Perpete
2008-04-04, 21:18
Hi all,
It seems that I have been infected by virtumonde...
Looking at previous threads, I have already disable Teatime and guard system and I have downloaded ComboFix.exe. If someone is available to help me to select the lines for the CFS script... I will really appreciate it.
Here below the ComboFix report:
ComboFix 08-04-03.3 - Philippe Perpete 2008-04-04 19:31:18.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1549 [GMT 2:00]
Endroit: C:\Documents and Settings\Philippe Perpete\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMdfa8150f.xml
C:\WINDOWS\install.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\andt.sys
C:\WINDOWS\system32\awtSIbbC.dll
C:\WINDOWS\system32\CbbIStwa.ini
C:\WINDOWS\system32\CbbIStwa.ini2
C:\WINDOWS\system32\cdfOrtwa.ini
C:\WINDOWS\system32\cdfOrtwa.ini2
C:\WINDOWS\system32\CIiSAJjl.ini
C:\WINDOWS\system32\CIiSAJjl.ini2
C:\WINDOWS\system32\crsvcxto.dll
C:\WINDOWS\system32\ddcCTNfE.dll
C:\WINDOWS\system32\drmgs.sys
C:\WINDOWS\system32\fkjvttnh.ini
C:\WINDOWS\system32\hnttvjkf.dll
C:\WINDOWS\system32\Indt2.sys
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mmUwDJlm.ini
C:\WINDOWS\system32\mmUwDJlm.ini2
C:\WINDOWS\system32\mSuDKRqr.ini
C:\WINDOWS\system32\mSuDKRqr.ini2
C:\WINDOWS\system32\mycijith.dll
C:\WINDOWS\system32\oibhrwrr.ini
C:\WINDOWS\system32\OXIQttwa.ini
C:\WINDOWS\system32\OXIQttwa.ini2
C:\WINDOWS\system32\rknvceqk.dll
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\rrwrhbio.dll
C:\WINDOWS\system32\snynmlav.dll
C:\WINDOWS\system32\VxxHQXyb.ini
C:\WINDOWS\system32\VxxHQXyb.ini2
C:\WINDOWS\system32\XEeLRXbc.ini
C:\WINDOWS\system32\XEeLRXbc.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PERFMONS
-------\Legacy_ROUTING
-------\Service_perfmons
-------\Service_Routing
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-04 to 2008-04-04 ))))))))))))))))))))))))))))))))))))
.
2008-04-03 20:47 . 2008-04-03 20:47 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-04-03 20:44 . 2008-04-03 20:44 3,272 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-03 20:43 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-03 20:43 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-03 20:43 . 2008-03-28 23:19 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-03 20:43 . 2008-03-26 08:50 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-03 20:43 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-03 20:43 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-03 20:43 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-04-03 20:01 . 2007-10-26 13:33 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-04-03 20:01 . 2007-10-26 14:23 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-04-03 19:33 . 2008-04-03 22:23 <REP> d-------- C:\VundoFix Backups
2008-04-02 21:09 . 2008-04-02 21:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-04-02 19:32 . 2008-04-02 19:57 559 --a------ C:\WINDOWS\system32\adcklog.dat
2008-04-01 19:35 . 2008-04-01 19:38 0 --a------ C:\WINDOWS\system32\1.tsk
2008-04-01 17:19 . 2008-04-01 20:30 294 ---hs---- C:\WINDOWS\system32\hbnsgdkf.ini
2008-04-01 09:43 . 2008-04-01 09:43 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\System Tweaker
2008-04-01 09:18 . 2008-04-02 21:09 <REP> d-------- C:\Program Files\Uniblue
2008-04-01 09:18 . 2008-04-02 21:09 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\Uniblue
2008-03-31 17:25 . 2008-03-31 17:25 <REP> d-------- C:\Program Files\Enigma Software Group
2008-03-31 17:18 . 2008-03-31 17:27 354 ---hs---- C:\WINDOWS\system32\mloydwit.ini
2008-03-31 15:42 . 2008-03-31 15:42 <REP> d-------- C:\Program Files\Lavasoft
2008-03-31 15:42 . 2008-03-31 15:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-31 09:17 . 2008-03-31 09:17 294 ---hs---- C:\WINDOWS\system32\sysyntxa.ini
2008-03-31 07:30 . 2008-03-31 08:30 294 ---hs---- C:\WINDOWS\system32\xxieuwxq.ini
2008-03-30 20:17 . 2008-03-30 20:46 354 ---hs---- C:\WINDOWS\system32\cptcukmd.ini
2008-03-24 17:36 . 2007-09-28 22:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-03-24 17:29 . 2008-03-24 17:29 <REP> d-------- C:\Program Files\Radeon Omega Drivers
2008-03-24 14:55 . 2008-03-24 17:23 <REP> d-------- C:\Program Files\ATI Technologies
