slt
oila le rapport apre combofix
ComboFix 08-05-15.3 - user 2008-05-19 10:20:03.2 - [color=red][b]FAT32
/b/colorx86
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
/b/color
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\1047747.exe
C:\WINDOWS\system32\104e027.exe
C:\WINDOWS\system32\104e9b3.exe
C:\WINDOWS\system32\11a4c18.exe
C:\WINDOWS\system32\11aa62f.exe
C:\WINDOWS\system32\11aaf2e.exe
C:\WINDOWS\system32\12fd4bf.exe
C:\WINDOWS\system32\12ff16c.exe
C:\WINDOWS\system32\130007b.exe
C:\WINDOWS\system32\1451616.exe
C:\WINDOWS\system32\14533e5.exe
C:\WINDOWS\system32\14548a1.exe
C:\WINDOWS\system32\14551be.exe
C:\WINDOWS\system32\15a8f72.exe
C:\WINDOWS\system32\15aaeb3.exe
C:\WINDOWS\system32\15ab8df.exe
C:\WINDOWS\system32\15db6d.exe
C:\WINDOWS\system32\15fb27.exe
C:\WINDOWS\system32\165d61.exe
C:\WINDOWS\system32\1677dd.exe
C:\WINDOWS\system32\169f73.exe
C:\WINDOWS\system32\16fef2e.exe
C:\WINDOWS\system32\17017dd.exe
C:\WINDOWS\system32\1702104.exe
C:\WINDOWS\system32\17b65e.exe
C:\WINDOWS\system32\17e2d8.exe
C:\WINDOWS\system32\180513.exe
C:\WINDOWS\system32\18274e.exe
C:\WINDOWS\system32\183595.exe
C:\WINDOWS\system32\184dc2.exe
C:\WINDOWS\system32\1854450.exe
C:\WINDOWS\system32\185b5fe.exe
C:\WINDOWS\system32\18637f2.exe
C:\WINDOWS\system32\19bf338.exe
C:\WINDOWS\system32\19bffbd.exe
C:\WINDOWS\system32\19c1613.exe
C:\WINDOWS\system32\1b4214.exe
C:\WINDOWS\system32\1b64e5.exe
C:\WINDOWS\system32\1b6ea3.exe
C:\WINDOWS\system32\2bc3ce.exe
C:\WINDOWS\system32\2bd11b.exe
C:\WINDOWS\system32\2bdace.exe
C:\WINDOWS\system32\2c2431.exe
C:\WINDOWS\system32\2c3495.exe
C:\WINDOWS\system32\2d6d92.exe
C:\WINDOWS\system32\2d7a99.exe
C:\WINDOWS\system32\2d8605.exe
C:\WINDOWS\system32\2d873c.exe
C:\WINDOWS\system32\2d9b43.exe
C:\WINDOWS\system32\2da818.exe
C:\WINDOWS\system32\343caa.exe
C:\WINDOWS\system32\34c45e.exe
C:\WINDOWS\system32\34dabe.exe
C:\WINDOWS\system32\40f1aa.exe
C:\WINDOWS\system32\40ff0a.exe
C:\WINDOWS\system32\410850.exe
C:\WINDOWS\system32\415922.exe
C:\WINDOWS\system32\4191bc.exe
C:\WINDOWS\system32\41a126.exe
C:\WINDOWS\system32\41aa4e.exe
C:\WINDOWS\system32\429414.exe
C:\WINDOWS\system32\42bbe6.exe
C:\WINDOWS\system32\430d4e.exe
C:\WINDOWS\system32\431662.exe
C:\WINDOWS\system32\49db9e.exe
C:\WINDOWS\system32\49fa85.exe
C:\WINDOWS\system32\4a1731.exe
C:\WINDOWS\system32\56210c.exe
C:\WINDOWS\system32\562e81.exe
C:\WINDOWS\system32\5637da.exe
C:\WINDOWS\system32\577272.exe
C:\WINDOWS\system32\5787ec.exe
C:\WINDOWS\system32\580ab2.exe
C:\WINDOWS\system32\5814d4.exe
C:\WINDOWS\system32\588754.exe
C:\WINDOWS\system32\58be7c.exe
C:\WINDOWS\system32\58c7ae.exe
C:\WINDOWS\system32\6b53b8.exe
C:\WINDOWS\system32\6b6122.exe
C:\WINDOWS\system32\6b6a54.exe
C:\WINDOWS\system32\6ccd22.exe
C:\WINDOWS\system32\6cd9f7.exe
C:\WINDOWS\system32\6ce301.exe
C:\WINDOWS\system32\808934.exe
C:\WINDOWS\system32\8098c6.exe
C:\WINDOWS\system32\80a2b6.exe
C:\WINDOWS\system32\81fab8.exe
C:\WINDOWS\system32\822f7e.exe
C:\WINDOWS\system32\823fc4.exe
