Thanks for your reply
Here's the ComboFix log:
ComboFix 08-07-02.5 - Omar 2008-07-04 0:21:12.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1173 [GMT 1:00]
Endroit: C:\Documents and Settings\Omar\Mes documents\Downloads\ComboFix.exe
Command switches used :: C:\Documents and Settings\Omar\Mes documents\Downloads\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\BM9756fc21.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\avexjosl.dll
C:\WINDOWS\system32\bosgdmpy.dll
C:\WINDOWS\system32\cJStBcfe.ini
C:\WINDOWS\system32\cJStBcfe.ini2
C:\WINDOWS\system32\cxmedgua.ini
C:\WINDOWS\system32\dpnbigyc.ini
C:\WINDOWS\system32\ehrwogwm.dll
C:\WINDOWS\system32\jhhbvdin.dll
C:\WINDOWS\system32\jpukaycx.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nftnhwdh.dll
C:\WINDOWS\system32\nyctfmbt.dll
C:\WINDOWS\system32\oagiovbv.dll
C:\WINDOWS\system32\ostbnptm.ini
C:\WINDOWS\system32\rdrfwutu.ini
C:\WINDOWS\system32\sbxkxphb.dll
C:\WINDOWS\system32\sjqglsqp.ini
C:\WINDOWS\system32\slrbiipw.ini
C:\WINDOWS\system32\tbmftcyn.ini
C:\WINDOWS\system32\tuxIlUtv.ini
C:\WINDOWS\system32\tuxIlUtv.ini2
C:\WINDOWS\system32\vbdiggvi.ini
C:\WINDOWS\system32\wpiibrls.dll
C:\WINDOWS\system32\xcyakupj.ini
C:\WINDOWS\system32\ygkrkfbv.dll
C:\WINDOWS\system32\zlib.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NOTEPAD
-------\Service_notepad
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-03 to 2008-07-03 ))))))))))))))))))))))))))))))))))))
.
2008-07-02 19:41 . 2008-07-02 22:22 139,264 --a------ C:\WINDOWS\War3Unin.exe
2008-07-02 19:41 . 2008-07-02 23:16 77,104 --a------ C:\WINDOWS\War3Unin.dat
2008-07-02 19:41 . 2008-07-02 22:22 2,829 --a------ C:\WINDOWS\War3Unin.pif
2008-07-02 19:39 . 2008-07-02 23:38 <REP> d-------- C:\Program Files\Warcraft III
2008-07-01 16:48 . 2008-07-01 16:48 <REP> d-------- C:\Program Files\Trend Micro
2008-06-30 09:27 . 2008-06-30 09:29 <REP> d-------- C:\Program Files\MegaSpoof
2008-06-30 09:27 . 2003-07-08 10:13 28,672 --a------ C:\WINDOWS\system32\sizelimit.ocx
2008-06-26 02:44 . 2008-07-04 00:35 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-26 02:44 . 2008-06-26 02:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-25 02:03 . 2008-06-25 02:14 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-25 02:03 . 2008-06-25 02:14 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-25 02:02 . 2008-07-03 23:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-06-25 02:02 . 2008-07-04 00:34 59,702,304 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-25 02:02 . 2008-07-04 00:33 811,076 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-25 02:02 . 2008-07-04 00:34 227,616 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-25 02:02 . 2008-07-04 00:33 24,380 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-25 00:30 . 2008-06-25 01:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-24 12:21 . 2008-05-16 14:01 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-06-24 12:21 . 2008-07-04 00:34 104 --a------ C:\WINDOWS\system32\nvapps.xml
2008-06-22 16:07 . 2008-06-22 16:07 7 --ahs---- C:\WINDOWS\iTiAN.id.uses
2008-06-22 16:06 . 2008-06-22 18:51 <REP> d-------- C:\Program Files\iArt
2008-06-22 02:59 . 2008-06-22 02:59 <REP> d-------- C:\Program Files\TuneSleeve
2008-06-22 02:59 . 2008-06-22 02:59 <REP> d-------- C:\Program Files\Fichiers communs\eSellerate
2008-06-22 02:59 . 2008-06-22 02:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\eSellerate
2008-06-20 07:07 . 2008-06-20 07:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-06-20 02:41 . 2008-07-03 22:46 <REP> d-------- C:\OutputFolder
2008-06-19 20:19 . 2008-06-19 20:20 <REP> d-------- C:\Program Files\ScreenShot2File
2008-06-17 16:55 . 2008-06-24 12:27 8 --a------ C:\WINDOWS\system32\nvModes.dat
2008-06-16 22:59 . 2008-06-16 22:59 <REP> d-------- C:\Program Files\VS Revo Group
2008-06-13 20:30 . 2008-07-03 01:04 110,419 --a------ C:\WINDOWS\BM9756fc21.xml
