Voila le log cclean 31/07/2007 a 16:15:24,95
*** Recherche des fichiers dans C:
C:\StubInstaller.exe FOUND
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
*** Recherche des fichiers dans C:\Program Files
*** Fin du rapport !
voila le rapport
ComboFix 07-07-31 - "mansou" 2007-07-31 16:24:20.1 [GMT 2:00] - NTFS
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.Vrai
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\video access activex object
((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-31 )))))))))))))))))))))))))))))))
2007-07-31 16:22 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-31 14:56 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-07-31 14:18 <REP> d-------- C:\WINDOWS\ERUNT
2007-07-31 13:16 <REP> d-------- C:\Program Files\Navilog1
2007-07-31 12:36 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-30 23:39 <REP> d-------- C:\WINDOWS\pss
2007-07-30 20:18 <REP> d-------- C:\Hijackthis
2007-07-30 10:52 12,417,543 --------- C:\AVG7QT.DAT
2007-07-29 20:01 31,232 -r-hs---- C:\WINDOWS\system32\msfDX.dll
2007-07-29 20:01 163,328 -r-hs---- C:\WINDOWS\system32\flvDX.dll
2007-07-29 20:01 <REP> d-------- C:\Program Files\eRightSoft
2007-07-29 18:48 719,872 --a------ C:\WINDOWS\system32\devil.dll
2007-07-29 18:48 70,656 --a------ C:\WINDOWS\system32\yv12vfw.dll
2007-07-29 18:48 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2007-07-29 18:48 66,560 --a------ C:\WINDOWS\MOTA113.exe
2007-07-29 18:48 394,240 --a------ C:\WINDOWS\system32\Smab.dll
2007-07-29 18:48 318,976 --a------ C:\WINDOWS\system32\avisynth.dll
2007-07-29 18:48 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2007-07-29 18:48 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2007-07-29 18:48 217,073 --a------ C:\WINDOWS\meta4.exe
2007-07-29 18:48 <REP> d-------- C:\Program Files\AviSynth 2.5
2007-07-29 16:52 61,440 --a------ C:\WINDOWS\system32\cygz.dll
2007-07-29 16:52 3,624,960 --a------ C:\WINDOWS\system32\mkgpmp.exe
2007-07-29 16:52 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2007-07-29 16:52 1,295,582 --a------ C:\WINDOWS\system32\cygwin1.dll
2007-07-29 16:51 167 --a------ C:\WINDOWS\system32\buyurl0502.dat
2007-07-28 15:31 <REP> d-------- C:\Temp
2007-07-28 15:22 <REP> d-------- C:\Program Files\Apple Software Update
2007-07-28 15:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-28 15:17 <REP> d-------- C:\Program Files\MediaInfo
2007-07-28 13:11 25,856 --a------ C:\WINDOWS\system32\drivers\hidbth.sys
2007-07-28 13:11 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-07-28 13:10 38,016 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2007-07-28 13:06 100,992 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2007-07-28 13:05 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2007-07-28 13:05 59,648 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2007-07-28 13:05 28,160 --a------ C:\WINDOWS\system32\irmon.dll
2007-07-28 13:05 274,944 --a------ C:\WINDOWS\system32\drivers\bthport.sys
2007-07-28 13:05 18,944 --a------ C:\WINDOWS\system32\drivers\BTHUSB.SYS
2007-07-28 13:05 17,024 --a------ C:\WINDOWS\system32\drivers\BthEnum.sys
2007-07-28 13:05 154,112 --a------ C:\WINDOWS\system32\irftp.exe
2007-07-22 20:54 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2007-07-22 20:42 <REP> d-------- C:\Program Files\Windows Live
2007-07-22 20:42 <REP> d-------- C:\Program Files\Messenger Plus! Live
2007-07-22 01:58 854,528 --a------ C:\WINDOWS\system32\Ltwvc12n.dll
2007-07-22 01:58 78,336 --a------ C:\WINDOWS\system32\LFFAX12n.DLL
2007-07-22 01:58 43,008 --a------ C:\WINDOWS\system32\lfgif12n.dll
2007-07-22 01:58 41,472 --a------ C:\WINDOWS\system32\LTTWN12n.DLL
2007-07-22 01:58 406,528 --a------ C:\WINDOWS\system32\LTKRN12n.DLL
2007-07-22 01:58 314,880 --a------ C:\WINDOWS\system32\LFCMP12n.DLL
2007-07-22 01:58 278,528 --a------ C:\WINDOWS\system32\LTDIS12n.DLL
2007-07-22 01:58 25,600 --a------ C:\WINDOWS\system32\lfavi12n.dll
2007-07-22 01:58 227,840 --a------ C:\WINDOWS\system32\LTEFX12n.DLL
2007-07-22 01:58 166,400 --a------ C:\WINDOWS\system32\LTIMG12n.DLL
2007-07-22 01:58 155,648 --a------ C:\WINDOWS\system32\LFTIF12n.DLL
2007-07-22 01:58 122,368 --a------ C:\WINDOWS\system32\LTFIL12n.DLL
2007-07-22 01:58 121,856 --a------ C:\WINDOWS\system32\lfmpg12n.dll
2007-07-22 01:58 10,940 --a------ C:\WINDOWS\system32\drivers\cdrbsvsd.sys
2007-07-22 01:58 <REP> d-------- C:\Program Files\Sony Corporation
2007-07-22 01:58 <REP> d-------- C:\Program Files\Fichiers communs\muvee Technologies
2007-07-21 12:00 5,376 --a------ C:\WINDOWS\system32\MSPCLOCK.sys
2007-07-21 11:55 6,097 --a------ C:\WINDOWS\system32\drivers\sonyhcb.sys
2007-07-21 11:55 53,248 --a------ C:\WINDOWS\system32\SONYHCY.DLL
2007-07-21 11:55 38,739 --a------ C:\WINDOWS\system32\drivers\sonyhcc.sys
2007-07-21 11:55 3,654 --a------ C:\WINDOWS\system32\drivers\Sonyhcp.dll
2007-07-21 11:55 299,923 --a------ C:\WINDOWS\system32\drivers\sonyhcs.sys
