Detection de Win32:Qandr par Avast

Bonjour, cette nuit Avast m'a fait une alerte avec Win32:Qandr. J'ai essayé de le mettre en quarantaine et après de le supprimer mais ça ne marche pas. Est-ce que quelqu'un aurait une solution pour s'en débarasser ?

Merci d'avance.

28 réponses

Résumé de la discussion

Une alerte Avast signale Win32:Qandr et la suppression échoue malgré la tentative de quarantaine, ce qui pousse à rechercher une méthode fiable pour s'en débarrasser et restaurer l'état initial du système. Des solutions impliqueront l'exécution de ComboFix après redémarrage, ce qui a conduit à des suppressions ciblées de fichiers et pilotes, et la création d'un nouveau point de restauration. Le rapport ComboFix récapitule des éléments supprimés et des entrées de registre, et indique que certains composants liés à Avast et à des outils tiers ont été touchés, avant le redémarrage. Pour autant, des vérifications complémentaires et une nouvelle analyse antivirus restent recommandées, notamment pour examiner les éléments de démarrage et les pilotes restants susceptibles d'affecter la stabilité.

Bobot (l’IA à votre service)
  1. Bonjour

    Post le rapport d'avast et fait ce qui suit.
    Bonjour

    Pour analyser ton pc.

    * Télécharge [https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html ZHPDiag ( de Nicolas coolman ).
    * Laisse toi guider lors de l'installation
    * Il se lancera automatiquement à la fin de l'installation
    * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
    * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
    * Héberge le rapport ZHPDiag.txt sur le site cijoint.fr, puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
    0
    1. Bonjour, merci pour votre réponse rapide.

      Alors Avast je n'ai pas vraiment de rapport, la seule chose qu'il me dit est qu'il y a l'infection Win32:Qandr [rtk] dans
      C:\WINDOWS\System3\Drivers\Changer.sys

      Voilà le lien pour le scan de ZHPdiag :

      http://www.cijoint.fr/cjlink.php?file=cj201004/cijKembAqt.txt
      0
      1. Plusieurs infections.On commence par l'infection par support amovible.
        * Télécharge et install: UsbFix.exe par El Desaparecido
        (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
        * Double clic sur le raccourci UsbFix présent sur ton bureau .
        * Au menu principal choisis l'option " F " pour français et tape sur [entrée] .
        * Au second menu Choisis l'option " 2" et tape sur [entrée]
        * Laisse travailler l'outil.
        * Ensuite post le rapport UsbFix.txt qui apparaitra.
        * Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
        * Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        * Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html
        0
        1. J'ai essayé de lancer UsbFix, mais il me dit qu'il ne le supporte pas... J'ai pourtant bien Windows XP
          0
          1. Je pense qu'une infection bloque Usbfix.On va donc continuer sur la seconde infection et on traitera la premiere ensuite.

            /!\ A l'attention de ceux qui passent sur ce sujet /!\
            Le logiciel qui suit n'est pas à utiliser à la légère et peut faire des dégâts s'il est mal utilisé ! Ne le faites que si un helpeur du forum qui connait bien cet outil vous l'a recommandé.

            /!\ Désactive tous tes logiciels de protection /!\

            * Télécharge combofix(de sUBs) sur ton Bureau.
            * Double-clique sur ComboFix.exe afin de le lancer.
            * Il va te demander d'installer la console de récupération : accepte. (important en cas de problème)
            /!\ Ne touche ni à la souris, ni au clavier durant le scan /!\
            * Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\Combofix.txt) dans ta prochaine réponse.
            #Si combofix ne veut pas se lancer renommes le en ccm.exe et éxécutes le en mode sans échec .
            Tutoriel officiel de Combofix : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser¬-combofix
            0
            1. J'ai téléchargé combofix et coupé avast. J'ai lancé le programme, il me dit "cd emulation running", et qu'il doit les désactivé. J'ai mis ok (y avait que ça), et puis il a eteint l'ordi, sauf que ça reste bloqué sur "fermeture de windows". Je fais quoi ?
              0
              1. Tu rallumes ton pc et tu desactive avast et "cd emulation runnig".ensuite tu lances combofix et post son rapport.
                0
                1. Ca y est c'est fini. Alors finalement j'ai juste rebooté l'ordi, et combofix s'est lancé tout seul, et a installé la console. Après par contre il ne m'a pas affiché le rapport mais je suis allé le chercher. Le voila :

                  ComboFix 10-04-15.02 - Xavier 16/04/2010 11:34:00.1.2 - x86
                  Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1023.371 [GMT 2:00]
                  Lancé depuis: c:\documents and settings\Xavier\Bureau\ComboFix.exe
                  AV: avast! antivirus 4.8.1368 [VPS 100415-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                  * Un nouveau point de restauration a été créé
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  c:\documents and settings\Xavier\RavMonLog
                  c:\program files\WinPCap
                  c:\program files\WinPCap\rpcapd.exe
                  c:\windows\patch.exe
                  c:\windows\system32\drivers\npf.sys
                  c:\windows\system32\fjhdyfhsn.bat
                  c:\windows\system32\Packet.dll
                  c:\windows\system32\pthreadVC.dll
                  c:\windows\system32\WanPacket.dll
                  c:\windows\system32\wpcap.dll

                  .
                  ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Legacy_NPF
                  -------\Service_npf

                  ((((((((((((((((((((((((((((( Fichiers créés du 2010-03-16 au 2010-04-16 ))))))))))))))))))))))))))))))))))))
                  .

                  2010-04-16 08:57 . 2010-04-16 09:13 -------- d-----w- C:\UsbFix
                  2010-04-16 07:51 . 2010-04-16 07:52 -------- d-----w- c:\program files\ZHPDiag
                  2010-04-15 23:48 . 2010-04-16 09:38 829440 ----a-w- c:\windows\system32\drivers\Changer.sys
                  2010-04-14 18:43 . 2010-04-14 18:43 86528 ----a-w- c:\windows\bnetunin.exe
                  2010-04-14 18:43 . 2010-04-14 18:43 61440 ----a-w- c:\windows\diabunin.exe