2008-03-24 14:49 . 2008-03-24 14:49 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-23 21:33 . 2008-03-27 21:15 <REP> d-------- C:\Program Files\Xplosiv
2008-03-20 21:57 . 2008-03-24 20:59 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\Off Road
2008-03-15 14:20 . 2008-03-15 14:20 <REP> d-------- C:\Program Files\MagicISO
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 16:20 --------- d-----w C:\Program Files\BitComet
2008-03-31 13:42 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-24 15:30 --------- d-----w C:\Program Files\MultiRes
2008-03-24 15:29 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-03-23 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-13 17:34 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Skype
2008-03-11 15:11 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Active Disk
2008-03-01 09:30 --------- d-----w C:\Program Files\iTunes
2008-03-01 09:29 --------- d-----w C:\Program Files\iPod
2008-03-01 09:28 --------- d-----w C:\Program Files\QuickTime
2008-02-28 05:57 --------- d-----w C:\Program Files\Azureus
2008-02-28 05:56 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Azureus
2008-02-23 17:06 --------- d-----w C:\Program Files\IGN-NGI
2008-02-23 07:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-23 07:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-23 07:32 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-21 07:49 --------- d-----w C:\Program Files\McAfee
2008-02-17 17:02 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-15 19:44 --------- d-----w C:\Program Files\Midway Games
2008-02-15 19:14 --------- d-----w C:\Program Files\AGEIA Technologies
2008-02-10 16:30 --------- d-----w C:\Program Files\Empire Interactive
2008-02-10 16:22 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-02-05 20:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-16 17:50 68856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 09:23 221568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 11:03 57344]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 17:39 147456]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 15:30 86016]
"Deskup"="C:\Program Files\Iomega\DriveIcons\deskup.exe" [2002-07-16 11:55 32768]
"snp2uvc"="C:\WINDOWS\vsnp2uvc.exe" [2007-03-12 19:49 569344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"AtiPTA"="atiptaxx.exe" [2006-02-22 03:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe
"HerculesCamService"=C:\Program Files\Hercules\DualPix Exchange\CamService.exe
"CTDVDDET"=C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"PRONoMgrWired"=C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"Alcmtr"=ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Midway Games\\Hour of Victory\\Binaries\\LTCG-HOVGame.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9813:TCP"= 9813:TCP:BitComet 9813 TCP
"9813:UDP"= 9813:UDP:BitComet 9813 UDP
"8050:TCP"= 8050:TCP:BitComet 8050 TCP
"8050:UDP"= 8050:UDP:BitComet 8050 UDP
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-20 01:10]
R3 camfilt2;camfilt2;C:\WINDOWS\system32\Drivers\camfilt2.sys [2007-05-29 13:23]
S1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v3.8.421\ATI Tray Tools\atitray.sys []
S3 bcgame;Nostromo HID Device Minidriver;C:\WINDOWS\system32\drivers\bcgame.sys [2003-07-24 03:16]
S3 ldiskl;ldiskl;C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\ldiskl.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-03-07 16:17:22 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-10-26 12:21:59 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2007-10-26 12:21:58 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-04-02 19:52:07 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-04 19:36:44
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-04 19:38:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-04 17:38:29
Pre-Run: 96,176,164,864 octets libres
Post-Run: 96,201,121,792 octets libres
.
2008-03-12 17:09:04 --- E O F ---
And the Hijackthis report will follow in the next message.
Thank you for your help in advance.....
It seems that I have been infected by virtumonde...
Looking at previous threads, I have already disable Teatime and guard system and I have downloaded ComboFix.exe. If someone is available to help me to select the lines for the CFS script... I will really appreciate it.
