ComboFix 09-10-14.09 - utilisateur 15/10/2009 17:56.1.2 - NTFSx86
Microsoft® Windows Vista™ Edition Familiale Premium 6.0.6002.2.1251.7.1036.18.2047.1067 [GMT 2:00]
Running from: c:\users\utilisateur\Desktop\killbagle.exe
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\28fd5.msi
c:\windows\Installer\3e311.msp
Infected copy of c:\windows\System32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :^)
.
((((((((((((((((((((((((( Files Created from 2009-09-15 to 2009-10-15 )))))))))))))))))))))))))))))))
.
2009-10-15 16:05 . 2009-10-15 16:06 -------- d-----w- c:\users\utilisateur\AppData\Local\temp
2009-10-15 16:05 . 2009-10-15 16:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-10-15 16:05 . 2009-10-15 16:05 -------- d-----w- c:\users\Administrateur\AppData\Local\temp
2009-10-15 04:52 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-15 04:52 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 04:52 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-14 16:29 . 2009-10-14 16:29 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-14 16:10 . 2009-10-14 16:48 -------- d-----w- C:\UsbFix
2009-10-14 14:57 . 2009-10-14 14:57 -------- d-----w- c:\users\Administrateur\AppData\Roaming\Malwarebytes
2009-10-14 05:50 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-14 05:50 . 2009-10-14 05:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-14 05:50 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-13 05:33 . 2009-10-13 05:33 -------- d-----w- c:\users\utilisateur\AppData\Roaming\Malwarebytes
2009-10-13 05:33 . 2009-10-13 05:33 -------- d-----w- c:\programdata\Malwarebytes
2009-10-13 05:22 . 2009-10-13 05:22 -------- d-----w- C:\_OTM
2009-10-13 05:01 . 2009-10-13 05:01 -------- d-----w- C:\rsit
2009-10-13 04:52 . 2009-10-14 15:48 -------- d-----w- c:\program files\Trend Micro
2009-10-13 04:19 . 2009-10-13 04:19 -------- d-----w- c:\programdata\WindowsSearch
2009-10-12 16:33 . 2009-10-12 16:33 102 ----a-w- c:\users\Administrateur\AppData\Local\fusioncache.dat
2009-10-12 16:33 . 2009-10-14 14:57 -------- d-----w- c:\users\Administrateur\AppData\Local\ApplicationHistory
2009-10-12 16:33 . 2009-10-12 16:33 -------- d-----w- c:\users\Administrateur\AppData\Local\Apple Computer
2009-10-12 16:33 . 2009-10-12 16:33 -------- d-----w- c:\users\Administrateur\AppData\Roaming\Roxio
2009-10-12 16:33 . 2009-10-12 16:33 119376 ----a-w- c:\users\Administrateur\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-12 01:12 . 2009-10-12 01:12 680 ----a-w- c:\users\utilisateur\AppData\Local\d3d9caps.dat
2009-10-12 01:12 . 2009-10-12 01:12 -------- d-----w- c:\windows\Sun
2009-10-07 09:39 . 2009-10-07 09:39 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-10-07 09:39 . 2009-10-07 09:39 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-07 09:37 . 2009-10-07 09:37 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-07 09:36 . 2009-10-07 09:40 -------- d-----w- c:\program files\Microsoft
2009-10-02 15:52 . 2009-10-01 08:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-27 17:31 . 2009-09-27 17:31 -------- d-----w- c:\windows\system32\ca-ES
2009-09-27 17:31 . 2009-09-27 17:31 -------- d-----w- c:\windows\system32\eu-ES
2009-09-27 17:31 . 2009-09-27 17:31 -------- d-----w- c:\windows\system32\vi-VN
2009-09-27 15:59 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-09-27 15:59 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-09-27 15:59 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-09-27 15:59 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-09-27 15:59 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-09-27 15:59 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-09-27 15:59 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-09-27 15:33 . 2009-09-27 15:33 -------- d-----w- c:\windows\system32\EventProviders
2009-09-24 03:10 . 2009-04-11 06:28 112640 ----a-w- c:\windows\system32\spreview.exe
