Le post combofixt
ComboFix 08-01-23.1C - Quentin 2008-01-26 21:57:33.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1176 [GMT 1:00]
Endroit: C:\Documents and Settings\Quentin\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Quentin\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
FILE
C:\WINDOWS\system32\mjcjt.exe
C:\WINDOWS\system32\mucltui.dll.mu
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\mjcjt.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-26 to 2008-01-26 ))))))))))))))))))))))))))))))))))))
.
2008-01-26 12:36 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-26 09:19 . 2008-01-26 09:19 <REP> d-------- C:\Program Files\Trend Micro
2008-01-23 17:20 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-23 17:16 . 2008-01-25 20:28 <REP> d-------- C:\Program Files\Navilog1
2008-01-23 17:15 . 2008-01-23 17:15 180 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-01-22 18:51 . 2008-01-22 18:51 7,168 --ahs---- C:\WINDOWS\Thumbs.db
2008-01-22 18:19 . 2008-01-22 18:19 <REP> d-------- C:\WINDOWS\Sun
2008-01-22 18:19 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-01-22 18:18 . 2008-01-22 18:19 <REP> d-------- C:\Program Files\Java
2008-01-22 18:18 . 2008-01-22 18:18 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-01-21 14:33 . 2008-01-21 14:33 <REP> d-------- C:\Program Files\uTorrent
2008-01-20 20:26 . 2008-01-20 20:26 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-01-20 20:26 . 2008-01-20 20:26 <REP> d-------- C:\Program Files\flapkeepbolt
2008-01-20 20:26 . 2008-01-20 20:26 <REP> d-------- C:\Program Files\Circle Developement
2008-01-20 13:57 . 2008-01-20 13:57 135,168 --a------ C:\WINDOWS\system32\tei.exe
2008-01-17 19:27 . 2008-01-17 19:27 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-17 17:43 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-01-17 17:43 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-01-17 17:43 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-01-16 18:14 . 2008-01-23 18:46 <REP> d-------- C:\Program Files\Thoosje Sidebar V2.3
2008-01-16 17:58 . 2008-01-16 18:02 <REP> d-------- C:\Program Files\RegCleaner
2008-01-16 17:17 . 2008-01-16 17:17 <REP> d-------- C:\Program Files\Google
2008-01-16 16:52 . 2008-01-22 19:07 <REP> d-------- C:\Program Files\Windows Live
2008-01-16 16:52 . 2008-01-16 16:55 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-16 16:44 . 2008-01-16 16:44 65,019 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-01-16 16:41 . 2008-01-16 16:41 <REP> d-------- C:\WINDOWS\BricoPacks
2008-01-16 16:41 . 2008-01-16 16:44 6,118 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-01-14 18:15 . 2008-01-14 18:15 <REP> d-------- C:\Program Files\Ubi Soft
2008-01-14 10:41 . 2008-01-23 18:24 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-01-14 10:41 . 2008-01-23 18:24 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-01-14 10:41 . 2008-01-23 18:24 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-01-14 10:36 . 2008-01-23 17:59 949 --a------ C:\WINDOWS\disney.ini
2008-01-14 10:36 . 2008-01-23 18:20 199 --a------ C:\WINDOWS\disneysy.ini
2008-01-13 17:36 . 2008-01-13 17:36 118 --a------ C:\WINDOWS\system32\MRT.INI
2008-01-12 19:47 . 2008-01-12 19:47 <REP> d-------- C:\Program Files\Auran
2008-01-11 18:14 . 2008-01-13 16:59 <REP> d-------- C:\Program Files\Dofus
2008-01-11 17:45 . 2008-01-13 16:59 <REP> d-------- C:\Program Files\Ahead
2008-01-11 17:33 . 2008-01-13 16:59 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-01-11 17:32 . 2008-01-13 16:59 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-01-11 17:21 . 2006-03-17 11:45 1,757,184 --a------ C:\WINDOWS\system32\imagX7.dll
2008-01-11 17:21 . 2006-03-17 11:45 497,296 --a------ C:\WINDOWS\system32\imagXpr7.dll
2008-01-05 18:27 . 2008-01-16 16:44 2,359,350 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-01-05 18:25 . 2008-01-05 19:30 <REP> d-------- C:\WINDOWS\Packs
