bonsoir,
voici le rapport :
ComboFix 09-05-31.06 - SSANE 01/06/2009 22:34.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.1982.947 [GMT 2:00]
Lancé depuis: c:\users\SSANE\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Kaspersky Anti-Virus *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\SSANE\AppData\Roaming\.#
c:\windows\system32\KBL.LOG
D:\Desktop.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-01 au 2009-06-01 ))))))))))))))))))))))))))))))))))))
.
2009-05-31 20:06 . 2007-11-08 14:26 1164728 ----a-w- c:\windows\system32\NMSDVDXU.dll
2009-05-24 15:05 . 2009-05-31 20:09 -------- d-----w- C:\Temp
2009-05-23 19:42 . 2009-05-23 19:42 -------- d-----w- c:\users\SSANE\AppData\Local\ZattooPlayer
2009-05-23 19:42 . 2009-05-23 19:44 -------- d-----w- c:\users\SSANE\AppData\Local\Zattoo
2009-05-10 22:35 . 2009-05-31 20:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-09 09:16 . 2009-03-08 11:34 914944 ----a-w- c:\windows\system32\wininet.dll
2009-05-04 19:21 . 2009-05-04 19:21 -------- d-----w- c:\programdata\SlySoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-01 20:39 . 2008-12-03 22:06 673186336 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-01 20:13 . 2009-02-09 22:14 42431 ----a-w- c:\programdata\nvModes.dat
2009-06-01 12:24 . 2009-02-10 22:22 -------- d-----w- c:\programdata\Google Updater
2009-05-31 20:10 . 2007-10-25 00:55 669566 ----a-w- c:\windows\system32\perfh00C.dat
2009-05-31 20:10 . 2007-10-25 00:55 123556 ----a-w- c:\windows\system32\perfc00C.dat
2009-05-31 20:05 . 2009-05-01 20:40 -------- d-----w- c:\program files\LG Electronics
2009-05-31 20:05 . 2007-10-24 15:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-27 18:45 . 2008-12-03 22:06 -------- d-----w- c:\programdata\Kaspersky Lab
2009-05-27 18:42 . 2008-12-03 22:06 1961984 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-05-27 07:43 . 2008-02-11 18:55 5035 ----a-w- c:\windows\bthservsdp.dat
2009-05-20 20:01 . 2008-12-03 22:07 94643 ----a-w- c:\windows\system32\drivers\klick.dat
2009-05-20 20:01 . 2008-12-03 22:07 105395 ----a-w- c:\windows\system32\drivers\klin.dat
2009-05-13 19:44 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-04 19:25 . 2008-12-06 21:22 -------- d-----w- c:\programdata\DVD Shrink
2009-05-02 19:53 . 2009-02-21 22:27 1 ----a-w- c:\users\SSANE\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-01 21:09 . 2008-12-06 21:26 -------- d-----w- c:\program files\DivX
2009-05-01 20:49 . 2008-12-06 21:07 -------- d-----w- c:\users\SSANE\AppData\Roaming\LG Electronics
2009-04-29 20:32 . 2008-12-20 21:12 -------- d-----w- c:\program files\Free Video Converter
2009-04-12 11:00 . 2009-01-18 12:51 -------- d-----w- c:\users\SSANE\AppData\Roaming\Free Download Manager
2009-04-12 08:12 . 2007-10-24 15:14 -------- d-----w- c:\program files\Hewlett-Packard
2009-04-10 20:49 . 2009-04-10 20:49 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-04-07 20:23 . 2009-04-07 20:23 -------- d-----w- c:\programdata\Malwarebytes
2009-03-17 03:38 . 2009-04-15 18:58 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 18:58 24064 ----a-w- c:\windows\system32\amxread.dll
2009-03-09 04:19 . 2008-12-07 10:10 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-05-09 09:17 43008 ----a-w- c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-05-09 09:17 18944 ----a-w- c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-05-09 09:16 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-05-09 09:16 109568 ----a-w- c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-05-09 09:16 132608 ----a-w- c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-05-09 09:16 107520 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-05-09 09:16 107008 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-05-09 09:16 103936 ----a-w- c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-05-09 09:17 420352 ----a-w- c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-05-09 09:17 72704 ----a-w- c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-05-09 09:17 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-05-09 09:17 66560 ----a-w- c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-05-09 09:16 169472 ----a-w- c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-05-09 09:17 34816 ----a-w- c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-05-09 09:17 48128 ----a-w- c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-05-09 09:16 45568 ----a-w- c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-05-09 09:17 156160 ----a-w- c:\windows\system32\msls31.dll
