Trojan Horse - Tradedaubler.com???

Bonjour,

J'ai une saleté de trojan horse sur mon ordinateur... Ben vi j'ai fais la connerie de downloadé un jeu mais pas vérifier s'il avait un virus. Bon. Là, j'ai faite scanné mon ordi avec Avast Familiale dernière mise à jour, j'ai faite le scan le plus minutieux, rien a changé. J'ai download Ad-Aware, il trouve, il a supprimé/réparé certain trucs, mais mon problème persiste toujours. J'explique. Quand j'allume mon ordinateur, les pop-ups apparaissent pas nécessairement toute suite. C'est plutôt quand je commence à naviguer sur internet, après un certain temps ça commence (je vais seulement sur Youtube, ou Deviantart ou Wowhead ou Hotmail). Voilà ce qui est écrit sur la pop-up (c'est une fenêtre qui s'ouvre avec un bouton OK de Windows Internet Explorer)

Warning!!! Your computer is infected!
To check your system and remove all harmful software write down this link
TRADEDAUBLER.COM
Open a new Internet Explorer window and type the adress manually
Go to website, download and run downloaded file.
FOR FREE!!!

Je l'ai retranscrit tel quel. Sinon une fois de temps en temps, ca fait 3 jours que je l'ai et ça m'ai seulement arrivé une fois par jour, une page internet explorer s'ouvrait et ensuite le virus en fait ouvrir pleins d'autres sans arrêt. Et le virus fait parfois ouvrir des pages internet. Si, par exemple, je suis sur une page et qui a une publicité, une fois de temps à autre le virus va l'ouvrir...

Si Avast et Ad-Aware peuvent rien faire, jfais quoi?
Configuration: Windows XP
Internet Explorer 7.0

27 réponses

Résumé de la discussion

Le fil relate une infection par un cheval de Troie apparaissant via des pop-ups alarmants et des redirections pendant la navigation, sur un PC Windows XP après le téléchargement d’un jeu non vérifié. Avast a été utilisé et n’a rien détecté, Ad-Aware a supprimé certains éléments mais le problème persiste, et un log HijackThis montre de nombreuses entrées suspectes. Les symptômes se manifestent notamment par des pages Internet Explorer qui s’ouvrent seules après certaines publicités, et par des suggestions d’adresse et de téléchargement via TRADEDAUBLER.COM. D'autres participants partagent des rapports et des extraits de logs, suggérant des actions manuelles et des nettoyages plus approfondis, sans toutefois conclure à une solution immédiate.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut,

    - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

    - Double-clique sur RSIT.exe afin de lancer le programme.

    - Clique sur Continue à l'écran Disclaimer.

    - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
    0
    1. J'ai le meme trojan...

      Logfile of random's system information tool 1.05 (written by random/random)
      Run by Thomas at 2009-02-09 10:31:57
      Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
      System drive C: has 17 GB (17%) free of 100 GB
      Total RAM: 2046 MB (43% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:32:08, on 09/02/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\Explorer.EXE
      C:\HP\KBD\kbd.exe
      C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Electronic Arts\EADM\Core.exe
      C:\Windows\system32\conime.exe
      C:\Windows\WindowsMobile\wmdc.exe
      C:\Program Files\SFR\Media Center\MediaCenter.exe
      C:\Program Files\SFR\Media Center\httpd\httpd.exe
      C:\Program Files\SFR\Media Center\httpd\httpd.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Windows\system32\rundll32.exe
      C:\Windows\system32\rundll32.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Thomas\Downloads\RSIT.exe
      C:\Program Files\trend micro\Thomas.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {DD13F31E-1846-4144-86D4-FEA137405391} - C:\Windows\system32\ljJYOiHB.dll
      O2 - BHO: (no name) - {DF986C2C-446C-49B7-913D-DBB1BAE4DC17} - C:\Windows\system32\byXOgfGx.dll
      O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
      O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\byXOgfGx.dll,#1
      O4 - HKLM\..\Run: [60f64673] rundll32.exe "C:\Windows\system32\egxukfxc.dll",b
      O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
      O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
      O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
      O13 - Gopher Prefix:
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
      O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
      O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.1.30\bin\mysqld.exe
      0
  2. Logfile of random's system information tool 1.05 (written by random/random)
    Run by Caroline at 2009-02-09 01:02:17
    Microsoft Windows XP Professionnel Service Pack 2
    System drive C: has 26 GB (35%) free of 75 GB
    Total RAM: 1919 MB (60% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 01:02:25, on 09/02/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\WINDOWS\vVX1000.exe
    C:\Program Files\Ideazon\ZEngine\Zboard.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
    C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
    c:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
    C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
    C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
    C:\Mabinogi\npkcmsvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
    C:\Documents and Settings\Caroline\Bureau\RSIT.exe
    C:\Program Files\trend micro\Caroline.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: (no name) - {4DBF1010-836F-46C0-B009-0E1AC06D279D} - C:\WINDOWS\system32\vtUlLfDV.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\ljJdbyVL.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {E907A067-EF80-4390-BACE-38BDC2F0A489} - C:\WINDOWS\system32\yayxxvtR.dll (file missing)
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [LifeCam] "c:\Program Files\Microsoft LifeCam\LifeExp.exe"
    O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
    O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
    O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [AntiMalwareProMFCT] C:\Program Files\AdwarePro\StartApp.exe
    O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648)" -"http://www.interactive.toyota.ca/shock/corolla2009/checker_l2.htm"
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: ljJdbyVL - C:\WINDOWS\SYSTEM32\ljJdbyVL.dll
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: MySQL4 - Unknown owner - C:\Program.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Mabinogi\npkcmsvc.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    0
    1. Bonjour,

