ok this is the log from ComboFix
By the way, thanks a lot for helping me !
ComboFix 09-02-15.01 - Alexandre 2009-02-17 16:48:09.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1023.653 [GMT -5:00]
Lancé depuis: c:\documents and settings\Alexandre\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\fxstaller.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-17 au 2009-02-17 ))))))))))))))))))))))))))))))))))))
.
2009-02-16 21:57 . 2009-02-16 21:57 <REP> d-------- c:\program files\Trend Micro
2009-02-16 21:22 . 2009-02-16 21:28 <REP> d-------- C:\QUARANTINE
2009-02-08 12:44 . 2009-02-08 12:44 <REP> d-------- c:\program files\Free M4a to MP3 Converter
2009-02-06 22:48 . 2009-02-06 22:48 <REP> d-------- c:\program files\MSXML 4.0
2009-02-05 17:08 . 2009-02-05 17:08 <REP> d-------- c:\program files\Motorola
2009-02-05 17:08 . 2009-02-05 17:08 <REP> d-------- c:\program files\Common Files
2009-02-05 17:08 . 2007-10-10 17:41 42,112 --a------ c:\windows\system32\drivers\motodrv.sys
2009-02-05 17:03 . 2009-02-05 17:03 <REP> d-------- c:\program files\Avanquest update
2009-02-05 16:57 . 2009-02-05 16:57 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-05 16:57 . 2009-02-05 16:57 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-02-05 16:56 . 2006-11-13 14:45 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2009-02-05 16:56 . 2007-06-18 14:18 23,680 --a------ c:\windows\system32\drivers\motmodem.sys
2009-02-05 16:55 . 2009-02-09 22:26 <REP> d-------- c:\program files\Motorola Phone Tools
2009-02-05 16:55 . 2009-02-09 22:05 <REP> d-------- c:\program files\Fichiers communs\Motorola Shared
2009-02-05 16:55 . 2009-02-05 17:02 <REP> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2009-02-05 16:55 . 2009-02-05 16:55 <REP> d-------- c:\documents and settings\Alexandre\Application Data\InstallShield
2009-02-05 16:54 . 2008-04-13 14:45 26,112 --a------ c:\windows\system32\drivers\usbser.sys
2009-02-05 16:54 . 2008-04-13 14:45 26,112 --a--c--- c:\windows\system32\dllcache\usbser.sys
2009-02-03 20:57 . 2009-02-03 20:57 268 --ah----- C:\sqmdata19.sqm
2009-02-03 20:57 . 2009-02-03 20:57 244 --ah----- C:\sqmnoopt19.sqm
2009-02-02 19:59 . 2009-02-02 19:59 268 --ah----- C:\sqmdata18.sqm
2009-02-02 19:59 . 2009-02-02 19:59 244 --ah----- C:\sqmnoopt18.sqm
2009-01-31 18:56 . 2009-01-31 18:56 268 --ah----- C:\sqmdata17.sqm
2009-01-31 18:56 . 2009-01-31 18:56 244 --ah----- C:\sqmnoopt17.sqm
2009-01-30 16:39 . 2009-01-30 16:39 268 --ah----- C:\sqmdata16.sqm
2009-01-30 16:39 . 2009-01-30 16:39 244 --ah----- C:\sqmnoopt16.sqm
2009-01-29 22:01 . 2009-01-29 22:01 268 --ah----- C:\sqmdata15.sqm
2009-01-29 22:01 . 2009-01-29 22:01 244 --ah----- C:\sqmnoopt15.sqm
2009-01-28 22:03 . 2009-01-28 22:03 268 --ah----- C:\sqmdata14.sqm
2009-01-28 22:03 . 2009-01-28 22:03 244 --ah----- C:\sqmnoopt14.sqm
2009-01-27 20:45 . 2009-01-27 20:45 268 --ah----- C:\sqmdata13.sqm
2009-01-27 20:45 . 2009-01-27 20:45 244 --ah----- C:\sqmnoopt13.sqm
2009-01-25 17:43 . 2009-01-25 17:43 268 --ah----- C:\sqmdata12.sqm
2009-01-25 17:43 . 2009-01-25 17:43 244 --ah----- C:\sqmnoopt12.sqm
2009-01-24 18:55 . 2009-01-24 18:55 268 --ah----- C:\sqmdata11.sqm
2009-01-24 18:55 . 2009-01-24 18:55 244 --ah----- C:\sqmnoopt11.sqm
2009-01-23 23:04 . 2009-01-23 23:04 268 --ah----- C:\sqmdata10.sqm
2009-01-23 23:04 . 2009-01-23 23:04 244 --ah----- C:\sqmnoopt10.sqm
2009-01-21 20:48 . 2009-01-21 20:48 268 --ah----- C:\sqmdata09.sqm
2009-01-21 20:48 . 2009-01-21 20:48 244 --ah----- C:\sqmnoopt09.sqm
2009-01-19 20:00 . 2009-01-19 20:00 268 --ah----- C:\sqmdata08.sqm