2009-09-24 03:09 . 2009-04-11 06:28 342528 ----a-w- c:\windows\system32\zipfldr.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-15 16:03 . 2007-02-08 06:00 671128 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-15 16:03 . 2007-02-08 06:00 128104 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-15 15:46 . 2008-02-11 17:10 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-10-15 15:46 . 2008-02-11 17:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-15 06:20 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-10-15 06:19 . 2008-02-11 17:18 -------- d-----w- c:\users\utilisateur\AppData\Roaming\Skype
2009-10-15 06:09 . 2008-02-11 17:19 -------- d-----w- c:\users\utilisateur\AppData\Roaming\skypePM
2009-10-13 15:05 . 2007-02-07 21:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-13 14:48 . 2008-10-29 21:08 -------- d-----w- c:\program files\Navilog1
2009-10-12 17:09 . 2008-03-02 21:54 -------- d-----w- c:\program files\DAEMON Tools
2009-10-07 09:39 . 2008-02-26 05:06 -------- d-----w- c:\program files\Windows Live
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-09-27 17:32 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-09-27 17:29 . 2008-04-10 13:43 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-09-14 09:29 . 2009-10-15 04:51 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 04:42 . 2008-11-20 18:59 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 04:44 . 2009-08-16 19:32 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-09-04 11:41 . 2009-10-15 04:51 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 00:27 . 2009-09-03 11:37 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-03 11:37 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:22 . 2009-10-15 04:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-15 04:51 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-15 04:51 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-15 04:51 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-24 09:21 . 2008-02-14 13:11 -------- d-----w- c:\program files\Java
2009-08-18 15:42 . 2009-05-29 03:23 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-16 21:00 . 2009-08-16 19:32 -------- d-----w- c:\users\utilisateur\AppData\Roaming\Nowe Gadu-Gadu
2009-08-14 16:27 . 2009-09-10 04:11 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-08-14 15:53 . 2009-09-10 04:11 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 13:49 . 2009-09-10 04:11 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 13:49 . 2009-09-10 04:11 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 13:49 . 2009-09-10 04:11 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 13:49 . 2009-09-10 04:11 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 13:49 . 2009-09-10 04:11 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 13:49 . 2009-09-10 04:11 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 13:49 . 2009-09-10 04:11 10240 ----a-w- c:\windows\system32\finger.exe
2009-08-14 13:48 . 2009-09-10 04:11 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48 . 2009-09-10 04:11 105984 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-25 03:23 . 2008-11-27 15:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-06 00:48 . 2007-02-07 22:04 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-07-06 00:48 . 2007-02-07 22:04 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-07-06 00:48 . 2007-02-07 22:04 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-07-06 00:48 . 2007-02-07 22:04 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-07-06 00:48 . 2007-02-07 22:04 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-02-08 06:15 . 2007-02-08 06:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 232184]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-05-10 4468736]
"Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-05-07 1826816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"UacDisableNotify"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):0b,80,ab,64,99,3f,ca,01
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5CC6D6A9-AC9D-4CD9-9EA9-1DA9736717F9}"= UDP:990:LocalSubnet:LocalSubnet|IF={CFD4D4AF-54F6-4BE7-A1A5-413E6076A502}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"TCP Query User{9278230A-D23B-45F6-9A8E-D44F78964378}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{E25D810B-26BE-451C-8C90-1A439EAE5482}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{FC890159-7475-4710-881F-375C86E4CC61}c:\\program files\\gadu-gadu\\gg.exe"= UDP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program glowny