C:\WINDOWS\system32\95c092.exe
C:\WINDOWS\system32\95cebb.exe
C:\WINDOWS\system32\95d85a.exe
C:\WINDOWS\system32\97935f.exe
C:\WINDOWS\system32\97a0a2.exe
C:\WINDOWS\system32\97a9e8.exe
C:\WINDOWS\system32\ab0102.exe
C:\WINDOWS\system32\ab0e63.exe
C:\WINDOWS\system32\ab185d.exe
C:\WINDOWS\system32\accdac.exe
C:\WINDOWS\system32\acef64.exe
C:\WINDOWS\system32\ad0542.exe
C:\WINDOWS\system32\c075fc.exe
C:\WINDOWS\system32\c083ad.exe
C:\WINDOWS\system32\c08d93.exe
C:\WINDOWS\system32\c22960.exe
C:\WINDOWS\system32\c239cf.exe
C:\WINDOWS\system32\c2444a.exe
C:\WINDOWS\system32\d61edf.exe
C:\WINDOWS\system32\d639f1.exe
C:\WINDOWS\system32\d6441d.exe
C:\WINDOWS\system32\wmdrtc32.dl_
C:\WINDOWS\system32\wmdrtc32.dll
.
---- Previous Run -------
.
C:\autorun.inf
C:\WINDOWS\MS32DLL.dll.vbs
C:\WINDOWS\svchost.exe
C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\1061e1c.exe
C:\WINDOWS\system32\10631b6.exe
C:\WINDOWS\system32\1064924.exe
C:\WINDOWS\system32\11bba3f.exe
C:\WINDOWS\system32\1313a19.exe
C:\WINDOWS\system32\1315585.exe
C:\WINDOWS\system32\13e3c6.exe
C:\WINDOWS\system32\15b8364.exe
C:\WINDOWS\system32\16593c.exe
C:\WINDOWS\system32\16957a.exe
C:\WINDOWS\system32\169e8d.exe
C:\WINDOWS\system32\1712af2.exe
C:\WINDOWS\system32\1867458.exe
C:\WINDOWS\system32\18681d7.exe
C:\WINDOWS\system32\1c63a2a.exe
C:\WINDOWS\system32\1db9aff.exe
C:\WINDOWS\system32\1f13c23.exe
C:\WINDOWS\system32\2072a76.exe
C:\WINDOWS\system32\228207.exe
C:\WINDOWS\system32\26bd9e.exe
C:\WINDOWS\system32\26d8a6.exe
C:\WINDOWS\system32\26e4ef.exe
C:\WINDOWS\system32\28adb9.exe
C:\WINDOWS\system32\290a01.exe
C:\WINDOWS\system32\292653.exe
C:\WINDOWS\system32\3e5046.exe
C:\WINDOWS\system32\3e7764.exe
C:\WINDOWS\system32\4d10a4.exe
C:\WINDOWS\system32\531298.exe
C:\WINDOWS\system32\531f1d.exe
C:\WINDOWS\system32\543dda.exe
C:\WINDOWS\system32\614199.exe
C:\WINDOWS\system32\615fae.exe
C:\WINDOWS\system32\625f8e.exe
C:\WINDOWS\system32\779528.exe
C:\WINDOWS\system32\77b044.exe
C:\WINDOWS\system32\902846.exe
C:\WINDOWS\system32\904e1a.exe
C:\WINDOWS\system32\905b03.exe
C:\WINDOWS\system32\9b1b90.exe
C:\WINDOWS\system32\9b31d2.exe
C:\WINDOWS\system32\9b3b36.exe
C:\WINDOWS\system32\a5a47d.exe
C:\WINDOWS\system32\a5f78a.exe
C:\WINDOWS\system32\a608d4.exe
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\b07afc.exe
C:\WINDOWS\system32\b0a080.exe
C:\WINDOWS\system32\b0b257.exe
C:\WINDOWS\system32\b6d0bb.exe
C:\WINDOWS\system32\bb6e78.exe
C:\WINDOWS\system32\bc012a.exe
C:\WINDOWS\system32\bc0af2.exe
C:\WINDOWS\system32\bcff5.exe
C:\WINDOWS\system32\d909c.exe
C:\WINDOWS\system32\e759dd.exe
C:\WINDOWS\system32\e82ca3.exe
C:\WINDOWS\system32\e88493.exe
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\f0a34e.exe
C:\WINDOWS\system32\f0b2ae.exe
C:\WINDOWS\system32\fe1702.exe
C:\WINDOWS\system32\fe2e5c.exe
C:\WINDOWS\system32\fe39a1.exe
C:\WINDOWS\system32\wmdrtc32.dl_
C:\WINDOWS\system32\wmdrtc32.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-19 to 2008-05-19 )))))))))))))))))))))))))))))))
.
