Here's the ComboFix Log :
ComboFix 11-10-19.03 - controleur 10/20/11 10:10:22.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.503.31 [GMT -4:00]
Lancé depuis: c:\documents and settings\controleur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\controleur\Bureau\cfscript.txt
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\pragmamfeklnmal.dll
c:\documents and settings\All Users\Favoris\_favdata.dat
C:\Thumbs.db
c:\windows\ehome\medctrro.exe
c:\windows\system32\d3d9caps.dat
c:\windows\system32\TZLog.log
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-09-20 au 2011-10-20 ))))))))))))))))))))))))))))))))))))
.
.
2011-10-19 16:54 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-10-19 16:54 . 2011-06-24 14:10 139656 ------w- c:\windows\system32\dllcache\rdpwd.sys
2011-10-19 16:53 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-10-19 16:52 . 2011-07-08 14:02 10496 ------w- c:\windows\system32\dllcache\ndistapi.sys
2011-10-19 16:51 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-10-12 13:24 . 2011-10-12 13:24 20 ----a-w- c:\windows\system32\drivers\SMR210.dat
2011-10-12 13:24 . 2011-10-12 13:24 83064 ----a-w- c:\windows\system32\drivers\SMR210.SYS
2011-10-12 13:24 . 2011-10-12 15:54 -------- d-----w- c:\documents and settings\controleur\Local Settings\Application Data\NPE
2011-09-26 15:41 . 2011-09-26 15:41 614400 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2011-09-26 15:41 22528 ------w- c:\windows\system32\dllcache\oleaccrc.dll
2011-09-26 15:41 . 2011-09-26 15:41 220160 ------w- c:\windows\system32\dllcache\oleacc.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 15:41 . 2004-08-05 02:00 22528 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-26 15:41 . 2004-08-05 02:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-09 09:12 . 2004-08-05 02:00 606208 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 14:10 . 2004-08-05 02:00 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:41 . 2004-08-05 02:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:41 . 2004-08-05 02:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:41 . 2004-08-05 02:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-05 02:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-05 02:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2004-08-05 . D6D65EA32B190401B57EDB6706F29669 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2002-08-29 . F4127A2A00825C69A870035DA1264AE0 . 22528 . . [5.1.2600.1106] . . c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot@2011-10-19_16.30.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-19 17:28 . 2011-10-19 17:28 16384 c:\windows\Temp\Perflib_Perfdata_7c4.dat
+ 2011-10-19 17:25 . 2011-10-19 17:25 16384 c:\windows\Temp\Perflib_Perfdata_740.dat
+ 2011-10-19 17:25 . 2011-10-19 17:25 16384 c:\windows\Temp\Perflib_Perfdata_634.dat
- 2007-01-29 08:58 . 2010-06-21 14:46 46080 c:\windows\system32\tzchange.exe
+ 2007-01-29 08:58 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2004-08-05 02:00 . 2010-09-10 05:50 66560 c:\windows\system32\mshtmled.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 66560 c:\windows\system32\mshtmled.dll
- 2006-11-08 02:03 . 2010-09-10 05:50 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 02:03 . 2011-08-22 23:41 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-05 02:00 . 2010-09-10 05:50 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-05 02:00 . 2010-11-18 18:12 86016 c:\windows\system32\isign32.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 86016 c:\windows\system32\isign32.dll
+ 2004-08-05 02:00 . 2010-11-02 15:17 40960 c:\windows\system32\drivers\ndproxy.sys
+ 2004-08-05 02:00 . 2011-07-08 14:02 10496 c:\windows\system32\drivers\ndistapi.sys
+ 2010-11-27 16:02 . 2011-07-06 16:44 27888 c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2004-08-05 02:00 . 2009-04-20 17:18 45568 c:\windows\system32\dnsrslvr.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 45568 c:\windows\system32\dnsrslvr.dll
- 2009-08-04 11:38 . 2010-09-10 05:50 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-08-04 11:38 . 2011-08-22 23:41 12800 c:\windows\system32\dllcache\xpshims.dll