"UDP Query User{98A7708E-86A6-431D-93DC-6137249594D1}c:\\program files\\gadu-gadu\\gg.exe"= TCP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program glowny
"TCP Query User{0406F418-9764-4453-B1A6-EC01FABD3383}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{E28C9CC3-B524-4102-A4E0-6FF7B2C38FD0}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{D1CB2E70-11A5-4DA1-9293-A8A6290B9024}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{C817E480-B105-410E-B4C1-27AC8188D73A}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{54BC3CB7-03E2-491F-B42D-1E2B7D9FCC0E}"= UDP:c:\users\utilisateur\Desktop\mes documents\jozef\BF2.exe:Battlefield 2
"{31F0DF6D-53F8-487C-B432-B945F8BCCB01}"= TCP:c:\users\utilisateur\Desktop\mes documents\jozef\BF2.exe:Battlefield 2
"TCP Query User{765A483E-D5E5-4800-97F4-569D83FECCA6}c:\\users\\utilisateur\\desktop\\mes documents\\jozef\\bf2_w32ded.exe"= UDP:c:\users\utilisateur\desktop\mes documents\jozef\bf2_w32ded.exe:bf2_w32ded.exe
"UDP Query User{CDA0AB30-C2EE-4E48-8118-E9A0F8CF5ED0}c:\\users\\utilisateur\\desktop\\mes documents\\jozef\\bf2_w32ded.exe"= TCP:c:\users\utilisateur\desktop\mes documents\jozef\bf2_w32ded.exe:bf2_w32ded.exe
"TCP Query User{F9C60E09-AC38-435E-9985-F2B694D01FF7}c:\\users\\utilisateur\\desktop\\jozek\\jeux\\jeux battlefield\\prg jeux\\bf2.exe"= UDP:c:\users\utilisateur\desktop\jozek\jeux\jeux battlefield\prg jeux\bf2.exe:bf2.exe
"UDP Query User{F4FA3984-1F65-4710-A972-57DD51109171}c:\\users\\utilisateur\\desktop\\jozek\\jeux\\jeux battlefield\\prg jeux\\bf2.exe"= TCP:c:\users\utilisateur\desktop\jozek\jeux\jeux battlefield\prg jeux\bf2.exe:bf2.exe
"{ADF2EBFF-6291-4342-BB59-B23EA73B3496}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM
"{4DB826BF-40AD-4D3A-B54F-C6F3E7F9F014}"= UDP:990:LocalSubnet:LocalSubnet|IF={CFD4D4AF-54F6-4BE7-A1A5-413E6076A502}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{E2AD7E0C-6F24-416E-9113-778DE9E0A741}"= UDP:990:LocalSubnet:LocalSubnet|IF={CFD4D4AF-54F6-4BE7-A1A5-413E6076A502}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{48EC5BAD-C30B-446A-95C3-F1A90A38C5C3}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F7082DE8-F9A0-46E4-9182-629C163C6F2A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{606525C5-0B0B-43D1-AE8D-1D02E590C3A8}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{C7E5C9EF-10B7-44BB-B7C7-3F1A3DA23DFB}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{EDE313AA-2AE8-4836-AD73-91A083A3DFAB}"= Disabled:UDP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{6CF7059D-ECD0-4524-A92A-D55E4C192EF1}"= Disabled:TCP:c:\program files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{5FB1D0BD-A4D2-44F5-A688-DDD9CBD0490C}"= Disabled:UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{552755DF-F1F2-4CA7-9BC0-12403AD5F5AA}"= Disabled:TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{7512B924-C7D5-4A75-BFF1-D07169B27217}"= UDP:c:\program files\Avira\AntiVir PersonalEdition Classic\avcenter.exe:Start AntiVir PersonalEdition Classic
"{5EF7CA74-E799-4F9B-B3E3-050CD9CEC52E}"= TCP:c:\program files\Avira\AntiVir PersonalEdition Classic\avcenter.exe:Start AntiVir PersonalEdition Classic
"{8F7AD699-BFCC-4F55-A16C-A8153814C461}"= UDP:80:emule
"{6D8F6E0F-FDBC-4782-AD7A-31F4FF39AE07}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{8D7C56B6-5381-4E07-BB6C-DD08E5AB4099}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{EA6296A9-A122-44D4-B5C8-6D166CE25749}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{6622A33E-D65D-45EE-81FB-4D817E06084C}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{7F296F6C-5782-43AC-A09F-BC1A571912E2}"= UDP:c:\program files\EA Games\Battlefield 2\BF2.exe:Battlefield 2
"{BCAA31A7-4109-457E-B4E9-D0E4FD1E12B5}"= TCP:c:\program files\EA Games\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{7C922BD5-2480-4101-A2E7-23478B8A454E}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{18F51588-888C-426A-8CED-33BF71B7ADDF}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{9C24C5F5-475D-4FA0-A57A-66731FC0A4CE}"= Disabled:UDP:443:TCP port 443 ooVoo
"{CDDB2D33-98EA-43BD-B7F6-B7275933DB0E}"= Disabled:TCP:443:UDP port 443 ooVoo
