voila mon nouveau hijakthis et bombofix :
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:51:31, on 23/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Softwin\BitDefender9\bdmcon.exe
C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
C:\Program Files\Softwin\BitDefender9\bdswitch.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\DidierLucie\Bureau\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.fr…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com…
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com…
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM…\Run: [nwiz] nwiz.exe /install
O4 - HKLM…\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM…\Run: [BDMCon] “C:\Program Files\Softwin\BitDefender9\bdmcon.exe”
O4 - HKLM…\Run: [BDOESRV] “C:\Program Files\Softwin\BitDefender9\bdoesrv.exe”
O4 - HKLM…\Run: [BDSwitchAgent] “C:\Program Files\Softwin\BitDefender9\bdswitch.exe”
O4 - HKLM…\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM…\Run: [PCMService] “C:\Program Files\Home Cinema\PowerCinema\PCMService.exe”
O4 - HKCU…\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU…\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU…\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKUS\S-1-5-19…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SERVICE LOCAL’)
O4 - HKUS\S-1-5-20…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SERVICE RÉSEAU’)
O4 - HKUS\S-1-5-18…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘SYSTEM’)
O4 - HKUS.DEFAULT…\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User ‘Default user’)
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE…
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - security.symantec.com…
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - security.symantec.com…
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - www.update.microsoft.com…
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - acs.pandasoftware.com…
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Service d’administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d’aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender9\vsserv.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
–
End of file - 7564 bytes
ComboFix 07-06-21.3 - C:\Documents and Settings\Bureau\ComboFix.exe
“” - 2007-06-23 12:45:44 - Service Pack 2 NTFS [SAFE MODE]
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\jkkjk.dll
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\vturo.dll
C:\WINDOWS\system32\fccdaax.dll
-
-
- POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1~1\Bureau\internet.lnk
C:\WINDOWS\system32\msxml3a.dll
((((((((((((((((((((((((( Files Created from 2007-05-23 to 2007-06-23 )))))))))))))))))))))))))))))))
2007-06-23 12:45 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-23 12:00 d-------- C:\DOCUME~1~1\APPLIC~1\Browzar
2007-06-22 23:23 1,572,864 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-22 23:23 dr------- C:\DOCUME~1\ADMINI~1\Menu D?marrer
2007-06-22 23:23 d–h----- C:\DOCUME~1\ADMINI~1\Voisinage r?seau
2007-06-22 23:23 d–h----- C:\DOCUME~1\ADMINI~1\Voisinage d’impression
2007-06-22 23:23 d–h----- C:\DOCUME~1\ADMINI~1\Mod?les
2007-06-22 23:23 d-------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-06-22 23:23 d-------- C:\DOCUME~1\ADMINI~1\Favoris
2007-06-22 23:23 d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-06-22 09:25 d-------- C:\VundoFix Backups
2007-06-22 00:15 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-06-20 21:37 28,672 --a------ C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-06-20 11:41 24,816 --a------ C:\WINDOWS\system32\mdimon.dll
2007-06-20 11:38 d-------- C:\Program Files\Microsoft.NET
2007-06-20 11:37 d-------- C:\WINDOWS\SHELLNEW
2007-06-20 00:43 d-------- C:\DOCUME~1~1\APPLIC~1\AdobeUM
2007-06-19 21:13 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-19 20:20 d-------- C:\WINDOWS\BDOSCAN8
2007-06-19 19:56 d-------- C:\WINDOWS\system32\ActiveScan
2007-06-18 21:43 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-06-18 21:32 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-06-18 12:00 d-------- C:\DOCUME~1~1\APPLIC~1\Google
2007-06-18 11:59 d-------- C:\Program Files\Google
2007-06-18 11:59 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google Updater
2007-06-18 11:59 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-18 11:47 d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\X10 Commander
2007-06-18 11:43 d-------- C:\WINDOWS\system32\fr-fr
2007-06-18 11:41 d-------- C:\WINDOWS\network diagnostic
2007-06-18 10:54 0 --a------ C:\WINDOWS\nsreg.dat
2007-06-18 10:50 5,248 --a------ C:\WINDOWS\system32\drivers\a347scsi.sys
2007-06-18 10:50 160,640 --a------ C:\WINDOWS\system32\drivers\a347bus.sys
2007-06-18 10:49 d-------- C:\Program Files\Alcohol Soft
2007-06-18 10:41 d-------- C:\WINDOWS\Cache
2007-06-18 10:35 d-------- C:\DOCUME~1\R~1\Contacts
2007-06-18 10:28 d----c— C:\WINDOWS\system32\DRVSTORE
2007-06-18 10:27 d-------- C:\Program Files\MSN Messenger
2007-06-18 10:14 d-------- C:\Program Files\Lavasoft
2007-06-18 10:08 d-------- C:\Logiciel
2007-06-17 21:17 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
2007-06-17 21:15 d-------- C:\Program Files\Yahoo!
