ComboFix 08-05-15.3 - NADIR 2008-05-18 18:54:31.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.543 [GMT 1:00]
Endroit: C:\Documents and Settings\NADIR\Bureau\killer.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\atkrqtyi.dll
C:\WINDOWS\system32\installer.exe
C:\WINDOWS\system32\iytqrkta.ini
C:\WINDOWS\system32\jiRrBJjl.ini
C:\WINDOWS\system32\jiRrBJjl.ini2
C:\WINDOWS\system32\ljJBrRij.dll
C:\WINDOWS\system32\mcpqhlib.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\rjbmrlwj.ini
C:\WINDOWS\system32\xchfmnuh.ini
C:\WINDOWS\xpupdate.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-18 to 2008-05-18 ))))))))))))))))))))))))))))))))))))
.
2008-05-18 18:37 . 2008-05-18 18:37 <REP> d-------- C:\Documents and Settings\NADIR\Application Data\Grisoft
2008-05-18 18:37 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-18 18:36 . 2008-05-18 18:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-18 17:40 . 2008-05-18 17:40 <REP> d-------- C:\Program Files\Trend Micro
2008-05-18 17:12 . 2008-05-18 17:12 <REP> d-------- C:\VundoFix Backups
2008-05-18 13:07 . 2008-05-18 13:07 <REP> d-------- C:\Documents and Settings\NADIR\Download
2008-05-18 13:07 . 2008-05-18 13:07 30,720 --a------ C:\WINDOWS\system32\ljJYRIBS.dll
2008-05-18 13:07 . 2008-05-18 13:07 2,537 --a------ C:\Documents and Settings\NADIR\Application Data\update.log
2008-05-18 13:01 . 2008-05-18 13:02 <REP> d-------- C:\Program Files\MalwareAlarm
2008-05-17 21:19 . 2008-05-17 21:19 <REP> d-------- C:\Temp
2008-05-17 19:58 . 2008-05-17 19:58 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-05-17 19:58 . 2008-05-17 19:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-17 19:58 . 2008-05-17 21:26 96,645 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-05-17 19:58 . 2008-05-17 21:26 87,941 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-05-17 19:57 . 2008-05-17 19:57 <REP> d-------- C:\KAV
2008-05-17 19:57 . 2008-05-18 18:57 2,499,872 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-17 19:57 . 2008-05-18 18:57 38,732 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-17 19:57 . 2008-05-18 18:57 2,192 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-17 19:57 . 2008-05-18 18:57 800 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-17 18:10 . 2008-05-17 18:10 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-17 18:04 . 2008-05-17 18:04 <REP> d-------- C:\WINDOWS\AU_Temp
2008-05-17 16:34 . 2008-05-17 18:12 40 --a------ C:\WINDOWS\TSC.INI
2008-05-17 15:44 . 2008-05-17 15:44 <REP> d-------- C:\WINDOWS\AU_Log
2008-05-17 15:44 . 2008-05-17 15:44 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-05-17 15:44 . 2008-05-17 15:44 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-05-17 15:44 . 2008-05-17 15:44 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-05-17 15:44 . 2008-05-17 18:04 170 --a------ C:\WINDOWS\GetServer.ini
2008-05-16 21:41 . 2008-05-16 21:41 <REP> d-------- C:\WINDOWS\NgrabLite
2008-05-16 21:41 . 2008-05-16 21:41 <REP> d-------- C:\Program Files\NgrabLite
2008-05-16 21:11 . 2008-05-16 21:11 82 --a------ C:\WINDOWS\mafosav.INI
2008-05-16 20:39 . 2008-05-18 16:59 109,834 --a------ C:\WINDOWS\BM87796a42.xml
2008-05-16 19:10 . 2008-05-16 19:10 2,290,176 --a------ C:\WINDOWS\system32\TUKernel.exe
2008-05-16 18:35 . 2008-04-04 14:51 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-05-16 08:32 . 2008-05-16 18:35 354,560 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-05-16 08:31 . 2008-05-16 08:31 <REP> d-------- C:\WINDOWS\Tnnp
2008-05-16 08:31 . 2008-05-16 08:31 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-05-16 08:31 . 2008-05-16 08:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-05-15 12:04 . 2008-05-15 12:04 <REP> d-------- C:\Program Files\MediaCoder
2008-05-15 10:06 . 2008-05-15 10:06 <REP> d-------- C:\Program Files\Tomato
2008-05-14 22:09 . 2008-05-14 22:09 <REP> d-------- C:\Program Files\PowerQuest
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-29 18:32 --------- d-----w C:\Documents and Settings\NADIR\Application Data\vlc
