 . 2001-08-28 14:00 18,688 --a--c--- C:\WINDOWS\system32\dllcache\cdaudio.sys
2008-08-10 20:55 . 2008-08-28 20:58 <REP> d-------- C:\Temp
2008-08-10 17:43 . 2008-08-10 17:43 <REP> d-------- C:\Program Files\pspvideo9
2008-08-10 17:43 . 2008-08-10 17:43 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-08-10 16:16 . 2008-08-28 19:46 <REP> d-------- C:\Program Files\eMule
2008-08-10 11:39 . 2008-08-12 10:52 <REP> d-------- C:\Program Files\Fichiers communs\DVDVideoSoft
2008-08-10 11:39 . 2008-08-12 10:51 <REP> d-------- C:\Program Files\DVDVideoSoft
2008-08-10 11:39 . 2008-08-10 11:51 <REP> d-------- C:\DVDVideoSoft
2008-07-29 13:52 . 2008-07-29 13:52 <REP> d-------- C:\Program Files\Free Audio Pack
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-31 17:41 --------- d-----w C:\Program Files\Windows Live
2008-08-31 17:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-11 13:13 --------- d-----w C:\Documents and Settings\Chou\Application Data\LimeWire
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_19.35.13.94 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 16:12:56 41,792 ----a-w C:\WINDOWS\system32\drivers\avgntdd.sys
+ 2008-01-21 16:11:28 22,336 ----a-w C:\WINDOWS\system32\drivers\avgntmgr.sys
+ 2008-03-04 11:28:53 79,424 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-03-01 08:34:22 28,352 ----a-w C:\WINDOWS\system32\drivers\ssmdrv.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-10-17 21:22]
R2 UxTuneUp;Extension de conception TuneUp;C:\WINDOWS\System32\svchost.exe [2004-08-20 01:10]
S3 se59bus;Sony Ericsson Device 089 driver (WDM);C:\WINDOWS\system32\DRIVERS\se59bus.sys [2006-09-05 20:07]
S3 se59mdfl;Sony Ericsson Device 089 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se59mdfl.sys [2006-09-05 20:07]
S3 se59mdm;Sony Ericsson Device 089 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se59mdm.sys [2006-09-05 20:07]
S3 se59mgmt;Sony Ericsson Device 089 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se59mgmt.sys [2006-09-05 20:08]
S3 se59nd5;Sony Ericsson Device 089 USB Ethernet Emulation SEMC59 (NDIS);C:\WINDOWS\system32\DRIVERS\se59nd5.sys [2006-09-05 20:06]
S3 se59obex;Sony Ericsson Device 089 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se59obex.sys [2006-09-05 20:09]
S3 se59unic;Sony Ericsson Device 089 USB Ethernet Emulation SEMC59 (WDM);C:\WINDOWS\system32\DRIVERS\se59unic.sys [2006-09-05 20:06]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-07-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-07-18 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-01-17 15:47]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 21:06:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
E:\UPHClean\uphclean.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-28 21:09:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-28 19:09:02
ComboFix2.txt 2008-08-28 17:36:21
Pre-Run: 612,442,112 octets libres
Post-Run: 599,015,424 octets libres
165 --- E O F --- 2008-07-09 20:55:19
Voila le résultat du scan merci pour ton aide, le message a disparu mais le virus est-il toujours là???