Bonjour, voici le nouveau rapport,
ComboFix 12-07-25.04 - user 26/07/2012 16:41:01.3.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1535.1054 [GMT 2:00]
Lancé depuis: c:\documents and settings\user\Bureau\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\explorer.exe . . . est infecté!!
.
Une copie infectée de c:\windows\system32\winlogon.exe a été trouvée et désinfectée
Copie restaurée à partir de - c:\windows\ServicePackFiles\i386\winlogon.exe
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2012-06-26 au 2012-07-26 ))))))))))))))))))))))))))))))))))))
.
.
2012-07-24 20:30 . 2012-07-24 20:30 -------- d-----w- c:\documents and settings\LocalService\Application Data\WTablet
2012-07-24 20:18 . 2012-07-26 14:50 -------- d-----w- c:\documents and settings\user\Application Data\WTablet
2012-07-24 20:10 . 2012-07-24 20:11 -------- d---a-w- c:\program files\PhotoshopPortableCS4
2012-07-24 19:59 . 2012-07-24 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\regid.1986-12.com.adobe
2012-07-24 19:18 . 2012-07-24 19:18 -------- d-----w- C:\WTablet
2012-07-24 19:18 . 2009-03-26 14:38 6561064 ----a-w- c:\windows\system32\WacomTablet.cpl
2012-07-24 19:17 . 2007-02-15 14:11 11440 ----a-w- c:\windows\system32\drivers\WacomVKHid.sys
2012-07-24 19:17 . 2008-07-11 09:16 13352 ----a-w- c:\windows\system32\drivers\wacomvhid.sys
2012-07-24 19:17 . 2007-02-16 09:12 11312 ----a-w- c:\windows\system32\drivers\wacommousefilter.sys
2012-07-24 19:17 . 2008-10-06 09:53 15656 ----a-w- c:\windows\system32\drivers\wacmoumonitor.sys
2012-07-24 19:17 . 2012-07-24 19:17 -------- d-----w- c:\windows\system32\WTablet
2012-07-24 19:16 . 2009-03-26 15:15 2789672 ----a-w- c:\windows\system32\Wacom_Tablet.exe
2012-07-24 19:16 . 2009-03-26 14:40 213288 ----a-w- c:\windows\system32\Wacom_Tablet.dll
2012-07-24 19:16 . 2009-03-26 14:10 172840 ----a-w- c:\windows\system32\Wintab32.dll
2012-07-24 19:16 . 2012-07-24 19:18 -------- d-----w- c:\program files\Tablet
2012-07-24 18:37 . 2012-07-24 19:40 -------- d-----w- c:\documents and settings\user\Adobe Photoshop CS6
2012-07-24 18:36 . 2012-07-24 18:36 -------- d-----w- c:\program files\Adobe Download Assistant
2012-07-24 14:46 . 2012-07-24 14:46 -------- d-----w- c:\documents and settings\user\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-07-24 14:46 . 2012-07-24 14:46 -------- d-----w- c:\program files\Fichiers communs\Adobe AIR
2012-07-24 14:24 . 2012-07-24 14:41 -------- d-----w- C:\TDSSKiller_Quarantine
2012-07-24 14:04 . 2012-07-24 19:55 -------- d-----w- c:\program files\Fichiers communs\Adobe
2012-07-24 14:04 . 2012-07-24 20:50 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Adobe
2012-07-20 18:28 . 2012-07-20 18:28 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-07-20 18:28 . 2012-07-14 00:15 136672 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-07-19 14:10 . 2012-07-19 15:44 -------- d-----w- C:\ZHP
2012-07-19 14:10 . 2012-07-19 15:44 -------- d-----w- c:\program files\ZHPDiag
2012-07-18 18:33 . 2012-07-03 16:21 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-18 18:31 . 2012-07-03 16:21 41224 ----a-w- c:\windows\avastSS.scr
2012-07-18 18:29 . 2012-07-18 18:29 -------- d-----w- c:\program files\AVAST Software
2012-07-18 18:28 . 2012-07-18 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-07-18 18:12 . 2012-07-03 16:21 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-18 18:12 . 2012-07-03 16:21 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-18 18:12 . 2012-07-03 16:21 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-18 18:12 . 2012-07-03 16:21 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-18 18:12 . 2012-07-03 16:21 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-18 18:12 . 2012-07-03 16:21 353688 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-18 18:12 . 2012-07-03 16:21 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-18 18:11 . 2012-07-03 16:21 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-18 18:11 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
2012-07-18 14:24 . 2012-07-18 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG2012
2012-07-18 14:09 . 2012-07-24 18:27 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Temp
2012-07-18 14:03 . 2012-07-18 18:16 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
2012-07-18 04:49 . 2012-07-18 04:49 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2012-07-17 21:19 . 2012-07-17 21:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-17 21:19 . 2012-07-03 11:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-17 21:07 . 2012-07-17 21:07 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-24 14:42 . 2001-08-28 12:00 66560 ----a-w- c:\windows\system32\drivers\serial.sys
