Det gik godt noget af vejen.
Combofix fandt rootkit. Genstart. Efter Etape 1, 2, 3, 4 og 5: Fingerprint software Error: Cannot initialize application. Jeg klikkede OK. Etape 6, 6A, 7,..., 50. Sletning af filer. Automatisk genstart. Rapport:
ComboFix 10-09-08.03 - Nathalie 11/09/2010 18:57:05.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.33.1033.18.3581.2645 [GMT 2:00]
Lancé depuis: c:\users\Nathalie\Desktop\alg.exe.exe
Commutateurs utilisés :: c:\users\Nathalie\Desktop\CFScript.txt
FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
“c:\users\Nathalie\AppData\Roaming\GetValue.vbs”
“c:\users\Nathalie\AppData\Roaming\SetValue.bat”
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Nathalie\AppData\Local\Temp\IadHide5.dll
c:\users\Nathalie\AppData\Roaming\GetValue.vbs
c:\users\Nathalie\AppData\Roaming\SetValue.bat
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-11 au 2010-09-11 ))))))))))))))))))))))))))))))))))))
.
2010-09-11 17:05 . 2010-09-11 17:05 ———— d——-w- c:\users\Public\AppData\Local\temp
2010-09-11 17:05 . 2010-09-11 17:05 ———— d——-w- c:\users\Default\AppData\Local\temp
2010-09-11 16:43 . 2010-09-11 16:43 ———— d——-w- C:\alg.exe4669a
2010-09-11 13:43 . 2010-09-11 17:08 ———— d——-w- c:\users\Nathalie\AppData\Local\temp
2010-09-11 13:21 . 2010-09-11 13:43 ———— d——-w- C:\alg.exe
2010-09-11 13:18 . 2010-09-11 13:18 56 —-ha-w- c:\windows\system32\ezsidmv.dat
2010-09-11 13:15 . 2010-09-11 13:15 ———— d——-w- C:\_OTS
2010-09-09 13:51 . 2010-09-09 13:51 ———— d——-w- c:\users\Nathalie\AppData\Roaming\Malwarebytes
2010-09-09 13:50 . 2010-04-29 13:39 38224 ——a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-09 13:50 . 2010-09-09 13:50 ———— d——-w- c:\program files\Malwarebytes’ Anti-Malware
2010-09-09 13:50 . 2010-09-09 13:50 ———— d——-w- c:\programdata\Malwarebytes
2010-09-09 13:50 . 2010-04-29 13:39 20952 ——a-w- c:\windows\system32\drivers\mbam.sys
2010-09-09 13:46 . 2010-09-09 13:46 109344 ——a-w- c:\users\Nathalie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-09 08:24 . 2010-09-09 08:24 ———— d——-w- c:\program files\Stay On Top
2010-08-30 19:59 . 2009-07-14 17:45 445008 ——a-w- c:\windows\system32\drivers\Wdf01000.sys
2010-08-30 19:59 . 2009-07-14 17:45 38480 ——a-w- c:\windows\system32\drivers\WdfLdr.sys
2010-08-30 19:56 . 2010-08-30 19:56 ———— d——-w- c:\program files\DIFX
2010-08-30 19:55 . 2010-08-30 19:55 ———— d——-w- c:\program files\Common Files\Livescribe
2010-08-30 19:55 . 2010-08-30 19:55 ———— d——-w- c:\users\Nathalie\AppData\Local\Livescribe
2010-08-30 19:54 . 2010-08-30 19:54 ———— d——-w- c:\program files\Livescribe
2010-08-30 19:52 . 2010-08-30 19:57 ———— d——-w- c:\users\Nathalie\AppData\Roaming\Downloaded Installations
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-11 17:09 . 2008-06-30 18:09 ———— d——-w- c:\users\Nathalie\AppData\Roaming\Skype
2010-09-11 17:07 . 2008-06-22 11:56 238432 ——a-w- c:\programdata\nvModes.dat
2010-09-11 17:05 . 2008-05-17 04:27 12 ——a-w- c:\windows\bthservsdp.dat
2010-09-11 16:36 . 2008-06-30 18:10 ———— d——-w- c:\users\Nathalie\AppData\Roaming\skypePM
2010-09-09 08:24 . 2010-09-09 08:24 10134 ——a-r- c:\users\Nathalie\AppData\Roaming\Microsoft\Installer\{5C6C0192-BA75-4932-8931-B2FF88346E49}\_28d27794.exe
2010-09-09 08:24 . 2010-09-09 08:24 10134 ——a-r- c:\users\Nathalie\AppData\Roaming\Microsoft\Installer\{5C6C0192-BA75-4932-8931-B2FF88346E49}\_16dd6dc4.exe
2010-09-04 06:52 . 2008-06-25 04:06 ———— d——-w- c:\program files\Microsoft Silverlight
2010-09-03 20:50 . 2008-05-17 04:55 ———— d——-w- c:\programdata\Dell
2010-08-30 19:59 . 2010-08-30 19:59 0 —-ha-w- c:\windows\system32\drivers\Msft_Kernel_PulseUsb_01009.Wdf
2010-08-30 19:59 . 2010-08-30 19:59 0 —-ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-08-17 18:10 . 2010-09-01 02:37 372736 ———w- c:\programdata\Dell\DSL\DSLCheck.exe
2010-08-11 21:26 . 2008-05-17 04:55 ———— d——-w- c:\program files\Microsoft Works
2010-08-11 21:24 . 2008-08-16 20:54 ———— d——-w- c:\programdata\Microsoft Help
2010-08-11 21:21 . 2006-11-02 11:18 ———— d——-w- c:\program files\Windows Mail
