Vista Internet Security 2010

Bonjour,

Mon Vista est infecté avec Internet Security 2010. A chaque démarrage il m'avertit que l'ordinateur est infecté, et après une analyse automatique il trouve 26 virus qui sont quasiment impossibles à supprimer !

A l'aide !

29 réponses

Résumé de la discussion

Un ordinateur sous Vista signale une infection Internet Security 2010 à chaque démarrage et identifie une quarantaine de menaces, dont 26 virus quasi impossibles à supprimer. Plusieurs réponses proposent des outils et méthodes variés, tels que GMER, ATF Cleaner, ToolsCleaner2 et USBFix, ainsi que des analyses en ligne et le partage des rapports pour confirmer le nettoyage. Des conseils pratiques incluent l'exécution en administrateur, la désactivation temporaire des protections et l'importation des rapports (.log, .txt) après chaque étape, avec des recommandations sur la gestion de la quarantaine et l'évaluation des résultats. Des nuances utiles indiquent que les résultats dépendent de l’exécution correcte des outils et de la validation des rapports, sans garantie de suppression immédiate et intégrale.

Bobot (l’IA à votre service)
  1. oui lol ces moi qui bug j'ai plusieurs topic qui ont le même nom

    re

    Télécharge gmer sur ton bureau ( IMPORTANT )
    http://www.gmer.net/#files

    Précautions d’usage :
    - Durant l’utilisation du logiciel, désactive tes protections actives ( antivirus et parefeu )
    - Ferme également toutes les applications actives dont ton navigateur.

    # Double-clique sur l’exécutable téléchargé .
    ( Si sous Vista , click droit sur l’exécutable et choisir exécuter en tant qu’administrateur )
    # Le scan va se lancer de lui-même.
    # Après cette première analyse, vérifie que tous les onglets ( System, Sections, … , Files ) sont cochés puis clique sur scan .
    # A la fin de l'analyse, clique sur save pour enregistrer le rapport
    # Enregistre-le sur le bureau ( fichier .log )

    Édite ce rapport dans ta prochaine réponse.
    1
    1. normale ces un rogue un faux logiciel de sécurité qui a pour but de te faire payer son produit qui ne marche pas

      Téléchargez MalwareByte's Anti-Malware

      http://www.malwarebytes.org/mbam/program/mbam-setup.exe

      . Enregistres le sur le bureau
      . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
      . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
      . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
      . Une fois la mise à jour terminé
      . Rend-toi dans l'onglet, Recherche
      . Sélectionnes Exécuter un examen complet
      . Cliques sur Rechercher
      . Le scan démarre.
      . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
      . Cliques sur Ok pour poursuivre.
      . Si des malwares ont été détectés, clique sur Afficher les résultats
      . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine. . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
      . Rends toi dans l'onglet rapport/log
      . Tu cliques dessus pour l'afficher, une fois affiché
      . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
      . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
      . tu cliques droit dans le cadre de la reponse et coller

      Si tu as besoin d'aide regarde ces tutoriels :
      Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
      http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

      si cela coince, faire la même chose en mode sans échec

      https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
      0
      1. Merci pour réponse.

        Voici le copier/coller du rapport de MalwareBytes :

        Malwarebytes' Anti-Malware 1.44
        Version de la base de données: 3809
        Windows 6.0.6002 Service Pack 2
        Internet Explorer 7.0.6002.18005

        01/03/2010 21:02:20
        mbam-log-2010-03-01 (21-02-09).txt

        Type de recherche: Examen complet (C:\|)
        Eléments examinés: 259338
        Temps écoulé: 1 hour(s), 33 minute(s), 46 second(s)

        Processus mémoire infecté(s): 2
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 9
        Valeur(s) du Registre infectée(s): 6
        Elément(s) de données du Registre infecté(s): 17
        Dossier(s) infecté(s): 1
        Fichier(s) infecté(s): 26

        Processus mémoire infecté(s):
        C:\Windows\System32\smss32.exe (Trojan.FakeAlert) -> No action taken.
        C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\F5JMWNZTHI (Trojan.FakeAlert) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\IS2010 (Rogue.InternetSecurity2010) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure (Rogue.SpywareSecure) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Purchased Products (Rogue.Multiple) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\ugescw (Rogue.BugsDestroyer) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\ROUA3O12PW (Trojan.FakeAlert) -> No action taken.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kfbqurf (Trojan.Agent.H) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\internet security 2010 (Rogue.Installer) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f5jmwnzthi (Trojan.FakeAlert) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\losalamos (Trojan.FakeAlert) -> No action taken.

