PC infecté par worm.win32.autorun.spw ?

Bonjour, depuis quelque jour je rencontre des problèmes avec mon pc, j'utilise l'antivirus ORANGE (f-secure) qui me détecte sans arret le virus suivant : worm.win32.autorun.spw.
L'antivirus me demande de le nettoyer mais en vain, le problème persiste.....
Lors de mes recherche sur internet, je suis sans arret redirigé vers d'autres site, et les pages internet defile de haut en bas sans arret à me donner mal à la tête....
J'utilise egalement Ccleaner......

Pourriez vous me donner les démarches a suivre, je ne trouve que des sites en anglais sur ce virus !!!

Encore merci et bonnes fêtes..........
Configuration: Windows XP
Internet Explorer 6.0

9 réponses

  1. Contributeur sécurité
    slt,

    Telecharge UsbFix sur ton bureau
    http://sd-1.archive-host.com/membres/up/116615172019703188/U­sbFix.exe

    --> Lance l installation avec les parametres par default

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Double clic sur le raccourci UsbFix sur ton bureau

    --> Le pc va redémarer

    -->Apres redémarrage post le rapport UsbFix.txt

    Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

    ____________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. Dans un premeir temps, mille merci de m'aider dans cette lourde tâches pour ma part....

      <souligne>Le premeir lien ne marche pas et me donne le textes suivant : </souligne>
      Objet non trouvé !

      L'URL requise n'a pu être trouvée sur ce serveur. Si vous avez tapé l'URL à la main, veuillez vérifier l'orthographe et réessayer.

      Si vous pensez qu'il s'agit d'une erreur du serveur, veuillez contacter un administrateur à cette adresse : archive.host@gmail.com

      Et voici les rapports de RSIT:

      Logfile of random's system information tool 1.05 (written by random/random)
      Run by HP_Propriétaire at 2008-12-30 12:55:48
      Microsoft Windows XP Édition familiale Service Pack 2
      System drive C: has 137 GB (93%) free of 147 GB
      Total RAM: 511 MB (63% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:56:15, on 30/12/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
      C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\keyhook.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
      C:\Program Files\OrangeHSS\Launcher\Launcher.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\2\AlertModule.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\OrangeHSS\systray\systrayapp.exe
      C:\Program Files\OrangeHSS\Deskboard\deskboard.exe
      C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
      C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
      C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
      C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
      C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\FSGK32.EXE
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Orange\AntivirusFirewall\Common\FSMB32.EXE
      c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Orange\AntivirusFirewall\Common\FCH32.EXE
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
      C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
      C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
      C:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
      C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
      C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
      C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\2\FTCOMModule.exe
      C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\21QZA9G7\RSIT[1].exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.orange.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
      O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
      O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: http://*.mappy.com
      O15 - Trusted Zone: http://*.orange.fr
      O15 - Trusted Zone: http://rw.search.ke.voila.fr
      O15 - Trusted Zone: http://orange.weborama.fr
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
      O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\2\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      0
  2. Contributeur sécurité
    usbfix ici:

    http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

    ________________

    mets a jour java: demarrer puis panneau de configuration puis java puis mise a jour

    mets a jour adobe:
    https://www.01net.com/telecharger/windows/Internet/internet_utlitaire/fiches/14537.html

    mets a jour internet explorer:
    https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

    ______________________

    colle un scan en ligne avec un des deux suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr
    0
    1. Voici les résultat pourL'aplication USBfix : changelog Usbfix

      Changelog UsbFix établit le 2 decembre 2008
      outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

      >>>>>>in "ProgramFiles"<<<<<<<<<

      Internet Explorer\Connection Wizard\icwconn1\rada
      Internet Explorer\Connection Wizard\icwconn1\rade
      Internet Explorer\Connection Wizard\icwconn1\radf
      Internet Explorer\Connection Wizard\icwconn1\rad5
      Internet Explorer\Connection Wizard\icwconn1\rad0
      Internet Explorer\Connection Wizard\icwconn1\rad9
      Internet Explorer\Connection Wizard\icwconn1\rad4
      Internet Explorer\Connection Wizard\icwconn1\rad1
      Internet Explorer\Connection Wizard\icwconn1
      Movie Maker\explorer.exe
      Internet Explorer\explorer.exe

      >>>>>>in "Windows"<<<<<<<<<

      autorun.inf
      autorun.exe
      autorun.vbs
      autorun.reg
      autorun.ini
      autorun.fcb
      autorun.bat
      autorun.com
      AdobeR.exe
      Alecks.vbs
      bittorrent.exe
      cmd32.exe
      CwbRmDir.bat
      Fonts\Fonts.exe
      FS6519.dll.vbs
      funny.exe
      GMOGLFEO.exe
      hiqalowo.inf
      icapy.scr
      ilezyvu.bin
      Lany.vbs
      lumy.exe
      manulopa.reg
      MS32DLL.dll.vbs
      MyMP3.vbs
      nar.vbs
      osok.inf
      osotilasiq.pif
      oxafa.com
      qobo.dat
      rundll32.vbe
      sleep.vbe
      SysRes.vbs
      takice.lib
      tusoha.exe
      unahafiwik.exe
      waol.exe
      waziqepehi.ban
      WillPolo.vbs
      Win32DLL.vbs
      win.vbe
      window.exe
      wyzeha.com
      xcopy.exe
      yjilu.inf
      ylacupyb.dll

      RECYCLER\systems.com

      temp\039.tmp

      >>>>>>in "Windows\system32"<<<<<<<<<

      agucuri.vbs
      ahr.exe
      Alecks.vbs
      antinul.vbe
      amvo.exe
      amvo0.dll
      amvo1.dll
      amvo2.dll
      autorun.bat
      Autorun.com
      autorun.exe
      autorun.fcb
      autorun.inf
      autorun.ini
      autorun.reg
      autorun.vbs
      Autoruns.exe
      avpo.exe
      avpo0.dll
      avpo1.dll
      Bitkvo.exe
      Bitkv0.dll
      Bitkv1.dll
      cftmonn.exe
      Christina.jpg
      Christina.vbs
      ckvo.exe
      ckvo0.dll
      ckvo1.dll
      ckvo2.dll
      cradle_of_filth.vbe
      delself.bat
      FS6519.dll.vbs
      GMOGLFEO.exe
      icf.exe.exe
      ie.exe
      jvvo.exe
      jvvo0.dll
      jvvo1.dll
      jvvo2.dll
      jvvo3.dll
      j3ewro.exe
      jwedsfdo0.dll
      jwedsfdo1.dll
      jwedsfdo2.dll
      jwedsfdo3.dll
      jxnraqjxg.exe
      kavo.exe
      kamsoft.exe
      kav0.dll
      kav1.dll
      kav2.dll
      kav3.dll
      kavo0.dll
      kavo1.dll
      kavo2.dll
      kavo3.dll
      kdkfm.exe
      KEYBOARD.exe
      keygen.exe
      kulitut.bat
      kulitut.vbs
      kxvo.exe
      kxvo0.dll
      kxvo1.dll
      kxvo2.dll
      kxvo3.dll
      lExplore.exe
      loader.exe
      logoneui.exe
      LOVE-LETTER-FOR-YOU.HTM
      LOVE-LETTER-FOR-YOU.TXT.vbs
      msfun80.exe
      msime82.exe
      MSKernel32.vbs
      ne0kS.dll.wsf
      ne0kS.exe
      OeApi.vbs
      pubnet.vbs
      rs32net.exe
      SemiAntiVirus.vbs
      Sexy Girls.scr
      SpiderH.bmp
      SpiderH.jpeg
      SpiderH.vbs
      sys.vbs
      Syso.vbs
      SysRes.vbs
      syx.exe
      taso.exe
      tavo.exe
      tavo0.dll
      tavo1.dll
      tavo2.dll
      tavo3.dll
      temp1.exe
      temp2.exe
      temp?.exe
      text.txt
      Ecran.exe
      THe Girls
      tmp.reg
      tmp.txt
      t.txt
      vb@dock.vbs
      vl@dock.vbs
      Win32.vbs
      winudp64.exe

