la suite de rapport combofix....
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_Psyche
-------\Legacy_PsycheEnqueue
-------\Legacy_ATI7PKXX
-------\Legacy_CBEVTSVC
-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_R_SERVER
-------\Legacy_SERV-U
-------\Legacy_TCPSR
-------\Service_ati7pkxx
-------\Service_FCI
-------\Service_ICF
-------\Service_r_server
-------\Service_Serv-U
((((((((((((((((((((((((( Files Created from 2008-10-10 to 2008-11-10 )))))))))))))))))))))))))))))))
.
2008-11-10 00:54 . 2008-11-10 11:08 16,451 --a--c--- c:\windows\gmail.com-error.html
2008-11-10 00:54 . 2008-11-10 11:08 6,182 --a--c--- c:\windows\live.com-error.html
2008-11-10 00:54 . 2008-11-10 11:08 5,596 --a--c--- c:\windows\aol.com-error.html
2008-11-10 00:54 . 2008-11-10 11:08 3,696 --a--c--- c:\windows\google.com-error.html
2008-11-10 00:54 . 2008-11-10 11:08 1,997 --a--c--- c:\windows\search.yahoo.com-error.html
2008-11-01 14:12 . 2008-11-01 14:16 556 --a--c--- c:\windows\eReg.dat
2008-11-01 00:58 . 2008-11-01 00:58
d----c--- c:\program files\EA GAMES
2008-10-25 13:50 . 2008-10-25 13:50 54,156 --ah-c--- c:\windows\QTFont.qfn
2008-10-25 13:50 . 2008-10-25 13:50 1,409 --a--c--- c:\windows\QTFont.for
2008-10-24 12:21 . 2008-10-24 12:21 2,275,840 --a--c--- c:\windows\system32\TUKernel.exe
2008-10-22 21:44 . 2008-10-22 21:44 189,796 --ah-c--- c:\windows\system32\mlfcache.dat
2008-10-22 21:39 . 2008-10-22 21:39 d----c--- c:\program files\Common Files\Adobe AIR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 03:08 --------- dc----w c:\program files\XoftSpySE
2008-11-10 00:56 --------- dc----w c:\program files\Opera
2008-11-09 14:21 --------- dc----w c:\program files\Internet Download Manager
2008-10-25 18:23 90,112 ----a-w c:\windows\DUMPed7c.tmp
2008-10-24 12:00 --------- dc----w c:\program files\nLite
2008-10-24 01:25 90,112 ----a-w c:\windows\DUMPe493.tmp
2008-10-22 00:13 90,112 ----a-w c:\windows\DUMP9124.tmp
2008-10-20 23:32 90,112 ----a-w c:\windows\DUMPa095.tmp
2008-10-17 22:38 --------- dc----w c:\program files\PDF Editeur 2
2008-10-12 22:47 90,112 ----a-w c:\windows\DUMP9de5.tmp
2008-10-09 21:12 --------- dc----w c:\program files\Labtec
2008-10-09 21:12 --------- dc----w c:\program files\Common Files\LogiShrd
2008-10-09 21:12 --------- dc----w c:\program files\Common Files\Labtec
2008-10-09 00:00 --------- dc----w c:\program files\NATATA eBook Compiler Gold
2008-10-08 23:43 --------- dc----w c:\program files\eBook Workshop
2008-10-07 14:59 --------- dc----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-09-23 20:34 32,768 -c-h--w c:\windows\system32\config\systemprofile\uvqoc.exe
2008-09-18 13:54 --------- dc----w c:\program files\SAMSUNG Corporation
2008-08-17 02:22 90,112 ----a-w c:\windows\DUMPe4b2.tmp
2008-08-11 01:03 90,112 ----a-w c:\windows\DUMP11be.tmp
2004-10-01 12:00 40,960 -c--a-w c:\program files\Uninstall_CDS.exe
2008-02-24 20:01 8,096 -csha-w c:\windows\system32\SiLeNtt\klog.dat
.