        Elément(s) de données du Registre infecté(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon32.exe -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon32.exe -> No action taken.
        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-is2010.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-is2010.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is10-soft-download.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-Internetsecurity10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-Internetsecurity10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download25.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\Windows\system32\winlogon32.exe) Good: (userinit.exe) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

        Dossier(s) infecté(s):
        C:\Program Files\InternetSecurity2010 (Rogue.InternetSecurity2010) -> No action taken.

        Fichier(s) infecté(s):
        C:\Users\charlotte\Local Settings\Application Data\kfbqurf_navps.dat (Adware.Navipromo.H) -> No action taken.
        C:\Users\charlotte\Local Settings\Application Data\kfbqurf_nav.dat (Adware.Navipromo.H) -> No action taken.
        C:\Users\charlotte\Local Settings\Application Data\kfbqurf.dat (Adware.Navipromo.H) -> No action taken.
        C:\Users\charlotte\Local Settings\Application Data\kfbqurf.exe (Adware.Navipromo.H) -> No action taken.
        c:\Users\charlotte\AppData\Local\kfbqurf.exe (Trojan.Agent.H) -> No action taken.
        C:\Windows\System32\smss32.exe (Trojan.FakeAlert) -> No action taken.
        C:\Program Files\InternetSecurity2010\IS2010.exe (Rogue.Installer) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\473F.tmp (Rootkit.TDSS) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\xmswocarne.exe (Trojan.Downloader) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\E81D.exe (Rootkit.TDSS) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\rmaencoxws.exe (Trojan.FakeAlert) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\F40E.exe (Rootkit.TDSS) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\cswormnexa.exe (Trojan.Hiloti) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\Aqz.exe (Trojan.Crypt) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\awenmsxroc.exe (Rootkit.TDSS) -> No action taken.
        C:\Users\charlotte\AppData\Local\VirtualStore\Windows\System32\net.net (Trojan.Downloader) -> No action taken.
        C:\Windows\System32\helper32.dll (Trojan.FakeAlert) -> No action taken.
        C:\Windows\System32\winlogon32.exe (Trojan.FakeAlert) -> No action taken.
        C:\Users\charlotte\AppData\Local\Temp\sshnas21.dll (Trojan.Downloader) -> No action taken.
        C:\Users\charlotte\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> No action taken.
        C:\Users\charlotte\AppData\Roaming\Microsoft\Windows\Start Menu\Internet Security 2010.lnk (Rogue.InternetSecurity2010) -> No action taken.
        C:\Windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job (Trojan.Downloader) -> No action taken.
        C:\Users\charlotte\Local Settings\Application Data\ljmqiey_nav.dat (Adware.NaviPromo) -> No action taken.
        C:\Windows\msa.exe (Trojan.Agent) -> No action taken.
        C:\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> No action taken.
        C:\Windows\System32\41.exe (Trojan.FakeAlert) -> No action taken.
        0
        1. tu n'a pas supprimer ce qu'il a trouve va dans la quarantaine puis supprime tous ce qui s'y trouve
          0
          1. Oui, oups, ça y est je viens de le faire ! Il ne reste plus rien en quarantaine, j'ai effacé tout ce qui s'y trouvait !
            0
            1. Téléchargez USBFIX de El Desaparecido, C_xx

              http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­­
              ou
              https://www.ionos.fr/?affiliate_id=77097

              • Lance l'installation avec les paramètres par défaut.
              • Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
              • Double-clique sur le raccourci UsbFix sur ton Bureau.
              • Choisis l'option 1 (Recherche).
              • Laisse travailler l'outil.
              • Poste le rapport UsbFix.txt.

              Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

              "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.eau .

              # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
              0
              1. Voici le rapport USBFix comme tu me l'as demandé :

                ############################## | UsbFix V6.097 |

                User : charlotte (Administrateurs) # PC-DE-CHARLOTTE
                Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                Start at: 21:23:30 | 01/03/2010
                Website : http://pagesperso-orange.fr/NosTools/index.html
                Contact : FindyKill.Contact@gmail.com

                Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                Internet Explorer 7.0.6002.18005
                Windows Firewall Status : Enabled
                AV : avast! antivirus 4.8.1229 [VPS 081217-0] 4.8.1229 [ Enabled | Updated ]

                C:\ -> Disque fixe local # 179,09 Go (107,95 Go free) # NTFS
                D:\ -> Disque amovible
                E:\ -> Disque amovible
                F:\ -> Disque CD-ROM
                G:\ -> Disque amovible # 14,94 Go (14,84 Go free) [RALLYE2] # NTFS

                ############################## | Processus actifs |

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                C:\Windows\System32\svchost.exe
                C:\Program Files\Sony\Network Utility\NSUService.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\DRIVERS\xaudio.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                C:\Windows\system32\igfxext.exe
                C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Windows\system32\WUDFHost.exe
                C:\Windows\system32\igfxext.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\System32\igfxpers.exe
                C:\Program Files\Apoint\Apoint.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                C:\Program Files\Apoint\ApMsgFwd.exe
                C:\Program Files\Sony\Network Utility\LANUtil.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Users\charlotte\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                C:\Program Files\Apoint\Apntex.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
                C:\Windows\system32\taskeng.exe
                \\?\C:\Windows\system32\wbem\WMIADAP.EXE
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                ################## | Elements infectieux |

                C:\Users\CHARLO~1\AppData\Local\Temp\a.dat
                C:\Users\CHARLO~1\AppData\Local\Temp\Aq0.exe
                C:\Users\CHARLO~1\AppData\Local\Temp\Aq1.exe

                ################## | Registre |

                ################## | Mountpoints2 |

                HKCU\..\..\Explorer\MountPoints2\G
                shell\AutoRun\command =G:\Autorun\Autorun.exe

                HKCU\..\..\Explorer\MountPoints2\H
                shell\AutoRun\command =H:\LaunchU3.exe -a

                HKCU\..\..\Explorer\MountPoints2\{349fb8e9-f0a4-11dc-801d-001a801c4204}
                shell\AutoRun\command =H:\LaunchU3.exe -a

                HKCU\..\..\Explorer\MountPoints2\{ada2b490-b947-11dc-8f75-001a801c4204}
                shell\Auto\command =AdobeR.exe e
                shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

                ################## | Vaccin |

                (!) Cet ordinateur n'est pas vacciné !

                ################## | ! Fin du rapport # UsbFix V6.097 ! |
                0
                1. C'est fait, USBFix a affiché dans sa fenêtre "Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-charlotte.zip".
                  Que dois-je faire exactement ?
                  0
                  1. tu envoi le fichier a l'adresse demandé

                    poste le rapport
                    0
                    1. Voici le rapport UsbFix après suppression :

                      ############################## | UsbFix V6.097 |

                      User : charlotte (Administrateurs) # PC-DE-CHARLOTTE
                      Update on 20/02/2010 by El Desaparecido , C_XX & Chimay8
                      Start at: 21:36:27 | 01/03/2010
                      Website : http://pagesperso-orange.fr/NosTools/index.html
                      Contact : FindyKill.Contact@gmail.com

                      Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                      Internet Explorer 7.0.6002.18005
                      Windows Firewall Status : Enabled
                      AV : avast! antivirus 4.8.1229 [VPS 081217-0] 4.8.1229 [ Enabled | Updated ]

                      C:\ -> Disque fixe local # 179,09 Go (107,86 Go free) # NTFS
                      D:\ -> Disque amovible
                      E:\ -> Disque amovible
                      F:\ -> Disque CD-ROM
                      G:\ -> Disque amovible # 14,94 Go (14,84 Go free) [RALLYE2] # NTFS