- 2006-05-10 05:24 . 2010-09-10 05:50 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:24 . 2011-08-22 23:41 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-09 11:48 . 2011-08-22 23:41 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-05-09 11:48 . 2010-09-10 05:50 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-10-17 17:05 . 2011-08-22 23:41 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2006-10-17 17:05 . 2010-09-10 05:50 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-05-10 05:24 . 2011-08-22 23:41 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-05-10 05:24 . 2010-09-10 05:50 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-11-18 18:12 . 2010-11-18 18:12 86016 c:\windows\system32\dllcache\isign32.dll
+ 2009-04-20 17:18 . 2009-04-20 17:18 45568 c:\windows\system32\dllcache\dnsrslvr.dll
- 2009-12-14 07:09 . 2009-12-14 07:09 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:09 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2004-08-05 02:00 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
- 2004-08-05 02:00 . 2009-12-14 07:09 33280 c:\windows\system32\csrsrv.dll
- 2010-09-23 19:55 . 2010-09-23 19:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-08 18:00 . 2011-07-08 18:00 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2011-07-07 16:04 . 2011-07-07 16:04 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 06:26 . 2010-09-23 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-09-23 06:26 . 2010-09-23 06:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2011-07-07 16:04 . 2011-07-07 16:04 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-09-23 06:26 . 2010-09-23 06:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2011-07-07 16:03 . 2011-07-07 16:03 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
- 2010-09-23 07:17 . 2010-09-23 07:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 17:09 . 2011-07-07 17:09 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2011-07-07 17:09 . 2011-07-07 17:09 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-09-23 07:17 . 2010-09-23 07:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 12800 c:\windows\ie8updates\KB2586448-IE8\xpshims.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 66560 c:\windows\ie8updates\KB2586448-IE8\mshtmled.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 55296 c:\windows\ie8updates\KB2586448-IE8\msfeedsbs.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 43520 c:\windows\ie8updates\KB2586448-IE8\licmgr10.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 25600 c:\windows\ie8updates\KB2586448-IE8\jsproxy.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_b98d6103\System.Drawing.Design.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_31b6a27a\CustomMarshalers.dll
- 2010-09-30 14:14 . 2010-09-30 14:14 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-10-19 17:07 . 2011-10-19 17:07 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
- 2008-05-05 11:25 . 2010-08-27 01:43 5632 c:\windows\system32\xpsp4res.dll
+ 2008-05-05 11:25 . 2011-02-17 12:54 5632 c:\windows\system32\xpsp4res.dll
- 2004-08-05 02:00 . 2010-06-18 17:45 293888 c:\windows\system32\winsrv.dll
+ 2004-08-05 02:00 . 2011-06-20 17:44 293888 c:\windows\system32\winsrv.dll
+ 2004-08-05 02:00 . 2011-03-04 06:36 420864 c:\windows\system32\vbscript.dll
- 2004-08-05 02:00 . 2009-03-08 08:34 105984 c:\windows\system32\url.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 105984 c:\windows\system32\url.dll
+ 2004-08-05 02:00 . 2009-07-27 23:17 135680 c:\windows\system32\shsvcs.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 135680 c:\windows\system32\shsvcs.dll
+ 2004-08-05 02:00 . 2011-01-21 14:44 441344 c:\windows\system32\shimgvw.dll
+ 2004-08-05 02:00 . 2011-04-29 17:25 151552 c:\windows\system32\schannel.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 270848 c:\windows\system32\sbe.dll
+ 2004-08-05 02:00 . 2011-02-09 13:54 270848 c:\windows\system32\sbe.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 551936 c:\windows\system32\oleaut32.dll
+ 2004-08-05 02:00 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
+ 2004-08-05 02:00 . 2010-11-09 14:52 249856 c:\windows\system32\odbc32.dll
- 2004-08-05 02:00 . 2008-04-14 02:33 249856 c:\windows\system32\odbc32.dll
- 2004-08-05 02:00 . 2010-09-10 05:50 206848 c:\windows\system32\occache.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 206848 c:\windows\system32\occache.dll
