Merci de ton conseil mais je passais systematiquement un scan Bitdefender sur les fichiers telechargés et pas question d'extraire et d'executer si il trouvais qqchose...
voici mon rapport combofix :
ComboFix 09-07-23.02 - Olje 24/07/2009 7:34.2.4 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2248 [GMT 2:00]
Running from: c:\users\Olje\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.
2009-07-23 18:09 . 2009-07-24 05:42 -------- d-----w- c:\users\Olje\AppData\Local\temp
2009-07-23 17:35 . 2009-07-23 17:35 -------- d-----w- c:\program files\CCleaner
2009-07-22 14:36 . 2009-07-22 14:36 -------- d-----w- c:\users\Olje\AppData\Roaming\Malwarebytes
2009-07-22 14:36 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-22 14:36 . 2009-07-22 14:36 -------- d-----w- c:\programdata\Malwarebytes
2009-07-22 14:36 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-22 14:36 . 2009-07-22 14:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-21 04:24 . 2009-07-21 04:24 -------- d-----w- C:\rsit
2009-07-20 12:50 . 2009-07-20 12:50 -------- d-----w- c:\users\Olje\AppData\Roaming\Avira
2009-07-20 12:34 . 2009-07-20 12:34 -------- d-sh--w- c:\windows\system32\%APPDATA% <-- #!!! C'est normal ca ? !!!#
2009-07-20 12:27 . 2009-05-08 12:13 97608 ----a-w- c:\windows\system32\drivers\avfwot.sys
2009-07-20 12:27 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-20 12:27 . 2009-03-24 14:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-20 12:27 . 2009-02-24 11:06 69632 ----a-w- c:\windows\system32\drivers\avfwim.sys
2009-07-20 12:27 . 2009-07-20 12:27 -------- d-----w- c:\programdata\Avira
2009-07-20 12:27 . 2009-07-20 12:27 -------- d-----w- c:\program files\Avira
2009-07-19 23:00 . 2009-07-19 23:00 -------- d-----w- c:\programdata\NortonInstaller
2009-07-17 19:04 . 2009-07-17 19:05 -------- d-----w- c:\users\Olje\AppData\Local\ApplicationHistory
2009-07-17 19:04 . 2009-07-17 19:04 92 ----a-w- c:\users\Olje\AppData\Local\fusioncache.dat
2009-07-17 12:57 . 2009-07-17 12:57 -------- d-----w- c:\windows\system32\logs
2009-07-17 12:53 . 2009-07-17 12:53 -------- d-----w- c:\windows\system32\URTTEMP
2009-07-16 13:27 . 2009-07-16 13:27 -------- dc-h--w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}
2009-07-16 13:27 . 2009-07-08 17:28 2920112 -c--a-w- c:\programdata\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
2009-07-16 13:27 . 2009-07-16 13:27 -------- d-----w- c:\programdata\Lavasoft
2009-07-16 13:27 . 2009-07-16 13:27 -------- d-----w- c:\program files\Lavasoft
2009-07-16 11:15 . 2009-07-17 00:46 117760 ----a-w- c:\users\Olje\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-16 06:37 . 2009-07-16 06:37 -------- d-----w- C:\a8e8234397ec7c9628
2009-07-16 06:37 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-16 06:37 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-16 06:37 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-16 06:37 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-16 06:37 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-11 00:57 . 2009-07-11 00:57 -------- d-----w- c:\users\Default User
2009-07-08 00:34 . 2009-07-08 00:34 -------- d-----w- c:\users\Olje\AppData\Roaming\Jasc
2009-07-03 10:38 . 2009-07-03 10:38 -------- d-----w- c:\program files\LizardTech
2009-07-03 07:59 . 2009-07-03 07:59 -------- d-----w- c:\users\Olje\.vnc
2009-07-03 00:28 . 2009-07-03 00:28 -------- d-----w- c:\users\Olje\AppData\Local\AudioMulch 2.0
2009-07-03 00:26 . 2009-07-03 00:26 -------- d-----w- c:\program files\AudioMulch 2.0.1