                      ############################## | Processus actifs |

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\runonce.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                      C:\Windows\System32\svchost.exe
                      C:\Program Files\Sony\Network Utility\NSUService.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                      C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\DRIVERS\xaudio.exe
                      C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                      C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                      C:\Windows\system32\igfxext.exe
                      C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Windows\system32\igfxext.exe
                      C:\Windows\system32\igfxsrvc.exe
                      C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                      C:\Windows\system32\wbem\wmiprvse.exe
                      C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                      C:\Windows\system32\PresentationSettings.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

                      ################## | Elements infectieux |

                      Supprimé ! C:\Users\CHARLO~1\AppData\Local\Temp\a.dat
                      Supprimé ! C:\Users\CHARLO~1\AppData\Local\Temp\Aq0.exe
                      Supprimé ! C:\Users\CHARLO~1\AppData\Local\Temp\Aq1.exe
                      Supprimé ! C:\Users\CHARLO~1\AppData\Local\Temp\65595.exe
                      Supprimé ! C:\Users\CHARLO~1\AppData\Local\Temp\8BD54F3E-DD19-4a69-93D8-5C6A5BBBE20E.exe
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-1437328930-1453272024-3085227174-500
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-1932403824-1131286293-3896414113-1000
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2152478756-3922319563-605102323-500
                      Supprimé ! C:\$Recycle.Bin\S-1-5-21-2538731447-3340924788-38760989-500

                      ################## | Registre |

                      ################## | Mountpoints2 |

                      Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{349fb8e9-f0a4-11dc-801d-001a801c4204}\Shell\AutoRun\Command
                      Supprimé ! HKCU\...\Explorer\MountPoints2\{ada2b490-b947-11dc-8f75-001a801c4204}\Shell\Auto\Command

                      ################## | Listing des fichiers présent |

                      [18/09/2006 22:43|--a------|24] C:\autoexec.bat
                      [11/04/2009 07:36|-rahs----|333257] C:\bootmgr
                      [03/08/2007 02:08|-ra-s----|8192] C:\BOOTSECT.BAK
                      [18/09/2006 22:43|--a------|10] C:\config.sys
                      [?|?|?] C:\hiberfil.sys
                      [?|?|?] C:\pagefile.sys
                      [04/03/2009 13:39|--a------|594] C:\updatedatfix.log
                      [01/03/2010 21:40|--a------|4590] C:\UsbFix.txt
                      [01/03/2010 21:26|--a------|5119] G:\Rapport USBfix.txt
                      [01/03/2010 21:20|--a------|1775008] G:\UsbFix.exe

                      ################## | Vaccination |

                      # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                      # G:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                      ################## | Upload |

                      Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_PC-de-charlotte.zip : https://www.ionos.fr/?affiliate_id=77097
                      Merci pour votre contribution .
                      0
                      1. ►Télécharge Télécharge /random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
                        http://images.malwareremoval.com/random/RSIT.exe

                        ►Ensuite double clique sur : RSIT.exe

                        ►Un moment un message apparait : "Disclaimaire of warranty" clique sur continuer.

                        ►Patientes lors du scanne.

                        ►A la fin du scanne.

                        ►Deux bloc note s'ouvriront.

                        ►Il s'appelle : log.txt et info.txt

                        ►Ensuite va sur ce site :

                        http://www.cijoint.fr/index.php

                        ►Clique sur parcourir et sélectionne les fichier :

                        ►C:\rsit\info.txt

                        ►C:\rsit\log.txt

                        ►Sa serras en forme de lien.

