Bonjour JFKpresident,
ComboFix 08-07-20.5 - Admin 2008-07-21 6:17:34.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.191 [GMT 2:00]
Endroit: C:\Documents and Settings\Admin.XPSP2-26C96EC83\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Admin.XPSP2-26C96EC83\Local Settings\Temporary Internet Files\fohuhaqy.pif
C:\Documents and Settings\Admin.XPSP2-26C96EC83\Local Settings\Temporary Internet Files\umiq._sy
C:\Documents and Settings\Admin.XPSP2-26C96EC83\ravmonlog
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\g32.txt
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-21 to 2008-07-21 ))))))))))))))))))))))))))))))))))))
.
2008-07-19 13:34 . 2008-07-19 13:34 1,836 --a--c--- C:\33-1212867830uraI.jpg
2008-07-19 13:32 . 2008-07-19 13:32 17,501 --a--c--- C:\1-1203879082HMCp.jpg
2008-07-19 12:25 . 2008-07-19 12:25 23,552 --ahsc--- C:\Thumbs.db
2008-07-19 01:51 . 2008-07-19 01:52 <REP> d-------- C:\WINDOWS\system32\NtmsData
2008-07-18 03:10 . 2008-07-18 03:10 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-07-18 01:57 . 2008-07-18 01:57 32,247 --a--c--- C:\photohotel.jpg
2008-07-18 01:55 . 2008-07-18 01:55 129,121 --a--c--- C:\photoTerrain.jpg
2008-07-17 14:34 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-07-17 14:34 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-17 13:41 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-17 13:41 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-07-17 13:41 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-17 11:43 . 2008-07-17 11:43 <REP> d-------- C:\WINDOWS\ERUNT
2008-07-17 11:36 . 2008-07-17 12:03 <REP> d----c--- C:\SDFix
2008-07-16 19:46 . 2008-07-17 11:28 <REP> d-------- C:\Program Files\Lopxp
2008-07-16 02:10 . 2008-07-16 02:10 <REP> d-------- C:\Program Files\Trend Micro
2008-07-15 16:59 . 2008-07-15 16:59 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Canon
2008-07-15 16:48 . 2008-07-15 16:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\OpenOffice.org2
2008-07-10 16:04 . 2008-07-10 16:04 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Thunderbird
2008-07-10 16:04 . 2008-07-10 16:04 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Talkback
2008-07-10 15:19 . 2007-06-03 17:03 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-07-10 15:19 . 2007-06-03 17:03 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-07-10 15:19 . 2007-06-03 15:10 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-07-10 15:19 . 2008-07-15 16:59 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-07-10 15:19 . 2007-06-03 17:03 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-07-10 15:19 . 2008-07-15 16:51 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-07-10 15:19 . 2007-06-03 17:03 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-07-10 15:19 . 2008-07-10 15:19 <REP> d-------- C:\Documents and Settings\Administrateur
2008-07-09 16:06 . 2008-07-14 04:04 <REP> d-------- C:\Program Files\a-squared Free
2008-07-01 03:15 . 2008-07-01 03:15 19,258 --a------ C:\WINDOWS\hujekorotu.ban
2008-07-01 03:15 . 2008-07-01 03:15 18,727 --a------ C:\WINDOWS\exys.reg
2008-07-01 03:15 . 2008-07-01 03:15 17,631 --a------ C:\WINDOWS\jivy._dl
2008-07-01 03:15 . 2008-07-01 03:15 17,574 --a------ C:\WINDOWS\evylewysoq.pif
2008-07-01 03:15 . 2008-07-01 03:15 15,594 --a------ C:\WINDOWS\yjuha.dl
2008-07-01 03:15 . 2008-07-01 03:15 14,579 --a------ C:\WINDOWS\system32\kafewi.reg
2008-07-01 03:15 . 2008-07-01 03:15 14,539 --a------ C:\Documents and Settings\Admin.XPSP2-26C96EC83\Application Data\lugiz.exe
2008-07-01 03:15 . 2008-07-01 03:15 12,851 --a------ C:\WINDOWS\system32\gujyhoreri.dat
2008-07-01 03:15 . 2008-07-01 03:15 10,242 --a------ C:\Program Files\Fichiers communs\gufase.exe
2008-07-01 03:14 . 2008-07-17 13:23 <REP> d-------- C:\Program Files\XPSecurityCenter
2008-06-29 13:53 . 2008-06-29 13:53 <REP> d-------- C:\Program Files\RadarSyncBar
2008-06-29 13:49 . 2008-06-29 13:49 <REP> d-------- C:\Program Files\torrent_search
2008-06-29 13:47 . 2008-06-30 17:35 <REP> d-------- C:\Program Files\BitTorrent Fastest Tool
2008-06-27 11:43 . 2008-06-27 11:43 <REP> d-------- C:\Documents and Settings\Admin.XPSP2-26C96EC83\Application Data\Canon
2008-06-27 11:40 . 2008-06-27 11:40 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft
2008-06-27 11:40 . 2008-06-27 11:40 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
2008-06-27 11:40 . 2008-06-27 11:40 <REP> d-------- C:\Documents and Settings\Admin.XPSP2-26C96EC83\Application Data\ScanSoft
