Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

le rapport combofix

 

ComboFix 08-04-08.5 - ordi 2008-04-09 0:00:31.1 - NTFSx86

Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.207 [GMT 2:00]

Endroit: C:\Users\ordi\Desktop\ComboFix.exe

* Création d'un nouveau point de restauration

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Users\ordi\Desktopblackbird.jpg

C:\Users\ordi\DesktopEditorFKWP1.5.exe

C:\Users\ordi\DesktopEditorFKWP2.0.exe

C:\Users\ordi\Desktopfilemanagerclient.exe

C:\Users\ordi\Desktopfkwp1.5.exe

C:\Users\ordi\Desktopfkwp2.0.exe

C:\Users\ordi\Desktopfwebd.exe

C:\Users\ordi\DesktopFWebdEditor.exe

C:\Users\ordi\DesktopTrojan.Win32.BlackBird.exe

C:\Users\ordi\Desktopvirii

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_poof

 

 

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-08 to 2008-04-08 ))))))))))))))))))))))))))))))))))))

.

 

2008-04-08 23:49 . 2008-04-08 23:49 16,658,632 --a------ C:\upload_moi_PC-de-ordi.tar.gz

2008-04-08 23:01 . 2008-04-08 23:01 <REP> d-------- C:\VundoFix Backups

2008-04-08 21:59 . 2008-04-08 22:43 <REP> d-------- C:\Program Files\Navilog1

2008-04-04 21:58 . 2008-04-04 21:58 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-04-04 20:39 . 2008-04-08 21:19 <REP> d-------- C:\Users\All Users\nizdxicv

2008-04-04 20:39 . 2008-04-08 21:19 <REP> d-------- C:\ProgramData\nizdxicv

2008-04-04 19:48 . 2008-04-04 19:48 0 --a------ C:\Windows\nsreg.dat

2008-04-04 19:24 . 2008-04-08 21:19 <REP> d-------- C:\Users\All Users\ojdkuyeu

2008-04-04 19:24 . 2008-04-08 21:19 <REP> d-------- C:\ProgramData\ojdkuyeu

2008-04-04 18:53 . 2008-04-04 18:53 <REP> d-------- C:\PerfLogs

2008-04-04 17:39 . 2008-04-04 17:40 <REP> d-------- C:\Program Files\Panda Security

2008-04-04 17:31 . 2008-01-19 09:42 179,256 --a------ C:\Windows\System32\drivers\pcmcia.sys

2008-04-04 17:31 . 2008-01-19 07:32 88,576 --a------ C:\Windows\System32\drivers\sdbus.sys

2008-04-04 17:31 . 2008-01-19 09:36 69,632 --a------ C:\Windows\System32\PNPXAssoc.dll

2008-04-04 17:31 . 2008-01-19 09:36 53,248 --a------ C:\Windows\System32\PNPXAssocPrx.dll

2008-04-04 17:31 . 2008-01-19 08:14 35,328 --a------ C:\Windows\System32\drivers\usbscan.sys

2008-04-04 17:29 . 2008-01-19 09:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll

2008-04-04 17:27 . 2008-01-19 07:31 8,322,048 --a------ C:\Windows\System32\spwizimg.dll

2008-04-04 17:26 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll

2008-04-04 17:23 . 2008-01-19 09:33 2,515,968 --a------ C:\Windows\System32\accessibilitycpl.dll

2008-04-04 17:22 . 2008-01-19 09:36 2,153,472 --a------ C:\Windows\System32\oobefldr.dll

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\Users\All Users\TEMP

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\ProgramData\TEMP

2008-04-04 16:35 . 2008-04-04 19:29 <REP> d-------- C:\Program Files\SpywareBlaster

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 16:23 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-04-04 16:13 . 2008-04-04 16:13 <REP> d-------- C:\Program Files\CCleaner

2008-04-03 16:32 . 2008-04-05 17:28 <REP> d-------- C:\Users\All Users\zksenpxq

2008-04-03 16:32 . 2008-04-04 20:39 <REP> d-------- C:\Users\All Users\bsdadmhw

2008-04-03 16:32 . 2008-04-05 17:28 <REP> d-------- C:\ProgramData\zksenpxq

2008-04-03 16:32 . 2008-04-04 20:39 <REP> d-------- C:\ProgramData\bsdadmhw

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-08 21:51 --------- d-----w C:\ProgramData\Symantec

2008-04-04 17:08 174 --sha-w C:\Program Files\desktop.ini

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Mail

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Journal

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Defender

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Collaboration

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Calendar

2008-04-04 15:01 --------- d-----w C:\Users\ordi\AppData\Roaming\OpenOffice.org2

2008-03-11 07:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat

2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf

2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys

2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys

2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys

2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys

2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys

2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys

2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf

2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys

2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat

2008-01-19 07:34 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll

2008-01-19 07:33 58,880 ----a-w C:\Windows\bfsvc.exe

2008-01-19 07:33 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll

2008-01-19 07:33 498,176 ----a-w C:\Windows\HelpPane.exe

2008-01-19 07:33 459,264 ----a-w C:\Windows\AppPatch\AcSpecfc.dll

2008-01-19 07:33 40,960 ----a-w C:\Windows\AppPatch\apihex86.dll

2008-01-19 07:33 237,568 ----a-w C:\Windows\AppPatch\AcRedir.dll

2008-01-19 07:33 2,927,104 ----a-w C:\Windows\explorer.exe

2008-01-19 07:33 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll

2008-01-19 07:33 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll

2008-01-19 07:33 151,040 ----a-w C:\Windows\notepad.exe

2008-01-19 07:33 134,656 ----a-w C:\Windows\regedit.exe

2008-01-19 07:33 13,312 ----a-w C:\Windows\fveupdate.exe

2007-10-14 16:33 540 ----a-w C:\Program Files\_DEISREG.ISR

1999-06-24 09:24 49,152 ----a-w C:\Program Files\_ISREG32.DLL

.

