ComboFix 08-10-24.02 - Denis 2008-10-24 15:31:47.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1587 [GMT -4:00]
Lancé depuis: C:\Documents and Settings\Denis\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Denis\Cookies\lyvu._sy
C:\Documents and Settings\Denis\Cookies\onubem.inf
C:\Documents and Settings\Denis\Menu Démarrer\Programmes\AntiSpywareXP2009
C:\Documents and Settings\Denis\Menu Démarrer\Programmes\AntiSpywareXP2009\AntiSpywareXP2009.lnk
C:\Documents and Settings\Denis\Menu Démarrer\Programmes\AntiSpywareXP2009\Uninstall.lnk
C:\WINDOWS\system32\nvsvc32.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS)
-------\Service_TDSSserv.sys)
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-24 au 2008-10-24 ))))))))))))))))))))))))))))))))))))
.
2008-10-24 14:42 . 2008-10-24 14:42 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 14:42 . 2008-10-24 14:42 <REP> d-------- C:\Documents and Settings\Denis\Application Data\Malwarebytes
2008-10-24 14:42 . 2008-10-24 14:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 14:42 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-24 14:42 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-23 22:19 . 2008-10-23 22:19 <REP> d-------- C:\Program Files\Trend Micro
2008-10-23 18:18 . 2008-10-23 18:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-23 17:53 . 2008-10-23 17:53 <REP> d-------- C:\Program Files\Yahoo!
2008-10-23 17:53 . 2008-10-23 17:53 <REP> d-------- C:\Program Files\CCleaner
2008-10-23 16:41 . 2008-10-23 16:41 <REP> d-------- C:\Program Files\Enigma Software Group
2008-10-23 15:18 . 2008-10-23 15:18 18,767 --a------ C:\WINDOWS\dyvolow.dll
2008-10-23 15:18 . 2008-10-23 15:18 18,708 --a------ C:\WINDOWS\system32\azotidug._sy
2008-10-23 15:18 . 2008-10-23 15:18 18,084 --a------ C:\Documents and Settings\Denis\Application Data\okigopor.exe
2008-10-23 15:18 . 2008-10-23 15:18 16,745 --a------ C:\WINDOWS\yqoly.pif
2008-10-23 15:18 . 2008-10-23 15:18 16,645 --a------ C:\WINDOWS\xylox.sys
2008-10-23 15:18 . 2008-10-23 15:18 16,181 --a------ C:\Documents and Settings\Denis\Application Data\olam.reg
2008-10-23 15:18 . 2008-10-23 15:18 15,583 --a------ C:\WINDOWS\pikuraxi.scr
2008-10-23 15:18 . 2008-10-23 15:18 14,798 --a------ C:\WINDOWS\ucaxet.db
2008-10-23 15:18 . 2008-10-23 15:18 13,948 --a------ C:\WINDOWS\system32\bafukedy.reg
2008-10-23 15:18 . 2008-10-23 15:18 13,895 --a------ C:\WINDOWS\ikygif.dat
2008-10-23 15:18 . 2008-10-23 15:18 12,627 --a------ C:\WINDOWS\ufoqog._dl
2008-10-23 15:18 . 2008-10-23 15:18 12,454 --a------ C:\Program Files\Fichiers communs\acedosuzir.pif
2008-10-23 15:18 . 2008-10-23 15:18 10,603 --a------ C:\WINDOWS\system32\owyp.lib
2008-10-23 15:00 . 2008-10-23 15:00 164 --a------ C:\WINDOWS\system32\TDSSosvd.dat
2008-10-23 14:52 . 2008-10-23 14:52 164 --a------ C:\WINDOWS\system32\TDSSmtvd.dat
2008-10-21 20:04 . 2008-10-21 20:04 <REP> d-------- C:\Documents and Settings\Denis\Application Data\AdobeUM
2008-10-17 02:30 . 2008-10-18 13:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-10-17 02:30 . 2008-10-17 02:30 1,409 --a------ C:\WINDOWS\QTFont.for
2008-10-15 22:28 . 2008-09-08 06:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 21:53 . 2008-09-15 11:26 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 21:51 . 2008-08-14 09:23 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 21:51 . 2008-08-14 09:23 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 21:51 . 2008-08-14 09:23 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 21:51 . 2008-08-14 09:23 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 12:15 . 2008-10-14 12:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Blizzard
2008-10-12 05:19 . 2008-10-12 05:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-10-12 05:18 . 2008-10-12 05:18 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-12 05:18 . 2008-10-12 05:18 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-10-12 05:17 . 2008-10-13 11:33 <REP> d-------- C:\Program Files\Fichiers communs\Logishrd
2008-10-08 20:47 . 2008-10-08 20:47 42,320 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-09-30 23:06 . 2008-10-14 22:12 <REP> d-------- C:\Program Files\Warcraft III
2008-09-25 13:03 . 2008-10-23 16:29 <REP> d-------- C:\Program Files\Steam
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-23 21:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-23 19:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-23 18:12 --------- d-----w C:\Program Files\EA GAMES
2008-10-23 18:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-23 04:43 --------- d-----w C:\Documents and Settings\Denis\Application Data\Xfire
2008-10-23 02:43 137,480 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-10-23 02:42 183,120 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-10-23 01:52 --------- d-----w C:\Program Files\Xfire
2008-10-21 18:59 --------- d-----w C:\Program Files\World of Warcraft
2008-10-15 00:28 --------- d-----w C:\Program Files\StarCraft
2008-10-12 18:41 --------- d-----w C:\Program Files\Logitech