      Le pc de mon frère est infecté du même virus.

      Je vais utiliser la même procédure pour les rapports en fichiers texte et je post ça ce soir.

      @+
      0
  3. Contributeur sécurité
    Salut

    ▶ Télécharge Combofix de sUBs

    ▶ et enregistre le sur le Bureau.

    ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

    Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    ▶ Je te conseille d'installer la console de récupération !!
    0
    1. salut j' ai le meme virus
      je poste tout ça se soir
      a+
      0
      1. Logfile of random's system information tool 1.05 (written by random/random)
        Run by corinne at 2009-02-09 18:05:55
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 31 GB (20%) free of 150 GB
        Total RAM: 1022 MB (61% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:06:10, on 09/02/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        c:\program files\mcafee.com\agent\mcdetect.exe
        c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\wanmpsvc.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\system32\taskmgr.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\corinne\Bureau\RSIT.exe
        C:\Program Files\trend micro\corinne.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://gamespace.daemon-tools.cc/fra/home
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
        O2 - BHO: (no name) - {66568e46-5edc-4e7f-96fb-7197dfc57747} - C:\WINDOWS\system32\awtrQGxV.dll
        O2 - BHO: (no name) - {6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} - C:\WINDOWS\system32\geBuUlIX.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
        O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
        O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
        O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
        O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
        O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
        O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1165772605\ee\AOLSoftware.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
        O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
        O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
        O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
        O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\corinne\LOCALS~1\Temp\winlognn.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
        O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6\ICQ.exe" silent
        O4 - HKCU\..\Run: [yeqmgwa] "c:\documents and settings\corinne\local settings\application data\yeqmgwa.exe" yeqmgwa
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\DOCUME~1\corinne\LOCALS~1\Temp\winlognn.exe
        O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\corinne\LOCALS~1\Temp\csrssc.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
        O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
        O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
        O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\corinne\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O20 - Winlogon Notify: geBuUlIX - C:\WINDOWS\SYSTEM32\geBuUlIX.dll
        O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
        O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
        O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
        O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
        O24 - Desktop Component 0: (no name) - http://www.chrisfarnsworth.com/images/101-0182_IMG.JPG
        0
        1. j'ai le même problème donc je poste se que vous m'aviez dit de poster:

