salut voici mon rapport
ComboFix 07-06-13.7 - D:\Documents and Settings\Corey\Bureau\ComboFix.exe
"Corey" - 2007-06-19 0:25:16 - Service Pack 2 NTFS [SAFE MODE]
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
D:\WINDOWS\system32\oswkmkuc.dll
D:\WINDOWS\system32\cukmkwso.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((( Files Created from 2007-05-18 to 2007-06-18 )))))))))))))))))))))))))))))))
2007-06-19 00:25 49,152 --a------ D:\WINDOWS\nircmd.exe
2007-06-18 18:18 <REP> d-------- D:\VundoFix Backups
2007-06-16 08:38 14,848 --a------ D:\WINDOWS\system32\drivers\kbdhid.sys
2007-06-16 08:36 5,600 --a------ D:\WINDOWS\system32\drivers\WmVirHid.sys
2007-06-16 08:36 45,504 --a------ D:\WINDOWS\system32\drivers\WmXlCore.sys
2007-06-16 08:36 22,240 --a------ D:\WINDOWS\system32\drivers\WmFilter.sys
2007-06-16 08:36 17,632 --a------ D:\WINDOWS\system32\drivers\WmHidLo.sys
2007-06-16 08:36 159,744 --a------ D:\WINDOWS\system32\WmJoyFrc.dll
2007-06-16 08:36 10,144 --a------ D:\WINDOWS\system32\drivers\WmBEnum.sys
2007-06-16 08:36 <REP> d-------- D:\Program Files\Logitech
2007-06-16 08:36 <REP> d-------- D:\Program Files\Fichiers communs\Logitech
2007-06-15 07:56 62,516 --a------ D:\WINDOWS\system32\mjdpunqb.dll
2007-06-10 19:23 2,366 --a------ D:\WINDOWS\system32\tmp.reg
2007-06-10 19:22 53,248 --a------ D:\WINDOWS\system32\Process.exe
2007-06-10 19:22 51,200 --a------ D:\WINDOWS\system32\dumphive.exe
2007-06-10 19:22 288,417 --a------ D:\WINDOWS\system32\SrchSTS.exe
2007-06-10 19:11 <REP> d-------- D:\backups
2007-06-06 21:20 524,288 --ah----- D:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-06 21:20 <REP> dr------- D:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-06-06 21:20 <REP> d--h----- D:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2007-06-06 21:20 <REP> d--h----- D:\DOCUME~1\ADMINI~1\Voisinage d'impression
2007-06-06 21:20 <REP> d--h----- D:\DOCUME~1\ADMINI~1\ModŠles
2007-06-06 21:20 <REP> d-------- D:\DOCUME~1\ADMINI~1\Mes documents
2007-06-06 21:20 <REP> d-------- D:\DOCUME~1\ADMINI~1\Favoris
2007-06-06 21:20 <REP> d-------- D:\DOCUME~1\ADMINI~1\Bureau
2007-06-06 20:55 <REP> d-------- D:\bfu
2007-06-06 20:14 55,316 --a------ D:\WINDOWS\system32\hdbojexp.dll
2007-06-06 17:25 420,816 --a------ D:\WINDOWS\system32\wunauclt.exe
2007-06-05 23:47 68,888 --a------ D:\WINDOWS\system32\xinput1_3.dll
2007-06-05 23:47 62,744 --a------ D:\WINDOWS\system32\xinput1_2.dll
2007-06-05 23:47 3,426,072 --a------ D:\WINDOWS\system32\d3dx9_32.dll
2007-06-05 23:47 255,848 --a------ D:\WINDOWS\system32\xactengine2_6.dll
2007-06-05 23:47 251,672 --a------ D:\WINDOWS\system32\xactengine2_5.dll
2007-06-05 23:47 237,848 --a------ D:\WINDOWS\system32\xactengine2_4.dll
2007-06-05 23:47 236,824 --a------ D:\WINDOWS\system32\xactengine2_3.dll
2007-06-05 23:47 2,414,360 --a------ D:\WINDOWS\system32\d3dx9_31.dll
2007-06-05 23:47 15,128 --a------ D:\WINDOWS\system32\x3daudio1_1.dll
2007-05-25 23:52 7,552 --a------ D:\WINDOWS\system32\drivers\enodpl.sys
2007-05-25 23:52 4,736 --a------ D:\WINDOWS\system32\drivers\tandpl.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-18 22:14:32 -------- d--h--w D:\Program Files\InstallShield Installation Information
2007-06-18 22:00:04 -------- d-----w D:\Program Files\eMule
2007-06-06 16:56:20 -------- d-----w D:\Program Files\Windows Defender
2007-05-24 17:39:25 -------- d-----w D:\Program Files\Winamp
2007-05-22 20:42:37 -------- d-----w D:\Program Files\GIMP-2.0
2007-05-18 20:41:57 -------- d-----w D:\Program Files\Ares