      dllcache\Default.exe

      >>>>>>in "Windows\system32\drivers"<<<<<<<<<

      ._Sanaa style-1 les formes.exe
      0hct8ybw.exe
      1ere partie du projet modifier.exe
      abdelali lahrach.exe
      Analyse transactionnelle.exe
      AutoRun.exe
      Bernoulli01215.exe"
      Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
      Copie de Devoir I.exe
      e-ticket Juba Paris.exe
      fdfp2.exe
      fihi ghizlane Rapport de stage.exe
      graphic.exe
      intel.exe
      isew32.exe
      kheireddine.exe
      le_cadeau_du_sud(1).exe
      LEADERSHIP SKILLS FINAL.exe
      lettre de motivation.exe
      MSDS.exe
      Note.exe
      PREMIER CHAPITRE modifié.exe
      Raila Odinga.exe
      Rapport NADIA.exe
      spectro_masse1.exe
      td de reacteur.exe
      these-223.exe
      xyw9tmdj.exe

      >>>>>>in "Documents and Settings"<<<<<<<<<

      tazebama.dl_
      hook.dl_

      >>>>>>in "appdata"<<<<<<<<<

      fetomiv.vbs
      gumugy.vbs
      jicapikase.vbs
      mobyhikaja.vbs
      nebohozi.com
      orimuwy.exe
      sidymyvig.vbs
      tazebama\tazebama.log
      tazebama\zPharaoh.dat
      tazebama

      >>>>>>in "Temp files"<<<<<<<<<

      1.reg
      2.dll
      6257890.exe
      fq9.dll
      help.exe
      help1.rar
      inst.exe
      system.dll
      w2e.sys
      winhqqo.exe
      wintoift.exe
      xhjb.dll
      xxx6042.exe
      zb5ok.dll