2009-07-02 21:56 . 2008-09-17 18:39 139264 ----a-w- c:\users\Olje\AppData\Roaming\Thunderbird\Profiles\42jgw4ub.default\extensions\{e2fda1a4-762b-4020-b5ad-a41df1933103}\components\calbscmp.dll
2009-07-02 12:39 . 2009-07-12 20:13 -------- d-----w- c:\users\Olje\AppData\Roaming\Alien Skin
2009-07-02 12:32 . 2009-07-02 12:32 -------- d-----w- c:\program files\Alien Skin
2009-07-02 03:37 . 2008-06-12 07:46 4608 ----a-w- c:\windows\system32\drivers\vncmirror.sys
2009-07-02 03:37 . 2008-06-12 07:46 20992 ----a-w- c:\windows\system32\vncmirror.dll
2009-07-01 12:07 . 2009-07-01 12:07 -------- d-----w- c:\users\Olje\AppData\Roaming\Plogue
2009-07-01 11:55 . 2009-07-01 12:07 -------- d-----w- c:\users\Olje\AppData\Local\Songsmith
2009-07-01 02:58 . 2009-07-01 12:06 -------- d-----w- c:\program files\Songsmith
2009-06-28 14:51 . 2009-07-16 10:32 -------- d-----w- c:\programdata\ma-config.com
2009-06-28 14:51 . 2009-07-16 10:32 -------- d-----w- c:\program files\ma-config.com
2009-06-25 07:36 . 2009-06-25 07:36 -------- d-----w- c:\windows\system32\oodag
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 03:46 . 2008-07-28 23:01 681864 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-24 03:46 . 2008-07-28 23:01 129422 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-24 01:11 . 2008-10-02 18:25 -------- d-----w- c:\users\Olje\AppData\Roaming\VMware
2009-07-24 01:06 . 2008-10-02 18:20 -------- d-----w- c:\programdata\VMware
2009-07-23 17:39 . 2008-12-22 03:21 -------- d-----w- c:\users\Olje\AppData\Roaming\Skype
2009-07-23 17:39 . 2008-12-22 03:23 -------- d-----w- c:\users\Olje\AppData\Roaming\skypePM
2009-07-23 14:35 . 2009-02-02 00:06 1 ----a-w- c:\users\Olje\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-22 04:01 . 2009-06-07 07:15 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-21 04:55 . 2008-12-19 22:43 -------- d-----w- c:\users\Olje\AppData\Roaming\Azureus
2009-07-21 00:41 . 2008-09-30 21:51 -------- d-----w- c:\program files\foobar2000
2009-07-20 02:33 . 2008-11-29 08:30 -------- d-----w- c:\users\Olje\AppData\Roaming\dvdcss
2009-07-19 23:23 . 2008-12-27 23:40 -------- d-----w- c:\users\Olje\AppData\Roaming\FileZilla
2009-07-19 23:03 . 2008-09-28 18:28 -------- d-----w- c:\program files\BitDefender
2009-07-19 19:57 . 2008-09-30 22:44 -------- d-----w- c:\program files\Notepad++
2009-07-19 16:50 . 2008-10-12 03:47 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-07-18 04:01 . 2008-04-23 16:34 192512 ----a-w- c:\windows\system32\txmlutil.dll
2009-07-17 09:18 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-16 16:22 . 2008-09-27 04:19 -------- d-----r- c:\program files\!Goodies
2009-07-16 11:14 . 2008-10-14 00:01 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-15 09:09 . 2009-01-22 11:07 -------- d-----w- c:\program files\Troubleshooter
2009-07-11 19:54 . 2009-06-15 19:14 -------- d-----w- c:\program files\REAPER
2009-07-09 15:44 . 2009-01-05 11:17 -------- d-----w- c:\users\Olje\AppData\Roaming\REAPER
2009-07-09 15:23 . 2008-10-14 23:46 -------- d-----r- c:\program files\VstPlugins
2009-07-08 00:30 . 2008-12-01 01:57 -------- d-----w- c:\program files\Jasc Software Inc
2009-07-03 10:38 . 2008-07-28 13:31 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-02 21:56 . 2008-12-21 23:18 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-06-29 04:07 . 2009-06-29 04:07 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-06-28 11:40 . 2008-11-30 19:18 -------- d-----w- c:\programdata\MAGIX
2009-06-28 10:26 . 2008-11-30 19:21 -------- d-----w- c:\users\Olje\AppData\Roaming\MAGIX