2009-01-19 20:00 . 2009-01-19 20:00 244 --ah----- C:\sqmnoopt08.sqm
2009-01-18 22:37 . 2009-02-15 13:06 268 --ah----- C:\sqmdata07.sqm
2009-01-18 22:37 . 2009-02-15 13:06 244 --ah----- C:\sqmnoopt07.sqm
2009-01-18 17:36 . 2009-01-18 17:36 <REP> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-18 17:13 . 2009-01-18 17:13 <REP> d-------- c:\program files\Fichiers communs\Macrovision Shared
2009-01-18 17:09 . 2009-01-18 17:57 <REP> d-------- c:\program files\Adobe CS3
2009-01-17 17:15 . 2009-02-14 22:50 268 --ah----- C:\sqmdata06.sqm
2009-01-17 17:15 . 2009-02-14 22:50 244 --ah----- C:\sqmnoopt06.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-17 21:30 --------- d-----w c:\program files\Steam
2009-02-15 21:17 --------- d-----w c:\documents and settings\Alexandre\Application Data\uTorrent
2009-02-14 17:38 --------- d-----w c:\documents and settings\Alexandre\Application Data\LimeWire
2009-02-11 03:32 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-10 03:17 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-01 19:24 --------- d-----w c:\documents and settings\Alexandre\Application Data\dvdcss
2009-01-18 22:26 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-01-10 23:26 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-10 23:26 --------- d-----w c:\program files\Java
2009-01-08 01:31 --------- d-----w c:\program files\Bonjour
2009-01-01 19:34 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-31 02:54 --------- d-----w c:\documents and settings\Alexandre\Application Data\vlc
2008-12-25 19:03 --------- d-----w c:\program files\Picasa2
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 02:31 --------- d-----w c:\program files\QuickTime
2008-12-19 18:59 --------- d-----w c:\program files\Fichiers communs\DVDVideoSoft
2008-12-19 18:58 --------- d-----w c:\program files\DVDVideoSoft
2008-12-19 18:19 --------- d-----w c:\program files\iTunes
2008-12-19 18:19 --------- d-----w c:\program files\iPod
2008-12-19 18:19 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-19 18:15 --------- d-----w c:\program files\Fichiers communs\Apple
2008-12-12 16:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
2008-12-12 16:11 61,440 ----a-w c:\windows\system32\dnssd.dll
2008-11-02 00:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008110120081102\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Gestionnaire Antidote.exe"="c:\program files\Druide\Antidote\Gestionnaire Antidote.exe" [2007-09-23 533944]
"Steam"="c:\program files\Steam\Steam.exe" [2008-12-23 1410296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-10 136600]
"StatusClient"="c:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="c:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\nash_benoit@hotmail.com\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\nash_benoit@hotmail.com\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Motorola\\Software Update\\msu.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2009-02-05 42112]
.
Contenu du dossier 'Tâches planifiées'
2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Alexandre\Application Data\Mozilla\Firefox\Profiles\fbhc2vb9.default\
FF - prefs.js: browser.startup.homepage - hxxp://ca.youtube.com/
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-02-17 16:49:39
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-02-17 16:51:12
ComboFix-quarantined-files.txt 2009-02-17 21:51:09
Avant-CF: 60 584 755 200 octets libres
Après-CF: 60,915,933,184 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
171 --- E O F --- 2009-02-11 03:33:55