"{EE70B640-47E0-4BD6-9445-0A120AAE29DB}"= Disabled:UDP:37674:TCP port 37674 ooVoo
"{13A6CA19-7646-4E4E-A009-F9903750676A}"= Disabled:TCP:37674:UDP port 37674 ooVoo
"{4D9FD498-0777-4163-B7F6-728A742A50BC}"= Disabled:TCP:37675:UDP port 37675 ooVoo
"TCP Query User{4F1A88E0-A939-41F6-999F-B1696DBB881E}c:\\program files\\gadu-gadu\\gg.exe"= UDP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program glowny
"UDP Query User{9CD2B29C-86E2-4B04-8A39-0D6C9AFDCCD0}c:\\program files\\gadu-gadu\\gg.exe"= TCP:c:\program files\gadu-gadu\gg.exe:Gadu-Gadu - program glowny
"TCP Query User{28E0D096-353B-46B7-A877-B7FEF5FDE537}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{ED8EA57B-07FA-4E31-8A37-4927E289F5AF}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{BB8ACE1E-1BF7-4D98-8114-EF321DF8705E}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{E115E5E6-4A18-4A6E-8143-97E3189D9E3E}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"TCP Query User{4189781F-D49A-427B-8119-92A1BF04529D}c:\\program files\\ea games\\battlefield 2\\bf2.exe"= UDP:c:\program files\ea games\battlefield 2\bf2.exe:BF2
"UDP Query User{66F583B1-19A1-47EC-AD20-AD4F90CB67C7}c:\\program files\\ea games\\battlefield 2\\bf2.exe"= TCP:c:\program files\ea games\battlefield 2\bf2.exe:BF2
"{02BD0B28-7262-4F8D-9A4A-0CE3E2B2E21A}"= c:\program files\Skype\Phone\Skype.exe:Skype
"TCP Query User{378AC956-7665-4FDC-B257-FB1C81CCF0CE}c:\\program files\\radio fr solo\\radio_fr_solo.exe"= UDP:c:\program files\radio fr solo\radio_fr_solo.exe:Radio Fr Solo
"UDP Query User{A7BD499C-9BCC-436C-ADD6-215542FEEB46}c:\\program files\\radio fr solo\\radio_fr_solo.exe"= TCP:c:\program files\radio fr solo\radio_fr_solo.exe:Radio Fr Solo
"TCP Query User{9964EA6E-58DE-44AB-9926-8979E5A827D2}c:\\program files\\nowe gadu-gadu\\gg.exe"= UDP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"UDP Query User{D5581F4C-1715-451A-8886-92DD583F50B3}c:\\program files\\nowe gadu-gadu\\gg.exe"= TCP:c:\program files\nowe gadu-gadu\gg.exe:Nowe Gadu-Gadu
"{D74849FA-8CB6-458E-9BA7-B9BD9DFE7D70}"= UDP:990:LocalSubnet:LocalSubnet|IF={CFD4D4AF-54F6-4BE7-A1A5-413E6076A502}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{73565605-97E9-452C-AA59-82E4BE63F83E}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live FolderShare
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [29/05/2009 05:23 108289]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [10/12/2008 10:49 185640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-15 c:\windows\Tasks\Extension de garantie.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2007-02-07 16:38]
2009-10-15 c:\windows\Tasks\Recovery DVD Creator.job
- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2007-02-07 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://france.meteofrance.com/france/meteo?PREVISIONS_PORTLET.path=previsionsregion/REG11
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\utilisateur\AppData\Roaming\Mozilla\Firefox\Profiles\tjuh56fp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/|http://partnerpage.google.com/packardbell.com/fr
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/...{moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{66886C4D-B307-4ECA-A228-52CA9B9851A4} - (no file)
WebBrowser-{A057A204-BACC-4D26-8087-36EE87E26986} - (no file)
WebBrowser-{000D05A6-041B-0000-0000-000000000000} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-15 18:06
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\users\UTILIS~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
c:\windows\TEMP\TMP00000034EEEEAA23CCDBF5A5 524288 bytes executable
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2606543019-183741034-154919260-1002\Software\SecuROM\License information*]
"datasecu"=hex:b1,4f,43,4d,69,b6,10,0a,1a,d4,99,d6,6b,69,f6,95,30,c1,b1,49,1d,
7f,82,cd,5d,17,f6,dc,e8,cf,bd,61,fe,74,8b,01,1c,ba,e4,d5,d8,e4,11,51,e2,71,\
"rkeysecu"=hex:8b,54,36,cb,8e,2d,48,00,ec,5e,16,b5,b6,82,5f,f6
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000000
.
Completion time: 2009-10-15 18:07
ComboFix-quarantined-files.txt 2009-10-15 16:07
Pre-Run: 94 426 292 224 octets libres
Post-Run: 94 367 551 488 octets libres
298 --- E O F --- 2009-10-15 05:25