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Sébastien Laneuville at 2009-02-10 17:37:17
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 249 GB (81%) free of 305 GB
          Total RAM: 1022 MB (39% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:38:56, on 2009-02-10
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\PnkBstrA.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\D-Tools\daemon.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Microsoft IntelliType Pro\type32.exe
          C:\Program Files\Microsoft IntelliPoint\point32.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Documents and Settings\Sébastien Laneuville\Application Data\advantage\AdVantage.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\WINDOWS\system32\wpabaln.exe
          C:\WINDOWS\system32\cmd.execf
          C:\Documents and Settings\Sébastien Laneuville\Bureau\RSIT.exe
          C:\32788R22FWJFW\NirCmd.cfexe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\trend micro\Sébastien Laneuville.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://sebas009.skyrock.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\cbXPfEVp.dll
          O2 - BHO: (no name) - {748E6C81-DC7D-4974-BE84-016C7A71A0D2} - C:\WINDOWS\system32\jkkighf.dll (file missing)
          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: (no name) - {7F648DBB-819F-4EAB-A7A0-38B148B4E6AC} - C:\WINDOWS\system32\iifddeCT.dll (file missing)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: (no name) - {B688255E-A1E3-4424-B2C9-346CB1E7A12D} - C:\WINDOWS\system32\mllmk.dll (file missing)
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [c0068aac] rundll32.exe "C:\WINDOWS\system32\icaxjcxk.dll",b
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [city dupe] C:\DOCUME~1\SBASTI~1\APPLIC~1\UPLOAD~1\PlusStyle.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [AdVantage] C:\Documents and Settings\Sébastien Laneuville\Application Data\advantage\AdVantage.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
          O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
          O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} (igLoader Content on Demand) - http://www.miniclip.com/igloader/igloader.CAB
          O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
          O20 - Winlogon Notify: cbXPfEVp - C:\WINDOWS\SYSTEM32\cbXPfEVp.dll
          O20 - Winlogon Notify: jkkighf - jkkighf.dll (file missing)
          O20 - Winlogon Notify: mllmk - C:\WINDOWS\system32\mllmk.dll (file missing)
          O20 - Winlogon Notify: opnnoppP - opnnoppP.dll (file missing)
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\oodahplx.exe (file missing)
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
          O24 - Desktop Component 0: (no name) - http://www.runescape.com/img/files/wallpaper_attack/attack_1440x900.jpg
          0
          1. Contributeur sécurité
            Pourquoi cette avalanche de rapport ?!!!

            crées votre propre topique !
            0
            1. Salut kevin ,tu croule sous l'avalanche de rapport,c 'est un virus replicateur ou quoi?
              0
              1. Contributeur sécurité
                Salut seb

                Il se clone vite alors XD
                0
                1. Contributeur sécurité
                  Re j'vais avoir du boulot ;-) xd
                  0
                  1. mais va tu touse nous aider quand meme a se qui parait moi sa se clone vite
                    0
                    1. Contributeur sécurité
                      D'accord lol j'analyze ton rapport et je dit la suite ... ;-)
                      0
                      1. Contributeur sécurité
                        Re tu es bien infecter...

                        télécharge smitfraudfix et enregistre le sur le bureau

                        ? Ensuite double clique sur smitfraudfix puis exécuter

                        ? Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                        (attention : N utilises pas l option 2 si je ne te l'ai pas demandé !!)

                        ? copier/coller le rapport dans la réponse.

                        TUTO si problème

                        (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
                        cet utilitaire pourrait arrêter des logiciels de sécurité.)
                        0
                        1. SmitFraudFix v2.395

                          Rapport fait à 21:30:52,11, 2009-02-10
                          Executé à partir de C:\Documents and Settings\Sébastien Laneuville\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\eHome\ehRecvr.exe
                          C:\WINDOWS\eHome\ehSched.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\PnkBstrA.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\ehome\ehtray.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\D-Tools\daemon.exe
                          C:\WINDOWS\system32\LVCOMSX.EXE
                          C:\Program Files\Logitech\Video\LogiTray.exe
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\Program Files\Microsoft IntelliType Pro\type32.exe
                          C:\Program Files\Microsoft IntelliPoint\point32.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Documents and Settings\Sébastien Laneuville\Application Data\advantage\AdVantage.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\WINDOWS\system32\dllhost.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\WINDOWS\eHome\ehmsas.exe
                          C:\Program Files\Logitech\Video\FxSvr2.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\WINDOWS\system32\wpabaln.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\WINDOWS\explorer.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Documents and Settings\Sébastien Laneuville\Bureau\SmitfraudFix\Policies.exe
                          C:\WINDOWS\system32\cmd.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          Fichier hosts corrompu !