2010-08-06 16:53 . 2010-08-06 16:52 ———— d——-w- c:\program files\iTunes
2010-08-06 16:52 . 2010-08-06 16:52 ———— d——-w- c:\program files\iPod
2010-08-06 16:52 . 2008-07-01 13:29 ———— d——-w- c:\program files\Common Files\Apple
2010-08-06 16:47 . 2010-08-06 16:47 73000 ——a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-08-06 16:46 . 2008-08-03 17:21 ———— d——-w- c:\program files\Safari
2010-08-06 16:45 . 2010-08-06 16:45 72488 ——a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-28 11:32 . 2010-07-28 11:32 1461992 ——a-w- c:\windows\system32\WdfCoInstaller01009.dll
2010-07-28 11:32 . 2010-07-28 11:32 20480 ——a-w- c:\windows\system32\drivers\PulseUsb.sys
2010-07-11 21:06 . 2010-07-11 21:06 354744 ——a-w- c:\users\Nathalie\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdaterInstall.exe
2010-07-11 21:06 . 2010-07-11 21:06 79872 ——a-w- c:\users\Nathalie\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
2010-07-11 21:06 . 2010-07-11 21:06 574344 ——a-w- c:\users\Nathalie\AppData\Roaming\SanDisk\Sansa Updater\SansaUpdater.exe
2010-07-11 19:15 . 2010-07-11 19:15 71992 ——a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-06-26 06:05 . 2010-08-11 17:40 916480 ——a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-11 17:40 71680 ——a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-11 17:40 109056 ——a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-11 17:40 133632 ——a-w- c:\windows\system32\ieUnatt.exe
2010-06-21 13:37 . 2010-08-11 17:39 2037760 ——a-w- c:\windows\system32\win32k.sys
2010-06-19 16:35 . 2008-07-02 09:53 7808 ——a-w- c:\users\Nathalie\AppData\Local\d3d9caps.dat
2010-06-18 17:31 . 2010-08-11 17:38 36864 ——a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-11 17:36 302080 ——a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-11 17:36 144896 ——a-w- c:\windows\system32\drivers\srv2.sys
2010-06-16 16:04 . 2010-08-11 17:36 905088 ——a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-24 16:26 . 2009-10-20 20:18 119808 ——a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2008-05-17 04:44 . 2008-05-17 04:44 74 —sh—r- c:\windows\CT4CET.bin
2008-05-17 12:15 . 2008-05-17 12:06 8192 —sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
“{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}”= “c:\program files\Winamp Toolbar\winamptb.dll” [2009-05-06 1262888]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@=”{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}”
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 04:13 721408 ——a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@=”{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}”
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 04:13 721408 ——a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DellSupport”=“c:\program files\DellSupport\DSAgnt.exe” [2007-03-15 460784]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2008-05-17 68856]
“LaCie Backup”=“c:\program files\LaCie\Backup Software\\LaCieBackup.exe” [2007-12-03 2600960]
“ISUSPM Startup”=“c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2004-06-14 221184]
“ISUSScheduler”=“c:\program files\Common Files\InstallShield\UpdateService\issch.exe” [2006-09-11 86960]
“DellSupportCenter”=“c:\program files\Dell Support Center\bin\sprtcmd.exe” [2009-05-21 206064]
“L08AXLRD_3904876”=“c:\program files\Microsoft Student\Microsoft Student with Encarta Premium 2008 DVD\EDICT.EXE” [2007-05-21 351000]
“LDM”=“c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe” [2008-07-02 32768]
“Picasa Media Detector”=“c:\program files\Picasa2\PicasaMediaDetector.exe” [2008-02-26 443968]
“Google Update”=“c:\users\Nathalie\AppData\Local\Google\Update\GoogleUpdate.exe” [2009-04-21 133104]
“Orb”=“c:\program files\Winamp Remote\bin\OrbTray.exe” [2008-04-01 507904]
“Skype”=“c:\program files\Skype\Phone\Skype.exe” [2010-05-13 26192168]
“SansaDispatch”=“c:\users\Nathalie\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe” [2010-07-11 79872]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-19 1008184]
“ECenter”=“c:\dell\E-Center\EULALauncher.exe” [2008-02-29 17920]
