jambonchile 09 septembre 2006 à 18h01
Voici le rapport, merci pour ton aide.
Logfile of HijackThis v1.99.1
Scan saved at 17:56:50, on 09/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\WINDOWS\system32\ati2sgag.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\Olivier\Bureau\Scanner.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{98D192B0-02AB-43F3-8F62-BB9F3BDEAA64}: NameServer = 212.27.54.252,212.27.53.252
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
jambonchile 10 septembre 2006 à 11h08
Désolé, je les avais collés, ça devait faire trop de texte pour une réponse rapide.
Rapport Ewido
---------------------------------------------------------
ewido anti-spyware - Scan-Bericht
---------------------------------------------------------
+ Erstellt um: 10:43:47 10/09/2006
+ Scan-Ergebnis:
:mozilla.70:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.247realmedia : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.71:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.247realmedia : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.39:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Adtech : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.40:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Adtech : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.21:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Atdmt : Mit Backup gesäubert (unter Quarantäne gestellt).
C:\Documents and Settings\Olivier\Cookies\olivier@atdmt[2].txt -> TrackingCookie.Atdmt : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.20:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Doubleclick : Mit Backup gesäubert (unter Quarantäne gestellt).
C:\Documents and Settings\Olivier\Cookies\olivier@doubleclick[1].txt -> TrackingCookie.Doubleclick : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.56:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Mediaplex : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.10:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Serving-sys : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.14:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Serving-sys : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.15:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Serving-sys : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.16:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Serving-sys : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.17:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Serving-sys : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.11:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Smartadserver : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.12:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Smartadserver : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.13:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Smartadserver : Mit Backup gesäubert (unter Quarantäne gestellt).
C:\Documents and Settings\Olivier\Cookies\olivier@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.33:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Tradedoubler : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.6:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Weborama : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.7:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Weborama : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.8:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Weborama : Mit Backup gesäubert (unter Quarantäne gestellt).
:mozilla.9:C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\20ph8cq9.default\cookies.txt -> TrackingCookie.Weborama : Mit Backup gesäubert (unter Quarantäne gestellt).
::Berichtende
Rapport clean
Script clean par Malekal_morte -
http://www.malekal.com
Microsoft Windows XP [version 5.1.2600]
Script execute en mode sans echec
*** Suppression de fichiers sur C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
*** Suppression des clefs du registre effectuee..
Rapport HijackThis
Logfile of HijackThis v1.99.1
Scan saved at 11:01:37, on 10/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Olivier\Bureau\Scanner.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{98D192B0-02AB-43F3-8F62-BB9F3BDEAA64}: NameServer = 212.27.54.252,212.27.53.252