2008-05-19 10:00 . 2008-05-19 10:00 7,168 --a------ C:\WINDOWS\system32\583ccf.exe
2008-05-19 09:13 . 2008-05-19 09:13 7,168 --a------ C:\WINDOWS\system32\2d52c7.exe
2008-05-19 08:49 . 2008-05-19 08:49 7,168 --a------ C:\WINDOWS\system32\17a102.exe
2008-05-19 08:25 . 2008-05-19 08:25 <DIR> d--hs---- C:\FOUND.019
2008-05-19 05:53 . 2008-05-19 05:53 7,168 --a------ C:\WINDOWS\system32\c06b9e.exe
2008-05-19 05:30 . 2008-05-19 05:30 7,168 --a------ C:\WINDOWS\system32\aaec5b.exe
2008-05-19 05:06 . 2008-05-19 05:06 7,168 --a------ C:\WINDOWS\system32\95b06a.exe
2008-05-19 04:43 . 2008-05-19 04:43 7,168 --a------ C:\WINDOWS\system32\807cc4.exe
2008-05-19 04:20 . 2008-05-19 04:20 7,168 --a------ C:\WINDOWS\system32\6b448a.exe
2008-05-19 03:57 . 2008-05-19 03:57 7,168 --a------ C:\WINDOWS\system32\5614a5.exe
2008-05-19 03:34 . 2008-05-19 03:34 7,168 --a------ C:\WINDOWS\system32\40e6c0.exe
2008-05-19 03:11 . 2008-05-19 03:11 7,168 --a------ C:\WINDOWS\system32\2bb5ff.exe
2008-05-19 02:47 . 2008-05-19 02:47 7,168 --a------ C:\WINDOWS\system32\15d2aa.exe
2008-05-19 02:19 . 2008-05-19 02:19 <DIR> d--hs---- C:\FOUND.018
2008-05-19 01:52 . 2008-05-19 01:52 1,024 --a------ C:\WINDOWS\system32\30a09a.exe
2008-05-19 01:28 . 2008-05-19 01:28 7,168 --a------ C:\WINDOWS\system32\1b191f.exe
2008-05-18 14:15 . 2008-05-18 14:15 7,168 --a------ C:\WINDOWS\system32\577a81.exe
2008-05-18 13:29 . 2008-05-18 13:29 7,168 --a------ C:\WINDOWS\system32\2d3168.exe
2008-05-18 13:04 . 2008-05-18 13:06 7,168 --a------ C:\WINDOWS\system32\15d66b.exe
2008-05-18 11:54 . 2008-05-18 11:54 <DIR> d-------- C:\Documents and Settings\user\Application Data\ErrorSmart
2008-05-18 11:53 . 2008-05-18 11:53 <DIR> d-------- C:\Program Files\ErrorSmart
2008-05-18 11:40 . 2008-05-18 11:40 7,168 --a------ C:\WINDOWS\system32\19be587.exe
2008-05-18 11:15 . 2008-05-18 11:15 7,168 --a------ C:\WINDOWS\system32\1852e2c.exe
2008-05-18 10:52 . 2008-05-18 10:52 7,168 --a------ C:\WINDOWS\system32\16fcaeb.exe
2008-05-18 10:28 . 2008-05-18 10:28 7,168 --a------ C:\WINDOWS\system32\15a7289.exe
2008-05-18 09:42 . 2008-05-18 09:42 7,168 --a------ C:\WINDOWS\system32\12fbe4b.exe
2008-05-18 09:18 . 2008-05-18 09:18 7,168 --a------ C:\WINDOWS\system32\11a0341.exe
2008-05-18 08:54 . 2008-05-18 08:54 7,168 --a------ C:\WINDOWS\system32\103f463.exe
2008-05-18 07:42 . 2008-05-18 07:42 7,168 --a------ C:\WINDOWS\system32\c216d6.exe
2008-05-18 07:18 . 2008-05-18 07:19 7,168 --a------ C:\WINDOWS\system32\acbd52.exe
2008-05-18 06:55 . 2008-05-18 06:55 7,168 --a------ C:\WINDOWS\system32\9780e9.exe
2008-05-18 06:32 . 2008-05-18 06:32 7,168 --a------ C:\WINDOWS\system32\81efce.exe
2008-05-18 06:09 . 2008-05-18 06:09 7,168 --a------ C:\WINDOWS\system32\6cc0a8.exe
2008-05-18 04:58 . 2008-05-18 04:58 7,168 --a------ C:\WINDOWS\system32\2c182f.exe
2008-05-18 04:34 . 2008-05-18 04:34 7,168 --a------ C:\WINDOWS\system32\15bd8a.exe
2008-05-17 12:32 . 2008-05-17 12:32 7,168 --a------ C:\WINDOWS\system32\49bdd9.exe
2008-05-17 12:06 . 2008-05-17 12:08 7,168 --a------ C:\WINDOWS\system32\32403d.exe