2007-05-05 19:53:11 -------- d-----w D:\Program Files\CCleaner
2007-05-05 08:06:22 -------- d-----w D:\Program Files\ewido anti-spyware 4.0
2007-04-30 15:46:10 745,600 ----a-w D:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:41:55 85,952 ----a-w D:\WINDOWS\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w D:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-30 15:39:41 23,416 ----a-w D:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-30 15:38:51 43,176 ----a-w D:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-30 15:37:23 26,888 ----a-w D:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w D:\WINDOWS\system32\AVASTSS.scr
2007-04-23 16:12:24 -------- d-----w D:\Program Files\Fichiers communs\Pointstone
2007-04-23 16:07:03 -------- d-----w D:\Program Files\Microsoft IntelliPoint
2007-04-23 16:06:51 -------- d-----w D:\DOCUME~1\Corey\APPLIC~1\Pointstone
2007-04-18 16:14:18 2,854,400 ----a-w D:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w D:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w D:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w D:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w D:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w D:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w D:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w D:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w D:\WINDOWS\system32\wups2.dll
2007-04-16 20:44:20 271,224 ----a-w D:\WINDOWS\system32\mucltui.dll
2007-04-16 20:44:18 208,248 ----a-w D:\WINDOWS\system32\muweb.dll
2007-03-30 20:25:45 6,712 ----a-w D:\WINDOWS\system32\d3d9caps.dat
2007-03-25 06:12:24 48,856 ----a-w D:\WINDOWS\system32\perfc00C.dat
2007-03-25 06:12:24 368,076 ----a-w D:\WINDOWS\system32\perfh00C.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 23:08]
{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}=D:\WINDOWS\system32\mjdpunqb.dll [2007-06-15 07:56]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=d:\program files\google\googletoolbar3.dll [2007-02-10 21:48]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [2007-05-27 20:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 21:10]
"avast!"="D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
"IntelliPoint"="D:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 01:50]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 09:54 D:\WINDOWS\SOUNDMAN.EXE]
"WinampAgent"="D:\Program Files\Winamp\winampa.exe" [2007-05-15 00:22]
"I downloaded pirated Software from P2P"="Virtua Tennis 3" []
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
"MSMSGS"="D:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"Start WingMan Profiler"="D:\Program Files\Logitech\Profiler\lwemon.exe" [2005-04-18 11:16]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrkq32]
winrkq32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"D:\Program Files\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
D:\Program Files\Winamp\winampa.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7be7cde-3c09-11da-b485-806d6172696f}]
AutoRun\command- H:\Setup.exe
Contents of the 'Scheduled Tasks' folder
2007-06-18 22:28:24 D:\WINDOWS\tasks\HP Usg Daily.job
2007-06-18 22:28:26 D:\WINDOWS\tasks\HP Usg Login.job
2007-06-06 07:28:52 D:\WINDOWS\tasks\MP Scheduled Scan.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-19 00:27:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
Completion time: 2007-06-19 0:29:18 - machine was rebooted
D:\ComboFix-quarantined-files.txt ... 2007-06-19 00:28
--- E O F ---