Voila:
ComboFix 08-04-20.5 - ATTALI 2008-04-22 0:26:41.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.104 [GMT 2:00]
Endroit: C:\Documents and Settings\ATTALI\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\sstem~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\auyhtmxm.dll
C:\WINDOWS\system32\bvslveus.dll
C:\WINDOWS\system32\dsvuqnap.dll
C:\WINDOWS\system32\elstcpfp.ini
C:\WINDOWS\system32\gdtubigk.ini
C:\WINDOWS\system32\isvxdciw.ini
C:\WINDOWS\system32\kgibutdg.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\npwslvoo.dll
C:\WINDOWS\system32\plcgtlik.dll
C:\WINDOWS\system32\qcjhqjgr.dll
C:\WINDOWS\system32\tnofnbjo.dll
C:\WINDOWS\system32\uwvwwxyb.ini
C:\WINDOWS\system32\uwvwwxyb.ini2
C:\WINDOWS\system32\vlhorfai.dll
C:\WINDOWS\system32\vxmrqyvh.dll
C:\WINDOWS\system32\vyevjewv.ini
C:\WINDOWS\system32\wprmwfos.dll
C:\WINDOWS\system32\wsxvmwkl.ini
C:\WINDOWS\system32\xcxkjvgl.ini
C:\WINDOWS\system32\yaobrvum.dll
C:\WINDOWS\system32\yhukchjh.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-21 to 2008-04-21 ))))))))))))))))))))))))))))))))))))
.
2008-04-21 22:43 . 2008-04-21 22:43 <REP> d-------- C:\Documents and Settings\ATTALI\Application Data\Malwarebytes
2008-04-21 22:40 . 2008-04-21 22:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-21 22:40 . 2008-04-21 22:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-21 16:58 . 2008-04-21 16:58 <REP> d-------- C:\Program Files\Trend Micro
2008-04-21 16:50 . 2008-04-21 16:59 9,089,599 --a------ C:\WINDOWS\system32\SBSP.dat
2008-04-21 16:50 . 2008-04-21 16:59 1,100 --a------ C:\WINDOWS\system32\SBFC.dat
2008-04-21 16:50 . 2008-04-21 16:51 104 --a------ C:\WINDOWS\system32\SBRC.dat
2008-04-20 14:00 . 2008-04-20 15:02 1,434 ---hs---- C:\WINDOWS\system32\shrfnojw.ini
2008-04-19 12:41 . 2008-04-20 13:55 1,314 ---hs---- C:\WINDOWS\system32\xoilpjyu.ini
2008-04-18 14:51 . 2008-04-18 14:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-18 14:51 . 2008-04-18 14:51 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-18 12:25 . 2008-04-19 12:41 594 ---hs---- C:\WINDOWS\system32\qcuflscp.ini
2008-04-17 18:30 . 2008-04-17 18:30 298,313 --a------ C:\WINDOWS\system32\gside.exe
2008-04-17 17:59 . 2008-04-17 17:59 <REP> d-------- C:\Documents and Settings\ATTALI\Application Data\Sunbelt Software
2008-04-17 17:59 . 2008-04-17 17:59 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
2008-04-17 17:58 . 2008-04-17 17:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
2008-04-17 12:24 . 2008-04-18 12:24 1,254 ---hs---- C:\WINDOWS\system32\xwhdibyx.ini
2008-04-17 09:32 . 2008-04-21 23:58 328,704 --------- C:\WINDOWS\system32\{848f2cad-99e4-cb47-4732-8dcf7f95f535}.dll
2008-04-16 12:56 . 2008-04-17 21:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:05 . 2008-04-16 12:05 105,536 --------- C:\WINDOWS\system32\jacncuch.dll_old
2008-04-16 12:04 . 2008-04-16 12:04 100,928 --------- C:\WINDOWS\system32\jduwdsub.dll_old
2008-04-16 10:53 . 2008-04-16 10:53 105,536 --------- C:\WINDOWS\system32\wtvievaf.dll_old
2008-04-16 10:47 . 2008-04-16 10:47 100,928 --------- C:\WINDOWS\system32\gbukjhxl.dll_old
2008-04-15 11:29 . 2008-04-15 11:29 105,536 --------- C:\WINDOWS\system32\ffqhhsfn.dll_old
2008-04-14 23:44 . 2008-04-16 13:02 <REP> d-------- C:\Program Files\SpywareBlaster
2008-04-14 23:03 . 2008-04-14 23:03 101,952 --------- C:\WINDOWS\system32\usbhswti.dll_old
2008-04-14 19:58 . 2008-04-14 19:58 106,560 --------- C:\WINDOWS\system32\iuqgixjq.dll_old
2008-04-14 19:52 . 2008-04-14 19:52 101,952 --------- C:\WINDOWS\system32\lvjguwfa.dll_old
2008-04-14 18:09 . 2008-04-16 12:56 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconFR.ico
2008-04-14 10:51 . 2008-04-14 10:51 106,560 --------- C:\WINDOWS\system32\jlauvvtw.dll_old
2008-04-14 10:47 . 2008-04-21 22:51 109,785 --a------ C:\WINDOWS\BMe7fd6679.xml
2008-04-14 10:46 . 2008-04-14 10:46 101,952 --------- C:\WINDOWS\system32\irskxpmn.dll_old
2008-04-14 00:27 . 2008-04-14 00:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
2008-04-13 21:30 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-04-13 21:30 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-04-13 21:30 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-04-13 21:30 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-04-13 21:30 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-04-13 21:30 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-04-13 21:30 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-04-13 21:30 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-04-13 17:43 . 2008-04-21 23:58 372,224 --------- C:\WINDOWS\system32\byxwwvwu.dll
2008-04-13 17:41 . 2008-04-13 17:41 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-04-13 17:39 . 2008-04-21 14:26 936 --a------ C:\WINDOWS\system32\winpfz33.sys
2008-04-13 17:38 . 2008-04-13 17:38 <REP> d-------- C:\WINDOWS\system32\MId2
2008-04-13 17:38 . 2008-04-17 20:48 <REP> d-------- C:\WINDOWS\system32\dtmp
2008-04-13 17:38 . 2008-04-13 17:38 <REP> d-------- C:\WINDOWS\system32\BL
2008-04-13 17:38 . 2008-04-13 17:38 <REP> d-------- C:\Temp\wdlw14
2008-04-13 17:38 . 2008-04-22 00:26 <REP> d-------- C:\Temp
2008-04-13 17:38 . 2008-04-13 17:38 400,571 --a------ C:\WINDOWS\system32\g4.exe