2008-05-17 10:43 . 2008-05-17 10:43 8,192 --ahs---- C:\WINDOWS\Thumbs.db
2008-05-17 10:43 . 2008-05-17 10:43 4,608 --ahs---- C:\Thumbs.db
2008-05-17 08:29 . 2008-05-17 08:30 7,168 --a------ C:\WINDOWS\system32\b06673.exe
2008-05-17 08:06 . 2008-05-17 08:06 7,168 --a------ C:\WINDOWS\system32\9b06e9.exe
2008-05-17 04:16 . 2008-05-17 04:16 7,168 --a------ C:\WINDOWS\system32\fdfbfa.exe
2008-05-17 03:51 . 2008-05-17 03:51 7,168 --a------ C:\WINDOWS\system32\e6d37e.exe
2008-05-17 03:28 . 2008-05-17 03:28 7,168 --a------ C:\WINDOWS\system32\d13354.exe
2008-05-17 03:03 . 2008-05-17 03:03 7,168 --a------ C:\WINDOWS\system32\bb1a99.exe
2008-05-17 02:40 . 2008-05-17 02:40 7,168 --a------ C:\WINDOWS\system32\a56e09.exe
2008-05-17 02:16 . 2008-05-17 02:16 7,168 --a------ C:\WINDOWS\system32\90076a.exe
2008-05-17 00:21 . 2008-05-17 00:21 7,168 --a------ C:\WINDOWS\system32\26b0ca.exe
2008-05-15 16:08 . 2008-05-15 16:08 <DIR> d--hs---- C:\FOUND.017
2008-05-15 05:55 . 2008-05-15 05:56 7,168 --a------ C:\WINDOWS\system32\162f92.exe
2008-05-14 23:53 . 2008-05-14 23:53 1,506 --a------ C:\WINDOWS\system32\533b47.exe
2008-05-14 23:53 . 2008-05-14 23:53 1,506 --a------ C:\WINDOWS\system32\532c73.exe
2008-05-14 23:06 . 2008-05-14 23:06 7,168 --a------ C:\WINDOWS\system32\289dc3.exe
2008-05-14 23:06 . 2008-05-14 23:07 1,506 --a------ C:\WINDOWS\system32\28d62c.exe
2008-05-14 23:06 . 2008-05-14 23:06 1,506 --a------ C:\WINDOWS\system32\28c762.exe
2008-05-14 22:26 . 2008-05-19 10:23 5,477 --a------ C:\WINDOWS\system32\drivers\knlqpn.sys
2008-05-14 22:24 . 2008-05-14 22:24 <DIR> d--hs---- C:\FOUND.016
2008-05-14 13:18 . 2008-05-14 13:18 1,506 --a------ C:\WINDOWS\system32\557eaa.exe
2008-05-14 13:16 . 2008-05-14 13:16 7,168 --a------ C:\WINDOWS\system32\5413eb.exe
2008-05-14 12:53 . 2008-05-14 12:53 1,506 --a------ C:\WINDOWS\system32\3ee2e4.exe
2008-05-14 12:53 . 2008-05-14 12:53 1,506 --a------ C:\WINDOWS\system32\3ec276.exe
2008-05-14 12:29 . 2008-05-14 12:29 7,168 --a------ C:\WINDOWS\system32\28f36f.exe
2008-05-14 12:29 . 2008-05-14 12:30 1,506 --a------ C:\WINDOWS\system32\293e80.exe
2008-05-14 12:06 . 2008-05-14 12:06 7,168 --a------ C:\WINDOWS\system32\13d2d6.exe
2008-05-14 12:06 . 2008-05-14 12:06 1,506 --a------ C:\WINDOWS\system32\140c1b.exe
2008-05-14 12:06 . 2008-05-14 12:06 1,506 --a------ C:\WINDOWS\system32\13f42a.exe
2008-05-14 10:47 . 2008-05-14 10:47 1,506 --a------ C:\WINDOWS\system32\77d622.exe
2008-05-14 10:47 . 2008-05-14 10:47 1,506 --a------ C:\WINDOWS\system32\77c27f.exe
2008-05-14 10:24 . 2008-05-14 10:24 7,168 --a------ C:\WINDOWS\system32\6254cc.exe
2008-05-14 10:24 . 2008-05-14 10:24 1,506 --a------ C:\WINDOWS\system32\627df3.exe
2008-05-14 10:24 . 2008-05-14 10:24 1,506 --a------ C:\WINDOWS\system32\626d2b.exe
2008-05-14 10:00 . 2008-05-14 10:00 7,168 --a------ C:\WINDOWS\system32\4d0524.exe
2008-05-14 10:00 . 2008-05-14 10:01 1,506 --a------ C:\WINDOWS\system32\4d39df.exe
2008-05-14 10:00 . 2008-05-14 10:00 1,506 --a------ C:\WINDOWS\system32\4d1fc7.exe
2008-05-14 09:14 . 2008-05-14 09:14 7,168 --a------ C:\WINDOWS\system32\223df6.exe
