C'est fait
ComboFix 08-09-15.02 - User 2008-09-16 16:44:00.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.709 [GMT 11:00]
Lancé depuis: H:\Documents and Settings\User\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\Documents and Settings\User\ravmonlog
H:\WINDOWS\system32\chbsofdn.ini
H:\WINDOWS\system32\emrynqvk.dll
H:\WINDOWS\system32\MSINET.oca
H:\WINDOWS\system32\nasoebss.dll
H:\WINDOWS\system32\ukdkscni.ini
H:\WINDOWS\system32\wHhjTBeg.ini
H:\WINDOWS\system32\wHhjTBeg.ini2
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-16 au 2008-09-16 ))))))))))))))))))))))))))))))))))))
.
2008-09-16 16:08 . 2008-09-16 16:08 <REP> d-------- H:\Program Files\Malwarebytes' Anti-Malware
2008-09-16 16:08 . 2008-09-16 16:08 <REP> d-------- H:\Documents and Settings\User\Application Data\Malwarebytes
2008-09-16 16:08 . 2008-09-16 16:08 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-16 16:08 . 2008-09-10 00:04 38,528 --a------ H:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-16 16:08 . 2008-09-10 00:03 17,200 --a------ H:\WINDOWS\system32\drivers\mbam.sys
2008-09-16 16:03 . 2008-09-16 16:03 <REP> d-------- H:\Documents and Settings\User\Application Data\GoodSync
2008-09-16 16:02 . 2008-09-16 16:22 <REP> d-------- H:\Program Files\Siber Systems
2008-09-16 15:14 . 2008-09-16 15:42 <REP> d-------- H:\Program Files\Navilog1
2008-09-16 14:48 . 2008-09-16 15:00 3,178 --a------ H:\Documents and Settings\Orph.egd
2008-09-16 14:01 . 2008-09-16 14:01 <REP> d-------- H:\Program Files\Trend Micro
2008-09-15 15:38 . 2008-09-15 15:38 <REP> d-------- H:\Program Files\Avira
2008-09-15 15:17 . 2008-09-15 15:17 <REP> d-------- H:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-09-15 15:16 . 2008-09-15 15:16 <REP> d-------- H:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-14 18:15 . 2008-09-15 15:15 <REP> d-------- H:\Program Files\Spybot - Search & Destroy
2008-09-14 18:15 . 2008-09-15 15:15 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-13 03:55 . 2008-09-13 03:55 <REP> d-------- H:\Documents and Settings\User\Application Data\Nettordinateur
2008-09-12 20:22 . 2008-09-15 15:17 <REP> d-------- H:\Program Files\Mozilla Firefox(2)
2008-09-12 20:22 . 2008-09-12 20:22 0 --a------ H:\WINDOWS\nsreg.dat
2008-09-12 20:05 . 2008-09-12 20:05 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Nettordinateur
2008-09-12 18:43 . 2008-09-15 15:17 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-12 18:21 . 2008-09-12 18:21 <REP> d-------- H:\Program Files\Fichiers communs\Nero
2008-09-12 18:20 . 2008-09-12 18:20 <REP> d-------- H:\WINDOWS\InCD
2008-09-12 18:20 . 2008-09-12 18:20 <REP> d-------- H:\Program Files\Ahead
2008-09-12 18:20 . 2005-01-28 18:02 2,658,304 --------- H:\WINDOWS\NuNinst.exe
2008-09-12 18:20 . 2005-01-27 19:08 99,200 --------- H:\WINDOWS\system32\drivers\InCDfs.sys
2008-09-12 18:20 . 2005-06-18 21:19 57,929 --------- H:\WINDOWS\NuNinst.cfg
2008-09-12 18:20 . 2005-01-27 19:07 28,928 --------- H:\WINDOWS\system32\drivers\InCDpass.sys
2008-09-12 18:20 . 2005-01-28 19:07 27,776 --------- H:\WINDOWS\system32\drivers\InCDrm.sys
2008-09-12 18:20 . 2005-01-27 19:08 8,704 --------- H:\WINDOWS\system32\drivers\InCDrec.sys
2008-09-12 12:59 . 2008-09-12 12:59 <REP> d-------- H:\Program Files\Attack on Pearl Harbor Demo
2008-09-11 21:20 . 2008-09-12 12:59 <REP> d-------- H:\Program Files\LimeWire
2008-09-11 20:31 . 2008-09-12 12:59 <REP> d-------- H:\Program Files\KaraFun
2008-09-11 20:16 . 2008-09-12 12:59 <REP> d-------- H:\Program Files\Minilyrics
2008-09-11 20:16 . 2008-09-11 20:43 <REP> d-------- H:\Lyrics
