suite
(((((((((((((((((((((((((((((
snapshot@2008-11-23_16.17.21,09 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-23 15:10:24 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-11-24 12:31:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-11-23 15:10:24 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-11-24 12:31:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-11-23 15:11:37 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-11-24 12:33:17 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-11-23 15:16:51 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-11-24 12:34:05 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-11-23 15:10:25 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-24 12:32:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-11-23 15:10:25 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-24 12:32:03 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-23 15:10:25 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-24 12:32:03 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-11-23 15:13:23 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-11-24 16:09:46 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2008-11-23 15:08:41 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2008-11-24 12:37:51 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2008-11-23 15:08:41 123,350 ----a-w c:\windows\System32\perfc00C.dat
+ 2008-11-24 12:37:51 123,350 ----a-w c:\windows\System32\perfc00C.dat
- 2008-11-23 15:08:41 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2008-11-24 12:37:51 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2008-11-23 15:08:41 669,328 ----a-w c:\windows\System32\perfh00C.dat
+ 2008-11-24 12:37:51 669,328 ----a-w c:\windows\System32\perfh00C.dat
- 2008-11-23 15:12:31 12,392 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1040815172-4254338365-605595671-1000_UserData.bin
+ 2008-11-24 12:34:43 12,416 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1040815172-4254338365-605595671-1000_UserData.bin
- 2008-11-22 18:12:30 10,338 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1040815172-4254338365-605595671-1001_UserData.bin
+ 2008-11-23 19:53:16 10,362 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1040815172-4254338365-605595671-1001_UserData.bin
- 2008-11-23 15:12:31 71,814 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-11-24 12:34:42 71,900 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-11-23 15:12:29 56,632 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-11-24 12:34:41 56,632 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-11-22 07:08:56 281,194 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2008-11-24 14:29:59 281,556 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Acer Empowering Technology Monitor"="c:\acer\Empowering Technology\SysMonitor.exe" [2007-01-24 319488]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
c:\users\laure\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 - Capture d'‚cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-04-24 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F95798C9-BF0A-4D20-BD7C-6B38E7FF9FEE}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{A5333138-7820-4A45-A0F8-9FD93BB4D627}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{D585109C-A3E9-47A0-B1F8-BEF827E9F6D7}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{31A60708-F002-42F4-9908-B33BD16550DD}"= c:\program files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{932D4E56-6D5F-4909-A913-8B5947834283}"= c:\program files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{B4E3A7E7-6249-4309-B05F-B68B9B030828}"= c:\program files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{383C1570-BA3C-4015-8188-2C4B6D3284C4}"= c:\program files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{96FB5B8F-6D95-4F7A-809C-7952FC936ACB}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{4FF06BD9-4370-4B76-ACF7-40542F1CF716}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{A3545E1B-C746-447F-9041-B38D5406AB1D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B27F2B2A-F1C3-4E65-8725-F857C07B7BEF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{1500FBFC-C1C1-4245-B248-56EBEB5E59CD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FBB121AE-141C-43E2-92D9-D16D52AB394C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{E4493D48-3FEE-4F2F-B529-CBA181FC2880}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{7D1828E5-3477-4EDA-A1CD-98AA57AADC61}"= Disabled:UDP:c:\program files\Magentic\bin\MgImp.exe:Magentic
"{5685531E-8057-4FC3-A948-69606AFA0539}"= Disabled:TCP:c:\program files\Magentic\bin\MgImp.exe:Magentic
"{D074CF1D-B372-417F-AE39-25D960C49789}"= Disabled:UDP:c:\users\pierrette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6X2MGRC5\magentic_install[1].exe:IncrediMail Installer