 

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]

"EPSON Stylus DX6000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.exe" [2006-09-22 06:01 139264]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]

"5NOEAsuPaW"="C:\ProgramData\bsdadmhw\bkbwtsvs.exe" [ ]

"2Ibhanza1E"="C:\ProgramData\bsdadmhw\bkbwtsvs.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Acer Tour"="" []

"eRecoveryService"="" []

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]

"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2006-11-09 14:37 86016]

"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 21:00 815104]

"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]

"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 20:57 3784704 C:\Windows\RtHDVCpl.exe]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 18:02 81920]

"osCheck"="c:\Program Files\Norton Internet Security\osCheck.exe" [2006-11-21 22:30 22696]

"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2006-08-29 09:26 241664]

"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2007-01-10 11:34 200704]

"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2005-07-25 13:36 32768]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 18:02 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 18:05 106496]

"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 18:58 464168]

"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 22:33 107112]

"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-01-14 20:38 151552]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]

Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-10 12:48:33 528384]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\DVWIZA~1\Kernel\Burner\MKDMP3Enc.ACM

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{8A01FC39-13F7-457E-8C62-7B4E57ADEAD2}"= UDP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

"{B624C9A4-F81C-400E-BF94-F1F1661678CA}"= TCP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-01-02 18:59]

R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-01-02 18:59]

R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-01-02 18:59]

R1 Hotkey;Hotkey;C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 11:27]

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080407.003\IDSvix86.sys [2008-02-13 18:18]

R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-01-02 18:58]

R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 20:07]

R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-01-02 16:46]

R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 12:57]

R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 09:33]

R3 Cam5607;Acer OrbiCam;C:\Windows\system32\Drivers\BisonC07.sys [2006-11-25 11:17]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-06 19:29]

R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 14:39]

R3 WisLMSvc;WisLMSvc;"C:\Program Files\Launch Manager\WisLMSvc.exe" [2006-11-17 20:45]

S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 09:30]

S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 21:18]

 

*Newly Created Service* - COMHOST

.

Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

"2008-04-04 15:34:02 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - ordi.job"

Posté(e)

Si elle n'est pas désactivée, désactive l'UAC.

 

  • Crée un fichier texte nommé CFScript.txt
    Double clique pour l'ouvrir, et copie colle ceci dedans :

 

File::

c:\windows\system32\activetoolband.dll

C:\Users\ordi\AppData\Local\Temp\vwetcogc.dll

 

Folder::

C:\Users\All Users\zksenpxq

C:\Users\All Users\bsdadmhw

C:\ProgramData\zksenpxq

C:\ProgramData\bsdadmhw

C:\ProgramData\nizdxicv

C:\ProgramData\ojdkuyeu

 

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NOEAsuPaW"=-

"2Ibhanza1E"=-

"7C243674620608525F24"=-

"nizdxicv"=-

"ojdkuyeu"=-

 

 

:arrow: Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture

CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

 

UAC réactivable.

Posté(e)
Si elle n'est pas désactivée, désactive l'UAC.

 

  • Crée un fichier texte nommé CFScript.txt
    Double clique pour l'ouvrir, et copie colle ceci dedans :

 

 

 

 

:arrow: Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture

CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

 

UAC réactivable.

 

nouveau rapport combofix

 

ComboFix 08-04-08.5 - ordi 2008-04-09 0:37:25.2 - NTFSx86

Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.171 [GMT 2:00]

Endroit: C:\Users\ordi\Desktop\ComboFix.exe

Command switches used :: C:\Users\ordi\Desktop\CFScript.txt

* Création d'un nouveau point de restauration

 

FILE ::

C:\Users\ordi\AppData\Local\Temp\vwetcogc.dll

c:\windows\system32\activetoolband.dll

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\ProgramData\bsdadmhw

C:\ProgramData\bsdadmhw\bkbwtsvs.exe.bak

C:\ProgramData\nizdxicv

C:\ProgramData\ojdkuyeu

C:\ProgramData\zksenpxq

C:\Users\All Users\bsdadmhw\bkbwtsvs.exe.bak

c:\windows\system32\activetoolband.dll

.

---- Previous Run -------

.

C:\Users\ordi\Desktopblackbird.jpg

C:\Users\ordi\DesktopEditorFKWP1.5.exe

C:\Users\ordi\DesktopEditorFKWP2.0.exe

C:\Users\ordi\Desktopfilemanagerclient.exe

C:\Users\ordi\Desktopfkwp1.5.exe

C:\Users\ordi\Desktopfkwp2.0.exe

C:\Users\ordi\Desktopfwebd.exe

C:\Users\ordi\DesktopFWebdEditor.exe

C:\Users\ordi\DesktopTrojan.Win32.BlackBird.exe

C:\Users\ordi\Desktopvirii

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_poof

 

 

((((((((((((((((((((((((((((( Fichiers créés 2008-03-08 to 2008-04-08 ))))))))))))))))))))))))))))))))))))

.

