[07/19/2008, 19:07:56] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nico\Bureau\VirtumundoBeGone.exe" )
[07/19/2008, 19:08:03] - Detected System Information:
[07/19/2008, 19:08:03] - Windows Version: 5.1.2600, Service Pack 3
[07/19/2008, 19:08:03] - Current Username: Nico (Admin)
[07/19/2008, 19:08:03] - Windows is in NORMAL mode.
[07/19/2008, 19:08:03] - Searching for Browser Helper Objects:
[07/19/2008, 19:08:03] - BHO 1: {0F2938EE-10AB-4F60-9AA4-6E14CCBF1EC6} ()
[07/19/2008, 19:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:03] - Checking for HKLM\...\Winlogon\Notify\tuvuSkLF
[07/19/2008, 19:08:03] - Key not found: HKLM\...\Winlogon\Notify\tuvuSkLF, continuing.
[07/19/2008, 19:08:03] - BHO 2: {2A65BE74-EC8D-401E-93DF-5BDA3DC05505} ()
[07/19/2008, 19:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:03] - Checking for HKLM\...\Winlogon\Notify\cbXNHWpP
[07/19/2008, 19:08:03] - Found: HKLM\...\Winlogon\Notify\cbXNHWpP - This is probably Virtumundo.
[07/19/2008, 19:08:03] - Assigning {2A65BE74-EC8D-401E-93DF-5BDA3DC05505} MSEvents Object
[07/19/2008, 19:08:03] - BHO list has been changed! Starting over...
[07/19/2008, 19:08:03] - BHO 1: {0F2938EE-10AB-4F60-9AA4-6E14CCBF1EC6} ()
[07/19/2008, 19:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:03] - Checking for HKLM\...\Winlogon\Notify\tuvuSkLF
[07/19/2008, 19:08:03] - Key not found: HKLM\...\Winlogon\Notify\tuvuSkLF, continuing.
[07/19/2008, 19:08:03] - BHO 2: {2A65BE74-EC8D-401E-93DF-5BDA3DC05505} (MSEvents Object)
[07/19/2008, 19:08:03] - ALERT: Found MSEvents Object!
[07/19/2008, 19:08:03] - BHO 3: {9372bc8c-56e0-4e81-8246-072894be246e} ()
[07/19/2008, 19:08:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:03] - Checking for HKLM\...\Winlogon\Notify\kyyhgc
[07/19/2008, 19:08:03] - Key not found: HKLM\...\Winlogon\Notify\kyyhgc, continuing.
[07/19/2008, 19:08:03] - Finished Searching Browser Helper Objects
[07/19/2008, 19:08:03] - *** Detected MSEvents Object
[07/19/2008, 19:08:03] - Trying to remove MSEvents Object...
[07/19/2008, 19:08:04] - Terminating Process: IEXPLORE.EXE
[07/19/2008, 19:08:05] - Terminating Process: RUNDLL32.EXE
[07/19/2008, 19:08:05] - Disabling Automatic Shell Restart
[07/19/2008, 19:08:05] - Terminating Process: EXPLORER.EXE
[07/19/2008, 19:08:05] - Suspending the NT Session Manager System Service
[07/19/2008, 19:08:05] - Terminating Windows NT Logon/Logoff Manager
[07/19/2008, 19:08:05] - Re-enabling Automatic Shell Restart
[07/19/2008, 19:08:05] - File to disable: C:\WINDOWS\system32\cbXNHWpP.dll
[07/19/2008, 19:08:05] - Renaming C:\WINDOWS\system32\cbXNHWpP.dll -> C:\WINDOWS\system32\cbXNHWpP.dll.vir
[07/19/2008, 19:08:05] - File successfully renamed!
[07/19/2008, 19:08:05] - Removing HKLM\...\Browser Helper Objects\{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}
[07/19/2008, 19:08:05] - Removing HKCR\CLSID\{2A65BE74-EC8D-401E-93DF-5BDA3DC05505}
[07/19/2008, 19:08:05] - Adding Kill Bit for ActiveX for GUID: {2A65BE74-EC8D-401E-93DF-5BDA3DC05505}
[07/19/2008, 19:08:05] - Deleting ATLEvents/MSEvents Registry entries
[07/19/2008, 19:08:05] - Removing HKLM\...\Winlogon\Notify\cbXNHWpP
[07/19/2008, 19:08:05] - Searching for Browser Helper Objects:
[07/19/2008, 19:08:05] - BHO 1: {0F2938EE-10AB-4F60-9AA4-6E14CCBF1EC6} ()
[07/19/2008, 19:08:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:05] - Checking for HKLM\...\Winlogon\Notify\tuvuSkLF
[07/19/2008, 19:08:05] - Key not found: HKLM\...\Winlogon\Notify\tuvuSkLF, continuing.