2008-09-11 20:16 . 2008-09-12 12:59 <REP> d-------- H:\Documents and Settings\User\Application Data\MiniLyrics
2008-09-08 13:27 . 2008-09-12 12:59 <REP> d-------- H:\Documents and Settings\Administrateur\Modèles
2008-09-08 13:27 . 2008-09-08 13:29 <REP> d-------- H:\Documents and Settings\Administrateur\Mes documents
2008-09-08 13:27 . 2008-09-12 12:59 <REP> d---s---- H:\Documents and Settings\Administrateur
2008-09-07 07:51 . 1998-11-13 13:16 308,224 --a------ H:\WINDOWS\IsUn040c.exe
2008-09-07 07:51 . 2008-09-07 07:51 256 --a------ H:\WINDOWS\_delis32.ini
2008-09-06 11:06 . 2008-09-12 08:14 <REP> d-------- H:\Documents and Settings\User\Application Data\LimeWire
2008-09-06 09:27 . 2008-09-06 09:27 <REP> d-------- H:\WINDOWS\Sun
2008-09-06 09:27 . 2008-09-06 09:27 <REP> d-------- H:\Program Files\Sun
2008-09-06 09:27 . 2008-06-10 02:32 73,728 --a------ H:\WINDOWS\system32\javacpl.cpl
2008-09-06 09:26 . 2008-09-06 09:27 <REP> d-------- H:\Program Files\Java
2008-09-06 09:24 . 2008-09-06 09:24 <REP> d-------- H:\Program Files\Fichiers communs\Java
2008-09-06 09:16 . 2008-09-15 15:16 <REP> d-------- H:\Program Files\Free Audio Pack
2008-09-02 18:19 . 2008-09-02 18:19 <REP> d-------- H:\WINDOWS\system32\IOSUBSYS
2008-09-02 18:19 . 2006-10-05 13:42 2,560 --------- H:\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-02 18:19 . 2006-10-05 13:42 2,432 --------- H:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-08-30 13:40 . 2008-09-13 04:01 <REP> d-------- H:\WINDOWS\system32\NtmsData
2008-08-30 13:18 . 2008-09-06 08:52 <REP> d-------- H:\Program Files\SIW
2008-08-27 19:47 . 2008-09-02 18:19 <REP> d-------- H:\Program Files\Picasa2
2008-08-24 18:40 . 2008-09-07 07:53 <REP> d-------- H:\Program Files\Yahoo!
2008-08-24 18:40 . 2008-08-24 18:40 <REP> d-------- H:\Program Files\CCleaner
2008-08-24 14:59 . 2008-08-24 19:04 <REP> d-a------ H:\Documents and Settings\All Users\Application Data\TEMP
2008-08-16 19:05 . 2008-08-17 18:01 <REP> d-------- H:\Program Files\Fichiers communs\Symantec Shared
2008-08-16 10:31 . 2008-09-02 12:43 <REP> d-------- H:\WINDOWS\system32\Adobe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-16 04:41 --------- d-----w H:\Program Files\Lx_cats
2008-09-15 10:40 --------- d-----w H:\Documents and Settings\User\Application Data\dvdcss
2008-09-15 04:38 --------- d-----w H:\Documents and Settings\All Users\Application Data\Avira
2008-09-12 01:57 --------- d-----w H:\Program Files\InterActual
2008-09-06 20:53 --------- d-----w H:\Program Files\Windows Live Toolbar
2008-09-06 20:52 --------- d--h--w H:\Program Files\InstallShield Installation Information
2008-08-17 19:32 --------- d-----w H:\Program Files\Google
2008-08-04 03:36 --------- d-----w H:\Program Files\Windows Media Connect 2
2008-08-01 08:52 --------- d-----w H:\Documents and Settings\User\Application Data\ArcSoft
2008-07-28 07:16 --------- d-----w H:\Documents and Settings\User\Application Data\Canon
2008-07-26 01:22 --------- d-----w H:\Program Files\Canon
2008-07-26 01:13 --------- d-----w H:\Program Files\ArcSoft
2008-07-23 08:41 --------- d-----w H:\Documents and Settings\User\Application Data\CyberLink
2008-07-21 08:05 --------- d-----w H:\Documents and Settings\User\Application Data\vlc
2008-07-20 20:06 --------- d-----w H:\Program Files\VideoLAN
2008-07-18 11:10 94,920 ----a-w H:\WINDOWS\system32\cdm.dll
2008-07-18 11:10 53,448 ----a-w H:\WINDOWS\system32\wuauclt.exe
2008-07-18 11:10 45,768 ----a-w H:\WINDOWS\system32\wups2.dll
2008-07-18 11:10 36,552 ----a-w H:\WINDOWS\system32\wups.dll
2008-07-18 11:09 563,912 ----a-w H:\WINDOWS\system32\wuapi.dll
