This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all!
So its been 3 days that my antivirus always show me an alert for a trojan.
Here is the report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:22:08, on 02/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Users\BRYAN\AppData\Roaming\Adobe\Manager.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\cmd.exe
C:\Users\BRYAN\AppData\Local\Temp\vistasp1.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircdown.com/index.php?rvs=hompag&hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F3 - REG:win.ini: run=C:\Users\BRYAN\AppData\Roaming\Adobe\Manager.exe
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [braviax] C:\Windows\system32\braviax.exe
O4 - HKCU\..\Run: [lphcc15j0ej49] C:\Windows\system32\lphcc15j0ej49.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 7812 bytes


Thank you
Hi and welcome to the forums.

First, download FixIEDef by ShadowPuterDude to the Desktop.

Double-click FixIEDef.exe
Click OK on the disclaimer
Click on Scan! button to run the tool. (Vista will pop up a message stating that FixIEDef is running as Administrator, click OK).

WARNING: FixIEDef will kill all copies of Internet Explorer and Explorer that are running, during removal of malicious files. The icons and Start Menu on your Desktop will not be visible while FixIEDef is removing malicious files. This is necessary to remove parts of the infection that would otherwise not be removed.

Click Exit once FixIEDef displays the All Finished message.
A log will be created on your desktop. Please post the text from FixIEDef.log in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.
hello,
Thank you for you help!
Here is the report from FixIEDef :

********************************************************************************
* *
* FixIEDef Log *
* Version 1.5.3.6049 *
* *
********************************************************************************

Created at 08:09:47 on Sunday, August 03, 2008

Time Zone : (GMT-10:00) Hawaii

Logged On User : BRYAN

Operating System : Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
OS Version : 6.0.6001
System Langauge : French (Standard)
Keyboard Layout : French (Standard)
Processor : X86 Intel® Core™2 Duo CPU E6550 @ 2.33GHz

System Drive : C:\
Windows Directory : C:\Windows
System Directory : C:\Windows\system32

Total Physical Memory : 1046288 KB
Free Physical Memory : 415472 KB
Total Virtual Memory : 2097024 KB
Free Virtual Memory : 1996932 KB

Boot State : Normal boot

——————————————————————————–

!!! Files that have been deleted !!!

C:\Windows\system32\tbs.dll

——————————————————————————–

!!! Directories that have been removed !!!

No malicious directories to be removed

——————————————————————————–

!!! Registry entries that have been removed !!!

No malicious Registry entries found

================================================================================

All Done :)

ShadowPuterDude

Safe Surfing!!!

and the report from Malwarebytes' anti-Malware:

Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1020
Windows 6.0.6001 Service Pack 1

08:21:12 03/08/2008
mbam-log-8-3-2008 (08-21-12).txt

Type de recherche: Examen rapide
Eléments examinés: 37622
Temps écoulé: 3 minute(s), 21 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 28
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 5
Fichier(s) infecté(s): 18

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\coresrv.lfgax (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.lfgax.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b0cb585f-3271-4e42-88d9-ae5c9330d554} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.clientdetector (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.clientdetector.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.userprofiles (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.userprofiles.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\srv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\srv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcc15j0ej49 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\[removed] (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Run (Trojan.Agent) -> Data: c:\users\bryan\appdata\roaming\adobe\manager.exe -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\ProgramData\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\ProgramData\Secure Solutions\Antispyware 2008 XP (Rogue.Multiple) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\PCHealthCenter\0.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\Program Files\PCHealthCenter\4.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAau.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSAEula.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\ZangoSA\ZangoSA_kyf_update.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\ProgramData\Secure Solutions\Antispyware 2008 XP\as2008xp.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Users\BRYAN\AppData\Roaming\Adobe\Manager.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\BRYAN\AppData\Local\Temp\s1265.php (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\BRYAN\AppData\Local\Temp\vistasp1.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

And the HiJackThis report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:22:24, on 03/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircdown.com/index.php?rvs=hompag&hl;=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [braviax] C:\Windows\system32\braviax.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Download; by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab; video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload; selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load; all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter; vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 7425 bytes

That's all you ask me to do.
OK great, next step.

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Here is the new report of HiJackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:06:02, on 03/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Steam\Steam.exe
C:\Windows\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircdown.com/index.php?rvs=hompag&hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 6966 bytes


And the comfix's report:

ComboFix 08-07-23.5 - BRYAN 2008-08-03 8:47:19.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.1.1036.18.308 [GMT -10:00]
Endroit: C:\LapinuX dossier\ComboFix.exe
* Création d'un nouveau point de restauration
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\BRYAN\AppData\Roaming\WeatherDPA
C:\Users\BRYAN\AppData\Roaming\WeatherDPA\Weather\WeatherStartup.xml
C:\Users\BRYAN\AppData\Roaming\Zango

—– BITS: Possible sites infect‚s —–

http://195.225.176.25
http://hqvideoporn.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_iprip


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-03 to 2008-08-03 ))))))))))))))))))))))))))))))))))))
.