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2010-04-15 23:44 . 2010-04-15 23:44 12 ----a-w- c:\windows\system32\config\systemprofile\Application Data\egodnu.dat
                  2010-04-15 18:58 . 2009-09-24 13:03 -------- d-----w- c:\documents and settings\Xavier\Application Data\foobar2000
                  2010-04-15 12:58 . 2008-06-11 07:50 138664 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
                  2010-04-15 12:57 . 2008-06-11 07:50 214864 ----a-w- c:\windows\system32\PnkBstrB.exe
                  2010-04-14 17:55 . 2008-08-06 21:01 -------- d-----w- c:\program files\Google
                  2010-04-14 17:07 . 2009-06-26 19:34 -------- d-----w- c:\program files\DOSBox-0.73
                  2010-04-11 15:23 . 2010-03-09 11:15 -------- d-----w- c:\documents and settings\Xavier\Application Data\vlc
                  2010-04-09 21:11 . 2009-01-04 23:12 1 ----a-w- c:\documents and settings\Xavier\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
                  2010-04-07 13:22 . 2006-09-23 12:59 -------- d-----w- c:\program files\Mozilla Thunderbird
                  2010-04-04 00:52 . 2004-08-05 12:00 75266 ----a-w- c:\windows\system32\perfc00C.dat
                  2010-04-04 00:52 . 2004-08-05 12:00 468072 ----a-w- c:\windows\system32\perfh00C.dat
                  2010-03-27 21:54 . 2007-11-20 17:40 32191 ----a-w- c:\windows\DIIUnin.dat
                  2010-03-23 00:44 . 2006-09-23 15:09 -------- d-----w- c:\program files\eMule
                  2010-03-19 21:11 . 2009-10-29 20:20 -------- d-----w- c:\documents and settings\Xavier\Application Data\Skype
                  2010-02-22 22:53 . 2006-09-23 12:04 84704 ----a-w- c:\documents and settings\Xavier\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                  2010-01-31 23:47 . 2010-01-31 23:47 16 ----a-w- c:\documents and settings\Xavier\Application Data\anvkgp.dat
                  2010-01-31 23:40 . 2010-01-31 23:40 16 ----a-w- c:\documents and settings\NetworkService\Application Data\anvkgp.dat
                  2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
                  2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
                  .

                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
                  "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
                  "nwiz"="nwiz.exe" [2006-08-11 1519616]
                  "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
                  "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                  @="Service"

                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoStart IR.lnk.disabled]

                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]

                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk.disabled]

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
                  2003-05-08 09:00 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                  2009-05-30 10:26 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                  2008-04-13 13:29 185896 ----a-w- c:\program files\Fichiers communs\Real\Update_OB\realsched.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                  "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                  "RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
                  "RoxioEngineUtility"="c:\program files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
                  "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  "ArcSoft Connection Service"=c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                  "WD Drive Manager"=c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
                  "95893135"=c:\docume~1\ALLUSE~1\APPLIC~1\95893135\95893135.exe
                  "CTFMON"=c:\windows\Temp\_ex-08.exe
                  "SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
                  "c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
                  "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                  "d:\\Jeux\\Diablo II\\Diablo II.exe"=
                  "d:\\Jeux\\Starcraft\\StarCraft.exe"=
                  "d:\\Xavier\\aMSN\\bin\\wish.exe"=
                  "c:\\Program Files\\SopCast\\SopCast.exe"=
                  "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                  "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                  "d:\\LoulouDidier\\PRIVE\\RawAvRecorder\\rawavrecorder.exe"=
                  "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                  "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
                  "d:\\Jeux\\Battlefield 2142\\BF2142.exe"=
                  "c:\\Program Files\\TVAnts\\Tvants.exe"=
                  "d:\\Jeux\\Age Of Empire Gold Edition\\EMPIRES.EXE"=
                  "c:\\WINDOWS\\system32\\dplaysvr.exe"=
                  "c:\\Program Files\\Messenger\\msmsgs.exe"=
                  "d:\\Jeux\\Bad company 2 béta\\BFBC2BetaUpdater.exe"=
                  "d:\\Jeux\\Bad company 2 béta\\BFBC2Game.exe"=
                  "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "d:\\Jeux\\Activision\\THPS2\\THawk2.exe"=
                  "d:\\Jeux\\Diablo\\diablo.exe"=

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                  "40662:TCP"= 40662:TCP:eMule : TCP Entrant
                  "40672:UDP"= 40672:UDP:eMule : UDP Entrant
                  "14974:TCP"= 14974:TCP:NortonAV
                  "13082:TCP"= 13082:TCP:NortonAV
                  "16795:TCP"= 16795:TCP:NortonAV

                  R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16/08/2009 17:31 64160]
                  R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [02/11/2006 21:57 611064]
                  R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/03/2008 21:12 114768]
                  R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/03/2008 21:12 20560]
                  R2 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\TVServer\HAUPPA~1.EXE [22/02/2009 21:55 434176]
                  R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 16:49 1029456]
                  R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [16/05/2008 18:12 102400]
                  R3 axvdkbus;axvdkbus;c:\windows\system32\drivers\axvdkbus.sys [25/02/2003 20:43 8672]
                  R3 axvodka;axvodka;c:\windows\system32\drivers\axvodka.sys [27/02/2003 18:50 102272]
                  S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [08/01/2010 19:39 135664]
                  S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [22/02/2009 21:53 562176]
                  S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [22/02/2009 21:53 15616]
                  S3 jbridgep;jbridgep; [x]

                  --- Autres Services/Pilotes en mémoire ---

                  *Deregistered* - Changer
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2010-04-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                  - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 16:31]

                  2010-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                  - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]

                  2010-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                  - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]
                  .
                  .
                  ------- Examen supplémentaire -------
                  .
                  uStart Page = hxxp://spiral.univ-lyon1.fr/
                  IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                  IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                  IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                  IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                  DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab
                  FF - ProfilePath - c:\documents and settings\Xavier\Application Data\Mozilla\Firefox\Profiles\xxh9utdp.default\
                  FF - prefs.js: browser.startup.homepage - hxxp://www.jornada.unam.mx/
                  FF - plugin: c:\program files\Download Manager\npfpdlm.dll
                  FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                  FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
                  FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
                  FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

                  ---- PARAMETRES FIREFOX ----
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
                  c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
                  c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
                  c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
                  c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
                  c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
                  c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
                  .
                  - - - - ORPHELINS SUPPRIMES - - - -

                  Notify-WgaLogon - (no file)

                  **************************************************************************

                  catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2010-04-16 11:38
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************

                  Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                  device: opened successfully
                  user: MBR read successfully
                  called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x867BF1D8]<<
                  kernel: MBR read successfully
                  detected MBR rootkit hooks:
                  \Driver\Disk -> CLASSPNP.SYS @ 0xf7630fc3
                  \Driver\ACPI -> ACPI.sys @ 0xf73d2cb8
                  \Driver\atapi -> 0x867bf1d8
                  IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582364
                  ParseProcedure -> ntkrnlpa.exe @ 0x80581462
                  \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582364
                  ParseProcedure -> ntkrnlpa.exe @ 0x80581462
                  NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf727eba0
                  PacketIndicateHandler -> NDIS.sys @ 0xf728bb21
                  SendHandler -> NDIS.sys @ 0xf726987b
                  Warning: possible MBR rootkit infection !
                  user & kernel MBR OK