+ 2004-08-05 02:00 . 2010-12-09 15:15 743424 c:\windows\system32\ntdll.dll
+ 2004-08-05 02:00 . 2008-06-20 16:03 247808 c:\windows\system32\mswsock.dll
- 2004-08-05 02:00 . 2008-06-20 17:47 247808 c:\windows\system32\mswsock.dll
+ 2004-08-05 02:00 . 2011-01-27 11:57 677888 c:\windows\system32\mstsc.exe
- 2004-08-05 02:00 . 2008-04-14 02:34 677888 c:\windows\system32\mstsc.exe
- 2004-08-05 02:00 . 2010-09-10 05:50 611840 c:\windows\system32\mstime.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 611840 c:\windows\system32\mstime.dll
- 2006-11-08 02:03 . 2010-09-10 05:50 602112 c:\windows\system32\msfeeds.dll
+ 2006-11-08 02:03 . 2011-08-22 23:41 602112 c:\windows\system32\msfeeds.dll
- 2004-08-05 02:00 . 2010-09-18 16:23 974848 c:\windows\system32\mfc42u.dll
+ 2004-08-05 02:00 . 2011-02-08 13:34 974848 c:\windows\system32\mfc42u.dll
+ 2004-08-05 02:00 . 2011-02-08 13:34 978944 c:\windows\system32\mfc42.dll
- 2004-08-05 02:00 . 2009-06-25 08:26 736768 c:\windows\system32\lsasrv.dll
+ 2004-08-05 02:00 . 2010-12-20 17:26 736768 c:\windows\system32\lsasrv.dll
- 2004-08-05 02:00 . 2009-06-25 08:26 301568 c:\windows\system32\kerberos.dll
+ 2004-08-05 02:00 . 2010-12-22 12:34 301568 c:\windows\system32\kerberos.dll
+ 2004-08-05 02:00 . 2011-03-04 06:36 726528 c:\windows\system32\jscript.dll
- 2004-08-05 02:00 . 2009-12-09 05:54 726528 c:\windows\system32\jscript.dll
- 2004-08-05 02:00 . 2010-06-09 07:44 692736 c:\windows\system32\inetcomm.dll
+ 2004-08-05 02:00 . 2011-05-02 15:31 692736 c:\windows\system32\inetcomm.dll
- 2004-08-05 02:00 . 2010-09-10 05:50 184320 c:\windows\system32\iepeers.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 184320 c:\windows\system32\iepeers.dll
- 2004-08-05 02:00 . 2010-09-10 05:50 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-05 02:00 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
- 2004-08-16 03:32 . 2011-02-15 21:17 122928 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-16 03:32 . 2011-10-19 17:25 122928 c:\windows\system32\FNTCACHE.DAT
- 2004-08-05 02:00 . 2008-04-14 02:33 186880 c:\windows\system32\encdec.dll
+ 2004-08-05 02:00 . 2011-02-09 13:54 186880 c:\windows\system32\encdec.dll
+ 2004-08-05 02:00 . 2011-02-17 13:18 357888 c:\windows\system32\drivers\srv.sys
- 2004-08-05 02:00 . 2008-04-14 02:34 139656 c:\windows\system32\drivers\rdpwd.sys
+ 2004-08-05 02:00 . 2011-06-24 14:10 139656 c:\windows\system32\drivers\rdpwd.sys
+ 2004-08-05 02:00 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2004-08-05 02:00 . 2011-07-15 13:29 456320 c:\windows\system32\drivers\mrxsmb.sys
+ 2004-08-05 02:00 . 2011-03-03 06:55 149504 c:\windows\system32\dnsapi.dll
+ 2010-06-18 17:45 . 2011-06-20 17:44 293888 c:\windows\system32\dllcache\winsrv.dll
- 2010-06-18 17:45 . 2010-06-18 17:45 293888 c:\windows\system32\dllcache\winsrv.dll
- 2006-05-10 05:24 . 2010-09-10 05:50 916480 c:\windows\system32\dllcache\wininet.dll
+ 2006-05-10 05:24 . 2011-08-22 23:41 916480 c:\windows\system32\dllcache\wininet.dll
+ 2006-09-18 14:15 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
+ 2008-05-09 10:55 . 2011-03-04 06:36 420864 c:\windows\system32\dllcache\vbscript.dll
- 2006-10-17 17:05 . 2009-03-08 08:34 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 17:05 . 2011-08-22 23:41 105984 c:\windows\system32\dllcache\url.dll
+ 2008-10-15 05:51 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
+ 2009-07-27 23:17 . 2009-07-27 23:17 135680 c:\windows\system32\dllcache\shsvcs.dll
+ 2011-01-21 14:44 . 2011-01-21 14:44 441344 c:\windows\system32\dllcache\shimgvw.dll
+ 2008-12-05 06:57 . 2011-04-29 17:25 151552 c:\windows\system32\dllcache\schannel.dll
+ 2011-02-09 13:54 . 2011-02-09 13:54 270848 c:\windows\system32\dllcache\sbe.dll
+ 2010-12-20 17:32 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
- 2006-10-17 17:04 . 2010-09-10 05:50 206848 c:\windows\system32\dllcache\occache.dll
+ 2006-10-17 17:04 . 2011-08-22 23:41 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-04-15 01:24 . 2010-12-09 15:15 743424 c:\windows\system32\dllcache\ntdll.dll
+ 2008-06-20 17:47 . 2008-06-20 16:03 247808 c:\windows\system32\dllcache\mswsock.dll
- 2008-06-20 17:47 . 2008-06-20 17:47 247808 c:\windows\system32\dllcache\mswsock.dll