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
jambonchile 17 septembre 2006 à 09h26
Olivier - 06-07-17 9:24:29,31 Service Pack 2
ComboFix 06.09.14 - Running from: C:\Documents and Settings\Olivier\Bureau
((((((((((((((((((((((((((((((( Files Created from 2006-06-17 to 2006-07-17 ))))))))))))))))))))))))))))))))))
2006-07-29 19:32 48,936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-29 15:04 476,320 --a------ C:\WINDOWS\system32\ImagXpr7.dll
2006-07-29 15:04 471,040 --a------ C:\WINDOWS\system32\ImagXRA7.dll
2006-07-29 15:04 262,144 --a------ C:\WINDOWS\system32\ImagXR7.dll
2006-07-29 15:04 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2006-07-29 15:04 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2006-07-29 15:04 1,568,768 --a------ C:\WINDOWS\system32\ImagX7.dll
2006-07-26 23:55 516,096 --a------ C:\WINDOWS\system32\ati2sgag.exe
2006-07-26 23:54 86,016 --a------ C:\WINDOWS\system32\ati2evxx.dll
2006-07-26 23:54 81,920 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2006-07-26 23:54 65,536 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2006-07-26 23:54 6,508,544 --a------ C:\WINDOWS\system32\atioglxx.dll
2006-07-26 23:54 389,120 --a------ C:\WINDOWS\system32\ati2evxx.exe
2006-07-26 23:54 30,720 --a------ C:\WINDOWS\system32\ati2edxx.dll
2006-07-26 23:54 294,912 --a------ C:\WINDOWS\system32\atiiiexx.dll
2006-07-26 23:54 24,064 --a------ C:\WINDOWS\system32\ativcoxx.dll
2006-07-26 23:54 17,408 --a------ C:\WINDOWS\system32\atitvo32.dll
2006-07-26 23:54 151,552 --a------ C:\WINDOWS\system32\ATIDEMGR.dll
2006-07-26 23:54 126,976 --a------ C:\WINDOWS\system32\atipdlxx.dll
2006-07-26 23:54 102,400 --a------ C:\WINDOWS\system32\Oemdspif.dll
2006-07-26 22:54 724,992 --a------ C:\WINDOWS\iun6002.exe
2006-07-26 22:38 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2006-07-26 22:33 107,134 --a------ C:\WINDOWS\UninstallFirefox.exe
2006-07-26 22:23 76,800 --a------ C:\WINDOWS\system32\storprop.dll
2006-07-26 22:23 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2006-07-26 22:23 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2006-07-26 21:27 24,816 --a------ C:\WINDOWS\system32\mdimon.dll
2006-07-26 21:14 476,928 --a------ C:\WINDOWS\system32\ativvaxx.dll
2006-07-26 21:14 237,568 --a------ C:\WINDOWS\system32\ati2cqag.dll
2006-07-26 21:14 209,408 --a------ C:\WINDOWS\system32\ati2dvag.dll
2006-07-26 21:14 2,239,328 --a------ C:\WINDOWS\system32\ati3duag.dll
2006-07-26 21:12 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2006-07-26 21:08 90,112 --a------ C:\WINDOWS\Updreg.EXE
2006-07-26 21:08 84,992 --a------ C:\WINDOWS\system32\SFCVRT32.DLL
2006-07-26 21:08 82,432 --a------ C:\WINDOWS\system32\CTWFLT32.DLL
2006-07-26 21:08 65,536 -ra------ C:\WINDOWS\system32\A3d.dll
2006-07-26 21:08 60,928 -ra------ C:\WINDOWS\system32\P17.dll
2006-07-26 21:08 54,784 --a------ C:\WINDOWS\system32\INETWH32.DLL
2006-07-26 21:08 53,552 --a------ C:\WINDOWS\CTCCW.DLL
2006-07-26 21:08 53,248 -ra------ C:\WINDOWS\system32\P17CPI.dll
2006-07-26 21:08 49,152 --a------ C:\WINDOWS\MIDIDEF.EXE
2006-07-26 21:08 40,960 --a------ C:\WINDOWS\system32\AC3API.DLL
2006-07-26 21:08 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2006-07-26 21:08 36,864 -ra------ C:\WINDOWS\system32\sfman32.dll
2006-07-26 21:08 26,768 --a------ C:\WINDOWS\system32\CTL3D.DLL
2006-07-26 21:08 24,976 --a------ C:\WINDOWS\CTRES.DLL
2006-07-26 21:08 24,576 --a------ C:\WINDOWS\INRES.DLL
2006-07-26 21:08 20,480 --a------ C:\WINDOWS\P17DEF.EXE
2006-07-26 21:08 172,032 -ra------ C:\WINDOWS\system32\sfms32.dll
2006-07-26 21:08 159,744 --a------ C:\WINDOWS\system32\OPENAL32.DLL
2006-07-26 21:08 149,504 --a------ C:\WINDOWS\system32\MFCANS32.DLL
2006-07-26 21:08 147,456 -ra------ C:\WINDOWS\system32\CtDvInst.dll
2006-07-26 21:08 139,264 --a------ C:\WINDOWS\system32\EAX.DLL
2006-07-26 21:08 136,704 -ra------ C:\WINDOWS\system32\P17res.dll
2006-07-26 21:08 11,766 --a------ C:\WINDOWS\SETTINGS.REG
2006-07-26 21:08 108,032 --a------ C:\WINDOWS\system32\MFCUIA32.DLL
2006-07-26 20:33 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2006-07-26 20:33 0 -rahs---- C:\MSDOS.SYS
2006-07-26 20:33 0 -rahs---- C:\IO.SYS
2006-07-26 20:33 0 --a------ C:\CONFIG.SYS
2006-07-26 20:33 0 --a------ C:\AUTOEXEC.BAT