                          127.0.0.1 mpa.one.microsoft.com

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Sébastien Laneuville

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Sébastien Laneuville\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SBASTI~1\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="http://www.runescape.com/img/files/wallpaper_attack/attack_1440x900.jpg"
                          "SubscribedURL"="http://www.runescape.com/img/files/wallpaper_attack/attack_1440x900.jpg"
                          "FriendlyName"=""

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
                          "Source"="About:Home"
                          "SubscribedURL"="About:Home"
                          "FriendlyName"="Ma page d'accueil"

                          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          o4Patch
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          Agent.OMZ.Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: Carte Fast Ethernet compatible VIA - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 206.123.6.230
                          DNS Server Search Order: 199.84.54.230

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                          1. Contributeur sécurité
                            Salut dans l'ordre ! :

                            Télécharge cet outil de SiRi sur ton bureau :

                            RHost

                            Double-clique dessus pour le lancer .

                            -> clique sur " Restore original Hosts " et attendre un court instant ...

                            ( ps : c'est normal que rien ne se passe ... )

                            ----------------------------------------------------------------------------

                            Relance smitfraudfix choisie l'option 2

                            Repond oui a tous

                            Poste le rapport...
                            0
                            1. ça ne fonctionne pas se programe sa fait absolument rien et je n'ai pas plusieur option seulement restaurer.Ques ce que je dois faire.
                              0
                              1. Contributeur sécurité
                                Suit ce que l'on te dit de faire !!!!!!!!!
                                0
                                1. SmitFraudFix v2.395

                                  Rapport fait à 19:31:29,96, 2009-02-11
                                  Executé à partir de C:\Documents and Settings\Sébastien Laneuville\Bureau\SmitfraudFix
                                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                  Le type du système de fichiers est NTFS
                                  Fix executé en mode normal

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                  127.0.0.1 localhost

                                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                                  VACFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                  S!Ri's WS2Fix: LSP not Found.

                                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                  GenericRenosFix by S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                                  IEDFix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                                  Agent.OMZ.Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                                  404Fix
                                  Credits: Malware Analysis & Diagnostic
                                  Code: S!Ri

                                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                  Description: Carte Fast Ethernet compatible VIA - Miniport d'ordonnancement de paquets
                                  DNS Server Search Order: 206.123.6.230
                                  DNS Server Search Order: 199.84.54.230

                                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                                  HKLM\SYSTEM\CS3\Services\Tcpip\..\{7AA4847D-0644-4590-9954-876AAF008E8A}: DhcpNameServer=206.123.6.230 199.84.54.230
                                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230
                                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230
                                  HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=206.123.6.230 199.84.54.230

                                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                  "System"=""

                                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                                  Nettoyage terminé.

                                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                  SrchSTS.exe by S!Ri
                                  Search SharedTaskScheduler's .dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                  0
                                  1. Contributeur sécurité
                                    Bien

                                    ▶ Télécharge Combofix de sUBs

                                    ▶ et enregistre le sur le Bureau.

                                    ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

                                    Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

                                    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                    ▶ Je te conseille d'installer la console de récupération !! après a toi de voir...
                                    0
                                    1. ComboFix 09-02-12.03 - Sébastien Laneuville 2009-02-12 16:35:29.1 - NTFSx86
                                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.620 [GMT -5:00]
                                      Lancé depuis: c:\documents and settings\Sébastien Laneuville\Bureau\ComboFix.exe
                                      AV: avast! antivirus 4.8.1201 [VPS 090212-0] *On-access scanning disabled* (Updated)
                                      * Un nouveau point de restauration a été créé
                                      .

                                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .

                                      c:\documents and settings\Sébastien Laneuville\Application Data\inst.exe
                                      c:\documents and settings\Sébastien Laneuville\Local Settings\Temporary Internet Files\ijjistarter_verinfo.dat
                                      c:\program files\FunWebProducts
                                      c:\program files\FunWebProducts\Shared\46EE38B3.dat
                                      c:\windows\cookies.ini
                                      c:\windows\system32\404Fix.exe
                                      c:\windows\system32\abckftvm.ini
                                      c:\windows\system32\Agent.OMZ.Fix.exe
                                      c:\windows\system32\algxevyv.ini
                                      c:\windows\system32\asfaafrg.ini
                                      c:\windows\system32\bafjkfpu.ini
                                      c:\windows\system32\bflgevtu.dll
                                      c:\windows\system32\bkeskrls.ini
                                      c:\windows\system32\bkgysbnw.dll
                                      c:\windows\system32\bpwerprr.ini
                                      c:\windows\system32\bqcbakpu.ini
                                      c:\windows\system32\brhywa.dll
                                      c:\windows\system32\bruerodl.ini
                                      c:\windows\system32\bwfjmygb.ini
                                      c:\windows\system32\cbXPfEVp.dll
                                      c:\windows\system32\cltgistf.ini
                                      c:\windows\system32\dumphive.exe
                                      c:\windows\system32\ejaheoas.ini
                                      c:\windows\system32\elvaixpd.ini
                                      c:\windows\system32\evmbvlcn.ini
                                      c:\windows\system32\fdequrfu.ini
                                      c:\windows\system32\fiyhnc.dll
                                      c:\windows\system32\fxtycp.dll
                                      c:\windows\system32\GhhRBcdd.ini
                                      c:\windows\system32\GhhRBcdd.ini2
                                      c:\windows\system32\giwcmveg.ini
                                      c:\windows\system32\gugnawsl.dll
                                      c:\windows\system32\hhgqufip.ini
                                      c:\windows\system32\icaxjcxk.dll
                                      c:\windows\system32\IEDFix.C.exe
                                      c:\windows\system32\IEDFix.exe
                                      c:\windows\system32\itripvoh.ini
                                      c:\windows\system32\jcfxhtkc.dll
                                      c:\windows\system32\jrbwxlbs.ini
                                      c:\windows\system32\kedcrtdb.dll
                                      c:\windows\system32\kejopunw.dll
                                      c:\windows\system32\khgjpcvd.ini
                                      c:\windows\system32\kmllm.bak1
                                      c:\windows\system32\kmllm.bak2
                                      c:\windows\system32\kmllm.ini
                                      c:\windows\system32\kxcjxaci.ini
                                      c:\windows\system32\lmesmckm.ini
                                      c:\windows\system32\mairvjad.ini
                                      c:\windows\system32\mchcquty.ini
                                      c:\windows\system32\mcrh.tmp
                                      c:\windows\system32\mdeqewxk.ini
                                      c:\windows\system32\mgsqonws.ini
                                      c:\windows\system32\miflqlvw.ini
                                      c:\windows\system32\mllppbfx.dll
                                      c:\windows\system32\mtoxlnot.ini
                                      c:\windows\system32\niadjtel.ini
                                      c:\windows\system32\o4Patch.exe
                                      c:\windows\system32\onftbgag.ini
                                      c:\windows\system32\opoxnqbo.ini
                                      c:\windows\system32\Process.exe
                                      c:\windows\system32\qcjqtnys.ini
                                      c:\windows\system32\qhhaosou.ini
                                      c:\windows\system32\rgqkdlev.ini
                                      c:\windows\system32\saoehaje.dll
                                      c:\windows\system32\snraur.dll
                                      c:\windows\system32\snwumoaj.ini
                                      c:\windows\system32\SrchSTS.exe
                                      c:\windows\system32\TCeddfii.ini
                                      c:\windows\system32\TCeddfii.ini2
                                      c:\windows\system32\tmp.reg
                                      c:\windows\system32\tuvvVLda.dll
                                      c:\windows\system32\urobpl.dll
                                      c:\windows\system32\VACFix.exe
                                      c:\windows\system32\VCCLSID.exe
                                      c:\windows\system32\vgnkqbsb.ini
                                      c:\windows\system32\vtmsbxgt.ini
                                      c:\windows\system32\WS2Fix.exe
                                      c:\windows\system32\wufsnbsc.dll
                                      c:\windows\system32\wwjxqaum.ini
                                      c:\windows\system32\xfbppllm.ini
                                      c:\windows\system32\yraydddt.ini
                                      c:\windows\system32\yspxas.dll

                                      .
                                      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                      .

                                      -------\Legacy_DOMAINSERVICE
                                      -------\Service_DomainService

                                      ((((((((((((((((((((((((((((( Fichiers créés du 2009-01-12 au 2009-02-12 ))))))))))))))))))))))))))))))))))))
                                      .

