ComboFix 07-12-02.6 - aubouin 2007-12-04 18:33:26.1 - NTFSx86
Running from: C:\Documents and Settings\aubouin\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\moviebox
C:\Program Files\moviebox\Uninstall.exe
C:\WINDOWS\mrofinu880.exe
C:\WINDOWS\system32\baartcuf.dll
C:\WINDOWS\system32\bbeeg.bak1
C:\WINDOWS\system32\bbeeg.bak2
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\bbeeg.tmp
C:\WINDOWS\system32\bmxcqail.dll
C:\WINDOWS\system32\ehtnptfg.dll
C:\WINDOWS\system32\evrjphfe.dll
C:\WINDOWS\system32\fgpgrdbr.dll
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\gmefngje.dll
C:\WINDOWS\system32\gttxwcwo.dll
C:\WINDOWS\system32\gygcnmoh.dll
C:\WINDOWS\system32\homncgyg.ini
C:\WINDOWS\system32\hvuttfkp.dll
C:\WINDOWS\system32\hxmqgeng.dll
C:\WINDOWS\system32\lqpbcvve.dll
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\mrdavydn.dll
C:\WINDOWS\system32\vsddlvqv.dll
C:\WINDOWS\system32\wqeopqly.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-04 to 2007-12-04 ))))))))))))))))))))))))))))))))))))
.
2007-12-04 17:15 . 2007-12-04 17:56 <REP> d-------- C:\VundoFix Backups
2007-12-04 17:13 . 2007-12-04 17:57 <REP> d-------- C:\hijackthis
2007-12-04 17:09 . 2007-12-04 17:09 <REP> d-------- C:\Program Files\Trend Micro
2007-12-03 21:01 . 2007-12-04 16:32 808,579 ---hs---- C:\WINDOWS\system32\ouumroir.ini
2007-12-03 16:50 . 2007-12-03 16:50 <REP> d-------- C:\WINDOWS\report
2007-12-03 16:49 . 2007-12-03 16:49 <REP> d-------- C:\WINDOWS\AU_Backup
2007-12-03 16:49 . 2007-12-03 16:49 39,811,417 --a------ C:\WINDOWS\VPTNFILE.857
2007-12-03 16:49 . 2007-12-03 16:49 39,811,417 --a------ C:\WINDOWS\LPT$VPN.857
2007-12-03 16:49 . 2007-12-03 16:49 1,899,383 --a------ C:\WINDOWS\tsc.ptn
2007-12-03 16:49 . 2007-12-03 16:49 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-12-03 16:49 . 2007-12-03 16:49 267,845 --a------ C:\WINDOWS\tsc.exe
2007-12-03 16:49 . 2007-12-03 16:49 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-12-03 16:49 . 2007-12-03 16:49 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-12-03 16:49 . 2007-12-03 17:45 823 --a------ C:\WINDOWS\tsc.ini
2007-12-03 16:47 . 2007-12-03 16:49 <REP> d-------- C:\WINDOWS\AU_Temp
2007-12-03 16:47 . 2007-12-03 16:47 <REP> d-------- C:\WINDOWS\AU_Log
2007-12-03 16:47 . 2007-12-03 16:47 170 --a------ C:\WINDOWS\GetServer.ini
2007-12-03 16:46 . 2007-12-03 16:46 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-12-03 16:46 . 2007-12-03 16:46 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-12-03 16:46 . 2007-12-03 16:46 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-12-03 16:23 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-12-03 16:23 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-12-03 16:23 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-12-02 19:51 . 2007-12-02 19:51 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-12-02 19:49 . 2007-12-02 19:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-02 19:35 . 2007-12-02 19:37 <REP> d-------- C:\WINDOWS\system32\fr-fr
2007-12-02 19:16 . 2007-12-02 19:38 1,374 --a------ C:\WINDOWS\imsins.BAK
2007-12-02 19:14 . 2007-08-20 10:59 6,058,496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-02 19:14 . 2007-04-17 10:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-02 19:14 . 2007-03-08 06:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-02 19:14 . 2007-08-20 10:59 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-02 19:14 . 2007-08-20 10:59 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-02 19:14 . 2007-08-20 10:59 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-02 19:14 . 2007-08-20 10:59 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-02 19:14 . 2007-08-20 10:59 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-02 19:14 . 2006-10-27 15:09 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2007-12-02 19:14 . 2007-08-17 11:20 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-01 10:31 . 2007-12-01 10:31 <REP> d-------- C:\Program Files\Guitar Pro 5