2008-04-13 17:38 . 2008-04-21 14:28 63,890 --a------ C:\WINDOWS\system32\{848f2cad-99e4-cb47-4732-8dcf7f95f535}.dll-uninst.exe
2008-04-13 17:37 . 2008-04-21 23:58 31,232 --------- C:\WINDOWS\system32\jkkiiffd.dll
2008-04-13 17:30 . 2008-04-13 17:30 <REP> d-------- C:\Program Files\VSO
2008-04-13 17:30 . 2008-04-14 11:07 <REP> d-------- C:\Documents and Settings\ATTALI\Application Data\Vso
2008-04-13 17:30 . 2004-05-04 11:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-04-13 17:30 . 2006-05-20 16:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-04-13 17:30 . 2006-05-11 19:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-04-13 17:30 . 2006-09-29 12:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-04-13 17:30 . 2006-09-29 12:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-04-13 17:30 . 2006-09-29 12:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-04-13 17:30 . 2008-04-13 17:30 87,608 --a------ C:\Documents and Settings\ATTALI\Application Data\inst.exe
2008-04-13 17:30 . 2007-03-18 20:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-04-13 17:30 . 2008-04-13 17:30 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-04-13 17:30 . 2008-04-13 17:30 47,360 --a------ C:\Documents and Settings\ATTALI\Application Data\pcouffin.sys
2008-04-13 17:25 . 2008-04-17 12:19 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-13 17:25 . 2008-04-13 17:37 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-04-13 17:17 . 2008-04-13 17:17 715,248 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-04-13 17:00 . 2008-04-16 12:07 <REP> d-------- C:\Documents and Settings\ATTALI\Application Data\LimeWire
2008-04-11 17:46 . 2008-04-21 23:58 334,848 --------- C:\WINDOWS\system32\myss_sb.dll
2008-03-24 12:09 . 2008-03-24 12:09 <REP> d-------- C:\WINDOWS\Sun
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 10:22 --------- d-----w C:\Program Files\Common Files
2008-04-13 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-09 18:17 --------- d-----w C:\Program Files\Java
2006-09-15 08:37 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
1992-03-10 00:10 94,720 ----a-w C:\Program Files\CARDFILE.EXE
1992-03-10 00:10 60,128 ----a-w C:\Program Files\CALENDAR.EXE
2006-09-14 20:57 56 --sh--r C:\WINDOWS\system32\21EB4DD478.sys
2006-09-14 20:57 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{613E1039-2493-4493-84E3-2E8E21F6FA5E}]
2008-04-21 23:58 372224 --------- C:\WINDOWS\system32\byxwwvwu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"Orange Desktop Search"="C:\Program Files\Orange HSS\Orange Desktop Search\OrangeDesktopSearch.exe" [2006-11-02 16:08 4937512]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-01 13:23 68856]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"Zpe"="C:\Program Files\Common Files\??sks\n?tdde.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2005-09-06 05:10 450560]
"VTTimer"="VTTimer.exe" [2005-03-07 21:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-10-31 22:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2004-10-11 08:54 589824]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"PE2CKFNT SE"="C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 12:51 25088]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 12:05 212992]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"ORAHSSStartup"="C:\Program Files\OrangeHSS\Launcher\Launcher.exe" [2007-01-04 11:40 462848]
"SystrayORAHSS"="C:\Program Files\OrangeHSS\Systray\SystrayApp.exe" [2007-01-04 11:45 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"g]eeV\mWhjlnspB"="C:\WINDOWS\system32\ocntokdn.exe" [ ]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [ ]
"SBRegRebootCleaner"="C:\Program Files\Sunbelt Software\CounterSpy\SBRC.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"= 64 (0x40)
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"Windows Printing Driver"= WinSpooler.exe
"WinUpdating"= WinUpdating.exe
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"= 64 (0x40)
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
"C:\\Documents and Settings\\ATTALI\\Application Data\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys []
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c6dc0ae-306d-11dc-bfff-001617209024}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7b947ee-0ba3-11dd-80fa-001617209024}]
\Shell\Auto\command - G:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c7b947ef-0ba3-11dd-80fa-001617209024}]
\Shell\Auto\command - H:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-18 11:41:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-22 00:30:10
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"g]eeV\\mWhjlnspB"="C:\\WINDOWS\\system32\\ocntokdn.exe DWram"
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\VSO\McShield.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\VSO\mcvsftsn.exe
C:\Program Files\OrangeHSS\Deskboard\Deskboard.exe
C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe
C:\Program Files\OrangeHSS\Connectivity\corecom\CoreCom.exe
C:\Program Files\OrangeHSS\Connectivity\corecom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\[u]0/u\FTCOMModule.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-22 0:35:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-21 22:34:54
Pre-Run: 27,993,948,160 octets libres
Post-Run: 28,010,938,368 octets libres
236