 

2008-04-08 23:49 . 2008-04-08 23:49 16,658,632 --a------ C:\upload_moi_PC-de-ordi.tar.gz

2008-04-08 23:01 . 2008-04-08 23:01 <REP> d-------- C:\VundoFix Backups

2008-04-08 21:59 . 2008-04-08 22:43 <REP> d-------- C:\Program Files\Navilog1

2008-04-04 21:58 . 2008-04-04 21:58 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-04-04 19:48 . 2008-04-04 19:48 0 --a------ C:\Windows\nsreg.dat

2008-04-04 18:53 . 2008-04-04 18:53 <REP> d-------- C:\PerfLogs

2008-04-04 17:39 . 2008-04-04 17:40 <REP> d-------- C:\Program Files\Panda Security

2008-04-04 17:31 . 2008-01-19 09:42 179,256 --a------ C:\Windows\System32\drivers\pcmcia.sys

2008-04-04 17:31 . 2008-01-19 07:32 88,576 --a------ C:\Windows\System32\drivers\sdbus.sys

2008-04-04 17:31 . 2008-01-19 09:36 69,632 --a------ C:\Windows\System32\PNPXAssoc.dll

2008-04-04 17:31 . 2008-01-19 09:36 53,248 --a------ C:\Windows\System32\PNPXAssocPrx.dll

2008-04-04 17:31 . 2008-01-19 08:14 35,328 --a------ C:\Windows\System32\drivers\usbscan.sys

2008-04-04 17:29 . 2008-01-19 09:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll

2008-04-04 17:27 . 2008-01-19 07:31 8,322,048 --a------ C:\Windows\System32\spwizimg.dll

2008-04-04 17:26 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll

2008-04-04 17:23 . 2008-01-19 09:33 2,515,968 --a------ C:\Windows\System32\accessibilitycpl.dll

2008-04-04 17:22 . 2008-01-19 09:36 2,153,472 --a------ C:\Windows\System32\oobefldr.dll

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\Users\All Users\TEMP

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\ProgramData\TEMP

2008-04-04 16:35 . 2008-04-04 19:29 <REP> d-------- C:\Program Files\SpywareBlaster

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 16:23 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-04-04 16:13 . 2008-04-04 16:13 <REP> d-------- C:\Program Files\CCleaner

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-08 21:51 --------- d-----w C:\ProgramData\Symantec

2008-04-04 17:08 174 --sha-w C:\Program Files\desktop.ini

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Mail

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Journal

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Defender

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Collaboration

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Calendar

2008-04-04 16:12 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-04-04 16:12 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-04-04 15:01 --------- d-----w C:\Users\ordi\AppData\Roaming\OpenOffice.org2

2008-03-11 07:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat

2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf

2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys

2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys

2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys

2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys

2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys

2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys

2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf

2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys

2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat

2008-02-14 02:09 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-01-19 07:44 986,680 ----a-w C:\Windows\System32\winload.exe

2008-01-19 07:44 926,776 ----a-w C:\Windows\System32\winresume.exe

2008-01-19 07:43 614,968 ----a-w C:\Windows\System32\ci.dll

2008-01-19 07:43 376,376 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll

2008-01-19 07:43 3,600,440 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-01-19 07:43 3,548,728 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-01-19 07:42 94,776 ----a-w C:\Windows\System32\MigAutoPlay.exe