      >>>>>>in "All Drives"<<<<<<<<<

      ._autorun.inf
      autorun.inf
      autorun.ini
      autorun.reg
      autorun.bat
      autorun.vbs
      autorun2.inf
      autosys.exe
      00hoeav.com
      096.bat
      0gjn3yw.exe
      0qx0sc6.bat
      0tmhoc.cmd
      0u.cmd
      0w.com
      0wk2.cmd
      108i.cmd
      1aq1obb.bat
      1bbvq96y.com
      1dg.exe
      1i.com
      1nkbd8h.bat
      1rfw8hjr.com
      1u0o8bnq.cmd
      1weicxa.com
      1XXEC.exe
      22xo.exe
      2ifetri.cmd
      2y8la.exe
      30ed3.exe
      33gmhso.bat
      39lpji.com
      3o.exe
      3wcxx91.cmd
      3xXx31.exe
      4vzjaw3o.sys
      62oop0ak.bat
      68.exe
      6tkoyhx.cmd
      6x8be16.cmd
      8e9gmih.bat
      8ng8w.com
      93vx0c.com
      9yqusig.bat
      22wcb21o.exe
      31n3b2h.exe
      39lpji.com
      80avp08.com
      82r9.cmd
      83fgj.com
      83l3v.cmd
      8df.exe >
      8h3hh3m.exe
      8tss2gwq.bat
      90imhpnc.exe
      92j11sm.com
      9es.com
      a1.bat
      a9.com
      abk.bat
      activexdebugger32.exe
      Administrateur_Fichiers.exe
      admp.exe
      adobeR.exe
      Akon.exe
      Alecks.vbs
      antihost.exe
      antinul.vbe
      aoutfq.exe
      ar.exe
      Atisetup.exe
      auto.exe
      autorum.exe
      AutoRun\Demo.exe
      autorun.exe
      autorun.pif
      autoruns.exe
      AutoScr.exe
      ay8p6v3.cmd
      Ayame.exe
      b3b9u.com
      bicsxk03.com
      bittorrent.exe
      bndafai.exe
      bo1dhu.bat
      bobm.exe
      boot.exe
      bootin.exe
      bplrl98.cmd
      buis.exe
      bwpncb6.com
      bxuup9r.bat c18vk.exe
      c9.com
      c9hehpa.bat
      camp.exe
      cayfq2.cmd
      cd8idoyl.com
      cdr.exe
      ceb6eu98.bat
      cekbru.pif
      clear.bat
      ClickMe.exe
      cftmonn.exe
      cfv90h.com
      Christina.vbs
      cjq.exe
      commands.txt
      comment.htt
      copetttt.com
      copy.exe
      cradle_of_filth.vbe
      cqdis.cmd
      cvqkuk.exe
      d3bn0j.exe
      ddyikr.cmd
      delautorun.bat
      DFD34719171.bat
      DFD34719375.bat
      DFD34719609.bat
      DFD34723328.bat
      DFD34723375.bat
      DFD34723781.bat
      DFD34724390.bat
      DFD34719609.bat
      DFD34724531.bat
      DFD34724656.bat
      DFD34725125.bat
      DFD34725218.bat
      DFD34726312.bat
      DFD34724390.bat
      DFD34726328.bat
      DFD34729609.bat
      DFD34730531.bat
      DFD34730937.bat
      DFD34734937.bat
      DFD34739859.bat
      DFD34741421.bat
      DFD34741734.bat
      DFD34741843.bat
      DFD*.bat
      dhv2u8.cmd
      DPFMate.exe
      dstart.exe
      dtqlv.exe
      dynrn6e.cmd
      e898.com
      e9ehn1m8.com
      eb9ehyh.exe
      Ecran.exe
      ek.com
      ekf6dbg0.com
      ekugb3.bat
      erdeIect.com
      esta ig.vbs
      ev60a2.cmd
      explorer.exe
      exqmmle.exe
      f0.cmd
      f2ir.com
      fe.bat
      ffojc.com
      fi.cmd
      FLIPART.EXE
      folder.exe
      Folder.htt
      fooool.exe
      Form5.exe
      forSV.exe
      FS6519.dll.vbs
      fucker.vbs
      fun.xls.exe
      g2p3s.exe
      g2pfnid.com
      g83816.com
      gdmae.bmp
      Ghost.pif
      gkyzcijfb.exe
      GMOGLFEO.exe
      gqsk.bat
      graphic.exe
      gsxlexd.cmd
      gxlxknou.exe
      gy.cmd
      h0s2.bat h2.com
      hfhludy.exe
      hgu.bat
      hni.cmd
      host.exe
      hsomklg.exe
      hxt9.bat
      i0.cmd
      i8.cmd
      ie.exe
      igxv.cmd
      ij.bat
      ilpg9ejd.com
      info.exe
      infrom.exe
      ino6.com
      install.exe
      intel.exe
      intro.exe
      ipy.cmd
      iq0ecwcj.cmd
      lsass.exe
      itsduel.exe
      iwjj.com
      j4c8t8b5l3a6.exe
      j8q8d.cmd
      jbfqv8j.cmd
      jdhc2x2.com
      jdwx.exe
      jfjsipw.exe
      jfvkcsy.bat
      jiwsxh39.exe
      JJJ.exe
      Jojo.exe
      jwwgtuh.exe
      jxnraqjxg.exe
      jxpiinstall.exe
      k6wkwon2.exe
      ka1nk.bat
      kaq86asx.bat
      kayira.bat
      kbqbptn.exe
      kdkfm.exe
      kdy.cmd
      kfmyoc.pif
      khbph.exe
      killVBS.vbs
      kk3.bat
      KM.exe
      kmd.exe
      kn6jhgc.cmd
      kqnns.exe
      kqsr.exe
      krg62.cmd
      kulitut.bat
      kulitut.vbs
      kxax.cmd
      l2f.cmd
      l9dwu8.bat
      lExplore.exe
      lgcadwx.bat
      lgrncie.bat
      lky.exe
      ln9.exe
      lo.exe
      loader.exe
      logoneui.exe
      Long.exe
      LOVE.PIF
      ltljrg.exe
      lumy.exe
      lurjlnps.exe
      lvxvo1xg.cmd
      m1t8ta.com
      m9j.com
      mail.exe
      manulopa.reg
      mcxa.exe
      Menu.exe
      mgjpcfdg.cm
      mnl6on3.com
      mp.bat
      mp.cmd
      mp.com
      Movie1.exe
      mrsne.bat
      MS-DOS.com
      MS32DLL.dll.vbs
      MSd040.vbs
      MSdC64.vbs
      MSdFB7.vbs
      MSd141.vbs
      MSd191.vbs
      MSd49A.vbs
      MSdE78.vbs
      MSd*.vbs
      mshta.exe
      MSKernel32.vbs
      muniu.exe
      MyMP3.vbs
      n1detect.com
      n2de.cmd
      n6j.com
      n6j6pc0.com
      n6t1h.cmd
      nansy ajram.vbs
      nar.vbs
      ne0kS.exe
      nemesis.exe
      nemesis.inf
      nfdmg.com
      nideiect.com
      niu.exe
      njibyekk.com
      nl.com
      nncu6kk.com
      NoLimit.exe
      np.exe
      nq0cq.cmd
      nqvarn.pif
      nriljal.exe
      ntde1ect.com
      ntdelect.com
      nq.bat
      nq0cq.cmd
      nqgcd.com
      nsv.bat
      nw0t1l0d.exe
      o2yf0w.bat
      o9o2u.bat
      o6opnro.bat
      OeApi.vbs
      oegbi.exe
      ogcikeq.com
      oka3yrf.bat
      oq.cmd
      oskkofa.exe
      osotilasiq.pif
      osy3.sys
      otyh.cmd
      oufddh.exe
      oxafa.com
      p3r1ud.exe
      p83gjy.exe
      p9.exe
      pa39xth.cmd
      pagefile.pif
      pbwkwj.com
      pefbutr.exe
      pkxfkrki.bat
      ph.com
      phgr1j.bat
      phim_nguoi_lon.exe
      pnc.exe
      prhyper.exe
      psqrhqn.exe
      pxka.exe
      q3v.com
      q83iwmgf.bat
      q8sywiva.cmd
      qcwpung.exe
      qd.cmd
      qjfl.exe
      qkarc.exe
      qquq.bat
      qqzjnhuoi.exe
      qpe6.com
      qobo.dat
      qrkugxtw.exe
      qxbx9blb.com
      r1y1.bat
      r2nl.com
      r6r.exe
      r813.bat
      Raila Odinga.exe
      Raila Odinga.gif
      ranvrgn.exe
      ravmon.exe
      ravmon.log
      ReadMe.exe
      RecInfo\RecInfo.exe
      Recycle.exe
      Recycled\ctfmon.exe
      RECYCLED\INFO.exe
      Recycled.exe
      RECYCLER\Lock Folder.exe
      RECYCLER\RECYCLER.exe
      RECYCLER\*.exe
      regxpcom.exe
      resycled\boot.com
      resycled\ctfmon.exe
      revo.exe
      rggbw.exe
      rjiybg.exe
      rn.exe
      rombkaewl.exe
      rosftpm.exe
      rqq2v.bat
      rs.cmd
      rt.exe
      Run.exe
      runaut~1\autorun.pif
      RunDll32.exe
      rxukgcm.exe
      s38k.exe
      sal.xls.exe
      sasyg1y8.com
      script.bat
      scriptlo.txt
      scvhosts.exe
      sdcvhost.exe
      SemiAntiVirus.vbs
      smkjd.cmd
      smss.exe
      semo2x.exe
      spq.bat
      serivces.exe
      server.exe
      server.inf
      Sex City.jpg.wsf
      sowar.vbs
      SpiderH.vbs
      sq.com
      sqlserv.exe
      SSVICHOSST.exe
      stwi.com
      svch0st.exe
      scvhosts.exe
      svdioajm.cmd
      sxs.exe
      sydp.exe
      sys.vbs
      Syso.vbs
      SysRes.vbs
      system.exe
      system32.exe
      systems.com
      systems.exe
      t82e2v.cmd
      TAE7ESLP.exe
      taipingtianguov1.1.exe
      takice.lib
      tel.xls.exe
      temp.bat
      temp.exe
      temp.temp
      temp1.exe
      temp2.exe
      test.exe
      testfile.bat
      testflo.bat
      tfk8.exe
      The_Cars.vbs
      THe Girls
      tknapl.exe
      tknn6.bat
      tmf3w3g0.com
      TMMDW8LP.exe
      Toy.exe
      tusoha.exe
      tyktjfww.exe
      u18vxqle.com
      u6k.cmd
      u9dyi.exe
      udnnnvq.exe
      UFO.exe
      ufuaugwq.exe
      uis.com
      uis.exe
      um.cmd
      un9.cmd
      unahafiwik.exe
      UnplugDrive.exe
      uorys.cmd
      update.exe
      uqhqx1.cmd
      usdeiect.com
      userinit.exe
      utdetect.com
      uxdeiect.com
      u?de?ect.com
      v2h3.exe
      v3pif.bat
      VB6FR.DLL
      vb@dock.vbs
      vfpkkbq.exe
      vksucydrh.exe
      vl@dock.vbs
      vmhr.bat
      vmyphd.bat
      vva0hc0p.cmd
      vxl.exe
      w0o.com
      w0owgn.bat
      w32sys.exe
      w3dn9f.bat
      waziqepehi.ban
      wa6.vbs
      Wallpaper.vbs
      WallpaperMEHDI.vbs
      wfhth.exe
      whi.com
      WillPolo.vbs
      WINDOWS.EXE
      Windows.scr
      winfile.exe
      winglogon.exe
      winrun.vbs
      winstall.exe
      wjlfhtfm.cmd
      wol.exe
      wsctf.exe
      wtbcccq.exe
      x0.cmd
      XAdeIect.com
      xcopy.exe
      xfoolavp.com
      xih9.cmd
      xj.bat
      xk2n.bat
      xlk9.com
      xlu8a8sy.exe
      xmnm2.cmd
      xn1i9x.com
      xnynrnh.exe
      xo8wr9.exe
      xp19.com
      xpbkh.com
      xqf.com
      xvlyb.exe
      xyhav.pif
      y82td3td.com
      ybj8df.exe
      yew.bat
      yg.cmd
      yjilu.inf
      ylacupyb.dl
      ylr.exe
      yjkjfuo.cmd
      yjvmtaa.exe
      ynfs9ks.cmd
      yssjnngm.cmd
      yvmkdwn.exe
      zPharaoh.exe
      0.cmd
      1.cmd
      2.cmd
      3.cmd
      4.cmd
      5.cmd
      6.cmd
      7.cmd
      8.cmd
      9.cmd
      0.bat
      1.bat
      2.bat
      3.bat
      4.bat
      5.bat
      6.bat
      7.bat
      8.bat
      9.bat
      0.exe
      1.exe
      2.exe
      3.exe
      4.exe
      5.exe
      6.exe
      7.exe
      8.exe
      9.exe
      0.com
      1.com
      2.com
      3.com
      4.com
      5.com
      6.com
      7.com
      8.com
      9.com
      0.vbs
      1.vbs
      2.vbs
      3.vbs
      4.vbs
      5.vbs
      6.vbs
      7.vbs
      8.vbs
      9.vbs
      a.com
      b.com
      c.com
      d.com
      e.com
      f.com
      g.com
      h.com
      i.com
      j.com
      k.com
      l.com
      m.com
      n.com
      o.com
      p.com
      q.com
      r.com
      s.com
      t.com
      u.com
      v.com
      w.com
      x.com
      y.com
      z.com
      a.bat
      b.bat
      c.bat
      d.bat
      e.bat
      f.bat
      g.bat
      h.bat
      i.bat
      j.bat
      k.bat
      l.bat
      m.bat
      n.bat
      o.bat
      p.bat
      q.bat
      r.bat
      s.bat
      t.bat
      u.bat
      v.bat
      w.bat
      x.bat
      y.bat
      z.bat
      a.cmd
      b.cmd
      c.cmd
      d.cmd
      e.cmd
      f.cmd
      g.cmd
      h.cmd
      i.cmd
      j.cmd
      k.cmd
      l.cmd
      m.cmd
      n.cmd
      o.cmd
      p.cmd
      q.cmd
      r.cmd
      s.cmd
      t.cmd
      u.cmd
      v.cmd
      w.cmd
      x.cmd
      y.cmd
      z.cmd
      a.exe
      b.exe
      c.exe
      d.exe
      e.exe
      f.exe
      g.exe
      h.exe
      i.exe
      j.exe
      k.exe
      l.exe
      m.exe
      n.exe
      o.exe
      p.exe
      q.exe
      r.exe
      s.exe
      t.exe
      u.exe
      v.exe
      w.exe
      x.exe
      y.exe
      z.exe
      a.vbs
      b.vbs
      c.vbs
      d.vbs
      e.vbs
      f.vbs
      g.vbs
      h.vbs
      i.vbs
      j.vbs
      k.vbs
      l.vbs
      m.vbs
      n.vbs
      o.vbs
      p.vbs
      q.vbs
      r.vbs
      s.vbs
      t.vbs
      u.vbs
      v.vbs
      w.vbs
      x.vbs
      y.vbs
      z.vbs
      *.dll.vbs

