Probléme avec l'arriére plan de mon bureau

Bonjour,
je sollicite de l'aide car g 1 probléme avec l'arriére plan de mn bureau qui est bloqué é je ne peu plus la modifier. seule la couleur apparait.
tout a commencé avec une entrée de virus et d trojan mé g réussit a lé supprimé( enfin je lespér) car mn anti virus McAfee version 8.5i ne les détecte plus.
est ce que kelk1n oré une idée pr maider
merci davance
Configuration: Windows XP
Safari 525.19

21 réponses

  1. Contributeur sécurité
    slt,

    Slt,

    scan avec malwarebyte , fais un scan minutieux et colle le rapport obtenu et vire ce qui est trouvé:

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

    ______________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. wi lé deux fichiers qui se sont ouvert sur le bloc notes sont effectivement log et info
      je te colle lé résultats ::
      info.txt logfile of random's system information tool 1.06 2009-03-24 13:14:18

      ======Uninstall list======

      -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Adobe Acrobat - Reader 6.0.2 Update-->MsiExec.exe /I{AC76BA86-0000-0000-0000-6028747ADE01}
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Reader 6.0.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A00000000001}
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Ares 2.1.1-->"C:\Program Files\Ares\uninstall.exe"
      Ask Toolbar-->rundll32 C:\PROGRA~1\AskTBar\bar\1.bin\AskTBar.dll,O
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Condition Zero 3-->C:\WINDOWS\iun6002.exe "C:\Program Files\Condition Zero\irunin.ini"
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Google Chrome-->"C:\Program Files\Google\Chrome\Application\1.0.154.48\Installer\setup.exe" --uninstall --system-level
      Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
      Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
      Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
      Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2782 PCI\VEN_8086&DEV_2582
      J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
      Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
      Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      McAfee VirusScan Enterprise-->MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
      Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Mozilla Firefox (3.0.7)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
      Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Picasa 3-->"C:\Program Files\Google\Picasa3\Uninstall.exe"
      PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      SLD Codec Pack-->C:\Program Files\SLD Codec Pack\uninstall.exe
      SuperCopier2-->"C:\Program Files\SuperCopier2\SC2Uninst.exe"
      Virtual DJ - Atomix Productions-->C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
      Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
      Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

      ======Security center information======

      AV: McAfee VirusScan Enterprise

      ======System event log======

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 4201
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FEA9EB68-B3C0-4E2F-9D52-7F90129A95C1} était connectée au réseau,
      et a lancé une opération normale sur la carte réseau.

      Record Number: 6099
      Source Name: Tcpip
      Time Written: 20090315223906.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 4202
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FEA9EB68-B3C0-4E2F-9D52-7F90129A95C1} était déconnectée du réseau,
      et la configuration réseau de la carte a été abandonnée. Si la carte
      réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
      Contactez le fabricant pour des pilotes mis à jour.

      Record Number: 6098
      Source Name: Tcpip
      Time Written: 20090315223856.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 4201
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FEA9EB68-B3C0-4E2F-9D52-7F90129A95C1} était connectée au réseau,
      et a lancé une opération normale sur la carte réseau.

      Record Number: 6097
      Source Name: Tcpip
      Time Written: 20090315223721.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 4202
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FEA9EB68-B3C0-4E2F-9D52-7F90129A95C1} était déconnectée du réseau,
      et la configuration réseau de la carte a été abandonnée. Si la carte
      réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
      Contactez le fabricant pour des pilotes mis à jour.

      Record Number: 6096
      Source Name: Tcpip
      Time Written: 20090315223711.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 4201
      Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FEA9EB68-B3C0-4E2F-9D52-7F90129A95C1} était connectée au réseau,
      et a lancé une opération normale sur la carte réseau.

      Record Number: 6095
      Source Name: Tcpip
      Time Written: 20090315223136.000000+060
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 0
      Message:
      Record Number: 1236
      Source Name: SeaPort
      Time Written: 20090228125722.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 0
      Message:
      Record Number: 1235
      Source Name: RichVideo
      Time Written: 20090228125722.000000+060
      Event Type: Informations
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 0
      Message:
      Record Number: 1234
      Source Name:
      Time Written: 20090228125100.000000+060
      Event Type: erreur
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 0
      Message:
      Record Number: 1233
      Source Name:
      Time Written: 20090228125100.000000+060
      Event Type: erreur
      User:

      Computer Name: YOUR-83F1D5C6CB
      Event Code: 0
      Message:
      Record Number: 1232
      Source Name:
      Time Written: 20090228121021.000000+060
      Event Type: erreur
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
      "PROCESSOR_REVISION"=0401
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "VSEDEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
      "DEFLOGDIR"=C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection

      -----------------EOF-----------------
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Admin at 2009-03-24 13:12:10
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 23 GB (60%) free of 38 GB
        Total RAM: 502 MB (7% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 13:13:45, on 24/03/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Program Files\McAfee\Common Framework\FrameworkService.exe
        C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
        C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
        C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\CyberLink\Shared files\RichVideo.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
        C:\Program Files\McAfee\Common Framework\UdaterUI.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\SuperCopier2\SuperCopier2.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Ares\Ares.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\McAfee\Common Framework\McTray.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\Program Files\Google\Chrome\Application\chrome.exe
        C:\WINDOWS\odb.exe
        C:\Documents and Settings\Admin\Mes documents\Downloads\RSIT.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\trend micro\Admin.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        F2 - REG:system.ini: UserInit=userinit.exe
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
        O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
        O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - (no file)
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
        O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
        O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
        O4 - HKLM\..\Run: [Hvixez] rundll32.exe "C:\WINDOWS\Ujuloco.dll",e
        O4 - HKLM\..\Run: [odby] C:\WINDOWS\odb.exe
        O4 - HKLM\..\Run: [UpdateWin] C:\WINDOWS\system32\1041p.exe
        O4 - HKLM\..\RunServices: [UpdateWin] C:\WINDOWS\system32\1041p.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [UpdateWin] C:\WINDOWS\system32\1041p.exe
        O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\system32\1041p.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
        O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
        O22 - SharedTaskScheduler: Windows Installer Class - {020487CC-FC04-4B1E-863F-D9801796230B} - (no file)
        O23 - Service: Service Google Update (gupdate1c9a682a5a4045e) (gupdate1c9a682a5a4045e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
        O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
        O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
        O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
        0
        1. Contributeur sécurité
          ok mais j'avais demandé un rapport malwarebyte avant !

          alors fais malwarebyte

          puis

          Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

          * Lance l'installation du programme en exécutant le fichier téléchargé.
          * Double-clique maintenant sur le raccourci de Toolbar-S&D.
          * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
          * Choisis maintenant l'option 2. Patiente jusqu'à la fin de la recherche.
          * Poste le rapport généré. (C:\TB.txt)

          puis remets un rapport RSIT
          0
          1. ok g fé malwarebyte et g eu le rapport suivant :
            Malwarebytes' Anti-Malware 1.34
            Version de la base de données: 1891
            Windows 5.1.2600 Service Pack 3

            24/03/2009 14:07:17
            mbam-log-2009-03-24 (14-07-17).txt

            Type de recherche: Examen complet (C:\|)
            Eléments examinés: 34126
            Temps écoulé: 34 minute(s), 45 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 1
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{020487cc-fc04-4b1e-863f-d9801796230b} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            0
            1. Contributeur sécurité
              Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
              https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

              * Lance l'installation du programme en exécutant le fichier téléchargé.
              * Double-clique maintenant sur le raccourci de Toolbar-S&D.
              * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
              * Choisis maintenant l'option 2. Patiente jusqu'à la fin de la recherche.
              * Poste le rapport généré. (C:\TB.txt)

              puis remets un rapport RSIT
              0
              1. t'as vu il a pas vu le vundo MBAM

                :)
                0
                1. voici le rapport :

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.80GHz )
                  BIOS : Version 5.00 R1.06.1844
                  USER : Admin ( Administrator )
                  BOOT : Normal boot
                  Antivirus : McAfee VirusScan Enterprise 8.5.0.781 (Activated)
                  C:\ (Local Disk) - NTFS - Total:37 Go (Free:22 Go)
                  D:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( 24/03/2009|14:17 )
                  C:\WINDOWS\iun6002.exe
                  C:\DOCUME~1\Admin\LOCALS~1\Temp\ICD1.tmp

                  -----------\\ SUPPRESSION

                  Supprime! - C:\Program Files\AskTBar\bar
                  Supprime! - C:\Program Files\AskTBar\SrchAstt
                  Supprime! - C:\WINDOWS\iun6002.exe
                  Supprime! - C:\DOCUME~1\Admin\LOCALS~1\Temp\ICD1.tmp
                  Supprime! - C:\Program Files\AskTBar

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.google.fr/?gws_rd=ssl"
                  "Search Page"="https://www.google.com/?gws_rd=ssl"
                  "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                  "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                  "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Start Page"="https://www.msn.com/fr-fr/"

                  --------------------\\ Recherche d'autres infections

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\Admin\Bureau\Rockstar Games\GTA San Andreas\data\Decision\Craig\crack1.ped

                  1 - "C:\ToolBar SD\TB_1.txt" - 24/03/2009|14:25 - Option : [2]

                  -----------\\ Fin du rapport a 14:25:07,23
                  0
                  1. Contributeur sécurité
                    ok fais la suite du message 9
                    0
                2. Contributeur sécurité
                  oui j'ai vu

                  mais aussi ceci

                  C:\WINDOWS\system32\1041p.exe

                  pouvant venir de spysheriff

                  on va voir!