2008-01-19 07:42 51,768 ----a-w C:\Windows\System32\PSHED.DLL

2008-01-19 07:42 247,352 ----a-w C:\Windows\System32\clfs.sys

2008-01-19 07:42 177,208 ----a-w C:\Windows\System32\halmacpi.dll

2008-01-19 07:42 141,880 ----a-w C:\Windows\System32\halacpi.dll

2008-01-19 07:41 24,120 ----a-w C:\Windows\System32\BOOTVID.DLL

2008-01-19 07:41 21,560 ----a-w C:\Windows\System32\kdusb.dll

2008-01-19 07:41 19,512 ----a-w C:\Windows\System32\kdcom.dll

2008-01-19 07:38 46,080 ----a-w C:\Windows\System32\NAPCRYPT.DLL

2008-01-19 07:38 4,595,712 ----a-w C:\Windows\System32\AuthFWSnapin.dll

2008-01-19 07:38 242,744 ----a-w C:\Windows\System32\rsaenh.dll

2008-01-19 07:38 155,704 ----a-w C:\Windows\System32\dssenh.dll

2008-01-19 07:38 131,640 ----a-w C:\Windows\System32\basecsp.dll

2008-01-19 07:38 103,936 ----a-w C:\Windows\System32\NAPHLPR.DLL

2008-01-19 07:38 1,203,792 ----a-w C:\Windows\System32\ntdll.dll

2008-01-19 07:36 996,352 ----a-w C:\Windows\System32\WMNetMgr.dll

2008-01-19 07:35 98,304 ----a-w C:\Windows\System32\mssitlb.dll

2008-01-19 07:34 98,816 ----a-w C:\Windows\System32\mfps.dll

2008-01-19 07:33 98,304 ----a-w C:\Windows\System32\makecab.exe

2008-01-19 07:32 879,616 ----a-w C:\Windows\System32\Bubbles.scr

2008-01-19 07:32 704,512 ----a-w C:\Windows\System32\PhotoScreensaver.scr

2008-01-19 07:32 5,714,432 ----a-w C:\Windows\System32\logon.scr

2008-01-19 07:32 258,048 ----a-w C:\Windows\System32\winspool.drv

2008-01-19 07:32 221,184 ----a-w C:\Windows\System32\Mystify.scr

2008-01-19 07:32 220,672 ----a-w C:\Windows\System32\Ribbons.scr

2008-01-19 07:32 21,504 ----a-w C:\Windows\System32\msacm32.drv

2008-01-19 07:32 166,912 ----a-w C:\Windows\System32\wdmaud.drv

2008-01-19 07:32 1,370,624 ----a-w C:\Windows\System32\Aurora.scr

2008-01-19 07:31 7,680 ----a-w C:\Windows\System32\spwizres.dll

2008-01-19 07:31 57,856 ----a-w C:\Windows\System32\nlsbres.dll

2008-01-19 07:31 118,272 ----a-w C:\Windows\System32\RDPENCDD.dll

2008-01-19 07:30 17,920 ----a-w C:\Windows\System32\netevent.dll

2008-01-19 07:29 705,536 ----a-w C:\Windows\System32\imagesp1.dll

2008-01-19 07:29 58,880 ----a-w C:\Windows\System32\msobjs.dll

2008-01-19 07:28 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll

2008-01-19 07:26 36,864 ----a-w C:\Windows\System32\cdd.dll

2008-01-19 06:06 8,147,456 ----a-w C:\Windows\System32\wmploc.DLL

2008-01-19 06:01 14,336 ----a-w C:\Windows\System32\tsddd.dll

2008-01-19 06:01 134,656 ----a-w C:\Windows\System32\rdpdd.dll

2008-01-19 05:52 56,320 ----a-w C:\Windows\System32\vga256.dll

2008-01-19 05:52 21,504 ----a-w C:\Windows\System32\vga64k.dll

2008-01-19 05:52 11,776 ----a-w C:\Windows\System32\framebuf.dll

2008-01-19 05:52 10,752 ----a-w C:\Windows\System32\vga.dll

2008-01-19 05:50 14,848 ----a-w C:\Windows\System32\iscsilog.dll

2008-01-19 05:48 20,992 ----a-w C:\Windows\System32\msdtcVSp1res.dll

2008-01-19 05:48 1,291,264 ----a-w C:\Windows\System32\comres.dll

2008-01-19 05:46 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll

2008-01-19 05:39 13,312 ----a-w C:\Windows\System32\WsmRes.dll

2008-01-19 05:37 2,031,616 ----a-w C:\Windows\System32\win32k.sys

2008-01-19 05:36 289,792 ----a-w C:\Windows\System32\atmfd.dll

2008-01-19 05:33 56,320 ----a-w C:\Windows\System32\graftabl.com

2008-01-19 05:27 8,704 ----a-w C:\Windows\System32\kd1394.dll

2008-01-19 05:26 605,696 ----a-w C:\Windows\System32\adtschema.dll

2008-01-19 03:17 100,043 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

2007-10-14 16:33 540 ----a-w C:\Program Files\_DEISREG.ISR

1999-06-24 09:24 49,152 ----a-w C:\Program Files\_ISREG32.DLL

.

 

((((((((((((((((((((((((((((( snapshot@2008-04-09_ 0.15.36.54 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-04-08 22:11:28 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-04-08 22:13:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

- 2008-04-08 21:59:18 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-04-08 22:16:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-04-08 21:59:18 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-04-08 22:16:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-04-08 21:59:18 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-04-08 22:16:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-04-08 20:00:57 101,250 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-04-08 22:17:15 101,250 ----a-w C:\Windows\System32\perfc009.dat

- 2008-04-08 20:00:57 123,556 ----a-w C:\Windows\System32\perfc00C.dat

+ 2008-04-08 22:17:15 123,556 ----a-w C:\Windows\System32\perfc00C.dat

- 2008-04-08 20:00:57 587,178 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-04-08 22:17:15 587,178 ----a-w C:\Windows\System32\perfh009.dat

- 2008-04-08 20:00:57 669,578 ----a-w C:\Windows\System32\perfh00C.dat

+ 2008-04-08 22:17:15 669,578 ----a-w C:\Windows\System32\perfh00C.dat

.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]

"EPSON Stylus DX6000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.exe" [2006-09-22 06:01 139264]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]

"5NOEAsuPaW"="C:\ProgramData\bsdadmhw\bkbwtsvs.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Acer Tour"="" []

"eRecoveryService"="" []

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]

"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2006-11-09 14:37 86016]

"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 21:00 815104]

"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]

"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 20:57 3784704 C:\Windows\RtHDVCpl.exe]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 18:02 81920]

"osCheck"="c:\Program Files\Norton Internet Security\osCheck.exe" [2006-11-21 22:30 22696]

"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2006-08-29 09:26 241664]