2009-06-28 09:48 . 2009-01-15 00:04 -------- d-----w- c:\users\Olje\AppData\Roaming\Steady Recorder
2009-06-28 02:57 . 2008-10-07 19:43 -------- d-----r- c:\program files\!Portables
2009-06-28 02:52 . 2008-09-30 20:45 31 ----a-w- c:\windows\popcinfo.dat
2009-06-28 02:32 . 2009-01-28 18:49 -------- d-----r- c:\program files\TC UP
2009-06-23 00:20 . 2009-06-17 03:30 -------- d-----w- c:\program files\VeryPDF PDF Editor v2.2
2009-06-18 21:42 . 2009-06-18 21:40 -------- d-----w- c:\program files\Drumagog40
2009-06-18 21:40 . 2009-06-18 21:40 737280 ----a-w- c:\windows\iun6002.exe
2009-06-18 19:16 . 2009-06-18 19:13 -------- d-----w- c:\programdata\FirmTools
2009-06-18 19:13 . 2009-06-18 19:13 -------- d-----w- c:\program files\DuplicateFinder
2009-06-18 16:04 . 2009-06-18 16:04 -------- d-----w- c:\program files\Common Files\Steinberg
2009-06-18 16:04 . 2009-06-18 16:02 -------- d-----w- c:\users\Olje\AppData\Roaming\Steinberg
2009-06-17 03:32 . 2009-06-17 03:32 1024 ----a-w- c:\windows\system32\pdfeditor.dat
2009-06-16 09:08 . 2009-06-16 09:07 62464 ----a-w- c:\windows\system32\rdpclip.exe
2009-06-16 01:01 . 2008-10-05 22:56 -------- d-----w- c:\program files\K-Meleon
2009-06-15 22:44 . 2008-10-11 07:07 -------- d-----w- c:\program files\ASIO4ALL v2
2009-06-15 04:46 . 2008-10-07 19:23 -------- d-----w- c:\users\Olje\AppData\Roaming\Media Control
2009-06-14 23:17 . 2009-06-14 18:30 -------- d-----w- c:\programdata\Creative
2009-06-14 18:30 . 2009-06-14 18:30 -------- d-----w- c:\program files\Creative
2009-06-12 09:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-12 09:13 . 2006-11-02 12:37 -------- d-----r- c:\program files\Windows Sidebar
2009-06-12 09:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-12 09:13 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-12 09:12 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-12 09:05 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-12 00:02 . 2009-06-11 02:26 -------- d-----w- c:\program files\Small Basic
2009-06-11 20:22 . 2008-12-15 06:18 -------- d-----w- c:\program files\Ice Breaker
2009-06-11 20:22 . 2009-05-18 17:27 -------- d-----w- c:\program files\hMailServer
2009-06-11 20:18 . 2009-05-02 02:44 -------- d-----w- c:\program files\Participatory Culture Foundation
2009-06-08 21:09 . 2009-06-08 21:09 -------- d-----w- c:\program files\AudioToMIDI 3.30
2009-06-07 07:55 . 2009-06-07 07:51 -------- d-----w- c:\users\Olje\AppData\Roaming\Juce VST Host
2009-06-07 03:48 . 2008-10-02 18:20 -------- d-----r- c:\program files\VMware
2009-05-28 02:52 . 2009-02-12 21:38 -------- d-----w- c:\program files\Associate This
2009-05-27 23:09 . 2009-05-27 23:08 5568180 ----a-w- c:\program files\Universal Extractor.rar
2009-05-27 19:22 . 2008-09-26 17:38 68632 ----a-w- c:\users\Olje\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-27 12:37 . 2009-01-27 00:18 -------- d-----w- c:\users\Olje\AppData\Roaming\FileBoss
2009-05-26 11:19 . 2009-05-26 11:19 -------- d-----w- c:\program files\QuickTime
2009-05-09 05:50 . 2009-06-11 19:35 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-11 19:35 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-08 14:24 . 2009-05-08 14:24 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-05-08 14:24 . 2009-05-08 14:24 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-05-02 15:43 . 2009-05-02 15:43 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-05-02 15:43 . 2009-05-02 15:43 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-04-27 12:21 . 2009-05-08 14:24 17152 ----a-w- c:\windows\system32\authuitu.dll
