Pour fusionner:
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
_______________
telecharge combofix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !
_________________
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
Collect::
c:\windows\system32\kbiwkmsetqkfes.dat
c:\windows\system32\kbiwkmbydknnmm.dll
c:\windows\system32\drivers\kbiwkmqlsuxwcm.sys
c:\windows\system32\kbiwkmbocinvxa.dat
c:\windows\system32\kbiwkmfnevqbvm.dll
Driver::
kbiwkmqlsuxwcm
File::
c:\windows\system32\kbiwkmsetqkfes.dat
c:\windows\system32\kbiwkmbydknnmm.dll
c:\windows\system32\drivers\kbiwkmqlsuxwcm.sys
c:\windows\system32\kbiwkmbocinvxa.dat
c:\windows\system32\kbiwkmfnevqbvm.dll
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Run by bob at 2009-08-16 23:29:05
Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
System drive C: has 51 GB (71%) free of 71 GB
Total RAM: 2047 MB (65% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:29:21, on 16/08/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\bob\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\bob.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cooxer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: a-squared Free Service a2freeAcerMemUsageCheckService (a2freeAcerMemUsageCheckService) - Unknown owner - C:\Windows\TEMP\kripibsvwa.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Acer\Empowering Technology\eMode\PCM\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.2047.1295 [GMT 1:00]
Running from: c:\users\bob\Desktop\ComboFix.exe
Command switches used :: c:\users\bob\Desktop\cfscript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-07-17 to 2009-08-17 )))))))))))))))))))))))))))))))
.
2009-08-17 18:32 . 2009-08-17 18:32 -------- d-----w- c:\users\bob\AppData\Local\temp
2009-08-17 18:32 . 2009-08-17 18:32 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-08-17 18:32 . 2009-08-17 18:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-17 11:31 . 2009-08-17 18:13 117760 ----a-w- c:\users\bob\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-17 11:30 . 2009-08-17 11:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-08-17 11:30 . 2009-08-17 11:30 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-17 11:30 . 2009-08-17 11:30 -------- d-----w- c:\users\bob\AppData\Roaming\SUPERAntiSpyware.com
2009-08-17 11:30 . 2009-08-17 11:30 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-16 22:29 . 2009-08-16 22:32 -------- d-----w- C:\rsit
2009-08-15 00:35 . 2009-08-15 00:35 91 ----a-w- c:\windows\system32\kbiwkmsetqkfes.dat
2009-08-15 00:25 . 2009-08-17 18:25 19968 ----a-w- c:\windows\system32\kbiwkmbydknnmm.dll
2009-08-15 00:24 . 2009-08-17 18:25 42496 ----a-w- c:\windows\system32\kbiwkmfnevqbvm.dll
2009-08-15 00:24 . 2009-08-15 01:26 68608 ------w- c:\windows\system32\drivers\kbiwkmqlsuxwcm.sys
2009-08-15 00:24 . 2009-08-15 00:40 1528 ----a-w- c:\windows\system32\kbiwkmbocinvxa.dat
2009-08-12 16:19 . 2009-08-15 01:15 -------- d-----w- c:\users\bob\.thumbnails
2009-08-12 15:25 . 2009-05-11 11:15 251392 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstfaad.dll
2009-08-12 15:25 . 2009-05-11 11:13 32256 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstmms.dll
2009-08-12 15:25 . 2009-05-11 11:13 51200 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgsta52dec.dll
2009-08-12 15:25 . 2009-05-11 11:13 90112 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstmpeg2dec.dll
2009-08-12 15:25 . 2009-05-11 15:12 5297152 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstffmpeg.dll
2009-08-12 15:25 . 2009-05-11 11:14 155648 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstdtsdec.dll
2009-08-12 15:25 . 2009-05-11 11:11 187392 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstmad.dll
2009-08-12 15:25 . 2009-05-11 11:09 42496 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_ffmpeg-0.1.99-py2.5.egg-tmp\elisa\plugins\ffmpeg\gstreamer\libgstmpegaudioparse.dll
2009-08-12 15:23 . 2009-08-13 17:04 -------- d-----w- c:\program files\Moovida