"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2007-01-10 11:34 200704]

"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2005-07-25 13:36 32768]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 18:02 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 18:05 106496]

"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 18:58 464168]

"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 22:33 107112]

"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-01-14 20:38 151552]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]

Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-10 12:48:33 528384]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\DVWIZA~1\Kernel\Burner\MKDMP3Enc.ACM

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{8A01FC39-13F7-457E-8C62-7B4E57ADEAD2}"= UDP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

"{B624C9A4-F81C-400E-BF94-F1F1661678CA}"= TCP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-01-02 18:59]

R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-01-02 18:59]

R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-01-02 18:59]

R1 Hotkey;Hotkey;C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 11:27]

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080407.003\IDSvix86.sys [2008-02-13 18:18]

R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-01-02 18:58]

R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 20:07]

R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-01-02 16:46]

R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 12:57]

R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 09:33]

R3 Cam5607;Acer OrbiCam;C:\Windows\system32\Drivers\BisonC07.sys [2006-11-25 11:17]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-06 19:29]

R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 14:39]

R3 WisLMSvc;WisLMSvc;"C:\Program Files\Launch Manager\WisLMSvc.exe" [2006-11-17 20:45]

S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 09:30]

S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 21:18]

 

*Newly Created Service* - COMHOST

.

Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

"2008-04-04 15:34:02 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - ordi.job"

- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeB/TASK:

.

**************************************************************************

 

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-09 00:41:17

Windows 6.0.6001 Service Pack 1 NTFS

 

Balayage processus cachés ...

 

Balayage caché autostart entries ...

 

Balayage des fichiers cachés ...

 

Scan terminé avec succès

Les fichiers cachés: 0

 

**************************************************************************

.

Temps d'accomplissement: 2008-04-09 0:42:29

ComboFix-quarantined-files.txt 2008-04-08 22:42:23

Pre-Run: 36,698,710,016 octets libres

Post-Run: 36,561,162,240 octets libres

.

2008-04-04 16:30:16 --- E O F ---

Posté(e)
Merci. :P

 

Poste un nouveau rapport HijackThis stp.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:03:48, on 09/04/2008

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Launch Manager\WButton.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Launch Manager\OSDCtrl.exe

C:\Program Files\Launch Manager\HotkeyApp.exe

C:\Program Files\Launch Manager\LaunchAp.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\ehome\ehmsas.exe

C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE

C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE

C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE

C:\Windows\system32\wbem\unsecapp.exe

C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Windows\system32\conime.exe

C:\Windows\explorer.exe

C:\Windows\System32\rundll32.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Users\ordi\Downloads\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"

O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"

O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"

O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [EPSON Stylus DX6000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\Windows\TEMP\E_SAFCE.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [5NOEAsuPaW] C:\ProgramData\bsdadmhw\bkbwtsvs.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O13 - Gopher Prefix:

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O20 - AppInit_DLLs: eNetHook.dll

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe

O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe

O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe

O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe

O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe

O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe

 

--

End of file - 8305 bytes

Posté(e)

Il en reste un, j'ai du mélanger deux clés (sans danger ici).

Nouveau script pour lui.

 

 

File::

C:\ProgramData\bsdadmhw\bkbwtsvs.exe

 

Folder::

C:\ProgramData\bsdadmhw

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"5NOEAsuPaW"=-

 

 

:arrow: Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture

CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

 

Après ça, ça devrait aller mieux.

Posté(e)
Il en reste un, j'ai du mélanger deux clés (sans danger ici).

Nouveau script pour lui.

 

 

 

 

 

:arrow: Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture

CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

 

Après ça, ça devrait aller mieux.

merci mille fois

 

les rapports après la dernière manipulation :

 

ComboFix 08-04-08.5 - ordi 2008-04-09 1:30:48.3 - NTFSx86

Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.288 [GMT 2:00]

Endroit: C:\Users\ordi\Desktop\ComboFix.exe

Command switches used :: C:\Users\ordi\Desktop\CFScript.txt

* Création d'un nouveau point de restauration

 

FILE ::

C:\ProgramData\bsdadmhw\bkbwtsvs.exe

.

 

((((((((((((((((((((((((((((( Fichiers créés 2008-03-08 to 2008-04-08 ))))))))))))))))))))))))))))))))))))

.

 

2008-04-08 23:49 . 2008-04-08 23:49 16,658,632 --a------ C:\upload_moi_PC-de-ordi.tar.gz

2008-04-08 23:01 . 2008-04-08 23:01 <REP> d-------- C:\VundoFix Backups

2008-04-08 21:59 . 2008-04-08 22:43 <REP> d-------- C:\Program Files\Navilog1

2008-04-04 21:58 . 2008-04-04 21:58 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-04-04 19:48 . 2008-04-04 19:48 0 --a------ C:\Windows\nsreg.dat

2008-04-04 18:53 . 2008-04-04 18:53 <REP> d-------- C:\PerfLogs

2008-04-04 17:39 . 2008-04-04 17:40 <REP> d-------- C:\Program Files\Panda Security

2008-04-04 17:31 . 2008-01-19 09:42 179,256 --a------ C:\Windows\System32\drivers\pcmcia.sys

2008-04-04 17:31 . 2008-01-19 07:32 88,576 --a------ C:\Windows\System32\drivers\sdbus.sys