                  ____________________

                  Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                  * Lance l'installation du programme en exécutant le fichier téléchargé.
                  * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                  * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                  * Choisis maintenant l'option 2. Patiente jusqu'à la fin de la recherche.
                  * Poste le rapport généré. (C:\TB.txt)

                  _____________________

                  puis remets un rapport RSIT

                  _____________________

                  smit fraud fix (colle le rapport)

                  1/ telecharger :

                  http://siri.urz.free.fr/Fix/SmitfraudFix.php

                  2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes.
                  0
                  1. voici le 2e rapport

                    -----------\\ ToolBar S&D 1.2.8 XP/Vista

                    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.80GHz )
                    BIOS : Version 5.00 R1.06.1844
                    USER : Admin ( Administrator )
                    BOOT : Normal boot
                    Antivirus : McAfee VirusScan Enterprise 8.5.0.781 (Activated)
                    C:\ (Local Disk) - NTFS - Total:37 Go (Free:22 Go)
                    D:\ (CD or DVD)

                    "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                    Option : [2] ( 24/03/2009|14:31 )

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                    "Start Page"="https://www.google.fr/?gws_rd=ssl"
                    "Search Page"="https://www.google.com/?gws_rd=ssl"
                    "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                    "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
                    "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Start Page"="https://www.msn.com/fr-fr/"

                    --------------------\\ Recherche d'autres infections

                    --------------------\\ Cracks & Keygens ..

                    C:\DOCUME~1\Admin\Bureau\Rockstar Games\GTA San Andreas\data\Decision\Craig\crack1.ped

                    1 - "C:\ToolBar SD\TB_1.txt" - 24/03/2009|14:25 - Option : [2]
                    2 - "C:\ToolBar SD\TB_2.txt" - 24/03/2009|14:38 - Option : [2]

                    -----------\\ Fin du rapport a 14:38:41,03

                    puis avec smit fraud fix g le rapport suivant :
                    SmitFraudFix v2.405

                    Rapport fait à 14:41:15,48, 24/03/2009
                    Executé à partir de C:\Program Files\Google\Chrome\Application\1.0.154.48\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Le type du système de fichiers est NTFS
                    Fix executé en mode normal

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\Program Files\Google\Update\GoogleUpdate.exe
                    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                    C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\Program Files\CyberLink\Shared files\RichVideo.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                    C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
                    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\SuperCopier2\SuperCopier2.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Ares\Ares.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\McAfee\Common Framework\McTray.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\WINDOWS\odb.exe
                    C:\WINDOWS\odb.exe
                    C:\WINDOWS\odb.exe
                    C:\WINDOWS\odb.exe
                    C:\WINDOWS\odb.exe
                    C:\WINDOWS\system32\cmd.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\Program Files\Google\Chrome\Application\chrome.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Admin

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Admin\LOCALS~1\Temp

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Admin\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Admin\Favoris

                    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="Ma page d'accueil"

                    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    o4Patch
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    Agent.OMZ.Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    404Fix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                    "IPC Configuration Utility"="IPC Configuration Utility"

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: SAGEM Wi-Fi 11g USB adapter #2 - Miniport d'ordonnancement de paquets
                    DNS Server Search Order: 213.154.64.13
                    DNS Server Search Order: 213.154.95.126

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{12B6E999-B158-4F14-BBFF-F345F9D55AEB}: DhcpNameServer=213.154.64.13 213.154.95.126
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{12B6E999-B158-4F14-BBFF-F345F9D55AEB}: DhcpNameServer=213.154.64.13 213.154.95.126
                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{12B6E999-B158-4F14-BBFF-F345F9D55AEB}: DhcpNameServer=213.154.64.13 213.154.95.126
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=213.154.64.13 213.154.95.126
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=213.154.64.13 213.154.95.126
                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=213.154.64.13 213.154.95.126

                    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin
                    0
                    1. Contributeur sécurité
                      puis remets un rapport RSIT
                      0
                      1. Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Admin at 2009-03-24 14:48:44
                        Microsoft Windows XP Professionnel Service Pack 3
                        System drive C: has 23 GB (60%) free of 38 GB
                        Total RAM: 502 MB (37% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 14:49:23, on 24/03/2009
                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\Program Files\Google\Update\GoogleUpdate.exe
                        C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                        C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                        C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                        C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\Program Files\CyberLink\Shared files\RichVideo.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\hkcmd.exe
                        C:\WINDOWS\system32\igfxpers.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                        C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
                        C:\Program Files\McAfee\Common Framework\UdaterUI.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\SuperCopier2\SuperCopier2.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Ares\Ares.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\McAfee\Common Framework\McTray.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Google\Chrome\Application\chrome.exe
                        C:\Program Files\Google\Chrome\Application\chrome.exe
                        C:\WINDOWS\odb.exe
                        C:\WINDOWS\system32\cmd.exe
                        C:\Program Files\Google\Chrome\Application\chrome.exe
                        C:\WINDOWS\odb.exe
                        C:\WINDOWS\odb.exe
                        C:\WINDOWS\odb.exe
                        C:\Documents and Settings\Admin\Mes documents\Downloads\RSIT (1).exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\Program Files\trend micro\Admin.exe
                        C:\WINDOWS\odb.exe
                        C:\WINDOWS\odb.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                        O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                        O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                        O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
                        O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
                        O4 - HKLM\..\Run: [Hvixez] rundll32.exe "C:\WINDOWS\Ujuloco.dll",e
                        O4 - HKLM\..\Run: [odby] C:\WINDOWS\odb.exe
                        O4 - HKLM\..\Run: [UpdateWin] C:\WINDOWS\system32\1041p.exe
                        O4 - HKLM\..\RunServices: [UpdateWin] C:\WINDOWS\system32\1041p.exe
                        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [UpdateWin] C:\WINDOWS\system32\1041p.exe
                        O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\system32\1041p.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                        O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                        O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                        O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
                        O23 - Service: Service Google Update (gupdate1c9a682a5a4045e) (gupdate1c9a682a5a4045e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
                        O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
                        O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                        O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
                        0
                        1. l'infection a eu lieu hier a 18.30

