et voilà :
ComboFix 09-08-18.04 - Eddy 19/08/2009 20:58.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2047.1611 [GMT 2:00]
Running from: c:\documents and settings\Eddy\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Eddy\Application Data\wiaserva.log
c:\windows\system32\braviax.exe
D:\resycled
E:\resycled
.
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.
2009-08-13 17:34 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-07 13:55 . 2009-08-07 13:55 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-07 13:55 . 2009-08-07 13:55 -------- d-----w- c:\program files\MSBuild
2009-08-07 13:55 . 2009-08-07 13:55 -------- d-----w- c:\program files\Reference Assemblies
2009-08-07 13:55 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-07 13:55 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-07 13:55 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-07 13:55 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-07 13:55 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-07 13:55 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-07 13:55 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-05 09:00 . 2009-08-05 09:00 205312 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 18:50 . 2002-08-29 00:13 606528 ----a-w- c:\windows\system32\drivers\ntfs.sys
2009-08-16 16:01 . 2009-08-16 16:01 27004 ----a-w- c:\windows\system32\msword98.exe
2009-08-16 16:01 . 2009-08-16 16:01 27004 ----a-w- c:\documents and settings\Eddy\msword98.exe
2009-08-16 14:35 . 2009-08-16 14:34 3942047 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-14 22:20 . 2007-11-29 22:51 -------- d-----w- c:\program files\ANTI-VIRUS
2009-08-09 11:35 . 2007-11-29 23:25 22128 ----a-w- c:\documents and settings\Eddy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-07 13:59 . 2001-08-28 12:00 84526 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-07 13:59 . 2001-08-28 12:00 510324 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-05 11:13 . 2008-09-24 08:36 -------- d-----w- c:\documents and settings\Eddy\Application Data\U3
2009-08-05 09:00 . 2002-08-29 09:44 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 11:36 . 2008-11-09 18:02 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 11:36 . 2008-11-09 18:03 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-17 19:03 . 2002-08-29 09:44 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 20:27 . 2009-07-16 20:27 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
2009-07-16 17:38 . 2009-06-07 13:46 -------- d-----w- c:\program files\Convertisseur
2009-07-16 17:24 . 2009-07-16 17:24 -------- d-----w- c:\program files\Fichiers communs\DVDVIDEOSOFT
2009-07-16 12:54 . 2007-11-29 22:46 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-12 10:21 . 2007-11-29 23:00 233472 ------w- c:\windows\system32\wmpdxm.dll
2009-07-03 16:57 . 2002-08-29 09:45 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-27 05:47 . 2009-06-27 05:47 10134 ----a-r- c:\documents and settings\Eddy\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-27 05:47 . 2009-06-27 05:47 -------- d-----w- c:\program files\Microsoft WSE
2009-06-22 11:33 . 2009-06-22 11:33 37440 ----a-w- c:\windows\system32\drivers\pssdklbf.drv
2009-06-22 11:33 . 2009-06-22 11:33 30272 ----a-w- c:\windows\system32\drivers\pssdk31.drv
2009-06-22 10:36 . 2009-06-22 10:36 289280 ----a-w- c:\windows\system32\gfbaksm.dat
2009-06-16 14:40 . 2001-08-28 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2001-08-28 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 10:44 . 2002-08-29 09:45 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-15 10:44 . 2002-08-29 09:45 82944 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-10 14:14 . 2002-08-29 09:44 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:21 . 2007-11-29 22:35 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:15 . 2001-08-28 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:10 . 2002-08-29 09:44 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-05-27 19:34 . 2008-08-27 12:42 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-05-25 17:24 . 2009-06-07 14:20 299008 ----a-w- c:\windows\system32\TubeFinder.exe
.
------- Sigcheck -------
[-] 2002-08-29 00:13 561920 E3AE9C79498210A5F39FE5A9AD62BC55 c:\windows\NTFS.SYS
[-] 2007-02-09 11:23 574976 05AB81909514BFD69CBB1F2C147CF6B9 c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
[-] 2007-02-09 11:10 574464 19A811EF5F1ED5C926A028CE107FF1AF c:\windows\$NtServicePackUninstall$\ntfs.sys
[7] 2004-08-03 22:15 574592 B78BE402C3F63DD55521F73876951CDD c:\windows\$NtUninstallKB930916$\ntfs.sys
[7] 2008-04-13 19:15 574976 78A08DD6A8D65E697C18E1DB01C5CDCA c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2009-08-19 18:50 606528 AF49998107D359B7DA9320551DF8AB3B c:\windows\system32\dllcache\ntfs.sys
[-] 2009-08-19 18:50 606528 AF49998107D359B7DA9320551DF8AB3B c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-11-17 171464]
"msword98"="c:\documents and settings\Eddy\msword98.exe" [2009-08-16 27004]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-04 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-04 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-27 136600]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-24 185896]
"OxigenClientAdmin"="c:\program files\ECRAN MOTO GP\Oxigen\bin\Oxigen.exe" [2007-06-23 887264]
"OxigenTrayIcon"="c:\program files\ECRAN MOTO GP\Oxigen\bin\OxiTray.exe" [2007-06-23 557536]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"msword98"="c:\windows\system32\msword98.exe" [2009-08-16 27004]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-17 61952]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-10-04 1626112]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Eddy\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2008-4-14 23552]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-2-11 110592]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-7-14 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 00:42 72208 ----a-w- c:\program files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Emule\\emule.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\BitSpirit\\BitSpirit.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\jeux\\WoW l'instal\\WoWq.exe"=
"e:\\jeux\\WoW l'instal\\WoWBC.exe"=
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [05/12/2007 15:58 3712]
R3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [03/12/2007 23:32 223232]
R3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [30/11/2007 01:29 1258432]
S3 PsSdk31;PsSdk31;c:\windows\system32\drivers\pssdk31.drv [22/06/2009 13:33 30272]
S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.drv [22/06/2009 13:33 37440]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\g:\ntglm7x.sys --> g:\NTGLM7X.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - IDSVC
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\User_Feed_Synchronization-{F84D4C8C-273E-45F0-B1A1-4526A5266CEA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
2009-08-19 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-31 20:18]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Regedit32 - c:\windows\system32\regedit.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.commStart Page =
hxxp://www.google.comIE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Télécharger avec &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: ÓñÈÌØ¾«ÁéÏÂÔØ(&B)
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cabDPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} -
hxxp://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-19 21:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk31]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdk31.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdkLBF]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdklbf.drv"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2000478354-492894223-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:85,cd,1a,40,79,c6,b4,43,af,31,e2,63,a4,4b,f4,78,cc,c5,3c,d7,87,01,39,
13,da,61,2d,ab,67,c3,85,33,3d,ad,f6,e4,64,9a,f0,47,f9,5b,0a,68,a5,25,34,68,\
"??"=hex:44,27,0c,a0,47,9c,73,5d,7e,ee,d6,67,0c,84,91,f6
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(808)
c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-08-19 21:04
ComboFix-quarantined-files.txt 2009-08-19 19:04
Pre-Run: 800 141 312 octets libres
Post-Run: 1 725 108 224 octets libres
208 --- E O F --- 2009-08-13 21:29