2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Users\BRYAN\AppData\Roaming\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Users\All Users\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\ProgramData\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-03 08:13 . 2008-07-30 20:15 38,472 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-08-03 08:13 . 2008-07-30 20:15 17,144 –a—— C:\Windows\System32\drivers\mbam.sys
2008-08-02 19:21 . 2008-08-02 19:21 d——– C:\Program Files\Trend Micro
2008-07-30 08:27 . 2008-07-30 08:27 d——– C:\Program Files\iPod
2008-07-22 20:30 . 2008-05-26 18:59 106,605 –a—— C:\Windows\System32\StructuredQuerySchema.bin
2008-07-22 20:30 . 2008-05-26 19:17 34,816 –a—— C:\Windows\System32\msscb.dll
2008-07-22 20:30 . 2008-05-26 18:59 18,904 –a—— C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-22 20:30 . 2008-05-26 19:17 11,776 –a—— C:\Windows\System32\msshooks.dll
2008-07-19 07:25 . 2008-07-19 07:25 dr——- C:\Windows\System32\config\systemprofile\Music
2008-07-11 11:15 . 2008-06-25 15:45 12,240,896 –a—— C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 11:15 . 2008-06-25 15:45 2,644,480 –a—— C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 11:15 . 2008-06-25 17:29 801,280 –a—— C:\Windows\System32\NaturalLanguage6.dll
2008-07-10 00:52 . 2008-07-10 00:52 d——– C:\Users\BRYAN\AppData\Roaming\dvdcss
2008-07-09 09:17 . 2008-07-09 09:17 d——– C:\Windows\SQL9_KB948109_ENU
2008-07-09 08:40 . 2008-04-25 22:25 3,600,952 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-07-09 08:40 . 2008-04-25 22:25 3,549,240 –a—— C:\Windows\System32\ntoskrnl.exe
2008-07-09 08:40 . 2008-04-25 22:26 891,448 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-07-09 08:40 . 2008-04-11 17:32 784,896 –a—— C:\Windows\System32\rpcrt4.dll
2008-07-09 08:40 . 2008-05-09 17:35 564,736 –a—— C:\Windows\System32\emdmgmt.dll
2008-07-09 08:40 . 2008-04-04 15:21 72,192 –a—— C:\Windows\System32\drivers\pacer.sys
2008-07-09 08:40 . 2008-04-04 17:34 15,360 –a—— C:\Windows\System32\pacerprf.dll
2008-07-09 08:33 . 2008-05-08 11:59 430,080 –a—— C:\Windows\System32\vbscript.dll
2008-07-09 08:33 . 2008-05-08 11:59 180,224 –a—— C:\Windows\System32\scrobj.dll
2008-07-09 08:33 . 2008-05-08 11:59 172,032 –a—— C:\Windows\System32\scrrun.dll
2008-07-09 08:33 . 2008-05-08 11:59 155,648 –a—— C:\Windows\System32\wscript.exe
2008-07-09 08:33 . 2008-05-08 11:58 135,168 –a—— C:\Windows\System32\wshom.ocx
2008-07-09 08:33 . 2008-05-08 11:58 135,168 –a—— C:\Windows\System32\cscript.exe
2008-07-09 08:33 . 2008-05-08 11:59 90,112 –a—— C:\Windows\System32\wshext.dll
2008-07-08 15:03 . 2008-07-08 15:03 22,328 –a—— C:\Windows\System32\drivers\PnkBstrK.sys
2008-07-08 15:03 . 2008-07-08 15:03 22,328 –a—— C:\Users\BRYAN\AppData\Roaming\PnkBstrK.sys
2008-07-08 15:02 . 2008-07-08 15:02 674,600 –a—— C:\Windows\System32\pbsvc.exe
2008-07-08 15:02 . 2008-07-08 15:02 103,736 –a—— C:\Windows\System32\PnkBstrB.exe
2008-07-08 15:02 . 2008-07-08 15:02 66,872 –a—— C:\Windows\System32\PnkBstrA.exe
2008-07-07 21:29 . 2008-07-07 21:30 d——– C:\Program Files\Capturino 1.4

