J'AI LE RAPPORT COMOFIX:
ComboFix 09-08-19.0C - Administrateur 20/08/2009 16:45.1.1 - FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.2.1256.213.1036.18.255.88 [GMT 1:00]
Running from: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Application Data\wiaserva.log
c:\documents and settings\Administrateur\Application Data\wiaservg.log
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\InfoSat.txt
C:\Muestras
c:\muestras\111WFS1INTWQ.SYS.Muestra EliBagle v12.79
c:\muestras\WINUPGRO.EXE.Muestra EliBagle v12.79
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\command
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\npf.sys
c:\windows\system32\pthreadVC.dll
----- BITS: Possible infected sites -----
hxxp://www.hhdsoftware.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_111111S1RO1S1A
-------\Legacy_NPF
-------\Legacy_SK9OU0S
-------\Service_NPF
-------\Service_sK9Ou0s
((((((((((((((((((((((((( Files Created from 2009-07-20 to 2009-08-20 )))))))))))))))))))))))))))))))
.
-----
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-20 15:22 . 2009-03-25 20:25 28672 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\NP_IDM5.dll
2009-08-20 15:22 . 2009-03-25 20:25 28672 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\NP_IDM4.dll
2009-08-20 15:22 . 2009-03-25 20:25 28672 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\NP_IDM3.dll
2009-08-20 15:22 . 2009-03-25 20:25 28672 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\NP_IDM2.dll
2009-08-20 15:22 . 2009-03-25 20:25 28672 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\NP_IDM1.dll
2009-08-20 13:13 . 2001-08-24 11:00 557770 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-20 13:13 . 2001-08-24 11:00 105136 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-19 20:21 . 2009-08-19 20:21 78415 ----a-w- c:\windows\system32\drivers\klif.cab
2009-08-12 00:13 . 2008-10-18 18:10 92600 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-10 12:07 . 2009-07-10 12:07 -------- d-----w- c:\program files\Fichiers communs\SWF Studio
2009-07-10 11:56 . 2009-07-10 11:56 -------- d-----w- c:\program files\Viewpoint
2009-07-10 11:56 . 2009-07-10 11:56 -------- d-----w- c:\program files\VIH1
2009-06-28 15:20 . 2009-06-28 15:20 0 ----a-w- c:\windows\nsreg.dat
2009-06-12 20:14 . 2009-06-12 20:13 85 ----a-w- c:\documents and settings\Administrateur\Application Data\IDM\DwnlData\Administrateur\registrybooster_1290\registrybooster.exe
2009-06-09 19:49 . 2009-06-09 19:00 71680 ----a-w- C:\lnvplo.exe
2009-06-08 19:59 . 2009-06-08 19:58 1614 ----a-w- c:\documents and settings\Administrateur\Application Data\filterclsid.dat
2007-04-19 11:01 . 2007-04-19 10:36 11208 ---h--w- c:\program files\folder.htt
2001-05-24 11:59 . 2007-07-15 07:43 162304 ----a-w- c:\program files\UNWISE.EXE
.
------- Sigcheck -------
[-] 2004-08-18 06:09 359040 7B11118B078B88F87183FE69EDA43137 c:\windows\SYSTEM32\DRIVERS\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SDTray"="c:\program files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 1063752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"= 64 (0x40)
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ClearDocsOnExit"= 64 (0x40)
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Ask Larousse Chambers.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Ask Larousse Chambers.lnk
backup=c:\windows\pss\Ask Larousse Chambers.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4661:TCP"= 4661:TCP:*:Disabled:tcp
"7065:UDP"= 7065:UDP:*:Disabled:UDP Sharing
"6002:UDP"= 6002:UDP:*:Disabled:newcamd
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [20/08/2009 14:12 729416]
R3 slnt;Real RTL8139 PCI Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\slnt.sys [10/10/2002 18:50 18004]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys --> c:\windows\system32\drivers\pavboot.sys [?]
S1 76b1135b;76b1135b;c:\windows\system32\drivers\76b1135b.sys --> c:\windows\system32\drivers\76b1135b.sys [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 ioperm;ioperm support for Cygwin driver;\??\c:\documents and settings\Administrateur\Bureau\gbox 1.9j avec gbox 2.25\gbox 1.9j avec gbox 2.25\ioperm.sys --> c:\documents and settings\Administrateur\Bureau\gbox 1.9j avec gbox 2.25\gbox 1.9j avec gbox 2.25\ioperm.sys [?]
S3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\DRIVERS\avfwim.sys --> c:\windows\system32\DRIVERS\avfwim.sys [?]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 07:01 2799808]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [19/08/2009 22:31 77312]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\zeb1hii8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - component: c:\documents and settings\Administrateur\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NP_IDM1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NP_IDM2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NP_IDM3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NP_IDM4.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NP_IDM5.dll
.
.
------- File Associations -------
.
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-20 16:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):36,db,78,4d,df,8e,de,81,07,20,30,fd,89,22,65,c8,2d,da,fe,0b,f0,
66,63,9f,ef,da,cf,83,35,0f,92,a4,af,dc,3a,33,a1,c1,69,50,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):04,54,83,20,3f,db,89,11,9e,dc,ef,cf,9c,5f,0f,22,4c,b6,cf,b6,59,
82,1f,2f,71,4a,24,8e,a3,6b,fa,ac,36,45,fe,ba,22,fe,82,40,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d9017151-da27-477f-b794-37201b8de726}]
@Denied: (Full) (Everyone)
"Model"=dword:00000163
"Therad"=dword:0000000f
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fe81229d-5185-4c6b-86f5-ab618f5de8e1}]
@Denied: (Full) (Everyone)
"Model"=dword:00000135
"Therad"=dword:0000001a
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2508)
c:\windows\system32\msi.dll
c:\windows\system32\shdoclc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
c:\program files\MICROSOFT SQL SERVER\MSSQL.1\MSSQL\BINN\SQLSERVR.EXE
c:\program files\Spyware Doctor\swdsvc.exe
c:\windows\system32\slserv.exe
.
**************************************************************************
.
Completion time: 2009-08-20 17:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-20 16:06
Pre-Run: 16 255 287 296 octets libres
Post-Run: 16 572 481 536 octets libres
250