2008-06-12 21:11 . 2008-06-16 21:30 <REP> d--hs---- C:\WINDOWS\T21hcg
2008-06-12 21:11 . 2008-06-16 21:30 <REP> d-------- C:\WINDOWS\system32\SSH8
2008-06-12 21:11 . 2008-06-12 21:11 <REP> d-------- C:\WINDOWS\system32\mod
2008-06-12 21:10 . 2008-06-16 21:30 <REP> d-------- C:\WINDOWS\system32\netrax18
2008-06-12 21:10 . 2008-06-12 21:11 <REP> d-------- C:\Temp\itmp4
2008-06-12 19:36 . 2008-06-12 19:36 <REP> d-------- C:\Program Files\Common Files
2008-06-12 16:49 . 2008-06-12 19:47 <REP> d-------- C:\Lineage II
2008-06-12 16:46 . 2008-06-12 16:46 <REP> d-------- C:\Program Files\Lineage II
2008-06-11 15:13 . 2008-06-14 18:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 15:13 . 2008-05-08 15:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-06-10 00:20 . 2008-06-10 00:20 <REP> d-------- C:\Program Files\Microsoft Synchronization Services
2008-06-10 00:20 . 2008-06-11 04:00 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-06-10 00:19 . 2008-06-10 00:19 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-06-10 00:14 . 2008-06-10 00:20 <REP> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-06-10 00:13 . 2008-06-10 00:13 <REP> d-------- C:\Program Files\Microsoft SDKs
2008-06-08 01:44 . 2008-06-08 01:44 <REP> d-------- C:\Documents and Settings\Omar\Application Data\Sierra Entertainment
2008-06-07 16:02 . 2008-06-07 16:02 <REP> d-------- C:\WINDOWS\85EBB28365AF4C539EBE7C0A232762F7.TMP
2008-06-06 22:23 . 2008-06-30 22:11 <REP> d-------- C:\Documents and Settings\Omar\Application Data\NoNameScript
2008-06-06 22:16 . 2008-07-02 22:18 <REP> d-------- C:\Downloads
2008-06-06 14:46 . 2008-03-05 16:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-06-06 14:46 . 2008-03-05 16:56 1,420,824 --a------ C:\WINDOWS\system32\D3DCompiler_37.dll
2008-06-06 14:46 . 2008-03-05 17:03 479,752 --a------ C:\WINDOWS\system32\XAudio2_0.dll
2008-06-06 14:46 . 2008-02-06 00:07 462,864 --a------ C:\WINDOWS\system32\d3dx10_37.dll
2008-06-06 14:46 . 2008-03-05 17:03 238,088 --a------ C:\WINDOWS\system32\xactengine3_0.dll
2008-06-06 14:46 . 2008-03-05 17:00 25,608 --a------ C:\WINDOWS\system32\X3DAudio1_3.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-03 23:31 --------- d-----w C:\Documents and Settings\Omar\Application Data\Skype
2008-07-03 22:28 --------- d-----w C:\Program Files\Steam
2008-07-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-07-03 18:41 --------- d-----w C:\Documents and Settings\Omar\Application Data\Azureus
2008-07-02 22:37 --------- d-----w C:\Program Files\FlashGet
2008-06-30 08:42 --------- d-----w C:\Program Files\Winamp
2008-06-26 07:04 --------- d-----w C:\Program Files\mIRC
2008-06-25 01:14 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-25 01:02 --------- d-----w C:\Program Files\Kaspersky Lab
2008-06-24 22:30 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-06-24 22:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-22 02:08 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-21 01:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-19 20:34 --------- d-----w C:\Documents and Settings\Omar\Application Data\FileZilla
2008-06-16 21:51 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-16 21:49 --------- d-----w C:\Program Files\Maple 11
2008-06-16 21:46 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-06-16 21:41 --------- d-----w C:\Program Files\AoA MP4 Converter
2008-06-16 21:40 --------- d-----w C:\Program Files\Agogo Video to iPod PSP 3GP Xbox PPC PDA MP4
2008-06-16 11:42 --------- d-----w C:\Program Files\Azureus
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-06-09 23:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-06-09 00:02 --------- d-----w C:\Documents and Settings\Omar\Application Data\LimeWire
2008-06-07 15:02 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-06-07 14:28 --------- d-----w C:\Program Files\EA Sports