2007-07-21 11:55 102,220 --a------ C:\WINDOWS\system32\drivers\sonypvs1.sys
2007-07-21 11:55 <REP> d-------- C:\Drivers
2007-07-21 11:54 <REP> d-------- C:\USB_DRV
2007-07-21 11:38 <REP> d-------- C:\WINDOWS\RegisteredPackages
2007-07-19 08:29 <REP> d---s---- C:\WINDOWS\Downloaded Program Files
2007-07-16 23:15 <REP> d-------- C:\Program Files\DivX
2007-07-05 18:58 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-07-05 18:50 <REP> d-------- C:\WINDOWS\system32\fr-fr
2007-07-05 18:46 <REP> d-------- C:\WINDOWS\network diagnostic
2007-06-18 22:30 <REP> d-------- C:\Program Files\CFWebAdvancedU
2007-06-03 09:24 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TomTom
2007-06-03 09:23 <REP> d-------- C:\DOCUME~1\mansou\APPLIC~1\InstallShield
2007-06-02 20:32 <REP> d-------- C:\Program Files\Incomplete
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-31 16:19 --------- d-------- C:\Program Files\Wanadoo
2007-07-30 19:41 --------- d-------- C:\Program Files\MSN Messenger
2007-07-30 10:05 63750 --a------ C:\WINDOWS\system32\perfc00C.dat
2007-07-30 10:05 436526 --a------ C:\WINDOWS\system32\perfh00C.dat
2007-07-29 17:25 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-21 11:38 --------- d-------- C:\Program Files\Movie Maker
2007-07-05 18:56 --------- d-------- C:\Program Files\Windows Live Toolbar
2007-06-28 00:37 --------- d-------- C:\Program Files\BitComet
2007-06-18 12:04 19392 --a------ C:\DOCUME~1\mansou\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-06-08 10:24 --------- d-------- C:\Program Files\LimeWire
2007-06-03 09:24 --------- d-------- C:\Program Files\TomTom HOME
2007-05-16 17:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-17 22:29 278528 --a------ C:\Program Files\Fichiers communs\FDEUnInstaller.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49]
"SiSPower"="SiSPower.dll" [2004-09-02 14:47 C:\WINDOWS\system32\SiSPower.dll]
"MAAgent"="C:\Program Files\MarkAny\ContentSafer\MAAgent.exe" [2007-02-20 11:07]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-21 13:43]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-11-22 00:19]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-04-01 20:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 15:50]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2006-11-17 23:21:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 17:51 192512]
R0 gagp30kx;Filtre AGP version 3.0 g‚n‚rique Microsoft pour plates-formes … base de processeur K8;C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R1 AmdK8;Pilote de processeur AMD Athlon64;C:\WINDOWS\system32\DRIVERS\AmdK8.sys
R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 BthServ;Bluetooth Support Service;C:\WINDOWS\system32\svchost.exe -k bthsvcs
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
R3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
R3 USB_RNDIS;Inventel Gateway;C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 BthEnum;Pilote de bloc de demande Bluetooth;C:\WINDOWS\system32\DRIVERS\BthEnum.sys
S3 BTHMODEM;Pilote de communications modem Bluetooth;C:\WINDOWS\system32\DRIVERS\bthmodem.sys
S3 BthPan;P‚riph‚rique Bluetooth (r‚seau personnel);C:\WINDOWS\system32\DRIVERS\bthpan.sys
S3 BTHPORT;Pilote de port Bluetooth;C:\WINDOWS\system32\Drivers\BTHport.sys
S3 BTHUSB;Pilote USB radio Bluetooth;C:\WINDOWS\system32\Drivers\BTHUSB.sys
S3 HidBth;Miniport HID Microsoft Bluetooth;C:\WINDOWS\system32\DRIVERS\hidbth.sys
S3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\PCAMPR5.SYS
S3 RFCOMM;P‚riph‚rique Bluetooth (TDI protocole RFCOMM);C:\WINDOWS\system32\DRIVERS\rfcomm.sys
S3 SE27bus;Sony Ericsson Device 039 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE27bus.sys
S3 SE27mdfl;Sony Ericsson Device 039 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys
S3 SE27mdm;Sony Ericsson Device 039 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE27mdm.sys
S3 SE27mgmt;Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys
S3 se27nd5;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS);C:\WINDOWS\system32\DRIVERS\se27nd5.sys
S3 se27unic;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM);C:\WINDOWS\system32\DRIVERS\se27unic.sys
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ssm_bus.sys
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S3 V0080Dev;Creative Camera VF0080 Driver;C:\WINDOWS\system32\DRIVERS\V0080Dev.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cce287b0-11ab-11dc-9f82-00073a13310b}]
AutoRun\command- E:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f80ad30d-eaa0-11db-9f09-00073a13310b}]
AutoRun\command- E:\LaunchU3.exe -a
Contents of the 'Scheduled Tasks' folder
2007-07-28 13:23:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-07-31 13:52:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-31 16:27:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-31 16:28:30
--- E O F ---