2008-01-04 22:59 . 2008-01-04 22:59 9,878 --a------ C:\WINDOWS\system32\dsm_fr.qm
2008-01-04 22:56 . 2008-01-04 22:56 8,835 --a------ C:\WINDOWS\system32\dpufr.qm
2008-01-04 22:56 . 2008-01-04 22:56 3,162 --a------ C:\WINDOWS\system32\dtu_fr.qm
2008-01-04 13:29 . 2003-11-04 15:11 159,744 --a------ C:\WINDOWS\system32\lfpng13n.dll
2007-12-29 20:10 . 2007-12-29 20:10 <REP> d-------- C:\Program Files\MSXML 4.0
2007-12-29 16:06 . 2007-12-29 17:41 <REP> d-------- C:\divx
2007-12-29 16:03 . 2008-01-13 16:58 <REP> d-------- C:\Program Files\DivX
2007-12-28 12:55 . 2008-01-23 18:13 <REP> d-------- C:\Program Files\Nero
2007-12-28 12:51 . 2007-12-29 11:46 <REP> d-------- C:\Program Files\AskTBar
2007-12-27 11:12 . 2005-01-31 11:04 2,180,096 --a------ C:\WINDOWS\system32\drivers\lvsvf2.sys
2007-12-27 11:12 . 2005-01-31 11:18 372,736 -ra------ C:\WINDOWS\system32\LVUI2RC.dll
2007-12-27 11:12 . 2005-01-31 11:20 211,712 -ra------ C:\WINDOWS\system32\drivers\LV561AV.SYS
2007-12-27 11:12 . 2005-01-31 11:10 204,800 -ra------ C:\WINDOWS\system32\LVUI2.dll
2007-12-27 11:12 . 2005-01-31 11:08 204,800 -ra------ C:\WINDOWS\system32\lvcodec2.dll
2007-12-27 11:12 . 2005-01-31 11:00 106,496 -ra------ C:\WINDOWS\system32\lvcoinst.dll
2007-12-27 11:12 . 2005-01-31 11:12 22,016 -ra------ C:\WINDOWS\system32\drivers\LVUSBSta.sys
2007-12-27 11:12 . 2005-01-31 09:37 9,255 -ra------ C:\WINDOWS\system32\lvcoinst.ini
2007-12-27 11:09 . 2007-12-27 11:09 <REP> d-------- C:\Program Files\Fichiers communs\FotoWire
2007-12-27 11:06 . 2007-12-27 11:09 <REP> d-------- C:\Program Files\Logitech
2007-12-27 10:53 . 2004-08-19 16:09 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-12-27 10:53 . 2004-08-19 16:09 54,784 --a--c--- C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-12-27 10:47 . 2007-12-27 10:47 <REP> d-------- C:\Program Files\Fichiers communs\Logitech
2007-12-27 10:47 . 1998-11-13 14:16 308,224 --a------ C:\WINDOWS\IsUn040c.exe
2007-12-27 10:47 . 2004-10-08 12:46 53,248 -ra------ C:\WINDOWS\system32\InstMed.exe
2007-12-27 10:47 . 2007-12-27 10:47 268 --a------ C:\WINDOWS\_delis32.ini
2007-12-26 09:11 . 2007-12-26 11:39 <REP> d-------- C:\Program Files\Omni
2007-12-26 09:11 . 2000-05-10 06:29 6,205 --a------ C:\WINDOWS\system32\LWBHMVXD.VXD
2007-12-26 09:11 . 2004-04-02 16:58 6,205 --a------ C:\WINDOWS\system32\KBDVX32A.VXD
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 17:09 --------- d-----w C:\Program Files\eMule
2008-01-17 16:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-14 09:26 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-01-05 21:59 --------- d-----w C:\Program Files\EA GAMES
2008-01-05 17:26 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-12-27 10:07 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.68-8876480L.exe
2007-12-21 08:09 --------- d-----w C:\Program Files\Wanadoo
2007-12-20 16:08 --------- d-----w C:\Program Files\Lavalys
2007-12-20 15:43 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2007-12-20 15:43 --------- d-----w C:\Program Files\Inventel
2007-12-20 15:33 --------- d-----w C:\Program Files\Securitoo
2007-12-20 12:44 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-16 17:00 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-12-15 16:47 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-15 13:13 --------- d-----w C:\Program Files\Croteam
2007-12-13 19:37 --------- d-----w C:\Program Files\Realtek
2007-12-13 19:15 --------- d-----w C:\Program Files\Alwil Software
2007-12-13 17:55 --------- d--h--w C:\Program Files\Uninstall Information
2007-12-13 17:47 558,142 ----a-w C:\WINDOWS\java\Packages\QICIKICR.ZIP
2007-12-13 17:47 155,995 ----a-w C:\WINDOWS\java\Packages\EIHNL39B.ZIP
2007-12-13 17:45 --------- d-----w C:\Program Files\Services en ligne