                          :)
                          0
                          1. Fichier odb.exe reçu le 2009.03.24 14:59:49 (CET)
                            Situation actuelle: terminé
                            Résultat: 6/40 (15%)
                            Formaté
                            Impression des résultats
                            Antivirus Version Dernière mise à jour Résultat
                            a-squared 4.0.0.101 2009.03.24 -
                            AhnLab-V3 5.0.0.2 2009.03.24 -
                            AntiVir 7.9.0.120 2009.03.24 TR/Dropper.Gen
                            Antiy-AVL 2.0.3.1 2009.03.24 -
                            Authentium 5.1.2.4 2009.03.23 -
                            Avast 4.8.1335.0 2009.03.23 -
                            AVG 8.5.0.283 2009.03.24 FakeAlert.HY
                            BitDefender 7.2 2009.03.24 -
                            CAT-QuickHeal 10.00 2009.03.24 (Suspicious) - DNAScan
                            ClamAV 0.94.1 2009.03.24 -
                            Comodo 1082 2009.03.23 -
                            DrWeb 4.44.0.09170 2009.03.24 -
                            eSafe 7.0.17.0 2009.03.24 -
                            eTrust-Vet 31.6.6414 2009.03.24 -
                            F-Prot 4.4.4.56 2009.03.23 -
                            F-Secure 8.0.14470.0 2009.03.24 -
                            Fortinet 3.117.0.0 2009.03.24 -
                            GData 19 2009.03.24 -
                            Ikarus T3.1.1.48.0 2009.03.24 -
                            K7AntiVirus 7.10.679 2009.03.23 -
                            Kaspersky 7.0.0.125 2009.03.24 -
                            McAfee 5562 2009.03.23 -
                            McAfee+Artemis 5562 2009.03.23 -
                            McAfee-GW-Edition 6.7.6 2009.03.24 Trojan.Dropper.Gen
                            Microsoft 1.4502 2009.03.24 VirTool:Win32/Obfuscator.EO
                            NOD32 3957 2009.03.24 -
                            Norman 6.00.06 2009.03.24 -
                            nProtect 2009.1.8.0 2009.03.24 -
                            Panda 10.0.0.10 2009.03.24 -
                            PCTools 4.4.2.0 2009.03.24 -
                            Prevx1 V2 2009.03.24 High Risk Cloaked Malware
                            Rising 21.22.12.00 2009.03.24 -
                            Sophos 4.39.0 2009.03.24 -
                            Sunbelt 3.2.1858.2 2009.03.23 -
                            Symantec 1.4.4.12 2009.03.24 -
                            TheHacker 6.3.3.4.288 2009.03.24 -
                            TrendMicro 8.700.0.1004 2009.03.24 -
                            VBA32 3.12.10.1 2009.03.23 -
                            ViRobot 2009.3.24.1661 2009.03.24 -
                            VirusBuster 4.6.5.0 2009.03.23 -
                            Information additionnelle
                            File size: 233984 bytes
                            MD5...: 4a4ff9be46e5dbe64b308ee7577fbaf4
                            SHA1..: e7cb3a2741af849c53a2b8ac66238ec4fa8c8279
                            SHA256: e6a0cc754ded2ae04cf1d48b2112aa0e00425e60b799601891b22a0bfdeca178
                            SHA512: 9c597ddfda77e5bab4ed2bb68b51e096b303d8392afc3cf4ebfe1cbd6aeaa45d
                            688143604dffeace1cd564c225cd13b6b2cd67537ffec7646f9e0a348adab80a
                            ssdeep: 3072:XesfHmSGWlw0s2LHqcVrR5Nq0oUgKihUeQqNUPRAbYeOKOAH7EXHAfw:Osm
                            uwl2FVrJqugUe6Ps6Kx7EXHAI
                            PEiD..: -
                            TrID..: File type identification
                            Win32 Executable Generic (38.4%)
                            Win32 Dynamic Link Library (generic) (34.2%)
                            Clipper DOS Executable (9.1%)
                            Generic Win/DOS Executable (9.0%)
                            DOS Executable Generic (9.0%)
                            PEInfo: PE Structure information

                            ( base data )
                            entrypointaddress.: 0x1461
                            timedatestamp.....: 0x45276aa8 (Sat Oct 07 08:51:52 2006)
                            machinetype.......: 0x14c (I386)