+ 2006-05-10 05:24 . 2011-08-22 23:41 611840 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:24 . 2010-09-10 05:50 611840 c:\windows\system32\dllcache\mstime.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2007-05-09 11:48 . 2011-08-22 23:41 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-09 11:48 . 2010-09-10 05:50 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
+ 2008-11-12 15:15 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
+ 2006-10-14 08:13 . 2011-02-08 13:34 974848 c:\windows\system32\dllcache\mfc42u.dll
- 2006-10-14 08:13 . 2010-09-18 16:23 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2010-10-14 17:24 . 2011-02-08 13:34 978944 c:\windows\system32\dllcache\mfc42.dll
- 2009-04-15 01:24 . 2009-06-25 08:26 736768 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-04-15 01:24 . 2010-12-20 17:26 736768 c:\windows\system32\dllcache\lsasrv.dll
+ 2011-01-27 11:57 . 2011-01-27 11:57 677888 c:\windows\system32\dllcache\lhmstsc.exe
- 2009-06-25 08:26 . 2009-06-25 08:26 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2009-06-25 08:26 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2008-05-09 10:55 . 2009-12-09 05:54 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-05-09 10:55 . 2011-03-04 06:36 726528 c:\windows\system32\dllcache\jscript.dll
- 2008-08-13 05:22 . 2010-06-09 07:44 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-08-13 05:22 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2009-08-04 11:38 . 2011-08-22 23:41 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-08-04 11:38 . 2010-09-10 05:50 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2006-05-10 05:24 . 2010-09-10 05:50 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2006-05-10 05:24 . 2011-08-22 23:41 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-10 18:30 . 2011-08-22 23:41 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-10 18:30 . 2010-09-10 05:50 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2006-11-07 08:27 . 2010-09-10 05:50 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-11-07 08:27 . 2011-08-22 23:41 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-11-07 08:26 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
+ 2011-02-09 13:54 . 2011-02-09 13:54 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-06-20 17:47 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
+ 2011-09-09 09:12 . 2011-09-09 09:12 606208 c:\windows\system32\dllcache\crypt32.dll
+ 2010-04-20 05:30 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-06-20 11:40 . 2011-08-17 13:49 138496 c:\windows\system32\dllcache\afd.sys
+ 2004-08-05 02:00 . 2011-02-15 12:56 290432 c:\windows\system32\atmfd.dll
- 2010-09-23 06:26 . 2010-09-23 06:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 16:04 . 2011-07-07 16:04 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2011-07-07 16:01 . 2011-07-07 16:01 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 06:25 . 2010-09-23 06:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
- 2010-09-23 07:17 . 2010-09-23 07:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-07-07 17:09 . 2011-07-07 17:09 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 916480 c:\windows\ie8updates\KB2586448-IE8\wininet.dll
+ 2011-10-19 17:13 . 2009-03-08 08:34 105984 c:\windows\ie8updates\KB2586448-IE8\url.dll
+ 2011-10-19 17:13 . 2010-07-05 13:17 406392 c:\windows\ie8updates\KB2586448-IE8\spuninst\updspapi.dll
+ 2011-10-19 17:13 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2586448-IE8\spuninst\spuninst.exe
+ 2011-10-19 17:13 . 2010-09-10 05:50 206848 c:\windows\ie8updates\KB2586448-IE8\occache.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 611840 c:\windows\ie8updates\KB2586448-IE8\mstime.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 602112 c:\windows\ie8updates\KB2586448-IE8\msfeeds.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 247808 c:\windows\ie8updates\KB2586448-IE8\ieproxy.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 184320 c:\windows\ie8updates\KB2586448-IE8\iepeers.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 743424 c:\windows\ie8updates\KB2586448-IE8\iedvtool.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 387584 c:\windows\ie8updates\KB2586448-IE8\iedkcs32.dll