"{3ADA255C-5973-4AFD-810C-3702F34F1290}"= Disabled:TCP:c:\users\pierrette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6X2MGRC5\magentic_install[1].exe:IncrediMail Installer
"TCP Query User{F4F46DFA-F8D1-499A-9217-700BB4B7A026}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{CE8350FD-C209-4654-9085-1C9304BE6D4F}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"{FA395558-2AC1-4375-9B93-1F1B9D594049}"= UDP:c:\users\laure\Documents\LimeWire\LimeWire.exe:LimeWire
"{BAF3E6D5-56AD-4557-88E1-C3DA3C05B3D2}"= TCP:c:\users\laure\Documents\LimeWire\LimeWire.exe:LimeWire
"{66D2BF3D-7B0A-4069-AF6D-EC100CFD8BF3}"= Disabled:UDP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{E066A6D2-E3CF-472D-81F7-D31ACF67CE98}"= Disabled:TCP:c:\program files\Magentic\bin\Magentic.exe:Magentic
"{AF624D3B-7773-4E4C-ACB8-5882056F66FC}"= Disabled:UDP:c:\program files\Magentic\bin\MgApp.exe:Magentic
"{E0CD5D4D-97AF-4D8C-8E28-508029E60052}"= Disabled:TCP:c:\program files\Magentic\bin\MgApp.exe:Magentic
"{07A36C3D-2D6A-475C-AF3D-15ED654C741A}"= Disabled:UDP:c:\users\pierrette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JJ8M1VLN\magentic_install[1].exe:IncrediMail Installer
"{F64F4548-5A84-4F5D-8D6F-1C22D6D434D6}"= Disabled:TCP:c:\users\pierrette\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JJ8M1VLN\magentic_install[1].exe:IncrediMail Installer
"{86B72025-761F-4C8A-8F15-3CB758633F2B}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B4931595-6007-42AA-BCFC-1CB7CCD7AE82}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{EB87CD40-487F-4A4E-9DC8-F055BA908C87}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{9EAE9BD7-2FB8-4931-A629-4A6D8F25DFD1}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImApp.exe:IncrediMail
"{34CDA314-7D55-43F8-842F-CEDF9E5FCAAF}"= Disabled:UDP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{B1006D5B-3FDE-46F7-8CD7-793D21818DAA}"= Disabled:TCP:c:\program files\IncrediMail\bin\IncMail.exe:IncrediMail
"{99E1F011-BE03-48EC-9EA8-50A13176D34B}"= Disabled:UDP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{259311A0-EF9B-48DF-875F-B10B74BF5F1D}"= Disabled:TCP:c:\program files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{5FB6FFBB-3E32-4834-A33C-1558F35283DF}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{03F47057-02E7-4CEB-850F-5229BDE7D440}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{5DAA0D3F-52E5-4D64-A057-11261841930A}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{E41A7513-D6C4-40B5-8513-91A86B4E769D}"= Disabled:UDP:c:\users\laure\AppData\Local\Temp\ImInstaller\incredimail_installer.exe:IncrediMail Installer
"{FBD88343-5E54-4C9E-B897-BD0809EC7E66}"= Disabled:TCP:c:\users\laure\AppData\Local\Temp\ImInstaller\incredimail_installer.exe:IncrediMail Installer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-04 110160]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-24 266343]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2007-12-10 51792]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2007-12-10 2929664]
R3 camfilt2;camfilt2;c:\windows\system32\Drivers\camfilt2.sys [2008-04-22 94208]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe []
S3 WSVD;WSVD;\??\c:\windows\system32\drivers\WSVD.sys [2008-05-05 80744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50e8be56-19e8-11dd-aa30-0019dba7b615}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
.
Contenu du dossier 'Tâches planifiées'
2008-11-24 c:\windows\Tasks\HerculesCamService 0.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-11-24 c:\windows\Tasks\HerculesCamService 1.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-11-24 c:\windows\Tasks\HerculesCamService 2.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-11-24 c:\windows\Tasks\HerculesCamService 3.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-04-22 c:\windows\Tasks\HerculesCamService 4.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-04-22 c:\windows\Tasks\HerculesCamService 5.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-04-22 c:\windows\Tasks\HerculesCamService 6.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-04-22 c:\windows\Tasks\HerculesCamService 7.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-04-22 c:\windows\Tasks\HerculesCamService 8.job
- c:\program files\Hercules\DualPix Exchange\CamService.exe [2007-06-05 16:50]
2008-11-24 c:\windows\Tasks\User_Feed_Synchronization-{AE4B3B41-74EC-4ED8-8A76-6EC4368A3807}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-11-24 17:12:52
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-24 17:14:22
ComboFix-quarantined-files.txt 2008-11-24 16:14:19
ComboFix2.txt 2008-11-23 15:18:33
Avant-CF: 68 691 226 624 octets libres
Après-CF: 68,455,215,104 octets libres
293 --- E O F --- 2008-11-21 10:46:32