Hi!
Weeks and weeks I try to get rid of this malaware, i tried: Spybot, C Cleaner, Malware's byte anti malware, Ad-aware...
Unable to turn on automatic Windows update, more and more difficult to surf when just not impossible
Here's what i got after having ran ComboFix:
ComboFix 08-07-28.4 - PIET 2008-07-29 11:44:57.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.182 [GMT 2:00]
Endroit: C:\Documents and Settings\PIET\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\PIET\Menu Démarrer\Programmes\PlayMP3z
C:\Documents and Settings\PIET\Menu Démarrer\Programmes\PlayMP3z\Run PlayMP3z.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bKnmlnmp.ini
C:\WINDOWS\system32\bKnmlnmp.ini2
C:\WINDOWS\system32\byXQIBuv.dll
C:\WINDOWS\system32\eljopbjh.dll
C:\WINDOWS\system32\eonbkwqc.dll
C:\WINDOWS\system32\epapphld.dll
C:\WINDOWS\system32\erjasqmu.ini
C:\WINDOWS\system32\fmjolhju.dll
C:\WINDOWS\system32\fukskfvf.ini
C:\WINDOWS\system32\gokwjlnc.dll
C:\WINDOWS\system32\hlcqrgdl.dll
C:\WINDOWS\system32\HOUEdMoq.ini
C:\WINDOWS\system32\HOUEdMoq.ini2
C:\WINDOWS\system32\ioygruim.dll
C:\WINDOWS\system32\ithkirab.ini
C:\WINDOWS\system32\jecqaplh.ini
C:\WINDOWS\system32\jyoakooj.ini
C:\WINDOWS\system32\kbseow.dll
C:\WINDOWS\system32\kexyhewf.ini
C:\WINDOWS\system32\knknpirm.ini
C:\WINDOWS\system32\knvtav.dll
C:\WINDOWS\system32\krajeu.dll
C:\WINDOWS\system32\ksdfdqnq.dll
C:\WINDOWS\system32\lpurnowg.ini
C:\WINDOWS\system32\lroexr.dll
C:\WINDOWS\system32\lvcofp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjrrxkfy.ini
C:\WINDOWS\system32\niuvkc.dll
C:\WINDOWS\system32\nxveluip.ini
C:\WINDOWS\system32\ococgnop.dll
C:\WINDOWS\system32\puaasvml.dll
C:\WINDOWS\system32\pwpcfy.dll
C:\WINDOWS\system32\qewfhxbw.dll
C:\WINDOWS\system32\tBHPonnn.ini
C:\WINDOWS\system32\tBLTtBeg.ini
C:\WINDOWS\system32\tBLTtBeg.ini2
C:\WINDOWS\system32\tnjeinei.ini
C:\WINDOWS\system32\ulgsfiiv.dll
C:\WINDOWS\system32\usoxsz.dll
C:\WINDOWS\system32\uvqvvhng.ini
C:\WINDOWS\system32\uyckpylb.dll
C:\WINDOWS\system32\vuBIQXyb.ini
C:\WINDOWS\system32\vuBIQXyb.ini2
C:\WINDOWS\system32\vwrprkbl.dll
C:\WINDOWS\system32\wejljxje.ini
C:\WINDOWS\system32\xykbvrtf.dll
C:\WINDOWS\system32\yceatp.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))))))
.
2008-07-29 11:17 . 2008-07-29 11:17 83,456 --a------ C:\WINDOWS\system32\gwonrupl.dll
2008-07-29 11:15 . 2008-07-29 11:15 105,472 --a------ C:\WINDOWS\system32\rhvnagnq.dll
2008-07-29 11:15 . 2008-07-29 11:15 105,472 --a------ C:\WINDOWS\system32\dyvidq.dll
2008-07-29 11:15 . 2008-07-29 11:15 91,648 --a------ C:\WINDOWS\system32\flmyljps.dll
2008-07-28 21:21 . 2008-07-29 11:42 111,587 --a------ C:\WINDOWS\BM0f1df940.xml
2008-07-28 18:45 . 2008-07-28 18:45 83,456 --------- C:\WINDOWS\system32\gnhvvqvu.dll
2008-07-28 17:57 . 2008-07-28 17:57 83,456 --------- C:\WINDOWS\system32\oqnnabwr.dll
2008-07-28 17:54 . 2008-07-28 17:54 105,472 --a------ C:\WINDOWS\system32\vegxpsjj.dll
2008-07-28 17:54 . 2008-07-28 17:54 105,472 --a------ C:\WINDOWS\system32\qgzxhr.dll
2008-07-28 17:52 . 2008-07-28 17:52 91,648 --a------ C:\WINDOWS\system32\erfpukpu.dll
2008-07-25 22:46 . 2008-07-25 22:46 105,472 --a------ C:\WINDOWS\system32\xlsxbu.dll
2008-07-25 22:46 . 2008-07-25 22:46 105,472 --a------ C:\WINDOWS\system32\gybtqrtn.dll
2008-07-25 17:57 . 2008-07-25 17:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-25 17:36 . 2008-07-25 17:36 105,472 --a------ C:\WINDOWS\system32\yexuiq.dll
2008-07-25 17:36 . 2008-07-25 17:36 105,472 --a------ C:\WINDOWS\system32\oxpcatkw.dll
2008-07-24 17:19 . 2008-07-24 17:19 105,472 --a------ C:\WINDOWS\system32\xuykrm.dll
2008-07-24 17:19 . 2008-07-24 17:19 105,472 --a------ C:\WINDOWS\system32\pbmrdade.dll
2008-07-23 22:43 . 2008-07-23 22:43 <REP> d-------- C:\Program Files\Yahoo!