2008-06-06 14:49 --------- d-----w C:\Program Files\Steganos Internet Anonym VPN
2008-06-05 11:08 --------- d-----w C:\Program Files\StuffPlug3
2008-06-05 11:08 --------- d-----w C:\Documents and Settings\Omar\Application Data\Screenshot Sender
2008-05-27 14:54 22,328 -c--a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-05-25 19:44 --------- d-----w C:\Program Files\Google
2008-05-25 19:24 --------- d-----w C:\Documents and Settings\Omar\Application Data\Steganos VPN
2008-05-25 19:23 --------- d-----w C:\Program Files\VMNetSrv
2008-05-23 16:57 --------- d-----w C:\Program Files\windirstat
2008-05-22 22:15 22,328 ----a-w C:\Documents and Settings\Omar\Application Data\PnkBstrK.sys
2008-05-22 18:26 --------- d-----w C:\Documents and Settings\Omar\Application Data\Media Player Classic
2008-05-22 16:42 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-21 12:47 --------- d-----w C:\Documents and Settings\Omar\Application Data\Maple
2008-05-21 12:28 --------- d-----w C:\Program Files\Maple 12
2008-05-17 12:01 --------- d-----w C:\Program Files\Notepad++
2008-05-17 11:51 --------- d-----w C:\Program Files\Java
2008-05-16 13:01 6,557,408 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2008-05-13 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\HHD Software
2008-05-13 12:24 --------- d-----w C:\Program Files\HHD Software
2008-05-08 14:02 203,136 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 15:00 --------- d-----w C:\Program Files\Allok 3GP PSP MP4 iPod Video Converter
2008-04-13 19:34 70,656 ----a-w C:\WINDOWS\notepad.exe
2008-04-13 19:34 32,866 ------w C:\WINDOWS\slrundll.exe
2008-04-13 19:34 288,256 ----a-w C:\WINDOWS\winhlp32.exe
2008-04-13 19:34 153,088 ----a-w C:\WINDOWS\regedit.exe
2008-04-13 19:34 10,752 ----a-w C:\WINDOWS\hh.exe
2008-04-13 19:34 1,037,824 ----a-w C:\WINDOWS\explorer.exe
2008-04-13 19:33 50,688 ----a-w C:\WINDOWS\twain_32.dll
2008-04-13 19:33 451,072 ----a-w C:\WINDOWS\AppPatch\aclayers.dll
2008-04-13 19:33 39,424 ------w C:\WINDOWS\AppPatch\acadproc.dll
2008-04-13 19:33 245,248 ----a-w C:\WINDOWS\AppPatch\acspecfc.dll
2008-04-13 19:33 141,312 ----a-w C:\WINDOWS\AppPatch\aclua.dll
2008-04-13 19:33 116,224 ----a-w C:\WINDOWS\AppPatch\acxtrnal.dll
2008-04-13 19:33 1,852,928 ----a-w C:\WINDOWS\AppPatch\acgenral.dll
2008-03-05 14:47 784 ----a-w C:\Documents and Settings\Omar\Application Data\mpauth.dat
2008-01-17 18:40 180,224 ----a-w C:\Program Files\spazm.vmp.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ProcessManager"="C:\Program Files\Bill2's Process Manager\ProcessManager.exe" [2007-11-18 19:50 1015808]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:34 15360]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-04-04 15:20 81920]
"ScreenShot2File"="C:\Program Files\ScreenShot2File\ScreenShot2File.exe" [2007-03-20 19:07 76800]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 14:08 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 17:49 77824]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 03:08 2512392]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 18:12 131072]
"StartupDelayer"="C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe" [2007-12-14 10:11 26112]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 14:01 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 14:01 86016]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 11:36 267048]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-11-29 03:17 55824 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2008-05-16 14:01 1630208 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 20:34 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-01-09 13:30 72208 c:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~ 1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoa dGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LVCOMSX"=C:\WINDOWS\system32\LVCOMSX.EXE
"Norton Ghost 12.0"="C:\Program Files\Norton Ghost\Agent\VProTray.exe"
