and here is the new combofix log:
ComboFix 08-03-05.1 - Claude et Francine 2008-03-06 12:54:55.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.429 [GMT -5:00]
Endroit: C:\Documents and Settings\Claude et Francine\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Claude et Francine\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\mhyvfa.exe2
C:\mmesckoj.exe2
C:\Program Files\tmp34767783.exe
C:\Program Files\tmp34768073.exe
C:\Program Files\tmp34768163.exe
C:\Program Files\tmp34768544.exe
C:\Program Files\tmp34770327.exe
C:\Program Files\tmp34770447.exe
C:\Program Files\tmp9641774.exe
C:\Program Files\tmp9833900.exe
C:\Program Files\udefender_setup.exe
.
The following files were disabled during the run:
C:\WINDOWS\system32\guard32.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\mhyvfa.exe2
C:\Program Files\udefender_setup.exe
C:\WINDOWS\Installer\{26df807e-b39e-4869-95c8-99227e6ae380}
C:\WINDOWS\Installer\{26df807e-b39e-4869-95c8-99227e6ae380}\DriveRunOnce.dll
C:\WINDOWS\Installer\{d0c92054-3a74-4c01-8bed-653c9da6f396}
C:\WINDOWS\Installer\{d0c92054-3a74-4c01-8bed-653c9da6f396}\zip.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-06 to 2008-03-06 ))))))))))))))))))))))))))))))))))))
.
2008-03-06 07:05 . 2008-03-06 07:05 3,847 --a------ C:\Program Files\tmp32187653.exe
2008-03-06 06:45 . 2008-03-06 10:37 250 --a------ C:\WINDOWS\gmer.ini
2008-03-05 06:32 . 2008-03-05 06:32 <REP> d-------- C:\Program Files\IE Extensions
2008-03-04 19:13 . 2008-03-04 19:13 <REP> d-------- C:\Program Files\COMODO
2008-03-04 19:13 . 2008-03-04 19:13 <REP> d-------- C:\Documents and Settings\Claude et Francine\Application Data\Comodo
2008-03-04 19:13 . 2008-03-04 20:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-03-04 19:13 . 2008-03-04 19:13 139,008 --a------ C:\WINDOWS\system32\guard32.dll.vir
2008-03-04 19:13 . 2008-03-04 19:13 84,856 --a------ C:\WINDOWS\system32\drivers\cmdguard.sys
2008-03-04 19:13 . 2008-03-04 19:13 23,800 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-03-04 15:26 . 2008-03-06 10:20 <REP> d-------- C:\Downloads mars 2008
2008-03-03 16:38 . 2008-03-03 16:38 <REP> d-------- C:\Program Files\Trend Micro
2008-03-03 11:19 . 2008-03-03 11:19 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-03 11:19 . 2008-03-03 11:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-03 08:30 . 2008-03-03 08:30 <REP> d--h----- C:\WINDOWS\PIF
2008-03-02 22:33 . 2008-03-02 22:38 339 --a------ C:\WINDOWS\wininit.ini
2008-03-02 22:04 . 2008-03-02 22:04 <REP> d-------- C:\Program Files\SysCleaner
2008-03-02 21:13 . 2008-03-02 21:12 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-02 21:13 . 2008-03-02 21:13 2,568 --a------ C:\WINDOWS\unins000.dat
2008-03-02 20:48 . 2008-03-02 21:15 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-02 20:48 . 2008-03-02 21:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-02 19:07 . 2008-03-02 19:07 145 --a------ C:\WINDOWS\system32\winver.bat2
2008-03-02 18:57 . 2008-03-02 18:57 <REP> dr-h----- C:\~MSSETUP.T
2008-02-26 23:06 . 2008-02-26 23:06 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-12 16:48 . 2008-02-12 16:48 <REP> d-------- C:\Program Files\SunNetPro
2008-02-12 16:46 . 2008-02-12 16:46 <REP> d-------- C:\WINDOWS\Downloaded Installations
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 00:21 --------- d-----w C:\Documents and Settings\Claude et Francine\Application Data\Skype
2008-03-03 21:30 --------- d-----w C:\Documents and Settings\Claude et Francine\Application Data\skypePM
2008-03-03 15:12 --------- d-----w C:\Program Files\eMule
2008-03-03 14:12 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-03-03 14:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-06 00:37 --------- d-----w C:\Documents and Settings\Claude et Francine\Application Data\Apple Computer
2008-02-06 00:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-06 00:35 --------- d-----w C:\Program Files\QuickTime
2008-02-05 12:09 --------- d-----w C:\Program Files\DivX
2007-12-20 14:08 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-05_19.31.42.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-06 11:45:28 819,200 ----a-w C:\WINDOWS\gmer.dll
+ 2008-01-19 01:31:10 757,760 ----a-w C:\WINDOWS\gmer.exe
+ 2008-03-06 11:45:28 85,713 ----a-w C:\WINDOWS\system32\drivers\gmer.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-10-15 18:00 1818624 C:\WINDOWS\mixer.exe]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-04-04 11:55 71304]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2006-11-25 11:18 100056]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-12-22 20:55 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"Easy-PrintToolBox"="C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-13 20:10 409600]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE" [2002-09-20 15:16 90112]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-09-11 12:58 155648]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-09-11 12:57 45056]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-05 19:25 385024]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-03-04 19:13 1502976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 07:00 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2004-03-26 16:26 54384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= C:\WINDOWS\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\CIMSVR.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Pctspk;PCTEL Speaker Phone;C:\WINDOWS\system32\pctspk.exe [2001-08-23 12:47]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-19 10:53]
R3 Ptserlp;PCTEL Serial Device Driver for PCI;C:\WINDOWS\system32\DRIVERS\ptserlp.sys [2001-08-17 16:28]
S2 BulkUsb;USB Scanner;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2002-06-10 14:21]
S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);C:\WINDOWS\system32\DRIVERS\LV551AV.sys [2002-06-10 14:24]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-25 11:07:26 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - Claude et Francine.job"
- C:\PROGRA~1\NORTON~1\NAVW32.EXEh/task:
"2008-03-01 11:12:53 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur.job"
- C:\PROGRA~1\NORTON~1\Navw32.exeh/task:
"2008-03-06 15:37:18 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-06 12:56:53
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
.
Temps d'accomplissement: 2008-03-06 12:58:00
ComboFix-quarantined-files.txt 2008-03-06 17:57:44
ComboFix2.txt 2008-03-06 00:39:44
.
2008-02-14 08:04:30 --- E O F ---