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-03 18:55 ——— d—–w C:\Program Files\Steam
2008-08-03 13:29 ——— d—–w C:\Users\BRYAN\AppData\Roaming\LimeWire
2008-08-03 06:22 ——— d—–w C:\Users\BRYAN\AppData\Roaming\Skype
2008-08-03 05:58 ——— d—–w C:\Users\BRYAN\AppData\Roaming\skypePM
2008-08-02 06:25 ——— d—–w C:\Program Files\LimeWire
2008-08-01 16:53 ——— d—–w C:\Program Files\Common Files\Steam
2008-07-30 18:29 ——— d—–w C:\ProgramData\Apple Computer
2008-07-30 18:27 ——— d—–w C:\Program Files\iTunes
2008-07-30 18:23 ——— d—–w C:\Program Files\QuickTime
2008-07-19 14:36 51,280 —-a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-07-16 19:19 ——— d—–w C:\Program Files\Java
2008-07-09 19:20 ——— d—–w C:\ProgramData\Microsoft Help
2008-07-09 19:18 ——— d—–w C:\Program Files\Microsoft SQL Server
2008-07-09 19:17 ——— d—–w C:\Program Files\Windows Mail
2008-07-01 19:51 ——— d—–w C:\ProgramData\Nokia
2008-07-01 19:50 ——— d—–w C:\Program Files\Nokia
2008-07-01 19:47 ——— d—–w C:\Program Files\Common Files\Nokia
2008-07-01 19:46 ——— d—–w C:\ProgramData\Installations
2008-07-01 18:57 ——— d—–w C:\Users\BRYAN\AppData\Roaming\PC Suite
2008-07-01 18:57 ——— d—–w C:\ProgramData\PC Suite
2008-07-01 18:49 ——— d—–w C:\Program Files\Common Files\PCSuite
2008-07-01 18:45 ——— d—–w C:\ProgramData\Downloaded Installations
2008-06-28 18:21 ——— d—–w C:\Users\BRYAN\AppData\Roaming\Orbit
2008-06-19 05:26 0 —ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-19 04:37 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-18 11:45 174 –sha-w C:\Program Files\desktop.ini
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Sidebar
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Photo Gallery
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Defender
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Collaboration
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Calendar
2008-06-18 11:35 ——— d—–w C:\Program Files\Microsoft Games
2008-06-18 11:04 82,432 —-a-w C:\Windows\System32\axaltocm.dll
2008-06-18 11:04 101,888 —-a-w C:\Windows\System32\ifxcardm.dll
2008-06-18 10:48 ——— d—–w C:\Program Files\Skype
2008-06-17 22:28 56 —ha-w C:\Users\All Users\ezsidmv.dat
2008-06-17 22:28 56 —ha-w C:\ProgramData\ezsidmv.dat
2008-06-17 00:31 ——— d—–w C:\ProgramData\Skype
2008-06-17 00:31 ——— d—–w C:\Program Files\Common Files\Skype
2008-06-15 21:51 ——— d—–w C:\Program Files\doubleTwist
2008-06-15 21:38 ——— d—–w C:\Program Files\Xilisoft
2008-06-15 21:35 ——— d—–w C:\Program Files\WON
2008-06-15 07:22 ——— d—–w C:\Users\BRYAN\AppData\Roaming\uTorrent
2008-06-15 06:34 ——— d—–w C:\Users\BRYAN\AppData\Roaming\vlc
2008-06-15 06:32 ——— d—–w C:\Program Files\Common Files\Java
2008-06-15 06:22 ——— d—–w C:\Program Files\uTorrent
2008-06-15 06:03 ——— d—–w C:\Program Files\myFairTunes6
2008-06-14 18:47 ——— d—–w C:\Users\BRYAN\AppData\Roaming\GrabPro
2008-06-14 18:47 ——— d—–w C:\Program Files\Orbitdownloader
2008-06-14 04:50 ——— d—–w C:\Program Files\Apple Software Update
2008-06-03 05:45 ——— d—–w C:\Users\BRYAN\AppData\Roaming\InstallShield Installation Information
2008-06-03 05:27 ——— d—–w C:\Program Files\Unreal Tournament 3
2008-06-03 05:26 ——— d—–w C:\Program Files\AGEIA Technologies
2008-06-03 05:24 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-27 05:21 1,582,592 —-a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 —-a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 —-a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 —-a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 —-a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 —-a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 —-a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 —-a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 —-a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 —-a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 —-a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 —-a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 —-a-w C:\Windows\System32\chsbrkr.dll
2008-01-25 03:53 23,510,720 —-a-w C:\Users\BRYAN\dotnetfx.exe
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 21:33 1233920]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Steam"="c:\program files\steam\steam.exe" [2008-04-04 07:13 1271032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2008-01-18 21:33 227840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo"= lvfwwdmt.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\Windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-10 09:47 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-10 10:51 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 18:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSLauncher]
–a—— 2006-11-28 01:12 2658304 C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-28 06:43 8466432 C:\Windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-28 06:43 81920 C:\Windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
–a—— 2007-06-28 06:43 86016 C:\Windows\System32\nvsvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
–a—— 2007-03-12 10:22 517768 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSys2]
–a—— 2006-05-31 19:21 53248 C:\Windows\System32\startup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
–a—— 2008-01-18 21:33 202240 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5AAFD2FD-9380-4250-841C-33EBBB249570}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{49DBC63D-CC91-44EB-B0E1-0799FB446E2D}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= UDP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2
"UDP Query User{BDA1C94B-869D-4B0B-9341-E64D65A5BF02}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= TCP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2
"TCP Query User{24E52F16-EE66-400E-9621-08D22C8A22E8}C:\\windows\\system32\\rundll32.exe"= UDP:C:\windows\system32\rundll32.exe:Processus hôte Windows (Rundll32)
"UDP Query User{541DB971-7539-4A80-A6B5-7F453AAA31FB}C:\\windows\\system32\\rundll32.exe"= TCP:C:\windows\system32\rundll32.exe:Processus hôte Windows (Rundll32)
"TCP Query User{B4244364-8701-4564-A20E-A34AF09E4FBD}C:\\lapinux dossier\\jeux\\counter-strike\\cstrike.exe"= UDP:C:\lapinux dossier\jeux\counter-strike\cstrike.exe:CounterStrike Launcher
"UDP Query User{E0C93C2A-6071-4A64-BEDF-93BC69BC6A54}C:\\lapinux dossier\\jeux\\counter-strike\\cstrike.exe"= TCP:C:\lapinux dossier\jeux\counter-strike\cstrike.exe:CounterStrike Launcher
"{13562565-2A05-42D8-BDDB-F82E5975E872}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{E9CAA78E-052C-4042-BADD-17460A989386}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{E1A5E13C-3DDF-4B20-BE54-AD22A2FBC552}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{D8085194-2AB5-43D7-B45B-ECFC244AD744}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{51D1CE54-7F9D-4AB1-BB3F-6A187CB3186D}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{AA1FBCD5-AB25-48AC-B7D3-2450AFF23829}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{7E2906B0-43F3-4444-B0C3-669C63FE864E}C:\\program files\\steam\\steamapps\\lapin\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\lapin\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{585BE951-CCC1-4678-BA5A-838E36CDB6B6}C:\\program files\\steam\\steamapps\\lapin\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\lapin\counter-strike\hl.exe:Half-Life Launcher
"{BF557DCC-C257-48DF-B705-72B02647E23A}"= UDP:C:\LapinuX dossier\WLinstaller.exe:WLinstaller.exe
"{3F156A6E-6273-4692-B3F9-1B561C24567E}"= TCP:C:\LapinuX dossier\WLinstaller.exe:WLinstaller.exe
"{7E076820-19C7-40A3-A0BA-DB278ECCE09C}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{AE9B3018-67BB-45A9-B9AC-ECF06789096D}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{B39604BB-1BDD-46C3-AEAA-507C2AC1EC26}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8A9047A8-5DDC-4C6C-A6DB-24E3E5BEE62A}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5070FF3B-646C-403D-A7BD-68586AA82FB9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{2E1F5E14-97EE-4D87-8564-92E45924766C}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= UDP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2.exe
"UDP Query User{133D2B19-AC11-4B62-945F-8CD39481A4DD}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= TCP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2.exe
"TCP Query User{0A91A44B-B043-42E5-9388-39387871FDDF}C:\\program files\\steam\\steamapps\\ma_\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\ma_\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{23D78A8A-C918-46AD-B43E-D9B4FD1C3485}C:\\program files\\steam\\steamapps\\ma_\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\ma_\counter-strike\hl.exe:Half-Life Launcher
"{FF0562AE-10CB-428C-BA62-0200404B705C}"= UDP:C:\LapinuX dossier\GRF402TNB.exe:GRF402TNB.exe
"{C774BE6B-2054-4FAA-8AE3-7E1EF19AE57D}"= TCP:C:\LapinuX dossier\GRF402TNB.exe:GRF402TNB.exe
"{5A364E94-2C33-41E0-B6A4-C0016F7C0239}"= UDP:C:\LapinuX dossier\L2Pride\system\L2.exe:L2.exe
"{B9CC82C7-B092-4E9B-86DD-D5FF2B79F800}"= TCP:C:\LapinuX dossier\L2Pride\system\L2.exe:L2.exe
"TCP Query User{7A40D28E-CA02-41AF-8EB3-D5B187E21C30}C:\\program files\\steam\\steamapps\\lapin\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\lapin\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{5F427A03-3674-4A79-997F-DF93D9587D6F}C:\\program files\\steam\\steamapps\\lapin\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\lapin\counter-strike\hl.exe:Half-Life Launcher
"{A264B472-FA68-4D78-BCFC-4213A22C1CDD}"= UDP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{23C6D69B-5F2A-4846-8039-0744C406838F}"= TCP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"TCP Query User{2AFA6A0D-A953-4918-8420-15749CC846BF}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9EC3D601-63A4-4C1C-9DAB-12FB583805D5}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{1C9D6D54-5CB4-43E6-AD5A-98A461C35083}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent.exe
"UDP Query User{7DDFA6E2-EE36-42DF-B8B3-3026E8884048}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent.exe
"TCP Query User{BB6C8FBD-D32F-4255-9B96-E5303C2C43E2}C:\\program files\\steam\\steamapps\\ma_\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\ma_\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{FAC3A91C-01A7-47CD-8A2E-5087344B3C14}C:\\program files\\steam\\steamapps\\ma_\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\ma_\counter-strike\hl.exe:Half-Life Launcher
"{CBA4800A-8D5A-4ED5-9FE1-06361BA703CE}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"TCP Query User{E4B8D03D-05BE-4B58-A746-832C4219CC5E}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E0B1E914-0EAC-4D5A-9006-402F75FBE91B}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{BCEFED0A-6039-4469-86FA-7A9EF4962D6A}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"UDP Query User{DDF65D40-23AC-4B38-BD37-952290AB29B2}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"TCP Query User{C4A0E4C8-043C-4561-9DAB-B7403B16D283}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= UDP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"UDP Query User{B7D5C905-21A5-4087-932C-A0627AD3AAC3}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= TCP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"{D1F32A76-D74C-4C0C-97AD-1A8AE88A76B4}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{2C4249C0-4642-475B-8AD8-383EF2C47EE7}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{C4413CCF-EA9B-4FBF-B0F1-B8793CE8911B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{4C397290-EE0E-461F-9804-B109BF204405}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{2C78C0DC-C8B1-4307-AC8B-029B4B3B7F5C}C:\\program files\\steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"= UDP:C:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe:iw3mp.exe
"UDP Query User{AD20641B-6B9C-477B-B5D6-0F215E43B802}C:\\program files\\steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"= TCP:C:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe:iw3mp.exe
"TCP Query User{6833835F-8A98-41A0-AC5B-81E5742BCA4B}C:\\program files\\steam\\steamapps\\ma_\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\ma_\half-life\hl.exe:Half-Life Launcher
"UDP Query User{D042AC78-02FE-47BF-B725-0F43205A366E}C:\\program files\\steam\\steamapps\\ma_\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\ma_\half-life\hl.exe:Half-Life Launcher
"{3A164198-EE6B-41F3-9606-52B60F1BE6FE}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{ED720074-D907-46D8-BA2F-14B2569EA765}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"= C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"= C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 04:35]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 04:37]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 04:36]
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 09:46]
R3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-07-31 07:31]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 22:08]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
ipripsvc REG_MULTI_SZ iprip