+ 2011-10-19 17:13 . 2010-08-26 12:22 173056 c:\windows\ie8updates\KB2586448-IE8\ie4uinit.exe
+ 2011-10-19 17:09 . 2009-03-08 08:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-10-19 17:09 . 2010-07-05 13:17 406392 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-10-19 17:09 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-10-19 17:10 . 2010-03-10 06:16 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-10-19 17:10 . 2010-07-05 13:18 406392 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-10-19 17:10 . 2010-07-05 13:17 234872 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-10-19 17:10 . 2009-12-09 05:54 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2008-11-12 15:15 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-10-19 17:08 . 2011-10-19 17:08 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_78d13170\System.Drawing.dll
+ 2011-10-19 16:53 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
+ 2004-08-05 02:00 . 2011-08-22 23:41 1212416 c:\windows\system32\urlmon.dll
- 2004-08-05 02:00 . 2010-07-27 06:30 8518656 c:\windows\system32\shell32.dll
+ 2004-08-05 02:00 . 2011-01-21 14:44 8518656 c:\windows\system32\shell32.dll
+ 2004-08-05 02:00 . 2010-12-09 15:14 2150912 c:\windows\system32\ntoskrnl.exe
+ 2004-08-05 02:00 . 2010-12-09 15:14 2029056 c:\windows\system32\ntkrnlpa.exe
+ 2004-08-05 02:00 . 2011-02-02 07:59 2067456 c:\windows\system32\mstscax.dll
+ 2004-08-05 02:00 . 2011-10-03 08:34 5971456 c:\windows\system32\mshtml.dll
+ 2006-10-17 16:57 . 2011-08-22 23:41 2000384 c:\windows\system32\iertutil.dll
+ 2008-10-15 05:50 . 2011-09-06 14:10 1859072 c:\windows\system32\dllcache\win32k.sys
+ 2006-05-10 05:24 . 2011-08-22 23:41 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2008-06-17 19:02 . 2010-07-27 06:30 8518656 c:\windows\system32\dllcache\shell32.dll
+ 2008-06-17 19:02 . 2011-01-21 14:44 8518656 c:\windows\system32\dllcache\shell32.dll
+ 2008-10-15 05:50 . 2010-12-09 15:14 2194816 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2029056 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2071424 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2150912 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:09 . 2011-10-03 08:34 5971456 c:\windows\system32\dllcache\mshtml.dll
+ 2011-02-02 07:59 . 2011-02-02 07:59 2067456 c:\windows\system32\dllcache\lhmstscx.dll
+ 2007-05-09 11:48 . 2011-08-22 23:41 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-07-08 17:59 . 2011-07-08 17:59 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-09-23 19:55 . 2010-09-23 19:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2011-07-08 17:59 . 2011-07-08 17:59 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-09-23 19:55 . 2010-09-23 19:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2011-07-07 16:02 . 2011-07-07 16:02 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-09-23 06:26 . 2010-09-23 06:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2011-07-07 16:02 . 2011-07-07 16:02 2527232 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2011-07-08 17:59 . 2011-07-08 17:59 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-09-23 19:55 . 2010-09-23 19:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 1210880 c:\windows\ie8updates\KB2586448-IE8\urlmon.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 5957120 c:\windows\ie8updates\KB2586448-IE8\mshtml.dll
+ 2011-10-19 17:13 . 2010-09-10 05:50 1986560 c:\windows\ie8updates\KB2586448-IE8\iertutil.dll
+ 2008-10-15 05:50 . 2010-12-09 15:14 2194816 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2029056 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2071424 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 05:50 . 2010-12-09 15:14 2150912 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-10-19 17:08 . 2011-10-19 17:08 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_b304c7f8\System.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_6a927b24\System.Xml.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_f07890f1\System.Windows.Forms.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 1466368 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_70f8f41b\System.Design.dll
+ 2011-10-19 17:08 . 2011-10-19 17:08 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_63ff40b8\mscorlib.dll