                                      2009-02-10 17:20 . 2009-02-10 17:22 <REP> d-------- C:\rsit
                                      2009-02-10 17:20 . 2009-02-10 17:38 <REP> d-------- c:\program files\trend micro
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
                                      2009-02-05 22:02 . 2006-11-25 14:48 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> d-------- c:\documents and settings\Administrateur\Favoris
                                      2009-02-05 22:02 . 2006-11-25 09:08 <REP> d-------- c:\documents and settings\Administrateur\Bureau
                                      2009-02-05 22:02 . 2009-02-05 22:02 <REP> d-------- c:\documents and settings\Administrateur
                                      2009-02-03 16:26 . 2009-02-03 16:26 72,704 --a------ c:\windows\system32\nfxbppyq.dll
                                      2009-01-27 22:31 . 2008-04-13 21:33 159,232 --a------ c:\windows\system32\ptpusd.dll
                                      2009-01-27 22:31 . 2001-08-23 17:47 5,632 --a------ c:\windows\system32\ptpusb.dll

                                      .
                                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      2009-02-12 21:45 --------- d-----w c:\documents and settings\Sébastien Laneuville\Application Data\advantage
                                      2009-02-11 23:00 --------- d-----w c:\program files\Norton Security Scan
                                      2009-02-07 15:38 --------- d-----w c:\documents and settings\Sébastien Laneuville\Application Data\UPLOAD NOUN
                                      2009-02-07 15:31 --------- d-----w c:\documents and settings\NetworkService\Application Data\UPLOAD NOUN
                                      2009-01-31 03:56 --------- d-----w c:\documents and settings\Sébastien Laneuville\Application Data\LimeWire
                                      2009-01-17 20:59 --------- d-----w c:\program files\Google
                                      2008-12-31 02:54 --------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
                                      2008-12-30 05:50 --------- d-----w c:\documents and settings\Sébastien Laneuville\Application Data\Apple Computer
                                      2008-12-28 08:09 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
                                      2008-12-28 00:06 --------- d-----w c:\program files\Java
                                      2008-12-27 18:30 --------- d-----w c:\program files\Circle Developement
                                      2008-12-27 18:29 --------- d-----w c:\program files\MSN Messenger
                                      2008-12-27 18:29 --------- d-----w c:\program files\Messenger Plus! Live
                                      2008-12-22 19:42 --------- d-----w c:\program files\Microsoft Silverlight
                                      2008-12-22 19:42 --------- d-----w c:\program files\iTunes
                                      2008-12-22 19:31 --------- d-----w c:\program files\Bonjour
                                      2008-12-22 19:28 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                                      2008-12-22 19:26 --------- d-----w c:\program files\iPod
                                      2008-12-22 19:26 --------- d-----w c:\program files\Fichiers communs\Apple
                                      2008-12-22 19:16 --------- d-----w c:\program files\QuickTime
                                      2008-12-22 18:54 --------- d-----w c:\program files\Safari
                                      2008-12-12 21:40 --------- d-----w c:\documents and settings\Sébastien Laneuville\Application Data\Vso
                                      2008-12-12 21:36 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
                                      2008-12-12 21:36 47,360 ----a-w c:\documents and settings\Sébastien Laneuville\Application Data\pcouffin.sys
                                      2008-12-12 21:36 --------- d-----w c:\program files\VSO
                                      2008-12-12 21:22 --------- d-----w c:\program files\Kingdia Software
                                      2008-09-11 01:00 23,256 ----a-w c:\documents and settings\Sébastien Laneuville\Application Data\GDIPFONTCACHEV1.DAT
                                      .

                                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                      .
                                      .
                                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                      REGEDIT4

                                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                                      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-10 68856]
                                      "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
                                      "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
                                      "MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2007-11-16 190024]
                                      "msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                                      "AdVantage"="c:\documents and settings\Sébastien Laneuville\Application Data\advantage\AdVantage.exe" [2008-10-22 174928]

                                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                      "ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
                                      "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 79224]
                                      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-27 136600]
                                      "DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
                                      "LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
                                      "LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
                                      "LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
                                      "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
                                      "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
                                      "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
                                      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
                                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
                                      "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
                                      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
                                      "SoundMan"="SOUNDMAN.EXE" [2005-06-20 c:\windows\SOUNDMAN.EXE]

                                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

                                      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 03:21:22 288472]
                                      Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 21:05:26 29696]
                                      Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [13/02/2001 04:01:04 83360]

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
                                      2001-12-20 23:34 24576 c:\program files\AlienGUIse\fastload.dll

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                      "AppInit_DLLs"=wbsys.dll

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                      "VIDC.XFR1"= xfcodec.dll