2008-05-14 09:14 . 2008-05-14 09:14 1,506 --a------ C:\WINDOWS\system32\22c6cd.exe
2008-05-14 08:49 . 2008-05-14 08:49 7,168 --a------ C:\WINDOWS\system32\bc4c5.exe
2008-05-13 23:54 . 2008-05-13 23:54 1,506 --a------ C:\WINDOWS\system32\dabae.exe
2008-05-13 23:54 . 2008-05-13 23:54 1,506 --a------ C:\WINDOWS\system32\d9cd0.exe
2008-05-13 23:53 . 2008-05-13 23:54 7,168 --a------ C:\WINDOWS\system32\d8792.exe
2008-05-13 16:16 . 2008-05-13 16:16 7,168 --a------ C:\WINDOWS\system32\b6beef.exe
2008-05-13 16:16 . 2008-05-13 16:16 1,506 --a------ C:\WINDOWS\system32\b6fb73.exe
2008-05-13 16:16 . 2008-05-13 16:16 1,506 --a------ C:\WINDOWS\system32\b6eadd.exe
2008-05-13 12:18 . 2008-05-13 12:18 1,506 --a------ C:\WINDOWS\system32\61a866.exe
2008-05-13 12:18 . 2008-05-13 12:18 1,506 --a------ C:\WINDOWS\system32\617b38.exe
2008-05-13 09:53 . 2008-05-13 09:53 7,168 --a------ C:\WINDOWS\system32\2071d51.exe
2008-05-13 09:53 . 2008-05-13 09:53 1,506 --a------ C:\WINDOWS\system32\207381d.exe
2008-05-13 09:30 . 2008-05-13 09:30 1,506 --a------ C:\WINDOWS\system32\1f1cbbe.exe
2008-05-13 09:29 . 2008-05-13 09:29 7,168 --a------ C:\WINDOWS\system32\1f0fb3d.exe
2008-05-13 09:29 . 2008-05-13 09:29 1,506 --a------ C:\WINDOWS\system32\1f16496.exe
2008-05-13 09:06 . 2008-05-13 09:06 1,506 --a------ C:\WINDOWS\system32\1dbd3ad.exe
2008-05-13 09:06 . 2008-05-13 09:06 1,506 --a------ C:\WINDOWS\system32\1dbb869.exe
2008-05-13 09:05 . 2008-05-13 09:05 7,168 --a------ C:\WINDOWS\system32\1db79c8.exe
2008-05-13 08:42 . 2008-05-13 08:42 7,168 --a------ C:\WINDOWS\system32\1c627ef.exe
2008-05-13 08:42 . 2008-05-13 08:42 1,506 --a------ C:\WINDOWS\system32\1c66275.exe
2008-05-13 08:42 . 2008-05-13 08:42 1,506 --a------ C:\WINDOWS\system32\1c6499e.exe
2008-05-13 07:33 . 2008-05-13 07:33 1,506 --a------ C:\WINDOWS\system32\186af2e.exe
2008-05-13 07:33 . 2008-05-13 07:33 1,506 --a------ C:\WINDOWS\system32\18694d0.exe
2008-05-13 07:09 . 2008-05-13 07:09 7,168 --a------ C:\WINDOWS\system32\17107db.exe
2008-05-13 07:09 . 2008-05-13 07:09 1,506 --a------ C:\WINDOWS\system32\17159ee.exe
2008-05-13 07:09 . 2008-05-13 07:09 1,506 --a------ C:\WINDOWS\system32\1713fcc.exe
2008-05-13 06:46 . 2008-05-13 06:46 1,506 --a------ C:\WINDOWS\system32\15ba974.exe
2008-05-13 06:46 . 2008-05-13 06:46 1,506 --a------ C:\WINDOWS\system32\15b9422.exe
2008-05-13 06:45 . 2008-05-13 06:45 7,168 --a------ C:\WINDOWS\system32\15b7025.exe
2008-05-13 05:59 . 2008-05-13 05:59 7,168 --a------ C:\WINDOWS\system32\1312b13.exe
2008-05-13 05:59 . 2008-05-13 06:00 1,506 --a------ C:\WINDOWS\system32\131664d.exe
2008-05-13 05:36 . 2008-05-13 05:36 7,168 --a------ C:\WINDOWS\system32\11b9cd4.exe
2008-05-13 05:36 . 2008-05-13 05:36 1,506 --a------ C:\WINDOWS\system32\11beeb4.exe
2008-05-13 05:36 . 2008-05-13 05:36 1,506 --a------ C:\WINDOWS\system32\11bccde.exe
2008-05-13 05:13 . 2008-05-13 05:13 1,506 --a------ C:\WINDOWS\system32\1066e76.exe
2008-05-13 04:49 . 2008-05-13 04:49 1,506 --a------ C:\WINDOWS\system32\f0e7f5.exe
2008-05-13 04:49 . 2008-05-13 04:49 1,506 --a------ C:\WINDOWS\system32\f0cb71.exe
2008-05-11 13:54 . 2008-05-11 13:54 <DIR> d--hs---- C:\FOUND.015
2008-05-11 02:02 . 2008-05-11 02:02 <DIR> d--hs---- C:\FOUND.014
2008-05-10 00:31 . 2008-05-10 00:31 <DIR> d--hs---- C:\FOUND.013
2008-05-09 09:19 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-05-09 09:17 . 2008-05-09 09:17 126,264 --a------ C:\Documents and Settings\All Users\Application Data\firstlsp.reg.dat
2008-05-09 09:16 . 2008-05-09 09:16 <DIR> d-------- C:\Program Files\AntiVir Workstation
2008-05-09 09:16 . 2008-05-09 09:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AntiVir Workstation
2008-05-09 09:12 . 2008-05-09 09:12 <DIR> d-------- C:\photoshop
2008-05-09 07:51 . 2008-05-09 07:51 <DIR> d--hs---- C:\FOUND.012
2008-05-09 04:42 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-09 04:42 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-09 04:42 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-08 12:36 . 2008-05-08 12:36 <DIR> d-------- C:\Program Files\LT-Extender 2000
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-19 17:24 40,960 ----a-w C:\WINDOWS\system32\wmdrtc32.dll
2008-04-24 21:00 22,016 ----a-w C:\WINDOWS\MDM.EXE
2008-04-19 21:47 3,754 ----a-w C:\MS32DLL.dll.vbs
2008-04-18 09:46 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-04-18 09:46 --------- d-----w C:\Documents and Settings\user\Application Data\skypePM
2008-04-18 09:43 --------- d-----w C:\Documents and Settings\user\Application Data\Skype
2008-04-18 09:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-04-17 21:27 --------- d-----w C:\Program Files\Whizlabs Suite
2008-04-17 21:18 --------- d-----w C:\Program Files\Windows Resource Kits
2008-04-17 21:16 --------- d-----w C:\Program Files\uCertify
2008-04-17 06:22 --------- d-----w C:\Program Files\GCIVIL SOFTWARE
2008-04-16 11:06 --------- d-----w C:\Documents and Settings\user\Application Data\vlc
2008-04-16 11:05 --------- d-----w C:\Program Files\VideoLAN
2008-04-14 15:30 --------- d-----w C:\Program Files\iMesh Applications
2008-04-14 15:30 --------- d-----w C:\Documents and Settings\user\Application Data\iMesh
2008-04-14 12:32 --------- d-----w C:\Program Files\SYSTRAN
2008-04-14 11:23 --------- d-----w C:\Program Files\Cain
2008-04-14 10:44 --------- d-----w C:\Program Files\Orbitdownloader
2008-04-14 10:44 --------- d-----w C:\Documents and Settings\user\Application Data\Orbit
2008-04-13 18:32 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-13 18:23 --------- d-----w C:\Documents and Settings\user\Application Data\GRETECH
2008-04-13 18:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\GRETECH
2008-04-13 18:22 --------- d-----w C:\Program Files\GRETECH
2008-04-13 13:50 --------- d-----w C:\Documents and Settings\user\Application Data\DivX
2008-04-13 13:50 --------- d-----w C:\Documents and Settings\user\Application Data\CyberLink
2008-04-13 13:49 --------- d-----w C:\Program Files\DivX
2008-04-11 10:07 --------- d-----w C:\Program Files\Common Files\L&H
2008-04-11 10:06 --------- d-----w C:\Program Files\Microsoft Works
2008-04-11 10:06 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-09 11:13 --------- d-----w C:\Program Files\Yahoo!
2008-04-09 11:13 --------- d-----w C:\Program Files\WIDCOMM
2008-04-04 13:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-04-04 09:07 --------- d-----w C:\Program Files\SIP Phone
2008-03-31 21:25 831,488 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-03-31 21:25 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-03-31 21:25 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
2008-03-31 21:25 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-21 20:30 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-03-21 20:30 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-03-21 20:30 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-03-21 20:30 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-03-21 20:30 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-03-21 20:30 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-03-21 20:30 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-03-21 20:30 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-03-21 20:30 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-03-21 20:28 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-03-21 20:28 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-03-21 20:28 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-03-21 20:28 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-03-21 20:28 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-03-21 20:28 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-03-21 20:28 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2006-11-25 18:11 2,560 --sh--r C:\WINDOWS\system32\fooool.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 22:56 15360]
"ares"="C:\Program Files\Ares\Ares.exe" [2008-02-20 07:33 991744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Barsaka"="explorer.exe" [2007-06-13 02:23 1033216 C:\WINDOWS\explorer.exe]
"avgnt"="C:\Program Files\AntiVir Workstation\avgnt.exe" [ ]
"ErrorSmart"="C:\Program Files\ErrorSmart\ErrorSmart.exe" [2008-05-01 08:47 18666744]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-06-02 17:48:22 565309]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-05-09 09:21:41 142336]
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-04-14 03:44:17 1678536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SIP Phone\\SIP Phone.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\11b9cd4.exe"=
"C:\\WINDOWS\\system32\\1312b13.exe"=
"C:\\WINDOWS\\system32\\15b7025.exe"=
"C:\\WINDOWS\\system32\\17107db.exe"=
"C:\\WINDOWS\\system32\\1c627ef.exe"=
"C:\\WINDOWS\\system32\\1db79c8.exe"=
"C:\\WINDOWS\\system32\\1f0fb3d.exe"=
"C:\\WINDOWS\\system32\\2071d51.exe"=
"C:\\WINDOWS\\system32\\b6beef.exe"=
"C:\\WINDOWS\\system32\\d8792.exe"=
"C:\\WINDOWS\\system32\\bc4c5.exe"=
"C:\\WINDOWS\\system32\\223df6.exe"=
"C:\\WINDOWS\\system32\\4d0524.exe"=
"C:\\WINDOWS\\system32\\6254cc.exe"=
"C:\\WINDOWS\\system32\\13d2d6.exe"=
"C:\\WINDOWS\\system32\\28f36f.exe"=
"C:\\WINDOWS\\system32\\5413eb.exe"=
"C:\\WINDOWS\\system32\\289dc3.exe"=
"C:\\WINDOWS\\system32\\162f92.exe"=
"C:\\WINDOWS\\system32\\26b0ca.exe"=
"C:\\WINDOWS\\system32\\90076a.exe"=
"C:\\WINDOWS\\system32\\a56e09.exe"=
"C:\\WINDOWS\\system32\\bb1a99.exe"=
"C:\\WINDOWS\\system32\\d13354.exe"=
"C:\\WINDOWS\\system32\\e6d37e.exe"=
"C:\\WINDOWS\\system32\\fdfbfa.exe"=