“Apoint”=“c:\program files\DellTPad\Apoint.exe” [2008-01-25 167936]
“OEM02Mon.exe”=“c:\windows\OEM02Mon.exe” [2008-03-04 36864]
“VolPanel”=“c:\program files\Creative\SBAudigy\Volume Panel\VolPanlu.exe” [2006-11-27 180224]
“UpdReg”=“c:\windows\UpdReg.EXE” [2000-05-11 90112]
“PSQLLauncher”=“c:\program files\Fingerprint Reader Suite\launcher.exe” [2007-04-17 49168]
“DELL Webcam Manager”=“c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe” [2007-07-27 118784]
“IAAnotif”=“c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe” [2007-03-21 174872]
“Google Desktop Search”=“c:\program files\Google\Google Desktop Search\GoogleDesktop.exe” [2010-06-24 30192]
“PCMService”=“c:\program files\Dell\MediaDirect\PCMService.exe” [2007-12-21 184320]
“LaCie Shortcut Startup”=“c:\program files\LaCie\Shortcut Button\LaCieShortcutTrayApp.exe” [2007-11-26 270336]
“dscactivate”=“c:\program files\Dell Support Center\gs_agent\custom\dsca.exe” [2008-03-11 16384]
“DellSupportCenter”=“c:\program files\Dell Support Center\bin\sprtcmd.exe” [2009-05-21 206064]
“Logitech Hardware Abstraction Layer”=“KHALMNPR.EXE” [2006-05-10 94208]
“GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe” [2008-10-25 31072]
“Dell DataSafe Online”=“c:\program files\Dell DataSafe Online\DataSafeOnline.exe” [2009-11-13 1807600]
“AppleSyncNotifier”=“c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe” [2010-07-13 47904]
“Windows Mobile-based device management”=“c:\windows\WindowsMobile\wmdSync.exe” [2006-11-02 215552]
“TkBellExe”=“c:\program files\Common Files\Real\Update_OB\realsched.exe” [2009-04-12 198160]
“SunJavaUpdateSched”=“c:\program files\Common Files\Java\Java Update\jusched.exe” [2010-02-18 248040]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2009-06-16 13793824]
“NVHotkey”=“c:\windows\system32\nvHotkey.dll” [2009-06-16 92704]
“BitDefender Antiphishing Helper”=“c:\program files\BitDefender\BitDefender 2010\IEShow.exe” [2009-10-19 71152]
“BDAgent”=“c:\program files\BitDefender\BitDefender 2010\bdagent.exe” [2010-04-01 1123360]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2010-06-20 35760]
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2010-06-09 976832]
“QuickTime Task”=“c:\program files\QuickTime\QTTask.exe” [2010-03-17 421888]
“SigmatelSysTrayApp”=“c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe” [2007-12-03 405504]
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe” [2010-07-21 141608]
c:\users\Nathalie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Stay On Top.lnk - c:\users\Nathalie\AppData\Roaming\Microsoft\Installer\{5C6C0192-BA75-4932-8931-B2FF88346E49}\_16dd6dc4.exe [2010-9-9 10134]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-4 703280]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-7-2 450560]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-9-7 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableLUA”= 0 (0x0)
“DisableCAD”= 1 (0x1)
“EnableUIADesktopToggle”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 04:04 86528 ——a-w- c:\windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=“Service”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
“DisableMonitoring”=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2009-10-19 183880]
R3 DellBIOS;DellBIOS;c:\windows\DellBIOS.Sys [2010-04-06 7168]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-24 30192]
R3 PulseUsb;Livescribe Smartpen USB Driver;c:\windows\system32\DRIVERS\PulseUsb.sys [2010-07-28 20480]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\ianvstor.sys [2007-09-07 209408]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-12-03 73728]
S2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2006-06-29 3712]
S2 PenCommService;Livescribe Smartpen Service;c:\program files\Common Files\Livescribe\PenComm\PenCommService.exe [2010-07-28 444928]
S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-02-10 153448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
bdx REG_MULTI_SZ scan
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier ‘Tâches planifiées’