Here below the ComboFix report:
ComboFix 08-04-03.3 - Philippe Perpete 2008-04-04 19:31:18.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1549 [GMT 2:00]
Endroit: C:\Documents and Settings\Philippe Perpete\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BMdfa8150f.xml
C:\WINDOWS\install.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\andt.sys
C:\WINDOWS\system32\awtSIbbC.dll
C:\WINDOWS\system32\CbbIStwa.ini
C:\WINDOWS\system32\CbbIStwa.ini2
C:\WINDOWS\system32\cdfOrtwa.ini
C:\WINDOWS\system32\cdfOrtwa.ini2
C:\WINDOWS\system32\CIiSAJjl.ini
C:\WINDOWS\system32\CIiSAJjl.ini2
C:\WINDOWS\system32\crsvcxto.dll
C:\WINDOWS\system32\ddcCTNfE.dll
C:\WINDOWS\system32\drmgs.sys
C:\WINDOWS\system32\fkjvttnh.ini
C:\WINDOWS\system32\hnttvjkf.dll
C:\WINDOWS\system32\Indt2.sys
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mmUwDJlm.ini
C:\WINDOWS\system32\mmUwDJlm.ini2
C:\WINDOWS\system32\mSuDKRqr.ini
C:\WINDOWS\system32\mSuDKRqr.ini2
C:\WINDOWS\system32\mycijith.dll
C:\WINDOWS\system32\oibhrwrr.ini
C:\WINDOWS\system32\OXIQttwa.ini
C:\WINDOWS\system32\OXIQttwa.ini2
C:\WINDOWS\system32\rknvceqk.dll
C:\WINDOWS\system32\routing.exe
C:\WINDOWS\system32\rrwrhbio.dll
C:\WINDOWS\system32\snynmlav.dll
C:\WINDOWS\system32\VxxHQXyb.ini
C:\WINDOWS\system32\VxxHQXyb.ini2
C:\WINDOWS\system32\XEeLRXbc.ini
C:\WINDOWS\system32\XEeLRXbc.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PERFMONS
-------\Legacy_ROUTING
-------\Service_perfmons
-------\Service_Routing
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-04 to 2008-04-04 ))))))))))))))))))))))))))))))))))))
.
2008-04-03 20:47 . 2008-04-03 20:47 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-04-03 20:44 . 2008-04-03 20:44 3,272 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-03 20:43 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-03 20:43 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-03 20:43 . 2008-03-28 23:19 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-03 20:43 . 2008-03-26 08:50 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-03 20:43 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-03 20:43 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-03 20:43 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-04-03 20:01 . 2007-10-26 13:33 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-04-03 20:01 . 2007-10-26 14:23 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-04-03 20:01 . 2007-10-26 14:23 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-04-03 19:33 . 2008-04-03 22:23 <REP> d-------- C:\VundoFix Backups
2008-04-02 21:09 . 2008-04-02 21:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-04-02 19:32 . 2008-04-02 19:57 559 --a------ C:\WINDOWS\system32\adcklog.dat
2008-04-01 19:35 . 2008-04-01 19:38 0 --a------ C:\WINDOWS\system32\1.tsk
2008-04-01 17:19 . 2008-04-01 20:30 294 ---hs---- C:\WINDOWS\system32\hbnsgdkf.ini
2008-04-01 09:43 . 2008-04-01 09:43 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\System Tweaker
2008-04-01 09:18 . 2008-04-02 21:09 <REP> d-------- C:\Program Files\Uniblue
2008-04-01 09:18 . 2008-04-02 21:09 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\Uniblue
2008-03-31 17:25 . 2008-03-31 17:25 <REP> d-------- C:\Program Files\Enigma Software Group
2008-03-31 17:18 . 2008-03-31 17:27 354 ---hs---- C:\WINDOWS\system32\mloydwit.ini
2008-03-31 15:42 . 2008-03-31 15:42 <REP> d-------- C:\Program Files\Lavasoft
2008-03-31 15:42 . 2008-03-31 15:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-31 09:17 . 2008-03-31 09:17 294 ---hs---- C:\WINDOWS\system32\sysyntxa.ini
2008-03-31 07:30 . 2008-03-31 08:30 294 ---hs---- C:\WINDOWS\system32\xxieuwxq.ini
2008-03-30 20:17 . 2008-03-30 20:46 354 ---hs---- C:\WINDOWS\system32\cptcukmd.ini
2008-03-24 17:36 . 2007-09-28 22:05 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-03-24 17:29 . 2008-03-24 17:29 <REP> d-------- C:\Program Files\Radeon Omega Drivers
2008-03-24 14:55 . 2008-03-24 17:23 <REP> d-------- C:\Program Files\ATI Technologies
2008-03-24 14:49 . 2008-03-24 14:49 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-23 21:33 . 2008-03-27 21:15 <REP> d-------- C:\Program Files\Xplosiv
2008-03-20 21:57 . 2008-03-24 20:59 <REP> d-------- C:\Documents and Settings\Philippe Perpete\Application Data\Off Road