2012-07-14 00:15 . 2012-07-20 18:28 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . DD73D6B9F6B4CB630CF35B438B540174 . 512000 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\winlogon.exe
[7] 2004-08-19 . 123EEA158F74D0F67A51DCDF065D1091 . 506368 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2004-08-19 . 229612EFC6EFFA5B2400A506F2353F45 . 506368 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
[7] 2001-08-28 . 00F9B5AA053EF5E4C0A5D95F26005810 . 433152 . . [5.1.2600.29] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
.
[-] 2008-04-14 . F2317622D29F9FF0F88AEECD5F60F0DD . 1037824 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\explorer.exe
[7] 2007-06-13 . B795475444D6D57A572C14B9E1A29839 . 1037312 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2004-08-19 . BF4D437A7591163265B316162DCC1F16 . 1036288 . . [6.00.2900.2180] . . c:\windows\explorer.exe
[7] 2004-08-19 . 2A7BD330924252A2FD80344FC949BB72 . 1036288 . . [6.00.2900.2180] . . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2001-08-28 . 9E20A8EF0CA524446AFEE29F4423CC8F . 1005056 . . [6.00.2600.0000] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((( SnapShot_2012-07-24_22.01.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-30 21:30 . 2008-07-08 13:03 18296 c:\windows\system32\spmsg.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 44544 c:\windows\system32\pngfilt.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 44544 c:\windows\system32\pngfilt.dll
+ 2007-08-13 16:54 . 2010-05-04 17:17 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 16:54 . 2010-03-11 12:34 52224 c:\windows\system32\msfeedsbs.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 27648 c:\windows\system32\jsproxy.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 27648 c:\windows\system32\jsproxy.dll
- 2007-08-13 16:39 . 2010-03-10 13:19 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 16:39 . 2010-05-04 12:39 13824 c:\windows\system32\ieudinit.exe
- 2001-08-28 12:00 . 2010-03-11 12:34 44544 c:\windows\system32\iernonce.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 44544 c:\windows\system32\iernonce.dll
- 2006-10-25 12:23 . 2010-03-11 12:34 78336 c:\windows\system32\ieencode.dll
+ 2006-10-25 12:23 . 2010-05-04 17:17 78336 c:\windows\system32\ieencode.dll
- 2001-08-28 12:00 . 2010-03-10 13:19 70656 c:\windows\system32\ie4uinit.exe
+ 2001-08-28 12:00 . 2010-05-04 12:39 70656 c:\windows\system32\ie4uinit.exe
- 2007-08-13 16:36 . 2010-03-11 12:34 63488 c:\windows\system32\icardie.dll
+ 2007-08-13 16:36 . 2010-05-04 17:17 63488 c:\windows\system32\icardie.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-24 16:19 . 2010-03-11 12:34 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-10-24 16:19 . 2010-05-04 17:17 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2007-10-24 16:19 . 2010-05-04 12:39 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2007-10-24 16:19 . 2010-03-10 13:19 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-08-13 16:39 . 2010-05-04 17:17 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 16:39 . 2010-03-11 12:34 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 16:45 . 2010-03-11 12:34 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2007-08-13 16:45 . 2010-05-04 17:17 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 16:39 . 2010-03-10 13:19 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-13 16:39 . 2010-05-04 12:39 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-10-24 16:19 . 2010-05-04 17:17 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-10-24 16:19 . 2010-03-11 12:34 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-08-13 16:42 . 2010-03-11 12:34 17408 c:\windows\system32\dllcache\corpol.dll
+ 2007-08-13 16:42 . 2010-05-04 17:17 17408 c:\windows\system32\dllcache\corpol.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 17408 c:\windows\system32\corpol.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 17408 c:\windows\system32\corpol.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 77824 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Web.RegularExpressions.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 81920 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Drawing.Design.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 69120 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\CustomMarshalers.dll