2008-06-27 11:40 . 2008-06-27 11:40 412 --a------ C:\WINDOWS\MAXLINK.INI
2008-06-27 11:38 . 2008-06-27 11:38 <REP> d-------- C:\Program Files\Fichiers communs\CANON
2008-06-27 11:36 . 2008-06-27 11:36 <REP> d--h----- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2008-06-27 11:36 . 2008-06-27 11:36 <REP> d--h----- C:\Program Files\CanonBJ
2008-06-24 14:36 . 2008-06-24 14:36 <REP> d--h----- C:\Documents and Settings\All Users.WINDOWS\Application Data\CanonBJ
2008-06-24 14:36 . 2006-12-25 22:00 198,656 --a------ C:\WINDOWS\system32\CNMLM8R.DLL
2008-06-24 14:34 . 2005-07-26 13:44 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-21 04:25 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-07-21 04:25 --------- d-----w C:\Program Files\eMule
2008-07-20 12:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-07-20 09:45 --------- d-----w C:\Documents and Settings\Admin.XPSP2-26C96EC83\Application Data\OpenOffice.org2
2008-07-19 15:44 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-07-18 10:00 --------- d-----w C:\Program Files\Spyware Doctor
2008-07-18 01:15 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-07-10 14:33 --------- d-----w C:\Program Files\WinamaxPoker
2008-07-01 01:15 12,613 ----a-w C:\Program Files\Fichiers communs\bafoluwyty.ban
2008-07-01 01:15 10,470 ----a-w C:\Program Files\Fichiers communs\ezybe.lib
2008-06-27 13:26 --------- d-----w C:\Program Files\Canon
2008-06-27 09:40 --------- d-----w C:\Program Files\ScanSoft
2008-06-27 09:40 --------- d-----w C:\Program Files\Fichiers communs\ScanSoft Shared
2008-06-27 09:40 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-06-06 00:03 --------- d-----w C:\Program Files\Everest Poker
2008-05-22 17:48 --------- d-----w C:\Program Files\QuickZip4
2006-08-16 12:18 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
------- Sigcheck -------
2005-07-26 15:01 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll
2005-09-18 12:29 359936 0df628756fb71111955be60bac216a70 C:\WINDOWS\system32\drivers\tcpip.sys
2005-10-12 10:33 2058880 73fa9c95d235844a36968c7852c7dbdd C:\WINDOWS\system32\ntkrnlpa.exe
2005-07-26 15:01 2181376 63729dd0f2aae36cc52b89c05505146c C:\WINDOWS\system32\ntoskrnl.exe
2005-07-26 15:01 1036288 0bee3b07ace3303ee57698808e1d2de3 C:\WINDOWS\explorer.exe
2005-08-10 12:15 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-07-31 11:45 139264]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-14 18:42 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-21 02:20 1211176]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 20:48 434528]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-14 18:43 1836544]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 19:32 132760]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 16:39 294400]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Nero\\Nero Sipps\\Phone.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"17004:TCP"= 17004:TCP:NortonAV
"14868:TCP"= 14868:TCP:NortonAV
"13542:TCP"= 13542:TCP:NortonAV
"12140:TCP"= 12140:TCP:NortonAV
"13321:TCP"= 13321:TCP:NortonAV
"18119:TCP"= 18119:TCP:NortonAV
"17019:TCP"= 17019:TCP:NortonAV
"12161:TCP"= 12161:TCP:NortonAV
"17978:TCP"= 17978:TCP:NortonAV
"12294:TCP"= 12294:TCP:NortonAV
"18491:TCP"= 18491:TCP:NortonAV
"17945:TCP"= 17945:TCP:NortonAV
"17752:TCP"= 17752:TCP:NortonAV
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2005-07-26 15:43]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2005-07-26 15:43]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-XP SecurityCenter - C:\Program Files\XPSecurityCenter\xpsecuritycenter.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R0 -: HKLM-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R0 -: HKCU-Search,SearchAssistant = hxxp://www.google.com/ie
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R0 -: HKLM-Search,SearchAssistant = hxxp://www.google.com/ie
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-21 06:25:27
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\searchindexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\WINDOWS\system32\searchprotocolhost.exe
C:\WINDOWS\system32\searchfilterhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-21 6:38:12 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2008-07-21 04:37:54
Pre-Run: 12,321,374,208 octets libres
Post-Run: 12,691,812,352 octets libres
221 --- E O F --- 2008-07-18 01:15:42