2008-07-23 22:43 . 2008-07-23 22:45 <REP> d-------- C:\Program Files\CCleaner
2008-07-23 22:06 . 2008-07-23 22:06 <REP> d-------- C:\Documents and Settings\PIET\Application Data\Malwarebytes
2008-07-23 22:05 . 2008-07-23 22:06 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-23 22:05 . 2008-07-23 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-23 22:05 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-23 22:05 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-23 21:53 . 2008-07-23 21:53 <REP> d-------- C:\Program Files\Lavasoft
2008-07-23 21:53 . 2008-07-23 21:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-23 21:50 . 2008-07-23 21:50 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-23 21:30 . 2008-07-23 21:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-23 21:30 . 2008-07-29 11:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-23 20:53 . 2008-07-23 20:53 1,042 --a------ C:\WINDOWS\PIET.reg
2008-07-02 11:56 . 2008-07-02 11:56 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-02 11:51 . 2008-07-02 11:51 719,352 --a------ C:\WINDOWS\Windows2000-KB842773-x86-FRA.EXE
2008-07-02 11:06 . 2008-07-02 11:06 <REP> d-------- C:\Program Files\Windows Defender
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 09:11 --------- d-----w C:\Program Files\Lx_cats
2008-07-29 09:11 --------- d-----w C:\Documents and Settings\PIET\Application Data\OpenOffice.org2
2008-07-25 21:00 --------- d-----w C:\Program Files\bwin
2008-07-23 16:30 --------- d-----w C:\Program Files\Java
2008-07-17 19:57 --------- d-----w C:\Program Files\Soulseek
2008-07-15 15:33 --------- d-----w C:\Documents and Settings\PIET\Application Data\EoRezo
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-31 17:30 --------- d-----w C:\Program Files\LimeWire
2008-04-25 17:22 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16702622-F7FA-4342-B2DD-144E7948A37C}]
2008-06-14 13:04 25440 --------- C:\WINDOWS\system32\xxyArRKc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-15 18:37 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 09:56 139264]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 23:05 344064]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 03:00 45056]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 13:34 122880]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 20:25 49152]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 03:00 90112]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]
"lxcemon.exe"="C:\Program Files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 19:45 192512]
"EzPrint"="C:\Program Files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 14:17 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 11:36 299008]
"Nero DriveSpeed"="C:\PROGRA~1\NERODR~1\DRIVES~1.EXE" [2004-12-18 23:01 593920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-15 00:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 14:11 267048]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-25 18:52 185896]
"LXCECATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 15:46 73728]
"0c2ecadc"="C:\WINDOWS\system32\gwonrupl.dll" [2008-07-29 11:17 83456]
"BM0f1df940"="C:\WINDOWS\system32\flmyljps.dll" [2008-07-29 11:15 91648]
"CTHelper"="CTHELPER.EXE" [2005-08-08 21:10 16384 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-11-11 07:07 19968 C:\WINDOWS\system32\CTXFIHLP.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 14:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{16702622-F7FA-4342-B2DD-144E7948A37C}"= "C:\WINDOWS\system32\xxyArRKc.dll" [2008-06-14 13:04 25440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyArRKc]
2008-06-14 13:04 25440 C:\WINDOWS\system32\xxyArRKc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23689:TCP"= 23689:TCP:limewire
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2005-08-08 20:54]
R3 ovt530;Webcam Deluxe;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 18:04]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 01:08]
S3 HDJCtrl;Hercules DJ Control MP3 Service;C:\WINDOWS\system32\Drivers\HDJCtrl.sys [2005-07-29 16:06]
S3 HDJMidi;Hercules DJ Console MIDI;C:\WINDOWS\system32\DRIVERS\HDJMidi.sys [2005-08-15 12:43]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 16:42]
.
