And finaly, the combofix log
ComboFix 08-06-30.2 - Simon 2008-07-01 21:52:16.3 -
FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.2.1036.18.665 [GMT -4:00]
Endroit: C:\Documents and Settings\Simon\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM465326c5.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\igiautal.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))))))))
.
2066-11-18 19:00 . 2066-11-18 19:00 0 --a------ C:\WINDOWS\BM465326c5.xml
2008-07-01 21:34 . 2008-07-01 21:34 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-01 21:34 . 2008-07-01 21:34 <REP> d-------- C:\Documents and Settings\Simon\Application Data\Malwarebytes
2008-07-01 21:34 . 2008-07-01 21:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-01 21:34 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamcatchme.sys
2008-07-01 21:34 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-07-01 10:24 . 2008-07-01 10:24 <REP> d-------- C:\Program Files\Trend Micro
2008-06-30 18:11 . 2008-06-30 18:11 <REP> d-------- C:\Program Files\Pure Networks
2008-06-30 18:11 . 2008-06-30 18:11 <REP> d-------- C:\Program Files\Fichiers communs\Pure Networks Shared
2008-06-30 18:10 . 2008-06-30 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-06-27 15:17 . 2008-06-27 15:17 <REP> d--hs---- C:\FOUND.046
2008-06-25 09:59 . 2004-11-19 11:02 221,184 --a------ C:\WINDOWS\SYSTEM32\wmpns.dll
2008-06-24 22:21 . 2008-06-24 22:21 <REP> d-------- C:\Program Files\Enigma Software Group
2008-06-24 09:27 . 2008-06-24 09:27 <REP> d--hs---- C:\FOUND.045
2008-06-23 10:40 . 2008-06-23 10:37 691,545 --a------ C:\WINDOWS\unins000.exe
2008-06-23 10:40 . 2008-06-23 10:40 2,546 --a------ C:\WINDOWS\unins000.dat
2008-06-16 20:20 . 2066-11-18 19:00 2,231 --a------ C:\iss.exe
2008-06-16 18:50 . 2008-06-16 18:50 415 ---hs---- C:\WINDOWS\SYSTEM32\dddgushg.ini
2008-06-16 14:29 . 2008-06-16 18:50 355 ---hs---- C:\WINDOWS\SYSTEM32\axcgvohk.ini
2008-06-16 12:29 . 2008-06-16 12:29 0 --a------ C:\is.exe
2008-06-16 12:10 . 2008-06-16 12:10 5,457 --a------ C:\a.exe
2008-06-11 08:54 . 2008-06-14 13:59 272,768 --------- C:\WINDOWS\SYSTEM32\DRIVERS\bthport.sys
2008-06-11 08:54 . 2008-06-14 13:59 272,768 --------- C:\WINDOWS\SYSTEM32\dllcache\bthport.sys
2008-06-03 11:03 . 2008-06-03 11:03 <REP> d--hs---- C:\FOUND.044
2008-06-02 16:06 . 2008-06-02 16:06 0 --a------ C:\WINDOWS\PowerReg.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\SYSTEM32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\SYSTEM32\dllcache\quartz.dll
2008-05-06 21:56 --------- d-----w C:\Program Files\iPod
2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\SYSTEM32\dllcache\iedw.exe
2008-03-03 15:16 351 ----a-w C:\Documents and Settings\Simon\.cb_layout.bin
2005-12-14 23:53 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2004-12-18 18:48 266 --sh--w C:\Program Files\desktop.ini
2004-12-18 18:48 11,208 ---h--w C:\Program Files\folder.htt
2004-10-01 19:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2007-04-19 00:11 848 --sha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
2007-04-19 00:11 56 --sh--r C:\WINDOWS\SYSTEM32\9D8CB5B4FF.sys
.