2008-10-12 09:47 --------- d-----w C:\Documents and Settings\Denis\Application Data\DivX
2008-10-08 00:48 --------- d-----w C:\Program Files\DivX
2008-10-03 01:31 --------- d-----w C:\Program Files\Diablo II
2008-10-01 03:07 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-09-23 19:40 --------- d-----w C:\Documents and Settings\Denis\Application Data\CyberLink
2008-09-23 19:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 01:59 --------- d-----w C:\Program Files\THQ
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-06 17:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-06 17:07 --------- d-----w C:\Program Files\Lavasoft
2008-09-06 17:07 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-08-31 16:46 --------- d-----w C:\Program Files\Stardock
2008-08-31 16:46 --------- d-----w C:\Program Files\Fichiers communs\Stardock
2008-08-29 16:07 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-24 07:31 --------- d-----w C:\Documents and Settings\Denis\Application Data\GarageGames
2008-08-14 13:23 2,191,232 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-05 22:02 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-08-05 22:02 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-08-05 22:02 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-08-05 22:02 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-08-05 22:02 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-08-05 22:00 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-08-05 22:00 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-08-05 21:59 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-08-05 21:59 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-08-05 21:59 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-08-05 21:59 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-08-05 21:59 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-08-05 21:59 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-08-05 21:59 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-08-05 21:59 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-08-05 21:58 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-08-05 21:58 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-08-05 21:58 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-08-05 21:58 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-08-05 21:58 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-08-05 21:58 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-08-05 21:58 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-26 01:20 86,528 ----a-w C:\WINDOWS\bnetunin.exe
2008-07-18 20:35 22,328 ----a-w C:\Documents and Settings\Denis\Application Data\PnkBstrK.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2008-07-18 32768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 86016]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SpyHunter Security Suite"="C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2008-09-10 864256]
"nwiz"="nwiz.exe" [2008-05-16 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2008-02-20 C:\WINDOWS\system32\CtHelper.exe]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-02-20 C:\WINDOWS\system32\Ctxfihlp.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-20 23:34 24576 C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\Nexon\Combat Arms\CombatArms.exe"= C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"C:\Nexon\Combat Arms\Engine.exe"= C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"C:\\Nexon\\Combat Arms\\NMService.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"C:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-29 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-17 76040]
R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-03-07 417792]
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2008-02-25 1172504]
S3 ADM8511;Convertisseur USB vers Fast Ethernet ADMtek ADM8511/AN986;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2001-08-17 20160]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Launch.exe
.
Contenu du dossier 'Tâches planifiées'
2008-07-17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 17:13]
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Denis\Application Data\Mozilla\Firefox\Profiles\xj7y44gk.default\
FF -: plugin - C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF -: plugin - C:\Documents and Settings\Denis\Application Data\Mozilla\Firefox\Profiles\xj7y44gk.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-24 15:35:17
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\explorer.exe
-> ?:\WINDOWS\system32\SETUPAPI.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\MagicTune Premium\MagicTuneEngine.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\CTxfispi.exe
C:\Program Files\MagicTune Premium\MagicTune.exe
.
**************************************************************************
.
Heure de fin: 2008-10-24 15:39:07 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-24 19:39:02
Avant-CF: 193 247 563 776 octets libres
Après-CF: 193,212,600,320 octets libres
244 --- E O F --- 2008-10-16 10:45:45