+ 2012-07-26 14:28 . 2008-07-25 09:16 13312 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\cscompmgd.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 10752 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\Accessibility.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 44544 c:\windows\ie7updates\KB982381-IE7\pngfilt.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 52224 c:\windows\ie7updates\KB982381-IE7\msfeedsbs.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 27648 c:\windows\ie7updates\KB982381-IE7\jsproxy.dll
+ 2012-07-26 14:17 . 2010-03-10 13:19 13824 c:\windows\ie7updates\KB982381-IE7\ieudinit.exe
+ 2012-07-26 14:17 . 2010-03-11 12:34 44544 c:\windows\ie7updates\KB982381-IE7\iernonce.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 78336 c:\windows\ie7updates\KB982381-IE7\ieencode.dll
+ 2012-07-26 14:18 . 2010-03-10 13:19 70656 c:\windows\ie7updates\KB982381-IE7\ie4uinit.exe
+ 2012-07-26 14:18 . 2010-03-11 12:34 63488 c:\windows\ie7updates\KB982381-IE7\icardie.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 17408 c:\windows\ie7updates\KB982381-IE7\corpol.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 8192 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\IEExecRemote.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 832512 c:\windows\system32\wininet.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 832512 c:\windows\system32\wininet.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 233472 c:\windows\system32\webcheck.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 233472 c:\windows\system32\webcheck.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 105984 c:\windows\system32\url.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 105984 c:\windows\system32\url.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 102912 c:\windows\system32\occache.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 102912 c:\windows\system32\occache.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 671232 c:\windows\system32\mstime.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 671232 c:\windows\system32\mstime.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 193024 c:\windows\system32\msrating.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 193024 c:\windows\system32\msrating.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 477696 c:\windows\system32\mshtmled.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 16:54 . 2010-03-11 12:34 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 16:54 . 2010-05-04 17:17 459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 16:34 . 2010-03-11 12:34 268288 c:\windows\system32\iertutil.dll
+ 2007-08-13 16:34 . 2010-05-04 17:17 268288 c:\windows\system32\iertutil.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 192512 c:\windows\system32\iepeers.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 192512 c:\windows\system32\iepeers.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 385024 c:\windows\system32\iedkcs32.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 10:27 . 2010-03-11 12:34 380928 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 10:27 . 2010-05-04 17:17 380928 c:\windows\system32\ieapfltr.dll
- 2001-08-28 12:00 . 2010-02-23 05:18 161792 c:\windows\system32\ieakui.dll
+ 2001-08-28 12:00 . 2010-04-16 11:43 161792 c:\windows\system32\ieakui.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 230400 c:\windows\system32\ieaksie.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 230400 c:\windows\system32\ieaksie.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 153088 c:\windows\system32\ieakeng.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 153088 c:\windows\system32\ieakeng.dll
+ 2006-10-25 12:23 . 2010-05-04 17:17 133120 c:\windows\system32\extmgr.dll
- 2006-10-25 12:23 . 2010-03-11 12:34 133120 c:\windows\system32\extmgr.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 214528 c:\windows\system32\dxtrans.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 214528 c:\windows\system32\dxtrans.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 347136 c:\windows\system32\dxtmsft.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 347136 c:\windows\system32\dxtmsft.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 832512 c:\windows\system32\dllcache\wininet.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 832512 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 16:54 . 2010-05-04 17:17 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 16:54 . 2010-03-11 12:34 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2007-08-13 16:44 . 2010-05-04 17:17 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 16:44 . 2010-03-11 12:34 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 16:44 . 2010-03-11 12:34 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-08-13 16:44 . 2010-05-04 17:17 102912 c:\windows\system32\dllcache\occache.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2007-10-24 16:19 . 2010-03-11 12:34 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-10-24 16:19 . 2010-05-04 17:17 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-08-13 16:43 . 2010-04-16 11:43 634656 c:\windows\system32\dllcache\iexplore.exe