2009-08-11 23:00 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-11 23:00 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-11 23:00 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-11 23:00 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-11 23:00 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-11 23:00 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-11 23:00 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-11 23:00 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-11 21:09 . 2009-08-13 09:42 -------- d-----w- c:\users\bob\AppData\Local\PowerCinema
2009-08-11 00:06 . 2009-08-12 15:39 76488 ----a-w- c:\users\bob\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-10 09:24 . 2009-08-10 09:47 -------- d-----w- c:\users\bob\AppData\Roaming\Broad Intelligence
2009-08-10 09:23 . 2009-08-10 09:23 12588752 ----a-w- c:\users\bob\AppData\Roaming\OpenCandy\pal_install_r83037.exe
2009-08-10 09:23 . 2009-08-10 09:23 -------- d-----w- c:\users\bob\AppData\Roaming\OpenCandy
2009-08-10 09:22 . 2009-08-10 09:47 -------- d-----w- c:\program files\MediaCoder
2009-08-06 09:54 . 2009-08-06 09:54 -------- d-----w- c:\users\bob\AppData\Local\Mozilla
2009-07-27 16:10 . 2009-07-27 16:10 -------- d-----w- c:\users\bob\AppData\Roaming\Talkback
2009-07-21 15:52 . 2009-07-21 15:52 -------- d-----w- c:\users\bob\AppData\Roaming\GRETECH
2009-07-19 14:41 . 2009-07-19 14:41 -------- d-----w- c:\users\bob\AppData\Roaming\Media Player Classic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 14:27 . 2009-02-26 21:48 -------- d-----w- c:\program files\a-squared Free
2009-08-16 17:25 . 2009-05-20 15:57 -------- d-----w- c:\program files\Glary Utilities
2009-08-16 17:25 . 2008-05-05 20:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-08-13 16:00 . 2009-08-12 15:24 -------- d-----w- c:\users\bob\AppData\Roaming\Python-Eggs
2009-08-13 15:08 . 2009-04-13 14:32 -------- d-----w- c:\programdata\Lavasoft
2009-08-13 10:18 . 2009-05-02 16:16 -------- d-----w- c:\programdata\PC Suite
2009-08-12 09:11 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-10 18:31 . 2008-02-19 19:39 -------- d-----w- c:\users\bob\AppData\Roaming\CyberLink
2009-08-09 10:04 . 2008-12-08 16:44 -------- d-----w- c:\users\bob\AppData\Roaming\OpenOffice.org
2009-08-09 00:28 . 2006-11-02 15:45 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-09 00:28 . 2006-11-02 15:45 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-08 11:54 . 2008-06-06 09:41 -------- d-----w- c:\users\bob\AppData\Roaming\Nokia
2009-08-08 11:33 . 2009-08-08 11:33 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2009-08-08 11:30 . 2008-06-06 09:37 -------- d-----w- c:\programdata\Installations
2009-08-06 15:52 . 2009-07-15 08:40 -------- d-----w- c:\program files\PC Health Optimizer Free Edition
2009-08-03 12:36 . 2009-05-29 11:52 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 12:36 . 2009-02-18 00:33 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 01:26 . 2009-02-18 00:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-31 14:39 . 2008-05-05 20:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-25 11:16 . 2009-06-02 10:38 -------- dc-h--w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-07-21 15:52 . 2009-07-14 00:06 -------- d-----w- c:\program files\GRETECH
2009-07-18 16:06 . 2009-07-28 10:54 827904 ----a-w- c:\windows\system32\wininet.dll
2009-07-18 16:01 . 2009-07-28 10:54 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-07-18 09:46 . 2009-07-28 10:54 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 00:26 . 2009-07-17 00:26 -------- d-----w- c:\program files\Alwil Software
2009-07-14 11:28 . 2009-06-15 14:51 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-07-11 13:53 . 2009-06-15 14:49 -------- d-sh--w- c:\programdata\{55A29068-F2CE-456C-9148-C869879E2357}
2009-06-21 09:00 . 2009-06-17 16:16 -------- d-----w- c:\program files\Paint.NET
2009-06-20 21:53 . 2008-12-10 20:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-20 14:43 . 2007-07-10 12:09 -------- d-----w- c:\program files\Microsoft Works