[07/19/2008, 19:08:05] - BHO 2: {9372bc8c-56e0-4e81-8246-072894be246e} ()
[07/19/2008, 19:08:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:08:05] - Checking for HKLM\...\Winlogon\Notify\kyyhgc
[07/19/2008, 19:08:05] - Key not found: HKLM\...\Winlogon\Notify\kyyhgc, continuing.
[07/19/2008, 19:08:05] - Finished Searching Browser Helper Objects
[07/19/2008, 19:08:05] - Finishing up...
[07/19/2008, 19:08:05] - A restart is needed.
[07/19/2008, 19:08:11] - Attempting to Restart via STOP error (Blue Screen!)
[07/19/2008, 19:10:45] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Nico\Bureau\VirtumundoBeGone.exe" )
[07/19/2008, 19:10:50] - Detected System Information:
[07/19/2008, 19:10:50] - Windows Version: 5.1.2600, Service Pack 3
[07/19/2008, 19:10:50] - Current Username: Nico (Admin)
[07/19/2008, 19:10:50] - Windows is in NORMAL mode.
[07/19/2008, 19:10:50] - Searching for Browser Helper Objects:
[07/19/2008, 19:10:50] - BHO 1: {8860BDC3-49C9-4868-882D-81BCF01B21B5} ()
[07/19/2008, 19:10:50] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:10:50] - Checking for HKLM\...\Winlogon\Notify\tuvuSkLF
[07/19/2008, 19:10:50] - Key not found: HKLM\...\Winlogon\Notify\tuvuSkLF, continuing.
[07/19/2008, 19:10:50] - BHO 2: {9372bc8c-56e0-4e81-8246-072894be246e} ()
[07/19/2008, 19:10:50] - WARNING: BHO has no default name. Checking for Winlogon reference.
[07/19/2008, 19:10:50] - Checking for HKLM\...\Winlogon\Notify\kyyhgc
[07/19/2008, 19:10:50] - Key not found: HKLM\...\Winlogon\Notify\kyyhgc, continuing.
[07/19/2008, 19:10:50] - Finished Searching Browser Helper Objects
[07/19/2008, 19:10:50] - Finishing up...
[07/19/2008, 19:10:50] - Nothing found! Exiting...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:12:16, on 19/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\freedom.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {8860BDC3-49C9-4868-882D-81BCF01B21B5} - C:\WINDOWS\system32\tuvuSkLF.dll
O2 - BHO: {e642eb49-8270-6428-18e4-0e65c8cb2739} - {9372bc8c-56e0-4e81-8246-072894be246e} - C:\WINDOWS\system32\kyyhgc.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [10bcd718] rundll32.exe "C:\WINDOWS\system32\tykhjasb.dll",b
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 3532 bytes
ComboFix 08-07-18.5 - Nico 2008-07-19 19:14:28.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2617 [GMT 2:00]
Endroit: C:\Documents and Settings\Nico\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Nico\Application Data\rhc9sbj0epb9
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\blphccsbj0epb9.scr
C:\WINDOWS\system32\bsajhkyt.ini
C:\WINDOWS\system32\FLkSuvut.ini
C:\WINDOWS\system32\FLkSuvut.ini2
C:\WINDOWS\system32\kyyhgc.dll
C:\WINDOWS\system32\lphccsbj0epb9.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\phccsbj0epb9.bmp
C:\WINDOWS\system32\pphccsbj0epb9.exe
C:\WINDOWS\system32\rlgefaqv.dll
C:\WINDOWS\system32\tuvuSkLF.dll
C:\WINDOWS\system32\tykhjasb.dll
C:\WINDOWS\system32\vtUnlIXn.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-19 to 2008-07-19 ))))))))))))))))))))))))))))))))))))
.
2008-07-19 19:02 . 2008-07-19 19:02 <REP> d-------- C:\VundoFix Backups
2008-07-19 18:58 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Program Files\Avira
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-19 18:16 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-07-19 18:16 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-07-19 18:16 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-07-19 18:16 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-07-19 18:16 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-07-19 18:16 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-07-19 18:16 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-07-19 18:16 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-07-19 18:16 . 2008-07-19 18:58 896 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-19 17:42 . 2008-07-19 17:42 <REP> d-------- C:\Program Files\Trend Micro
2008-07-19 15:45 . 2008-07-19 15:45 <REP> d-------- C:\Program Files\Enigma Software Group
2008-07-19 15:19 . 2008-07-19 16:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-19 15:13 . 2008-07-19 15:13 32,640 --a------ C:\WINDOWS\system32\cbXNHWpP.dll.vir
2008-07-18 18:36 . 2008-07-18 18:36 <REP> d-------- C:\Program Files\Alcohol Soft
2008-07-18 18:36 . 2008-04-13 20:45 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-07-18 18:34 . 2008-07-18 18:34 716,272 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-18 00:16 . 2008-07-19 16:50 <REP> d-------- C:\Documents and Settings\Nico\Application Data\Azureus
2008-07-18 00:16 . 2008-07-18 00:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2008-07-18 00:13 . 2008-07-18 00:14 <REP> d-------- C:\Program Files\Vuze
2008-07-18 00:11 . 2008-07-18 00:11 <REP> d-------- C:\Documents and Settings\Nico\Application Data\vlc
2008-07-18 00:10 . 2008-07-18 00:10 <REP> d-------- C:\Program Files\VideoLAN
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage r‚seau
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage d'impression
2008-07-17 23:47 . 2008-07-17 21:52 <REP> d--h----- C:\Documents and Settings\Default User\ModŠles
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d-------- C:\Documents and Settings\Default User\Mes documents
2008-07-17 23:47 . 2008-07-17 23:47 <REP> dr------- C:\Documents and Settings\Default User\Menu D‚marrer
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d-------- C:\Documents and Settings\Default User\Favoris
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d-------- C:\Documents and Settings\Default User\Bureau
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d--h----- C:\Documents and Settings\All Users\ModŠles
2008-07-17 23:47 . 2008-07-19 15:49 <REP> dr------- C:\Documents and Settings\All Users\Menu D‚marrer
2008-07-17 23:47 . 2008-07-17 23:47 <REP> d-------- C:\Documents and Settings\All Users\Favoris
2008-07-17 23:47 . 2008-07-17 21:53 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-07-17 23:47 . 2008-07-19 19:07 <REP> d-------- C:\Documents and Settings\All Users\Bureau
2008-07-17 23:46 . 2008-07-18 08:01 <REP> d-------- C:\temp
2008-07-17 23:45 . 2004-08-05 14:00 1,086,058 -ra------ C:\WINDOWS\SET1F.tmp
2008-07-17 23:45 . 2004-08-05 14:00 1,014,836 -ra------ C:\WINDOWS\SET1C.tmp
2008-07-17 23:45 . 2004-08-05 14:00 14,043 -ra------ C:\WINDOWS\SET2B.tmp
2008-07-17 23:44 . 2008-07-17 22:46 <REP> d--h----- C:\Documents and Settings\Default User
2008-07-17 23:44 . 2008-07-17 21:55 <REP> d-------- C:\Documents and Settings\All Users
2008-07-17 23:39 . 2008-07-17 23:39 <REP> d-------- C:\Program Files\Hamachi
2008-07-17 23:39 . 2008-07-17 23:39 10,345 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-07-17 23:32 . 2008-07-17 23:32 <REP> d-------- C:\Documents and Settings\Nico\Application Data\teamspeak2
2008-07-17 23:31 . 2008-07-17 23:32 <REP> d-------- C:\Program Files\Teamspeak2_RC2
2008-07-17 23:31 . 2008-07-17 23:31 34,064 --a------ C:\WINDOWS\system32\lhacm.acm
2008-07-17 20:49 . 2008-04-13 20:32 196,224 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-07-17 20:49 . 2008-04-14 04:33 191,488 --a------ C:\WINDOWS\system32\cmprops.dll
2008-07-17 20:49 . 2008-04-14 04:33 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2008-07-17 20:49 . 2008-04-14 04:33 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2008-07-17 20:49 . 2008-04-14 04:34 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-07-17 20:49 . 2008-04-14 04:33 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll
2008-06-20 19:47 . 2008-06-20 19:47 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 19:47 . 2008-06-20 19:47 147,968 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 13:51 . 2008-06-20 13:51 361,600 -----c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 13:40 . 2008-06-20 13:40 138,496 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 13:08 . 2008-06-20 13:08 225,856 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 20:39 --------- d-----w C:\Program Files\Alwil Software
2008-07-17 20:33 --------- d-----w C:\Program Files\Google
2008-07-17 20:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-17 20:24 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-07-17 20:17 --------- d-----w C:\Program Files\DIFX
2008-07-17 19:56 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-17 19:55 --------- d-----w C:\Program Files\Services en ligne
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-11-21 04:12 3297280]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 04:34 1695232]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 18:46 217544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:33 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Vuze\\Azureus.exe"=
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-10bcd718 - C:\WINDOWS\system32\tykhjasb.dll
ShellExecuteHooks-{2A65BE74-EC8D-401E-93DF-5BDA3DC05505} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-19 19:21:45
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-19 19:23:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-19 17:23:07
Pre-Run: 14,299,463,680 octets libres
Post-Run: 14,266,060,800 octets libres
152 --- E O F --- 2008-07-19 10:27:13