2008-03-15 14:20 . 2008-03-15 14:20 <REP> d-------- C:\Program Files\MagicISO
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 16:20 --------- d-----w C:\Program Files\BitComet
2008-03-31 13:42 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-24 15:30 --------- d-----w C:\Program Files\MultiRes
2008-03-24 15:29 472,576 ----a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-03-23 19:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-13 17:34 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Skype
2008-03-11 15:11 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Active Disk
2008-03-01 09:30 --------- d-----w C:\Program Files\iTunes
2008-03-01 09:29 --------- d-----w C:\Program Files\iPod
2008-03-01 09:28 --------- d-----w C:\Program Files\QuickTime
2008-02-28 05:57 --------- d-----w C:\Program Files\Azureus
2008-02-28 05:56 --------- d-----w C:\Documents and Settings\Philippe Perpete\Application Data\Azureus
2008-02-23 17:06 --------- d-----w C:\Program Files\IGN-NGI
2008-02-23 07:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-23 07:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-23 07:32 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-21 07:49 --------- d-----w C:\Program Files\McAfee
2008-02-17 17:02 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-15 19:44 --------- d-----w C:\Program Files\Midway Games
2008-02-15 19:14 --------- d-----w C:\Program Files\AGEIA Technologies
2008-02-10 16:30 --------- d-----w C:\Program Files\Empire Interactive
2008-02-10 16:22 715,248 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-02-05 20:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-16 17:50 68856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 09:23 221568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"CTHelper"="CTHELPER.EXE" [2006-08-11 14:56 17920 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-08-11 14:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 15:32 56080 C:\WINDOWS\KHALMNPR.Exe]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 11:03 57344]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"ADUserMon"="C:\Program Files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 17:39 147456]
"Iomega Drive Icons"="C:\Program Files\Iomega\DriveIcons\ImgIcon.exe" [2002-08-13 15:30 86016]
"Deskup"="C:\Program Files\Iomega\DriveIcons\deskup.exe" [2002-07-16 11:55 32768]
"snp2uvc"="C:\WINDOWS\vsnp2uvc.exe" [2007-03-12 19:49 569344]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"AtiPTA"="atiptaxx.exe" [2006-02-22 03:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe
"HerculesCamService"=C:\Program Files\Hercules\DualPix Exchange\CamService.exe
"CTDVDDET"=C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
"PRONoMgrWired"=C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"Alcmtr"=ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Midway Games\\Hour of Victory\\Binaries\\LTCG-HOVGame.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9813:TCP"= 9813:TCP:BitComet 9813 TCP
"9813:UDP"= 9813:UDP:BitComet 9813 UDP
"8050:TCP"= 8050:TCP:BitComet 8050 TCP
"8050:UDP"= 8050:UDP:BitComet 8050 UDP
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-20 01:10]
R3 camfilt2;camfilt2;C:\WINDOWS\system32\Drivers\camfilt2.sys [2007-05-29 13:23]
S1 atitray;atitray;C:\Program Files\Radeon Omega Drivers\v3.8.421\ATI Tray Tools\atitray.sys []
S3 bcgame;Nostromo HID Device Minidriver;C:\WINDOWS\system32\drivers\bcgame.sys [2003-07-24 03:16]
S3 ldiskl;ldiskl;C:\DOCUME~1\PHILIP~1\LOCALS~1\Temp\ldiskl.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-03-07 16:17:22 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-10-26 12:21:59 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2007-10-26 12:21:58 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-04-02 19:52:07 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-04 19:36:44
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-04 19:38:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-04 17:38:29
Pre-Run: 96,176,164,864 octets libres
Post-Run: 96,201,121,792 octets libres
.
2008-03-12 17:09:04 --- E O F ---
And the Hijackthis report will follow in the next message.
Thank you for your help in advance.....