2009-06-15 15:24 . 2009-07-13 23:59 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-13 23:59 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-13 23:59 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-13 23:59 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-06-11 15:52 . 2009-08-12 15:24 123904 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_codecs-0.1.101-py2.5.egg-tmp\elisa\plugins\codecs\gstreamer\libgstflumpegdemux.dll
2009-06-11 15:52 . 2009-08-12 15:24 128000 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_codecs-0.1.101-py2.5.egg-tmp\elisa\plugins\codecs\gstreamer\libgstfluasfdemux.dll
2009-06-02 10:38 . 2009-03-13 15:09 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-05-20 22:52 . 2009-08-12 15:24 108032 ----a-w- c:\users\bob\AppData\Roaming\Python-Eggs\elisa_plugin_codecs-0.1.101-py2.5.egg-tmp\elisa\plugins\codecs\gstreamer\libgstcoreelements.dll
2008-12-17 23:04 . 2009-08-06 16:06 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-17 23:04 . 2009-08-06 16:06 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-17 23:04 . 2009-08-06 16:06 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-17 23:04 . 2009-08-06 16:06 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-17 23:04 . 2009-08-06 16:06 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Ad-Watch"=c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
"PCMService"="c:\acer\Empowering Technology\eMode\PCM\PCMService.exe"
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EBF00423-765B-4BCB-9694-FD0A5747AB01}"= UDP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{E7521040-F2A1-46DE-82BC-41CE0035A1D0}"= TCP:c:\acer\Empowering Technology\eMode\PCM\PCMService.exe:CyberLink PowerCinema Resident Program
"{889A3DE1-37FF-4843-9067-0A4FE0C9B168}"= UDP:c:\program files\Moovida\moovida.exe:Moovida Media Center
"{ACAA56E4-FE6D-4843-B638-906E3533320E}"= TCP:c:\program files\Moovida\moovida.exe:Moovida Media Center
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [21/04/2009 13:02 64160]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [17/07/2009 01:26 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/08/2009 16:06 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/08/2009 16:06 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [17/07/2009 01:26 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [17/07/2009 01:26 51792]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 22:34 1029456]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [05/05/2008 21:28 809296]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/08/2009 16:06 7408]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\System32\drivers\SiSGB6.sys [10/07/2007 21:29 46592]
S3 SiS6350;SiS6350;c:\windows\System32\drivers\SISGRKMD.sys [10/07/2007 21:29 454520]
S3 WSVD;WSVD;c:\windows\System32\drivers\WSVD.sys [04/03/2008 16:42 80744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-06-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 11:46]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://orange.fr/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.cooxer.com/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\bob\AppData\Roaming\Mozilla\Firefox\Profiles\l4r4gg60.default\
FF - prefs.js: browser.startup.homepage - hxxp://orange.fr/
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/...{moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-17 19:32
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\S45\Par]
@DACL=(02 0000)
"ID"=dword:0038580b
"CheckPort25DateTime"=dword:00384ff4
"CheckPort25Result"=dword:00000001
"CheckNATDateTime"=dword:004dad31
"CheckNATResult"=dword:00000003
"RA"=dword:1e686b59
"RP"=dword:0000f00a
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-17 19:35
ComboFix-quarantined-files.txt 2009-08-17 18:35
ComboFix2.txt 2009-08-17 13:05
Pre-Run: 50 488 295 424 octets libres
Post-Run: 50 287 394 816 octets libres
219 --- E O F --- 2009-08-17 10:44
apparament c encor le meme!