"Adobe_ID0EYTHM"=C:\PROGRA~1\FICHIE~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EX E
"nwiz"=nwiz.exe /install
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
"QuickTime Task"="C:\Program Files\QT Lite\qttask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\thrones.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"C:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"D:\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"D:\\GOW\\Binaries\\WarGame-G4WLive.exe"=
"D:\\Crysis\\Bin32\\Crysis.exe"=
"D:\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Fichiers communs\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Unreal Tournament 3\\Binaries\\UT3.exe"=
"C:\\Program Files\\Sierra\\FEARCombat\\FEARMP.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\French\\setup.exe"=
"C:\\WINDOWS\\system32\\CNAB4RPK.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"C:\\kav\\kis7.0\\english\\setup.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\patriots.exe"=
"D:\\Empire Earth III\\EE3.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"1434:UDP"= 1434:UDP

iskeeperSQL
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Icmp Settings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R1 bbcap;bbcap;C:\WINDOWS\system32\DRIVERS\bbcap.sys [2007-10-25 19:23]
R2 AcuWVSSchedulerv5;Acunetix WVS Scheduler v5;C:\Program Files\Acunetix\Web Vulnerability Scanner 5\WVSScheduler.exe [2007-10-26 13:50]
R2 SVPNStarter;Steganos VPN Starter Service;"C:\Program Files\Steganos Internet Anonym VPN\SVPNStarter.exe" [2007-02-16 14:35]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-04-13 20:34]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
R3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2007-02-15 18:48]
S3 BrlAPI;BrlAPI;C:\cygwin\bin\cygrunsrv.exe [2006-06-19 10:43]
S3 BS_DEF;BS_DEF;C:\Program Files\ASUS\AsusUpdate\BS_DEF.sys [2008-03-31 00:34]
S3 cpuz129;cpuz129;C:\DOCUME~1\Omar\LOCALS~1\Temp\cpuz_x32.sys []
S3 GoogleDesktopManager-010108-205858;Google Desktop Manager 5.7.801.1629;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-03 17:42]
S3 MSSQL$ADMINDB;MSSQL$ADMINDB;C:\Program Files\Microsoft SQL Server\MSSQL$ADMINDB\Binn\sqlservr.exe [2002-12-17 18:26]
S3 protection;protection;C:\Documents and Settings\Omar\Mes documents\My Received Files\Output(2)\protector.sys [2008-06-22 07:54]
S3 SQLAgent$ADMINDB;SQLAgent$ADMINDB;C:\Program Files\Microsoft SQL Server\MSSQL$ADMINDB\Binn\sqlagent.EXE [2002-12-17 18:23]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-11 20:01]
S3 wampapache;wampapache;"c:\wamp\apache2\bin\httpd.exe" -k runservice []
S3 wampmysqld;wampmysqld;c:\wamp\mysql\bin\mysqld-nt.exe [2007-07-06 13:14]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{8f535f99-3827-11dd-8d59-0018f82ece01}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{bbd0e44d-52eb-11dc-851d-0013d449e267}]
\Shell\AutoRun\command - fooool.exe
\Shell\explore\Command - fooool.exe
\Shell\open\Command - fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{d64aa2c3-c9f2-11dc-a24c-0018f82ece01}]
\Shell\AutoRun\command - L:\fooool.exe
\Shell\explore\Command - L:\fooool.exe
\Shell\open\Command - L:\fooool.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-27 16:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-07-01 18:07:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BM9756fc21 - C:\WINDOWS\system32\nftnhwdh.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-04 00:35:22
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\CNAB4RPK.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-04 0:51:27 - machine was rebooted [Omar]
ComboFix-quarantined-files.txt 2008-07-03 23:51:23
Pre-Run: 7,280,373,760 octets libres
Post-Run: 7,218,483,200 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=AlwaysOff /fastdetect /usepmtimer
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
352 --- E O F --- 2008-06-21 00:38:20