2009-03-08 08:50 . 2009-03-08 08:50 684872 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-03-06 15:12 . 2009-04-12 08:15 21256 ----a-w- c:\windows\Help\OEM\scripts\HPScript.exe
2009-03-05 10:29 . 2009-04-12 08:07 16648 ----a-w- c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-04-26 07:37 . 2008-12-02 22:59 22 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{997EBF0C-CA0E-4411-980D-DE595BE4A63C}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4C3ED039-FEED-42EE-82BC-483897E71969}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{8FDD44D2-A5CC-4351-AA3D-7461B9D0F7DB}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{381055F4-E7D3-4942-A3D2-33C0FAA6BB3A}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{CDF9097F-BFF4-40FE-9988-B8D0C98FBB1E}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"TCP Query User{212F5F17-E519-442A-9C76-1788659683F9}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{F25DB19C-572D-4743-8888-3595B8CCDD02}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{CB47ACE9-0171-4DD9-9692-5BF2AE4C8326}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B01AB3E4-3674-471B-B5A8-CE304B9455EC}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{78E2164F-C988-4E19-AA30-FDFF6339922F}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{914DB3EE-D6B7-4A01-BB53-9D4E22CDCE5F}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{8077D5A3-E4FE-414E-8F71-881C3482D520}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{2CFCE911-08C5-43E5-BA1A-309C4DCA18A0}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{95596FCB-ADF7-43E4-ADCC-D40268640A02}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{07AE654A-B787-46D7-BC47-91DA44660B78}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{5C9B26FD-B709-47FB-98B9-6F26E4662E04}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{E8919EEF-D1F0-43F0-89F7-DBE8D31715AA}"= UDP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
"{DB172AA5-5D59-45DA-BC0A-305BF1BB7961}"= TCP:c:\program files\ma-config.com\maconfservice.exe:maconfservice
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [16/10/2007 12:05 20496]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - ElbyCDIO
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-06-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-10 05:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://
www.google.fr/
mWindow Title =
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\users\SSANE\AppData\Roaming\Mozilla\Firefox\Profiles\tg9332sn.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://google.fr
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.switch.threshold - 1000000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-01 22:39
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2885700723-3891951473-2433636308-1000\Software\SecuROM\License information*]
"datasecu"=hex:38,9b,d2,af,54,e0,2e,34,77,07,cb,41,10,ef,e0,c0,27,fc,64,bc,26,
ca,bf,d4,fd,04,2b,12,1f,83,b5,0b,fb,97,3f,2d,57,96,74,e5,58,58,e9,bf,1d,36,\
"rkeysecu"=hex:b2,62,59,15,ed,6e,3a,9b,1b,df,37,f2,69,3c,8b,fc
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(792)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
c:\windows\system32\NSI.dll
- - - - - - - > 'lsass.exe'(732)
c:\progra~1\KASPER~1\KASPER~1.0\r3hook.dll
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\dnsq.dll
c:\windows\system32\DPPWDFLT.dll
.
Heure de fin: 2009-06-01 22:41
ComboFix-quarantined-files.txt 2009-06-01 20:41
Avant-CF: 95 599 083 520 octets libres
Après-CF: 95 537 471 488 octets libres
233 --- E O F --- 2009-05-29 19:32
merci!
papapoule