                        ►Envoie moi les deux liens, dans ta prochaines réponse.
                        0
                        1. Voici le lien concernant le fichier info.txt :

                          http://www.cijoint.fr/cjlink.php?file=cj201003/cijDrwrY0x.txt

                          Et voici celui de log.txt :

                          http://www.cijoint.fr/cjlink.php?file=cj201003/cijd7zFLrd.txt
                          0
                          1. Téléchargez USBFIX de El Desaparecido, C_xx

                            http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­­
                            ou
                            https://www.ionos.fr/?affiliate_id=77097

                            • Lance l'installation avec les paramètres par défaut.
                            • Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
                            • Double-clique sur le raccourci UsbFix sur ton Bureau.
                            • Choisis l'option 1 (Recherche).
                            • Laisse travailler l'outil.
                            • Poste le rapport UsbFix.txt.

                            Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).

                            "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.eau .

                            # Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
                            0
                            1. Contributeur sécurité
                              hello,

                              Multiples infections avec rootkit TDSS V3 sur Vista ... intéressant ... pour suivre ...

                              Pourquoi encore UsbFix , c'est déjà fait non ? .... ^^"
                              0
                          2. Heu... cette consigne s'adresse à qui ? ^^
                            0
                            1. fait gmer

                              crapoulou ben oui la plupart des infection par msn sont détecter par USBfix lol option 1 aucun risque ensuite rsit pour le reste de l'infection
                              0
                              1. Voici le rapport de GMER :

                                GMER 1.0.15.15281 - http://www.gmer.net
                                Rootkit scan 2010-03-01 23:14:31
                                Windows 6.0.6002 Service Pack 2
                                Running: xojci9ru.exe; Driver: C:\Users\CHARLO~1\AppData\Local\Temp\kxtoyuod.sys

                                ---- User code sections - GMER 1.0.15 ----

                                .text C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe[3876] kernel32.dll!SetUnhandledExceptionFilter 7763A84F 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}

                                ---- User IAT/EAT - GMER 1.0.15 ----

                                IAT C:\Windows\system32\services.exe[652] @ C:\Windows\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 001F0002
                                IAT C:\Windows\system32\services.exe[652] @ C:\Windows\system32\services.exe [KERNEL32.dll!CreateProcessW] 001F0000
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74AE7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74B3A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74AEBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74ADF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74AE75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74ADE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74B18395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74AEDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74ADFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74ADFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74AD71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74B6CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74B0C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74ADD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74AD6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74AD687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
                                IAT C:\Windows\Explorer.EXE[1892] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74AE2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

                                ---- Devices - GMER 1.0.15 ----

                                AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
                                AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
                                AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)

                                ---- EOF - GMER 1.0.15 ----
                                0
                                1. sous vista : Désactives le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection).

                                  comme sa https://www.androidworld.fr/

                                  Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                  Ou ici : https://forospyware.com
                                  >Renomme le pour l’enregistrer sur ton bureau en asdehi (tout simplement pour que l’infection ne le contre pas)
                                  -> Double clique combofix.exe.(ou clic droit sous vista « exécuter en tant que… » )
                                  -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                                  -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                                  NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                                  Avant d'utiliser ComboFix :

                                  -> Déconnecte toi d'Internet et referme les fenêtres de tous les programmes en cours.

                                  -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                                  Une fois fait, sur ton bureau double-clic sur Combofix.exe ; (ou clic droit sous vista « exécuter en tant que… »)

                                  - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                                  - Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programme. Risque de figer l'ordinateur

                                  - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                                  - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                                  -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                                  -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                                  /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordinateur (plantage complet)

                                  ::Si combofix détecte quelque chose et de demande a redémarrer tu acceptes
                                  0
                                  1. Voila le rapport Combofix :

                                    ComboFix 10-03-01.01 - charlotte 01/03/2010 23:40:48.1.2 - x86
                                    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2038.883 [GMT 1:00]
                                    Lancé depuis: c:\users\charlotte\Desktop\ashdi.exe
                                    AV: avast! antivirus 4.8.1229 [VPS 081217-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                                    SP: avast! antivirus 4.8.1229 [VPS 081217-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                                    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                                    .

