ComboFix 10-06-25.01 - NingNing 25/06/2010 22:16:00.1.2 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3070.1925 [GMT 2:00]
Lancé depuis: c:\users\NingNing\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LHTFC2D.tmp
c:\windows\system32\muzapp.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-05-25 au 2010-06-25 ))))))))))))))))))))))))))))))))))))
.
2010-06-25 20:20 . 2010-06-25 20:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-25 19:54 . 2010-06-25 19:54 -------- d-----w- c:\program files\Trend Micro
2010-06-24 14:04 . 2010-06-24 14:05 -------- d-----w- c:\windows\system32\ca-ES
2010-06-24 14:04 . 2010-06-24 14:05 -------- d-----w- c:\windows\system32\eu-ES
2010-06-24 14:04 . 2010-06-24 14:05 -------- d-----w- c:\windows\system32\vi-VN
2010-06-24 13:23 . 2010-06-24 13:23 -------- d-----w- c:\program files\Common Files\Java
2010-06-24 13:23 . 2010-04-12 15:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-24 12:49 . 2010-06-24 12:49 -------- d-----w- c:\windows\system32\EventProviders
2010-06-24 01:00 . 2009-11-08 08:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 01:00 . 2009-11-08 08:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 01:00 . 2009-11-08 08:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 01:00 . 2009-11-08 08:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 01:00 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 20:33 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 20:33 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-23 20:33 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-06-09 22:24 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-06-09 10:26 . 2009-03-08 11:33 18944 ----a-w- c:\windows\system32\corpol.dll
2010-06-09 03:19 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-09 03:19 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-09 03:19 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-09 03:18 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-05-28 13:03 . 2010-06-18 10:23 -------- d-----w- c:\program files\Common Files\Steam
2010-05-28 13:03 . 2010-06-25 19:52 -------- d-----w- c:\program files\Steam
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-25 19:59 . 2008-01-21 08:40 669328 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-25 19:59 . 2008-01-21 08:40 123350 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-06-24 14:05 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-06-24 14:05 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-06-24 14:04 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-06-24 13:22 . 2009-09-06 17:38 -------- d-----w- c:\program files\Java
2010-06-24 12:58 . 2009-09-11 10:39 7512 ----a-w- c:\users\NingNing\AppData\Local\d3d9caps.dat
2010-06-15 18:05 . 2009-09-06 23:51 -------- d-----w- c:\users\NingNing\AppData\Roaming\vlc
2010-06-09 10:35 . 2009-04-23 20:32 -------- d-----w- c:\programdata\Microsoft Help
2010-06-09 10:29 . 2009-08-23 14:01 -------- d-----w- c:\program files\Microsoft
2010-06-06 01:05 . 2009-08-23 14:04 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-30 23:52 . 2009-08-23 13:23 -------- d-----w- c:\users\NingNing\AppData\Roaming\Skype
2010-05-30 22:09 . 2009-08-23 18:29 -------- d-----w- c:\users\NingNing\AppData\Roaming\skypePM
2010-05-25 13:30 . 2009-08-23 13:55 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-05-06 17:18 . 2009-09-08 10:19 -------- d-----w- c:\users\NingNing\AppData\Roaming\dvdcss
2010-05-06 16:59 . 2009-11-27 20:37 1312 ----a-w- c:\users\NingNing\AppData\Roaming\wklnhst.dat
2010-05-04 05:59 . 2010-06-09 10:27 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-09 10:27 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-09 10:27 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-09 10:27 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-04-23 14:13 . 2010-05-26 08:42 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-16 16:43 . 2010-06-23 20:33 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-04-16 16:43 . 2010-06-23 20:33 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-04-16 16:43 . 2010-06-23 20:33 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-04-16 16:43 . 2010-06-23 20:33 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2009-10-27 16:44 . 2009-10-27 16:44 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-10-27 10:05 40496 ----a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-04-06 26102056]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-23 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MailNotifier"="c:\program files\Orange\MailNotifier\MailNotifier.exe" [2009-08-04 684032]
"Steam"="c:\program files\Steam\Steam.exe" [2010-05-28 1238352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-09-12 182808]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-03-10 6957600]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-10-27 30192]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2008-10-27 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2008-10-27 346672]
"MDS_Menu"="c:\program files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe" [2008-12-03 218408]
"UpdatePDRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-01-04 222504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"ArcadeDeluxeAgent"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2009-03-26 156968]
"CLMLServer"="c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2009-03-26 202024]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe" [2009-03-05 173288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SMSTray"="c:\program files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-12-14 132624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ORAHSSSessionManager"="c:\program files\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe" [2009-08-24 135920]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-10 1833504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):42,ad,c2,19,a7,13,cb,01
R2 gupdate1ca23f4dd7ea790;Service Google Update (gupdate1ca23f4dd7ea790);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-23 133104]
R3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-10-27 30192]
R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
R3 PCAMPR4;PCAMPR4 NDIS Protocol Driver;c:\windows\system32\PCAMPR4.SYS [x]
R3 PCANDIS4;PCANDIS4 NDIS Protocol Driver;c:\windows\system32\PCANDIS4.SYS [x]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-08-25 108289]
S2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [2009-03-18 75048]
S2 CyberLink Media Server Monitor Service;CyberLink Media Server Monitor Service;c:\program files\Acer Arcade Deluxe\Acer HomeMedia Connect\Kernel\DMS\CLMSMonitorService.exe [2008-12-24 58664]
S2 CyberLink Media Server Service;CyberLink Media Server Service;c:\program files\Acer Arcade Deluxe\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-12-24 288120]
S2 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2008-10-09 19504]
S2 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2008-10-09 16432]
S2 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2008-10-09 59952]
S2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [2008-10-27 306736]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-11-21 220288]
.
Contenu du dossier 'Tâches planifiées'
2010-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-23 13:22]
2010-06-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-23 13:22]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.com/mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1006&m=aspire_x3810uSearchURL,(Default) =
hxxp://www.google.com/search/?q=%sIE: ajouter cette page à vos favoris Orange - c:\users\NingNing\AppData\Local\Temp\cce83FC.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: traduire la page - c:\users\NingNing\AppData\Local\Temp\cce83FA.html
IE: traduire le texte sélectionné - c:\users\NingNing\AppData\Local\Temp\cce83FB.html
IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: mappy.com
Trusted Zone: orange.fr
Trusted Zone: voila.fr\rw.search.ke
Trusted Zone: weborama.fr\orange
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Setresolution - c:\acer\config\1920X1080.cmd
HKLM-Run-MontiorGeo - c:\acer\MonitorGeo.cmd
HKLM-Run-SystrayORAHSS - c:\program files\Orange HSS\Systray\SystrayApp.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-25 22:20
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2010-06-25 22:22:35
ComboFix-quarantined-files.txt 2010-06-25 20:22
Avant-CF: 260 479 762 432 octets libres
Après-CF: 262 535 516 160 octets libres
- - End Of File - - BC291A84547152682EDB5353B09D17E2