                  **************************************************************************

                  [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]

                  .
                  --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                  [HKEY_USERS\S-1-5-21-1060284298-287218729-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                  "??"=hex:cf,12,1b,01,0f,b4,a9,47,62,dc,3a,cd,11,e3,91,98,10,d5,69,92,f4,19,b2,
                  09,22,4d,00,29,a1,29,ed,6a,ac,4e,14,5e,43,dc,a3,5a,0e,b5,d6,09,8f,12,b1,31,\
                  "??"=hex:3f,f1,38,43,b3,20,4d,58,b8,83,0d,9d,9b,06,43,fe
                  .
                  --------------------- DLLs chargées dans les processus actifs ---------------------

                  - - - - - - - > 'explorer.exe'(1984)
                  c:\windows\system32\WPDShServiceObj.dll
                  c:\windows\system32\PortableDeviceTypes.dll
                  c:\windows\system32\PortableDeviceApi.dll
                  c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTJBNS.DLL
                  c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSHK.dll
                  c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTIntrfc.dll
                  c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSRES.DLL
                  .
                  ------------------------ Autres processus actifs ------------------------
                  .
                  c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                  c:\program files\Alwil Software\Avast4\ashServ.exe
                  c:\windows\system32\CTsvcCDA.EXE
                  c:\program files\Java\jre6\bin\jqs.exe
                  c:\windows\system32\nvsvc32.exe
                  c:\windows\system32\PnkBstrA.exe
                  c:\windows\system32\PnkBstrB.exe
                  c:\windows\system32\MsPMSPSv.exe
                  c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                  c:\windows\system32\wbem\unsecapp.exe
                  c:\program files\Alwil Software\Avast4\ashWebSv.exe
                  .
                  **************************************************************************
                  .
                  Heure de fin: 2010-04-16 11:45:12 - La machine a redémarré
                  ComboFix-quarantined-files.txt 2010-04-16 09:45

                  Avant-CF: 8 122 007 552 octets libres
                  Après-CF: 8 249 839 616 octets libres

                  WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                  [boot loader]
                  timeout=2
                  default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                  [operating systems]
                  c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                  multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                  - - End Of File - - 6531C6910CAA37FD18BAF1853279F100
                  0
                  1. Alors finalement j'ai juste rebooté et combix s'est lancé tout de suite, il a installé la console etc... Par contre il ne m'a pas affiché le rapport, j'ai du aller le chercher. Le voila :

                    ComboFix 10-04-15.02 - Xavier 16/04/2010 11:34:00.1.2 - x86
                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1023.371 [GMT 2:00]
                    Lancé depuis: c:\documents and settings\Xavier\Bureau\ComboFix.exe
                    AV: avast! antivirus 4.8.1368 [VPS 100415-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                    * Un nouveau point de restauration a été créé
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    c:\documents and settings\Xavier\RavMonLog
                    c:\program files\WinPCap
                    c:\program files\WinPCap\rpcapd.exe
                    c:\windows\patch.exe
                    c:\windows\system32\drivers\npf.sys
                    c:\windows\system32\fjhdyfhsn.bat
                    c:\windows\system32\Packet.dll
                    c:\windows\system32\pthreadVC.dll
                    c:\windows\system32\WanPacket.dll
                    c:\windows\system32\wpcap.dll

                    .
                    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Legacy_NPF
                    -------\Service_npf

                    ((((((((((((((((((((((((((((( Fichiers créés du 2010-03-16 au 2010-04-16 ))))))))))))))))))))))))))))))))))))
                    .

                    2010-04-16 08:57 . 2010-04-16 09:13 -------- d-----w- C:\UsbFix
                    2010-04-16 07:51 . 2010-04-16 07:52 -------- d-----w- c:\program files\ZHPDiag
                    2010-04-15 23:48 . 2010-04-16 09:38 829440 ----a-w- c:\windows\system32\drivers\Changer.sys
                    2010-04-14 18:43 . 2010-04-14 18:43 86528 ----a-w- c:\windows\bnetunin.exe
                    2010-04-14 18:43 . 2010-04-14 18:43 61440 ----a-w- c:\windows\diabunin.exe

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2010-04-15 23:44 . 2010-04-15 23:44 12 ----a-w- c:\windows\system32\config\systemprofile\Application Data\egodnu.dat
                    2010-04-15 18:58 . 2009-09-24 13:03 -------- d-----w- c:\documents and settings\Xavier\Application Data\foobar2000
                    2010-04-15 12:58 . 2008-06-11 07:50 138664 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
                    2010-04-15 12:57 . 2008-06-11 07:50 214864 ----a-w- c:\windows\system32\PnkBstrB.exe
                    2010-04-14 17:55 . 2008-08-06 21:01 -------- d-----w- c:\program files\Google
                    2010-04-14 17:07 . 2009-06-26 19:34 -------- d-----w- c:\program files\DOSBox-0.73
                    2010-04-11 15:23 . 2010-03-09 11:15 -------- d-----w- c:\documents and settings\Xavier\Application Data\vlc
                    2010-04-09 21:11 . 2009-01-04 23:12 1 ----a-w- c:\documents and settings\Xavier\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
                    2010-04-07 13:22 . 2006-09-23 12:59 -------- d-----w- c:\program files\Mozilla Thunderbird
                    2010-04-04 00:52 . 2004-08-05 12:00 75266 ----a-w- c:\windows\system32\perfc00C.dat
                    2010-04-04 00:52 . 2004-08-05 12:00 468072 ----a-w- c:\windows\system32\perfh00C.dat
                    2010-03-27 21:54 . 2007-11-20 17:40 32191 ----a-w- c:\windows\DIIUnin.dat
                    2010-03-23 00:44 . 2006-09-23 15:09 -------- d-----w- c:\program files\eMule
                    2010-03-19 21:11 . 2009-10-29 20:20 -------- d-----w- c:\documents and settings\Xavier\Application Data\Skype
                    2010-02-22 22:53 . 2006-09-23 12:04 84704 ----a-w- c:\documents and settings\Xavier\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                    2010-01-31 23:47 . 2010-01-31 23:47 16 ----a-w- c:\documents and settings\Xavier\Application Data\anvkgp.dat
                    2010-01-31 23:40 . 2010-01-31 23:40 16 ----a-w- c:\documents and settings\NetworkService\Application Data\anvkgp.dat
                    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
                    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
                    .