- - - - ORPHANS REMOVED - - - -
BHO-{7D16C74A-3FD9-4257-81EF-5A4C1756395F} - (no file)
BHO-{7DC52C09-F380-4D72-8B11-3E7CE0F945CB} - (no file)
BHO-{90EFFC88-4F76-46E3-9856-FBB07537168D} - (no file)
BHO-{9F4F962E-F20B-4864-8935-5EE734BD8C23} - (no file)
BHO-{B24BC789-D458-49C2-ABF0-879D52676599} - (no file)
BHO-{B9BDFB4A-C5FA-4C82-ABB2-4133BBC6C647} - (no file)
BHO-{C9F96DFE-5424-4B0E-B6ED-10BDCBD03216} - (no file)
BHO-{DB1634C9-DF85-4920-9701-C1E71A7D843C} - (no file)
HKLM-Run-CTXFIREG - CTxfiReg.exe
HKLM-Run-EoWeather - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.hotmail.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R0 -: HKLM-Main,Start Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
O8 -: &eBay Search - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O16 -: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://www.namur.be/AMC.cab
C:\WINDOWS\Downloaded Program Files\setup.inf
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
Balayage processus cach‚s ...
C:\WINDOWS\explorer.exe [1768] 0x8162E2B0
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s:
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\xxyArRKc.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\gwonrupl.dll
-> C:\WINDOWS\system32\flmyljps.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\CTXFISPI.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-29 11:56:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-29 09:56:47
Pre-Run: 3,666,104,320 octets libres
Post-Run: 3,630,968,832 octets libres
248 --- E O F --- 2008-06-11 21:27:51
Weeks and weeks I try to get rid of this malaware, i tried: Spybot, C Cleaner, Malware's byte anti malware, Ad-aware...
Unable to turn on automatic Windows update, more and more difficult to surf when just not impossible
Here's what i got after having ran ComboFix:
ComboFix 08-07-28.4 - PIET 2008-07-29 11:44:57.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.182 [GMT 2:00]
Endroit: C:\Documents and Settings\PIET\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\PIET\Menu Démarrer\Programmes\PlayMP3z
C:\Documents and Settings\PIET\Menu Démarrer\Programmes\PlayMP3z\Run PlayMP3z.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bKnmlnmp.ini
C:\WINDOWS\system32\bKnmlnmp.ini2
C:\WINDOWS\system32\byXQIBuv.dll
C:\WINDOWS\system32\eljopbjh.dll
C:\WINDOWS\system32\eonbkwqc.dll
C:\WINDOWS\system32\epapphld.dll
C:\WINDOWS\system32\erjasqmu.ini
C:\WINDOWS\system32\fmjolhju.dll
C:\WINDOWS\system32\fukskfvf.ini
C:\WINDOWS\system32\gokwjlnc.dll
C:\WINDOWS\system32\hlcqrgdl.dll
C:\WINDOWS\system32\HOUEdMoq.ini
C:\WINDOWS\system32\HOUEdMoq.ini2
C:\WINDOWS\system32\ioygruim.dll
C:\WINDOWS\system32\ithkirab.ini
C:\WINDOWS\system32\jecqaplh.ini
C:\WINDOWS\system32\jyoakooj.ini
C:\WINDOWS\system32\kbseow.dll
C:\WINDOWS\system32\kexyhewf.ini
C:\WINDOWS\system32\knknpirm.ini
C:\WINDOWS\system32\knvtav.dll
C:\WINDOWS\system32\krajeu.dll
C:\WINDOWS\system32\ksdfdqnq.dll
C:\WINDOWS\system32\lpurnowg.ini
C:\WINDOWS\system32\lroexr.dll
C:\WINDOWS\system32\lvcofp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjrrxkfy.ini
C:\WINDOWS\system32\niuvkc.dll
C:\WINDOWS\system32\nxveluip.ini
C:\WINDOWS\system32\ococgnop.dll
C:\WINDOWS\system32\puaasvml.dll
C:\WINDOWS\system32\pwpcfy.dll
C:\WINDOWS\system32\qewfhxbw.dll
C:\WINDOWS\system32\tBHPonnn.ini
C:\WINDOWS\system32\tBLTtBeg.ini
C:\WINDOWS\system32\tBLTtBeg.ini2
C:\WINDOWS\system32\tnjeinei.ini
C:\WINDOWS\system32\ulgsfiiv.dll
C:\WINDOWS\system32\usoxsz.dll
C:\WINDOWS\system32\uvqvvhng.ini
C:\WINDOWS\system32\uyckpylb.dll
C:\WINDOWS\system32\vuBIQXyb.ini
C:\WINDOWS\system32\vuBIQXyb.ini2
C:\WINDOWS\system32\vwrprkbl.dll
C:\WINDOWS\system32\wejljxje.ini
C:\WINDOWS\system32\xykbvrtf.dll
C:\WINDOWS\system32\yceatp.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-28 to 2008-07-29 ))))))))))))))))))))))))))))))))))))
.
2008-07-29 11:17 . 2008-07-29 11:17 83,456 --a------ C:\WINDOWS\system32\gwonrupl.dll
2008-07-29 11:15 . 2008-07-29 11:15 105,472 --a------ C:\WINDOWS\system32\rhvnagnq.dll
2008-07-29 11:15 . 2008-07-29 11:15 105,472 --a------ C:\WINDOWS\system32\dyvidq.dll
2008-07-29 11:15 . 2008-07-29 11:15 91,648 --a------ C:\WINDOWS\system32\flmyljps.dll
2008-07-28 21:21 . 2008-07-29 11:42 111,587 --a------ C:\WINDOWS\BM0f1df940.xml
2008-07-28 18:45 . 2008-07-28 18:45 83,456 --------- C:\WINDOWS\system32\gnhvvqvu.dll
2008-07-28 17:57 . 2008-07-28 17:57 83,456 --------- C:\WINDOWS\system32\oqnnabwr.dll
2008-07-28 17:54 . 2008-07-28 17:54 105,472 --a------ C:\WINDOWS\system32\vegxpsjj.dll
2008-07-28 17:54 . 2008-07-28 17:54 105,472 --a------ C:\WINDOWS\system32\qgzxhr.dll
2008-07-28 17:52 . 2008-07-28 17:52 91,648 --a------ C:\WINDOWS\system32\erfpukpu.dll
2008-07-25 22:46 . 2008-07-25 22:46 105,472 --a------ C:\WINDOWS\system32\xlsxbu.dll
2008-07-25 22:46 . 2008-07-25 22:46 105,472 --a------ C:\WINDOWS\system32\gybtqrtn.dll
2008-07-25 17:57 . 2008-07-25 17:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-25 17:36 . 2008-07-25 17:36 105,472 --a------ C:\WINDOWS\system32\yexuiq.dll
2008-07-25 17:36 . 2008-07-25 17:36 105,472 --a------ C:\WINDOWS\system32\oxpcatkw.dll
2008-07-24 17:19 . 2008-07-24 17:19 105,472 --a------ C:\WINDOWS\system32\xuykrm.dll
2008-07-24 17:19 . 2008-07-24 17:19 105,472 --a------ C:\WINDOWS\system32\pbmrdade.dll
2008-07-23 22:43 . 2008-07-23 22:43 <REP> d-------- C:\Program Files\Yahoo!
2008-07-23 22:43 . 2008-07-23 22:45 <REP> d-------- C:\Program Files\CCleaner
2008-07-23 22:06 . 2008-07-23 22:06 <REP> d-------- C:\Documents and Settings\PIET\Application Data\Malwarebytes
2008-07-23 22:05 . 2008-07-23 22:06 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-23 22:05 . 2008-07-23 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-23 22:05 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-23 22:05 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-23 21:53 . 2008-07-23 21:53 <REP> d-------- C:\Program Files\Lavasoft
2008-07-23 21:53 . 2008-07-23 21:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-23 21:50 . 2008-07-23 21:50 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-23 21:30 . 2008-07-23 21:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-23 21:30 . 2008-07-29 11:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-23 20:53 . 2008-07-23 20:53 1,042 --a------ C:\WINDOWS\PIET.reg
2008-07-02 11:56 . 2008-07-02 11:56 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-07-02 11:51 . 2008-07-02 11:51 719,352 --a------ C:\WINDOWS\Windows2000-KB842773-x86-FRA.EXE
2008-07-02 11:06 . 2008-07-02 11:06 <REP> d-------- C:\Program Files\Windows Defender
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 09:11 --------- d-----w C:\Program Files\Lx_cats
2008-07-29 09:11 --------- d-----w C:\Documents and Settings\PIET\Application Data\OpenOffice.org2
2008-07-25 21:00 --------- d-----w C:\Program Files\bwin
2008-07-23 16:30 --------- d-----w C:\Program Files\Java
2008-07-17 19:57 --------- d-----w C:\Program Files\Soulseek
2008-07-15 15:33 --------- d-----w C:\Documents and Settings\PIET\Application Data\EoRezo
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-31 17:30 --------- d-----w C:\Program Files\LimeWire
2008-04-25 17:22 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16702622-F7FA-4342-B2DD-144E7948A37C}]
2008-06-14 13:04 25440 --------- C:\WINDOWS\system32\xxyArRKc.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-15 18:37 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 09:56 139264]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 23:05 344064]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]
