et voilà le rapport ComboFix !!
ComboFix 09-08-25.05 - Tazkilleur 26/08/2009 18:30.2.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1535.1122 [GMT 2:00]
Running from: c:\documents and settings\Tazkilleur\Bureau\Tazkiller.exe
AV: avast! antivirus 4.8.1335 [VPS 090826-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\PurpleBean.exe
c:\windows\Installer\2b326d.msi
c:\windows\Installer\857942.msi
c:\windows\Installer\9183ba.msi
c:\windows\Installer\9f529.msi
c:\windows\system32\nerocheck.exe
c:\windows\system32\uninstall.exe
.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 23:21 . 2009-05-06 20:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-22 22:26 . 2008-01-02 19:30 -------- d-----w- c:\program files\Windows Live Safety Center
2009-07-15 08:59 . 2009-07-09 08:20 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
2009-07-09 11:40 . 2009-07-09 11:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2009-07-07 21:20 . 2007-04-22 14:43 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-26 20:53 . 2009-06-26 20:53 10134 ----a-r- c:\documents and settings\Tazkilleur\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-06 21:10 . 2006-09-27 11:16 29760 ----a-w- c:\documents and settings\Tazkilleur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-04 21:54 . 2009-06-04 21:54 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-06-03 17:44 . 2009-04-17 14:08 1 ----a-w- c:\documents and settings\Tazkilleur\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
.
------- Sigcheck -------
[7] 2001-08-28 12:00 4224 DA1F27D85E0D1525F6621372E7B685E9 c:\windows\system32\dllcache\beep.sys
c:\windows\system32\drivers\beep.sys ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-08-29 171464]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-08 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"I downloaded pirated Software from P2P"="Jaws" [X]
"I downloaded pirated Software from P2P 2006"="Jaws" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"avast!"="c:\progra~1\avast\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-12-05 1626112]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-08-17 90112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Tazkilleur\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\open office\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
e-Carte Bleue Banque Populaire.lnk - c:\program files\e-Carte Bleue Banque Populaire\ecbl-nxbp.exe [2009-4-25 278528]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll schannel.dll digest.dll msnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Utilitaires\\emule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\jeux\\trackmania\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"\\\\EDDY-PC\\JEUX\\CSsource\\CSsource\\srcds.exe"=
"d:\\jeux\\steam\\SteamApps\\crounchy\\counter-strike source\\hl2.exe"=
"d:\\jeux\\steam\\SteamApps\\crounchy\\day of defeat source\\hl2.exe"=
"d:\\jeux\\steam\\SteamApps\\crounchy\\half-life 2 deathmatch\\hl2.exe"=
"c:\\StubInstaller.exe"=
"d:\\jeux\\New populous\\D3DPopTB.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BitSpirit\\BitSpirit.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"d:\\jeux\\New populous\\D3DPopTBUW.exe"=
"d:\\jeux\\New populous\\popTBUW.exe"=
"d:\\jeux\\New populous\\popTB.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\jeux\\WoW\\WoWq.exe"=
"d:\\jeux\\WoW\\WoWBC.exe"=
"d:\\jeux\\WoW\\World of Warcraft\\Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4787:UDP"= 4787:UDP:Windows Media Format SDK (iexplore.exe)
"4786:UDP"= 4786:UDP:Windows Media Format SDK (iexplore.exe)
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"36649:TCP"= 36649:TCP:*:Disabled:SolidNetworkManager
"36649:UDP"= 36649:UDP:*:Disabled:SolidNetworkManager
"28498:TCP"= 28498:TCP:*:Disabled:SolidNetworkManager
"28498:UDP"= 28498:UDP:*:Disabled:SolidNetworkManager
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [05/04/2009 23:01 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/04/2009 23:01 20560]
S2 gupdate1c9ce8a7d785bb6;Service Google Update (gupdate1c9ce8a7d785bb6);c:\program files\Google\Update\GoogleUpdate.exe [06/05/2009 22:37 133104]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [26/09/2006 22:12 223232]
S3 cdrmkaun;cdrmkaun;\??\c:\docume~1\TAZKIL~1\LOCALS~1\Temp\cdrmkaun.sys --> c:\docume~1\TAZKIL~1\LOCALS~1\Temp\cdrmkaun.sys [?]
S3 XDva120;XDva120;\??\c:\windows\system32\XDva120.sys --> c:\windows\system32\XDva120.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-08-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 20:35]
2009-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 20:37]
2009-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 20:37]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{A057A204-BACC-4D26-8287-79A187E26987} - (no file)
HKLM-Run-NeroFilterCheck - c:\windows\system32\NeroCheck.exe
HKLM-Run-c:\windows\system32\kdapj.exe - c:\windows\system32\kdapj.exe
.
------- Supplementary Scan -------
.
uLocal Page = about:blank
uStart Page =
hxxp://www.google.fr/uSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemLocal Page = about:blank
mStart Page = about:blank
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Télécharger avec &BitSpirit - c:\program files\BitSpirit\bsurl.htm
IE: ÓñÈÌØ¾«ÁéÏÂÔØ(&B)
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} -
hxxp://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-26 18:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1292428093-1606980848-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1292428093-1606980848-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:02,5d,3b,3b,90,c1,93,3b,ab,36,ef,7e,3a,be,36,f9,1c,32,31,2d,cf,dd,29,
e1,cc,b2,63,19,82,f6,e1,41,56,ea,f5,b0,59,76,2f,19,a6,09,1f,90,40,bc,05,2c,\
"??"=hex:91,e2,d6,b5,94,73,8f,83,7b,0d,1b,13,71,77,34,06
[HKEY_USERS\S-1-5-21-1292428093-1606980848-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:13,95,19,db,b6,8b,35,65,e3,f8,28,b7,37,69,f2,f5,84,db,1b,39,73,
0c,36,b1,03,87,e6,b9,f2,6f,3d,54,97,61,ec,ff,66,22,46,14,0c,ec,1b,03,78,5a,\
"rkeysecu"=hex:1d,75,d6,62,e4,5e,9d,c7,c6,c1,9d,91,48,dc,a8,9c
.
Completion time: 2009-08-26 18:37
ComboFix-quarantined-files.txt 2009-08-26 16:37
Pre-Run: 3 611 721 728 octets libres
Post-Run: 3 868 237 824 octets libres
166
@ + tard !!