                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
                    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
                    "nwiz"="nwiz.exe" [2006-08-11 1519616]
                    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
                    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                    @="Service"

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoStart IR.lnk.disabled]

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk.disabled]

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
                    2003-05-08 09:00 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                    2009-05-30 10:26 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                    2008-04-13 13:29 185896 ----a-w- c:\program files\Fichiers communs\Real\Update_OB\realsched.exe

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                    "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                    "RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
                    "RoxioEngineUtility"="c:\program files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
                    "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    "ArcSoft Connection Service"=c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                    "WD Drive Manager"=c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
                    "95893135"=c:\docume~1\ALLUSE~1\APPLIC~1\95893135\95893135.exe
                    "CTFMON"=c:\windows\Temp\_ex-08.exe
                    "SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "%windir%\\system32\\sessmgr.exe"=
                    "c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
                    "c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
                    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                    "d:\\Jeux\\Diablo II\\Diablo II.exe"=
                    "d:\\Jeux\\Starcraft\\StarCraft.exe"=
                    "d:\\Xavier\\aMSN\\bin\\wish.exe"=
                    "c:\\Program Files\\SopCast\\SopCast.exe"=
                    "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                    "d:\\LoulouDidier\\PRIVE\\RawAvRecorder\\rawavrecorder.exe"=
                    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
                    "d:\\Jeux\\Battlefield 2142\\BF2142.exe"=
                    "c:\\Program Files\\TVAnts\\Tvants.exe"=
                    "d:\\Jeux\\Age Of Empire Gold Edition\\EMPIRES.EXE"=
                    "c:\\WINDOWS\\system32\\dplaysvr.exe"=
                    "c:\\Program Files\\Messenger\\msmsgs.exe"=
                    "d:\\Jeux\\Bad company 2 béta\\BFBC2BetaUpdater.exe"=
                    "d:\\Jeux\\Bad company 2 béta\\BFBC2Game.exe"=
                    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                    "d:\\Jeux\\Activision\\THPS2\\THawk2.exe"=
                    "d:\\Jeux\\Diablo\\diablo.exe"=

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                    "40662:TCP"= 40662:TCP:eMule : TCP Entrant
                    "40672:UDP"= 40672:UDP:eMule : UDP Entrant
                    "14974:TCP"= 14974:TCP:NortonAV
                    "13082:TCP"= 13082:TCP:NortonAV
                    "16795:TCP"= 16795:TCP:NortonAV

                    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16/08/2009 17:31 64160]
                    R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [02/11/2006 21:57 611064]
                    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/03/2008 21:12 114768]
                    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/03/2008 21:12 20560]
                    R2 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\TVServer\HAUPPA~1.EXE [22/02/2009 21:55 434176]
                    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 16:49 1029456]
                    R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [16/05/2008 18:12 102400]
                    R3 axvdkbus;axvdkbus;c:\windows\system32\drivers\axvdkbus.sys [25/02/2003 20:43 8672]
                    R3 axvodka;axvodka;c:\windows\system32\drivers\axvodka.sys [27/02/2003 18:50 102272]
                    S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [08/01/2010 19:39 135664]
                    S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [22/02/2009 21:53 562176]
                    S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [22/02/2009 21:53 15616]
                    S3 jbridgep;jbridgep; [x]

                    --- Autres Services/Pilotes en mémoire ---

                    *Deregistered* - Changer
                    .
                    Contenu du dossier 'Tâches planifiées'

                    2010-04-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 16:31]

                    2010-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]

                    2010-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]
                    .
                    .
                    ------- Examen supplémentaire -------
                    .
                    uStart Page = hxxp://spiral.univ-lyon1.fr/
                    IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                    IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                    IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                    IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                    DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab
                    FF - ProfilePath - c:\documents and settings\Xavier\Application Data\Mozilla\Firefox\Profiles\xxh9utdp.default\
                    FF - prefs.js: browser.startup.homepage - hxxp://www.jornada.unam.mx/
                    FF - plugin: c:\program files\Download Manager\npfpdlm.dll
                    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                    FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
                    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
                    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
                    FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

                    ---- PARAMETRES FIREFOX ----
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
                    .
                    - - - - ORPHELINS SUPPRIMES - - - -

                    Notify-WgaLogon - (no file)

                    **************************************************************************

                    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2010-04-16 11:38
                    Windows 5.1.2600 Service Pack 2 NTFS

                    Recherche de processus cachés ...

                    Recherche d'éléments en démarrage automatique cachés ...

                    Recherche de fichiers cachés ...

                    Scan terminé avec succès
                    Fichiers cachés: 0

                    **************************************************************************

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x867BF1D8]<<
                    kernel: MBR read successfully
                    detected MBR rootkit hooks:
                    \Driver\Disk -> CLASSPNP.SYS @ 0xf7630fc3
                    \Driver\ACPI -> ACPI.sys @ 0xf73d2cb8
                    \Driver\atapi -> 0x867bf1d8
                    IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582364
                    ParseProcedure -> ntkrnlpa.exe @ 0x80581462
                    \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582364
                    ParseProcedure -> ntkrnlpa.exe @ 0x80581462
                    NDIS: Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf727eba0
                    PacketIndicateHandler -> NDIS.sys @ 0xf728bb21
                    SendHandler -> NDIS.sys @ 0xf726987b
                    Warning: possible MBR rootkit infection !
                    user & kernel MBR OK

                    **************************************************************************

                    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Changer]

                    .
                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                    [HKEY_USERS\S-1-5-21-1060284298-287218729-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                    "??"=hex:cf,12,1b,01,0f,b4,a9,47,62,dc,3a,cd,11,e3,91,98,10,d5,69,92,f4,19,b2,
                    09,22,4d,00,29,a1,29,ed,6a,ac,4e,14,5e,43,dc,a3,5a,0e,b5,d6,09,8f,12,b1,31,\
                    "??"=hex:3f,f1,38,43,b3,20,4d,58,b8,83,0d,9d,9b,06,43,fe
                    .
                    --------------------- DLLs chargées dans les processus actifs ---------------------