2008-04-04 17:31 . 2008-01-19 09:36 69,632 --a------ C:\Windows\System32\PNPXAssoc.dll

2008-04-04 17:31 . 2008-01-19 09:36 53,248 --a------ C:\Windows\System32\PNPXAssocPrx.dll

2008-04-04 17:31 . 2008-01-19 08:14 35,328 --a------ C:\Windows\System32\drivers\usbscan.sys

2008-04-04 17:29 . 2008-01-19 09:34 6,103,040 --a------ C:\Windows\System32\chtbrkr.dll

2008-04-04 17:27 . 2008-01-19 07:31 8,322,048 --a------ C:\Windows\System32\spwizimg.dll

2008-04-04 17:26 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll

2008-04-04 17:23 . 2008-01-19 09:33 2,515,968 --a------ C:\Windows\System32\accessibilitycpl.dll

2008-04-04 17:22 . 2008-01-19 09:36 2,153,472 --a------ C:\Windows\System32\oobefldr.dll

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\Users\All Users\TEMP

2008-04-04 16:39 . 2008-04-04 20:25 <REP> d-a------ C:\ProgramData\TEMP

2008-04-04 16:35 . 2008-04-04 19:29 <REP> d-------- C:\Program Files\SpywareBlaster

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 17:00 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy

2008-04-04 16:23 . 2008-04-04 16:23 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-04-04 16:13 . 2008-04-04 16:13 <REP> d-------- C:\Program Files\CCleaner

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-04-08 21:51 --------- d-----w C:\ProgramData\Symantec

2008-04-04 17:08 174 --sha-w C:\Program Files\desktop.ini

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Sidebar

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Mail

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Journal

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Defender

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Collaboration

2008-04-04 16:56 --------- d-----w C:\Program Files\Windows Calendar

2008-04-04 16:12 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-04-04 16:12 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-04-04 15:01 --------- d-----w C:\Users\ordi\AppData\Roaming\OpenOffice.org2

2008-03-11 07:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat

2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf

2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys

2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys

2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys

2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys

2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys

2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys

2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf

2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys

2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat

2008-02-14 02:09 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-01-19 07:44 986,680 ----a-w C:\Windows\System32\winload.exe