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Spyware-Secure
                                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Website.lnk
                                    c:\users\charlotte\AppData\Local\bpvzzo_navfx.dat
                                    c:\users\charlotte\AppData\Local\bpvzzo_navtmp.dat
                                    c:\users\charlotte\AppData\Local\sssulbxyx_navtmp.dat
                                    c:\users\charlotte\AppData\Local\xqfkafxqw_navtmp.dat
                                    c:\windows\system32\11478.exe
                                    c:\windows\system32\15724.exe
                                    c:\windows\system32\18467.exe
                                    c:\windows\system32\19169.exe
                                    c:\windows\system32\26500.exe
                                    c:\windows\system32\6334.exe

                                    .
                                    ((((((((((((((((((((((((((((( Fichiers créés du 2010-02-01 au 2010-03-01 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2010-03-01 22:48 . 2010-03-01 22:48 -------- d-----w- c:\users\Default\AppData\Local\temp
                                    2010-03-01 21:07 . 2010-03-01 21:07 -------- d-----w- c:\program files\trend micro
                                    2010-03-01 21:07 . 2010-03-01 21:07 -------- d-----w- C:\rsit
                                    2010-03-01 20:40 . 2010-03-01 20:40 9956009 ----a-w- C:\UsbFix_Upload_Me_PC-de-charlotte.zip
                                    2010-03-01 20:22 . 2010-03-01 20:40 -------- d-----w- C:\UsbFix
                                    2010-03-01 18:26 . 2010-03-01 18:26 -------- d-----w- c:\users\charlotte\AppData\Roaming\Malwarebytes
                                    2010-03-01 18:26 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                    2010-03-01 18:26 . 2010-03-01 18:26 -------- d-----w- c:\programdata\Malwarebytes
                                    2010-03-01 18:26 . 2010-03-01 18:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                    2010-03-01 18:26 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                                    2010-02-13 11:52 . 2009-12-04 15:56 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
                                    2010-02-13 11:52 . 2009-12-04 15:56 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
                                    2010-02-13 11:52 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
                                    2010-02-13 11:52 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
                                    2010-02-13 11:52 . 2009-12-08 20:01 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
                                    2010-02-13 11:52 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
                                    2010-02-13 11:51 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
                                    2010-02-13 11:51 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
                                    2010-02-13 11:51 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
                                    2010-02-13 11:51 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
                                    2010-02-13 11:46 . 2010-03-01 20:05 -------- d-----w- c:\windows\Sun

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2010-03-01 20:42 . 2006-11-02 15:48 669566 ----a-w- c:\windows\system32\perfh00C.dat
                                    2010-03-01 20:42 . 2006-11-02 15:48 123556 ----a-w- c:\windows\system32\perfc00C.dat
                                    2010-03-01 20:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
                                    2010-03-01 18:23 . 2009-01-22 20:24 94 ----a-w- c:\users\charlotte\AppData\Local\mqesc.bat
                                    2010-03-01 18:05 . 2007-08-03 09:54 -------- d-----w- c:\programdata\Microsoft Help
                                    2010-01-29 14:08 . 2010-01-29 14:08 86576 ----a-w- c:\users\charlotte\AppData\Roaming\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
                                    2010-01-29 14:08 . 2010-01-29 14:08 392728 ----a-w- c:\users\charlotte\AppData\Roaming\Microsoft\Services Windows Live\Services Windows Live.dll
                                    2010-01-29 14:08 . 2010-01-29 14:08 135680 ----a-w- c:\users\charlotte\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                                    2010-01-29 14:08 . 2010-01-29 14:08 132672 ----a-w- c:\users\charlotte\AppData\Roaming\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
                                    2010-01-24 01:00 . 2009-10-07 19:40 -------- d-----w- c:\program files\Microsoft Silverlight
                                    2010-01-14 10:12 . 2009-10-07 17:47 181120 ------w- c:\windows\system32\MpSigStub.exe
                                    2009-12-18 13:01 . 2010-01-22 23:58 78336 ----a-w- c:\windows\system32\ieencode.dll
                                    2009-12-16 11:44 . 2010-01-22 23:59 834048 ----a-w- c:\windows\system32\wininet.dll
                                    2009-12-13 23:11 . 2009-12-13 23:11 653576 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
                                    2009-11-29 22:18 . 2008-09-23 22:32 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
                                    .