                    - - - - - - - > 'explorer.exe'(1984)
                    c:\windows\system32\WPDShServiceObj.dll
                    c:\windows\system32\PortableDeviceTypes.dll
                    c:\windows\system32\PortableDeviceApi.dll
                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTJBNS.DLL
                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSHK.dll
                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTIntrfc.dll
                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSRES.DLL
                    .
                    ------------------------ Autres processus actifs ------------------------
                    .
                    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                    c:\program files\Alwil Software\Avast4\ashServ.exe
                    c:\windows\system32\CTsvcCDA.EXE
                    c:\program files\Java\jre6\bin\jqs.exe
                    c:\windows\system32\nvsvc32.exe
                    c:\windows\system32\PnkBstrA.exe
                    c:\windows\system32\PnkBstrB.exe
                    c:\windows\system32\MsPMSPSv.exe
                    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                    c:\windows\system32\wbem\unsecapp.exe
                    c:\program files\Alwil Software\Avast4\ashWebSv.exe
                    .
                    **************************************************************************
                    .
                    Heure de fin: 2010-04-16 11:45:12 - La machine a redémarré
                    ComboFix-quarantined-files.txt 2010-04-16 09:45

                    Avant-CF: 8 122 007 552 octets libres
                    Après-CF: 8 249 839 616 octets libres

                    WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                    [boot loader]
                    timeout=2
                    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                    [operating systems]
                    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                    - - End Of File - - 6531C6910CAA37FD18BAF1853279F100
                    0
                    1. Tu as une sacrée merdouille sur ton pc .N'utilise pas ta carte bancaire jusqu'à la fin de la désinfection.

                      /!\ Il faut IMPERATIVEMENT désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                      * Rends toi ICI , et clique sur "Download EXE" pour télécharger Gmer (sous un nom aléatoire, pour éviter qu'il soit bloqué par l'infection)
                      * Lance Gmer
                      * Dans l'onglet "Rootkit", clique sur "SCAN" puis patiente...
                      * A la fin, clique sur "SAVE" et enregistre le rapport sur ton Bureau.
                      * Héberge le rapport sur le site cijoint.fr, puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
                      ---------------

                      0
                      1. Voilà c'est fait. Il a effectivement dit qu'il y avait eu des modifs à cause d'activit" Rootkit
                        Voilà le rapport (c'est en .log à la base, mais le site le prenait pas)

                        http://www.cijoint.fr/cjlink.php?file=cj201004/cijr9TUrDk.txt
                        0
                        1. Télécharger tdsskiller de loup_blancsur le bureau. Cet outil est conçu pour automatiser différentes tâches proposées par TDSSKiller, un fix de Kaspersky.
                          * Lancer load_tdsskiller en double-cliquant dessus :(si tu es sous Windows Vista ou Windows 7, fais un clic-droit dessus ? Exécuter en temps qu'administrateur)
                          l'outil va se connecter au Net pour télécharger une copie à jour de TDSSKiller et lancer le scan
                          * Un message dans la fenêtre noire d'invite de commande vous demandera d'appuyer sur une touche pour continuer
                          * Le rapport s'affichera automatiquement : copier-coller son contenu dans la prochaine réponse
                          (le fichier est également présent ici : C:\tdsskiller\report.txt)
                          * Redémarrer le PC

                          NB: Pendant la procédure, si TDSSKiller fait apparaître ce message:
                          Citation
                          Hidden service detected: H8SRTd.sys
                          Type "delete" (without quotes) to delete it: 14:30:08:000 0256
                          , tape delete et valide.

                          0
                          1. J'ai fait ce que vous m'avez dit, et je n'ai eu aucun rapport (j'ai eu à taper delete à un moment) qui s'est affiché, et il n'y rien dans le dossier.
                            0
                            1. Oups en fait il avait juste été créé à un autre endroit, désolé. Voilà donc le rapport :

                              14:05:43:968 3332 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
                              14:05:43:968 3332 ================================================================================
                              14:05:43:968 3332 SystemInfo:

                              14:05:43:968 3332 OS Version: 5.1.2600 ServicePack: 2.0
                              14:05:43:968 3332 Product type: Workstation
                              14:05:43:968 3332 ComputerName: PLAT-63329D6ACD
                              14:05:43:968 3332 UserName: Xavier
                              14:05:43:968 3332 Windows directory: C:\WINDOWS
                              14:05:43:968 3332 Processor architecture: Intel x86
                              14:05:43:968 3332 Number of processors: 2
                              14:05:43:968 3332 Page size: 0x1000
                              14:05:43:968 3332 Boot type: Normal boot
                              14:05:43:968 3332 ================================================================================
                              14:05:43:968 3332 UnloadDriverW: NtUnloadDriver error 2
                              14:05:43:968 3332 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
                              14:05:43:968 3332 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
                              14:05:43:968 3332 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
                              14:05:43:968 3332 wfopen_ex: Trying to KLMD file open
                              14:05:43:968 3332 wfopen_ex: File opened ok (Flags 2)
                              14:05:43:968 3332 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
                              14:05:43:968 3332 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
                              14:05:43:968 3332 wfopen_ex: Trying to KLMD file open
                              14:05:43:968 3332 wfopen_ex: File opened ok (Flags 2)
                              14:05:43:968 3332 Initialize success
                              14:05:43:968 3332
                              14:05:43:968 3332 Scanning Services ...
                              14:05:44:265 3332 Raw services enum returned 329 services
                              14:05:44:281 3332 Suspicious serv Changer (h: 0, b: 1)
                              14:05:44:281 3332
                              14:05:44:281 3332 Hidden service detected!
                              14:05:44:281 3332 Service name: Changer
                              14:05:44:281 3332 Image path:
                              14:05:44:281 3332 Type "delete" (without quotes) to delete it: 14:06:11:843 3332
                              14:06:11:843 3332 By user detect Changer
                              14:06:11:843 3332 RegNode HKLM\SYSTEM\ControlSet001\services\Changer infected by TDSS rootkit ... 14:06:11:843 3332 will be deleted on reboot
                              14:06:11:843 3332 RegNode HKLM\SYSTEM\ControlSet002\services\Changer infected by TDSS rootkit ... 14:06:11:843 3332 will be deleted on reboot
                              14:06:11:843 3332 File C:\WINDOWS\system32\drivers\Changer.sys infected by TDSS rootkit ... 14:06:11:843 3332 will be deleted on reboot
                              14:06:11:843 3332
                              14:06:11:843 3332 Scanning Kernel memory ...
                              14:06:11:843 3332 Devices to scan: 3
                              14:06:11:843 3332
                              14:06:11:843 3332 Driver Name: Disk
                              14:06:11:843 3332 IRP_MJ_CREATE : F7632C30
                              14:06:11:843 3332 IRP_MJ_CREATE_NAMED_PIPE : 804F4282
                              14:06:11:843 3332 IRP_MJ_CLOSE : F7632C30
                              14:06:11:843 3332 IRP_MJ_READ : F762CD9B
                              14:06:11:843 3332 IRP_MJ_WRITE : F762CD9B
                              14:06:11:843 3332 IRP_MJ_QUERY_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_EA : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_EA : 804F4282
                              14:06:11:843 3332 IRP_MJ_FLUSH_BUFFERS : F762D366
                              14:06:11:843 3332 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_VOLUME_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_DIRECTORY_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_DEVICE_CONTROL : F762D44D
                              14:06:11:843 3332 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7630FC3
                              14:06:11:843 3332 IRP_MJ_SHUTDOWN : F762D366
                              14:06:11:843 3332 IRP_MJ_LOCK_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_CLEANUP : 804F4282
                              14:06:11:843 3332 IRP_MJ_CREATE_MAILSLOT : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_SECURITY : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_SECURITY : 804F4282
                              14:06:11:843 3332 IRP_MJ_POWER : F762EEF3
                              14:06:11:843 3332 IRP_MJ_SYSTEM_CONTROL : F7633A24
                              14:06:11:843 3332 IRP_MJ_DEVICE_CHANGE : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_QUOTA : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_QUOTA : 804F4282
                              14:06:11:843 3332 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
                              14:06:11:843 3332
                              14:06:11:843 3332 Driver Name: Disk
                              14:06:11:843 3332 IRP_MJ_CREATE : F7632C30
                              14:06:11:843 3332 IRP_MJ_CREATE_NAMED_PIPE : 804F4282
                              14:06:11:843 3332 IRP_MJ_CLOSE : F7632C30
                              14:06:11:843 3332 IRP_MJ_READ : F762CD9B
                              14:06:11:843 3332 IRP_MJ_WRITE : F762CD9B
                              14:06:11:843 3332 IRP_MJ_QUERY_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_EA : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_EA : 804F4282
                              14:06:11:843 3332 IRP_MJ_FLUSH_BUFFERS : F762D366
                              14:06:11:843 3332 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_VOLUME_INFORMATION : 804F4282
                              14:06:11:843 3332 IRP_MJ_DIRECTORY_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_DEVICE_CONTROL : F762D44D
                              14:06:11:843 3332 IRP_MJ_INTERNAL_DEVICE_CONTROL : F7630FC3
                              14:06:11:843 3332 IRP_MJ_SHUTDOWN : F762D366
                              14:06:11:843 3332 IRP_MJ_LOCK_CONTROL : 804F4282
                              14:06:11:843 3332 IRP_MJ_CLEANUP : 804F4282
                              14:06:11:843 3332 IRP_MJ_CREATE_MAILSLOT : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_SECURITY : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_SECURITY : 804F4282
                              14:06:11:843 3332 IRP_MJ_POWER : F762EEF3
                              14:06:11:843 3332 IRP_MJ_SYSTEM_CONTROL : F7633A24
                              14:06:11:843 3332 IRP_MJ_DEVICE_CHANGE : 804F4282
                              14:06:11:843 3332 IRP_MJ_QUERY_QUOTA : 804F4282
                              14:06:11:843 3332 IRP_MJ_SET_QUOTA : 804F4282
                              14:06:11:859 3332 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
                              14:06:11:859 3332
                              14:06:11:859 3332 Driver Name: atapi
                              14:06:11:859 3332 IRP_MJ_CREATE : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_CREATE_NAMED_PIPE : 804F4282
                              14:06:11:859 3332 IRP_MJ_CLOSE : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_READ : 804F4282
                              14:06:11:859 3332 IRP_MJ_WRITE : 804F4282
                              14:06:11:859 3332 IRP_MJ_QUERY_INFORMATION : 804F4282
                              14:06:11:859 3332 IRP_MJ_SET_INFORMATION : 804F4282
                              14:06:11:859 3332 IRP_MJ_QUERY_EA : 804F4282
                              14:06:11:859 3332 IRP_MJ_SET_EA : 804F4282
                              14:06:11:859 3332 IRP_MJ_FLUSH_BUFFERS : 804F4282
                              14:06:11:859 3332 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4282
                              14:06:11:859 3332 IRP_MJ_SET_VOLUME_INFORMATION : 804F4282
                              14:06:11:859 3332 IRP_MJ_DIRECTORY_CONTROL : 804F4282
                              14:06:11:859 3332 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4282
                              14:06:11:859 3332 IRP_MJ_DEVICE_CONTROL : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_INTERNAL_DEVICE_CONTROL : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_SHUTDOWN : 804F4282
                              14:06:11:859 3332 IRP_MJ_LOCK_CONTROL : 804F4282
                              14:06:11:859 3332 IRP_MJ_CLEANUP : 804F4282
                              14:06:11:859 3332 IRP_MJ_CREATE_MAILSLOT : 804F4282
                              14:06:11:859 3332 IRP_MJ_QUERY_SECURITY : 804F4282
                              14:06:11:859 3332 IRP_MJ_SET_SECURITY : 804F4282
                              14:06:11:859 3332 IRP_MJ_POWER : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_SYSTEM_CONTROL : 867BF1D8
                              14:06:11:859 3332 IRP_MJ_DEVICE_CHANGE : 804F4282
                              14:06:11:859 3332 IRP_MJ_QUERY_QUOTA : 804F4282
                              14:06:11:859 3332 IRP_MJ_SET_QUOTA : 804F4282
                              14:06:11:859 3332 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
                              14:06:11:859 3332 Reboot required for cure complete..
                              14:06:11:859 3332 Cure on reboot scheduled successfully
                              14:06:11:859 3332
                              14:06:11:859 3332 Completed
                              14:06:11:859 3332
                              14:06:11:859 3332 Results:
                              14:06:11:859 3332 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
                              14:06:11:859 3332 Registry objects infected / cured / cured on reboot: 2 / 0 / 2
                              14:06:11:859 3332 File objects infected / cured / cured on reboot: 1 / 0 / 1
                              14:06:11:859 3332
                              14:06:11:859 3332 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
                              14:06:11:859 3332 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
                              14:06:11:859 3332 KLMD(ARK) unloaded successfully
                              0
                              1. Je me permets de remonter le sujet....
                                0
                                1. A faire impérativement.

                                  Redémarres ton pc .(important)
                                  supprimes combofix de cette maniere.
                                  Pour combofix

                                  # Cliquez sur Démarrer >> Exécuter ...
                                  # Maintenant, tapez ou fait un copié/collé ComboFix /uninstall et cliquez sur OK.