2006-07-26 20:31 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2006-07-26 20:31 72,192 --a------ C:\WINDOWS\system32\acctres.dll
2006-07-26 20:31 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2006-07-26 20:31 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2006-07-26 20:31 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2006-07-26 20:31 432,640 --a------ C:\WINDOWS\system32\wuapi.dll
2006-07-26 20:31 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2006-07-26 20:31 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2006-07-26 20:31 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2006-07-26 20:31 36,864 --a------ C:\WINDOWS\system32\wups.dll
2006-07-26 20:31 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2006-07-26 20:31 184,320 --a------ C:\WINDOWS\system32\wuaueng1.dll
2006-07-26 20:31 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-07-26 20:31 168,960 --a------ C:\WINDOWS\system32\wuauclt1.exe
2006-07-26 20:31 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2006-07-26 20:31 120,320 --a------ C:\WINDOWS\system32\wuweb.dll
2006-07-26 20:31 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2006-07-26 20:31 114,176 --a------ C:\WINDOWS\system32\wucltui.dll
2006-07-26 20:31 112,640 --a------ C:\WINDOWS\system32\wuauclt.exe
2006-07-26 20:31 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2006-07-26 20:31 1,134,592 --a------ C:\WINDOWS\system32\wuaueng.dll
2006-07-26 20:30 86,016 --a------ C:\WINDOWS\system32\isign32.dll
2006-07-26 20:30 81,920 --a------ C:\WINDOWS\system32\ils.dll
2006-07-26 20:30 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2006-07-26 20:30 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2006-07-26 20:30 678,400 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-26 20:30 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2006-07-26 20:30 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2006-07-26 20:30 50,688 --a------ C:\WINDOWS\system32\inetres.dll
2006-07-26 20:30 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2006-07-26 20:30 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2006-07-26 20:30 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2006-07-26 20:30 282,624 --a------ C:\WINDOWS\system32\inetcfg.dll
2006-07-26 20:30 281,600 --a------ C:\WINDOWS\system32\mstask.dll
2006-07-26 20:30 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2006-07-26 20:30 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2006-07-26 20:30 241,664 --a------ C:\WINDOWS\system32\srrstr.dll
2006-07-26 20:30 22,528 --a------ C:\WINDOWS\system32\fltMc.exe
2006-07-26 20:30 193,024 --a------ C:\WINDOWS\system32\schedsvc.dll
2006-07-26 20:30 171,008 --a------ C:\WINDOWS\system32\srsvc.dll
2006-07-26 20:30 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-07-26 20:30 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2006-07-26 20:30 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2006-07-26 20:29 949,248 --a------ C:\WINDOWS\system32\msdtctm.dll
2006-07-26 20:29 94,208 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2006-07-26 20:29 90,112 --a------ C:\WINDOWS\system32\mtxoci.dll
2006-07-26 20:29 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2006-07-26 20:29 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2006-07-26 20:29 82,432 --a------ C:\WINDOWS\system32\comrepl.dll
2006-07-26 20:29 80,896 --a------ C:\WINDOWS\system32\charmap.exe
2006-07-26 20:29 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2006-07-26 20:29 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2006-07-26 20:29 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2006-07-26 20:29 634,880 --a------ C:\WINDOWS\system32\getuname.dll
2006-07-26 20:29 628,224 --a------ C:\WINDOWS\system32\catsrvut.dll
2006-07-26 20:29 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2006-07-26 20:29 62,464 --a------ C:\WINDOWS\system32\colbact.dll
2006-07-26 20:29 61,952 --a------ C:\WINDOWS\system32\remotepg.dll
2006-07-26 20:29 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2006-07-26 20:29 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2006-07-26 20:29 57,344 --a------ C:\WINDOWS\system32\sol.exe
2006-07-26 20:29 55,808 --a------ C:\WINDOWS\system32\freecell.exe