2008-01-19 07:44 926,776 ----a-w C:\Windows\System32\winresume.exe

2008-01-19 07:43 614,968 ----a-w C:\Windows\System32\ci.dll

2008-01-19 07:43 376,376 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll

2008-01-19 07:43 3,600,440 ----a-w C:\Windows\System32\ntkrnlpa.exe

2008-01-19 07:43 3,548,728 ----a-w C:\Windows\System32\ntoskrnl.exe

2008-01-19 07:42 94,776 ----a-w C:\Windows\System32\MigAutoPlay.exe

2008-01-19 07:42 51,768 ----a-w C:\Windows\System32\PSHED.DLL

2008-01-19 07:42 247,352 ----a-w C:\Windows\System32\clfs.sys

2008-01-19 07:42 177,208 ----a-w C:\Windows\System32\halmacpi.dll

2008-01-19 07:42 141,880 ----a-w C:\Windows\System32\halacpi.dll

2008-01-19 07:41 24,120 ----a-w C:\Windows\System32\BOOTVID.DLL

2008-01-19 07:41 21,560 ----a-w C:\Windows\System32\kdusb.dll

2008-01-19 07:41 19,512 ----a-w C:\Windows\System32\kdcom.dll

2008-01-19 07:38 46,080 ----a-w C:\Windows\System32\NAPCRYPT.DLL

2008-01-19 07:38 4,595,712 ----a-w C:\Windows\System32\AuthFWSnapin.dll

2008-01-19 07:38 242,744 ----a-w C:\Windows\System32\rsaenh.dll

2008-01-19 07:38 155,704 ----a-w C:\Windows\System32\dssenh.dll

2008-01-19 07:38 131,640 ----a-w C:\Windows\System32\basecsp.dll

2008-01-19 07:38 103,936 ----a-w C:\Windows\System32\NAPHLPR.DLL

2008-01-19 07:38 1,203,792 ----a-w C:\Windows\System32\ntdll.dll

2008-01-19 07:36 996,352 ----a-w C:\Windows\System32\WMNetMgr.dll

2008-01-19 07:35 98,304 ----a-w C:\Windows\System32\mssitlb.dll

2008-01-19 07:34 98,816 ----a-w C:\Windows\System32\mfps.dll

2008-01-19 07:33 98,304 ----a-w C:\Windows\System32\makecab.exe

2008-01-19 07:32 879,616 ----a-w C:\Windows\System32\Bubbles.scr

2008-01-19 07:32 704,512 ----a-w C:\Windows\System32\PhotoScreensaver.scr

2008-01-19 07:32 5,714,432 ----a-w C:\Windows\System32\logon.scr

2008-01-19 07:32 258,048 ----a-w C:\Windows\System32\winspool.drv

2008-01-19 07:32 221,184 ----a-w C:\Windows\System32\Mystify.scr

2008-01-19 07:32 220,672 ----a-w C:\Windows\System32\Ribbons.scr

2008-01-19 07:32 21,504 ----a-w C:\Windows\System32\msacm32.drv

2008-01-19 07:32 166,912 ----a-w C:\Windows\System32\wdmaud.drv

2008-01-19 07:32 1,370,624 ----a-w C:\Windows\System32\Aurora.scr

2008-01-19 07:31 7,680 ----a-w C:\Windows\System32\spwizres.dll

2008-01-19 07:31 57,856 ----a-w C:\Windows\System32\nlsbres.dll

2008-01-19 07:31 118,272 ----a-w C:\Windows\System32\RDPENCDD.dll

2008-01-19 07:30 17,920 ----a-w C:\Windows\System32\netevent.dll

2008-01-19 07:29 705,536 ----a-w C:\Windows\System32\imagesp1.dll

2008-01-19 07:29 58,880 ----a-w C:\Windows\System32\msobjs.dll

2008-01-19 07:28 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll

2008-01-19 07:26 36,864 ----a-w C:\Windows\System32\cdd.dll

2008-01-19 06:06 8,147,456 ----a-w C:\Windows\System32\wmploc.DLL

2008-01-19 06:01 14,336 ----a-w C:\Windows\System32\tsddd.dll

2008-01-19 06:01 134,656 ----a-w C:\Windows\System32\rdpdd.dll

2008-01-19 05:52 56,320 ----a-w C:\Windows\System32\vga256.dll

2008-01-19 05:52 21,504 ----a-w C:\Windows\System32\vga64k.dll

2008-01-19 05:52 11,776 ----a-w C:\Windows\System32\framebuf.dll

2008-01-19 05:52 10,752 ----a-w C:\Windows\System32\vga.dll

2008-01-19 05:50 14,848 ----a-w C:\Windows\System32\iscsilog.dll

2008-01-19 05:48 20,992 ----a-w C:\Windows\System32\msdtcVSp1res.dll

2008-01-19 05:48 1,291,264 ----a-w C:\Windows\System32\comres.dll

2008-01-19 05:46 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll

2008-01-19 05:39 13,312 ----a-w C:\Windows\System32\WsmRes.dll

2008-01-19 05:37 2,031,616 ----a-w C:\Windows\System32\win32k.sys

2008-01-19 05:36 289,792 ----a-w C:\Windows\System32\atmfd.dll

2008-01-19 05:33 56,320 ----a-w C:\Windows\System32\graftabl.com

2008-01-19 05:27 8,704 ----a-w C:\Windows\System32\kd1394.dll

2008-01-19 05:26 605,696 ----a-w C:\Windows\System32\adtschema.dll

2008-01-19 03:17 100,043 ----a-w C:\Windows\System32\StructuredQuerySchema.bin

2007-10-14 16:33 540 ----a-w C:\Program Files\_DEISREG.ISR

1999-06-24 09:24 49,152 ----a-w C:\Program Files\_ISREG32.DLL

.

 

((((((((((((((((((((((((((((( snapshot@2008-04-09_ 0.15.36.54 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-04-08 22:10:39 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2008-04-08 23:26:47 67,584 --s-a-w C:\Windows\bootstat.dat

- 2008-04-08 22:11:30 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-04-08 23:28:45 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-04-08 23:28:45 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-04-08 22:11:28 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-04-08 23:28:00 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-04-08 23:28:00 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-04-08 21:59:18 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-04-08 23:20:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-04-08 21:59:18 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-04-08 23:20:51 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-04-08 21:59:18 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-04-08 23:20:51 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-04-08 20:00:57 101,250 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-04-08 23:34:47 101,250 ----a-w C:\Windows\System32\perfc009.dat

- 2008-04-08 20:00:57 123,556 ----a-w C:\Windows\System32\perfc00C.dat

+ 2008-04-08 23:34:47 123,556 ----a-w C:\Windows\System32\perfc00C.dat

- 2008-04-08 20:00:57 587,178 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-04-08 23:34:47 587,178 ----a-w C:\Windows\System32\perfh009.dat

- 2008-04-08 20:00:57 669,578 ----a-w C:\Windows\System32\perfh00C.dat

+ 2008-04-08 23:34:47 669,578 ----a-w C:\Windows\System32\perfh00C.dat

- 2008-04-08 22:13:24 10,958 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1224772120-3823277818-4152024611-1000_UserData.bin

+ 2008-04-08 23:28:45 10,974 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1224772120-3823277818-4152024611-1000_UserData.bin

- 2008-04-08 22:13:23 70,360 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-04-08 23:28:44 70,424 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-04-08 19:56:06 54,492 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-04-08 23:28:40 54,500 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 09:33 1233920]

"EPSON Stylus DX6000 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.exe" [2006-09-22 06:01 139264]

"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]

"5NOEAsuPaW"="C:\ProgramData\bsdadmhw\bkbwtsvs.exe" [ ]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Acer Tour"="" []

"eRecoveryService"="" []

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 09:38 1008184]

"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2006-11-09 14:37 86016]

"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]

"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 21:00 815104]

"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]

"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 20:57 3784704 C:\Windows\RtHDVCpl.exe]

"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 18:02 81920]

"osCheck"="c:\Program Files\Norton Internet Security\osCheck.exe" [2006-11-21 22:30 22696]

"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2006-08-29 09:26 241664]

"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2007-01-10 11:34 200704]

"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2005-07-25 13:36 32768]

"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 18:02 98304]

"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 18:05 106496]