2009-04-27 12:21 . 2009-05-08 14:24 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2008-11-06 00:50 . 2008-09-28 10:28 1820 ----a-w- c:\program files\operadef6.ini
2008-10-28 16:59 . 2008-10-28 16:59 8252 ----a-w- c:\program files\license.rtf
2008-10-28 16:59 . 2008-10-28 16:59 234215 ----a-w- c:\program files\english.lng
2008-10-28 16:45 . 2008-10-28 16:45 3704320 ----a-w- c:\program files\opera.dll
2008-10-28 16:45 . 2008-10-28 16:45 653419 ----a-w- c:\program files\encoding.bin
2008-10-28 16:45 . 2008-10-28 16:45 98816 ----a-w- c:\program files\opera.exe
2008-09-03 13:12 . 2008-09-03 13:12 8470 ----a-w- c:\program files\search.ini
2008-06-09 09:17 . 2008-06-09 09:17 301 ----a-w- c:\program files\c3nform.vxml
2008-05-05 08:51 . 2008-05-05 08:51 3873 ----a-w- c:\program files\lngcode.txt
2004-02-26 12:35 . 2004-02-26 12:35 7904 ----a-w- c:\program files\html40_entities.dtd
2005-05-13 16:12 . 2005-05-13 16:12 217073 --sha-r- c:\windows\meta4.exe
2005-10-24 10:13 . 2005-10-24 10:13 66560 --sha-r- c:\windows\MOTA113.exe
2007-05-19 22:08 . 2007-05-19 22:08 108 --sha-r- c:\windows\neoqaz2.dll
2005-10-13 20:27 . 2005-10-13 20:27 422400 --sha-r- c:\windows\x2.64.exe
2005-10-07 18:14 . 2005-10-07 18:14 308224 --sha-r- c:\windows\System32\avisynth.dll
2005-07-14 11:31 . 2005-07-14 11:31 27648 --sha-r- c:\windows\System32\AVSredirect.dll
2005-06-26 14:32 . 2005-06-26 14:32 616448 --sha-r- c:\windows\System32\cygwin1.dll
2005-06-21 21:37 . 2005-06-21 21:37 45568 --sha-r- c:\windows\System32\cygz.dll
2004-01-24 23:00 . 2004-01-24 23:00 70656 --sha-r- c:\windows\System32\i420vfw.dll
2006-04-27 09:24 . 2006-04-27 09:24 2945024 --sha-r- c:\windows\System32\Smab.dll
2005-02-28 12:16 . 2005-02-28 12:16 240128 --sha-r- c:\windows\System32\x.264.exe
2004-01-24 23:00 . 2004-01-24 23:00 70656 --sha-r- c:\windows\System32\yv12vfw.dll
2008-07-28 23:05 . 2008-07-28 23:05 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-07-23_18.23.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-26 17:05 . 2009-07-24 05:06 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-26 17:05 . 2009-07-23 18:11 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-09-26 17:05 . 2009-07-23 18:11 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-26 17:05 . 2009-07-24 05:06 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-26 17:05 . 2009-07-23 18:11 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-26 17:05 . 2009-07-24 05:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-23 18:11 . 2009-07-23 18:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-24 01:06 . 2009-07-24 01:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-07-23 18:11 . 2009-07-23 18:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-24 01:06 . 2009-07-24 01:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-07-24 03:46 598432 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-07-23 18:17 598432 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-07-23 18:17 106288 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-07-24 03:46 106288 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"USB Safely Remove"="c:\program files\!Goodies\USBSafelyRemove.exe" [2008-10-11 799744]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2007-10-08 72240]
"VMware hqtray"="c:\program files\VMware\VMware Workstation\hqtray.exe" [2007-10-08 55856]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912]