------- Sigcheck -------
2006-12-07 02:11 57856 ad3d9d191aea7b5445fe1d82ffbb4788 c:\windows\system32\spoolsv.exe
2006-12-07 02:12 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableLockWorkstation"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
"NoFind"= 0 (0x0)
"NoRun"= 0 (0x0)
"NoDesktop"= 0 (0x0)
"NoClose"= 0 (0x0)
"StartMenuLogOff"= 0 (0x0)
"HideClock"= 0 (0x0)
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCloseDragDropBands"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
"NoLogOff"= 0 (0x0)
"NoHelp"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoViewOnDrive"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Pinnacle PCTV Scheduler.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Pinnacle PCTV Scheduler.lnk
backup=c:\windows\pss\Pinnacle PCTV Scheduler.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SnagIt 8.lnk
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^crystal^Start Menu^Programs^Startup^Registration-PCTV Sat.lnk]
path=c:\documents and settings\crystal\Start Menu\Programs\Startup\Registration-PCTV Sat.lnk
backup=c:\windows\pss\Registration-PCTV Sat.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 08:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
--a--c--- 2004-03-10 13:26 406016 c:\windows\system32\PSDrvCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-02-16 07:54 282624 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
-----c--- 2004-11-02 17:24 32768 c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2007-09-24 23:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adiras]
--a--c--- 2005-05-03 12:57 143360 c:\windows\adiras.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autoclk]
--a--c--- 2005-07-21 10:34 143360 c:\windows\autoclk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\config\\systemprofile\\uvqoc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:@xpsp2res.dll,-22004
R2 UxTuneUp;TuneUp Design Expansion;c:\windows\System32\svchost.exe [2008-11-10 14336]
R3 pctvvbi;PCTVVBI;c:\windows\system32\DRIVERS\pctvvbi.sys [2002-11-11 6400]
R3 qcusbser;Mobile Connector USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\cmusbser.sys [2007-10-16 97408]
S2 DIG_TS;Pinnacle PCTV Sat TS;c:\windows\system32\DRIVERS\dig_ts.sys [2003-02-04 17664]
S2 DIG_V;Pinnacle PCTV Sat Analog;c:\windows\system32\drivers\dig_v.sys [2003-05-13 125568]
S3 ALI5261;ALi Based Ethernet NT Driver;c:\windows\system32\DRIVERS\ALI5261.SYS [2001-08-17 27678]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - f:\.\ShowModem.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d10d2b8d-385d-11dc-8d88-4d6564696130}]
\Shell\AutoRun\command - RavMon.exe
\Shell\explore\Command - RavMon.exe -e
\Shell\open\Command - RavMon.exe
*Newly Created Service* - HELPSVC
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A744F16C-B2D5-4138-81A2-085CDFCDE83A}]
rundll32 sxmg4.dll,InitModule
.
Contents of the 'Scheduled Tasks' folder
2008-11-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2006\SystemOptimizer.exe [2006-10-05 13:09]
2008-11-10 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-11-10 03:08]
2007-05-16 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-11-10 03:08]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-2cda6898 - c:\windows\system32\moefltss.dll
MSConfigStartUp-ASUS Probe - c:\program files\ASUS\Probe\AsusProb.exe
MSConfigStartUp-AVP - c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
MSConfigStartUp-BM2fe95b04 - c:\windows\system32\pdqbjrcq.dll
MSConfigStartUp-CursorXP - c:\program files\CursorXP\CursorXP.exe
MSConfigStartUp-GPLv3 - c:\windows\system32\ueyvxhro.dll
MSConfigStartUp-LBTWiz - c:\windows\LBTWiz.exe
MSConfigStartUp-Salestart - c:\program files\Common Files\DriveCleaner Free\dcsm.exe
MSConfigStartUp-SystemOptimizer - c:\windows\system32\wfhugyuh.dll
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\crystal\Application Data\Mozilla\Firefox\Profiles\wnv7ts8e.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.co.ma/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 11:59:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-11-10 12:09:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-10 12:08:52
Pre-Run: 422,121,472 bytes free
Post-Run: 229,806,080 bytes free
448
.....................