2007-11-30 17:34 . 2007-11-30 17:34 <REP> d-------- C:\Team17
2007-11-27 17:14 . 2007-11-30 17:56 <REP> d-------- C:\Liero Xtreme
2007-11-27 16:35 . 2007-11-27 16:35 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\Uniblue
2007-11-26 21:30 . 2007-11-26 21:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-26 21:19 . 2007-11-26 21:19 <REP> d-------- C:\Program Files\CCleaner
2007-11-25 18:09 . 2007-11-25 18:08 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-11-25 18:09 . 2007-11-25 18:09 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-25 18:08 . 2007-11-25 18:08 <REP> d-------- C:\WINDOWS\system32\LogFiles
2007-11-25 18:08 . 2007-11-25 18:08 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-11-25 17:34 . 2007-11-27 16:24 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-25 17:34 . 2007-11-25 17:34 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\SUPERAntiSpyware.com
2007-11-25 17:34 . 2007-11-25 17:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-24 19:50 . 2007-11-24 19:50 <REP> d-------- C:\etmain
2007-11-24 19:50 . 2007-11-24 19:50 <REP> d-------- C:\Creations [RW]
2007-11-24 19:50 . 2007-11-24 19:50 49,891 --a------ C:\Uninstal.exe
2007-11-24 12:34 . 2007-11-24 12:37 <REP> d-------- C:\Documents and Settings\aubouin\Citrix
2007-11-24 12:34 . 2007-11-24 12:34 81 --a------ C:\CTX.DAT
2007-11-24 12:29 . 2007-11-24 12:29 <REP> d-------- C:\WINDOWS\system32\Resource
2007-11-24 12:29 . 2007-11-24 12:29 <REP> d-------- C:\Program Files\Citrix
2007-11-24 11:58 . 2007-11-24 11:58 <REP> d-------- C:\Documents and Settings\aubouin\.tuxguitar
2007-11-24 11:57 . 2007-11-24 11:57 <REP> d-------- C:\Program Files\tuxguitar-0.9.1
2007-11-23 16:38 . 2007-11-23 16:40 <REP> d-------- C:\WINDOWS\$regcmp$
2007-11-21 20:57 . 2007-11-21 20:57 <REP> d-------- C:\Program Files\Musicmatch
2007-11-21 20:57 . 2007-11-21 20:57 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\Musicmatch
2007-11-21 20:57 . 2005-05-10 15:04 503,808 --a------ C:\WINDOWS\system32\msvc563d.rra
2007-11-21 19:24 . 2007-11-21 19:24 <REP> d-------- C:\Program Files\Registry Clean Expert
2007-11-18 14:10 . 2007-11-18 14:10 <REP> d-------- C:\OEMCUST
2007-11-11 16:55 . 2007-11-11 16:55 32 --a------ C:\WINDOWS\banana.ini
2007-11-10 20:51 . 2007-11-11 11:12 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\Shareaza
2007-11-10 19:15 . 2007-12-04 18:10 <REP> d-------- C:\Program Files\Best_Security_Tips
2007-11-10 19:14 . 2007-11-23 19:51 0 --a------ C:\WINDOWS\system32\efcdedb.dll
2007-11-10 19:13 . 2007-11-23 19:51 0 --a------ C:\WINDOWS\system32\rqrstrr.dll
2007-11-05 20:17 . 2007-11-30 16:34 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\DMCache
2007-11-05 17:38 . 2007-11-05 17:38 <REP> d-------- C:\soldatmapmaker
2007-11-05 14:53 . 2007-12-01 19:29 <REP> d-------- C:\Program Files\World of Warcraft
2007-11-05 11:18 . 2007-11-05 11:18 <REP> d-------- C:\Program Files\RPG Maker 2003
2007-11-04 18:58 . 2007-11-04 18:58 <REP> d-------- C:\Documents and Settings\aubouin\Application Data\Soldat
2007-11-04 12:01 . 2007-11-11 11:12 <REP> d-------- C:\Program Files\Shareaza
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 17:49 --------- d-----w C:\Program Files\Packard Bell EverSafe
2007-12-04 17:41 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-04 15:41 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-12-03 20:43 --------- d-----w C:\Program Files\Microsoft SQL Server
2007-12-02 19:24 --------- d-----w C:\Documents and Settings\aubouin\Application Data\uTorrent
2007-12-02 19:24 --------- d-----w C:\Documents and Settings\aubouin\Application Data\LimeWire
2007-12-02 19:24 --------- d-----w C:\Documents and Settings\aubouin\Application Data\Azureus
2007-12-02 19:23 --------- d-----w C:\Documents and Settings\aubouin\Application Data\Canon
2007-12-02 18:50 --------- d-----w C:\Program Files\Windows Live
2007-11-30 16:35 --------- d-----w C:\Program Files\directx
2007-11-26 20:19 --------- d-----w C:\Program Files\Yahoo!