2006-07-26 20:29 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2006-07-26 20:29 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2006-07-26 20:29 539,136 --a------ C:\WINDOWS\system32\spider.exe
2006-07-26 20:29 501,248 --a------ C:\WINDOWS\system32\clbcatq.dll
2006-07-26 20:29 5,632 --a------ C:\WINDOWS\system32\write.exe
2006-07-26 20:29 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2006-07-26 20:29 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2006-07-26 20:29 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2006-07-26 20:29 425,472 --a------ C:\WINDOWS\system32\msdtcprx.dll
2006-07-26 20:29 411,648 --a------ C:\WINDOWS\system32\mstsc.exe
2006-07-26 20:29 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2006-07-26 20:29 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2006-07-26 20:29 39,424 --a------ C:\WINDOWS\system32\cfgbkend.dll
2006-07-26 20:29 352,256 --a------ C:\WINDOWS\system32\hypertrm.dll
2006-07-26 20:29 35,840 --a------ C:\WINDOWS\system32\winchat.exe
2006-07-26 20:29 347,648 --a------ C:\WINDOWS\system32\mspaint.exe
2006-07-26 20:29 33,792 --a------ C:\WINDOWS\system32\regini.exe
2006-07-26 20:29 297,984 --a------ C:\WINDOWS\system32\termsrv.dll
2006-07-26 20:29 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2006-07-26 20:29 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2006-07-26 20:29 232,960 --a------ C:\WINDOWS\system32\avtapi.dll
2006-07-26 20:29 229,888 --a------ C:\WINDOWS\system32\catsrv.dll
2006-07-26 20:29 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe
2006-07-26 20:29 22,528 --a------ C:\WINDOWS\system32\msg.exe
2006-07-26 20:29 20,992 --a------ C:\WINDOWS\system32\qprocess.exe
2006-07-26 20:29 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2006-07-26 20:29 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-07-26 20:29 189,952 --a------ C:\WINDOWS\system32\accwiz.exe
2006-07-26 20:29 17,408 --a------ C:\WINDOWS\system32\tsshutdn.exe
2006-07-26 20:29 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe
2006-07-26 20:29 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2006-07-26 20:29 16,896 --a------ C:\WINDOWS\system32\tskill.exe
2006-07-26 20:29 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe
2006-07-26 20:29 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2006-07-26 20:29 15,872 --a------ C:\WINDOWS\system32\logoff.exe
2006-07-26 20:29 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2006-07-26 20:29 15,360 --a------ C:\WINDOWS\system32\tscon.exe
2006-07-26 20:29 15,360 --a------ C:\WINDOWS\system32\shadow.exe
2006-07-26 20:29 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2006-07-26 20:29 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2006-07-26 20:29 142,336 --a------ C:\WINDOWS\system32\sessmgr.exe
2006-07-26 20:29 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2006-07-26 20:29 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe
2006-07-26 20:29 133,120 --a------ C:\WINDOWS\system32\sndrec32.exe
2006-07-26 20:29 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-07-26 20:29 128,000 --a------ C:\WINDOWS\system32\mshearts.exe
2006-07-26 20:29 124,928 --a------ C:\WINDOWS\system32\mplay32.exe
2006-07-26 20:29 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2006-07-26 20:29 115,200 --a------ C:\WINDOWS\system32\calc.exe
2006-07-26 20:29 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2006-07-26 20:29 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2006-07-26 20:29 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2006-07-26 20:29 104,448 --a------ C:\WINDOWS\system32\clipbrd.exe
2006-07-26 20:29 10,240 --a------ C:\WINDOWS\system32\reset.exe
2006-07-26 20:29 1,263 --a------ C:\WINDOWS\system32\usrlogon.cmd
2006-07-26 20:29 1,251,840 --a------ C:\WINDOWS\system32\comsvcs.dll
2006-07-26 20:28 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2006-07-26 20:28 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2006-07-26 20:28 191,488 --a------ C:\WINDOWS\system32\cmprops.dll
2006-07-26 20:28 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll
2006-07-16 17:34 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2006-07-16 17:34 13,312 --a------ C:\WINDOWS\system32\irclass.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
[B]Rootkit driver pe386 is present. A rootkit scan is required[/B]