2010-09-11 c:\windows\Tasks\AutoSmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-01-04 23:07]
2010-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-239197203-1647586574-351346142-1000Core.job
- c:\users\Nathalie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-21 08:14]
2010-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-239197203-1647586574-351346142-1000UA.job
- c:\users\Nathalie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-21 08:14]
.
.
———- Examen supplémentaire———-
.
uInternet Settings,ProxyOverride = *.local
IE: &Winamp; Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Nathalie\AppData\Roaming\Mozilla\Firefox\Profiles\zxi4vbkv.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query;=
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
——PARAMETRES FIREFOX——
c:\program files\Mozilla Firefox\greprefs\all.js - pref(“network.IDN.whitelist.xn—mgbaam7a8h”, true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref(“network.IDN.whitelist.xn—mgberp4a5d4ar”, true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref(“dom.ipc.plugins.enabled”, false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-11 19:07
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d’éléments en démarrage automatique cachés ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\users\Nathalie\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe?D?i?s?k?\?S?a?n?s?a? ?U?p?d?a?t?e?r??????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x9270911B]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8ddb9d24
\Driver\ACPI -> acpi.sys @ 0x80696d68
\Driver\atapi -> ataport.SYS @ 0x84b78a2c
\Driver\iaStor -> iastor.sys @ 0x84adf918
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
——————————- CLES DE REGISTRE BLOQUEES——————————-
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@=“FlashBroker”
“LocalizedString”=”@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
“Enabled”=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@=“c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@=“IFlashBroker4”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@=”{00020424-0000-0000-C000-000000000046}”
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@=”{FAB3E735-69C7-453B-A446-B6823C6DF1C9}”
“Version”=“1.0”
.
——————————- DLLs chargées dans les processus actifs——————————-
- - - - - - - > ‘lsass.exe’(772)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
- - - - - - - > ‘Explorer.exe’(6088)
c:\users\Nathalie\AppData\Local\Temp\IadHide5.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
————————————Autres processus actifs————————————
.
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\BitDefender\BitDefender 2010\vsserv.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Retrospect\Retrospect Express HD 2.0\retrorun.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\STacSV.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\BitDefender\BitDefender 2010\seccenter.exe
c:\windows\system32\conime.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\windows\System32\rundll32.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\Stay On Top\StayOnTop.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Dell Support Center\gs_agent\dsc.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Heure de fin: 2010-09-11 19:17:19 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-11 17:17
ComboFix2.txt 2010-09-11 13:43
Avant-CF: 110 519 013 376 bytes free
Après-CF: 110 478 487 552 bytes free
- - End Of File - - 5A80370EA7C09C4ABFD057C495E28927
Herefter kunne jeg ikke starte nogen af mine tre browsere (fejlmeddelelse: registry key that has been marked for deletion). Jeg foretog download af gmer på USB-nøgle (anden computer). Derefter kopi på skrivebord. Ved forsøg på start af program fremkommer samme fejlmeddelelse: registry key that has been marked for deletion.
Hvis jeg kommer over denne forhindring, hvordan sørger jeg så for, at ingen programmer starter under gmer-scan? Skal jeg åbne alle ikoner i taskbar og lukke programmerne, f.eks.?
Tak igen
Jesper Rasmussen