                            ( 4 sections )
                            name viradd virsiz rawdsiz ntrpy md5
                            .text 0x1000 0x13f6c 0x14000 7.98 6633f72e6e466d137776bc4525c7a02e
                            .idata 0x15000 0x740 0x800 4.56 ed76e971b42e982b63e093a3ac481913
                            .data 0x16000 0x3227d 0x24200 7.98 7e3f1e299d702f886080876ac0fd92f0
                            .rsrc 0x49000 0x2e000 0x400 3.44 702735e8a54294e133b47a926205d85a

                            ( 3 imports )
                            > KERNEL32.DLL: CreateFileA, WriteFileGather, OpenSemaphoreW, GetFileAttributesA, FreeEnvironmentStringsA, CreateFileW, VirtualFreeEx, CopyFileExW, EnumSystemCodePagesA, GetCommModemStatus, RaiseException, VirtualProtect, WriteFile, OutputDebugStringA, lstrcpynW, CreateMailslotA, RemoveDirectoryW, GetFullPathNameW, CloseHandle, GlobalFindAtomA, GetCommTimeouts, CreateToolhelp32Snapshot, SetConsoleWindowInfo, EnumResourceNamesA, GetCommandLineA, FindAtomA, CreatePipe, FlushConsoleInputBuffer, WriteConsoleOutputA, GlobalWire, FreeConsole, WritePrivateProfileStringA, GlobalAlloc, GetProfileIntA, GetMailslotInfo
                            > ADVAPI32.DLL: ObjectPrivilegeAuditAlarmA, SetPrivateObjectSecurity, RevertToSelf, CryptDuplicateHash, QueryServiceObjectSecurity, LookupPrivilegeDisplayNameW, InitiateSystemShutdownA, CloseServiceHandle, IsValidSecurityDescriptor, RegUnLoadKeyW, RegSaveKeyW, RegQueryMultipleValuesW, LookupSecurityDescriptorPartsA, GetEffectiveRightsFromAclA, CryptGetKeyParam, ImpersonateNamedPipeClient, ReportEventA
                            > GDI32.DLL: SetAbortProc, SetWindowOrgEx, CreateICW, Arc, GetEnhMetaFileW, DPtoLP, CreateCompatibleDC, GetTextAlign, GetTextMetricsA, SetBitmapBits, GetBrushOrgEx, SetFontEnumeration, DeviceCapabilitiesExA, SetTextColor, PtVisible, RealizePalette, SetMagicColors, ExtSelectClipRgn, DrawEscape, SetPixel

                            ( 0 exports )
                            ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=4a4ff9be46e5dbe64b308ee7577fbaf4' target='_blank'>https://www.symantec.com?md5=4a4ff9be46e5dbe64b308ee7577fbaf4</a>
                            Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=6977031C00B849EF921203442BA59900411E03FB' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=6977031C00B849EF921203442BA59900411E03FB</a>
                            0
                            1. Antivirus Version Dernière mise à jour Résultat
                              a-squared 4.0.0.101 2009.03.24 -
                              AhnLab-V3 5.0.0.2 2009.03.24 -
                              AntiVir 7.9.0.120 2009.03.24 TR/Crypt.ZPACK.Gen
                              Antiy-AVL 2.0.3.1 2009.03.24 -
                              Authentium 5.1.2.4 2009.03.23 -
                              Avast 4.8.1335.0 2009.03.23 -
                              AVG 8.5.0.283 2009.03.24 -
                              BitDefender 7.2 2009.03.24 -
                              CAT-QuickHeal 10.00 2009.03.24 -
                              ClamAV 0.94.1 2009.03.24 -
                              Comodo 1082 2009.03.23 -
                              DrWeb 4.44.0.09170 2009.03.24 -
                              eSafe 7.0.17.0 2009.03.24 Suspicious File
                              eTrust-Vet 31.6.6414 2009.03.24 -
                              F-Prot 4.4.4.56 2009.03.23 -
                              F-Secure 8.0.14470.0 2009.03.24 -
                              Fortinet 3.117.0.0 2009.03.24 -
                              GData 19 2009.03.24 -
                              Ikarus T3.1.1.48.0 2009.03.24 -
                              K7AntiVirus 7.10.679 2009.03.23 -
                              Kaspersky 7.0.0.125 2009.03.24 -
                              McAfee 5562 2009.03.23 -
                              McAfee+Artemis 5562 2009.03.23 -
                              McAfee-GW-Edition 6.7.6 2009.03.24 Trojan.Crypt.ZPACK.Gen
                              Microsoft 1.4502 2009.03.24 Trojan:Win32/Hiloti.gen!A
                              NOD32 3957 2009.03.24 -
                              Norman 6.00.06 2009.03.24 -
                              nProtect 2009.1.8.0 2009.03.24 -
                              Panda 10.0.0.10 2009.03.24 -
                              PCTools 4.4.2.0 2009.03.24 -
                              Prevx1 V2 2009.03.24 High Risk Fraudulent Security Program
                              Rising 21.22.12.00 2009.03.24 -
                              Sophos 4.39.0 2009.03.24 -
                              Sunbelt 3.2.1858.2 2009.03.23 -
                              Symantec 1.4.4.12 2009.03.24 -
                              TheHacker 6.3.3.4.288 2009.03.24 -
                              TrendMicro 8.700.0.1004 2009.03.24 -
                              VBA32 3.12.10.1 2009.03.23 -
                              ViRobot 2009.3.24.1661 2009.03.24 -
                              VirusBuster 4.6.5.0 2009.03.23 -
                              0
                              1. g pa trouvé le ficher C:\WINDOWS\system32\1041p.exe
                                0
                                1. Contributeur sécurité
                                  Pour fusionner:

                                  http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

                                  _______________

                                  telecharge combofix:

                                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                  Sauvegarde le sur ton bureau et pas ailleurs !