                                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                      "%windir%\\system32\\sessmgr.exe"=
                                      "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
                                      "c:\\StubInstaller.exe"=
                                      "c:\\Program Files\\LimeWire\\LimeWire.exe"=
                                      "c:\\Documents and Settings\\Sébastien Laneuville\\Mes documents\\Nouveau dossier\\SwiftSwitch.exe"=
                                      "c:\\Program Files\\MSN Messenger\\msrr.exe"=
                                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                      "c:\\Program Files\\Java\\jre1.6.0_02\\bin\\javaw.exe"=
                                      "c:\\WINDOWS\\system32\\spoolsv.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                                      "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
                                      "c:\\Program Files\\iTunes\\iTunes.exe"=
                                      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                                      R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [02/06/2008 20:40:06 78416]
                                      R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [25/11/2006 17:08:13 13696]
                                      R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [02/06/2008 20:40:06 20560]
                                      S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [18/09/2008 18:24:49 16512]

                                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                                      .
                                      Contenu du dossier 'Tâches planifiées'

                                      2009-02-09 c:\windows\Tasks\AppleSoftwareUpdate.job
                                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                                      2009-02-11 c:\windows\Tasks\Norton Security Scan.job
                                      - c:\program files\Norton Security Scan\Nss.exe [2008-01-09 03:08]
                                      .
                                      - - - - ORPHELINS SUPPRIMES - - - -

                                      BHO-{28a74bb3-ac11-4cff-9864-209e489f9aea} - c:\windows\system32\brhywa.dll
                                      BHO-{7F648DBB-819F-4EAB-A7A0-38B148B4E6AC} - c:\windows\system32\iifddeCT.dll
                                      BHO-{B688255E-A1E3-4424-B2C9-346CB1E7A12D} - c:\windows\system32\mllmk.dll
                                      HKCU-Run-city dupe - c:\docume~1\SBASTI~1\APPLIC~1\UPLOAD~1\PlusStyle.exe
                                      Notify-mllmk - c:\windows\system32\mllmk.dll
                                      Notify-jkkighf - jkkighf.dll
                                      Notify-opnnoppP - opnnoppP.dll
                                      Notify-WgaLogon - (no file)

                                      .
                                      ------- Examen supplémentaire -------
                                      .
                                      uInternet Settings,ProxyOverride = *.local
                                      IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                                      .

                                      **************************************************************************

                                      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2009-02-12 16:44:45
                                      Windows 5.1.2600 Service Pack 3 NTFS

                                      Recherche de processus cachés ...

                                      Recherche d'éléments en démarrage automatique cachés ...

                                      Recherche de fichiers cachés ...

                                      Scan terminé avec succès
                                      Fichiers cachés: 0

                                      **************************************************************************
                                      .
                                      --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                      [HKEY_USERS\S-1-5-21-1993962763-1957994488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
                                      @Denied: (Full) (LocalSystem)
                                      .
                                      --------------------- DLLs chargées dans les processus actifs ---------------------

                                      - - - - - - - > 'winlogon.exe'(676)
                                      c:\program files\AlienGUIse\fastload.dll
                                      .
                                      ------------------------ Autres processus actifs ------------------------
                                      .
                                      c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                                      c:\program files\Alwil Software\Avast4\ashServ.exe
                                      c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                      c:\program files\Bonjour\mDNSResponder.exe
                                      c:\windows\ehome\ehRecvr.exe
                                      c:\windows\ehome\ehSched.exe
                                      c:\program files\Java\jre6\bin\jqs.exe
                                      c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                      c:\windows\system32\PnkBstrA.exe
                                      c:\windows\system32\dllhost.exe
                                      c:\program files\Alwil Software\Avast4\ashDisp.exe
                                      c:\windows\ehome\ehmsas.exe
                                      c:\program files\Logitech\Video\FxSvr2.exe
                                      c:\program files\iPod\bin\iPodService.exe
                                      c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
                                      c:\windows\system32\wpabaln.exe
                                      c:\program files\HP\Digital Imaging\bin\hpqste08.exe
                                      c:\windows\system32\wscntfy.exe
                                      c:\windows\system32\msiexec.exe
                                      .
                                      **************************************************************************
                                      .
                                      Heure de fin: 2009-02-12 16:53:03 - La machine a redémarré
                                      ComboFix-quarantined-files.txt 2009-02-12 21:52:19

                                      Avant-CF: 262 764 584 960 octets libres
                                      Après-CF: 264,999,682,048 octets libres

                                      WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                                      [boot loader]
                                      timeout=2
                                      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                                      [operating systems]
                                      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                                      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

                                      285 --- E O F --- 2008-12-29 23:47:32
                                      0
                                      • 1
                                      • 2