"VX1000"="c:\windows\vVX1000.exe" [2007-04-10 709992]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-02-13 6814240]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 92704]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Drive-Meter.lnk - c:\program files\!Goodies\Drive-Meter.exe [2008-10-8 685568]
PowerMenu.lnk - c:\program files\!Goodies\PowerMenu\PowerMenu.exe [2008-10-22 22016]
winroll.lnk - c:\program files\!Goodies\winroll.exe [2004-4-7 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-07-16 11:14 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-07-16 11:14 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=ma_cmidn.dll
"midi2"=ma_cmidn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):36,27,a9,c8,3e,eb,c9,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3893382906-3363802250-3863203260-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{0CEEF67B-2C01-4557-85CB-61CF6091454B}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{0C6EEE45-4261-4CA7-B0E3-C5B3156C243A}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{D2A48786-1D12-4F44-AAA5-CFFD5FC3A366}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{34E6A35B-F9EE-46AB-B2B6-0210E2067FF8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{B74F52C4-CCEC-4E7F-9B17-61C9E2300CCB}c:\\program files\\packard bell\\updator\\pbupdator.exe"= UDP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"UDP Query User{BE970A8C-9F96-4807-802E-2563B2B2DF63}c:\\program files\\packard bell\\updator\\pbupdator.exe"= TCP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"TCP Query User{0D81A6BB-C3AF-42E0-94D1-6AA8B13B4422}c:\\program files\\videolan\\vlc\\vlc.exe"= UDP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"UDP Query User{573E4A1A-0923-4B22-86BB-B930522243C6}c:\\program files\\videolan\\vlc\\vlc.exe"= TCP:c:\program files\videolan\vlc\vlc.exe:VLC media player
"{D12A2B4C-653D-4591-97A5-7B94345B66ED}"= UDP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"{290A493C-9607-410A-B605-E2203C407BCC}"= TCP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"{370CCF69-31C7-4DFE-B801-66128B0B70C9}"= UDP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{B873FD32-7A16-4209-ADC7-8078EE501761}"= TCP:c:\program files\Sierra\FEAR\FEARMP.exe:FEAR
"{99037253-8697-48A1-A365-D18FE3C91CEE}"= UDP:c:\program files\Sierra\FEAR Perseus Mandate\FEARXP2.exe:FEARXP2
"{66BB13E8-C9FF-431D-B718-9D918589FF6B}"= TCP:c:\program files\Sierra\FEAR Perseus Mandate\FEARXP2.exe:FEARXP2
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 PzWDM;PzWDM;c:\windows\System32\drivers\PzWDM.sys [07/10/2008 03:49 15172]
R1 avfwot;avfwot;c:\windows\System32\drivers\avfwot.sys [20/07/2009 14:27 97608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [03/09/2008 14:07 9968]
R1 VD_FileDisk;VD_FileDisk;c:\windows\System32\drivers\vd_filedisk.sys [13/01/2006 15:00 15872]
R2 AntiVirFirewallService;Avira Pare-feu;c:\program files\Avira\AntiVir Desktop\avfwsvc.exe [20/07/2009 14:27 388865]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\Avira\AntiVir Desktop\avmailc.exe [20/07/2009 14:27 194817]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [20/07/2009 14:27 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [20/07/2009 14:27 434945]
R2 AtomicAlarmClock;Atomic Alarm Clock Time;c:\program files\Atomic Alarm Clock\timeserv.exe [01/12/2008 03:15 414720]
R2 CoLinuxDriver;CoLinuxDriver;c:\portable_ubuntu\linux.sys [08/05/2009 02:20 68096]
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 04:23 21504]