                                  _________________

                                  Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

                                  Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                                  File::

                                  C:\WINDOWS\Ujuloco.dll
                                  C:\WINDOWS\system32\1041p.exe
                                  E:\log.exe
                                  C:\WINDOWS\system32\wsnpoem
                                  Registry::
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "Hvixez"=-
                                  "odby"=-
                                  "UpdateWin"=-
                                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "UpdateWin"=-
                                  [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a1453756-023b-11de-be8e-0060b3ff166e}]

                                  Enregistre ce fichier sous le nom CFscript

                                  Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

                                  Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

                                  Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                                  Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                                  Ne touche à rien tant que le scan n'est pas terminé.

                                  Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

                                  Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
                                  0
                                  1. ComboFix 09-03-23.01 - Admin 2009-03-24 16:00:12.1 - NTFSx86
                                    Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.502.199 [GMT 1:00]
                                    Lancé depuis: c:\documents and settings\Admin\Bureau\ComboFix.exe
                                    Commutateurs utilisés :: c:\documents and settings\Admin\Bureau\cfscript.txt
                                    AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)
                                    * Un nouveau point de restauration a été créé
                                    * Resident AV is active

                                    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
                                    .
                                    [color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:[/color]
                                    c:\program files\SuperCopier2\SC2Hook.dll

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    c:\documents and settings\Admin\Application Data\~tmp.html
                                    c:\windows\odb.exe
                                    c:\windows\system32\404Fix.exe
                                    c:\windows\system32\Agent.OMZ.Fix.exe
                                    c:\windows\system32\dumphive.exe
                                    c:\windows\system32\IEDFix.C.exe
                                    c:\windows\system32\IEDFix.exe
                                    c:\windows\system32\o4Patch.exe
                                    c:\windows\system32\Process.exe
                                    c:\windows\system32\SrchSTS.exe
                                    c:\windows\system32\tmp.reg
                                    c:\windows\system32\VACFix.exe
                                    c:\windows\system32\VCCLSID.exe
                                    c:\windows\system32\WS2Fix.exe
                                    c:\windows\system32\wsnpoem
                                    c:\windows\system32\wsnpoem\[u]0[/u]0AFF4EC.uf
                                    c:\windows\system32\wsnpoem\audio.dll
                                    c:\windows\system32\wsnpoem\audio.dll.cla
                                    c:\windows\system32\wsnpoem\video.dll
                                    c:\windows\Ujuloco.dll