                                  A présent télécharge a nouveau combofix et lances le .Post le rapport qu'il va générer.
                                  0
                                  1. Voilà le rapport :

                                    ComboFix 10-04-15.05 - Xavier 17/04/2010 10:15:02.2.2 - x86
                                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1023.542 [GMT 2:00]
                                    Lancé depuis: c:\documents and settings\Xavier\Bureau\ComboFix.exe
                                    AV: avast! antivirus 4.8.1368 [VPS 100416-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                                    .

                                    ((((((((((((((((((((((((((((( Fichiers créés du 2010-03-17 au 2010-04-17 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2010-04-16 08:57 . 2010-04-16 09:13 -------- d-----w- C:\UsbFix
                                    2010-04-16 07:51 . 2010-04-16 07:52 -------- d-----w- c:\program files\ZHPDiag
                                    2010-04-14 18:43 . 2010-04-14 18:43 86528 ----a-w- c:\windows\bnetunin.exe
                                    2010-04-14 18:43 . 2010-04-14 18:43 61440 ----a-w- c:\windows\diabunin.exe

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2010-04-17 08:00 . 2009-09-24 13:03 -------- d-----w- c:\documents and settings\Xavier\Application Data\foobar2000
                                    2010-04-16 23:00 . 2008-06-11 07:50 138664 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
                                    2010-04-16 22:59 . 2008-06-11 07:50 214864 ----a-w- c:\windows\system32\PnkBstrB.exe
                                    2010-04-14 17:55 . 2008-08-06 21:01 -------- d-----w- c:\program files\Google
                                    2010-04-14 17:07 . 2009-06-26 19:34 -------- d-----w- c:\program files\DOSBox-0.73
                                    2010-04-11 15:23 . 2010-03-09 11:15 -------- d-----w- c:\documents and settings\Xavier\Application Data\vlc
                                    2010-04-09 21:11 . 2009-01-04 23:12 1 ----a-w- c:\documents and settings\Xavier\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
                                    2010-04-07 13:22 . 2006-09-23 12:59 -------- d-----w- c:\program files\Mozilla Thunderbird
                                    2010-04-04 00:52 . 2004-08-05 12:00 75266 ----a-w- c:\windows\system32\perfc00C.dat
                                    2010-04-04 00:52 . 2004-08-05 12:00 468072 ----a-w- c:\windows\system32\perfh00C.dat
                                    2010-03-27 21:54 . 2007-11-20 17:40 32191 ----a-w- c:\windows\DIIUnin.dat
                                    2010-03-23 00:44 . 2006-09-23 15:09 -------- d-----w- c:\program files\eMule
                                    2010-03-19 21:11 . 2009-10-29 20:20 -------- d-----w- c:\documents and settings\Xavier\Application Data\Skype
                                    2010-02-22 22:53 . 2006-09-23 12:04 84704 ----a-w- c:\documents and settings\Xavier\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                                    2010-01-31 23:47 . 2010-01-31 23:47 16 ----a-w- c:\documents and settings\Xavier\Application Data\anvkgp.dat
                                    2010-01-31 23:40 . 2010-01-31 23:40 16 ----a-w- c:\documents and settings\NetworkService\Application Data\anvkgp.dat
                                    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
                                    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
                                    .

                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
                                    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
                                    "nwiz"="nwiz.exe" [2006-08-11 1519616]
                                    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-11 86016]
                                    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]

                                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
                                    @="Service"

                                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^AutoStart IR.lnk.disabled]

                                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]

                                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk.disabled]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE2]
                                    2003-05-08 09:00 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE2.0\opwareSE2.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                                    2009-05-30 10:26 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                                    2008-04-13 13:29 185896 ----a-w- c:\program files\Fichiers communs\Real\Update_OB\realsched.exe

                                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                                    "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                    "RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
                                    "RoxioEngineUtility"="c:\program files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
                                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
                                    "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    "ArcSoft Connection Service"=c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
                                    "WD Drive Manager"=c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
                                    "95893135"=c:\docume~1\ALLUSE~1\APPLIC~1\95893135\95893135.exe
                                    "CTFMON"=c:\windows\Temp\_ex-08.exe
                                    "SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "c:\\Program Files\\Mozilla Thunderbird\\thunderbird.exe"=
                                    "c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
                                    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                                    "d:\\Jeux\\Diablo II\\Diablo II.exe"=
                                    "d:\\Jeux\\Starcraft\\StarCraft.exe"=
                                    "d:\\Xavier\\aMSN\\bin\\wish.exe"=
                                    "c:\\Program Files\\SopCast\\SopCast.exe"=
                                    "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                                    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                                    "d:\\LoulouDidier\\PRIVE\\RawAvRecorder\\rawavrecorder.exe"=
                                    "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                                    "c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
                                    "d:\\Jeux\\Battlefield 2142\\BF2142.exe"=
                                    "c:\\Program Files\\TVAnts\\Tvants.exe"=
                                    "d:\\Jeux\\Age Of Empire Gold Edition\\EMPIRES.EXE"=
                                    "c:\\WINDOWS\\system32\\dplaysvr.exe"=
                                    "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                    "d:\\Jeux\\Bad company 2 béta\\BFBC2BetaUpdater.exe"=
                                    "d:\\Jeux\\Bad company 2 béta\\BFBC2Game.exe"=
                                    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                                    "d:\\Jeux\\Activision\\THPS2\\THawk2.exe"=
                                    "d:\\Jeux\\Diablo\\diablo.exe"=

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                    "40662:TCP"= 40662:TCP:eMule : TCP Entrant
                                    "40672:UDP"= 40672:UDP:eMule : UDP Entrant
                                    "14974:TCP"= 14974:TCP:NortonAV
                                    "13082:TCP"= 13082:TCP:NortonAV
                                    "16795:TCP"= 16795:TCP:NortonAV

                                    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [16/08/2009 17:31 64160]
                                    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/03/2008 21:12 114768]
                                    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/03/2008 21:12 20560]
                                    R2 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\WinTV\TVServer\HAUPPA~1.EXE [22/02/2009 21:55 434176]
                                    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 16:49 1029456]
                                    R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [16/05/2008 18:12 102400]
                                    R3 axvdkbus;axvdkbus;c:\windows\system32\drivers\axvdkbus.sys [25/02/2003 20:43 8672]
                                    R3 axvodka;axvodka;c:\windows\system32\drivers\axvodka.sys [27/02/2003 18:50 102272]
                                    S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [08/01/2010 19:39 135664]
                                    S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [22/02/2009 21:53 562176]
                                    S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [22/02/2009 21:53 15616]
                                    S3 jbridgep;jbridgep; [x]
                                    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [02/11/2006 21:57 611064]
                                    .
                                    Contenu du dossier 'Tâches planifiées'