      >>Dossiers :

      AutoRun
      autorun.inf
      fsc.tmp
      RecInfo
      Recycled\Recycled
      Recycler\Recycler
      resycled
      runaut~1
      sdlflzoip

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Window Title"=-
      "Start Page"=-
      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
      "Start Page"="https://www.msn.com/fr-fr"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "fucker"=-
      "SysDir"=-
      "ms32dll"=-
      "cftmonn"=-
      "Lany"=-
      "Zip"=-
      "RavAV"=-
      "cmd32"=-
      "Install.exe"=-
      "FIXEDFON.FON"=-
      "MS-RAD0"=-
      "MS-RAD1"=-
      "MS-RAD2"=-
      "MS-RAD3"=-
      "MS-RAD4"=-
      "MS-RAD5"=-
      "MS-RAD6"=-
      "MS-RAD7"=-
      "MS-RAD8"=-
      "MS-RAD9"=-
      "MS-RADA"=-
      "MS-RADB"=-
      "MS-RADC"=-
      "MS-RADD"=-
      "MS-RADE"=-
      "MS-RADF"=-
      "MS-RADG"=-
      "MS-RADH"=-
      "MS-RADI"=-
      "MS-RADJ"=-
      "MS-RADK"=-
      "MS-RADL"=-
      "MS-RADM"=-
      "MS-RADN"=-
      "MS-RADO"=-
      "MS-RADP"=-
      "MS-RADQ"=-
      "MS-RADR"=-
      "MS-RADS"=-
      "MS-RADT"=-
      "MS-RADU"=-
      "MS-RADV"=-
      "MS-RADW"=-
      "MS-RADX"=-
      "MS-RADY"=-
      "MS-RADZ"=-
      " "=-
      "winrun.dll"=-
      "loader.exe"=-
      "recinfo49"=-
      "System"=-
      "System Updater Machine"=-
      "SpiderH"=-
      "winudp64.exe"=-
      "System12"=-
      "System64"=-
      "IMJPMIG8.2"=-
      "CARPService"=-
      "039.tmp"=-
      "userd"=-
      "nar"=-
      "MSKernel32"=-
      "WillPolo"=-
      "MyMP3"=-
      "FS6519"=-
      "Windows\SysRes.vbs"=-
      "SysRes"=-
      "Raila Odinga"=-
      "reginit"=-
      "lnternet Update"=-
      "GMOGLFEO"=-
      "WintelUpdate"=-
      "Pubnet"=-
      "antihost"=-

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
      "System Updater Machine"=-
      "Win32DLL"=-
      "lnternet Update"=-

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
      " "=-

      [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "kamsoft"=-
      "amva"=-
      "kava"=-
      "tava"=-
      "avpa"=-
      "internet_explorer"=-
      "anti-virus 2007"=-
      "Mp3 player"=-
      "kxvo"=-
      "EXPLORER.EXE"=-
      "wsctf.exe"=-
      "loader.exe"=-
      "jvvo"=-
      "taso"=-
      "Avg_AntiHost"=-
      "jvsoft"=-
      "tasoft"=-
      "SpiderH"=-
      "MsServer"=-
      "MSFox"=-
      "msn"=-
      "????r"=-
      "Windows Update"=-
      "Microsoft Debug Manager"=-
      "protect_autorun"=-
      "Le Petit Robert Hyperappel"=-
      "firewall 2008"=-
      " "=-

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
      " "=-

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
      "test"=-
      "Msn"=-
      "MsnHost"=-
      "MsnLoad"=-
      "MsnConvert"=-
      "MsnMessendger"=-
      "sys"=-