R2 gearsec;gearsec;c:\windows\System32\gearsec.exe [01/12/2003 16:27 53248]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [08/05/2009 16:24 604416]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\System32\drivers\avfwim.sys [20/07/2009 14:27 69632]
S4 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [03/09/2008 14:07 7408]
S4 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [03/09/2008 14:07 55024]
--- Other Services/Drivers In Memory ---
*Deregistered* - PROCEXP113
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-23 c:\windows\Tasks\Extension de garantie-Olje.job
- c:\program files\Packard Bell\SetupmyPC\PBCarNot.exe [2008-07-28 10:13]
2009-07-24 c:\windows\Tasks\User_Feed_Synchronization-{3B6294E5-A486-450E-A2A2-3604A1A3D115}.job
- c:\windows\system32\msfeedssync.exe [2009-05-02 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Linkman - file://c:\program files\!Portables\Linkman\iescript_add.htm
IE: Add to Linkman (all tabs) - file://c:\program files\!Portables\Linkman\iescript_addall.htm
IE: Add to Linkman and Edit - file://c:\program files\!Portables\Linkman\iescript_edit.htm
IE: Ajouter cette page à la file d'attente de Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebidqueue.htm
IE: Ajouter à la file d'attente le lien ciblé - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm
IE: Ouvrir cette page avec Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebid.htm
IE: Ouvrir le lien ciblé avec Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebidlink.htm
IE: Show Linkman - file://c:\program files\!Portables\Linkman\iescript_show.htm
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
Trusted Zone: bitdefender.com\kb
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-24 07:42
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\users\Olje\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\InprocServer32]
@DACL=(02 0000)
@="c:\\lotus\\org6\\organize\\iehelper.dll"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\ProgID]
@DACL=(02 0000)
@="IEHlprObj.IEHlprObj.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\Programmable]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE7C3CF0-4B15-11D1-ABED-709549C10000}\VersionIndependentProgID]
@DACL=(02 0000)
@="IEHlprObj.IEHlprObj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj\CurVer]
@DACL=(02 0000)
@="IEHlprObj.IEHlprObj.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHlprObj.IEHlprObj.1\CLSID]
@DACL=(02 0000)
@="{CE7C3CF0-4B15-11D1-ABED-709549C10000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EncryptionInterface*]
"l_encryption_d"="585A4B584A5A"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System*]
"OODI01.00.00.01PRO"="31E570EC93BAE4FBDE44AA2B64C2111855D6E595EB863849D493A2059169DA0EDB814182C68C512A2CB507B626D3BA6394DEF2ECF6FAB7481A6C62246BC4770BDFB1053642A2936E6DAF2385A909BDBFBD592D427640BB5D9EF9A9BA34C7B4D6E120DDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14079DB7CE019D40AA5C8EDD5E5BE2F6E667F24BEF10864C38E1E6B0F952EE98FEBAA50D237BE1D9406E8D1FAAD85800120DEF560D910BD4450166DFE6F884B0DAC335F470A3D3F6F95BBA8EFD59C36804B575579C502344B14B1776B6B7A337C29322A4C5963F9CB949A09B2076390EAA7CE6C84BE322459EFBE1D4E2B4F6CDF986008211A7C78083CE1C51905276596BD408F8C8DCFD95EF021631F08BCDA506A6C547C59FB4699EB76D0ED4015BC7EDE5810ECABB4F084F04E59264CB9A06B1B84F02DABA72B59681B984710CEEEA1E8CE27E88775581AAD9E7D646F7F54C0BAFDC92C9A8905339DD07BAF3EE57E6AC579C164079F0FDB29095AEA58718E663B61031120E43C91BB5C38CEC9DE2778C8A83F3321FA88A5C674E1E9464E057512BF1653602622E92A1C0A8EEF98367F69C528D223BA5C9E0D3D37F276E55B6301EEB0DBC11692D3C70B09111DECB19E83