ComboFix 08-09-30.01 - Caroline 2008-09-30 22:01:09.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.335 [GMT 2:00]
Lancé depuis: c:\Users\Caroline\Downloads\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-28 au 2008-09-30 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-30 19:13 --------- d-----w C:\Program Files\Norton Internet Security
2008-09-30 17:27 --------- d-----w C:\Users\Caroline\AppData\Roaming\Malwarebytes
2008-09-30 17:27 --------- d-----w C:\ProgramData\Malwarebytes
2008-09-30 17:27 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-30 17:12 --------- d-----w C:\Program Files\Trend Micro
2008-09-30 16:44 71 ----a-w C:\Users\Caroline\3955.bat
2008-09-30 16:44 45,056 ----a-w C:\Users\Caroline\index.exe
2008-09-30 16:20 --------- d-----w C:\ProgramData\Symantec
2008-09-29 09:25 --------- d-----w C:\Program Files\Navilog1
2008-09-29 09:14 71 ----a-w C:\Users\Caroline\5237.bat
2008-09-29 09:05 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-09-29 08:37 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-29 07:48 --------- d-----w C:\ProgramData\Lavasoft
2008-09-29 07:43 --------- d-----w C:\Program Files\Lavasoft
2008-09-29 07:41 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-25 14:44 268,800 ----a-w C:\Windows\System32\es.dll
2008-09-25 13:16 71 ----a-w C:\Users\Caroline\8092.bat
2008-09-25 13:09 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-09-25 13:09 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-09-25 13:09 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-09-25 13:09 --------- d-----w C:\Program Files\Symantec
2008-09-25 13:07 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-25 12:47 174 --sha-w C:\Program Files\desktop.ini
2008-09-25 12:39 --------- d-----w C:\Program Files\Windows Mail
2008-09-25 12:38 --------- d-----w C:\Program Files\Windows Sidebar
2008-09-25 12:35 61,440 ----a-w C:\Windows\System32\winipsec.dll
2008-09-25 12:35 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-09-25 12:35 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
2008-09-25 12:35 272,896 ----a-w C:\Windows\System32\polstore.dll
2008-09-25 12:34 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-09-25 12:34 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-09-25 12:34 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-25 12:34 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
2008-09-25 12:34 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-09-25 12:34 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-09-25 12:34 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-09-25 12:34 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-09-25 12:31 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-09-25 12:31 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-09-25 12:29 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-09-25 12:29 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-09-25 12:28 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-09-25 12:27 303,616 ----a-w C:\Windows\System32\wmpeffects.dll
2008-09-25 12:25 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-09-25 12:25 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-09-25 12:25 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-09-25 12:25 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-09-25 12:25 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-09-25 12:25 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-09-25 12:25 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-09-25 12:25 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-09-25 12:23 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-09-25 12:23 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-09-25 12:23 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-09-25 12:23 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-09-25 12:23 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-09-25 12:13 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-09-25 12:13 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-09-25 12:12 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-09-25 12:12 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-09-25 12:07 1,585,664 ----a-w C:\Windows\System32\setupapi.dll
2008-09-25 12:05 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-09-25 12:05 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-09-25 12:05 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-09-25 12:03 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-09-25 12:01 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-09-25 12:01 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-09-25 12:01 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-09-25 12:00 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-09-25 11:59 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-09-25 11:59 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-09-25 11:59 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-09-25 11:57 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-09-25 11:57 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
2008-09-25 11:57 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-09-25 11:57 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
2008-09-25 11:57 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-09-25 11:57 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-09-25 11:56 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-09-25 11:56 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-09-25 11:55 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-09-25 11:54 428,032 ----a-w C:\Windows\System32\EncDec.dll
2008-09-25 11:54 292,352 ----a-w C:\Windows\System32\psisdecd.dll
2008-09-25 11:54 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-09-25 11:47 71 ----a-w C:\Users\Caroline\1995.bat
2008-09-24 15:28 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-09-24 15:28 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-09-24 15:28 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-09-24 15:28 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-09-24 15:27 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-09-24 15:27 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-09-24 15:27 36,552 ----a-w C:\Windows\System32\wups.dll
2008-09-24 15:26 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-09-24 15:26 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-09-24 10:33 --------- d-----w C:\Users\Caroline\AppData\Roaming\Sony Corporation
2008-09-09 22:04 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
2008-09-09 22:03 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-09-01 20:25 --------- d-----w C:\Users\Caroline\AppData\Roaming\EPSON
2008-07-30 15:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-07-30 15:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2007-08-18 21:04 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-08-18 21:04 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-08-18 21:04 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-09-25 1232896]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 20053544]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-11-13 472632]
"EPSON Stylus DX6000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE" [2006-09-22 139264]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-13 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-13 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-13 81920]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2006-09-11 118784]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2006-11-11 43128]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-17 107112]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-11-17 22696]
"Controleur de calendrier pour Ulead Photo Express"="C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe" [2004-01-12 69632]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe" [2007-01-11 484984]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 C:\Windows\RtHDVCpl.exe]
C:\Users\Caroline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-11-10 18:26 73728 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{1566E031-AD76-4E98-810A-A6C0FB1110C0}"= UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{4327F3E5-F4CB-4DAE-AD97-35DCE8BB507A}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{1ABEE62E-F445-4B50-9506-AF4206FECD4E}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{E2E1D57D-3781-43A3-BFBA-C7BCBB4E5136}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20071030.004\IDSvix86.sys [2007-10-02 180272]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-11-15 28933976]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2006-11-17 37008]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2006-11-06 227328]
R3 yukonwlh;Pilote miniport NDIS6.0 pour contrôleur Ethernet Marvell Yukon;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S3 athrusb;Atheros Wireless LAN USB device driver;C:\Windows\system32\DRIVERS\athrusb.sys [2006-12-22 449536]
S3 DCamUSBDigitalCamera;Digital Camera;C:\Windows\system32\Drivers\mpixvid.sys [2005-04-26 104593]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2006-10-11 741376]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2006-10-09 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2006-10-11 1089536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\shell\AutoRun\command - H:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09aaa6b2-8556-11dc-a019-0013a94ffad8}]
\shell\verb1\command - G:\desktop.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{600ad47d-62ef-11dc-a1c1-0013a94ffad8}]
\shell\Auto\command - H:\Start.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL H:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5e225b7-6396-11dd-bc5a-0013a94ffad8}]
\shell\Auto\command - G:\Start.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d7b127dc-5284-11dc-9e4a-0013a94ffad8}]
\shell\Auto\command - G:\Start.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eab9cf12-d102-11dc-a0a5-0013a94ffad8}]
\shell\verb1\command - desktop.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
ShellExecuteHooks-{EB338DB6-EC2C-456B-B5AD-ED97FB489684} - C:\Windows\system32\qoMfDVMf.dll
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.club-vaio.com
O8 -: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-30 22:05:17
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\Windows\Explorer.exe
-> ?:\Windows\system32\urlmon.dll
.
Heure de fin: 2008-09-30 22:07:00
ComboFix-quarantined-files.txt 2008-09-30 20:06:41
Avant-CF: Le texte du message associ‚ au num‚ro 0x2379 est introuvable dans le fichier de messages pour Application.
Après-CF: 69,519,204,352 octets libres
231 --- E O F --- 2008-09-29 07:31:48