((((((((((((((((((((((((((((( snapshot_2008-06-27_12.04.01.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-27 15:56:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-01 14:01:42 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-06-26 00:15:16 2,704 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{761D618F-B59F-4164-97D5-115BBF664D98}.bin
+ 2008-06-26 00:15:16 3,352 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{761D618F-B59F-4164-97D5-115BBF664D98}.bin
+ 2006-01-25 21:36:40 487,424 ----a-w C:\WINDOWS\SYSTEM32\MSVCP70.dll
+ 2006-01-25 21:36:40 344,064 ----a-w C:\WINDOWS\SYSTEM32\MSVCR70.dll
+ 2008-07-01 14:01:46 16,384 ----a-w C:\WINDOWS\TEMP\Perflib_Perfdata_594.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@="{7D688A77-C613-11D0-999B-00C04FD655E1}"
[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2007-10-25 11:56 8510976 --a------ C:\WINDOWS\SYSTEM32\SHELL32.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-11-19 11:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2007-11-07 10:06 1881400]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-11-19 11:01 144384]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28 790528]
"iKeyWorks"="C:\PROGRA~1\Keyboard\Ikeymain.exe" [2002-11-22 18:22 73728]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [2000-11-28 05:10 20480]
"Client Access Help Update"="C:\Program Files\IBM\Client Access\cwbinhlp.exe" [2000-11-28 05:10 24576]
"Client Access Express Welcome"="C:\Program Files\IBM\Client Access\cwbwlwiz.exe" [2000-11-28 05:10 20480]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" [2007-04-12 17:26 249856]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Ulead AutoDetector"="C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe" [2003-03-24 19:29 45056]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-03-13 21:06 1397760]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-28 05:03 188416]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2006-05-01 16:27 1042000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-11-19 11:00 15360]
C:\Documents and Settings\Simon\Menu D‚marrer\Programmes\D‚marrage\
PowerReg Scheduler.exe [2008-06-02 16:08:08 256000]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Jean Coutu Client VPN.lnk - C:\Program Files\Jean Coutu\Client VPN\vpngui.exe [2006-01-15 19:26:53 1470296]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= IR41_32.DLL
"VIDC.VDOM"= vdowave.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\BIN\\hpoews01.exe"=
"C:\\Program Files\\Dofus\\Dofus.exe"=
"C:\\Program Files\\JVTorrent\\btdownloadgui.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\Age2_X1\\AGE2_X1.ICD"=
"C:\\WINDOWS\\System32\\dplaysvr.exe"=
"C:\\Program Files\\THQ\\Titan Quest\\Titan Quest.exe"=
"C:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
"C:\\Documents and Settings\\Simon\\Mes documents\\age2_x1.exe"=
"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"C:\\Program Files\\Fichiers communs\\i4j_jres\\1.6.0\\bin\\java.exe"=
"C:\\Program Files\\FileZilla\\FileZilla.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Microsoft Games\\Rise of Nations\\Thrones.exe"=
"C:\\Program Files\\Teamspeak2_RC2_serveur\\server_windows.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16841:TCP"= 16841:TCP:BitComet 16841 TCP
"16841:UDP"= 16841:UDP:BitComet 16841 UDP
"67:UDP"= 67:UDP

HCP Discovery Service
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R1 Odptdi;Odptdi;C:\WINDOWS\system32\drivers\odptdi.sys [2007-02-05 10:58]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
S2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" /service []
S3 ewdmaudn;ewdmaudn;C:\DOCUME~1\Simon\LOCALS~1\Temp\ewdmaudn.sys []
S3 gprocess;gprocess;C:\DOCUME~1\Simon\LOCALS~1\Temp\gprocess.sys []
S3 twanarp;twanarp;C:\DOCUME~1\Simon\LOCALS~1\Temp\twanarp.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd96b544-5106-11d9-a423-806d6172696f}]
\Shell\AutoRun\command - D:\AutoRun.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-07 13:00:02 C:\WINDOWS\Tasks\Démarrage du programme de réglages.job"
"2008-06-21 13:47:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PowerBar - (no file)
MSConfigStartUp-= - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-01 21:54:27
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-01 21:54:51
ComboFix-quarantined-files.txt 2008-07-02 01:54:50
ComboFix2.txt 2008-06-27 16:04:16
Pre-Run: 18,947,637,248 octets libres
Post-Run: 19,038,240,768 octets libres
191 --- E O F --- 2008-06-21 07:02:40
Hope tou can still help me