925A95915B771BD7DCCFDF7F919309B54CFDBAF3AF909F425AD1E6F19F68120407DE325644ECDB3C2C31B24CA798278C9CED61F735593E07633F8A9E85FA922C5C1AC545880BAC832A62BCD1F6480E9A902561CA36538E7CDA1A16483883037903BC73E9309ABC412C8589AA3EB13DDD56489BF26B470344B3C69C59316C4EB1D16CB382BC327B4D9601DB37DC8B37F64557221CC744DB540AD78FA3551AD8F1964A622A8B4C66BB586CB484255F2C19F9766E15AF6F29F3381C7B1F7A6C3B6699C16DA0C80B97D06BA0A877D8FF3DA84D20FA307B51BE75EA7299F6226F4B92616AEC6C57041436160CE292E1B6CC5C292698C7F4C8F4A32F4BC7A6D8641331910584FBB74B35A0EBC66E546BE2ABFC24648C86279B2464FA1F97F06213E85432ACDE1499DFB2509F8747B2F658A4B1CC1D106C4A2F71F8D4A2C6E0C7097D3D76C216D3A21984603A5EA2B419D81AE9CBBFEF52ECEE7DB76EF720A579607863DBD3468D3591B28E13414BBCD1B9672C64F1E509BAA1F47C8F4BE1AAD585FC890EC3F49C8C3A9783D7A0CF516B3E3674FFDCFCFFB054C71762357E94E9E860CA02B4E8EC50300286034C4A752E39A1E20A80B333452352BA728D74AE877F483710DC039E6DC6AEB4DFE02232DC87C6DD598993C1CAAB18EB5912F8D231238283A8C4ACB403A4C3D385DDB3D4527616E43F698B2FE4AAE752F569F8C96C472356507F2CFD4AA9AD889B541CF2E63"
"OODEFRAG10.00.00.01WORKSTATION"="F347784FFBD7EE8193C92C57790449ED88ABFBEA9E74F804D60B006731ADE6A30CC4A0A2208A8BCFD2A388EB8AAC963BE69A00910C02E3D54B0F86096AD4CA7B5AB1C59B8470B1A5206B521C1A51F6B38C563B41DB6AABC0E5C9EC7E5574990B9CF05E711CD31DE7697C1463D9074E4FB153EDD59B2D78ED4CE8C922F995DF4A080AF7A48BE461828C55EE822A45D38A842B6CEF09A94488983D481594217D39C1A72FF62CB6E2E35E9B98FBA26811E4FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A9C6AECB7A5D14079DB7CE019D40AA5C8EDD5E5BE2F6E6679AE472394150BCBA02FE9D9EEA2C70E3EEF1CB5E1FAF20D2308497E57374761F27916EECB637BE58E6AF18EFF3D10B0621700642C733A941DE22F12685FC755F91B5D0862A9DE6A1EB1E1227A2067E0012522FFEE06DFE7E93560F923CA2769238D2B15F2BEB131D1B43B75FC4FE4E6B1CACAA93147C6653956D2427C10C24D46F913C178073745575C048F6DBD252E28AB9ECBEC2617C8B9D5AFD2371C20142FD3BB00E24E713D96F5A99131F80B5861F557E83FD8231785A33780F5B36E0FC9DC060EBC25E46BCEF7813187AE6F4F98F00FEAC1027C76EED3108B2C4396DAA0032B4993ED43D9454A5B0B489CA64E4045F1DC372FD58C6EDB2309A2700A175C549A6C62C29797B6A938355A0532BF219BC9F1BD599CDDC64B88D98ADA6518A07DFC7E4D59F511278942F2D460F43D260045F441DECE89250EA4EC0B8AB1E1B4E743A29385F6DF7B5A1EBB4356DFAB9DFC6C99A5F53BCCCA211336E5E7082DD1C2A348E8573CB57CE568627DA43F6DE8F39DF38E9883272419B13BCE5BCCA8B61C78354A34B3E576272DF025BC72CFCDCB4B7FC3A3084F0871A5A8DCB391762063885F9ABBAEAA98558E9898B996654A836790E054DC23A4244830641F55DA3E40B2EC8EB784CFE4013AFC5F636C2A8475EE2D331CAD0C13372A30FAAE4E615CDF10548E3A1AE0E8DCC4C7FDB83B6C102724579DA7667011123DF579FDB4F0103C5A4C7CA3334935F556FC82C4B07EA97DB85EF520012728678734D6D950634BC7F3C598A12D34B97A1DD721037CF74B6261E6A197EB01AB038ABA715B0D200233E8FD3BE06D5791048EF94E0D8FEB185821BE168E975F9224CEA604A2FCDBA58C677CFBAB8D8659305120AACA557789D471E132AA0EA1C6043273476F761BE6EFC5B2D04BBCDD8E1B8C4F2B7F4EE280B6BDCFCFEE36A0C654D6CA1B554D0686BEE3E0C5201FBA231E71BB0F603331DCE8D9F633B58A45A1FC1D6F1D7F3301A4BC9B1D4945F7B1427B8BE6C15F0DF3DDEED454FE4881D9DF09A1BABE1E8E63A7C5FDCAF6D943B85E077EB8FF1C2096E23F03D8DB8E1AC6C2F74FB1D8C2AB4B0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2404)
c:\program files\RocketDock\RocketDock.dll
c:\program files\!Goodies\PowerMenu\PowerMenuHook.dll
c:\program files\!Goodies\winroll.dll
c:\windows\system32\NetworkExplorer.dll
.
Completion time: 2009-07-24 7:45
ComboFix-quarantined-files.txt 2009-07-24 05:45
ComboFix2.txt 2009-07-24 04:35
Pre-Run: 131 189 637 120 octets libres
Post-Run: 131 151 708 160 octets libres
338 --- E O F --- 2009-07-24 04:14