2008-07-18 11:09 325,832 ----a-w H:\WINDOWS\system32\wucltui.dll
2008-07-18 11:09 205,000 ----a-w H:\WINDOWS\system32\wuweb.dll
2008-07-18 11:09 1,811,656 ----a-w H:\WINDOWS\system32\wuaueng.dll
2008-07-18 11:07 270,880 ----a-w H:\WINDOWS\system32\mucltui.dll
2008-07-18 11:07 210,976 ----a-w H:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w H:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w H:\WINDOWS\system32\mscms.dll
2008-06-24 07:12 295,936 ------w H:\WINDOWS\system32\wmpeffects.dll
2008-06-23 15:40 663,552 ----a-w H:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w H:\WINDOWS\system32\mswsock.dll
2008-06-06 08:54 35,152 -c--a-w H:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT
2008-06-01 07:15 15,397 -c--a-w H:\Program Files\settings.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="H:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="H:\Program Files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"swg"="H:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-07-25 171448]
"Picasa Media Detector"="H:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2006-06-01 86016]
"LXCFCATS"="H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-21 73728]
"LVCOMSX"="H:\WINDOWS\system32\LVCOMSX.EXE" [2004-12-14 221184]
"LogitechVideoRepair"="H:\Program Files\Logitech\Video\ISStart.exe" [2004-12-14 458752]
"LogitechVideoTray"="H:\Program Files\Logitech\Video\LogiTray.exe" [2004-12-14 217088]
"Adobe Reader Speed Launcher"="H:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"RemoteControl"="H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SunJavaUpdateSched"="H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"InCD"="H:\Program Files\Ahead\InCD\InCD.exe" [2005-01-28 1381376]
"avgnt"="H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2006-06-01 H:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
H:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - H:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2007-01-15 16:14 147456 H:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 00:54 15360 H:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 H:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 H:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a--c--- 2005-05-03 18:43 69632 H:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Raccourci vers la page des propriétés de High Definition Audio]
--------- 2005-01-07 17:07 61952 H:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a--c--- 2005-06-29 13:25 14720000 H:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"H:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"H:\\WINDOWS\\system32\\dpvsetup.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12011:TCP"= 12011:TCP:NortonAV
"12914:TCP"= 12914:TCP:NortonAV
R3 3xHybrid;3xHybrid service;H:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{0CCADB30-E6E0-4190-B957-07475720491E} - (no file)
BHO-{2E88B5AE-9737-415B-BE30-371B8E5DC001} - (no file)
ShellExecuteHooks-{2E88B5AE-9737-415B-BE30-371B8E5DC001} - (no file)
Notify-yayyWpQH - yayyWpQH.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - H:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ugo6h234.default\
FF -: plugin - H:\Program Files\Picasa2\npPicasa2.dll
FF -: plugin - H:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-16 16:45:15
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCFCATS = rundll32 H:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-16 16:46:42
ComboFix-quarantined-files.txt 2008-09-16 05:46:19
Avant-CF: 223,587,094,528 octets libres
AprŠs-CF: 223,590,854,656 octets libres
202 --- E O F --- 2008-09-12 06:49:54