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "DefaultUserName"=-
      "LegalNoticeCaption"=-
      "LegalNoticeText"=-

      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

      -------------------------------------------------------------------------------------------------------------

      Mises a jours du 5 decembre 2008

      >>>>>>in "All Drives"<<<<<<<<<

      6xdgw26.com
      6xig.com
      8386nac.com
      8e.com
      8u.com
      8uot.exe
      arun.exe
      asneg.com
      bpu.exe
      br1e.com
      cdwfql2v.com
      ceqfqp.bat
      cm0.com
      d1y36.com
      dh66ln.cmd
      dpu1.exe
      dyr2j6mv.exe
      ermvu8.cmd
      fblfnthuh.exe
      fn20.exe
      fufb6tq3.cmd
      g2o1n.exe
      gx.com h3hi1k3.exe
      i8.com
      ivcvknr.bat
      jv.exe
      kernel32.dll.vbs
      kg2v.com
      klp8j6i.com
      ktnquo.exe
      l1.cmd
      lp3c.bat
      m0g8sqx.cmd
      m6dqm2vd.exe
      m8wafly.com
      m9as2c.cmd
      MicrosoftPowerPoint.exe
      MSd30D.vbs
      msnmsgr_plus.exe
      ncyrf.bat
      ntdeIect.com
      ntnq.exe
      ntphyy.com
      NTsys.exe
      o6pq1n8.com
      okhr.exe
      ous.exe
      ox.cmd
      p1f6b.exe
      program.exe
      qeoc6sj.exe
      qwultj1.bat
      rcukd.cmd
      rdsfk.com
      rjx0.exe
      rqb0v2ot.bat
      scene.exe
      Server082.exe
      tigi.cmd
      uh31.exe
      uwlmj.com
      uxkktr.cmd
      vd91t29.exe
      w2qagd.com
      welcome.exe
      WindowsXP.exe
      winsys3.exe
      ypjq1.cmd

      .MGT_reg32.dll.vbs
      achitasin.dll.vbs
      autoupdate.dll.vbs
      bat32.txt
      happy.vbs
      ie.vbs
      killgodzilla.vbs
      maskrider.dll.vbs
      maskrider2001.vbs
      msiexec.dll.vbs
      MsUpdate.sys.vbs
      nohack.vbs
      RUNDLL64.dll.vbs
      setup.dll.vbs
      VBRuntime32.dll.vbs
      viva.dll.vbs
      Win32.dll.vbs
      winconfig.dll.vbs
      xepet.html
      xepet.txt

      >>>>>>in "Windows"<<<<<<<<<

      .MGT_reg32.dll.vbs
      achitasin.dll.vbs
      autoupdate.dll.vbs
      bat32.txt
      boot.ini
      happy.vbs
      ie.vbs
      killgodzilla.vbs
      maskrider.dll.vbs
      maskrider2001.vbs
      msiexec.dll.vbs
      MsUpdate.sys.vbs
      nohack.vbs
      RUNDLL64.dll.vbs
      setup.dll.vbs
      VBRuntime32.dll.vbs
      viva.dll.vbs
      Win32.dll.vbs
      winconfig.dll.vbs
      xepet.html
      xepet.txt

      >>>>>>in "Windows\system32"<<<<<<<<<

      kdyul.exe
      gasretyw0.dll
      gasretyw1.dll
      gasretyw2.dll
      gasretyw3.dll
      DC4491.DLL

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Winboot"=-

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "UC"=-
      "r4n694-24y"=-
      "kernel32"=-
      "MSConfigs"=-
      "Microsoft"=-
      "MGT_reg"=-
      "Winboot"=-
      "Winamp"=-
      "Macromedia"=-
      "WINFIX"=-
      "winconfig"=-
      "Achitasin"=-
      "mcafee"=-
      "wscript32dll"=-
      "Batch32"=-
      "maskrider"=-
      "autoupdate"=-
      "KILLMS32DLL"=-
      "WinExpress"=-
      "WinDebugger"=-
      "C:\WINDOWS\system32\kdyul.exe"=-

      mises a jours du 6 Décembre 2008

      >>>>>>in "All Drives"<<<<<<<<<

      lgrncie.bat
      info.bat
      iqosrtk.bat
      0oyl662q.cmd
      eb.bat
      New Folder.exe
      Setup_ver1.1779.2.exe
      Setup_ver*.exe

      >>>>>>in "Windows"<<<<<<<<<

      SSVICHOSST.exe

      >>>>>>in "Windows\system32"<<<<<<<<<

      SSVICHOSST.exe
      kdxkt.exe
      kdjay.exe
      kdwzh.exe
      msiconf.exe

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      "MsUpdate"=-
      "C:\WINDOWS\system32\kdxkt.exe"=-
      "C:\WINDOWS\system32\kdjay.exe"=-
      "C:\WINDOWS\system32\kdwzh.exe"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      "msiexec.exe"=-
      "Yahoo Messengger"=-

      mises a jours du 11 Décembre 2008

      >>>>>>in "All Drives"<<<<<<<<<

      Secret.exe
      hupxj.bat
      fphj6j31.bat
      shell.exe
      Installer.exe
      fvbk.exe
      snaoc9i.exe
      bt8vuaw.com
      wjlc.exe
      6fnlpetp.exe
      g8rruyw.exe
      o1.com
      yannh.cmd
      1t6yxlxx.cmd
      2h60k.cmd
      3rl3lqbq.bat
      ewatr.cmd
      Maradona.exe
      iw.bat
      m2nl.bat
      ov.cmd
      pnt.com
      t1ypkh.exe
      grgarevn.inf
      microsvn.inf
      refsanvn.inf
      Zidan vs Tito.exe
      desktop.exe
      omsirutnarg.exe
      Alisa.exe
      blazzers.exe
      burimi.exe
      nfd.exe
      repppp.exe
      wax.exe
      wny.exe
      msv2008.exe
      GETBOOTD.BAT
      tbm9.bat
      08dgu.com

      >>>>>>in "Windows\system32"<<<<<<<<<

      vamsoft.exe
      vbsdfe0.dll
      vbsdfe1.dll
      vbsdfe2.dll
      vbsdfe3.dll
      syx.exe

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      "Host Process for Windows Services"=-
      "Advanced DHTML Enable"=-

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
      "Host Process for Windows Services"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
      "Runonce"=-
      "vamsoft"=-

      mises a jours du 17 Décembre 2008

      >>>>>>in "Windows"<<<<<<<<<

      pagefile.sys.vbs
      backinf.tab
      session.exe
      startup.vbs
      KAT.vbs
      explorar.vbs

      help\destrukto.vbs
      inf\destrukto.vbs
      registration\destrukto.vbs

      >>>>>>in "Windows\system32"<<<<<<<<<

      filekan.exe
      socksa.exe
      KAT.vbs
      destrukto.vbs
      security.vbs
      explorar.vbs
      destrukto.html