                                    2010-04-12 c:\windows\Tasks\Ad-Aware Update (Weekly).job
                                    - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 16:31]

                                    2010-04-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]

                                    2010-04-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-08 17:39]
                                    .
                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    uStart Page = hxxp://spiral.univ-lyon1.fr/
                                    IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                                    IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                                    IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                                    IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                                    DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} - hxxp://dl.uc.sina.com/cab/downloader.cab
                                    FF - ProfilePath - c:\documents and settings\Xavier\Application Data\Mozilla\Firefox\Profiles\xxh9utdp.default\
                                    FF - prefs.js: browser.startup.homepage - hxxp://www.jornada.unam.mx/
                                    FF - plugin: c:\program files\Download Manager\npfpdlm.dll
                                    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                                    FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
                                    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                                    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
                                    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
                                    FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

                                    ---- PARAMETRES FIREFOX ----
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
                                    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
                                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
                                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
                                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
                                    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
                                    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -

                                    SafeBoot-klmdb.sys

                                    **************************************************************************

                                    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2010-04-17 10:19
                                    Windows 5.1.2600 Service Pack 2 NTFS

                                    Recherche de processus cachés ...

                                    Recherche d'éléments en démarrage automatique cachés ...

                                    Recherche de fichiers cachés ...

                                    Scan terminé avec succès
                                    Fichiers cachés: 0

                                    **************************************************************************
                                    .
                                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                                    [HKEY_USERS\S-1-5-21-1060284298-287218729-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                                    "??"=hex:cf,12,1b,01,0f,b4,a9,47,62,dc,3a,cd,11,e3,91,98,10,d5,69,92,f4,19,b2,
                                    09,22,4d,00,29,a1,29,ed,6a,ac,4e,14,5e,43,dc,a3,5a,0e,b5,d6,09,8f,12,b1,31,\
                                    "??"=hex:3f,f1,38,43,b3,20,4d,58,b8,83,0d,9d,9b,06,43,fe
                                    .
                                    --------------------- DLLs chargées dans les processus actifs ---------------------

                                    - - - - - - - > 'explorer.exe'(1656)
                                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTJBNS.DLL
                                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSHK.dll
                                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\CTIntrfc.dll
                                    c:\program files\Creative\Creative Zen Touch\NOMAD Explorer\JBNSRES.DLL
                                    c:\windows\system32\WPDShServiceObj.dll
                                    c:\windows\system32\PortableDeviceTypes.dll
                                    c:\windows\system32\PortableDeviceApi.dll
                                    .
                                    Heure de fin: 2010-04-17 10:20:39
                                    ComboFix-quarantined-files.txt 2010-04-17 08:20
                                    ComboFix2.txt 2010-04-16 09:45

                                    Avant-CF: 10 414 661 632 octets libres
                                    Après-CF: 10 384 748 544 octets libres

                                    - - End Of File - - 53F816B7E0E483F77C2004FD73E3A27D
                                    0
                                    1. Comment va ton pc?

                                      * Télécharge et installe : Malwarebyte's Anti-Malware
                                      * (NB : S'il te manque"COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/
                                      * A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
                                      * Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
                                      * Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
                                      * Sélectionne tes disques durs" puis clique sur "Lancer l'examen"
                                      * A la fin du scan, clique sur Afficher les résultats
                                      * Coche tous les éléments détectés puis clique sur Supprimer la sélection
                                      * Enregistre le rapport
                                      * S'il t'est demandé de redémarrer, clique sur Yes
                                      * Poste le rapport de scan après la suppression ici.(poste le rapport, même si rien n'est détecté.)
                                      * Si tu as besoin d'aide regarde ce tutorial
                                      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                      0
                                      1. L'ordi va mieux, je n'ai plus l'alerte Avast que j'avais hier matin. Par contre il reste encore quelque chose non d'après le rapport combofix ?
                                        Voilà le rapport de MBAM :

                                        Malwarebytes' Anti-Malware 1.45
                                        www.malwarebytes.org

                                        Version de la base de données: 4000

                                        Windows 5.1.2600 Service Pack 2
                                        Internet Explorer 6.0.2900.2180

                                        17/04/2010 12:29:34
                                        mbam-log-2010-04-17 (12-29-34).txt

                                        Type d'examen: Examen complet (C:\|D:\|)
                                        Elément(s) analysé(s): 215362
                                        Temps écoulé: 52 minute(s), 33 seconde(s)

                                        Processus mémoire infecté(s): 0
                                        Module(s) mémoire infecté(s): 0
                                        Clé(s) du Registre infectée(s): 0
                                        Valeur(s) du Registre infectée(s): 0
                                        Elément(s) de données du Registre infecté(s): 0
                                        Dossier(s) infecté(s): 0
                                        Fichier(s) infecté(s): 1

                                        Processus mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Module(s) mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Clé(s) du Registre infectée(s):
                                        (Aucun élément nuisible détecté)

                                        Valeur(s) du Registre infectée(s):
                                        (Aucun élément nuisible détecté)

                                        Elément(s) de données du Registre infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Dossier(s) infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Fichier(s) infecté(s):
                                        C:\WINDOWS\system32\config\systemprofile\Menu Démarrer\Programmes\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
                                        0
                                        1. Par contre il reste encore quelque chose non d'après le rapport combofix ?

                                          J'ai un doute sur deux fichiers.

                                          1- Avoir accès aux fichiers cachés :

                                          Cliquer sur démarrer
                                          Cliquer sur panneau de configuration
                                          Cliquer sur l'icône option des dossiers
                                          Cliquer sur onglet affichage
                                          Cochez afficher les fichiers et dossiers cachés
                                          décochez masquer les extensions de fichiers connus
                                          Décochez masquer les fichiers protégés du système faire appliquer et ok

                                          * Rends toi sur le site https://www.virustotal.com/gui/
                                          * Clique sur Parcourir, et navigue jusqu'au fichier suivant et valide :
                                          c:\windows\bnetunin.exe
                                          et
                                          c:\windows\diabunin.exe

                                          * Clique sur "Envoyer le fichier" : s'il a déjà été analysé, demande une nouvelle analyse.
                                          * Fais un copier/coller du rapport sur le forum.
                                          0
                                          • 1
                                          • 2