2007-12-13 17:45 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-12-13 00:40 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-12-13 00:40 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2007-11-29 22:30 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-29 22:30 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-29 22:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-11-29 22:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-11-29 22:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-11-29 22:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-11-29 22:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-11-29 22:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-11-29 22:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-11-28 21:55 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:53 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-11-28 21:53 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-11-28 21:53 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-11-28 21:53 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-11-28 21:53 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-11-28 21:52 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-26_13.03.05.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 11:36:57 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000001\NTUSER.DAT
+ 2008-01-26 20:57:24 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000001\NTUSER.DAT
- 2008-01-26 11:36:57 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000002\UsrClass.dat
+ 2008-01-26 20:57:24 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000002\UsrClass.dat
- 2008-01-26 11:36:57 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000003\NTUSER.DAT
+ 2008-01-26 20:57:24 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000003\NTUSER.DAT
- 2008-01-26 11:36:57 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000004\UsrClass.dat
+ 2008-01-26 20:57:24 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000004\UsrClass.dat
- 2008-01-26 11:36:57 3,067,904 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000005\NTUSER.DAT
+ 2008-01-26 20:57:24 3,067,904 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000005\NTUSER.DAT
- 2008-01-26 11:36:57 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000006\UsrClass.dat
+ 2008-01-26 20:57:24 147,456 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0/u0000006\UsrClass.dat
+ 2008-01-26 15:55:45 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2007-12-27 11:07 20480]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 17:07 196608]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [ ]
"EXIT BAT"="C:\DOCUME~1\Quentin\APPLIC~1\FLAPKE~1\Byte Itch 16.exe" [2008-01-20 20:26 448000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-20 14:32 8429568]
"nwiz"="nwiz.exe" [2007-04-20 14:32 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-20 14:32 81920]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 12:49 16269312 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 11:04 2879488 C:\WINDOWS\SkyTel.exe]
"LWBKEYBOARD"="C:\Program Files\Omni\Omni keyboard driver\5.0\KbdAp32A.exe" [2004-05-27 03:37 392704]
"LWBMOUSE"="C:\Program Files\Omni\OmniMouse Driver\4.06\MOUSE32A.EXE" [2001-11-09 07:47 356352]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"Base road long save"="C:\Documents and Settings\All Users\Application Data\File dvd base road\Wipe Enc.exe" [2008-01-26 16:57 1658368]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2007-02-16 01:50]
S2 y8ikijlpu7eeaveq;Print Spooler Service;C:\WINDOWS\system32\tei.exe [2008-01-20 13:57]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-01-26 21:00:01 C:\WINDOWS\Tasks\ADD76F629154E962.job"
- c:\docume~1\quentin\applic~1\flapke~1\Rdr Poke User.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 22:00:24
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-01-26 22:01:25
ComboFix-quarantined-files.txt 2008-01-26 21:01:05
ComboFix2.txt 2008-01-26 12:04:09
.
2008-01-17 18:27:49 --- E O F ---
je fais la suite