                                    .
                                    ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-24 au 2009-03-24 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2009-03-24 14:16 . 2009-03-24 14:38 <REP> d-------- C:\ToolBar SD
                                    2009-03-24 13:28 . 2009-03-24 13:28 <REP> d-------- c:\documents and settings\Admin\Application Data\Malwarebytes
                                    2009-03-24 13:28 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                                    2009-03-24 13:28 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                                    2009-03-24 13:27 . 2009-03-24 13:28 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                                    2009-03-24 13:27 . 2009-03-24 13:27 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                                    2009-03-24 13:12 . 2009-03-24 13:14 <REP> d-------- C:\rsit
                                    2009-03-24 13:12 . 2009-03-24 14:48 <REP> d-------- c:\program files\trend micro
                                    2009-03-23 22:33 . 2009-03-23 22:34 <REP> d-------- c:\program files\Yahoo!
                                    2009-03-23 22:33 . 2009-03-23 22:33 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
                                    2009-03-23 22:33 . 2009-03-23 22:33 <REP> d-------- c:\documents and settings\Admin\Application Data\Yahoo!
                                    2009-03-23 22:32 . 2009-03-23 22:34 <REP> d-------- c:\program files\CCleaner
                                    2009-03-23 18:31 . 2009-03-23 18:30 41,472 -r-hs---- c:\windows\system32\1041p.exe
                                    2009-03-23 18:31 . 2009-03-23 18:37 128 --ahs---- c:\windows\system32\2889825949.dat
                                    2009-03-17 18:18 . 2009-03-17 18:18 <REP> dr-h----- c:\documents and settings\Admin\Application Data\SecuROM
                                    2009-03-16 22:55 . 2009-03-24 10:55 <REP> d-------- c:\documents and settings\All Users\Application Data\Google Updater
                                    2009-03-15 17:24 . 2009-03-15 17:30 <REP> d-------- c:\program files\VirtualDJ
                                    2009-03-07 12:47 . 2009-03-07 12:47 <REP> d-------- c:\program files\Windows Media Connect 2
                                    2009-03-06 20:17 . 2009-03-06 20:17 <REP> d-------- c:\windows\Sun
                                    2009-03-06 14:48 . 2008-04-14 03:33 159,232 --a------ c:\windows\system32\ptpusd.dll
                                    2009-03-06 14:48 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
                                    2009-03-06 14:48 . 2008-04-13 19:45 15,104 --a------ c:\windows\system32\dllcache\usbscan.sys
                                    2009-03-06 14:48 . 2001-08-23 17:47 5,632 --a------ c:\windows\system32\ptpusb.dll
                                    2009-03-03 22:01 . 2009-03-03 22:01 <REP> d-------- c:\documents and settings\Admin\Application Data\AdobeUM
                                    2009-03-03 21:51 . 2009-03-03 21:52 <REP> d-------- c:\program files\Fichiers communs\Adobe
                                    2009-03-01 14:06 . 2009-03-01 13:21 6,114 --a------ c:\windows\BricoPackFoldersDelete.cmd
                                    2009-03-01 14:04 . 2009-03-01 14:04 <REP> d-------- c:\windows\BricoPacks
                                    2009-03-01 13:21 . 2009-03-01 13:21 65,385 --a------ c:\windows\BricoPackUninst.cmd
                                    2009-02-27 18:54 . 2008-07-31 23:17 9,200 --------- c:\windows\system32\drivers\cdralw2k.sys
                                    2009-02-27 18:54 . 2008-07-31 23:17 9,072 --------- c:\windows\system32\drivers\cdr4_xp.sys
                                    2009-02-27 18:32 . 2009-02-27 18:32 <REP> d-------- c:\windows\system32\IOSUBSYS
                                    2009-02-26 19:54 . 2009-03-17 18:18 107,888 --a------ c:\windows\system32\CmdLineExt.dll
                                    2009-02-26 18:57 . 2009-02-26 18:57 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools Pro
                                    2009-02-26 18:57 . 2009-02-26 18:57 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools
                                    2009-02-26 18:55 . 2009-02-26 18:55 <REP> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
                                    2009-02-26 18:12 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
                                    2009-02-26 18:04 . 2009-02-26 18:04 717,296 --a------ c:\windows\system32\drivers\sptd.sys
                                    2009-02-26 18:03 . 2009-02-26 18:03 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools Lite
                                    2009-02-25 10:20 . 2009-03-23 18:32 31,891,667 --a------ c:\windows\pfirewall.log.old
                                    2009-02-24 18:55 . 2009-02-24 19:21 <REP> d-------- c:\program files\Condition Zero
                                    2009-02-24 08:00 . 2009-03-24 16:00 <REP> d-------- C:\QUARANTINE
                                    2009-02-24 07:31 . 2009-02-24 07:31 <REP> d-------- c:\program files\Fichiers communs\DirectX

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2009-03-24 15:08 --------- d-----w c:\program files\SuperCopier2
                                    2009-03-24 11:09 --------- d-----w c:\program files\Google
                                    2009-03-17 20:04 --------- d--h--w c:\program files\InstallShield Installation Information
                                    2009-03-17 20:04 --------- d-----w c:\program files\Fichiers communs\InstallShield
                                    2009-03-10 12:26 --------- d-----w c:\documents and settings\Admin\Application Data\uTorrent
                                    2009-03-01 12:21 219,648 ----a-w c:\windows\system32\uxtheme.dll
                                    2009-02-23 21:06 410,984 ----a-w c:\windows\system32\deploytk.dll
                                    2009-02-23 21:05 --------- d-----w c:\program files\Java
                                    2009-02-21 12:57 --------- d-----w c:\program files\Microsoft Works
                                    2009-02-20 19:28 --------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
                                    2009-02-20 17:44 --------- d-----w c:\program files\Ares
                                    2009-02-20 17:18 --------- d-----w c:\program files\Windows Live
                                    2009-02-20 17:17 --------- d-----w c:\program files\Microsoft Sync Framework
                                    2009-02-20 17:16 --------- d-----w c:\program files\Windows Live SkyDrive
                                    2009-02-20 17:16 --------- d-----w c:\program files\Microsoft
                                    2009-02-20 16:37 --------- d-----w c:\program files\Fichiers communs\Windows Live
                                    2009-02-20 11:00 402,432 ----a-w c:\windows\system32\drivers\WlanBZXP.sys
                                    2009-02-19 14:54 --------- d-----w c:\program files\McAfee
                                    2009-02-19 14:54 --------- d-----w c:\program files\Fichiers communs\Cisco Systems
                                    2009-02-19 14:54 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
                                    2009-02-19 14:53 --------- d-----w c:\program files\Fichiers communs\McAfee
                                    2009-02-19 14:50 --------- d-----w c:\program files\SLD Codec Pack
                                    2009-02-09 14:05 1,846,912 ----a-w c:\windows\system32\win32k.sys
                                    2009-02-09 14:05 1,846,912 ------w c:\windows\system32\dllcache\win32k.sys
                                    2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
                                    2009-01-16 20:15 3,594,752 ------w c:\windows\system32\dllcache\mshtml.dll
                                    2009-01-05 22:33 3,751,995 ----a-w c:\windows\system32\GPhotos.scr
                                    .