      >>>>>>in "Windows\system32\drivers"<<<<<<<<<

      Memoire Jeff EYEGHE.exe

      >>>>>>in "All Drives"<<<<<<<<<

      .\Recycled\Driveinfo.exe
      m9ma.exe
      JIM.exe
      iri.exe
      lol.exe
      mpsn.exe
      pagefile.sys.vbs
      al.xls.exe
      MDM.EXE
      RavManE.exe
      iexp1ore.exe
      msvcr71.dll
      BSserver
      FileKan.exe
      ASocksrv.exe
      algsrv.exe
      BACKINF.TAB
      ufdata2000.log
      twunk32.exe
      windhcp.ocx
      algssl.exe
      msfir80.exe
      msime80.exe
      destrukto.vbs
      Xsfr.exe
      Zser.exe
      THUMBS.DB.COM
      KAT.vbs
      startup.vbs
      THUMBS.DB
      MrHelloween.scr
      mig2.exe
      Perso_Stress.exe
      msfun80.exe
      IMJPMIG8.2
      msime82.exe
      IMJPMIG8.1
      algsrvs.exe
      pr2.exe
      sdfgh.exe
      p1y2.cmd h3.bat
      session.exe
      explorar.vbs
      security.vbs

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "MSRegInfo"=-
      "ASocksrv"=-
      "Startup"=-
      "Explorer"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "BSserver"=-

      Mises a jours de 21 decembre 2008

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "zakariag"=-

      >>>>>>in "Windows"<<<<<<<<<

      csrss.exe

      >>>>>>in "Windows\system32"<<<<<<<<<

      GG.bat
      install.exe

      >>>>>>in "All Drives"<<<<<<<<<

      yt8a.exe
      log.exe
      iri.exe
      okea.exe
      system43.exe
      system9.exe
      xx.exe
      recycled\sirc32.exe
      iky.bat
      GuelmimG.bat

      Mises a jours de 23 decembre 2008

      >>>>>>in "Windows"<<<<<<<<<

      help.exe
      mg.exe

      >>>>>>in "Windows\system32"<<<<<<<<<

      kav320.dll
      kav321.dll
      kav322.dll
      mldmm.exe
      spooIsv.exe
      system.exe

      >>>>>>in "Temp files"<<<<<<<<<

      help.rar
      nodB.tmp

      >>>>>>in "appdata"<<<<<<<<<

      addon.dat
      CISxCC.tmp
      ISxCB.tmp
      ISx97.tmp

      >>>>>>in "All Drives"<<<<<<<<<

      MSd355.vbs
      xrdygg.bat
      MSd48F.vbs
      bold.log
      qthqdso.exe
      mguvbfr.exe
      kxhvehm.exe
      msvsc.exe
      2w.cmd
      x0.com
      u2.cmd
      je26200.com
      lkxcqdb.bat
      gr06t.cmd
      xfl3hx.exe
      1gk8ha.bat
      sucksa.exe

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
      "mmsass"=-
      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
      "mmsass"=-
      "Spooler SubSystem App"=-

      Mises a jours de 24 decembre 2008 ( Feliz Navidad )

      >>>>>>in "Windows"<<<<<<<<<

      system32.exe

      >>>>>>in "Windows\system32"<<<<<<<<<

      dse235rgd1.dll
      kavo.exe
      kavo0.dll
      kavo1.dll
      kavo2.dll
      kavo3.dll
      wedasgads0.dll
      wedasgads1.dll
      wedasgads2.dll
      wedasgads3.dll
      WS2Fix.exe
      VCCLSID.exe
      VACFix.exe
      swxcacls.exe
      swsc.exe
      swreg.exe
      SrchSTS.exe
      Process.exe
      o4Patch.exe
      IEDFix.exe
      IEDFix.C.exe
      dumphive.exe
      Agent.OMZ.Fix.exe
      404Fix.exe

      >>>>>>in "All Drives"<<<<<<<<<

      6j2j.com
      iok.exe
      MSd05E.vbs
      MSd329.vbs
      wi.com
      ab31.exe

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "EXPLORER.EXE"=-
      "wsctf.exe"=-

      Mises a jours du 27 Décembre 2008

      >>>>>>in "Windows"<<<<<<<<<

      admintxt.txt
      u.bat
      u.vbe
      s.vbe

      >>>>>>in "Windows\system32"<<<<<<<<<

      temp#01.exe
      dse235rgd0.dll
      dse235rgd2.dll
      dse235rgd3.dll

      >>>>>>in "Temp files"<<<<<<<<<

      pa.exe

      >>>>>>in "All Drives"<<<<<<<<<

      reps.exe
      bud3.bat
      sjqkci.cmd
      hehe.exe
      oskie.exe
      u.vbe
      Knight.exe
      sss.exe
      x6.bat
      sokeie.exe
      sucker.exe
      fhrqdpi.exe
      plugin.exe
      s.vbe

      >>>>>>"Registry"<<<<<<<<<

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "vbe"=-

      PAR CONTRE ikl m'est impossible de mettre a jour interner explorer 7, lors de l'instalation il me demande de redémarrer le PC car l'instalation a échoué, je doit donc utiliser le raccourci, met leur méthode m'ont l'air bien compliqué, il me demande de démarre le PC en mode minimal pour pouvoir l'installer. Est ce normal ?
      0
      1. PAR CONTRE ikl m'est impossible de mettre a jour interner explorer 7, lors de l'instalation il me demande de redémarrer le PC car l'instalation a échoué, je doit donc utiliser le raccourci, met leur méthode m'ont l'air bien compliqué, il me demande de démarre le PC en mode minimal pour pouvoir l'installer. Est ce normal ?

        Voici le lien du raccourci :
        https://support.microsoft.com/en-us/help/917925
        0
        1. Contributeur sécurité
          c'est pas le bon rapport usbfix tu peut refaire pour voir?

          puis

          colle un scan en ligne avec un des deux suivants:

          bitdefender en ligne :
          http://www.bitdefender.fr/scan_fr/scan8/ie.html

          Panda en ligne :
          http://pandasoftware.fr

          pour internet explorer on verra après
          0
          1. Voici le nouveau rapport Usbfix qui doit etre le bon, ainsi que le rapport du scan effectué par activescan qui suite au scan à detecter 1 virus et qui me l'a apparement désinfecter.
            Les disques dur sont t'il vraiment désinfecter ?
            Que dois-je faire pour internet explorer ? Est t'il important de télécharger la derniere version ?

            Usbfix

            -------------- UsbFix V2.413.8 ---------------

            * User : HP_Propri‚taire - NOM-641695C7437
            * Outils mis a jours le 27/12/2008 par Chiquitine29 et Chimay8
            * Recherche effectuée à 16:55:36 le 30/12/2008
            * Windows Xp - Internet Explorer 6.0.2900.2180

            --------------- [ Processus actifs ] ----------------

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\logonui.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\userinit.exe
            C:\WINDOWS\Explorer.EXE

            --------------- [ Informations lecteurs ] ----------------

            C: - Lecteur fixe

            D: - Lecteur fixe

            E: - Lecteur de CD-ROM

            J: - Lecteur fixe

            +- Contenu de l'autorun : C:\autorun.inf

            [autorun]
            ;fieixyjuwtc
            shellexecute="resycled\boot.com c:"
            ;ohoqjnhvscwjqtqsommjnsadngdvbrogdeirwfmizaxtpzbszrvyhgwevkwiqkwnzvmistsuqzkqhbmhfnfdke
            shell\Open\command="resycled\boot.com c:"
            ;qdahycrwicbaevnmlzdprrcnlciufakpfcxhwvagxayggyuosjsc
            shell=