                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
                                    "NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-01-16 253952]
                                    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                                    "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
                                    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-30 137752]
                                    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-30 154136]
                                    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-30 133656]
                                    "Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
                                    "RtHDVCpl"="RtHDVCpl.exe" [2007-06-26 4489216]
                                    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-06-11 317560]
                                    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-11-29 30192]
                                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-10 136600]
                                    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
                                    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                                    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
                                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
                                    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
                                    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-06-02 81920]

                                    c:\users\charlotte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                    Notification de cadeaux MSN.lnk - c:\users\charlotte\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2010-1-29 135680]

                                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
                                    NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2007-12-16 118784]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                    "EnableLUA"= 0 (0x0)
                                    "EnableUIADesktopToggle"= 0 (0x0)

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                                    "HonorAutoRunSetting"= 0 (0x0)

                                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                                    "HonorAutoRunSetting"= 0 (0x0)

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
                                    2007-07-24 17:26 98304 ----a-w- c:\windows\System32\VESWinlogon.dll

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                    "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll

                                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                                    @="Service"

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                    "DisableMonitoring"=dword:00000001

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                    "DisableMonitoring"=dword:00000001

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                    "DisableMonitoring"=dword:00000001

                                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
                                    "VistaSp2"=hex(b):43,45,c1,43,ad,4e,ca,01

                                    R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [21/06/2008 10:51 111184]
                                    R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [21/06/2008 10:51 20560]
                                    R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [05/11/2007 15:50 51792]
                                    R2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [21/03/2008 16:23 204800]
                                    R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [03/08/2007 02:07 812544]
                                    S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [07/10/2009 20:40 54632]
                                    S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
                                    S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/08/2007 11:03 30192]
                                    S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [12/08/2007 09:50 415392]
                                    S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [12/08/2007 10:14 745472]
                                    S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [12/08/2007 10:14 397312]
                                    S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [12/08/2007 10:14 1089536]
                                    S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [12/08/2007 10:09 292152]
                                    S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [02/01/2008 16:08 79136]

                                    --- Autres Services/Pilotes en mémoire ---

                                    *NewlyCreated* - KXTOYUOD
                                    *Deregistered* - kxtoyuod

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                                    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                                    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
                                    .
                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                                    Trusted Zone: canalplay.com
                                    Trusted Zone: canalplusactive.com
                                    Trusted Zone: canalplay.com
                                    Trusted Zone: canalplusactive.com
                                    FF - ProfilePath - c:\users\charlotte\AppData\Roaming\Mozilla\Firefox\Profiles\pfsjud48.default\
                                    FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
                                    FF - prefs.js: browser.search.selectedEngine - Google
                                    FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
                                    FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?mkt=fr-FR&form=IEFM1&q=
                                    FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
                                    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                                    FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
                                    FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
                                    FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
                                    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                                    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
                                    AddRemove-Winamp Toolbar for Firefox - c:\users\charlotte\AppData\Roaming\Mozilla\Firefox\Profiles\pfsjud48.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\uninstall.exe
                                    AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe

                                    **************************************************************************

                                    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2010-03-01 23:48
                                    Windows 6.0.6002 Service Pack 2 NTFS

                                    Recherche de processus cachés ...

                                    Recherche d'éléments en démarrage automatique cachés ...

                                    Recherche de fichiers cachés ...

                                    Scan terminé avec succès
                                    Fichiers cachés: 0

                                    **************************************************************************
                                    .
                                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                                    @Denied: (A) (Users)
                                    @Denied: (A) (Everyone)
                                    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                    "BlindDial"=dword:00000000
                                    "MSCurrentCountry"=dword:0000003d
                                    .
                                    Heure de fin: 2010-03-01 23:51:16
                                    ComboFix-quarantined-files.txt 2010-03-01 22:51

                                    Avant-CF: 116 212 367 360 octets libres
                                    Après-CF: 116 163 727 360 octets libres

                                    - - End Of File - - 0A784E8D2660DD84567516799C3E48A7
                                    0
                                    • 1
                                    • 2