2007-06-17 20:57 1,769,472 --------- C:\WINDOWS\UNNMP.exe
2007-06-17 20:53 155,648 -ra------ C:\WINDOWS\system32\NeroCheck.exe
2007-06-17 20:51 1,794,048 --------- C:\WINDOWS\UNNeroVision.exe
2007-06-17 20:50 569,344 -ra------ C:\WINDOWS\system32\imagr5.dll
2007-06-17 20:50 544,768 -ra------ C:\WINDOWS\system32\imagx5.dll
2007-06-17 20:50 38,912 -ra------ C:\WINDOWS\system32\picn20.dll
2007-06-17 20:50 283,920 -ra------ C:\WINDOWS\system32\ImagXpr5.dll
2007-06-17 20:50 106,496 -ra------ C:\WINDOWS\system32\TwnLib20.dll
2007-06-17 20:50 d-------- C:\Program Files\Fichiers communs\Ahead
2007-06-17 20:50 d-------- C:\Program Files\Ahead
2007-06-17 20:50 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
2007-06-17 20:49 d-------- C:\Program Files\eMule
2007-06-17 20:40 d-------- C:\WINDOWS\Prefetch
2007-06-17 20:40 d-------- C:\DOCUME~1\NETWOR~1\Menu D?marrer
2007-06-17 20:40 d-------- C:\DOCUME~1\LOCALS~1\Menu D?marrer
2007-06-17 20:02 d-------- C:\WINDOWS\provisioning
2007-06-17 20:02 d-------- C:\WINDOWS\peernet
2007-06-17 20:00 d-------- C:\WINDOWS\ServicePackFiles
2007-06-17 19:57 d-------- C:\WINDOWS\system32\ReinstallBackups
2007-06-17 19:55 d-------- C:\WINDOWS\EHome
2007-06-17 19:28 4,569 --------- C:\WINDOWS\system32\secupd.dat
2007-06-17 19:28 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2007-06-17 19:03 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2007-06-17 19:03 40,960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-06-17 19:03 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2007-06-17 19:03 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2007-06-17 19:01 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-06-17 18:59 d–hs---- C:\DOCUME~1~1\UserData
2007-06-17 18:10 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2007-06-17 18:10 d-------- C:\DOCUME~1~1\APPLIC~1\vlc
2007-06-17 18:09 d-------- C:\Program Files\VideoLAN
2007-06-17 18:03 d-------- C:\WINDOWS\system32\bits
2007-06-17 18:02 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2007-06-17 18:02 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2007-06-17 18:02 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2007-06-17 18:02 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-06-17 18:02 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2007-06-17 18:02 d–h----- C:\WINDOWS$hf_mig$
2007-06-17 18:02 d-------- C:\WINDOWS\system32\PreInstall
2007-06-17 17:59 d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-06-17 17:58 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-06-17 17:58 33,624 --a------ C:\WINDOWS\system32\wups.dll
2007-06-17 17:58 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-06-17 17:58 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-06-17 17:58 195,352 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-06-17 17:58 175,896 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-06-17 17:58 d-------- C:\WINDOWS\SoftwareDistribution
2007-06-17 17:52 198,424 --a------ C:\WINDOWS\system32\iuengine.dll
2007-06-17 17:49 127,184 --a------ C:\WINDOWS\Unwise.exe
2007-06-17 17:49 10,761 --a------ C:\WINDOWS\system32\drivers\x10uif.sys
2007-06-17 17:49 dr-hsc— C:\WINDOWS\system32\dllcache
2007-06-17 17:49 dr–s---- C:\WINDOWS\Fonts
2007-06-17 17:49 dr------- C:\WINDOWS\Web
2007-06-17 17:49 d–h----- C:\WINDOWS\inf
2007-06-17 17:49 d-------- C:\WINDOWS\WinSxS
2007-06-17 17:49 d-------- C:\WINDOWS\twain_32
2007-06-17 17:49 d-------- C:\WINDOWS\system32\wins
2007-06-17 17:49 d-------- C:\WINDOWS\system32\wbem
2007-06-17 17:49 d-------- C:\WINDOWS\system32\usmt
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-18 09:50:19 48,616 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-06-18 09:50:19 367,658 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 20:43:40 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
Note empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-05-15 00:47]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar1.dll [2007-06-18 11:59]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [2007-06-18 11:59]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“nwiz”=“nwiz.exe” [2004-06-07 13:11 C:\WINDOWS\system32\nwiz.exe]
“Cmaudio”=“cmicnfg.cpl” []
“BDMCon”=“C:\Program Files\Softwin\BitDefender9\bdmcon.exe” [2007-06-17 17:42]
“BDOESRV”=“C:\Program Files\Softwin\BitDefender9\bdoesrv.exe” [2005-03-11 18:53]
“BDSwitchAgent”=“C:\Program Files\Softwin\BitDefender9\bdswitch.exe” [2005-04-06 14:09]
“High Definition Audio Property Page Shortcut”=“HDAudPropShortcut.exe” [2004-03-17 15:10 C:\WINDOWS\system32\HDAudPropShortcut.exe]
“PCMService”=“C:\Program Files\Home Cinema\PowerCinema\PCMService.exe” [2004-06-16 11:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-20 01:09]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-06-18 11:59]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“appinit_dlls”=sockspy.dll
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, www.gmer.net…
Rootkit scan 2007-06-23 12:48:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
Completion time: 2007-06-23 12:49:09 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-06-23 12:49
--- E O F ---