- 2007-10-24 16:19 . 2010-03-11 12:34 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-10-24 16:19 . 2010-05-04 17:17 268288 c:\windows\system32\dllcache\iertutil.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 192512 c:\windows\system32\dllcache\iepeers.dll
- 2007-08-13 16:39 . 2010-03-11 12:34 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 16:39 . 2010-05-04 17:17 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-10-24 16:19 . 2010-03-11 12:34 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-10-24 16:19 . 2010-05-04 17:17 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2001-08-28 12:00 . 2010-04-16 11:43 161792 c:\windows\system32\dllcache\ieakui.dll
- 2001-08-28 12:00 . 2010-02-23 05:18 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2007-08-13 16:39 . 2010-05-04 17:17 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 16:39 . 2010-03-11 12:34 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2007-08-13 16:39 . 2010-05-04 17:17 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-13 16:39 . 2010-03-11 12:34 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-06-23 11:11 . 2010-05-04 17:17 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-06-23 11:11 . 2010-03-11 12:34 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-08-13 16:39 . 2010-03-11 12:34 124928 c:\windows\system32\dllcache\advpack.dll
+ 2007-08-13 16:39 . 2010-05-04 17:17 124928 c:\windows\system32\dllcache\advpack.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 124928 c:\windows\system32\advpack.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 124928 c:\windows\system32\advpack.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 839680 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Web.Services.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 835584 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Web.Mobile.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 188416 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.DirectoryServices.Protocols.dll
+ 2012-07-26 14:28 . 2008-07-25 09:16 507904 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\AspNetMMCExt.dll
+ 2010-02-24 22:14 . 2010-02-24 22:14 543232 c:\windows\Installer\127bfe.msp
+ 2012-07-26 14:17 . 2010-03-11 12:34 832512 c:\windows\ie7updates\KB982381-IE7\wininet.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 233472 c:\windows\ie7updates\KB982381-IE7\webcheck.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 105984 c:\windows\ie7updates\KB982381-IE7\url.dll
+ 2012-07-26 14:18 . 2009-05-26 11:40 406392 c:\windows\ie7updates\KB982381-IE7\spuninst\updspapi.dll
+ 2012-07-26 14:18 . 2008-07-08 13:03 234872 c:\windows\ie7updates\KB982381-IE7\spuninst\spuninst.exe
+ 2012-07-26 14:17 . 2010-03-11 12:34 102912 c:\windows\ie7updates\KB982381-IE7\occache.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 671232 c:\windows\ie7updates\KB982381-IE7\mstime.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 193024 c:\windows\ie7updates\KB982381-IE7\msrating.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 477696 c:\windows\ie7updates\KB982381-IE7\mshtmled.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 459264 c:\windows\ie7updates\KB982381-IE7\msfeeds.dll
+ 2012-07-26 14:18 . 2010-02-23 05:20 634648 c:\windows\ie7updates\KB982381-IE7\iexplore.exe
+ 2012-07-26 14:17 . 2010-03-11 12:34 268288 c:\windows\ie7updates\KB982381-IE7\iertutil.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 192512 c:\windows\ie7updates\KB982381-IE7\iepeers.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 385024 c:\windows\ie7updates\KB982381-IE7\iedkcs32.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 380928 c:\windows\ie7updates\KB982381-IE7\ieapfltr.dll
+ 2012-07-26 14:18 . 2010-02-23 05:18 161792 c:\windows\ie7updates\KB982381-IE7\ieakui.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 230400 c:\windows\ie7updates\KB982381-IE7\ieaksie.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 153088 c:\windows\ie7updates\KB982381-IE7\ieakeng.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 133120 c:\windows\ie7updates\KB982381-IE7\extmgr.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 214528 c:\windows\ie7updates\KB982381-IE7\dxtrans.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 347136 c:\windows\ie7updates\KB982381-IE7\dxtmsft.dll