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{442b0a2d-3e39-11dd-a27a-001a4d52f9d6}]
\shell\AutoRun\command - xn1i9x.com
\shell\explore\Command - xn1i9x.com
\shell\open\Command - xn1i9x.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d38e07a8-5f25-11dd-a01d-001a4d52f9d6}]
\shell\AutoRun\command - J:\RavMon.exe
\shell\explore\Command - J:\RavMon.exe -e
\shell\open\Command - J:\RavMon.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-08-03 19:00:32 C:\Windows\Tasks\User_Feed_Synchronization-{AB5D752F-D262-4A00-827B-A7CC28C3337B}.job"
- C:\Windows\system32\msfeedssync.exe
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.ircdown.com/index.php?rvs=hompag&hl=fr
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &Download by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 -: &Grab video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 -: Do&wnload selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 -: Down&load all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-03 08:55:28
Windows 6.0.6001 Service Pack 1 NTFS

Balayage processus cach‚s …

Balayage cach‚ autostart entries …

Balayage des fichiers cach‚s …

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Windows\System32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\System32\wbem\WMIADAP.exe
C:\Windows\System32\dllhost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-03 9:01:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-03 19:00:53

Pre-Run: 101,180,280,832 octets libres
Post-Run: 102,510,305,280 octets libres

324 — E O F — 2008-08-01 16:56:50
You can try that if you like but I would wait. That seems to be an older copy and that's not an "approved" download link. For some reason the tool may be offline for a bit. You may want to try in a couple hours and see if it's back. If you already ran the version you posted then go ahead and post the log.
hehehe :P Can i try to download the other version later if i already ran the one i have already ?
Hi, I have since discovered that combofix has been pulled due to some issues. I'm sure it will return soon. In the meantime, please describe how it's running.
Hi, On Avast not running any more….did you check to see if it has been disabled with msconfig? There are also some things we need to deal with using combofix. Go ahead and get rid of the version you ran and download a fresh copy. Run as instructed earlier and post the log. On Avast…is it the free version? If so we may need to just do a re-install after if we can't get it to work.
Yes it is the free version and in the msconfig i don't see avast in the startup menu only in the service menu and it is already check. I will post the new combofix's report later then reinstall avast.
Here are the new reports:
Combofix

ComboFix 08-08-11.01 - BRYAN 2008-08-11 21:07:10.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.1.1036.18.442 [GMT -10:00]
Endroit: C:\LapinuX dossier\ComboFix.exe
* Création d'un nouveau point de restauration
.