2006-09-16 18:06 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-07-29 15:04 -------- d-------- C:\Program Files\Ahead
2006-07-28 12:54 -------- d-------- C:\Documents and Settings\Olivier\Application Data\vlc
2006-07-28 12:28 -------- d-------- C:\Documents and Settings\Olivier\Application Data\Macromedia
2006-07-27 17:02 -------- d-------- C:\Program Files\Adobe
2006-07-27 14:24 -------- d-------- C:\Program Files\FMScout
2006-07-27 12:23 -------- d-------- C:\Documents and Settings\Olivier\Application Data\VadeRetro
2006-07-27 12:22 -------- d-------- C:\Program Files\Goto Software
2006-07-27 00:35 -------- d-------- C:\Program Files\PhotoFiltre
2006-07-26 23:55 -------- d--h----- C:\Program Files\ATI Technologies
2006-07-26 22:56 -------- d-------- C:\Program Files\Lavasoft
2006-07-26 22:56 -------- d-------- C:\Program Files\CCleaner
2006-07-26 22:56 -------- d-------- C:\Documents and Settings\Olivier\Application Data\Lavasoft
2006-07-26 22:55 -------- d-------- C:\Program Files\VideoLAN
2006-07-26 22:55 -------- d-------- C:\Program Files\QuickPar
2006-07-26 22:54 -------- d-------- C:\Program Files\DVD Shrink
2006-07-26 22:42 -------- d--h----- C:\Program Files\Java
2006-07-26 22:41 -------- d-------- C:\Program Files\Fichiers communs\Java
2006-07-26 22:38 -------- d-------- C:\Program Files\Zone Labs
2006-07-26 22:34 -------- d-------- C:\Documents and Settings\Olivier\Application Data\Mozilla
2006-07-26 22:24 -------- d-------- C:\Program Files\Fichiers communs\SpeechEngines
2006-07-26 22:24 -------- d-------- C:\Program Files\Fichiers communs\ODBC
2006-07-26 22:23 62 --ahs---- C:\Documents and Settings\Olivier\Application Data\desktop.ini
2006-07-26 22:23 -------- d--h----- C:\Program Files\Free.fr
2006-07-26 21:59 -------- d-------- C:\Program Files\Sports Interactive
2006-07-26 21:39 -------- d--h----- C:\Program Files\Microsoft Office
2006-07-26 21:39 -------- d-------- C:\Program Files\Fichiers communs\System
2006-07-26 21:20 -------- d--h----- C:\Program Files\Broadcom
2006-07-26 21:20 -------- d-------- C:\Program Files\Fichiers communs\InstallShield
2006-07-26 21:02 -------- d--h----- C:\Program Files\Uninstall Information
2006-07-26 21:02 -------- d-------- C:\Documents and Settings\Olivier\Application Data\Identities
2006-07-26 20:33 -------- d--h----- C:\Program Files\xerox
2006-07-26 20:33 -------- d--h----- C:\Program Files\microsoft frontpage
2006-07-26 20:32 -------- d--h----- C:\Program Files\WindowsUpdate
2006-07-26 20:32 -------- d--h----- C:\Program Files\Services en ligne
2006-07-26 20:31 -------- d--h----- C:\Program Files\Outlook Express
2006-07-26 20:31 -------- d--h----- C:\Program Files\NetMeeting
2006-07-26 20:31 -------- d--h----- C:\Program Files\Movie Maker
2006-07-26 20:31 -------- d-------- C:\Program Files\Fichiers communs\Services
2006-07-26 20:31 -------- d-------- C:\Program Files\Fichiers communs\MSSoap
2006-07-26 20:30 -------- d--h----- C:\Program Files\ComPlus Applications
2006-07-26 20:29 -------- d--h----- C:\Program Files\Windows NT
2006-07-26 20:29 -------- d--h----- C:\Program Files\MSN Gaming Zone
2006-07-26 20:29 -------- d-------- C:\Program Files\MSN
2006-07-17 09:13 -------- d-------- C:\Program Files\Mozilla Firefox
2006-07-17 09:13 -------- d-------- C:\Documents and Settings\Olivier\Application Data\dvdcss
2006-07-16 17:47 -------- d--h----- C:\Program Files\Windows Media Player
2006-07-16 17:45 -------- d--h----- C:\Program Files\Internet Explorer
2006-04-22 22:11 568850 --a------ C:\WINDOWS\system32\x264vfw.dll
2006-04-20 20:09 5120 --a------ C:\WINDOWS\system32\ff_vfw.dll
2006-04-19 22:09 619156 --a------ C:\WINDOWS\system32\divx.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"P17Helper"="Rundll32 P17.dll,P17Helper"
"CTSysVol"="C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,c4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:91,00,00,00
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Vaderetro Outlook]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VrMoRegister"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Goto Software\\Vade Retro\\VrMoRegister.exe -s\""
"inimapping"="0"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
Completion time: 17/07/2006 9:25:13.60
ComboFix.txt