- 2010-09-30 14:14 . 2010-09-30 14:14 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-10-19 17:07 . 2011-10-19 17:07 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
- 2010-09-30 14:14 . 2010-09-30 14:14 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-10-19 17:07 . 2011-10-19 17:07 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2006-06-17 12:53 . 2011-10-05 14:09 48324552 c:\windows\system32\MRT.exe
+ 2006-11-08 02:03 . 2011-08-23 21:41 11081728 c:\windows\system32\ieframe.dll
+ 2007-05-09 11:48 . 2011-08-23 21:41 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-07-13 02:49 . 2011-07-13 02:49 11459584 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2572067\M2572067Uninstall.msp
+ 2011-07-12 19:50 . 2011-07-12 19:50 17555968 c:\windows\Installer\3e6c6e.msp
+ 2011-10-19 17:13 . 2010-09-10 05:50 11080192 c:\windows\ie8updates\KB2586448-IE8\ieframe.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-09-30 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-09-30 126976]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-07-06 20:32 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2003-07-30 07:08 143360 ----a-w- c:\program files\Analog Devices\SoundMAX\SMTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
2004-01-05 22:34 40960 ----a-w- c:\windows\vsnpstd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-10-15 11:51 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\system32\drivers\SMR210.SYS [10/12/11 09:24 83064]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\SymDS.sys [05/23/11 13:34 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\SymEFA.sys [05/23/11 13:34 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111014.001\BHDrvx86.sys [10/14/11 19:10 818808]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\Ironx86.sys [05/23/11 13:34 136312]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [10/12/10 06:49 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [08/03/07 15:09 12856]
R2 MSSQL$PAIEPC;MSSQL$PAIEPC;c:\program files\Microsoft SQL Server\MSSQL$PAIEPC\Binn\sqlservr.exe -sPAIEPC --> c:\program files\Microsoft SQL Server\MSSQL$PAIEPC\Binn\sqlservr.exe -sPAIEPC [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [08/08/11 02:59 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111019.030\IDSXpx86.sys [10/19/11 22:04 356280]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\CONTRO~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\CONTRO~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\CONTRO~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS --> c:\docume~1\CONTRO~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S2 gupdate1ca411d58378d40;Service Google Update (gupdate1ca411d58378d40);c:\program files\Google\Update\GoogleUpdate.exe [09/29/09 11:56 133104]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [09/29/09 11:56 133104]
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - 51627947
*Deregistered* - 51627947
.
Contenu du dossier 'Tâches planifiées'
.
2011-10-19 c:\windows\Tasks\bu_bert.job
- C:\bu_bert.bat [2007-07-05 14:01]
.
2011-10-20 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
2011-10-16 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.1.0.4\DriverRobot.exe [2009-09-30 14:22]
.
2011-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 15:55]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-29 15:55]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sympatico.ca/defaultf.aspx?lang=fr-CA
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
TCP: Interfaces\{F7BC2B6C-44B5-4B70-A34F-00FB81375E32}: NameServer = 90.0.0.2,198.235.216.134
DPF: {0F7A9297-7268-11D1-B81A-00A076C01B0A} - hxxp://www.registrefoncier.gouv.qc.ca/Sirf/Script/14_05_04/CPCViewAX_060503/CpcViewAX.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-20 10:22
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
Binary file raw_enum.dat matches
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Heure de fin: 2011-10-20 10:26:46
ComboFix-quarantined-files.txt 2011-10-20 14:26
ComboFix2.txt 2011-10-19 16:33
.
Avant-CF: 66 076 057 600 octets libres
Après-CF: 66 069 336 064 octets libres
.
- - End Of File - - A87539B56DEA26F91FA5ABD09837A394
Norton still detects the threat. Besides that, everything looks normal.
Thanks