((((((((((((((((((((((((((((( Fichiers créés 2008-07-12 to 2008-08-12 ))))))))))))))))))))))))))))))))))))
.

2008-08-10 20:59 . 2008-08-10 22:49 d——– C:\Program Files\Lineage II
2008-08-10 20:53 . 2006-02-04 04:50 5,174 –a—— C:\Windows\System32\nppt9x.vxd
2008-08-10 20:53 . 2006-02-04 04:50 4,682 –a—— C:\Windows\System32\npptNT2.sys
2008-08-10 20:41 . 2008-08-10 22:49 d——– C:\Program Files\Lineage II CR
2008-08-10 20:41 . 2008-08-10 20:41 d–h—– C:\Program Files\InstallShield Installation Information
2008-08-10 20:40 . 2008-08-10 20:40 d——– C:\Users\BRYAN\AppData\Roaming\InstallShield
2008-08-08 21:11 . 2008-08-08 21:11 d——– C:\Program Files\ElcomSoft
2008-08-08 21:11 . 2008-08-08 23:14 1,371 –a—— C:\Windows\ARPR.INI
2008-08-08 20:55 . 2008-08-08 20:55 d——– C:\Program Files\RAR Password Cracker
2008-08-06 21:57 . 2008-08-06 21:57 d——– C:\Users\BRYAN\AppData\Roaming\SharePod
2008-08-05 21:48 . 2008-08-10 20:58 d——– C:\Users\BRYAN\AppData\Roaming\Free Download Manager
2008-08-05 21:48 . 2008-08-05 21:48 d——– C:\Users\All Users\FreeDownloadManager.ORG
2008-08-05 21:48 . 2008-08-05 21:48 d——– C:\ProgramData\FreeDownloadManager.ORG
2008-08-05 21:48 . 2008-08-05 21:48 d——– C:\Program Files\Free Download Manager
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Users\BRYAN\AppData\Roaming\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Users\All Users\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\ProgramData\Malwarebytes
2008-08-03 08:13 . 2008-08-03 08:13 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-03 08:13 . 2008-07-30 20:15 38,472 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-08-03 08:13 . 2008-07-30 20:15 17,144 –a—— C:\Windows\System32\drivers\mbam.sys
2008-08-02 19:21 . 2008-08-02 19:21 d——– C:\Program Files\Trend Micro
2008-07-30 08:27 . 2008-07-30 08:27 d——– C:\Program Files\iPod
2008-07-22 20:30 . 2008-05-26 18:59 106,605 –a—— C:\Windows\System32\StructuredQuerySchema.bin
2008-07-22 20:30 . 2008-05-26 19:17 34,816 –a—— C:\Windows\System32\msscb.dll
2008-07-22 20:30 . 2008-05-26 18:59 18,904 –a—— C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-22 20:30 . 2008-05-26 19:17 11,776 –a—— C:\Windows\System32\msshooks.dll
2008-07-19 07:25 . 2008-07-19 07:25 dr——- C:\Windows\System32\config\systemprofile\Music