                                    ------- Sigcheck -------

                                    2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
                                    2008-06-20 11:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
                                    2008-06-20 12:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
                                    2008-06-20 12:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
                                    2008-06-20 11:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\$NtServicePackUninstall$\tcpip.sys
                                    2004-08-05 13:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtUninstallKB941644$\tcpip.sys
                                    2008-04-13 20:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\$NtUninstallKB951748$\tcpip.sys
                                    2007-10-30 18:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
                                    2008-04-13 20:20 361344 accf5a9a1ffaa490f33dba1c632b95e1 c:\windows\ServicePackFiles\i386\tcpip.sys
                                    2008-06-20 12:51 361600 9425b72f40257b45d45d24773273dad0 c:\windows\system32\dllcache\tcpip.sys
                                    2008-06-20 12:51 361600 9425b72f40257b45d45d24773273dad0 c:\windows\system32\drivers\tcpip.sys
                                    .
                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                                    "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2005-03-14 1057280]
                                    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                                    "ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
                                    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
                                    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
                                    "Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]
                                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-23 136600]
                                    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
                                    "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
                                    "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2006-11-30 112216]
                                    "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]

                                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                    "msacm.l3acm"= l3codecp.acm

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                                    UpdateWin REG_SZ c:\windows\system32\1041p.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                    "AntiVirusDisableNotify"=dword:00000001
                                    "UpdatesDisableNotify"=dword:00000001
                                    "AntiVirusOverride"=dword:00000001
                                    "FirewallOverride"=dword:00000001

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                    "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
                                    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                                    "c:\\Program Files\\Ares\\Ares.exe"=
                                    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                    "c:\\Program Files\\Condition Zero\\hl.exe"=
                                    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                                    "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=

                                    R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
                                    R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\drivers\WlanBZXP.sys [2009-02-20 402432]
                                    R3 SMBus_2k;SMBus_2k;c:\windows\system32\drivers\SMBus_2k.sys [2008-01-15 14208]
                                    S2 gupdate1c9a682a5a4045e;Service Google Update (gupdate1c9a682a5a4045e);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-16 133104]

                                    --- Autres Services/Pilotes en mémoire ---

                                    *Deregistered* - mchInjDrv
                                    .
                                    Contenu du dossier 'Tâches planifiées'

                                    2009-03-24 c:\windows\Tasks\Google Software Updater.job
                                    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-16 22:55]

                                    2009-03-24 c:\windows\Tasks\GoogleUpdateTaskMachine.job
                                    - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-16 23:00]
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    SharedTaskScheduler-IPC Configuration Utility - (no file)
                                    Notify-NavLogon - (no file)

                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    uStart Page = hxxp://www.google.fr/
                                    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                                    uDefault_Search_URL = hxxp://www.google.com/ie
                                    mWindow Title =
                                    uInternet Settings,ProxyServer = proxy:8080
                                    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                                    IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
                                    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                                    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
                                    IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
                                    IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
                                    FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\il907ttu.default\
                                    FF - plugin: c:\program files\Google\Google Updater\2.4.1508.6312\npCIDetect13.dll
                                    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
                                    FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
                                    .

                                    **************************************************************************

                                    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2009-03-24 16:10:32
                                    Windows 5.1.2600 Service Pack 3 NTFS

                                    Recherche de processus cachés ...

                                    Recherche d'éléments en démarrage automatique cachés ...

                                    Recherche de fichiers cachés ...

                                    Scan terminé avec succès
                                    Fichiers cachés: 0

                                    **************************************************************************

                                    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
                                    "ImagePath"="\??\c:\docume~1\Admin\LOCALS~1\Temp\mc29.tmp"
                                    .
                                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                                    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                                    .
                                    --------------------- DLLs chargées dans les processus actifs ---------------------

                                    - - - - - - - > 'explorer.exe'(3052)
                                    c:\program files\SuperCopier2\SC2Hook.dll
                                    .
                                    ------------------------ Autres processus actifs ------------------------
                                    .
                                    c:\program files\Java\jre6\bin\jqs.exe
                                    c:\program files\McAfee\Common Framework\FrameworkService.exe
                                    c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
                                    c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
                                    c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                    c:\program files\McAfee\Common Framework\naPrdMgr.exe
                                    c:\program files\CyberLink\Shared files\RichVideo.exe
                                    c:\program files\McAfee\Common Framework\Mctray.exe
                                    .
                                    **************************************************************************
                                    .
                                    Heure de fin: 2009-03-24 16:18:17 - La machine a redémarré
                                    ComboFix-quarantined-files.txt 2009-03-24 15:18:02

                                    Avant-CF: 23 920 517 120 octets libres
                                    Après-CF: 23,950,397,440 octets libres

                                    237 --- E O F --- 2009-03-13 21:04:05
                                    0
                                    1. larriere plan est revenu merci infiniment
                                      k t dieu te béniss !!!
                                      0
                                      • 1
                                      • 2