"C:\\WINDOWS\\system32\\9b06e9.exe"=
"C:\\WINDOWS\\system32\\b06673.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\WINDOWS\\system32\\32403d.exe"=
"C:\\WINDOWS\\system32\\49bdd9.exe"=
"C:\\WINDOWS\\system32\\15bd8a.exe"= C:\\WINDOWS\\System32\\15bd8a.exe
"C:\\WINDOWS\\system32\\2c182f.exe"=
"C:\\WINDOWS\\system32\\6cc0a8.exe"=
"C:\\WINDOWS\\system32\\81efce.exe"=
"C:\\WINDOWS\\system32\\9780e9.exe"=
"C:\\WINDOWS\\system32\\acbd52.exe"=
"C:\\WINDOWS\\system32\\c216d6.exe"=
"C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"C:\\WINDOWS\\system32\\103f463.exe"=
"C:\\WINDOWS\\system32\\11a0341.exe"=
"C:\\WINDOWS\\system32\\12fbe4b.exe"=
"C:\\WINDOWS\\system32\\15a7289.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\WINDOWS\\system32\\16fcaeb.exe"=
"C:\\WINDOWS\\system32\\1852e2c.exe"=
"C:\\WINDOWS\\system32\\19be587.exe"=
"C:\\WINDOWS\\system32\\15d66b.exe"=
"C:\\WINDOWS\\system32\\2d3168.exe"=
"C:\\WINDOWS\\system32\\577a81.exe"=
"C:\\WINDOWS\\system32\\1b191f.exe"=
"C:\\WINDOWS\\system32\\15d2aa.exe"=
"C:\\WINDOWS\\system32\\2bb5ff.exe"=
"C:\\WINDOWS\\system32\\40e6c0.exe"=
"C:\\WINDOWS\\system32\\5614a5.exe"=
"C:\\WINDOWS\\system32\\6b448a.exe"=
"C:\\WINDOWS\\system32\\807cc4.exe"=
"C:\\WINDOWS\\system32\\95b06a.exe"=
"C:\\WINDOWS\\system32\\aaec5b.exe"=
"C:\\WINDOWS\\system32\\c06b9e.exe"=
"C:\\WINDOWS\\system32\\17a102.exe"=
"C:\\WINDOWS\\system32\\2d52c7.exe"=
"C:\\WINDOWS\\system32\\583ccf.exe"=
R2 AVEService;AntiVir Windows Workstation MailGuard helper service;"C:\Program Files\AntiVir Workstation\avesvc.exe" [2007-02-26 11:33]
R3 CONAN;CONAN;C:\WINDOWS\system32\drivers\o2mmb.sys [2003-07-29 00:49]
R3 MbxStby;MbxStby;C:\WINDOWS\system32\drivers\MbxStby.sys [2003-07-24 14:50]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\ar5211.sys [2005-09-15 00:49]
R4 NdisFileServices32;NdisFileServices32;C:\WINDOWS\system32\drivers\knlqpn.sys [2008-05-19 10:28]
S2 AntiVirMailService;AntiVir Windows Workstation MailGuard;"C:\Program Files\AntiVir Workstation\avmailc.exe" [2007-04-04 11:57]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b641320-0ddd-11dd-b012-000fb36c33fd}]
\Shell\AutoRun\command - E:\RavMon.exe
\Shell\explore\Command - E:\RavMon.exe -e
\Shell\open\Command - E:\RavMon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f44cb90-1235-11dd-b029-000fb36c33fd}]
\Shell\AutoRun\command - E:\d.com
\Shell\explore\Command - E:\d.com
\Shell\open\Command - E:\d.com
.
Contents of the 'Scheduled Tasks' folder
"2008-05-19 17:27:02 C:\WINDOWS\Tasks\McAfee.com Update Check (HP-5B778D56A8D5-user).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.ex
- C:\PROGRA~1\mcafee.com\agent
"2008-05-19 17:26:16 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Program Files\ErrorSmart\ErrorSmart.ex
- C:\Program Files\ErrorSmart
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-19 10:25:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\wmdrtc32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\PROGRAM FILES\ORBITDOWNLOADER\ORBITNET.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-05-19 10:29:14 - machine was rebooted [user]
ComboFix-quarantined-files.txt 2008-05-19 17:29:02
Pre-Run: 15,111,733,248 bytes free
Post-Run: 15,357,984,768 bytes free
543 --- E O F --- 2008-05-14 15:43:59
merci