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-12 07:07 786,432 –sha-w C:\Users\Invité\NTUSER.DAT
2008-08-12 07:07 786,432 –sha-w C:\Users\Invité\NTUSER.DAT
2008-08-12 02:46 ——— d—–w C:\Program Files\Steam
2008-08-06 07:40 ——— d—–w C:\Users\BRYAN\AppData\Roaming\LimeWire
2008-08-03 06:22 ——— d—–w C:\Users\BRYAN\AppData\Roaming\Skype
2008-08-03 05:58 ——— d—–w C:\Users\BRYAN\AppData\Roaming\skypePM
2008-08-02 06:25 ——— d—–w C:\Program Files\LimeWire
2008-08-01 16:53 ——— d—–w C:\Program Files\Common Files\Steam
2008-07-30 18:29 ——— d—–w C:\ProgramData\Apple Computer
2008-07-30 18:27 ——— d—–w C:\Program Files\iTunes
2008-07-30 18:23 ——— d—–w C:\Program Files\QuickTime
2008-07-19 14:36 51,280 —-a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-07-16 19:19 ——— d—–w C:\Program Files\Java
2008-07-10 10:52 ——— d—–w C:\Users\BRYAN\AppData\Roaming\dvdcss
2008-07-09 19:20 ——— d—–w C:\ProgramData\Microsoft Help
2008-07-09 19:18 ——— d—–w C:\Program Files\Microsoft SQL Server
2008-07-09 19:17 ——— d—–w C:\Program Files\Windows Mail
2008-07-09 01:03 22,328 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-07-09 01:03 22,328 —-a-w C:\Users\BRYAN\AppData\Roaming\PnkBstrK.sys
2008-07-09 01:02 674,600 —-a-w C:\Windows\System32\pbsvc.exe
2008-07-09 01:02 66,872 —-a-w C:\Windows\System32\PnkBstrA.exe
2008-07-09 01:02 103,736 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-07-08 07:30 ——— d—–w C:\Program Files\Capturino 1.4
2008-07-01 19:51 ——— d—–w C:\ProgramData\Nokia
2008-07-01 19:50 ——— d—–w C:\Program Files\Nokia
2008-07-01 19:47 ——— d—–w C:\Program Files\Common Files\Nokia
2008-07-01 19:46 ——— d—–w C:\ProgramData\Installations
2008-07-01 18:57 ——— d—–w C:\Users\BRYAN\AppData\Roaming\PC Suite
2008-07-01 18:57 ——— d—–w C:\ProgramData\PC Suite
2008-07-01 18:49 ——— d—–w C:\Program Files\Common Files\PCSuite
2008-07-01 18:45 ——— d—–w C:\ProgramData\Downloaded Installations
2008-06-28 18:21 ——— d—–w C:\Users\BRYAN\AppData\Roaming\Orbit
2008-06-26 03:29 801,280 —-a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 —-a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 —-a-w C:\Windows\System32\NlsLexicons0007.dll
2008-06-19 05:26 0 —ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-19 04:37 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-18 11:45 174 –sha-w C:\Program Files\desktop.ini
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Sidebar
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Photo Gallery
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Defender
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Collaboration
2008-06-18 11:36 ——— d—–w C:\Program Files\Windows Calendar
2008-06-18 11:35 ——— d—–w C:\Program Files\Microsoft Games
2008-06-18 11:04 82,432 —-a-w C:\Windows\System32\axaltocm.dll
2008-06-18 11:04 101,888 —-a-w C:\Windows\System32\ifxcardm.dll
2008-06-18 10:48 ——— d—–w C:\Program Files\Skype
2008-06-17 22:28 56 —ha-w C:\Users\All Users\ezsidmv.dat
2008-06-17 22:28 56 —ha-w C:\ProgramData\ezsidmv.dat
2008-06-17 00:31 ——— d—–w C:\ProgramData\Skype
2008-06-17 00:31 ——— d—–w C:\Program Files\Common Files\Skype
2008-06-15 21:51 ——— d—–w C:\Program Files\doubleTwist
2008-06-15 21:38 ——— d—–w C:\Program Files\Xilisoft
2008-06-15 21:35 ——— d—–w C:\Program Files\WON
2008-06-15 07:22 ——— d—–w C:\Users\BRYAN\AppData\Roaming\uTorrent
2008-06-15 06:34 ——— d—–w C:\Users\BRYAN\AppData\Roaming\vlc
2008-06-15 06:32 ——— d—–w C:\Program Files\Common Files\Java
2008-06-15 06:22 ——— d—–w C:\Program Files\uTorrent
2008-06-15 06:03 ——— d—–w C:\Program Files\myFairTunes6
2008-06-14 18:47 ——— d—–w C:\Users\BRYAN\AppData\Roaming\GrabPro
2008-06-14 18:47 ——— d—–w C:\Program Files\Orbitdownloader
2008-06-14 04:50 ——— d—–w C:\Program Files\Apple Software Update
2008-05-27 05:21 1,582,592 —-a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 —-a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 —-a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 —-a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 —-a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 —-a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 —-a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 —-a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 —-a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 —-a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 —-a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 —-a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 —-a-w C:\Windows\System32\chsbrkr.dll
2008-01-25 03:53 23,510,720 —-a-w C:\Users\BRYAN\dotnetfx.exe
.