+ 2012-07-26 14:18 . 2010-03-11 12:34 124928 c:\windows\ie7updates\KB982381-IE7\advpack.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 1168384 c:\windows\system32\urlmon.dll
- 2001-08-28 12:00 . 2010-03-11 12:34 1168384 c:\windows\system32\urlmon.dll
+ 2001-08-28 12:00 . 2010-05-04 17:17 3600384 c:\windows\system32\mshtml.dll
- 2007-08-13 16:54 . 2010-03-11 12:34 6067200 c:\windows\system32\ieframe.dll
+ 2007-08-13 16:54 . 2010-05-04 17:17 6067200 c:\windows\system32\ieframe.dll
- 2006-07-25 20:41 . 2010-03-11 12:34 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2006-07-25 20:41 . 2010-05-04 17:17 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2006-07-28 11:28 . 2010-05-04 17:17 3600384 c:\windows\system32\dllcache\mshtml.dll
+ 2007-10-24 16:19 . 2010-05-04 17:17 6067200 c:\windows\system32\dllcache\ieframe.dll
- 2007-10-24 16:19 . 2010-03-11 12:34 6067200 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Windows.Forms.dll
+ 2012-07-26 14:27 . 2008-11-25 02:59 5242880 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Web.dll
+ 2012-07-26 14:28 . 2008-07-25 09:17 5062656 c:\windows\Microsoft.NET\Framework\v2.0.50727\GAC19301\System.Design.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 1168384 c:\windows\ie7updates\KB982381-IE7\urlmon.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 3599872 c:\windows\ie7updates\KB982381-IE7\mshtml.dll
+ 2012-07-26 14:17 . 2010-03-11 12:34 6067200 c:\windows\ie7updates\KB982381-IE7\ieframe.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-03-24 3309568]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"AdobeAAMUpdater-1.0"="c:\program files\Fichiers communs\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"SwitchBoard"="c:\program files\Fichiers communs\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files\Fichiers communs\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [18/07/2012 20:33 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [18/07/2012 20:12 353688]
R2 ASPIXNT;ASPIXNT;c:\windows\system32\drivers\Aspixnt.sys [25/10/2007 11:24 6336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18/07/2012 20:12 21256]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [17/07/2012 23:19 655944]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [24/07/2012 21:16 2789672]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [17/07/2012 23:19 22344]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [24/07/2012 21:17 15656]
S0 NeroCdNt;NeroCdNt;c:\windows\system32\drivers\NEROCDNT.SYS [25/10/2007 11:24 13344]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [20/07/2012 20:28 113120]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\system32\drivers\usbiad.sys [05/07/2008 20:25 31547]
S3 SwitchBoard;SwitchBoard;c:\program files\Fichiers communs\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13:37 517096]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contenu du dossier 'Tâches planifiées'
.
2012-07-26 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-18 16:21]
.
2012-07-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-10-30 21:18]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0B670054-4B5A-4C6D-B3B2-2B665AED02E1}: NameServer = 80.10.246.3,80.10.246.130
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\6k251cpm.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://google.be/FF - prefs.js: keyword.URL -
hxxp://isearch.avg.com/search?cid=%7Bbf ... &sap=ku&q=.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-07-26 16:51
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: SEAGATE_ rev.DS09 -> Harddisk0\DR0 -> \Device\Scsi\symmpi2Port2Path0Target1Lun0
.
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user != kernel MBR !!!
sectors 71132957 (+255): user != kernel
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:b4,20,b0,a5,89,7a,39,03,b5,3c,6c,51,58,fe,cc,77,49,be,60,e7,af,
88,0f,a2,b0,58,4f,fa,09,a4,10,7c,68,72,59,1f,e6,70,93,f9,32,95,4b,b2,31,6e,\
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:b4,20,b0,a5,89,7a,39,03,b5,3c,6c,51,58,fe,cc,77,49,be,60,e7,af,
88,0f,a2,b0,58,4f,fa,09,a4,10,7c,68,72,59,1f,e6,70,93,f9,32,95,4b,b2,31,6e,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'explorer.exe'(2472)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\System32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\spkrmon.exe
c:\windows\system32\WTablet\Wacom_TabletUser.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2012-07-26 16:55:18 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-07-26 14:55
ComboFix2.txt 2012-07-24 22:07
ComboFix3.txt 2012-07-19 17:45
.
Avant-CF: 20 551 057 408 octets libres
Après-CF: 20 617 814 016 octets libres
.
- - End Of File - - D40DD1130907A28CB8E4E9EAF4ED67E1