2008-03-29 17:46 171,520 ----a-w C:\WINDOWS\system32\cncs32.dll
2008-03-29 09:34 --------- d-----w C:\Program Files\WinHTTrack
2008-03-28 08:39 --------- d-----w C:\Documents and Settings\NADIR\Application Data\Lumen
2008-03-27 09:08 --------- d-----w C:\Program Files\Internet Download Manager
2008-03-26 16:58 --------- d-----w C:\Program Files\Need2Find
2008-03-26 12:49 --------- d-----w C:\Documents and Settings\NADIR\Application Data\IDM
2008-03-25 15:36 --------- d-----w C:\Program Files\Kazaa
2008-03-25 14:25 --------- d-----w C:\Documents and Settings\NADIR\Application Data\TuneUp Software
2008-03-25 13:58 --------- d-----w C:\Program Files\uTorrent
2008-03-25 13:58 --------- d-----w C:\Documents and Settings\NADIR\Application Data\uTorrent
2008-03-25 13:34 --------- d-sh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-03-25 13:34 --------- d-----w C:\Program Files\Windows Live
2008-03-25 13:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-25 12:54 --------- d-----w C:\Program Files\Triogical!
2008-03-25 12:53 --------- d-----w C:\Program Files\SuperCopier2
2008-03-25 12:51 --------- d-----w C:\Program Files\Samsung
2008-03-25 12:43 --------- d-----w C:\Program Files\Innovative Solutions
2008-03-25 12:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Innovative Solutions
2008-03-25 09:42 --------- d-----w C:\Program Files\Lavasoft
2008-03-25 09:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-25 09:41 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9523A8F7-75D0-4E0C-854A-7CF2A1EF79EA}]
2008-05-18 13:07 30720 --a------ C:\WINDOWS\system32\ljJYRIBS.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 17:45 1052672]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2008-03-27 10:08 2553264]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2008-03-30 14:09 263472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 22:32 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-28 21:39 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2002-08-28 21:39 455168]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 08:47 67072 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2001-12-16 18:55 2899968]
"nwiz"="nwiz.exe" [2001-12-16 18:55 782336 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2001-12-16 18:55 46080]
"lnternet Update"="lExplore.exe" []
"BM87796a42"="C:\WINDOWS\system32\pntciqjm.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"lnternet Update"="lExplore.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:54 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{9523A8F7-75D0-4E0C-854A-7CF2A1EF79EA}"= C:\WINDOWS\system32\ljJYRIBS.dll [2008-05-18 13:07 30720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXNeCvv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJYRIBS]
ljJYRIBS.dll 2008-05-18 13:07 30720 C:\WINDOWS\system32\ljJYRIBS.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\outlook.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24411:TCP"= 24411:TCP:BitComet 24411 TCP
"24411:UDP"= 24411:UDP:BitComet 24411 UDP
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:55]
S3 DrvSnSht;DrvSnSht;C:\Program Files\R-Drive Image\DrvSnSht.sys []
S3 R-ImageDisk;R-ImageDisk;C:\Program Files\R-Drive Image\R-ImageDisk.sys []
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-05-16 18:35]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - AVGASCLN
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-05-18 18:00:10 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-18 19:00:31
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\DOCUME~1\NADIR\LOCALS~1\Temp\mc22.tmp"
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ljJYRIBS.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\LAVASOFT\AD-AWARE 2007\AAWSERVICE.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IEMONITOR.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-18 19:02:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-18 18:02:12
Pre-Run: 15,282,700,288 octets libres
Post-Run: 15,265,792,000 octets libres
189