((((((((((((((((((((((((((((( snapshot@2008-08-03_ 9.00.06.16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-03 18:53:34 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-08-12 02:45:50 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-08-03 18:53:34 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-08-12 02:45:50 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-08-03 18:55:17 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-12 02:47:21 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-12 02:47:21 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-08-03 18:55:14 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-12 02:47:26 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-12 02:47:26 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-03 18:53:57 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-08-12 06:46:46 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-08-03 18:53:57 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-12 06:46:46 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-03 18:53:57 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-08-12 06:46:46 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-08-03 18:47:14 262,144 —-a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-08-12 07:07:04 262,144 —-a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-06-18 11:40:03 371,200 —-a-w C:\Windows\System32\FNTCACHE.DAT
+ 2008-08-12 02:13:09 371,224 —-a-w C:\Windows\System32\FNTCACHE.DAT
- 2008-08-03 17:38:42 125,800 —-a-w C:\Windows\System32\perfc009.dat
+ 2008-08-12 04:23:25 125,800 —-a-w C:\Windows\System32\perfc009.dat
- 2008-08-03 17:38:42 155,666 —-a-w C:\Windows\System32\perfc00C.dat
+ 2008-08-12 04:23:25 155,666 —-a-w C:\Windows\System32\perfc00C.dat
- 2008-08-03 17:38:42 661,612 —-a-w C:\Windows\System32\perfh009.dat
+ 2008-08-12 04:23:25 661,612 —-a-w C:\Windows\System32\perfh009.dat
- 2008-08-03 17:38:42 756,770 —-a-w C:\Windows\System32\perfh00C.dat
+ 2008-08-12 04:23:25 756,770 —-a-w C:\Windows\System32\perfh00C.dat
- 2008-07-23 07:59:15 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-08-12 02:12:16 6,291,456 —-a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2008-08-03 17:53:03 12,866 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2491772059-1121666233-4043940238-1003_UserData.bin
+ 2008-08-12 02:47:42 13,042 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2491772059-1121666233-4043940238-1003_UserData.bin
- 2008-08-03 17:53:02 72,620 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-12 02:47:42 72,714 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-03 18:56:46 46,490 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-12 02:47:41 47,460 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-08-03 05:15:38 251,336 —-a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2008-08-12 04:22:10 253,272 —-a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
- 2008-07-23 06:30:53 107,119,566 —-a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-08-11 06:59:54 107,121,897 —-a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-08-11 06:59:49 65,536 —-a-w C:\Windows\winsxs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e5070
87\vcomp.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-18 21:33 1233920]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"Steam"="c:\program files\steam\steam.exe" [2008-04-04 07:13 1271032]
"Ad Muncher"="C:\Users\BRYAN\Documents\Mes fichiers reçus\AdMuncher\AdMunch.exe" [2006-03-14 11:09 7168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2008-01-18 21:33 227840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo"= lvfwwdmt.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=C:\Windows\pss\WinZip Quick Pick.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
–a—— 2008-07-10 09:47 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-10 10:51 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-09 18:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSLauncher]
–a—— 2006-11-28 01:12 2658304 C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-06-28 06:43 8466432 C:\Windows\System32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-06-28 06:43 81920 C:\Windows\System32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
–a—— 2007-06-28 06:43 86016 C:\Windows\System32\nvsvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
–a—— 2007-03-12 10:22 517768 C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSys2]
–a—— 2006-05-31 19:21 53248 C:\Windows\System32\startup.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
–a—— 2008-01-18 21:33 202240 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5AAFD2FD-9380-4250-841C-33EBBB249570}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{49DBC63D-CC91-44EB-B0E1-0799FB446E2D}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= UDP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2
"UDP Query User{BDA1C94B-869D-4B0B-9341-E64D65A5BF02}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= TCP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2
"TCP Query User{24E52F16-EE66-400E-9621-08D22C8A22E8}C:\\windows\\system32\\rundll32.exe"= UDP:C:\windows\system32\rundll32.exe:Processus hôte Windows (Rundll32)
"UDP Query User{541DB971-7539-4A80-A6B5-7F453AAA31FB}C:\\windows\\system32\\rundll32.exe"= TCP:C:\windows\system32\rundll32.exe:Processus hôte Windows (Rundll32)
"TCP Query User{B4244364-8701-4564-A20E-A34AF09E4FBD}C:\\lapinux dossier\\jeux\\counter-strike\\cstrike.exe"= UDP:C:\lapinux dossier\jeux\counter-strike\cstrike.exe:CounterStrike Launcher
"UDP Query User{E0C93C2A-6071-4A64-BEDF-93BC69BC6A54}C:\\lapinux dossier\\jeux\\counter-strike\\cstrike.exe"= TCP:C:\lapinux dossier\jeux\counter-strike\cstrike.exe:CounterStrike Launcher
"{13562565-2A05-42D8-BDDB-F82E5975E872}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{E9CAA78E-052C-4042-BADD-17460A989386}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{E1A5E13C-3DDF-4B20-BE54-AD22A2FBC552}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{D8085194-2AB5-43D7-B45B-ECFC244AD744}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{51D1CE54-7F9D-4AB1-BB3F-6A187CB3186D}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{AA1FBCD5-AB25-48AC-B7D3-2450AFF23829}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{7E2906B0-43F3-4444-B0C3-669C63FE864E}C:\\program files\\steam\\steamapps\\lapinux\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\lapinux\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{585BE951-CCC1-4678-BA5A-838E36CDB6B6}C:\\program files\\steam\\steamapps\\lapinux\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\lapinux\counter-strike\hl.exe:Half-Life Launcher
"{BF557DCC-C257-48DF-B705-72B02647E23A}"= UDP:C:\LapinuX dossier\WLinstaller.exe:WLinstaller.exe
"{3F156A6E-6273-4692-B3F9-1B561C24567E}"= TCP:C:\LapinuX dossier\WLinstaller.exe:WLinstaller.exe
"{7E076820-19C7-40A3-A0BA-DB278ECCE09C}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{AE9B3018-67BB-45A9-B9AC-ECF06789096D}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{B39604BB-1BDD-46C3-AEAA-507C2AC1EC26}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8A9047A8-5DDC-4C6C-A6DB-24E3E5BEE62A}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{5070FF3B-646C-403D-A7BD-68586AA82FB9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{2E1F5E14-97EE-4D87-8564-92E45924766C}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= UDP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2.exe
"UDP Query User{133D2B19-AC11-4B62-945F-8CD39481A4DD}C:\\lapinux dossier\\jeux\\counter strike source\\hl2.exe"= TCP:C:\lapinux dossier\jeux\counter strike source\hl2.exe:hl2.exe
"TCP Query User{0A91A44B-B043-42E5-9388-39387871FDDF}C:\\program files\\steam\\steamapps\\mars_\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\mars_\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{23D78A8A-C918-46AD-B43E-D9B4FD1C3485}C:\\program files\\steam\\steamapps\\mars_\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\mars_\counter-strike\hl.exe:Half-Life Launcher
"{FF0562AE-10CB-428C-BA62-0200404B705C}"= UDP:C:\LapinuX dossier\GRF402TNB.exe:GRF402TNB.exe
"{C774BE6B-2054-4FAA-8AE3-7E1EF19AE57D}"= TCP:C:\LapinuX dossier\GRF402TNB.exe:GRF402TNB.exe
"{5A364E94-2C33-41E0-B6A4-C0016F7C0239}"= UDP:C:\LapinuX dossier\L2Pride\system\L2.exe:L2.exe
"{B9CC82C7-B092-4E9B-86DD-D5FF2B79F800}"= TCP:C:\LapinuX dossier\L2Pride\system\L2.exe:L2.exe
"TCP Query User{7A40D28E-CA02-41AF-8EB3-D5B187E21C30}C:\\program files\\steam\\steamapps\\lapinux\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\lapinux\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{5F427A03-3674-4A79-997F-DF93D9587D6F}C:\\program files\\steam\\steamapps\\lapinux\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\lapinux\counter-strike\hl.exe:Half-Life Launcher
"{A264B472-FA68-4D78-BCFC-4213A22C1CDD}"= UDP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{23C6D69B-5F2A-4846-8039-0744C406838F}"= TCP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"TCP Query User{2AFA6A0D-A953-4918-8420-15749CC846BF}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{9EC3D601-63A4-4C1C-9DAB-12FB583805D5}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{1C9D6D54-5CB4-43E6-AD5A-98A461C35083}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent.exe
"UDP Query User{7DDFA6E2-EE36-42DF-B8B3-3026E8884048}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent.exe
"TCP Query User{BB6C8FBD-D32F-4255-9B96-E5303C2C43E2}C:\\program files\\steam\\steamapps\\mars_\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\mars_\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{FAC3A91C-01A7-47CD-8A2E-5087344B3C14}C:\\program files\\steam\\steamapps\\mars_\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\mars_\counter-strike\hl.exe:Half-Life Launcher
"{CBA4800A-8D5A-4ED5-9FE1-06361BA703CE}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"TCP Query User{E4B8D03D-05BE-4B58-A746-832C4219CC5E}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{E0B1E914-0EAC-4D5A-9006-402F75FBE91B}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{BCEFED0A-6039-4469-86FA-7A9EF4962D6A}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= UDP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"UDP Query User{DDF65D40-23AC-4B38-BD37-952290AB29B2}C:\\program files\\common files\\nokia\\service layer\\a\\nsl_host_process.exe"= TCP:C:\program files\common files\nokia\service layer\a\nsl_host_process.exe:Nokia Service Layer Host Process
"TCP Query User{C4A0E4C8-043C-4561-9DAB-B7403B16D283}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= UDP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"UDP Query User{B7D5C905-21A5-4087-932C-A0627AD3AAC3}C:\\program files\\nokia\\nokia software updater\\nsu_ui_client.exe"= TCP:C:\program files\nokia\nokia software updater\nsu_ui_client.exe:Nokia Software Updater
"{D1F32A76-D74C-4C0C-97AD-1A8AE88A76B4}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{2C4249C0-4642-475B-8AD8-383EF2C47EE7}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{C4413CCF-EA9B-4FBF-B0F1-B8793CE8911B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{4C397290-EE0E-461F-9804-B109BF204405}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{2C78C0DC-C8B1-4307-AC8B-029B4B3B7F5C}C:\\program files\\steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"= UDP:C:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe:iw3mp.exe
"UDP Query User{AD20641B-6B9C-477B-B5D6-0F215E43B802}C:\\program files\\steam\\steamapps\\common\\call of duty 4\\iw3mp.exe"= TCP:C:\program files\steam\steamapps\common\call of duty 4\iw3mp.exe:iw3mp.exe
"TCP Query User{6833835F-8A98-41A0-AC5B-81E5742BCA4B}C:\\program files\\steam\\steamapps\\mars_\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\mars_\half-life\hl.exe:Half-Life Launcher
"UDP Query User{D042AC78-02FE-47BF-B725-0F43205A366E}C:\\program files\\steam\\steamapps\\mars_\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\mars_\half-life\hl.exe:Half-Life Launcher
"{3A164198-EE6B-41F3-9606-52B60F1BE6FE}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{ED720074-D907-46D8-BA2F-14B2569EA765}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{1A742640-E32A-4B30-B847-F59E0F6FE500}C:\\users\\bryan\\documents\\mes fichiers reçus\\admuncher\\admunch.exe"= UDP:C:\users\bryan\documents\mes fichiers reçus\admuncher\admunch.exe:admunch.exe
"UDP Query User{D755624F-88A2-4193-9BC7-4EE36C84A860}C:\\users\\bryan\\documents\\mes fichiers reçus\\admuncher\\admunch.exe"= TCP:C:\users\bryan\documents\mes fichiers reçus\admuncher\admunch.exe:admunch.exe
"TCP Query User{1C86807B-A1E5-4B9B-9895-AB80C19B0439}C:\\program files\\free download manager\\fdm.exe"= UDP:C:\program files\free download manager\fdm.exe:Free Download Manager
"UDP Query User{37E94858-2C6B-4042-9A07-A0A28643AF3F}C:\\program files\\free download manager\\fdm.exe"= TCP:C:\program files\free download manager\fdm.exe:Free Download Manager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"= C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"= C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-07-19 04:35]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 04:37]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 04:36]
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-16 09:46]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-02-26 22:08]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-07-31 07:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
ipripsvc REG_MULTI_SZ iprip

