hi
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:13:43, on 11/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sylvain\Bureau\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://home.neuf.fr
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://home.neuf.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5090] cmd /c del "C:\WINDOWS\system32\uvotkcuq.dll_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 4810 bytes
ComboFix 07-11-08.1 - Sylvain 2007-11-11 22:12:41.1 - NTFSx86
Running from: C:\Documents and Settings\Sylvain\Bureau\ComboFix.exe
* Created a new restore point
.
Incapable d'obtenir les privilèges Système
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\Sylvain\Bureau\Live Safety Center.lnk
C:\Documents and Settings\Sylvain\Bureau\Online Security Guide.lnk
C:\Documents and Settings\Sylvain\Favoris\Online Security Guide.lnk
C:\WINDOWS\system32\hgjjl.bak1
C:\WINDOWS\system32\hgjjl.bak2
C:\WINDOWS\system32\hgjjl.ini
C:\WINDOWS\system32\hgjjl.ini2
C:\WINDOWS\system32\hgjjl.tmp
C:\WINDOWS\system32\ljjgh.dll
C:\WINDOWS\system32\qknovhnf.dll
C:\WINDOWS\system32\qohlrdft.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))))))))
.
2007-11-11 22:04 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-10 17:32 71,232 --a------ C:\WINDOWS\system32\tjliwxxs.exe
2007-11-09 21:28 1,156 --a------ C:\WINDOWS\mozver.dat
2007-11-09 20:49 <REP> d-------- C:\Program Files\eMule
2007-11-09 14:40 <REP> d-------- C:\Documents and Settings\Sylvain\Application Data\Talkback
2007-11-09 14:39 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-07 11:37 86,080 --a------ C:\WINDOWS\system32\vuabbprm.dll
2007-11-07 11:34 79,936 --a------ C:\WINDOWS\system32\ogbfrssq.dll
2007-11-07 11:30 71,232 --a------ C:\WINDOWS\system32\aquxvyhj.exe
2007-11-07 11:29 145,984 --a------ C:\WINDOWS\system32\ayjmvdrj.dll
2007-11-04 12:16 <REP> d-------- C:\Documents and Settings\Sylvain\Application Data\vlc
2007-11-04 12:13 <REP> d-------- C:\Program Files\VideoLAN
2007-11-03 18:01 123 --a------ C:\WINDOWS\system32\oghiysc.bat
2007-11-03 13:41 154,624 --a------ C:\WINDOWS\system32\netman.dll
2007-11-03 13:35 1,006,592 --a------ C:\WINDOWS\system32\esent.dll
2007-11-03 13:34 25,600 --------- C:\WINDOWS\system32\verclsid.exe
2007-11-03 13:27 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-03 13:26 83,456 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-11-03 13:26 64,512 --a------ C:\WINDOWS\system32\mtxclu.dll
2007-11-03 13:05 125 --a------ C:\WINDOWS\system32\orsbns.bat
2007-11-03 12:58 35,328 --a------ C:\WINDOWS\system32\ljjjhgg.dll
2007-11-02 21:02 40,960 --a------ C:\WINDOWS\system32\cazvky.exe
2007-11-02 21:02 12,288 --a------ C:\WINDOWS\system32\eqaijawh.exe
2007-11-02 19:50 36,864 --a------ C:\WINDOWS\system32\mf3216.dll
2007-11-02 19:50 36,864 --a--c--- C:\WINDOWS\system32\dllcache\mf3216.dll
2007-11-02 19:49 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-11-02 19:49 1,110,528 --a------ C:\WINDOWS\system32\msxml3.dll
2007-11-02 14:43 <REP> d-------- C:\WINDOWS\system32\bits
2007-11-02 14:28 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-11-02 14:28 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-11-02 14:28 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-11-02 14:28 187,160 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-11-02 14:28 170,776 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-11-02 14:28 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-11-02 14:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-02 14:19 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-11-01 10:34 185,624 --a------ C:\WINDOWS\system32\iuengine.dll
2007-11-01 10:34 185,624 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2007-10-31 15:58 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2007-10-31 15:55 <REP> d-------- C:\WINDOWS\Downloaded Installations
2007-10-30 10:01 <REP> d-------- C:\Documents and Settings\Sylvain\Contacts
2007-10-30 10:00 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-30 09:52 <REP> d-------- C:\Program Files\MSN Messenger
2007-10-30 09:27 <REP> d-------- C:\Program Files\WhatsRunning
2007-10-30 09:23 <REP> d-------- C:\Program Files\Google
2007-10-30 09:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-10-30 09:20 <REP> d-------- C:\Program Files\Port Detective
2007-10-30 09:20 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-10-30 09:09 <REP> d-------- C:\Documents and Settings\Sylvain\Application Data\Grisoft
2007-10-29 19:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-29 19:44 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-29 19:42 <REP> d---s---- C:\Documents and Settings\Sylvain\UserData
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 21:22 6,343,712 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-11 21:19 86,960 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-11 21:19 19,712 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-11 21:19 188,192 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-11 21:11 --------- d-----w C:\Program Files\Kaspersky Lab
2007-10-29 17:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-29 17:41 --------- d-----w C:\Program Files\Kit ADSL
2007-10-29 17:41 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-10-29 17:40 --------- d-----w C:\Program Files\CCleaner
2007-10-29 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-29 17:21 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-29 17:18 --------- d-----w C:\Program Files\Services en ligne
2007-10-29 17:17 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-10-29 17:07 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-10-29 17:07 --------- d-----w C:\Program Files\Fichiers communs\ODBC
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1D5AB83E-B256-42EB-A0AA-D58796CBAEC1}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{419ad68f-adf2-48e9-b757-9e8f11fa8946}]
C:\WINDOWS\System32\jobnap.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c8a2e720-c2e2-46d2-a86e-d02ce0c77f3c}]
2007-11-07 11:34 79936 --a------ C:\WINDOWS\System32\ogbfrssq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kis"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" [2006-03-24 19:09]
"@"="" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 10:45]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jobnap]
jobnap.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjjhgg]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\uvotkcuq]
uvotkcuq.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\ljjgh.dll
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 22:21:55
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-11 22:25:00 - machine was rebooted
.
--- E O F ---