            +- Contenu de l'autorun : D:\autorun.inf

            [autorun]
            ;nflwclhcidnuezyxkonxmnsgarpjqligsatdtqidjyhizssxnftqcntrzersajyjc
            shellexecute="resycled\boot.com d:"
            ;szicfkuutwakdribnraeuditkmzt
            shell\Open\command="resycled\boot.com d:"
            ;zxyrsirqymaklejees
            shell=Open
            ;utisvjkaxqmcrffherlpfzxwkgimimm

            +- Contenu de l'autorun : J:\autorun.inf

            [autorun]
            ;dgnvyrohrjiwphoipftpzxesgirhcbuyzgpdamhticaxskkt
            shellexecute="resycled\boot.com j:"
            ;zcenlaxm
            shell\Open\command="resycled\boot.com j:"
            ;objsglpbjlzkveyczanxjcjdovnirqjsctyrjcallyudgaoheffojqmjxreqqexewnbyjhsesre
            shell=Open
            ;awonuvzxkln

            --------------- [ Lecteur C ] ----------------

            C: - Lecteur fixe

            +- Listing des fichiers présents :

            [01/01/2004 14:06][--a------] C:\AUTOEXEC.BAT
            [05/08/2004 04:00][-rahs----] C:\NTDETECT.COM
            [29/12/2008 11:11][-rahs----] C:\boot.ini
            [30/12/2008 16:19][-r-hs----] C:\autorun.inf
            [29/12/2008 23:05][--a------] C:\log_lobby.txt
            [29/12/2008 23:05][--a------] C:\log_lobby_dumper.txt
            [29/12/2008 23:05][--a------] C:\UsbFix.txt
            [01/01/2004 14:06][--a------] C:\CONFIG.SYS
            [01/01/2004 14:06][--a------] C:\hiberfil.sys
            [01/01/2004 14:06][--a------] C:\IO.SYS
            [01/01/2004 14:06][--a------] C:\MSDOS.SYS
            [01/01/2004 14:06][--a------] C:\pagefile.sys

            --------------- [ Lecteur D ] ----------------

            D: - Lecteur fixe

            +- Listing des fichiers présents :

            [27/07/2001 22:07][---hs----] D:\AUTOEXEC.BAT
            [25/07/2001 14:00][---hs----] D:\NTDETECT.COM
            [30/04/2004 14:00][---hs----] D:\Info.exe
            [30/04/2004 14:00][---hs----] D:\setupSNK.exe
            [09/01/2002 11:52][---hs----] D:\BOOT.INI
            [09/01/2002 11:52][---hs----] D:\Desktop.ini
            [09/01/2002 11:52][---hs----] D:\WINBOM.INI
            [30/12/2008 16:20][-r-hs----] D:\autorun.inf
            [10/09/2002 09:21][---hs----] D:\Folder.htt
            [27/07/2001 22:07][---hs----] D:\CONFIG.SYS
            [27/07/2001 22:07][---hs----] D:\IO.SYS
            [27/07/2001 22:07][---hs----] D:\MSDOS.SYS
            [27/07/2001 22:07][---hs----] D:\RCBoot.sys

            --------------- [ Lecteur E ] ----------------

            E: - Lecteur de CD-ROM

            +- Listing des fichiers présents :

            --------------- [ Lecteur J ] ----------------

            J: - Lecteur fixe

            +- Listing des fichiers présents :

            [07/03/2001 19:11][--a------] J:\WINWORD.EXE
            [30/12/2008 16:20][-r-hs----] J:\autorun.inf

            --------------- [ Registre / Startup ] ----------------

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Search Page"="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop"
            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
            hpsysdrv=c:\windows\system\hpsysdrv.exe
            HPHUPD06=c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
            HPHmon06=C:\WINDOWS\system32\hphmon06.exe
            KBD=C:\HP\KBD\KBD.EXE
            Home Theater SchSvr="C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
            WINREMOTE="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
            iTunesHelper=C:\Program Files\iTunes\iTunesHelper.exe
            Recguard=C:\WINDOWS\SMINST\RECGUARD.EXE
            NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            nwiz=nwiz.exe /installquiet /keeploaded /nodetect
            VTTimer=VTTimer.exe
            SiS Windows KeyHook=C:\WINDOWS\system32\keyhook.exe
            PS2=C:\WINDOWS\system32\ps2.exe
            SSC_UserPrompt=c:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
            AGRSMMSG=AGRSMMSG.exe
            AlcxMonitor=ALCXMNTR.EXE
            Reminder="C:\Windows\Creator\Remind_XP.exe"
            ORAHSSSessionManager=C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
            F-Secure Manager="C:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
            F-Secure TNB="C:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
            Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
            Installed=1
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
            NoChange=1
            Installed=1
            <NO NAME>=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
            Installed=1
            <NO NAME>=

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=dword:00000091

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

            --------------- [ Registre / Mountpoint2 ] ----------------

            -> Recherche négative.

            --------------- [ Nettoyage des disques ] ----------------

            C:\autorun.inf ~> fichier appelé : "C:\"resycled\boot.com c:"" ( absent ! )
            D:\autorun.inf ~> fichier appelé : "D:\"resycled\boot.com d:"" ( absent ! )
            J:\autorun.inf ~> fichier appelé : "J:\"resycled\boot.com j:"" ( absent ! )
            Supprimé ! - [30/12/2008 16:19][-r-hs----] C:\autorun.inf
            Supprimé ! - [20/12/2008 19:12][-r-hs----] C:\resycled\boot.com
            Supprimé ! - [30/12/2008 16:55][dr-hs----] C:\resycled
            Supprimé ! - [30/12/2008 16:20][-r-hs----] D:\autorun.inf
            Supprimé ! - [10/09/2002 09:21][---hs----] D:\Folder.htt
            Supprimé ! - [30/04/2004 14:00][---hs----] D:\info.exe
            Supprimé ! - [20/12/2008 19:12][-r-hs----] D:\resycled\boot.com
            Supprimé ! - [24/12/2008 12:16][dr-hs----] D:\resycled
            Supprimé ! - [30/12/2008 16:20][-r-hs----] J:\autorun.inf
            Supprimé ! - [20/12/2008 19:12][-r-hs----] J:\resycled\boot.com
            Supprimé ! - [17/10/2007 22:59][--ahs----] J:\THUMBS.DB
            Supprimé ! - [24/12/2008 12:16][dr-hs----] J:\resycled

            --------------- [ Resumé ] ----------------

            -> /!\ Le resultat doit etre interprété par un spécialiste /!\

            [01/01/2004 14:06][--a------] C:\AUTOEXEC.BAT
            [05/08/2004 04:00][-rahs----] C:\NTDETECT.COM
            [29/12/2008 11:11][-rahs----] C:\boot.ini
            [27/07/2001 22:07][---hs----] D:\AUTOEXEC.BAT
            [25/07/2001 14:00][---hs----] D:\NTDETECT.COM
            [04/08/2004 00:55][--a------] D:\setupSNK.exe
            [09/01/2002 11:52][---hs----] D:\BOOT.INI
            [09/01/2002 11:52][---hs----] D:\Desktop.ini
            [09/01/2002 11:52][---hs----] D:\WINBOM.INI
            [07/03/2001 19:11][--a------] J:\WINWORD.EXE