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\AutoRun\command - J:\RavMon.exe
\shell\explore\Command - J:\RavMon.exe -e
\shell\open\Command - J:\RavMon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{442b0a2d-3e39-11dd-a27a-001a4d52f9d6}]
\shell\AutoRun\command - xn1i9x.com
\shell\explore\Command - xn1i9x.com
\shell\open\Command - xn1i9x.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d38e07a8-5f25-11dd-a01d-001a4d52f9d6}]
\shell\AutoRun\command - J:\RavMon.exe
\shell\explore\Command - J:\RavMon.exe -e
\shell\open\Command - J:\RavMon.exe

*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

2008-08-12 C:\Windows\Tasks\User_Feed_Synchronization-{AB5D752F-D262-4A00-827B-A7CC28C3337B}.job
- C:\Windows\system32\msfeedssync.exe [2008-01-18 21:33]
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Users\BRYAN\AppData\Roaming\Mozilla\Firefox\Profiles\427e4an6.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npclntax_ZangoSA.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-11 21:11:41
Windows 6.0.6001 Service Pack 1 NTFS

Balayage processus cachés …

Balayage caché autostart entries …

Balayage des fichiers cachés …

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-08-11 21:13:18
ComboFix-quarantined-files.txt 2008-08-12 07:13:02

Pre-Run: 86,829,088,768 octets libres
Post-Run: 86,837,571,584 octets libres

341 — E O F — 2008-08-08 03:26:06


HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:27:41, on 11/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ircdown.com/index.php?rvs=hompag&hl=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Ad Muncher] C:\Users\BRYAN\Documents\Mes fichiers reçus\AdMuncher\AdMunch.exe /bt
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 7554 bytes
Hi,

Couple of questions…

What is your "J:" drive? Is it a USB drive?

It looks like you still also have Symantec/Norton installed, just disabled with msconfig. Do you plan on keeping it? If not then I would just uninstall it using Add or Remove Programs.

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI