ComboFix 07-11-08.1 - M 2007-11-15 21:01:47.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.35 [GMT 1:00]
Running from: C:\Documents and Settings\M\Bureau\ComboFix.exe
* Created a new restore point
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\M\Bureau\Live Safety Center.lnk
C:\Documents and Settings\M\Bureau\Online Security Guide.lnk
C:\Documents and Settings\M\Favoris\Online Security Guide.lnk
C:\Program Files\BestsellerAntivirus
C:\WINDOWS\system32\__c00B9194.dat
C:\WINDOWS\system32\bbeeg.ini
C:\WINDOWS\system32\bbeeg.ini2
C:\WINDOWS\system32\geebb.dll
C:\WINDOWS\system32\rjummrqr.dll
C:\WINDOWS\system32\rkhoarkm.dllbox
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-15 to 2007-11-15 ))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:58 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-15 19:31 <REP> d-------- C:\Documents and Settings\M\Stellarium
2007-11-15 19:28 85,056 --a------ C:\WINDOWS\system32\phftwawl.dll
2007-11-15 19:27 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-15 19:25 79,936 --a------ C:\WINDOWS\system32\jbjuwrow.dll
2007-11-15 19:20 145,984 --a------ C:\WINDOWS\system32\rkhoarkm.dll
2007-11-15 19:19 145,984 --a------ C:\WINDOWS\system32\kdjrpsiy.dll
2007-11-15 19:16 71,232 --a------ C:\WINDOWS\system32\cxmqngrl.exe
2007-11-14 17:40 <REP> d-------- C:\Program Files\MSXML 4.0
2007-11-14 17:33 37,376 --a------ C:\WINDOWS\system32\urqoomj.dll
2007-11-14 16:53 <REP> d-------- C:\Program Files\DirectX9
2007-11-13 19:05 63,890 --a------ C:\WINDOWS\BricoPackUninst.cmd
2007-11-13 19:01 6,106 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-11-13 18:59 <REP> d-------- C:\WINDOWS\BricoPacks
2007-11-13 18:42 <REP> d-------- C:\Documents and Settings\M\Application Data\Media Player Classic
2007-11-13 18:41 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-11-13 18:41 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-11-13 18:41 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2007-11-13 18:41 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-11-13 18:39 <REP> d-------- C:\Program Files\CursorXP
2007-11-03 10:47 <REP> d-------- C:\WINDOWS\Sun
2007-11-03 10:46 <REP> d-------- C:\Program Files\Java
2007-11-03 10:43 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-11-03 10:22 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2007-11-02 09:14 <REP> d-------- C:\Program Files\ComOne
2007-11-02 08:59 <REP> d-------- C:\Documents and Settings\M\Application Data\Nokia
2007-11-02 08:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2007-11-02 08:58 <REP> d-------- C:\Program Files\DIFX
2007-11-02 08:57 <REP> d-------- C:\Documents and Settings\M\Application Data\PC Suite
2007-11-02 08:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-02 08:56 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 22:02 --------- d-----w C:\Documents and Settings\M\Application Data\XnView
2007-11-14 13:25 --------- d-----w C:\Program Files\Paint Shop Pro 6
2007-11-10 12:50 --------- d-----w C:\Documents and Settings\M\Application Data\U3
2007-11-03 09:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skyline
2007-09-21 20:53 --------- d-----w C:\Program Files\Mozilla Thunderbird
2007-09-15 12:58 --------- d-----w C:\Program Files\Avast4
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{028c96f3-da78-42d1-adb5-cd75933424c4}]
2007-11-15 19:25 79936 --a------ C:\WINDOWS\system32\jbjuwrow.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-15 19:20 145984 --a------ C:\WINDOWS\system32\rkhoarkm.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\rkhoarkm.dll [2007-11-15 19:20 145984]
[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GSICONEXE"="GSICON.EXE" [2002-01-22 20:01 C:\WINDOWS\system32\gsicon.exe]
"DSLAGENTEXE"="dslagent.exe" [2002-01-22 20:01 C:\WINDOWS\system32\dslagent.exe]
"SoundMan"="SOUNDMAN.EXE" [2002-11-19 21:01 C:\WINDOWS\SOUNDMAN.EXE]
"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.exe" [2002-01-28 13:48]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" []
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
"TPP Auto Loader"="C:\WINDOWS\tppaldr.exe" [2002-06-24 10:20]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"OmniPage"="C:\Program Files\Caere\OmniPagePro10.0\opware32.exe" [1999-11-08 01:04]
"CheckMedi8or"="C:\Program Files\Mediator5\CheckNewUser.exe" [1999-10-20 10:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"40af1f42"="C:\WINDOWS\system32\phftwawl.dll" [2007-11-15 19:28]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-01-19 14:18]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 16:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rkhoarkm]
rkhoarkm.dll 2007-11-15 19:20 145984 C:\WINDOWS\system32\rkhoarkm.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\geebb.dll
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R2 BsUDF;BsUDF;C:\WINDOWS\system32\drivers\BsUDF.sys
R3 wanusb;ECI Telecom USB ADSL WAN Modem;C:\WINDOWS\system32\DRIVERS\gwausb.sys
S2 gafwload;ECI Telecom USB ADSL Loader;C:\WINDOWS\system32\DRIVERS\gafwload.sys
S3 fbxusb;FreeBox USB Network Adapter;C:\WINDOWS\system32\DRIVERS\fbxusb.sys
S3 TPP200;USB Storage Adapter V2 (TPP);C:\WINDOWS\system32\DRIVERS\TPP200.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b6e8b5-b9f1-11db-8421-00ff00300101}]
\Shell\AutoRun\command - G:\LaunchU3.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-15 21:14:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-15 21:17:22 - machine was rebooted
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:45, on 15/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avast4\aswUpdSv.exe
C:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Avast4\ashMaiSv.exe
C:\Program Files\Avast4\ashWebSv.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\GSICON.EXE
C:\WINDOWS\system32\dslagent.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LXSUPMON.EXE
C:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\tppaldr.exe
C:\Program Files\Caere\OmniPagePro10.0\opware32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\Acrobat\Reader\reader_sl.exe
C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: {4c424339-57dc-5bda-1d24-87ad3f69c820} - {028c96f3-da78-42d1-adb5-cd75933424c4} - C:\WINDOWS\system32\jbjuwrow.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\rkhoarkm.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\rkhoarkm.dll
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [OmniPage] C:\Program Files\Caere\OmniPagePro10.0\opware32.exe
O4 - HKLM\..\Run: [CheckMedi8or] C:\Program Files\Mediator5\CheckNewUser.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [40af1f42] rundll32.exe "C:\WINDOWS\system32\phftwawl.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Acrobat\Reader\reader_sl.exe
O4 - Global Startup: NETGEAR WG311T Wireless Assistant.lnk = C:\Program Files\NETGEAR\WG311T\wlancfg5.exe
O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{EF62248E-0C67-4288-AD76-758A84639512}: NameServer = 84.103.237.140 86.64.145.140
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: rkhoarkm - C:\WINDOWS\SYSTEM32\rkhoarkm.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
--
End of file - 7038 bytes