2007-11-25 16:33 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-11-24 18:16 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
2007-11-22 18:14 --------- d-----w C:\Program Files\Norton Internet Security
2007-11-21 19:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-11 17:54 --------- d-----w C:\Program Files\Street Fighter Online
2007-11-10 18:18 --------- d-----w C:\Program Files\Tweak-XP Pro 4
2007-11-10 18:15 --------- d-----w C:\Program Files\Common Files
2007-11-05 21:09 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2007-11-04 11:14 10 ----a-w C:\Program Files\.autoreg
2007-10-31 11:12 --------- d-----w C:\Program Files\Game Vindicator
2007-10-31 08:31 --------- d-s---w C:\Program Files\Xfire
2007-10-30 17:03 --------- d-----w C:\Documents and Settings\aubouin\Application Data\Xfire
2007-10-30 16:44 --------- d-----w C:\Documents and Settings\aubouin\Application Data\Bioshock
2007-10-30 16:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-10-30 16:20 --------- d-----w C:\Program Files\GALA-NET
2007-10-30 10:16 --------- d-----w C:\Program Files\Bodom-Child - RaBBi
2007-10-29 18:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-10-29 17:58 --------- d-----w C:\Program Files\MSN Messenger
2007-10-29 17:58 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-10-29 14:19 --------- d--h--r C:\Documents and Settings\aubouin\Application Data\SecuROM
2007-10-29 14:19 --------- d-----w C:\Program Files\BoontyGames
2007-10-29 10:31 --------- d-----w C:\Program Files\Sauerbraten
2007-10-29 09:39 --------- d-----w C:\Program Files\Mario Forever
2007-10-22 19:53 --------- d-----w C:\Documents and Settings\aubouin\Application Data\EPSON
2007-10-21 17:16 --------- d-----w C:\Program Files\Diablo II
2007-10-21 17:15 --------- d-----w C:\Program Files\Fichiers communs\WhenU
2007-10-21 17:14 --------- d-----w C:\Program Files\Azureus
2007-10-21 17:05 --------- d-----w C:\Program Files\The All-Seeing Eye
2007-10-21 16:57 --------- d-----w C:\Documents and Settings\aubouin\Application Data\Hamachi
2007-10-21 16:49 26,056 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2007-10-21 16:10 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-10-20 11:16 --------- d-----w C:\Program Files\CDBurnerXP Pro 3
2007-10-20 09:46 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-10-20 09:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2007-10-20 09:40 --------- d-----w C:\Program Files\EPSON
2007-10-20 09:37 --------- d-----w C:\Documents and Settings\aubouin\Application Data\InstallShield
2007-10-20 09:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON
2007-10-17 18:26 --------- d-----w C:\Program Files\Auralog
2007-10-17 11:51 --------- d-----w C:\Program Files\Mindscape
2007-10-10 12:52 --------- d-----w C:\Program Files\Micro Application
2007-10-07 08:49 --------- d-----w C:\Documents and Settings\aubouin\Application Data\DivX
2007-10-07 08:46 --------- d-----w C:\Program Files\Google
2007-10-05 15:48 --------- d-----w C:\Documents and Settings\aubouin\Application Data\OpenArena
2007-10-05 14:24 --------- d-----w C:\Program Files\Warcraft III
2007-08-21 07:33 87,608 -c--a-w C:\Documents and Settings\aubouin\Application Data\ezpinst.exe
2007-08-21 07:33 47,360 -c--a-w C:\Documents and Settings\aubouin\Application Data\pcouffin.sys
2007-08-11 20:00 39,560 ----a-w C:\Documents and Settings\aubouin\Application Data\GDIPFONTCACHEV1.DAT
2005-05-13 15:12 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-10-24 09:13 66,560 --sha-r C:\WINDOWS\MOTA113.exe
2005-10-13 19:27 422,400 --sha-r C:\WINDOWS\x2.64.exe
2005-10-07 17:14 308,224 --sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 10:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 13:32 616,448 --sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 08:24 2,945,024 --sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 11:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"Update Service"="C:\PROGRA~1\FICHIE~1\TEKNUM~1\update.exe" [2004-02-11 15:23]
"EPSON Stylus DX4400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.exe" [2007-03-01 07:01]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 21:10]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31]
"NovaNet-WEB Tray Control"="C:\Program Files\Packard Bell EverSafe\TrayControl.exe" [2003-07-21 14:20]
"VCSPlayer"="C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" [2003-08-13 10:33]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-06-06 20:41]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-22 11:08]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 00:12]
"Realtime Audio Engine"="mmrtkrnl.exe" [2002-04-29 21:22 C:\WINDOWS\system32\MMRTKRNL.EXE]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 09:22]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-04 12:07]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-08-03 16:29]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
"DisableChangePassword"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R0 Ramdisk;Ramdisk Driver;C:\WINDOWS\system32\DRIVERS\ramdsk.sys
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys
R1 vcsmpdrv;vcsmpdrv;C:\WINDOWS\system32\DRIVERS\vcsmpdrv.sys
R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys
S3 adiusbae;USB ADSL LAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbae.sys
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
S3 sony_ssm.sys;sony_ssm.sys;\??\C:\DOCUME~1\aubouin\LOCALS~1\Temp\sony_ssm.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-11-30 18:01:04 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-30 19:00:24 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - aubouin.job"
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-04 18:50:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-04 18:53:38 - machine was rebooted
.
--- E O F ---
et dernier rapport bonne chance et merci de m' aider