            --------------- ! Fin du rapport ! ----------------

            Activescan

            ;***********************************************************************************************************************************************************************************
            ANALYSIS: 2008-12-30 18:05:42
            PROTECTIONS: 2
            MALWARE: 1
            SUSPECTS: 0
            ;***********************************************************************************************************************************************************************************
            PROTECTIONS
            Description Version Active Updated
            ;===================================================================================================================================================================================
            F-Secure Antivirus 7.44 No Yes
            F-Secure Internet Security 6.16 No No
            ;===================================================================================================================================================================================
            MALWARE
            Id Description Type Active Severity Disinfectable Disinfected Location
            ;===================================================================================================================================================================================
            02919763 Trj/Downloader.MDW Virus/Trojan No 0 Yes No J:\System Volume Information\_restore{A51C5CDE-3710-45ED-AEAF-4DBEE7E77752}\RP5\A0001156.EXE
            ;===================================================================================================================================================================================
            SUSPECTS
            Sent Location V
            ;===================================================================================================================================================================================
            ;===================================================================================================================================================================================
            VULNERABILITIES
            Id Severity Description V
            ;===================================================================================================================================================================================
            184380 MEDIUM MS08-002 V
            184379 MEDIUM MS08-001 V
            182048 HIGH MS07-069 V
            182046 HIGH MS07-067 V
            182043 HIGH MS07-064 V
            179553 HIGH MS07-061 V
            176382 HIGH MS07-057 V
            176383 HIGH MS07-058 V
            170911 HIGH MS07-050 V
            170907 HIGH MS07-046 V
            170906 HIGH MS07-045 V
            170904 HIGH MS07-043 V
            164915 HIGH MS07-035 V
            164913 HIGH MS07-033 V
            164911 HIGH MS07-031 V
            160623 HIGH MS07-027 V
            157262 HIGH MS07-022 V
            157261 HIGH MS07-021 V
            157260 HIGH MS07-020 V
            157259 HIGH MS07-019 V
            156477 HIGH MS07-017 V
            150253 HIGH MS07-016 V
            150249 HIGH MS07-013 V
            150248 HIGH MS07-012 V
            150247 HIGH MS07-011 V
            150243 HIGH MS07-008 V
            150242 HIGH MS07-007 V
            150241 MEDIUM MS07-006 V
            141034 HIGH MS06-076 V
            141033 MEDIUM MS06-075 V
            141030 HIGH MS06-072 V
            137571 HIGH MS06-070 V
            137568 HIGH MS06-067 V
            133387 MEDIUM MS06-065 V
            133386 MEDIUM MS06-064 V
            133385 MEDIUM MS06-063 V
            133379 HIGH MS06-057 V
            131654 HIGH MS06-055 V
            129977 MEDIUM MS06-053 V
            129976 MEDIUM MS06-052 V
            126093 HIGH MS06-051 V
            126092 MEDIUM MS06-050 V
            126087 HIGH MS06-046 V
            126086 MEDIUM MS06-045 V
            126083 HIGH MS06-042 V
            126082 HIGH MS06-041 V
            126081 HIGH MS06-040 V
            123421 HIGH MS06-036 V
            123420 HIGH MS06-035 V
            120825 MEDIUM MS06-032 V
            120823 MEDIUM MS06-030 V
            120818 HIGH MS06-025 V
            120815 HIGH MS06-022 V
            120814 HIGH MS06-021 V
            117384 MEDIUM MS06-018 V
            114666 HIGH MS06-015 V
            114664 HIGH MS06-013 V
            108744 MEDIUM MS06-008 V
            108743 MEDIUM MS06-007 V
            108742 MEDIUM MS06-006 V
            104567 HIGH MS06-002 V
            104237 HIGH MS06-001 V
            96574 HIGH MS05-053 V
            93395 HIGH MS05-051 V
            93394 HIGH MS05-050 V
            93454 MEDIUM MS05-049 V
            ;===================================================================================================================================================================================
            0
        2. Contributeur sécurité
          ok les clés sont clean

          fais ceci pour verifier

          télécharge malwarebyte mets le a jour et colle un rapport avec :

          https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

          ______________

          pour internet explorer il faudrait sinon navigue avec firefox ou opera ou safari moins touchés pasr les infections surtout si internet explorer non a jour: on verra a la fin pour tenter de mettre internet explorer 7 ou sinon mets internet explorer 8: en version beta 2:

          https://www.microsoft.com/en-us/windows/

          _________________

          et il faut aussi mettre windows a jour avec le sp3
          0
          1. Une fois sur le site il m'est impossible de charger l'aplication il ne trouve pas la page ou alors je tombe sur le moteur de recherche.
            Je veux bien utiliser firefox, a partir du moment ou je suis moins embeter et comment faire pour mettre à jour windows avec le sp3?
            0
            1. Contributeur sécurité
              mets firefox ici:

              http://www.mozilla-europe.org/fr/firefox/

              pour malwarebyte ici:
              http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes anti malware

              pour mettre a jour windows: DEMARRER puis TOUS LES PROGRAMMES puis WINDOWS UPDATE et suivre la procedure
              0
              1. Encore merci je viens d'installer firefox qui fonctionne correctement ainsi que la mise a jour de windows, par contre je dois supprimer internet explorer6 ou pas ?

                Voici le rapport de malwarebyte, il me semble que le pc soit encore infecté....

                Malwarebytes' Anti-Malware 1.31
                Version de la base de données: 1578
                Windows 5.1.2600 Service Pack 2

                30/12/2008 20:36:58
                mbam-log-2008-12-30 (20-36-44).txt

                Type de recherche: Examen complet (C:\|D:\|J:\|)
                Eléments examinés: 134052
                Temps écoulé: 1 hour(s), 4 minute(s), 38 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 1
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 6

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CLASSES_ROOT\videosoft (Trojan.DNSChanger) -> No action taken.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\Program Files\Everest Poker\var\Everest Casino.exe (Rogue.AdorableCasino) -> No action taken.
                C:\WINDOWS\system32\msqpdxymxxtfnd.dll (Trojan.TDSS) -> No action taken.
                C:\WINDOWS\system32\drivers\msqpdxltxjikha.sys (Trojan.Agent) -> No action taken.
                C:\WINDOWS\system32\drivers\msqpdxujhioetl.sys (Trojan.Agent) -> No action taken.
                C:\WINDOWS\system32\drivers\msqpdxvorsgvnt.sys (Trojan.Agent) -> No action taken.
                C:\WINDOWS\system32\drivers\msqpdxvsewsrfw.sys (Trojan.Agent) -> No action taken.
                0
            2. Contributeur sécurité
              non garde internet explorer 6 car windows n'utilise que lui pour se mettre a jour

              vire ce qui a été trouve par malwarebyte

              puis

              télécharge combofix (par sUBs) ici :

              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              et enregistre le sur le bureau.

              déconnecte toi d'internet et ferme toutes tes applications.

              désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

              double-clique sur combofix.exe et suis les instructions

              à la fin, il va produire un rapport C:\ComboFix.txt

              réactive ton parefeu, ton antivirus, la garde de ton antispyware

              copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

              Tu as un tutoriel complet ici :

              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
              0