"CTDVDDET"="C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 03:00 45056]
"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 13:34 122880]
"AudioDrvEmulator"="C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 20:25 49152]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 03:00 90112]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]
"lxcemon.exe"="C:\Program Files\Lexmark 4300 Series\lxcemon.exe" [2005-08-02 19:45 192512]
"EzPrint"="C:\Program Files\Lexmark 4300 Series\ezprint.exe" [2005-07-26 14:17 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 11:36 299008]
"Nero DriveSpeed"="C:\PROGRA~1\NERODR~1\DRIVES~1.EXE" [2004-12-18 23:01 593920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-15 00:43 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 14:11 267048]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-25 18:52 185896]
"LXCECATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 15:46 73728]
"0c2ecadc"="C:\WINDOWS\system32\gwonrupl.dll" [2008-07-29 11:17 83456]
"BM0f1df940"="C:\WINDOWS\system32\flmyljps.dll" [2008-07-29 11:15 91648]
"CTHelper"="CTHELPER.EXE" [2005-08-08 21:10 16384 C:\WINDOWS\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-11-11 07:07 19968 C:\WINDOWS\system32\CTXFIHLP.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 14:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{16702622-F7FA-4342-B2DD-144E7948A37C}"= "C:\WINDOWS\system32\xxyArRKc.dll" [2008-06-14 13:04 25440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyArRKc]
2008-06-14 13:04 25440 C:\WINDOWS\system32\xxyArRKc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23689:TCP"= 23689:TCP:limewire
R3 ha20x2k;Creative 20X HAL Driver;C:\WINDOWS\system32\drivers\ha20x2k.sys [2005-08-08 20:54]
R3 ovt530;Webcam Deluxe;C:\WINDOWS\system32\Drivers\ov530vid.sys [2005-03-15 18:04]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 01:08]
S3 HDJCtrl;Hercules DJ Control MP3 Service;C:\WINDOWS\system32\Drivers\HDJCtrl.sys [2005-07-29 16:06]
S3 HDJMidi;Hercules DJ Console MIDI;C:\WINDOWS\system32\DRIVERS\HDJMidi.sys [2005-08-15 12:43]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 16:42]
.
- - - - ORPHANS REMOVED - - - -
BHO-{7D16C74A-3FD9-4257-81EF-5A4C1756395F} - (no file)
BHO-{7DC52C09-F380-4D72-8B11-3E7CE0F945CB} - (no file)
BHO-{90EFFC88-4F76-46E3-9856-FBB07537168D} - (no file)
BHO-{9F4F962E-F20B-4864-8935-5EE734BD8C23} - (no file)
BHO-{B24BC789-D458-49C2-ABF0-879D52676599} - (no file)
BHO-{B9BDFB4A-C5FA-4C82-ABB2-4133BBC6C647} - (no file)
BHO-{C9F96DFE-5424-4B0E-B6ED-10BDCBD03216} - (no file)
BHO-{DB1634C9-DF85-4920-9701-C1E71A7D843C} - (no file)
HKLM-Run-CTXFIREG - CTxfiReg.exe
HKLM-Run-EoWeather - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.hotmail.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R0 -: HKLM-Main,Start Page = hxxp://ads.eorezo.com/cgi-bin/advert/getads.cgi?x_format=redirect&x_dp_id=9
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR
O8 -: &eBay Search - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O16 -: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://www.namur.be/AMC.cab
C:\WINDOWS\Downloaded Program Files\setup.inf
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
Balayage processus cach‚s ...
C:\WINDOWS\explorer.exe [1768] 0x8162E2B0
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s:
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\xxyArRKc.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\gwonrupl.dll
-> C:\WINDOWS\system32\flmyljps.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\CTXFISPI.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-29 11:56:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-29 09:56:47
Pre-Run: 3,666,104,320 octets libres
Post-Run: 3,630,968,832 octets libres
248 --- E O F --- 2008-06-11 21:27:51