"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 18:58 464168]

"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 22:33 107112]

"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-01-14 20:38 151552]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]

Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-10 12:48:33 528384]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\DVWIZA~1\Kernel\Burner\MKDMP3Enc.ACM

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UacDisableNotify"=dword:00000001

"InternetSettingsDisableNotify"=dword:00000001

"AutoUpdateDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{8A01FC39-13F7-457E-8C62-7B4E57ADEAD2}"= UDP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

"{B624C9A4-F81C-400E-BF94-F1F1661678CA}"= TCP:C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-01-02 18:59]

R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-01-02 18:59]

R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-01-02 18:59]

R1 Hotkey;Hotkey;C:\Windows\system32\drivers\Hotkey.sys [2003-04-28 11:27]

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080407.003\IDSvix86.sys [2008-02-13 18:18]

R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-01-02 18:58]

R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2006-12-28 20:07]

R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-01-02 16:46]

R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 12:57]

R2 WMIService;ePower Service;C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-01-02 09:33]

R3 Cam5607;Acer OrbiCam;C:\Windows\system32\Drivers\BisonC07.sys [2006-11-25 11:17]

R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-06 19:29]

R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 14:39]

R3 WisLMSvc;WisLMSvc;"C:\Program Files\Launch Manager\WisLMSvc.exe" [2006-11-17 20:45]

S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2006-11-02 09:30]

S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-12-19 21:18]

 

*Newly Created Service* - COMHOST

.

Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

"2008-04-04 15:34:02 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - ordi.job"

- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeB/TASK:

.

**************************************************************************

 

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-04-09 01:35:15

Windows 6.0.6001 Service Pack 1 NTFS

 

Balayage processus cachés ...

 

Balayage caché autostart entries ...

 

Balayage des fichiers cachés ...

 

Scan terminé avec succès

Les fichiers cachés: 0

 

**************************************************************************

.

Temps d'accomplissement: 2008-04-09 1:36:15

ComboFix-quarantined-files.txt 2008-04-08 23:36:08

ComboFix2.txt 2008-04-08 22:42:30

Pre-Run: 36,148,449,280 octets libres

Post-Run: 35,906,293,760 octets libres

.

2008-04-04 16:30:16 --- E O F ---

Posté(e)

Hijackthis :

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 01:42:50, on 09/04/2008

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Windows\system32\taskeng.exe

C:\Windows\system32\Dwm.exe

C:\Program Files\Launch Manager\WButton.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Windows\RtHDVCpl.exe

C:\Windows\System32\igfxpers.exe

C:\Program Files\Launch Manager\OSDCtrl.exe

C:\Program Files\Launch Manager\HotkeyApp.exe

C:\Program Files\Launch Manager\LaunchAp.exe

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

C:\Program Files\Common Files\Symantec Shared\ccApp.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Windows\ehome\ehtray.exe

C:\Windows\ehome\ehmsas.exe

C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE

C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE

C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE

C:\Windows\System32\mobsync.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE

C:\Windows\system32\conime.exe

C:\Windows\Explorer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Users\ordi\Downloads\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"

O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe

O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"

O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"

O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"

O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"

O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe

O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe

O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [EPSON Stylus DX6000 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\Windows\TEMP\E_SAFCE.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [5NOEAsuPaW] C:\ProgramData\bsdadmhw\bkbwtsvs.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O13 - Gopher Prefix:

O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O20 - AppInit_DLLs: eNetHook.dll

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe

O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe

O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe

O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe

O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe

O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe

O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe

O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe

O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe

 

--

End of file - 8262 bytes

Posté(e)

Il en reste un, qui résiste.

 

Si tu as toujours VundoFix sur ton bureau, fais "file", "add file to list"

Tu parcours les dossiers pour aller chercher ceci :

C:\ProgramData\bsdadmhw\bkbwtsvs.exe

 

Ca va l'ajouter à la liste dans VundoFix, n'oublie pas de cocher la case à gauche de la ligne.

Clique sur Fix Vundo.

 

Le bureau va disparaître (fond d'écran et icônes (c'est normal)), puis VundoFix va te dire que la machine doit être redémarrée.

Tu auras un rapport dans c:\vundofix.txt à poster, après le redémarrage.

 

@ toute

Posté(e)
Il en reste un, qui résiste.

 

Si tu as toujours VundoFix sur ton bureau, fais "file", "add file to list"

Tu parcours les dossiers pour aller chercher ceci :

C:\ProgramData\bsdadmhw\bkbwtsvs.exe

 

Ca va l'ajouter à la liste dans VundoFix, n'oublie pas de cocher la case à gauche de la ligne.

Clique sur Fix Vundo.

 

Le bureau va disparaître (fond d'écran et icônes (c'est normal)), puis VundoFix va te dire que la machine doit être redémarrée.

Tu auras un rapport dans c:\vundofix.txt à poster, après le redémarrage.

 

@ toute

 

bonjour Falkra

 

je ne trouve pas de dossier C:\ProgramData\bsdadmhw ( j'ai bien cocher dans les options de dossiers -> afficher les dossiers cachés )

en revanche j'ai un fichier bkbwtsvs.exe.bak.vir dans C:\QooBox\Quarantine\C\ProgramData\bsdadmhw.

 

dois-je passer ce dernier sur vundofix ?

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...